#data-theft

[ follow ]
#cybersecurity

Urgent warning to Google users after hackers uploaded fake ads

Users were warned about a cyberattack posing as Google Authenticator, leading to personal data theft.

$75 Million Record-Breaking Ransom Paid To Cybercriminals, Say Researchers

The largest known ransom payment of US $75 million was made by a Fortune 50 company to the Dark Angels ransomware group.

Ongoing campaign compromises senior execs' Azure accounts, locks them using MFA

Unknown attackers are targeting Microsoft Azure accounts in an ongoing campaign to steal sensitive data and financial assets.
The attackers use phishing techniques and account takeovers to compromise the targeted accounts and enroll them in multifactor authentication to secure them.

Researchers warn high-risk ConnectWise flaw under attack is 'embarrassingly easy' to exploit | TechCrunch

High-risk vulnerability in ConnectWise ScreenConnect is easy to exploit
Malicious hackers actively exploiting the flaw

Fake IT workers from North Korea have started blackmailing their victims

North Korean group Nickel Tapestry is now training IT workers not only to find jobs abroad but also to steal data for extortion.

So your data was stolen in a data breach

The recent data breach affects hundreds of millions, highlighting severe vulnerabilities in data security.

Urgent warning to Google users after hackers uploaded fake ads

Users were warned about a cyberattack posing as Google Authenticator, leading to personal data theft.

$75 Million Record-Breaking Ransom Paid To Cybercriminals, Say Researchers

The largest known ransom payment of US $75 million was made by a Fortune 50 company to the Dark Angels ransomware group.

Ongoing campaign compromises senior execs' Azure accounts, locks them using MFA

Unknown attackers are targeting Microsoft Azure accounts in an ongoing campaign to steal sensitive data and financial assets.
The attackers use phishing techniques and account takeovers to compromise the targeted accounts and enroll them in multifactor authentication to secure them.

Researchers warn high-risk ConnectWise flaw under attack is 'embarrassingly easy' to exploit | TechCrunch

High-risk vulnerability in ConnectWise ScreenConnect is easy to exploit
Malicious hackers actively exploiting the flaw

Fake IT workers from North Korea have started blackmailing their victims

North Korean group Nickel Tapestry is now training IT workers not only to find jobs abroad but also to steal data for extortion.

So your data was stolen in a data breach

The recent data breach affects hundreds of millions, highlighting severe vulnerabilities in data security.
morecybersecurity

SK hynix chip engineer gets 1.5 years in prison on IP theft

A former SK hynix employee was sentenced to 18 months for stealing semiconductor technology, raising concerns about corporate espionage and data protection.

Hazem Altal: Unraveling the Web of Fraud at a Turkish Hair Clinic - Social Media Explorer

A scandal in Istanbul exposes extensive medical fraud involving data theft and unauthorized practices by former clinic manager Hazem Altal.
#cybercrime

Latvian Hacker Extradited to U.S. for Role in Karakurt Cybercrime Group

Deniss Zolotarjovs has been indicted in the U.S. for cybercrimes including data theft, extortion, and money laundering since August 2021.

Meow ransomware sees surge of activity post-overhaul

Meow ransomware has shifted from file encryption to pure data theft, becoming highly active in global cybercrime.

FCC staff targeted in phishing attack that cloned agency login site

The FCC was targeted in a phishing operation using a fake login page.
The phishing kit named CryptoChameleon targeted cryptocurrency exchange platforms and successfully collected sensitive information.

Brazilian police claim they've cuffed the USDoD cybercrook

Brazilian police arrest a suspected hacker linked to high-profile data thefts, including attacks on the FBI and Airbus.

Europol confirms incident after data breach claims

Europol is investigating a cybercriminal's claims of stealing data; Europol Platform for Experts affected but no core systems compromised.

Snowflake Users Targeted for Data Theft and Extortion

Financially motivated threat actor UNC5537 accessed data from 165 organizations' Snowflake instances using stolen credentials and sold data to cybercriminals for various malicious purposes.

Latvian Hacker Extradited to U.S. for Role in Karakurt Cybercrime Group

Deniss Zolotarjovs has been indicted in the U.S. for cybercrimes including data theft, extortion, and money laundering since August 2021.

Meow ransomware sees surge of activity post-overhaul

Meow ransomware has shifted from file encryption to pure data theft, becoming highly active in global cybercrime.

FCC staff targeted in phishing attack that cloned agency login site

The FCC was targeted in a phishing operation using a fake login page.
The phishing kit named CryptoChameleon targeted cryptocurrency exchange platforms and successfully collected sensitive information.

Brazilian police claim they've cuffed the USDoD cybercrook

Brazilian police arrest a suspected hacker linked to high-profile data thefts, including attacks on the FBI and Airbus.

Europol confirms incident after data breach claims

Europol is investigating a cybercriminal's claims of stealing data; Europol Platform for Experts affected but no core systems compromised.

Snowflake Users Targeted for Data Theft and Extortion

Financially motivated threat actor UNC5537 accessed data from 165 organizations' Snowflake instances using stolen credentials and sold data to cybercriminals for various malicious purposes.
morecybercrime
#security-vulnerability

Google Cloud Document AI flaw (still) allows data theft

The Google Cloud Document AI service has a serious vulnerability that remains unaddressed, enabling potential data theft from Cloud Storage.

1Password vulnerability lets attackers steal Vault items

Mac users with versions before 8.10.36 of 1Password are vulnerable to a bug allowing theft of vault items.

Google Cloud Document AI flaw (still) allows data theft

The Google Cloud Document AI service has a serious vulnerability that remains unaddressed, enabling potential data theft from Cloud Storage.

1Password vulnerability lets attackers steal Vault items

Mac users with versions before 8.10.36 of 1Password are vulnerable to a bug allowing theft of vault items.
moresecurity-vulnerability
#malware-campaign

New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions

Malware campaign installs rogue extensions via trojan masquerading as popular software.
Trojan malware distributes adware to sophisticated malicious scripts targeting private data theft.
Extensions can't be disabled by users and newer scripts disable browser updates, affecting at least 300,000 Chrome and Edge users.

GitHub struggles to keep up with automated malicious forks

Malware campaign started in PyPI spread to GitHub infecting 100,000 repositories.
Attackers upload altered files to GitHub, cloning legitimate repos to spread malware loaders.

New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions

Malware campaign installs rogue extensions via trojan masquerading as popular software.
Trojan malware distributes adware to sophisticated malicious scripts targeting private data theft.
Extensions can't be disabled by users and newer scripts disable browser updates, affecting at least 300,000 Chrome and Edge users.

GitHub struggles to keep up with automated malicious forks

Malware campaign started in PyPI spread to GitHub infecting 100,000 repositories.
Attackers upload altered files to GitHub, cloning legitimate repos to spread malware loaders.
moremalware-campaign

Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords

Security flaws in Roundcube webmail could allow theft of sensitive information through malicious JavaScript.

Facebook ads for this fake AI image editor were just an excuse to infect your PC with malware

Attackers exploit AI image editing tool popularity to distribute malware through fake applications on social media, stealing credentials and data for sale on the dark web.

Facebook Ads Lead to Fake Websites Stealing Credit Card Information

Facebook users targeted by ERIAKOS scam e-commerce network, employing fake websites for data theft.
#lilacsquid

New Nork-y cyberespionage outfit uncovered after three years

A new cybercrime group named LilacSquid has been active for three years, targeting organizations in the US, Europe, and Asia with espionage-focused attacks.

Cisco Talos: LilacSquid Threat Actor Targets Multiple Sectors Worldwide With PurpleInk Malware

LilacSquid, a cyberespionage group, uses various tactics to compromise systems with custom malware, targeting organizations worldwide for data theft.

New Nork-y cyberespionage outfit uncovered after three years

A new cybercrime group named LilacSquid has been active for three years, targeting organizations in the US, Europe, and Asia with espionage-focused attacks.

Cisco Talos: LilacSquid Threat Actor Targets Multiple Sectors Worldwide With PurpleInk Malware

LilacSquid, a cyberespionage group, uses various tactics to compromise systems with custom malware, targeting organizations worldwide for data theft.
morelilacsquid

Hackers are threatening to publish a huge stolen sanctions and financial crimes watchlist | TechCrunch

The stolen World-Check database contains 5.3 million records

185K people's data stolen in Cherry Health ransomware raid

Ransomware attack on US healthcare organization compromised sensitive data of nearly 185,000 individuals.

PyPI suspends registrations amid malware attack

PyPI has suspended new project creation due to a malware upload campaign.
Attackers are using typosquatting to distribute malicious Python packages for data theft.
#cyber-attack

Ransomware gang leaks data stolen from Scottish NHS board | Computer Weekly

Inc Ransom claimed to have stolen three terabytes of data from NHS Scotland, including sensitive medical reports and patient letters.
NHS Dumfries and Galloway acknowledged a cyber attack, with a small data dump disclosed and ongoing efforts to limit any data sharing.

After cyber attack, New York hospitals find stolen patient info stored in Massachusetts, look for its return

Claxton-Hepburn Medical Center and Carthage Area Hospital have filed legal paperwork to get their stolen data back
The stolen data was found to be stored on a server owned by Wasabi Technologies in Boston, Massachusetts

Ransomware gang leaks data stolen from Scottish NHS board | Computer Weekly

Inc Ransom claimed to have stolen three terabytes of data from NHS Scotland, including sensitive medical reports and patient letters.
NHS Dumfries and Galloway acknowledged a cyber attack, with a small data dump disclosed and ongoing efforts to limit any data sharing.

After cyber attack, New York hospitals find stolen patient info stored in Massachusetts, look for its return

Claxton-Hepburn Medical Center and Carthage Area Hospital have filed legal paperwork to get their stolen data back
The stolen data was found to be stored on a server owned by Wasabi Technologies in Boston, Massachusetts
morecyber-attack
#minnesota-timberwolves

Fired Wolves employee given supervised release

An ex-employee of the Minnesota Timberwolves was arrested for stealing sensitive internal information.
The stolen data included strategic NBA information and the executive's personal details.

Wolves employee fired, arrested for alleged theft

An employee of the Minnesota Timberwolves was fired, arrested, and charged with felony third-degree burglary for stealing strategic NBA information.
The Timberwolves executive, Sachin Gupta, had his personal and team-related information stolen from a hard drive left in his office.

Fired Wolves employee given supervised release

An ex-employee of the Minnesota Timberwolves was arrested for stealing sensitive internal information.
The stolen data included strategic NBA information and the executive's personal details.

Wolves employee fired, arrested for alleged theft

An employee of the Minnesota Timberwolves was fired, arrested, and charged with felony third-degree burglary for stealing strategic NBA information.
The Timberwolves executive, Sachin Gupta, had his personal and team-related information stolen from a hard drive left in his office.
moreminnesota-timberwolves

Change Healthcare's data protection under US investigation

Change Healthcare under investigation for alleged data theft by ALPHV ransomware group
US HHS launching formal inquiry into Change Healthcare's data protection practices
#extortion

Capital Health acknowledges a cyberattack last month but details are lacking

LockBit3.0 claims to have stolen over 10 million files and 7 terabytes of medical confidentiality data from CapitalHealth.org in New Jersey.
There is no proof to support LockBit3.0's claims and Capital Health has not mentioned any extortion attempt or known group claiming responsibility.

Vastaamo victims' lawyer: Some took their own lives after patient record leak

Patient records from Vastaamo used in extortion led to suicides.
Trial of Aleksanteri Kivimäki nearing conclusion in data theft case.

Capital Health acknowledges a cyberattack last month but details are lacking

LockBit3.0 claims to have stolen over 10 million files and 7 terabytes of medical confidentiality data from CapitalHealth.org in New Jersey.
There is no proof to support LockBit3.0's claims and Capital Health has not mentioned any extortion attempt or known group claiming responsibility.

Vastaamo victims' lawyer: Some took their own lives after patient record leak

Patient records from Vastaamo used in extortion led to suicides.
Trial of Aleksanteri Kivimäki nearing conclusion in data theft case.
moreextortion

Here Come the AI Worms

AI worms can now spread between generative AI agents, potentially causing data theft and malware deployment.
As generative AI systems become more autonomous, the risk of new cyberattacks increases.
#cyberattack

Pharmaceutical giant Cencora says data was stolen in a cyberattack

Cencora, previously AmerisourceBergen, faced a cyberattack involving data theft.
The company contained the incident, is cooperating with authorities, but impact on finances is undetermined.

4 Remote Workplaces Most Vulnerable To Cyberattacks And 9 Common Mistakes

Remote workers face increased cyber threats as cyberattacks on individuals and companies continue to rise.
Co-working spaces, libraries, coffee shops, cafes, and working in a different country or city from your company are the most vulnerable locations for data theft.

Caravan club admits members' personal data possibly accessed

The Caravan and Motorhome Club (CAMC) still cannot confirm whether members' data was stolen in a January cyberattack.
The club has listed the types of data that might have been accessed, but remains uncertain about any theft.

Rhysida ransomware gang hits hospital holding royal family's data | Computer Weekly

The Rhysida ransomware group has targeted the private King Edward VII Hospital in London and claims to have stolen data on the royal family.
The gang is offering the stolen data for sale, with a price set at 10 bitcoin if no buyer takes up the offer within seven days, they will make the data publicly available.

NHS confirms stolen data published online is from blood test provider

The NHS provider Synnovis suffered a cyber-attack by the Russian group Qilin, leading to the publication of stolen data online.

Pharmaceutical giant Cencora says data was stolen in a cyberattack

Cencora, previously AmerisourceBergen, faced a cyberattack involving data theft.
The company contained the incident, is cooperating with authorities, but impact on finances is undetermined.

4 Remote Workplaces Most Vulnerable To Cyberattacks And 9 Common Mistakes

Remote workers face increased cyber threats as cyberattacks on individuals and companies continue to rise.
Co-working spaces, libraries, coffee shops, cafes, and working in a different country or city from your company are the most vulnerable locations for data theft.

Caravan club admits members' personal data possibly accessed

The Caravan and Motorhome Club (CAMC) still cannot confirm whether members' data was stolen in a January cyberattack.
The club has listed the types of data that might have been accessed, but remains uncertain about any theft.

Rhysida ransomware gang hits hospital holding royal family's data | Computer Weekly

The Rhysida ransomware group has targeted the private King Edward VII Hospital in London and claims to have stolen data on the royal family.
The gang is offering the stolen data for sale, with a price set at 10 bitcoin if no buyer takes up the offer within seven days, they will make the data publicly available.

NHS confirms stolen data published online is from blood test provider

The NHS provider Synnovis suffered a cyber-attack by the Russian group Qilin, leading to the publication of stolen data online.
morecyberattack

Google's Threat Analysis Group's Spyware Research: How CSVs Target Devices and Applications

Commercial surveillance vendors sell surveillance services to governments for monitoring or spying purposes.
CSVs openly operate with websites, marketing content, and sales teams, and may change names to avoid scrutiny.

Phishers pwn hundreds of users, dozens of Azure environments

Phishing campaign targets senior business executives, including C-suite roles and VPs.
Attackers aim to gain access to privileged accounts and steal sensitive data.

Warzone RAT Sales and Support Actors in Malta and Nigeria Charged in U.S. Federal Indictments

Federal authorities seized internet domains used to sell RAT malware
Individuals in Malta and Nigeria were indicted for selling malware and supporting cybercriminals

New attack steals AI secrets from GPUs made by Apple, AMD, and Qualcomm

Demand for GPU chips is increasing as companies rely on them for running large language models and processing data at scale.
Researchers have uncovered a vulnerability in multiple brands of GPUs, including Apple, Qualcomm, and AMD chips, that could allow attackers to steal data from a GPU's memory.

Data-theft malware exploits Windows Defender SmartScreen

Criminals are exploiting a Windows Defender SmartScreen bypass vulnerability to distribute Phemedrone Stealer malware that steals sensitive information from infected PCs.
The malware targets a wide range of browsers, applications, cryptocurrency wallets, and messaging apps to gather sensitive information and login credentials.

First American makes progress on restoring systems from pre-Christmas cyberattack

First American Financial is making progress in restoring its systems after a data theft incident.
This is the second major cyber security incident to hit the title industry in less than a month.

Recent attacks on Fred Hutch and Integris: Is attempting to extort patients directly becoming the "new normal?"

DataBreaches previously reported a breach involving Integris Health in Oklahoma.

Au: St Vincent's unable to confirm if medical records stolen

Jess Malcolm and Greg Brown report:

Multiple Data Leaks at 23andme

Genetics testing firm 23andme and its users were targeted by cybercriminals who leaked or breached millions of user profiles and genetic data records.
The threat actors accessed user accounts through credential stuffing and scraped data from the DNA Relatives feature.
#data theft

An email vulnerability let hackers steal data from governments around the world

Google's Threat Analysis Group discovered and helped patch an email server flaw used to steal data from government organizations in several countries.
The exploit targeted the email server Zimbra Collaboration and stole email data, user credentials, and authentication tokens.
Updating software with the latest fixes is crucial to protect against these types of exploits.

British Library confirms data stolen during ransomware attack | TechCrunch

The British Library has confirmed that a ransomware attack led to the theft of internal data.
The attack caused a major technology outage across the library's sites and disrupted online and on-site services.
The ransomware gang responsible for the attack has demanded over $740,000 worth of bitcoin.

Some city data was stolen during cyber breach; full scope remains unknown, Long Beach says

Long Beach officials confirmed a cybersecurity breach and data theft.
The city does not currently know what data was taken or the extent of the breach.

An email vulnerability let hackers steal data from governments around the world

Google's Threat Analysis Group discovered and helped patch an email server flaw used to steal data from government organizations in several countries.
The exploit targeted the email server Zimbra Collaboration and stole email data, user credentials, and authentication tokens.
Updating software with the latest fixes is crucial to protect against these types of exploits.

British Library confirms data stolen during ransomware attack | TechCrunch

The British Library has confirmed that a ransomware attack led to the theft of internal data.
The attack caused a major technology outage across the library's sites and disrupted online and on-site services.
The ransomware gang responsible for the attack has demanded over $740,000 worth of bitcoin.

Some city data was stolen during cyber breach; full scope remains unknown, Long Beach says

Long Beach officials confirmed a cybersecurity breach and data theft.
The city does not currently know what data was taken or the extent of the breach.
moredata theft

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware | TechCrunch

Snowflake, a cloud data analysis company, is at the center of recent alleged data thefts affecting some of its major customers.

Entertainment giant Ticketmaster acknowledges cybersecurity incident

Live Nation Entertainment, Ticketmaster's parent company, faces a cybersecurity breach after data being advertised for sale by a hacker.
Cybersecurity researchers suspect authenticity of stolen data while Ticketmaster remains unresponsive to inquiries about the incident.

Data stealing malware evolves to abuse .NET CLR

ViperSoftX malware evolves with .NET CLR obfuscation, posing increased threat to enterprises.

Mac users served info-stealer malware through Google ads

Mac malware circulating through Google ads steals sensitive data, highlighting risks for users.
The malware mimics a real browser to deceive users and uses clever techniques to bypass macOS security measures.
Developers are actively creating Mac-focused stealers like Poseidon for illicit data collection.
[ Load more ]