Tag: theft
-
Opera GX browser vulnerability could allow data theft and DoS attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/opera-gx-browser-vulnerability-allows-data-theft-and-dos-attacks
-
U.S. Government Agency Paid $1M to Data Extortion Group Kairos
Tags: blockchain, data, data-breach, extortion, government, group, ransom, ransomware, theft, threatA U.S. government agency paid $1M to Kairos, a group focused on data theft and extortion rather than ransomware, Ransom-ISAC reports. A new case study from Ransom-ISAC reconstructs a complete data-extortion incident involving a U.S. government body and a threat actor called Kairos, using a leaked negotiation transcript and blockchain tracing of the ransom payment.…
-
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
Tags: blockchain, breach, data, data-breach, extortion, government, group, ransom, ransomware, theftA U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left.The odd part: the group that took the money calls itself Kairos, but it may not be…
-
FortiBleed Credential Theft Connected to INC and Lynx Ransomware
FortiBleed, the Fortinet credential theft campaign, is now connected to INC Ransom and Lynx, with a Nextcloud zero-day vulnerability also under investigation. First seen on hackread.com Jump to article: hackread.com/fortibleed-credential-theft-in-lynx-ransomware/
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.”An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment First seen on thehackernews.com Jump to…
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
FortiBleed credential-theft campaign linked to Lynx ransomware
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/
-
Amazon fined $2.25M for withholding evidence from fraud victims
The U.S. Federal Trade Commission (FTC) says Amazon will pay a $2.25 million civil penalty to settle charges that it blocked identity theft victims’ access to transaction records. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/amazon-fined-225m-for-withholding-evidence-from-fraud-victims/
-
Medtronic Notifying Patients Affected by Data Theft Hack
Ransomware Gang ShinyHunters Gang Claimed It Stole 9M Records From Device Maker. Medical device maker Medtronic has begun notifying a yet undisclosed number of patients that their information, including health records and Social Security numbers – was compromised in an April cyber incident. ShinyHunters had earlier claimed to steal more than 9 million of the…
-
New BioShocking attack manipulates AI browser into data theft
A new prompt injection attack dubbed “BioShocking” could trick AI-powered browsers into treating real-world risky actions as part of a fictional scenario, causing them to ignore any safety guardrails. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-bioshocking-attack-manipulates-ai-browser-into-data-theft/
-
Nissan Traces Data Breach to PeopleSoft Zero-Day Exploit
Extortionists Add National Association of Insurance Commissioners to Breach List. Japanese automotive giant Nissan and the U.S. National Association of Insurance Commissioners are the latest organizations to confirm they fell victim to cyber extortionists who recently wielded a zero-day exploit against Oracle PeopleSoft, leading to the theft of data. First seen on govinfosecurity.com Jump to…
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to turn trusted executive channels into fraud infrastructure. The campaign was highlighted in advisories tied to India’s I4C and NCTAU, which warned that attackers pose as regulators or senior bosses, deliver malicious…
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/
-
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/amazon-q-vs-extension-flaw-leads-cloud-credential-theft
-
4 arrested in Poland for SIM-swapping and cryptocurrency theft
First seen on scworld.com Jump to article: www.scworld.com/brief/four-arrested-in-poland-for-sim-swapping-and-cryptocurrency-theft
-
NAIC confirms cyberattack after ShinyHunters claims 3.1TB data theft
First seen on scworld.com Jump to article: www.scworld.com/brief/naic-confirms-cyberattack-after-shinyhunters-claims-3-1tb-data-theft
-
Grand Theft Auto VI hype fuels new wave of scams targeting gamers
First seen on scworld.com Jump to article: www.scworld.com/brief/grand-theft-auto-vi-hype-fuels-new-wave-of-scams-targeting-gamers
-
Third-Party Breach at Polymarket Leads to $2.94M Crypto Theft
Polymarket confirmed hackers stole funds from some users after attackers injected malicious code through a compromised third-party vendor. Polymarket confirmed that a security breach at a third-party vendor allowed attackers to inject malicious code into its website, leading to the theft of funds from an undisclosed number of users. The company said it has contained…
-
CMC Releases Analysis and Guidance for Education Sector After Canvas Data Breach
The UK Cyber Monitoring Centre reviews the Canvas breach affecting 160 UK universities, highlighting data theft risks and financial impacts of cyber incidents First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cmc-analysis-education-canvas-data/
-
Iranian Hacker Arrested Over Alleged $3.4 Billion Cyberattack on USA Infrastructure
An alleged Iranian hacker accused of hacking US infrastructure has been arrested in Montenegro following a joint operation by Montenegrin police and the U.S. Federal Bureau of Investigation (FBI). The suspect is expected to face charges related to computer fraud, hacking, conspiracy, and identity theft after authorities linked him to a years-long cyber campaign that…
-
AI Firms Seek US Help Against China Model Distillation
Anthropic Says Legal Gaps Leave Frontier Labs Vulnerable to LLM Copying. U.S.-based AI companies are urging the U.S. government to crack down on alleged illicit model distillation by Chinese AI developers, arguing current protections lack enforcement. Anthropic and others say legal reforms and clearer antitrust rules are needed to deter theft of frontier AI models.…
-
Poland busts SIM-swapping gang tied to millions in crypto theft
Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/poland-busts-sim-swapping-gang-tied-to-millions-in-crypto-theft/
-
GTA 6 Early Access Scam Uses Fake VIP Pages to Steal Cryptocurrency Payments
A fresh wave of scam websites is exploiting the fevered anticipation for Grand Theft Auto VI, offering “VIP early access” in exchange for cryptocurrency payments and delivering nothing in return. These pages are carefully designed to look legitimate neon Vice Citystyle art, official-looking logos, luxury-car imagery and polished layouts then instruct victims to pay hundreds…
-
LastPass Confirms Customer Data Breach After Klue OAuth Token Theft
LastPass has confirmed it was affected by the Klue supply chain incident, saying an unauthorised actor used stolen… First seen on hackread.com Jump to article: hackread.com/lastpass-customer-data-breach-klue-oauth-token/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/
-
GTA 6 early access offers are taking gamers’ crypto
Scam websites are circulating across the internet with a pitch aimed at millions of gamers: a way to play Grand Theft Auto VI before its release. The pages promise early … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/23/gta-6-early-access-scam/

