< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles

Malware at contractor exposes 8.7M karaoke records

🔒 Daiichi Kosho disclosed a malware infection at contractor Nippon Columbia Group that exposed records for 8,631,000 customers and 93,000 employees. The affected data reportedly includes full names, genders, dates of birth, email addresses, and phone numbers for patrons of chains such as BIG ECHO and MEGA BIG. Daiichi Kosho says its own systems were not breached and that NCG reset authentication credentials while investigating the incident. The company warns customers to be cautious of unsolicited contact requesting payments or personal information.
read more →

Cyber exec arrested amid ShinyHunters probe

🔍 Canadian cybersecurity executive Edward Dubrovsky was arrested in Pennsylvania in an investigation tied to alleged extortion activity linked to the ShinyHunters hacking group. Dubrovsky, who held senior roles at firms assisting ransomware and data breach victims with extortion negotiations, was taken into custody while attending a cybersecurity conference and later transferred to the Eastern District of Texas. Court dockets list conspiracy and extortion-related charges, though the formal complaint remains under seal.
read more →

AI-powered intrusion hits South Korea banks

🔒 A Chinese-speaking hacker used the ARTEX AI penetration testing suite and Claude agents to target multiple South Korean banks, including Shinhan, KB Kookmin, and Hana. CrowdStrike investigators found attacker infrastructure containing Claude session histories, ARTEX configs, and memory files that linked the incidents to previous financial-sector breaches. The exposure included clients' personal and credit card data and caused outages, prompting an emergency government response and calls for stronger protections for critical IT systems.
read more →

FBI Arrests Founder Linked to ShinyHunters Probe

📰 Agents with the FBI arrested the co-founder of a Canadian cybersecurity firm in Pennsylvania this week as part of an investigation into the ShinyHunters hacking group that stole sensitive FBI agent data. The suspect, identified in court records as Edward Dubrovsky (also spelled Dobrovsky), was reportedly attending a Cyber Risk Summit when arrested on charges including cyber extortion and conspiracy. Court filings show the case was moved to the Eastern District of Texas, where the ShinyHunters inquiry is now centralized. Sources say devices seized in Europe and other pending charges against ransomware negotiation firms may follow.
read more →

Credential-stealing workflow campaign hits hundreds

🔒 Cybersecurity researchers disclosed an active credential-theft campaign that used compromised maintainer GitHub accounts to inject malicious GitHub Actions workflows into more than 340 repositories. The malicious workflows, masquerading as Security Audit or GitHub Actions Security, exfiltrate repository secrets and credentials to a hard-coded IP address and scan the working tree and git history for API keys and tokens. The activity, attributed to the GhostAction campaign, has affected hundreds of users and led to thousands of secrets being harvested since late August 2026. Developers are urged to search for the offending workflow files, assume compromise, revoke affected credentials, and remove the injected workflows across branches and forks.
read more →

FBI Arrests Another Suspect Linked to ShinyHunters

🔎 The FBI announced on October 9 that it arrested another suspected ShinyHunters co-conspirator, a Canadian citizen taken into custody in Pennsylvania. The agency has not released the suspect's name or filed public charges, and details come from media reports citing unnamed sources. The arrest follows earlier detentions in the Netherlands and Jordan as investigators continue to probe the breach of the FBI jobs portal.
read more →

Unpatched AhsayCBS flaws used to deploy webshells

🔒 Threat actors are exploiting two unpatched AhsayCBS vulnerabilities to deploy webshells and cryptocurrency miners. The activity, observed on October 7, targeted at least five organizations and chained CVE-2026-105133 (authentication bypass) with CVE-2026-105134 (OS command injection). Researchers at Huntress report that the flaws persist in Ahsay 10.3.4 despite fixes in 10.3.2. Huntress recommends restricting management interface access and investigating potential compromise.
read more →

FBI arrests another suspected ShinyHunters member

🔍 The FBI announced the arrest of another suspected member of the ShinyHunters extortion group tied to last month's breach of FBI systems, Director Kash Patel said. While authorities have not named the suspect or detailed charges, reports indicate a Canadian citizen was detained in Pennsylvania and is considered a primary co-conspirator. The arrest follows earlier detentions and international cooperation as investigators work to dismantle the group and recover evidence.
read more →

P7 DarkSword iOS Exploit Kit Upgrades Capabilities

📣 iVerify and Censys researchers detailed a new P7 variant of the DarkSword iOS exploit kit that reduces on-device footprint, adds on-device keychain and crypto-wallet theft, and implements two-way C2 communication. The toolkit, which chains multiple iOS vulnerabilities to escape the browser sandbox and inject into SpringBoard, has been used in campaigns since late 2025 against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. P7 extracts keychain data to JSON prior to exfiltration, polls for commands frequently, and supports numerous remote actions including file exfiltration, command execution, and wallet extraction. Analysts also linked open directories and C2 infrastructure to multiple actors and uncovered two previously undocumented CVEs used by the kit.
read more →

Ransomware remediation owner charged with wire fraud

🛡️ The owner of a ransomware remediation firm, Zohar Pinhasi (aka "Zack Silver"), has been arraigned in New York on wire fraud charges for allegedly defrauding clients of MonsterCloud. Prosecutors say he claimed to recover encrypted data without paying ransoms but instead paid attackers and charged clients inflated fees. One alleged 2023 incident involved an $8,200 payment to criminals while the client was billed $150,000. Experts note such schemes and other scams continue to target ransomware victims.
read more →

Germany arrests alleged core Qilin ransomware member

🔒 Germany has arrested a Russian national suspected to be a leading member of the Qilin ransomware group after extradition from Japan earlier this month. Japanese and German authorities coordinated detention and extradition under the Extradition Law for Fugitives. Qilin (formerly Agenda) is a prolific RaaS operation blamed for attacks on major organizations worldwide.
read more →

US offers $10M reward for alleged Hafnium hacker

📰 The US State Department has offered up to US $10 million for information on Zhang Yu, a 44-year-old alleged member of the Chinese state-linked hacker group Hafnium. Zhang is accused of directing intrusions that exploited zero-day flaws in Microsoft Exchange Server and of stealing data, including COVID-19 research, from US institutions. He is charged alongside Xu Zewei, who was arrested in Italy and extradited to the US; Zhang is believed to be in China and unlikely to be extradited. The bounty aims to pressure his movements and encourage tips despite diplomatic and legal complications.
read more →

Five US States Sue TP‑Link Over Router Security Claims

🔍 Four more U.S. states—Florida, Iowa, Montana and Nebraska—filed suits on October 6 accusing TP‑Link Systems of misleading customers about router security and its separateness from China; Texas had sued in February. The complaints cite device flaws, end‑of‑life models, and privacy concerns tied to Chinese intelligence law, while TP‑Link denies the allegations and vows to contest them. Researchers disclosed technical details of five ISP‑supplied device flaws on October 8, and 21 state attorneys general have written the FCC about TP‑Link's pending approvals.
read more →

Attackers exploit AhsayCBS flaws to deploy miners

🔍 Threat actors have been observed chaining two recently disclosed AhsayCBS vulnerabilities—an improper authentication bug (CVE-2026-105133) and an OS command injection (CVE-2026-105134)—to bypass authentication and execute arbitrary commands. Exploitation began on October 7, 2026, enabling deployment of web shells and XMRig miners that masquerade as Microsoft Edge processes. Huntress reported targeted reconnaissance, AI-assisted PowerShell scripts, and use of legitimate-but-vulnerable drivers to gain kernel access. Organizations are advised to restrict web management access and monitor for compromise until patches are confirmed effective.
read more →

CISA Adds Five Flaws Exploited by Flax Typhoon

🛡️ CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after a China-linked actor called Flax Typhoon abused them to gain access and exfiltrate data. The flaws span ProFTPD, ONLYOFFICE Docs, Strapi, Apache Struts, and ISC BIND with CVSS scores from 7.2 to 10.0. A joint advisory from multiple nations links the activity to a China-based company, and federal agencies must patch or discontinue affected systems by October 11, 2026.
read more →

Q3 2026 Sees Record Quarterly Ransomware Volume

🔍 Comparitech found 2,627 claimed ransomware incidents in Q3 2026, marking a 27% increase from Q2 and 61% year-on-year. The finance and technology sectors saw the largest rises, while education, healthcare, government and utilities also experienced notable increases. The report linked part of the surge to AI-driven campaigns and highlighted a rise in triple extortion tactics, with average demands around $602,400.
read more →

Dual Citizen Pleads Guilty in Global Mule Scheme

📰 A Ukrainian-Russian dual citizen, Oleg Korniev, pleaded guilty to leading a large money laundering ring that processed millions for cybercriminals. The organization, Your Mule Cashout (YMCO), recruited over 15,000 money mules, primarily in the U.S., to move stolen funds through bank accounts and wire services. Korniev admitted laundering at least $7 million and faces substantial prison time and restitution obligations.
read more →

Inside Luna Moth’s Data Extortion Playbook

🔍 This article examines an anonymous archive called “The Luna Moth Files,” which purportedly exposes internal materials from Silent Ransom Group (SRG), also tracked as Luna Moth and UNC3753. The release contains chat logs, a vishing playbook, screenshots, and a claimed fake résumé, offering insight into a social engineering‑driven extortion operation. Check Point treats the claims as unverified while highlighting how the group structures research, calling, technical access, and negotiation into a repeatable, commercialized process.
read more →

GoBalance bug allows .onion address hijacking

🛡️ A critical bug in GoBalance, a Go rewrite of Onionbalance used by many dark-web sites, leaks the private key that controls an .onion address by signing descriptors with only half of the Tor private key. The flaw lets anyone derive the site's long-term master key from a single public descriptor and then replace the address with a copy they control. Searchlight Cyber disclosed the issue after Dread experienced two address takeovers; vulnerable sites must generate new addresses and migrate users to remain safe.
read more →

Pwn2Own Ireland 2026: $1.26M Awarded to Researchers

🔒 The Pwn2Own Ireland 2026 contest concluded with security researchers earning $1,262,000 after demonstrating 98 zero-day vulnerabilities across seven product categories. Ikotas Labs topped the event with $361,000 and 42.5 Master of Pwn points after successful exploits against the Samsung Galaxy S26, OpenAI Codex, and Oracle Autonomous AI Database. Vendors are required to patch disclosed flaws within 90 days per Trend Micro's Zero Day Initiative rules.
read more →