< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 13 of 165

Fake TTF loader used in global phishing campaign

🛡️ Fortinet's FortiGuard Labs reports a global phishing campaign using obfuscated JavaScript and a Lua-based loader disguised as a TrueType Font (.ttf) to evade detection. The attack chain delivers RATs and infostealers such as Agent Tesla, Remcos, XWorm, and a Snake Keylogger variant, employing in-memory execution and various anti-analysis techniques. Researchers noted business- and payment-themed lures, compressed archives with script loaders, and Donut shellcode to avoid writing payloads to disk. Defenders are advised to combine identity controls, application restrictions, and behavior-based detection.
read more →

US Charges Two for Laundering $43M in Investment Fraud

💼 U.S. prosecutors charged two New York residents, Zhuoying Chen and Haojie Zhang, for operating a money-laundering network that moved at least $43 million stolen in investment fraud schemes between 2020 and 2022. The indictment alleges they used roughly 45 shell companies and 140 bank accounts to funnel proceeds to China while coordinating a network of over a dozen associates. Authorities say the scams used social media and fake profiles to lure victims and show fabricated profits to induce further investments. If convicted of conspiracy to commit money laundering, both face up to 20 years in prison.
read more →

Coca‑Cola reports Fairlife ransomware halts US production

📰 Coca‑Cola disclosed a ransomware incident affecting its Fairlife dairy subsidiary that led to temporary suspension of U.S. production. The company reported unauthorized access to production-related systems, activated incident response and engaged outside cybersecurity advisors while notifying law enforcement. Product safety remains unaffected and Canadian operations are not impacted. An investigation is ongoing and no claim of data theft or extortion has been confirmed.
read more →

OkoBot framework deploys 20+ payloads to steal crypto

🛡️ A new modular malware framework named OkoBot delivers over 20 payloads to steal cryptocurrency seed phrases, credentials, and other sensitive data. The campaign uses ClickFix lures and malicious GitHub repositories, sometimes trojanizing legitimate tools, and evolved from the earlier TookPS activity. Kaspersky found the campaign active since January and primarily targeting victims in Brazil, Vietnam, Canada, Mexico, and Turkey. Notable modules include browser injectors, SeedHunter for wallet recovery prompts, keyloggers, and spyware that records wallet and password manager windows.
read more →

23andMe to Pay $18M After Massive Genetic Data Breach

🔒 A coalition of 43 state attorneys general reached an $18 million settlement with 23andMe (now Chrome Holding Co.) over a 2023 data breach that exposed genetic data of 6.9 million customers. Investigators found the company lacked basic protections against credential-stuffing attacks, including multifactor authentication, password blocklisting, and adequate monitoring. The settlement imposes new security requirements, governance measures, and preserves consumer deletion rights while following prior lawsuits and fines.
read more →

ClickLock macOS stealer leverages ClickFix social lure

🛡️ Group-IB researchers describe a new macOS stealer called ClickLock that combines a ClickFix "paste-a-command" lure with a coercion routine that disables the desktop until a password is surrendered. The modular campaign downloaded four components from compromised WordPress sites to steal Keychain and browser credentials, exfiltrate wallet data, and install a GSocket backdoor. Operators forced compliance by killing system processes in loops, suppressing warnings and relaunching credential prompts; exfiltration used Telegram bots and modules self-deleted, leaving a stealthy backdoor.
read more →

The TTF Trap: Lua Loader Campaign Analysis

🔍 Since late March 2026, FortiGuard Labs documented a global phishing campaign that uses heavily obfuscated JScript droppers and AutoIt/Lua-based loaders disguised as .ttf files to deploy RATs and infostealers. Attackers impersonate reputable organizations to deliver malicious archives that stage multi-layered loaders with low detection rates. The campaign ultimately deploys payloads like Agent Tesla, Remcos, XWorm, and Snake-derived keyloggers, enabling remote control and data theft.
read more →

TELEPUZ modular malware spreads via ClickFix attacks

🛡️ Elastic Security Labs disclosed a new lightweight, modular malware named TELEPUZ that has been propagated through ClickFix (pastejacking) lures since late April 2026. The campaign delivers a Go-based Vidar stealer variant which then fetches a C-based TELEPUZ stager and main DLL, with artifacts hosted on a domain linked to the campaign. TELEPUZ includes extensive obfuscation, anti-VM and geofencing checks, AMSI/ETW unhooking, privilege escalation, service persistence, and WebSocket-based C2 with fallback retrieval via Telegram, Steam, DNS and a Polygon smart contract.
read more →

Two Scattered Spider Members Sentenced for TfL Hack

🔒 Two leading members of the Scattered Spider collective were sentenced to five years and six months each for the August 2024 breach of Transport for London (TfL). The attack disrupted internal systems, affected services like Dial-a-Ride and contactless ticketing, and rendered 148 systems inoperable. Investigations led to arrests in September 2024, and authorities credited TfL's cooperation with enabling convictions.
read more →

PhantomEnigma Abuses Brazilian Government Sites

🛡️ ANY.RUN uncovered an active PhantomEnigma campaign that hijacked over 20 Brazilian government websites to deliver malware. The operation used authenticated emails, compromised mailboxes, and trusted .gov.br hosts to redirect victims to malicious installers and a modular index.js backdoor. Researchers linked hundreds of sandbox sessions to reveal the campaign’s infrastructure, delivery chains, and detection guidance.
read more →

Sentencing in TfL cyber-attack highlights motive

🔒 Two young men were sentenced to five years and six months each for an unauthorised cyber-attack against Transport for London (TfL) after pleading guilty under the UK Computer Misuse Act. The judge found motives included "selfish bravado" alongside other factors, and noted their high expertise despite youth and neurodiversity. The attack, linked to group Scattered Spider, caused widespread service and data disruption affecting millions and significant financial losses.
read more →

CISA orders federal patching for exploited Oracle EBS flaw

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch systems by Saturday to mitigate active exploitation of a critical Oracle E-Business Suite vulnerability, tracked as CVE-2026-46817. The flaw in the Oracle Payments File Transmission component allows unauthenticated HTTP access leading to system takeover in low-complexity attacks. Oracle issued fixes in its May 2026 Critical Security Patch Update and urged immediate patching, while security firms and CISA have observed active exploitation. Shadowserver reports over 1,000 Internet-exposed Oracle EBS instances, many in the U.S., prompting CISA to add the flaw to its list of known exploited vulnerabilities and mandate remediation under BOD 26-04.
read more →

Spirals ransomware encrypts corporate networks rapidly

🛡️Researchers report a June intrusion where the new Spirals ransomware actor moved from initial access to data theft and encryption in under 24 hours. After compromising a publicly exposed IIS server and uploading an ASP.NET web shell, the attacker bypassed UAC, enabled RDP, created local accounts, and harvested credentials. They disabled security and backup services, used multiple lateral movement and remote-access tools, and deployed a Rust-based payload named bitsadmin.exe to encrypt files and drop a ransom note.
read more →

Dutch police dismantle large investment fraud ring

🔍 The Dutch Police announced arrests tied to an international investment fraud operation that ran multiple call centers and posed as financial advisers. Authorities say the organization generated over €100 million per month at its peak, targeted victims with fake trading dashboards, and persuaded them to transfer cryptocurrencies. The main suspect, a 46-year-old Israeli-Polish national with an alleged history of hacking, was arrested in Poland and extradited to the Netherlands. Additional arrests took place in Cyprus, Greece, and Belgium as investigations continue.
read more →

Google Gemini CLI abused to operate malware botnet

🔍 A Russian-speaking actor called "bandcampro" leveraged Google's open-source Gemini CLI as an AI hacking agent and to run a small botnet targeting at least eight systems in a dental clinic. Over 200 sessions between May and April, the AI executed migration, troubleshooting, and operational improvements, storing credentials and following a built-in C2 playbook. Trend Micro found the setup tiny and unsophisticated, with Python HTTP and PowerShell agents and persistence via scheduled tasks, WMI, and registry changes.
read more →

Spanish police dismantle €140M cyber fraud ring

🔍 Spanish police dismantled an industrial-scale cybercrime and money-laundering operation that stole €140 million via investment fraud and business email compromise. Four suspects were arrested across Spain, Portugal, and Panama after raids on multiple premises and an international operation with Interpol and Europol. Authorities seized digital devices, froze €3 million in proceeds, and identified hundreds of mule accounts used to launder funds.
read more →

LabubaRAT Rust RAT Masquerades as NVIDIA Runtime

🛡️ Cybersecurity researchers disclosed a previously undocumented Rust-based remote access trojan, LabubaRAT, which impersonates an NVIDIA runtime executable to evade detection and establish persistent access. The implant supports multiple communication channels including HTTPS, WebView2, and DNS tunneling, accepts runtime configuration via command-line arguments or Base64 payloads, and stores its settings in a local SQLite database. Once active, it profiles hosts for browsers and security products, captures screenshots, executes commands, handles files and archives, and proxies traffic via SOCKS5, enabling hands-on operations without a separate loader.
read more →

LastPass and Bitwarden Users Targeted by Phishing Alerts

🔔 LastPass warns of an active phishing campaign using fake corporate-style security notices that redirect recipients to fraudulent landing pages impersonating DocuSign. The emails, claiming to announce policy updates, come from addresses like hello@lastpassnewsletter.com and lead to domains such as lastpasscompliance[.]com, which have been flagged as malicious. Bitwarden users have received similar messages from hello@bitwardennewsletter.com redirecting to bitwardencompliance[.]com. LastPass confirms its systems were not breached and urges users to never share their master password and to report suspicious messages to abuse@lastpass.com.
read more →

New phishing kits target Microsoft 365 and evade MFA

🛡️ Two new phishing kits, Jalisco and OmegaLord, are being used to target Microsoft 365 accounts and bypass multi-factor authentication. Jalisco leverages the OAuth 2.0 device-code flow to trick victims into authorizing attacker-controlled devices, while OmegaLord poses as a PDF reader to harvest credentials and phone numbers. Researchers at ReliaQuest analyzed both toolkits and found attackers quickly exfiltrate data from SaaS platforms before demanding extortion. The report recommends tightening device-registration limits and blocking device-code authentication to reduce risk.
read more →

OAuth client ID spoofing exposes cloud sign‑in blind spot

🔒 Proofpoint has identified at least two threat clusters weaponizing a technique called OAuth client ID spoofing to enumerate accounts and validate stolen credentials in Microsoft Entra ID environments while avoiding successful sign‑in telemetry. By supplying spoofed or manipulated client_id values in OAuth token requests—often using the ROPC flow—attackers can cause different AADSTS error responses that reveal whether an account exists and whether a password is correct without recording a successful login. Campaigns such as UNK_pyreq2323 and UNK_OutFlareAZ have used millions of randomized or modified client IDs across thousands of tenants to probe and lock out users, undermining per‑application detections and Conditional Access policies.
read more →