< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches”

3607 articles · page 2 of 181

Ransomware Causes Outage at IDCF Cloud in Japan

🔒 IDCF Cloud, operated by IDC Frontier (a SoftBank subsidiary), suffered a ransomware attack on October 7 that forced the shutdown of East Japan Region 1 and disrupted services for 495 corporate and government customers. The company isolated affected systems, disabled customer management console access across regions, and is investigating the intrusion route and full scope. Threat actor screenshots claim extensive encryption and deletion of databases, hypervisors, VM disks, and snapshots, while investigations continue.
read more →

UAC-0099 Deploys ASHVEIN .NET Infostealer Against Ukraine

🛡️ TrendAI attributes a previously undocumented .NET infostealer and RAT named ASHVEIN (aka TelemetryBrowser) to the Russia-aligned actor UAC-0099, used in operations targeting Ukrainian government personnel. The malware combines credential theft from Chrome and Firefox, GDI-based screenshots, file collection, PowerShell remote shells, system fingerprinting, and encrypted C2 communications, with delivery via DLL sideloading, VHD containers, and .NET droppers. UAC-0099 has evolved from PowerShell- and Go-based tools to C# and .NET-protected binaries and has expanded targeting to logistics and civilian infrastructure.
read more →

AI-powered pentest tool exploited in Korean data theft

🛡️ CrowdStrike detailed a targeted campaign against South Korean financial organizations that used the open-source agentic pentesting tool ARTEX alongside multiple LLMs to exfiltrate data between late September and early October 2026. Researchers discovered exposed Claude Code sessions, memory files, and ARTEX configs on a Hong Kong-hosted IP, linking the operation to an ARTEX instance using DeepSeek v4.1-flash and supplementary models. The activity is unattributed but points to a suspected Chinese-speaking, financially motivated operator; Autumn-27 has since closed ARTEX's source citing abuse.
read more →

Uranium Finance hacker convicted for $53M theft

🛡️ A Maryland man was convicted after hacking the decentralized exchange Uranium Finance twice in April 2021, stealing more than $53 million in cryptocurrency. Jonathan Spalletta (aka "Jspalletta" and "Cthulhon") exploited smart contract flaws to drain liquidity pools and launder funds through Tornado Cash and DEXs. Law enforcement recovered about $31 million and seized high‑value collectibles bought with the proceeds, and Spalletta faces lengthy prison sentences for computer fraud and money laundering.
read more →

AWS Agent Security Issues Highlight Autonomous Agent Risks

🔒 Researchers from Palo Alto Networks’ Unit 42 and Zenity Labs detail repeated security regressions in AWS AgentCore and AgentCore Runtime, where default tools and misconfigured metadata access allowed prompt-injection and IMDS-based credential exfiltration. Reports show agents can return full STS credentials, move laterally, and access other agents’ code and secrets, exposing broad blast radius risks. AWS has issued fixes, but timelines and completeness remain unclear, underscoring the difficulty of securing autonomous agents.
read more →

ASOS attributes breach to credential theft via social engineering

🛡️ ASOS confirmed a data breach caused by a social engineering attack in which an employee’s login credentials were stolen and used to access information on third-party platforms. The company locked down affected systems, engaged external experts, law enforcement and regulators, and said payment details and account passwords were not accessed. ASOS warned customers to be wary of unsolicited messages and said no action is required on accounts while the investigation continues.
read more →

Chinese-linked Hacker Used AI to Breach Korean Banks

🛡️ CrowdStrike attributes a late-September to early-October campaign to a suspected China-based actor who used open-source agentic tooling ARTEX and Anthropic’s Claude to identify vulnerabilities and exfiltrate data from South Korean financial firms. The attacker hosted ARTEX and Claude Code artifacts on attacker-controlled IPs and supplemented with multiple LLM backends. Victims include Shinhan Bank and Yegaram Savings Bank, prompting a consumer alert from South Korea’s Financial Services Commission.
read more →

Wazza phishkit uses multi-stage routing to evade detection

🛡️ ANY.RUN researchers uncovered Wazza, a phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign employs a multi-stage routing chain that mints short-lived tokens, validates browser telemetry, and filters visitors before delivering an Adobe-themed Device Code phishing page. This layered delivery complicates automated detection and increases investigation workload for MSSPs. Interactive sandboxing and continuous threat intelligence are presented as operational mitigations.
read more →

Operator of Empire Market Sentenced to 40 Years

🔒 The co-creator and operator of Empire Market, a major dark web marketplace, was sentenced to 40 years in prison for facilitating roughly $430 million in illicit transactions between 2018 and 2020. Operating as a TOR hidden service and modeled after AlphaBay, the site handled over 4 million transactions and primarily trafficked controlled substances. Authorities seized substantial cryptocurrency and assets tied to the operation, and the operator admitted to using encryption and tumblers to evade law enforcement.
read more →

AI‑Assisted AitM Spear‑Phishing Targeting Taiwan

🛡️ Talos observed a mid‑2026 spear‑phishing campaign targeting Taiwan research institutions that used plausible event details and deceptive links. The emails used a reusable, formulaic template with personalized flattery and impersonated legitimate organizations while hiding actor‑controlled registration pages. Malicious posters included altered QR codes to expand the attack surface. The phishing kit replicated Google sign‑in pages across locales and used obfuscated JavaScript, HTTP POST exfiltration, and WebSocket C2 to perform real‑time AitM credential harvesting.
read more →

FBI and Secret Service Warn of Ongoing FortiBleed

🔒 The FBI and US Secret Service warned administrators to harden Fortinet FortiGate firewalls and SSL VPN gateways after reporting the persistent FortiBleed campaign. Agencies cited SOCRadar data indicating 86,644 compromised devices across 194 countries and linked ransomware affiliates to use of stolen credentials. The notice details attacker techniques including credential stuffing, GPU-accelerated cracking, and creation of administrative accounts to maintain stealthy persistence. Organizations are urged to isolate affected hosts, perform threat hunting, reset credentials, enable phishing-resistant MFA, and follow CISA eviction guidance.
read more →

MonsterCloud Owner Accused of Defrauding Ransomware Victims

🛡️ The U.S. Department of Justice charged Zohar Pinhasi, owner of MonsterCloud, with wire fraud and conspiracy for allegedly paying ransomware actors to obtain decryptors while falsely claiming proprietary decryption tools. He is accused of billing clients far more than the ransoms he secretly paid and collecting over $19 million in fees while paying more than $8 million to criminals. Authorities say his actions re-victimized clients and could carry lengthy prison terms.
read more →

Tensorlake npm Package Compromised in ChainDrop Attack

🔒 The npm package tensorlake, a TypeScript SDK for Tensorlake applications and cloud services, was compromised in a ChainDrop / Shai-Hulud supply chain attack after a malicious 0.5.144 release was published. The trojanized release used a preinstall hook and an obfuscated Bun-based loader to deploy a credential-stealing worm that harvests secrets, drops additional malware, establishes persistence, and enables remote code execution. Affected users are urged to remove the package and rotate exposed credentials.
read more →

Denmark reviews national ID system after breach

🔒 Danish authorities are examining security controls after attackers used a company's credentials to query the national citizen registry and retrieve records for roughly 8.8 million people over a 10-day span. The incident, discovered on Oct. 2, involved more than 14 million searches and affected residents, deceased individuals, and those living abroad, though protected identities were spared. The vendor's access has been revoked and the National Special Crime Unit is investigating while officials warn of fraud risks and urge stronger identity checks.
read more →

Telegram Account Linked to ASOS Notification Incident

🔍 Group-IB found the Telegram account tied to the October 6 ASOS notification was previously active in gaming-item trading communities and used multiple aliases. Investigators say the channel was created the same day and have not found evidence that ASOS customer data was dumped or that Snowflake was compromised. ASOS confirmed possible access to basic contact details, restricted notification-platform access, and is working with advisers and authorities while customers are urged to remain vigilant.
read more →

Encrypted instructions make Copilot CLI leak secrets

🔐 Security researchers at Adversa AI disclosed a technique called Cryptographic Context Injection (CCI) that embeds malicious instructions inside encrypted content to influence GitHub Copilot CLI. When Copilot decrypts and executes that content in autopilot mode, it can be tricked into reading local secret files and exfiltrating them to an attacker-controlled endpoint. GitHub validated the behavior but declined to classify it as a vulnerability, citing user authorization and autonomous mode, while Adversa disputes that assessment.
read more →

Musician sentenced for $10M AI-driven streaming fraud

🎵 A North Carolina musician was sentenced to 18 months in prison after admitting to a scheme that generated over $10 million in royalties by using AI-generated tracks and automated bots to inflate streams on major platforms. With accomplices, he uploaded hundreds of thousands of synthetic songs and routed bot traffic through VPNs to avoid detection, producing billions of streams between 2017 and 2024. He was also ordered to forfeit more than $8 million and serve two years of supervised release.
read more →

Advantest Confirms Personal Data Stolen in Breach

🔒 Advantest Corporation disclosed that a February 15 ransomware intrusion led to unauthorized access and data extraction from its systems. In an October 6, 2026 notification the company confirmed that personally identifiable information (PII) was among the files taken, including contact details, government ID numbers, financial and medical records. Advantest offers affected parties 18 months of free identity and credit monitoring through Kroll and urges increased vigilance against fraud and phishing.
read more →

Brand-deal scam targeting YouTube creators exposed

📧 This article describes a modular phishing campaign that impersonates brands to trick YouTube creators into surrendering Google account access. The attackers start with personalized collaboration emails, direct victims to convincing fake platforms, and then present a Google sign-in or permissions prompt to capture credentials or obtain channel-management rights. Creators are advised to verify offers, check domains and permissions, use strong authentication, and follow recovery steps if compromised.
read more →

Stored XSS in WordPress plugins leads to site takeovers

🛡️ Researchers observed threat actors exploiting stored cross-site scripting (XSS) flaws in two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create hidden admin accounts. Both high-severity issues require an authenticated session and are tracked as CVE-2026-94504 and CVE-2026-93836. The campaign delivered identical JavaScript from imgcdn1[.]com to plant a malicious plugin and establish multiple persistence mechanisms, including a secret login URL and a concealed administrator account.
read more →