< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3296 articles · page 6 of 165

DeadLock ransomware leverages blockchain for resilience

🛡️ Microsoft and security vendors observed DeadLock using decentralized services and an interactive HTML recovery chat to maintain extortion and data-leak operations without traditional backend infrastructure. The group, active since July 2025, uses Session messaging, Polygon smart contracts for proxy rotation, and blockchain-hosted leak content while employing selective encryption, hybrid crypto, and anti-forensic measures. Multiple actors have deployed it and it has claimed nearly 100 victims across Europe and the U.S.
read more →

Wesco Investigates CRM Data Exfiltration Claim

🔍 Wesco is investigating a reported cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen CRM data and published alleged records. The company says it worked with its cloud CRM vendor and found no evidence of ransomware or malware, and believes payment card and sensitive customer or employee data are not at risk. Wesco reported no business disruption and stated operations continue as normal.
read more →

Adform ad platform compromise enabled crypto theft

🛡️ Adform, a major ad-serving platform, was compromised for about 24 hours from late July 26 to the evening of July 27, allowing attackers to inject malicious JavaScript into ads that monitored clipboard contents and swapped copied cryptocurrency wallet addresses with the attacker’s addresses. The injected code collected site and IP data and targeted Bitcoin, Ethereum, and Tron addresses. Adform remediated the issue, and the incident highlights the persistent risk of malvertising and the need for users to block ads and use layered protections. The company has not disclosed how the breach occurred or how many users were affected.
read more →

Researchers Expose North Korean Hiring Subterfuge

🔍 Security researchers created a fake cryptocurrency startup and hired three individuals they suspect were North Korean operatives. Each new hire completed onboarding, received work virtual machines, and performed reconnaissance while their VMs recorded activity. Analysts found image metadata and a Google SynthID watermark on some documents, and traced infrastructure and tooling patterns consistent with prior North Korean campaigns. The team advises stronger, ongoing identity checks, in-person verification for remote-first firms, and network controls to block known VPN services.
read more →

Data Breach Impacts Ceva Logistics Supply Chain

🛡️ Ceva Logistics, part of CMA CGM Group, reported a breach affecting its European contract logistics operations, impacting eight warehouses. The company notified affected customers on August 1 after an incident that reportedly ran from July 29 to August 1. Client data potentially exposed included names, emails, addresses, phone numbers and order details, affecting customers such as Valve, Bol, De Bijenkorf, Ajax and ING. Vendors warn of follow-on phishing and impersonation risks and stress logistics firms are high-value attack targets.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

Valve notifies Steam hardware customers of breach

🔔 Valve is informing Steam hardware customers in Europe that a breach at shipping partner CEVA Logistics exposed delivery-related data. The company says attackers accessed CEVA systems between July 29 and August 1, 2026, and likely obtained names, addresses, phone numbers, emails, and order details. Valve clarified that payment, passwords, and Steam Guard codes were not exposed and warned customers to watch for phishing attempts using the stolen information.
read more →

Metabase zero-day exploited; urgent patches advised

🔒 Metabase disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) affecting versions from x.58.0 through x.63.x that has been actively exploited in the wild. The flaw allows unauthenticated SQL injection into the application database, enabling attackers to gain administrator access, alter configurations, steal stored database credentials, and exfiltrate data. Metabase Cloud has been patched; self-hosted users must apply updates immediately or block the "/api/session/reset_password" endpoint as an interim mitigation.
read more →

Unlimited Technology Systems Exposes 3.8M Records

🛡️ Unlimited Technology Systems disclosed a data breach affecting 3,803,750 individuals after a server compromise in October 2025. The company, which provides financial and revenue cycle software to specialty healthcare providers, discovered unauthorized access between October 5 and October 10 and notified authorities and patients in July 2026. Affected data may include names, SSNs, dates of birth, contact details, scanned IDs, insurance information, medical records, and diagnosis details. Affected patients were offered identity monitoring through Kroll.
read more →

UNC6671 vishing extortion targets enterprise identities

🔎 Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employees’ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

North Carolina ports confirm disruptive cyberattack

🔒 The North Carolina Ports Authority confirmed a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The incident was detected on August 4, with recovery actions initiated August 5 and gates operating on a normal schedule by August 7. The authority has not attributed the incident to any threat actor or confirmed data theft, and some delays continue as systems are restored.
read more →

Snowflake attacker pleads guilty in mass data hacks

🔒 A Canadian hacker has pleaded guilty to participating in a group that compromised logins and breached a US cloud data warehouse, impacting 165 organizations and resulting in theft of customer records and multimillion-dollar extortion. Identified as Connor Riley Moucka, he worked with two co-conspirators and is linked to intrusions affecting companies such as AT&T, Ticketmaster and Neiman Marcus. The coordinated investigation involved the FBI and international law enforcement partners and led to guilty pleas and arrests tied to the Snowflake-focused campaign.
read more →

Beacon CRM Breach Impacts Around 1,500 UK Charities

🔒 Around 1500 UK charities may have had personal data accessed after a cyber incident at CRM provider Beacon. The provider says customers should assume all stored data, including attachments, was likely downloaded and has notified all affected organisations. Beacon attributes the breach to a compromised access key, is working with external experts to investigate and has contained the incident, while advising charities on reporting and payment safety steps.
read more →

Microsoft 365 AitM Phishing Targets Payroll Workflows

🔍 Arctic Wolf Labs warns of a widespread email-driven phishing campaign using adversary-in-the-middle (AitM) techniques to seize Microsoft 365 sessions and harvest payroll and HR email. The campaign leverages residential proxies, multi-step redirections through trusted services, and fingerprinting scripts to evade filters and maintain compromised sessions at roughly eight-hour intervals. Affected sectors include healthcare, education, manufacturing, government, and professional services across the U.S., Canada, and Europe.
read more →

Python package supply-chain risks for AI development

🛡️ On March 24, 2026, widely used Python package LiteLLM was compromised on PyPI, delivering a .pth-based payload that auto-executed on interpreter start. The threat actor group TeamPCP pushed malicious versions that harvested cloud tokens, SSH keys and other secrets, and poisoned packages were available for roughly three hours. The incident is part of a broader rise in malicious open-source packages and highlights unique risks in AI development environments where dependencies can expose models, data and multi-cloud credentials.
read more →

ClickFix macOS infostealer targets crypto and credentials

🛡️ A Go-based malware delivered via a ClickFix campaign targets macOS users to steal cryptocurrency, browser passwords, Apple Keychain data, and cached credentials. Researchers at Huntress found the attack uses a Bash profiler and Mach-O payload tailored to the victim’s CPU, persists by faking errors with osascript, and removes quarantine flags to bypass Gatekeeper. The malware can intercept and divert crypto transactions and selectively drain a percentage of funds.
read more →

Canadian Hacker Pleads Guilty in Snowflake Extortion Case

🛡️ Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting more than 165 Snowflake customers and stealing AT&T call and text metadata for over 100 million users. Authorities say the conspirators used stolen credentials where multi-factor authentication was not enforced, exfiltrated terabytes of sensitive data, and extorted victims for ransom. Moucka admitted to threatening officials and security researchers and faces significant prison time at his October sentencing.
read more →

Post‑exploitation toolkit embedded inside Oracle DB

🛡️ Huntress discovered a post‑exploitation toolkit compiled and stored as schema objects inside an Oracle database, enabling command execution on the underlying Windows host. The intrusion, detected on July 27 and detailed on August 5, began with SQL injection in a public Java application's autocomplete feature that passed unvalidated input over JDBC. Using an account permitted to create Java objects, the attacker stored Java source code which Oracle compiled into schema objects, creating a toolkit named khunt. Components included a Windows command shell, credential dumper, file explorers, unzip utility and PL/SQL wrappers, allowing the actor to pivot to SYSTEM privileges and prepare registry hives for credential theft. Huntress highlighted detection gaps because endpoint tools typically do not inspect Java classes and PL/SQL objects inside databases, turning the DB into an operational foothold; they recommended input sanitization, parameterized queries and least‑privilege for query‑capable accounts.
read more →

UNC6671 Targets Financial and Cloud Environments

🔎 GTIG reports UNC6671 continues active compromises and data-theft extortion despite the alleged BlackFile retirement, diversifying into Redact, Pink, Helix, and Falcon. The actor uses targeted voice phishing (vishing) to lure employees—often on personal phones—to spoofed login portals with AiTM infrastructure to harvest credentials and MFA tokens, then deploys scripts to exfiltrate data from enterprise cloud apps like Microsoft 365 and Okta. The update details infrastructure linkages, evolving targeting focused on financial services and private equity, and offers hardening guidance to mitigate these identity-centric threats.
read more →