< ciso
brief />
Incidents and Data Breaches Banner

All news in category “Incidents and Data Breaches

3300 articles · page 63 of 165

AppsFlyer Web SDK Temporarily Hijacked to Steal Crypto

🛡️ The AppsFlyer Web SDK was temporarily hijacked to deliver obfuscated JavaScript that intercepts cryptocurrency wallet inputs and replaces them with attacker-controlled addresses, diverting funds. Profero researchers identified the malicious payload being served from websdk.appsflyer.com between March 9 and March 11. AppsFlyer says the mobile SDK was not affected, the incident has been contained, and an investigation with external forensics is ongoing.
read more →

GlassWorm Escalates via 72 Malicious Open VSX Extensions

🔒 Cybersecurity researchers have identified a significant escalation in the GlassWorm campaign, which has abused at least 72 extensions in the Open VSX registry to target developers, Socket reports. The actor leverages extensionPack and extensionDependencies to turn benign-looking extensions into transitive delivery vehicles that install malicious packages after trust is established. The malicious listings impersonated common developer tools and used heavier obfuscation, invisible Unicode characters, Solana transactions as dead drops, and rotating wallets to evade detection. Open VSX has removed the flagged extensions while vendors and researchers continue their analysis.
read more →

FBI Seeks Victims After Malware-Embedded Games on Steam

🎮 The FBI's Seattle Division is seeking information from gamers who installed Steam titles later found to contain malware between May 2024 and January 2026. Identified titles include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova. The agency's questionnaire targets cryptocurrency theft and account hijacking and requests transaction details, compromised account information, and screenshots of communications to help trace stolen funds and those who distributed the malware.
read more →

Chinese APT Targets Southeast Asian Militaries Since 2020

🛡️ Palo Alto Networks' Unit 42 attributes a China-linked espionage campaign, tracked as CL-STA-1087, to long-running intrusions against Southeast Asian military organizations dating to 2020. The operators used staged loaders, DLL hijacking and sleep-based sandbox evasion to deploy backdoors AppleChris and MemFun, plus a credential stealer named Getpass. Persistent, modular tooling and Pastebin-based dead drops enabled stealthy, long-term access focused on C4I and organizational intelligence.
read more →

Poland's Nuclear Research Centre Foils Cyberattack

🛡️ Poland’s National Centre for Nuclear Research (NCBJ) says its IT infrastructure was targeted by a cyberattack that was detected and blocked before causing any impact. Security systems and internal procedures enabled rapid containment, and the institute reports that the MARIA research reactor was unaffected and continues to operate safely. Authorities have been notified and an investigation is underway.
read more →

Interpol-led Operation Synergia III Nets 94 Arrests Worldwide

🔍 Interpol coordinated Operation Synergia III from 18 July 2025 to 31 January 2026, involving law enforcement units in 72 countries and private partners. The action produced 94 arrests, the seizure of 212 electronic devices and servers, and the takedown of some 45,000 malicious IP addresses, while 110 individuals remain under investigation. The operation targeted phishing, ransomware, romance scams and credit card fraud and disrupted infrastructure used to impersonate banks, government sites and payment services. Private-sector partners including Group-IB, Trend Micro and S2W supplied intelligence that helped identify hosting and malware distribution points.
read more →

INTERPOL Disrupts 45,000 Malicious IPs and Servers

🛡️ INTERPOL announced the takedown of 45,000 malicious IP addresses and servers linked to phishing, malware, and ransomware campaigns across 72 countries. The effort, part of Operation Synergia's third phase, resulted in 94 arrests, 212 devices seized and 110 suspects under investigation. Targeted actions in Bangladesh, Togo and Macau uncovered large fraud rings and over 33,000 phishing sites.
read more →

Storm-2561 Uses SEO Poisoning to Distribute Trojan VPNs

🔒 Microsoft disclosed a credential-theft campaign that uses SEO poisoning to push trojanized VPN clients impersonating legitimate enterprise software. Attackers hosted ZIPs on GitHub containing MSI installers that sideload malicious DLLs and deploy a Hyrax variant, presenting a fake sign-in dialog to harvest VPN credentials. Microsoft removed the repositories and revoked the signing certificate; organizations should enable MFA and verify software sources.
read more →

Global Police Sinkhole 45,000 IPs in Cybercrime Sweep

🔍 An Interpol-led operation, Operation Synergia III, sinkholed tens of thousands of IP addresses and seized servers linked to global cybercrime between July 2025 and January 2026. Authorities from 72 countries made 94 arrests and seized 212 electronic devices, disrupting thousands of phishing and fraud sites including a large 33,000-site network identified in Macau. The action builds on earlier Synergia efforts and highlights the importance of international cooperation and private-sector partnerships to dismantle criminal infrastructures.
read more →

Fake Enterprise VPN Installers Steal Company Credentials

🔒 A threat actor tracked as Storm-2561 is distributing spoofed enterprise VPN clients impersonating vendors such as Ivanti, Cisco, and Fortinet to harvest corporate VPN credentials. The campaign uses SEO poisoning to push victims to convincing fake vendor pages that link to a GitHub-hosted ZIP containing a malicious MSI installer. When run, the installer places a fake Pulse.exe, drops a loader (dwmapi.dll) and a Hyrax infostealer variant (inspector.dll), captures credentials and configuration files, then displays an installation error and redirects victims to the legitimate vendor site to avoid immediate suspicion.
read more →

Law Enforcement Dismantles SocksEscort Proxy Network

🔒Operation Lightning dismantled the malicious proxy service SocksEscort, which investigators say compromised hundreds of thousands of routers and IoT devices globally. The service marketed thousands of proxy endpoints that enabled criminals to hide originating IPs and carry out bank and cryptocurrency account takeovers, fraudulent unemployment claims, ransomware operations, DDoS attacks and distribution of CSAM. Authorities seized domains and servers, froze cryptocurrency assets, and urged users and vendors to regularly update device firmware and apply security patches.
read more →

Storm-2561 Hijacks Search Results to Serve Trojan VPNs

🔍 Microsoft warns that the cybercriminal group Storm-2561 is poisoning search results to distribute trojanized VPN clients that harvest corporate credentials. The campaign redirects victims to digitally signed malware hosted on GitHub and then opens legitimate vendor sites to minimize detection. The installer side-loads malicious DLLs — including a variant of the Hyrax infostealer — to extract VPN credentials and achieve persistence via the RunOnce registry key. Microsoft recommends enforcing multifactor authentication, disabling browser password syncing on managed devices, and running endpoint detection and response in block mode with network and web protections enabled.
read more →

Starbucks Discloses Data Breach Affecting Employees

🔒 Starbucks disclosed a data breach that exposed personal and financial information from Starbucks Partner Central accounts belonging to employees. The company says it discovered unauthorized access on February 6 after threat actors obtained login credentials via websites impersonating Partner Central, compromising 889 accounts. Exposed data may include names, Social Security numbers, dates of birth, and bank account/routing numbers. Starbucks notified law enforcement and is providing two years of Experian identity and credit monitoring to affected partners.
read more →

Authorities Disrupt SocksEscort Proxy Botnet Service

🚨 Authorities dismantled the criminal proxy service SocksEscort, which enslaved thousands of residential routers worldwide to operate a large-scale proxy botnet and sold anonymous access for fraud and other crimes. U.S. and European partners executed a court-authorized disruption, seizing domains and servers and freezing roughly $3.5 million in cryptocurrency. The service relied on AVrecon malware that exploited SOHO router vulnerabilities to persistently infect devices and route traffic for criminal customers.
read more →

Telus Digital Suffers Massive Data Breach by ShinyHunters

🔒 Telus Digital, a BPO provider to global clients, is investigating a significant cybersecurity incident after extortion group ShinyHunters claimed to have exfiltrated up to one petabyte of data. The company says core operations and customer connectivity remain unaffected and that it has engaged leading forensics teams and law enforcement. Early indications point to abuse of legitimate access rather than an obvious malware intrusion, and Telus is notifying affected customers and implementing additional safeguards.
read more →

Suspected China-Linked Espionage Against SE Asian Militaries

🔍 Palo Alto Networks Unit 42 details a persistent espionage campaign, CL-STA-1087, suspected to operate from China and targeting Southeast Asian military organizations. The actors used custom backdoors AppleChris and MemFun, plus a modified credential harvester Getpass, and relied on Pastebin/Dropbox dead-drop resolvers for stealthy C2 resolution. Unit 42 provides IoCs, SHA256 hashes and defensive guidance for Cortex XDR, Advanced WildFire and related protections.
read more →

Loblaw Notifies Customers After Network Data Breach

🔒 Loblaw Companies Limited has detected an intrusion into a contained, non-critical portion of its IT network and confirmed that a criminal third party accessed basic customer information. The exposed data includes names, phone numbers, and email addresses, which could be used for phishing and fraud. Loblaw says there is no evidence that financial information, health data, or account passwords were compromised and that PC Financial has not been impacted. The company has automatically logged customers out, urges users to sign in again and change passwords, and continues to investigate.
read more →

Handala Hack Wiper Attacks Targeting Intune Admins

🔒 Unit 42 warns of elevated risk from destructive wiper operations attributed to the Iranian-linked Handala Hack actor, which has used phishing and compromised Microsoft Intune administrative access to delete servers and devices and disrupt operations. The actor, first seen in late 2023 and also tracked as Void Manticore, COBALT MYSTIQUE and Storm‑1084/0842, is assessed as a state-directed front for Iran’s MOIS. Mitigations focus on eliminating standing privileges (JIT, PIM), hardening Entra ID and Intune admin roles, enforcing conditional access and hardware MFA, reducing session lifetimes and ensuring immutable offline backups.
read more →

England Hockey Probes Alleged AiLock Ransomware Breach

🔒 England Hockey is investigating claims that the AiLock ransomware gang stole approximately 129GB of data and listed the organization on its leak site, threatening to publish files unless a ransom is paid. The governing body says it has prioritized an inquiry involving internal teams, external specialists, and cooperation with law enforcement. England Hockey cannot yet provide specifics while the investigation continues and urges members to remain vigilant for phishing and suspicious account activity.
read more →

AI-Generated Slopoly Backdoor Used in Interlock Attack

🔒 A PowerShell backdoor called Slopoly, likely generated with an LLM, was used in an Interlock ransomware intrusion that allowed attackers to persist on a compromised server for over a week and exfiltrate data. IBM X-Force observed developer-style comments, structured logging, clear variable names, and robust error handling that suggest AI-assisted creation. Deployed to C:\ProgramData\Microsoft\Windows\Runtime\, Slopoly beacons to a C2 endpoint, polls for commands, executes them via cmd.exe, and establishes persistence as a scheduled task.
read more →