< ciso
brief />
Tag Banner

All news with #breach tag

250 articles

ASOS attributes breach to credential theft via social engineering

πŸ›‘οΈ ASOS confirmed a data breach caused by a social engineering attack in which an employee’s login credentials were stolen and used to access information on third-party platforms. The company locked down affected systems, engaged external experts, law enforcement and regulators, and said payment details and account passwords were not accessed. ASOS warned customers to be wary of unsolicited messages and said no action is required on accounts while the investigation continues.
read more β†’

Chinese-linked Hacker Used AI to Breach Korean Banks

πŸ›‘οΈ CrowdStrike attributes a late-September to early-October campaign to a suspected China-based actor who used open-source agentic tooling ARTEX and Anthropic’s Claude to identify vulnerabilities and exfiltrate data from South Korean financial firms. The attacker hosted ARTEX and Claude Code artifacts on attacker-controlled IPs and supplemented with multiple LLM backends. Victims include Shinhan Bank and Yegaram Savings Bank, prompting a consumer alert from South Korea’s Financial Services Commission.
read more β†’

Wazza phishkit uses multi-stage routing to evade detection

πŸ›‘οΈ ANY.RUN researchers uncovered Wazza, a phishkit targeting banking, manufacturing, and government organizations across the US, Europe, and Australia. The campaign employs a multi-stage routing chain that mints short-lived tokens, validates browser telemetry, and filters visitors before delivering an Adobe-themed Device Code phishing page. This layered delivery complicates automated detection and increases investigation workload for MSSPs. Interactive sandboxing and continuous threat intelligence are presented as operational mitigations.
read more β†’

ASOS confirms breach after hacked app notifications

πŸ“± ASOS confirmed unauthorized access to third-party customer communication platforms after users received push notifications claiming a Snowflake compromise and directing victims to a threat actor's Telegram channel. The retailer says basic personal details such as names and contact information may have been exposed but believes payment card data and account passwords were not impacted. Customers are advised to ignore the malicious in-app alert and not follow the external link.
read more β†’

South Korea probes bank breaches amid AI suspicions

πŸ”Ž South Korea's Financial Services Commission convened an emergency meeting after a string of cyberattacks affected major banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. Authorities confirmed data leaks β€” reportedly affecting tens of thousands of customers β€” and launched on-site investigations while coordinating with KISA and other agencies. Financial firms were ordered to inspect externally accessible systems, tighten access controls, share threat intelligence, and submit security inspection results promptly.
read more β†’

Suspected ShinyHunters Member Reportedly Detained in Jordan

πŸ” Reports indicate a suspected ShinyHunters member known as "Rey" (identified as Saif al-Din Khader) was detained in Jordan and is cooperating with the FBI and international law enforcement. Sources say he is assisting by walking investigators through his devices and communications to help identify other group members. The arrest follows an FBI probe into a claimed ShinyHunters breach of FBI systems and comes after other recent arrests tied to the group.
read more β†’

Frontline Education breach exposes employee data

πŸ” Frontline Education has informed school districts of a data breach after attackers exploited a vulnerability in a third-party application to access its systems and steal employee information. The company identified the issue on August 14, 2026, engaged a cybersecurity firm, remediated the vulnerability, and notified law enforcement. Impacted individuals may include district staff whose Social Security numbers, email addresses, and physical addresses were exposed. Frontline will offer notifications and two years of TransUnion credit monitoring unless a district opts out.
read more β†’

ShinyHunters suspect arrested and probed for murder plots

πŸ” Dutch police arrested a 24-year-old Amsterdam man on September 15 on suspicion of involvement with the ShinyHunters cybercrime group, and investigators say his laptop contained details of two alleged murder plots abroad. Authorities are treating the homicide allegations separately from cybercrime probes and have extended his detention for three months while digital forensic work continues. The suspect, identified by reporting as Pepijn van der Stap, previously served prison time for data theft and later worked as a penetration tester.
read more β†’

Pentagon HR system breach exposes millions' data

πŸ”’ The Pentagon's Defense Manpower Data Center (DMDC) confirmed a breach of its human resources management systems that exposed sensitive personal data. The intrusion, active from October 2025 to July 2026, allowed unauthorized access to PII including Social Security numbers, names, dates of birth, contact details, sex, race, and military personnel information for millions. DMDC said it initiated incident response measures and is offering 12 months of free credit monitoring through IDX; affected individuals must enroll by August 19, 2027.
read more β†’

Automated AI agent breaches Dutch cybersecurity nonprofit

πŸ” The Dutch Institute for Vulnerability Disclosure (DIVD) reported an autonomous, AI-driven intrusion that it described as β€œloud and very, very messy.” Evidence suggests a technical vulnerability was exploited to gain access, after which an automated AI agent carried out post-exploitation actions, often making obvious errors. DIVD has launched an investigation, notified authorities, and will publish further details on October 1 while working to identify and inform other potential victims.
read more β†’

Times Car confirms breach affecting 6.6M accounts

πŸ”’ Times Car disclosed that a cyberattack compromised approximately 6.6 million current and former user accounts after unauthorized access earlier this month. The company identified the intrusion on September 25 and blocked access on September 26 while launching a forensic investigation with external experts. Exposed data reportedly includes names, addresses, contact details, driver’s license and identity document images, account passwords, and linked service IDs, while credit card data appears unaffected.
read more β†’

Dutch police arrest former hacker linked to ShinyHunters

πŸ“° Dutch authorities arrested a 23-year-old convicted cybercriminal, identified by sources as Pepijn van der Stap, on suspicion of aiding the ShinyHunters hacking collective in data thefts and extortion. Van der Stap β€” previously convicted in 2023 and released in December 2025 β€” had presented himself as reformed while working in offensive security. Following his detention, ShinyHunters escalated attacks, claiming breaches of the FBI jobs site and extorting other groups, exploiting a PeopleSoft flaw (CVE-2026-35273). Investigations continue into ties between ShinyHunters, a rival teenage operator known as Rey, and recent large-scale data thefts.
read more β†’

Rydox admin pleads guilty; faces lengthy sentence

πŸ”’ Rydox administrator Ardit Kutleshi pleaded guilty to operating a major illicit marketplace that sold stolen identities, login credentials, credit card data, and cybercrime tools. Arrested in a 2024 international operation that seized the site's domain and servers, Kutleshi was extradited to the U.S. in 2025 and charged with identity theft, money laundering, and related offenses. He faces sentencing in February 2027 and substantial prison time.
read more β†’

Bitget Loses $351.6M in Suspected North Korean Hack

πŸ›‘οΈ Bitget confirmed unauthorized transfers from a limited set of hot wallets on September 24, 2026, resulting in a theft of $351.6 million. The exchange says cold wallets and most platform assets remain secure, deposits and trading continue, but withdrawals are temporarily suspended during a comprehensive security review. Bitget has engaged Mandiant and SlowMist for investigation and reports the pattern aligns with known North Korean threat actors.
read more β†’

Z.ai disables feature after repository uploads exposed

πŸ›‘οΈ Z.ai disabled components of its ZCode coding assistant after researchers discovered a default workflow that silently packaged and uploaded local code repositories to Alibaba Cloud without user consent. The company apologized, removed the feature in the v3.14.0 client, deleted associated cloud storage, and invited external security assessments. Z.ai also opened its codebase for review and asserted the data was not retained or used for model training.
read more β†’

Webinar: Inside Real-World Google Workspace Breaches

πŸ” Tomorrow BleepingComputer hosts a live webinar, "Breach autopsy: How fast-growing companies are breached through Google Workspace," featuring Material Security. Speakers Rajan Kapoor and Rick Fitzgerald will analyze real, publicly documented Google Workspace breaches, focusing on incidents where social engineering and malicious OAuth apps enabled access. The session will cover initial access, the critical first hours of response, and which Google Workspace controls deliver the most value for lean security teams.
read more β†’

ShinyHunters breaches Clop leak site, claims keys

πŸ”’ The ShinyHunters extortion group breached and defaced the Clop (Cl0p) ransomware gang's Tor data leak site after exploiting an alleged unauthenticated file upload flaw in Grav CMS. The attackers uploaded a taunting text file and replaced the site with ASCII art, claiming to have obtained server data, logs, source code, and the onion service's private keys. BleepingComputer confirmed the defacement and file upload but has not independently verified theft of logs or keys, while ShinyHunters says it will extort Clop within 72 hours.
read more β†’

US agencies investigate cyber intrusion on supertanker

🚒 The US Coast Guard and FBI boarded the Liberian-flagged VL Prosperity after indications its network may have been compromised during a voyage from Egypt to Galveston. The alleged intrusion reportedly affected fuel systems, engine speed and communications for about 30 hours before a specialised team spent four days eradicating the threat. Authorities report no injuries or environmental impact while urging stronger cyber hygiene and network segmentation.
read more β†’

Gyazo breach exposes millions of user records

πŸ”’ Helpfeel's image-sharing service Gyazo disclosed a breach that exposed about 23.62 million user records and roughly 490 million image metadata records, mostly from January 2019 or earlier. The attacker exploited a vulnerability in Gyazo's image upload server to run arbitrary commands and access the database; Helpfeel has disabled some image viewing and urged users to change passwords and watch for suspicious messages. The company says no payment data was exposed and external forensics are ongoing.
read more β†’

Florida DMV DAVID Database Breach Confirmed

πŸ›‘οΈ The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a breach of its DAVID driver database after the ShinyHunters extortion group claimed to have compromised the system. The agency says the intrusion involved compromised credentials from a single Plant City Police Department user improperly stored on a personal device and that the incident was quickly mitigated. FLHSMV is coordinating with state authorities and treating the matter as an ongoing criminal investigation.
read more β†’