< ciso
brief />
Tag Banner

All news with #credential stuffing tag

94 articles

North Korean job fraud expands beyond IT roles

🛡️ Researchers report DPRK-linked operators have broadened their employment fraud beyond IT into sales, marketing, and healthcare, using stolen and forged identities, VPNs, and proxy services to secure remote jobs at global firms. Investigations found evidence of PiKVM and USB capture hardware, synthetic personas aided by AI, and coordination via multi-account tools and facilitators who provision laptop farms. Agencies and firms are urged to strengthen identity verification and background checks to detect these sophisticated schemes.
read more →

Android NFC Relay Malware and SpyNote Abuse Report

🛡️ A new Android attack blends SpyNote RAT with a novel NFC relay malware called WindRelay to steal card data and enable fraud. Attackers socially engineer victims over the phone to sideload a malicious app, grant Accessibility and NFC permissions, and relay live card transactions. Group-IB found multiple WindRelay samples targeting Central Europe and warns users to avoid APKs outside official stores and verify bank calls.
read more →

Ransom Cartel founder sentenced to 16 years

🔒 A federal judge sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, a ransomware-as-a-service operation active from 2021 to 2023. The group attacked at least 18 companies across the U.S. and abroad, using stolen credentials from initial access brokers, a hidden affiliate panel, and cryptocurrency mixers to process ransoms. The sentence follows an indictment unsealed in 2024 and a separate unresolved prosecution in New Jersey.
read more →

Phishing campaign installs ScreenConnect via fake audit

🛡️ Proofpoint has identified a phishing campaign impersonating COLDCARD that lures victims with a bogus "Hardware audit" notice tied to a recent wallet vulnerability and large Bitcoin theft. The scam directs targets to a clone site that downloads a batch file which escalates privileges, decodes embedded files, and installs a signed decoy plus a ConnectWise ScreenConnect remote access tool. Once connected to the actor-controlled ScreenConnect server, attackers can remotely access systems, steal data or cryptocurrency, and deploy additional malware or ransomware.
read more →

Fake Xeno script launcher infects Roblox players

🛡️ Bitdefender identified malicious installers posing as the Xeno Executor Roblox utility that deliver a multi-stage Java-based loader and a final RAT/infostealer. The campaign, active since early this year and spiking in March, lures gamers via forums, Discord, and compromised accounts with archives mimicking legitimate Xeno installations. Once executed, the malware extracts a Java runtime, registers victims with a C2, and deploys payloads that steal browsers, wallets, and account tokens while enabling surveillance and remote control.
read more →

Old BMC Vulnerability Exposes Data Center Management

🔒 Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more →

Chick‑fil‑A reports credential stuffing breach

🔐 Chick‑fil‑A confirmed that more than 13,000 customers were impacted by credential stuffing attacks targeting its website and mobile app between June 17 and June 19. The attackers used credentials obtained from a third‑party source and accessed names, emails, membership numbers, Chick‑fil‑A credit amounts, mobile pay numbers, and card last four digits; some accounts may have also exposed birth dates, phone numbers, and addresses. The company logged out affected accounts, removed payment methods, restored balances, added rewards, and urged users to change passwords.
read more →

23andMe Agrees $18M Settlement and New Security Terms

🔒 A coalition of 42 US attorneys general has secured an $18m settlement with genetic testing firm 23andMe following the 2023 credential-stuffing breach that exposed profile and ancestry data for over six million individuals. The settlement, led by New York Attorney General Letitia James, includes more than $705,000 payable to New York and imposes new data protection requirements on the company and its successor. As 23andMe entered bankruptcy in March 2025, its customer data was transferred to TTAM Research; the agreement mandates risk analysis, an advisory board on data security, and continued consumer deletion rights to safeguard that information.
read more →

Search for Clean Residential Proxies in Carding

🔍 Flare researchers examined nearly 2,900 underground posts to map how carders assess residential proxies and build fraud-ready digital identities. The analysis shows proxies are judged by reputation and history rather than just being residential, and are commonly paired with antidetect browsers, device fingerprints, and billing consistency. Providers’ restrictions and takedowns have pushed demand for “finance-compatible” IPs and increased operational complexity for attackers.
read more →

23andMe to Pay $18M After Massive Genetic Data Breach

🔒 A coalition of 43 state attorneys general reached an $18 million settlement with 23andMe (now Chrome Holding Co.) over a 2023 data breach that exposed genetic data of 6.9 million customers. Investigators found the company lacked basic protections against credential-stuffing attacks, including multifactor authentication, password blocklisting, and adequate monitoring. The settlement imposes new security requirements, governance measures, and preserves consumer deletion rights while following prior lawsuits and fines.
read more →

INTERPOL-led Operation First Light nets global arrests

🕵️ Law enforcement agencies coordinated Operation First Light 2026 across 97 countries, arresting 5,811 suspects and seizing $293 million in illicit assets. The operation targeted social engineering fraud — including BEC, sextortion, impersonation, romance, and investment scams — and associated money laundering between January 15 and April 30. Authorities identified over 142,000 victims, blocked 31,014 bank accounts, and analyzed 152,808 cases while additional suspects were identified. INTERPOL coordinated the effort with regional policing bodies and funding support from China's Ministry of Public Security.
read more →

Phishing campaign abused Facebook verification claims

🔒 Cybercriminals abused Facebook Messenger chatbots to deliver phishing messages that appeared to come from legitimate Facebook Business accounts. The campaign, active from November 2025 until June 2026, coaxed victims to log in on fake pages and surrender credentials, MFA codes, contact details and images of government IDs. Meta disrupted the infrastructure after Huntress reported the activity, but business accounts remain attractive targets.
read more →

KDDI breach may expose millions of ISP email logins

📧 KDDI Corporation disclosed a breach affecting an email system shared with five Japanese ISPs after discovering unauthorized access on June 17. The company attributes the intrusion to a vulnerability in unnamed third-party software and says it immediately blocked the attacker and implemented defenses. Up to 14.22 million current, former, and inactive customer email addresses and passwords may have been exposed, though some credentials were stored hashed or encrypted. KDDI is notifying regulators and working with affected ISPs while advising customers to reset passwords and enable 2FA where possible.
read more →

Shop app abused to deliver callback phishing scams

🛒 Researchers warn that threat actors are abusing Shop, Shopify’s order-tracking app, by adding fake purchase receipts to users' histories to trick them into calling scam phone numbers. Fraudulent receipts impersonate brands like Apple, PayPal, Norton, and McAfee, and aim to collect credentials, payment details, OTPs, or persuade victims to install remote access software. Users are advised to verify charges with their bank rather than call numbers on suspicious receipts.
read more →

KDDI Breach Exposes Millions of Japanese Email Accounts

📧 KDDI has confirmed an unauthorized intrusion into an email system it provides to several Japanese ISPs, potentially exposing up to 14.22 million email addresses and passwords. The incident, detected on June 17, affected customers across multiple providers, including JCOM, Nifty, Biglobe and others. KDDI said the attacker likely exploited a vulnerability in third-party software and has implemented technical countermeasures. The company is collaborating with affected ISPs and authorities and has urged users to change their passwords.
read more →

Search-Your-Target Market for Stolen Credentials

🔎 Flare analyzed 470 underground forum posts from January 2025 to June 2026 revealing a growing service layer that lets buyers query massive infostealer-derived credential collections for specific companies, platforms, domains, geographies, or account types. These sellers act as brokers, offering search, deduplication, formatting, and targeted delivery of credentials from databases claiming billions of records. Buyer feedback highlights gaps in quality, freshness, and validity, while the market partially overlaps with Initial Access Brokers and amplifies account takeover risks.
read more →

CISA Warns Fortinet Customers Amid FortiBleed Campaign

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure FortiGate appliances after a large-scale campaign, dubbed FortiBleed, compromised 86,644 devices as of June 19, 2026. The campaign, attributed to Russian-speaking actors, used mass scanning and credential spraying against internet-facing VPN and firewall endpoints, leveraging leaked and reused credentials. Telecom, government, and education sectors were heavily affected, prompting guidance to reset passwords, enable MFA, and move to PBKDF2 hashing for admin credentials.
read more →

Prime Day 2026: Surge in Amazon-Themed Scams

🛡️ Check Point Research warns that Amazon Prime Day (June 23–26, 2026) is generating a large pre-event surge in phishing, fake storefronts, and domain-squatting operations. Between December 2025 and May 2026, thousands of Amazon-themed domains were registered, with many already flagged as malicious. Attackers are building multi-TLD campaigns, regional IDN spoofs, and convincing counterfeit product pages to steal credentials and payments.
read more →

World Cup 2026 Scams: Watch for Fake Streams

⚠️ Scammers are exploiting World Cup hype with fake streaming sites, fraudulent betting platforms, and counterfeit merchandise stores that harvest payments and personal data. Many sites demand extensive personal information or up-front payments, sometimes even in cryptocurrency, and use professional-looking pages to trick victims. Fans and bettors risk losing money and having credentials reused across accounts stolen; strong security measures and unique passwords are advised.
read more →

FortiBleed leak exposes Fortinet VPN credentials

🔒 A newly discovered data leak called FortiBleed appears to expose Fortinet and FortiGate VPN credentials for 73,932 firewall URLs worldwide. Researcher Bob Diachenko discovered a server containing usernames, emails, and plaintext passwords and linked the collection to a Russian-speaking multi-operator group that performed massive credential harvesting and cracking. Hudson Rock and other researchers validated the dataset, noting impacts across many industries and countries, and urged affected organizations to rotate credentials and enforce MFA.
read more →