< ciso
brief />
Tag Banner

All news with #insider threat tag

146 articles

Risk-First CISO Approach to Prioritizing AI Risks

🔒 AI gives defenders powerful discovery tools but grants attackers the same advantages, forcing CISOs to manage AI risks both externally and internally. External threats include AI-enhanced phishing, rapid exploit development, and autonomous agent attacks, while internal risks arise from uncontrolled employee use of consumer AI platforms, shared copilots, and compromised API billing. The author advocates a Risk-First approach: map AI use, prioritize controls like RBAC and data classification, improve continuous testing, and run tabletop exercises to prepare for AI-specific failures.
read more →

Data Analyst Sentenced for Extortion Using Stolen Payroll Data

📰 A contract data analyst misused privileged access to steal sensitive corporate and payroll records after learning his contract would not be renewed. Adopting the alias "Loot," he sent over 60 extortion emails demanding $2.5 million in cryptocurrency and attached screenshots of employee personal data to pressure his employer. Forensic evidence and metadata tied the emails and a Coinbase payment trail to the analyst, leading to his arrest, conviction on six counts of transmitting interstate communications with intent to extort, and a 24-month federal prison sentence.
read more →

Data analyst jailed for $2.5M extortion scheme

🛡️ A former Brightly Software contractor was sentenced to two years in prison after pleading guilty to orchestrating a $2.5 million extortion scheme. He stole payroll and corporate data, emailed employees threatening to leak PII, and demanded ransom in cryptocurrency after his contract ended. Brightly paid a small Bitcoin ransom before involving law enforcement; the FBI recovered devices linking the suspect to the crimes.
read more →

North Korean remote hires evade standard security checks

🛡️ Researchers investigated suspected North Korean IT operatives who applied for and secured remote developer roles, revealing forged identities, VPN/VPS infrastructure, and AI-assisted workflows. The FBI is probing a case where a suspected DPRK worker reportedly accessed a U.S. federal agency. The report highlights hiring-stage inconsistencies—document anomalies, interview behavior, and location mismatches—as key warning signs requiring deeper verification and sandboxed validation.
read more →

Researchers Expose North Korean Hiring Subterfuge

🔍 Security researchers created a fake cryptocurrency startup and hired three individuals they suspect were North Korean operatives. Each new hire completed onboarding, received work virtual machines, and performed reconnaissance while their VMs recorded activity. Analysts found image metadata and a Google SynthID watermark on some documents, and traced infrastructure and tooling patterns consistent with prior North Korean campaigns. The team advises stronger, ongoing identity checks, in-person verification for remote-first firms, and network controls to block known VPN services.
read more →

Unlimited Technology Systems Exposes 3.8M Records

🛡️ Unlimited Technology Systems disclosed a data breach affecting 3,803,750 individuals after a server compromise in October 2025. The company, which provides financial and revenue cycle software to specialty healthcare providers, discovered unauthorized access between October 5 and October 10 and notified authorities and patients in July 2026. Affected data may include names, SSNs, dates of birth, contact details, scanned IDs, insurance information, medical records, and diagnosis details. Affected patients were offered identity monitoring through Kroll.
read more →

KT fined for security failures after customer fraud

🔒 South Korea’s largest telco, KT, was fined after security lapses allowed attackers to exploit a stolen femtocell and conduct fraudulent micropayments. The PIPC found that long-lived certificates, unrestricted femtocell IP access and weak internal controls enabled the intrusion, exposing PII for 16,647 users and defrauding 368 customers. Investigators also discovered malware infections on internal servers and criticized KT for delayed reporting and log deletions.
read more →

AgentForger shows AI agents as persistent insider threats

🔒 Zenity Labs disclosed AgentForger, a phishing-based technique that creates autonomous AI agents inside OpenAI Workspaces that can access Outlook, Slack, SharePoint, Google Drive and more. Once installed by a single click, the agent can toggle approvals to act without human prompts, run on schedules, accept attacker task emails, harvest data and impersonate users. OpenAI patched the flaw quickly, but the finding highlights broader risks as agents gain autonomy and integration into enterprise workflows.
read more →

Synthetic Machine Identity Fraud and Emerging Risks

🔒 Synthetic identity fraud for machines involves attackers fabricating service accounts or credentials rather than stealing existing ones. These fabricated NHIs blend real environmental attributes with fake data to appear legitimate, evading detection because no human owner flags misuse. Techniques include rogue service accounts, DCShadow-style fake domain authorities, and shadow credentials implanted into existing objects. Defenses focus on ownership, secrets rotation, least privilege, and continuous behavioral verification.
read more →

How enterprise GenAI can amplify ransomware risk

🛡️ Generative AI is increasingly embedded in business workflows as assistants and agents that access documents, apps, and identities. While AI promises productivity gains, it can amplify existing ransomware tactics by accelerating reconnaissance, credential abuse, and data theft when compromised. The article outlines two threat models—attackers using AI and organizations deploying AI—and recommends governance, least privilege, monitoring, and human approval for high-risk actions.
read more →

Craneware reports file-name data theft incident

🛡️ Craneware disclosed a cyber incident on July 20 after unauthorized access to parts of its data environment resulted in the exfiltration of a significant volume of file names. The firm said much of the data was non-sensitive or public regulatory material, but admitted some employee, customer and partner records were also accessed. No customer service disruption occurred; regulators in the UK and US have been notified and the company is working to identify affected parties.
read more →

Abbott investigates dual cybersecurity incidents amid claims

🔍 Abbott Laboratories is probing two separate cybersecurity incidents after confirming unauthorized access to legacy Exact Sciences systems within its Cancer Diagnostics business and investigating a separate claim of a breach of its LabCentral portal. The company says the Cancer Diagnostics intrusion does not affect operations, products, manufacturing, or patient services and that legacy systems are separate from Abbott's main environment. Abbott engaged incident response teams, notified law enforcement, and does not expect a material business impact. The extortion gang ShinyHunters and another actor, ShadowByt3$, each claim to have exfiltrated different sets of data, though Abbott disputes some characterizations.
read more →

Sentencing in TfL cyber-attack highlights motive

🔒 Two young men were sentenced to five years and six months each for an unauthorised cyber-attack against Transport for London (TfL) after pleading guilty under the UK Computer Misuse Act. The judge found motives included "selfish bravado" alongside other factors, and noted their high expertise despite youth and neurodiversity. The attack, linked to group Scattered Spider, caused widespread service and data disruption affecting millions and significant financial losses.
read more →

Ransomware Negotiator Betrays Victims, Sentenced

🔒 A trusted ransomware negotiator secretly aided the BlackCat/ALPHV gang, sharing victims' insurance limits and negotiation strategies in exchange for cuts of ransom payments. Angelo John Martino III, a DigitalMint negotiator, funneled sensitive negotiation details through a hidden panel to attackers, inflating ransoms and enabling multimillion-dollar payouts. He and accomplices also acted as affiliates, deploying ransomware and siphoning proceeds; authorities seized assets and secured convictions and prison sentences.
read more →

CISOs Warn Executives Lack Understanding of Cyber Risk

🔒 A MetaCompliance report (July 9) based on responses from over 200 European CISOs finds 78% believe C-level executives do not fully grasp cybersecurity risks tied to employee behaviour. The survey highlights fading leadership support for security awareness, with 79% saying backing wanes over time and 40% worried employees share sensitive data with generative AI tools. AI-driven social engineering is cited as a key factor eroding confidence in organisational cyber resilience.
read more →

INTERPOL-led Operation First Light nets global arrests

🕵️ Law enforcement agencies coordinated Operation First Light 2026 across 97 countries, arresting 5,811 suspects and seizing $293 million in illicit assets. The operation targeted social engineering fraud — including BEC, sextortion, impersonation, romance, and investment scams — and associated money laundering between January 15 and April 30. Authorities identified over 142,000 victims, blocked 31,014 bank accounts, and analyzed 152,808 cases while additional suspects were identified. INTERPOL coordinated the effort with regional policing bodies and funding support from China's Ministry of Public Security.
read more →

Critical Dialogflow CX 'Rogue Agent' code execution flaw

🛡️ A critical flaw in Google Dialogflow CX's Code Blocks could let an attacker with edit rights on one agent compromise other Code Block-enabled agents in the same Google Cloud project. Varonis named the issue Rogue Agent; it required the dialogflow.playbooks.update permission and thus implied a malicious insider or compromised developer account rather than an unauthenticated internet attacker. Google fixed the vulnerability after Varonis disclosed it via the VRP; there are no signs of exploitation.
read more →

Kubota reports month-long network intrusion affecting employees

🔒 Kubota North America disclosed that a threat actor accessed parts of its network from March 16 to April 20, exposing personal data for employees and dependents. The company says exposed information may include names, Social Security numbers, dates of birth, tax IDs, driver’s license numbers, bank account and corporate card details, and limited benefits claims. Notifications were sent starting June 30 with instructions to enroll in Kroll identity protection and guidance to monitor accounts; Kubota has enacted additional security measures and has not reported business disruptions.
read more →

Cyber Risks and Privacy Threats Around World Cup 2026

🛡️ The 2026 FIFA World Cup presents an unprecedented cyberattack surface across three host countries, with illegal streaming and black-market gambling exposing viewers to significant risks. UpGuard researchers found publicly exposed log systems containing plain-text credentials, IP addresses, and betting details tied to pirate streams and offshore bookmakers. Law enforcement and international operations are disrupting many servers, but resilient criminal networks continue to adapt and monetize audiences via unregulated gambling.
read more →

Meta pauses employee monitoring program after failures

🛑 Meta has frozen its Model Compatibility Initiative (MCI) after employees reportedly bypassed guardrails and accessed sensitive internal data, then did so again after an attempted fix. The program collected inputs like keystrokes, mouse movements, clicks, and screen content to train AI, and employees were initially not allowed to opt out. Meta says it found unauthorized access on June 18 and paused MCI while investigating, asserting no indication yet of improper access beyond what was reported. Analysts criticized inadequate protections and insufficient risk tagging for highly sensitive non-PII telemetry.
read more →