Topic: data extortion

  • SickKids data breach: Employee and applicant info exposed

    SickKids data breach: Employee and applicant info exposed

    SickKids Hospital in Toronto confirmed a cybersecurity breach that exposed personal data of current and former staff, job applicants, and affiliated foundation personnel, originating from a vulnerability in a third-party vendor's product; patient care and medical records were not compromised. The...

    Read More »
  • How AI Made Two-Thirds of Ransomware Attacks Worse

    How AI Made Two-Thirds of Ransomware Attacks Worse

    A new Proofpoint survey found that 65% of organizations hit by ransomware reported AI made the attack more potent, with AI now used to create highly convincing phishing emails and credential theft campaigns. Human interaction remains the primary entry point for ransomware, with 47% of incidents i...

    Read More »
  • New Helix vishing group targets SharePoint in data theft attacks

    New Helix vishing group targets SharePoint in data theft attacks

    A new threat group called Helix uses voice phishing, device code phishing, and MFA abuse to compromise SharePoint environments for data extortion. Helix bypasses security by tricking employees through vishing calls and then exploiting device code phishing to gain persistent access without trigger...

    Read More »
  • Extortion crew hijacks Microsoft 365 accounts with fake passkey scam

    Extortion crew hijacks Microsoft 365 accounts with fake passkey scam

    A sophisticated vishing campaign by the Pink cyber extortion crew uses fake passkey enrollment requests to hijack Microsoft 365 accounts, directing victims to a fake Microsoft Entra ID login page that captures credentials and MFA factors. The attack employs a panel-controlled phishing kit with lo...

    Read More »
  • Tata Electronics confirms data leak after cyberattack

    Tata Electronics confirms data leak after cyberattack

    Tata Electronics confirmed a cybersecurity attack on some IT systems weeks ago, but stated its manufacturing operations, including Apple iPhone production, remain fully operational and unaffected. The World Leaks threat group, a rebrand of the Hunters International ransomware group, claimed respo...

    Read More »
  • Healthcare Firm Hit Days After Novo Nordisk Breach

    Healthcare Firm Hit Days After Novo Nordisk Breach

    iRhythm Technologies disclosed a cyberattack on June 8, 2026, involving unauthorized access to third-party-hosted business applications, resulting in the theft of protected health information and proprietary data, which the company deemed material. A threat actor contacted iRhythm demanding payme...

    Read More »
  • Foxconn Ransomware Attack Underscores Ongoing Security Risks

    Foxconn Ransomware Attack Underscores Ongoing Security Risks

    The ransomware group Nitrogen claims to have stolen 8 TB of sensitive data, including schematics from major clients like Apple and Dell, from Foxconn, which confirmed a cyberattack affecting its North American factories. Foxconn is a prime target due to its role as a global manufacturer holding i...

    Read More »
  • Meta Halts Mercor Partnership Following AI Data Breach

    Meta Halts Mercor Partnership Following AI Data Breach

    Meta has indefinitely suspended its partnership with data contractor Mercor following a major security breach, prompting other AI labs to reassess their engagements with the firm. The breach is linked to a supply-chain attack via the AI tool LiteLLM by a group called TeamPCP, which has disrupted ...

    Read More »
  • Aura Data Breach Exposes 900,000 Contacts

    Aura Data Breach Exposes 900,000 Contacts

    Aura, a digital safety firm, suffered a data breach exposing nearly 900,000 records, primarily names and email addresses, due to a successful voice phishing attack on an employee. The threat group ShinyHunters claimed responsibility, leaked the data online, and while sensitive financial data was ...

    Read More »
  • Canada Goose Data Breach Exposes 600,000 Customers

    Canada Goose Data Breach Exposes 600,000 Customers

    A data leak exposed over 600,000 Canada Goose customer records, but the company states its own systems were not breached and no full financial data was involved. The leaked information includes extensive personal and order details, enabling highly targeted phishing, social engineering, and fraud ...

    Read More »
  • Cyberattack Forces La Sapienza University Offline

    Cyberattack Forces La Sapienza University Offline

    La Sapienza University in Rome has taken its entire network offline due to a major cyberattack, causing widespread disruption for over 112,500 students as authorities and a technical task force work on remediation. The attack is reported to be a ransomware incident by a pro-Russian group, involvi...

    Read More »
  • ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft

    ShinyHunters Breach Okta, Microsoft SSO in Major Data Theft

    The ShinyHunters gang is conducting a sophisticated voice phishing campaign, using social engineering to steal credentials and MFA codes by impersonating IT support and using real-time, interactive phishing kits. Attackers exploit compromised SSO accounts (e.g., Okta, Microsoft Entra, Google) to ...

    Read More »
  • Pharma's Biggest Cyber Threat Isn't a Breach

    Pharma's Biggest Cyber Threat Isn't a Breach

    The primary digital threat is shifting from data breaches to silent data misuse within complex vendor and AI systems, requiring a move from prevention to continuous governance. Ransomware groups are weaponizing regulatory exposure, extorting payments by threatening to force disclosure of stolen s...

    Read More »
  • CISA Warns of Rising Bulletproof Hosting Threat

    CISA Warns of Rising Bulletproof Hosting Threat

    CISA and global partners have released a guide to help combat bulletproof hosting, which enables ransomware, phishing, and other cybercrimes by ignoring legal complaints and aiding criminal anonymity. The guide recommends defensive measures like identifying malicious resources, improving traffic ...

    Read More »
  • ShinyHunters Unleash ShinySp1d3r Ransomware-as-a-Service

    ShinyHunters Unleash ShinySp1d3r Ransomware-as-a-Service

    A new ransomware-as-a-service platform called ShinySp1d3r is being developed by threat actors linked to ShinyHunters and Scattered Spider, marking a strategic shift from using established gangs' encryptors to building their own bespoke operation. The ransomware features advanced capabilities incl...

    Read More »
  • GlobalLogic Hit by Cl0p Ransomware Following Oracle EBS Breach

    GlobalLogic Hit by Cl0p Ransomware Following Oracle EBS Breach

    GlobalLogic, a Hitachi-owned software firm, notified 10,471 current and former employees that their personal and financial data was stolen due to a breach in its Oracle E-Business Suite platform. The breach exploited a zero-day vulnerability in Oracle's system, leading to data exfiltration on Oct...

    Read More »
  • Hacker Groups Unite: Scattered Spider, ShinyHunters, LAPSUS$ Form Alliance

    Hacker Groups Unite: Scattered Spider, ShinyHunters, LAPSUS$ Form Alliance

    Scattered LAPSUS$ Hunters (SLH) is a confirmed alliance merging the reputations of Scattered Spider, ShinyHunters, and LAPSUS$, signaling a long-term strategic consolidation in the cybercrime world. The group operates through a small core of operators managing multiple personas, using Telegram as...

    Read More »
  • Salesforce Refuses to Pay Ransom in Massive Data Breach

    Salesforce Refuses to Pay Ransom in Massive Data Breach

    Salesforce has refused to pay a ransom after a data breach allegedly exposed nearly one billion customer records, emphasizing its policy against negotiating with cybercriminals despite the risk of data exposure. The attack, initiated in May, involved English-speaking operatives tricking employees...

    Read More »
  • Salesforce, CentreStack Hit by Hackers in Zero-Day Attacks

    Salesforce, CentreStack Hit by Hackers in Zero-Day Attacks

    Major platforms like Salesforce and CentreStack have been compromised by zero-day vulnerabilities, underscoring the need for timely patching and robust security measures. Recent incidents include the Cl0p gang exploiting Oracle E-Business Suite flaws and North Korean hackers stealing over $2 bill...

    Read More »
  • 'Happy Gilmore' Producer Acquires Spyware Maker NSO Group

    'Happy Gilmore' Producer Acquires Spyware Maker NSO Group

    NSO Group, the developer of Pegasus spyware, is nearing acquisition by a U.S. consortium led by Robert Simonds, pending Israeli regulatory approval, amid financial struggles from lawsuits by WhatsApp and Apple. Apple has removed ICE-monitoring apps from its App Store under Department of Justice p...

    Read More »