Topic: extortion tactics
-
Telegram CEO: Extortionist planted CSAM to get app pulled from App Store
Telegram CEO Pavel Durov claims Apple removed Telegram from the App Store without prior notice, allegedly due to an extortionist planting child sexual abuse material in a public chat. Durov argues this incident signals a systemic risk for all apps hosting user-generated content, warning that any ...
Read More » -
New Spirals ransomware encrypts networks in under 24 hours
A new ransomware strain called "Spirals" completed a full corporate intrusion cycle in under 24 hours, targeting an IT services company in South Asia by compromising a publicly exposed IIS server. The attacker bypassed UAC, enabled Remote Desktop, dumped credentials, disabled Microsoft Defender...
Read More » -
Blackfield ransomware demands $2M from Nidec Corporation
Blackfield ransomware group demands $2 million from Nidec Corporation after attacking its Taiwanese subsidiary, Nidec Chaun Choung Technology, on June 22, 2026, threatening to publish stolen data unless paid within 15 days. Nidec confirmed the ransomware attack, shut down affected servers to prev...
Read More » -
Ransomware's New Tactic: Creating Chaos
Ransomware attacks are increasing in frequency and sophistication, with over half occurring during weekends or holidays to exploit reduced staffing, and groups now employing aggressive tactics like quadruple extortion to cause operational paralysis. The economics are shifting as fewer victims pay...
Read More » -
BlackFile Group Targets Retail, Hospitality via Vishing Attacks
A new cyber extortion group, CL-CRI-1116, linked to BlackFile and "The Com," has targeted retail and hospitality sectors since February 2026, using vishing attacks and living-off-the-land strategies to steal credentials and bypass MFA. The group abuses APIs and SharePoint to exfiltrate sensitive ...
Read More » -
Odido Data Breach: ShinyHunters Gang Claims Millions Affected
The ShinyHunters extortion gang breached Dutch telecom provider Odido, potentially exposing millions of customers' sensitive personal data like names, addresses, and ID numbers, though the company states passwords and financial details were not compromised. Odido and the attackers dispute the sca...
Read More » -
FBI and Google warn of ransomware gangs posing as IT workers
The Silent Ransom Group has escalated attacks on law firms by dispatching fake IT workers in person to victims' offices to steal data using USB drives or remote access tools. The gang uses social engineering and phishing to gain remote access, but also employs physical intrusions to bypass securi...
Read More » -
How ShinyHunters Hackers Exploit SSO to Steal Cloud Data
The ShinyHunters group uses sophisticated voice phishing (vishing) to steal employee credentials and bypass multi-factor authentication by impersonating IT support and using fake login pages. Once inside via a compromised single sign-on (SSO) account, attackers gain a centralized springboard to a...
Read More » -
Salesforce customer data exposed in Gainsight breach
A security breach involving Salesforce customer data occurred through applications developed by Gainsight, with Salesforce confirming the incident is under investigation but not due to a vulnerability in its own platform. The cybercriminal group ShinyHunters has claimed responsibility for the bre...
Read More » -
Washington Post confirms data breach in Oracle hack
The Washington Post confirmed a data breach through vulnerabilities in Oracle's E-Business Suite, highlighting risks from ransomware groups exploiting third-party platforms. The ransomware group Clop exploited security flaws in Oracle's software to steal sensitive business and employee data from ...
Read More » -
Iran-Linked Hackers Posed as Ransomware Group in Spy Campaign
Iranian state-linked group MuddyWater used the Chaos ransomware brand as cover for espionage, infiltrating an organization via Microsoft Teams screen sharing and harvesting credentials before exfiltrating data, but never deploying actual ransomware. Key red flags indicating state sponsorship incl...
Read More » -
ShinyHunters' New MFA Bypass Fuels Data Theft
A sophisticated social engineering campaign is bypassing multi-factor authentication (MFA) using synchronized voice and email phishing attacks, successfully targeting major companies like Panera Bread and Match Group. Attackers, linked to groups like UNC6661 and ShinyHunters, use IT impersonation...
Read More » -
Millions of PornHub Users' Data Stolen in Extortion Hack
U.S. border agencies are expanding surveillance by deploying small drones operationally and enhancing cybersecurity to monitor employees, amid investigations into leaks. Major data breaches include the theft of over 200 million user records from PornHub by hackers and the rise of AI tools like Ha...
Read More » -
Bolster Defenses Against Scattered Spider Attacks, Experts Warn
The Scattered Spider hacking group poses a severe threat to businesses by using sophisticated methods like social engineering and ransomware, requiring immediate improvements in identity management, security processes, and third-party risk management. Their attack strategy often starts with vishi...
Read More »