Topic: ransom negotiation
-
Instructure Reaches Deal With Hackers in Canvas Attack
Instructure reached an agreement with the ShinyHunters cybercriminal group behind the breach, securing the return and claimed destruction of stolen data affecting nearly 9,000 educational institutions, though no details on ransom payment were disclosed. The original breach exploited a vulnerabili...
Read More » -
Silent Ransom Group targets law firms via fake IT support calls
The Silent Ransom Group is aggressively targeting U.S. law firms and professional services through sophisticated social engineering, beginning with invoice-themed phishing emails followed by callback phishing where attackers impersonate IT help desk staff to gain remote access. Once inside, the g...
Read More » -
ShinyHunters hacks Canvas login portals in mass extortion campaign
The ShinyHunters extortion gang defaced Canvas login portals at approximately 330 educational institutions, displaying a ransom demand and threatening to release stolen data unless a settlement is reached by May 12, 2026. This attack follows a recent breach where ShinyHunters claimed to have stol...
Read More » -
Wynn Resorts Employee Data Breached Following Extortion Threat
Wynn Resorts suffered a data breach by the ShinyHunters hacking group, compromising employee data including Social Security numbers, but guest operations were unaffected. The group threatened to leak the data and demanded contact, with the incident listing later removed, though it's unclear if a ...
Read More » -
Zara Data Breach Exposes Data of Nearly 200,000 Customers
A ShinyHunters campaign compromised personal data of over 197,000 Zara customers, including email addresses and order details, via stolen authentication tokens from analytics provider Anodot, which were used to access BigQuery and Snowflake instances. The breach originated from an attack on Anodo...
Read More » -
MATLAB Developer Hit by Ransomware, 10,000 Users' Data Stolen
MathWorks experienced a ransomware attack in April that compromised the personal data of over 10,000 individuals, including sensitive information like names, addresses, and Social Security Numbers. The breach caused significant service disruptions, affecting multi-factor authentication, the onlin...
Read More » -
New Canvas Hack Ransomware Attack Sparks Security Crisis
A ransomware attack on Instructure's Canvas learning platform caused widespread disruption at thousands of schools, including Harvard and Columbia, during finals week, forcing the system into maintenance mode. Hackers known as ShinyHunters stole sensitive student data (names, emails, student IDs)...
Read More » -
DeadLock Ransomware Evades Security with BYOVD Attack
The DeadLock ransomware campaign uses a BYOVD technique, exploiting a known vulnerability (CVE-2024-51324) in a Baidu Antivirus driver to disable security software and delete recovery options before deploying its payload. The ransomware itself, written in C++, uses process hollowing and a custom ...
Read More » -
GlobalLogic Alerts 10,000 Staff to Data Theft After Oracle Hack
GlobalLogic notified over 10,000 current and former employees of a data breach after attackers exploited a zero-day vulnerability in Oracle's E-Business Suite, compromising sensitive HR data. The breach, attributed to the Clop ransomware group, involved the theft of extensive personal and financi...
Read More » -
Qilin Ransomware Hits Asahi Brewery, Leaks Sensitive Data
The Qilin ransomware group claimed responsibility for a cyberattack on Asahi, leaking thousands of sensitive documents including financial records and employee IDs to prove the breach. The attack disrupted Asahi's operations, forcing the temporary shutdown of six production facilities and causing...
Read More » -
Asahi Hit by Ransomware Attack, Data Breach Confirmed
Asahi Group Holdings experienced a ransomware attack causing major IT system failures, halting automated order and shipping operations and forcing a temporary switch to manual processes. The cyber intrusion led to a confirmed data breach, with evidence of information being illicitly extracted, an...
Read More » -
Massive cPanel Bug Exploited by Hackers to Hijack Thousands of Sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-41940) in cPanel and WebHost Manager, with over 550,000 servers potentially vulnerable and thousands already compromised. The U.S. cybersecurity agency CISA has added the flaw to its Known Exploited Vulnerabilities catalog, mandat...
Read More » -
Ransomware gang asked BBC reporter to hack media giant
A BBC cybersecurity journalist was targeted by the Medusa ransomware gang, which attempted to recruit him as an insider threat to gain network access in exchange for a share of a ransom payment. The Medusa gang is known for double-extortion tactics and has been linked to over 300 attacks on U.S. ...
Read More » -
M&S hit by ransomware attack due to social engineering
M&S suffered a ransomware attack after cybercriminals used social engineering to impersonate an employee, gaining access via a third-party provider and deploying DragonForce ransomware. The attack involved detailed impersonation tactics, potentially facilitated by Tata Consultancy Services, and e...
Read More » -
Gentlemen Ransomware Strikes Romanian Energy Provider
A ransomware attack on Romania's Oltenia Energy Complex, a major power supplier, disrupted its IT systems during the holiday period but did not compromise the national energy grid's stability. The attack is attributed to the Gentlemen ransomware group, which uses specific tactics like unique file...
Read More »