Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Monday, 26 September 2022

Data Breaches Digest - Week 39 2022

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 26th September and 2nd October 2022.


2nd October

5 Windows security settings you should change now to protect your laptop

According To The Latest Survey, VPNs Are The New Door To Cyberhacking

Australians race to secure their data in the wake of a cyber attack

BlackCat ransomware gang claims to have hacked US defense contractor NJVC

Cybercriminals behind Los Angeles Unified School District ransomware attack release hacked data, superintendent says

‘Drawbridge needs to come down’: Government says Optus must show more transparency

Energy bills support scheme: Scam texts warning as fraudsters target £400 support for households

German police identified a gang that stole €4 million via phishing attacks

Hacker Exploits $21M Vulnerability in Transit Swap

Hackers claim to reveal identities of cops who arrested Mahsa Amini

Hackers Release L.A. School District Data Over Failure To Pay Ransom, Officials Say

How cyber governance and disclosures are closing the gaps in 2022

How to enable two-factor authentication on every social platform (and yes, you should)

Iran: Hackers Reveal Alleged Identities Of Amini's Arrest Team

Los Angeles Unified School District (LAUSD) Creates Hotline After Stolen Data Posted by Ransomware Group

Lost money to cyber criminals? Know from experts how to protect your hard-earned money, credit cards, data from scammers

New DDoS Malware ‘Chaos’ Hits Linux and Windows Devices

North Korean Hackers Lacing Legit Software with Malware

Optus grilled for not being forthcoming over data breach

Optus hack response 'not going to cut it'

Optus yet to share hacked customer details with Services Australia

Ransomware gang leaks data stolen from LAUSD school system

Russians dodging mobilization behind flourishing scam market

Scamwatch advises Optus data breach victims to take action to protect themselves

Singapore: Police warn of SMS phishing scams involving Singpass

T-Mobile $350 Million Data Breach Settlement: Here's How Much Money Could You Qualify For

T-Mobile Is Awaiting Approval of $350 Million Data Breach Settlement, Cyberattack Victims can Claim Compensation Soon

Tech-savvy teens and state-sponsored hacks: Notorious cyberattacks in history

The Top 5 Cloud Vulnerabilities You Should Know Of

What Is Shodan and How Can It Improve Your Online Security?

What will determine Optus’ future after cyber attack

1st October

3 types of potential business liability associated with data breaches

A Security Expert Tells Us How To Protect Your Personal Data From Hackers

China: Notorious U.S. cyber attacks

Chinese Hackers Hiding Malware in Windows Logo

CISA Warns of Hackers Exploiting Critical Atlassian Bitbucket Server Vulnerability

Cybercriminals behind ransomware attack plan to release hacked data, Los Angeles Unified School District says

Eight Shangri-La hotels in Asia hit by data breach, potentially exposing guest information

Electricity Company of Ghana (ECG) systems hacked with ransomware

Electricity Company of Ghana prepaid central database compromised

Guacamaya hacktivists stole sensitive data from Mexico and Latin American countries

Hackers targeted 8 Shangri-La hotels between May and July, guests' data potentially leaked

Hackers would like you to join their LinkedIn network — be wary of these phishing attacks

Hotel Booking App Ordered to Compensate 300 Customers for Data Breach

How Optus was hacked by someone acting like a ‘kid in a garage’

How to mitigate the risk of the Optus data breach

Lazarus hackers abuse Dell driver bug using new FudModule rootkit

Microsoft to let Office 365 users report Teams phishing messages

Portugal: Tax Authority (AT) "Phishing" scam warning

Protecting online data has never been more vital

Shangri-La hack may affect over 290,000 Hong Kong guests

Shangri-La Hacked & Guest Information At Select Hotels Exposed

Shangri-La reports major data breach at eight hotels; guests' data leaked

Shift in scams targeting banks in South Africa

State-Sponsored Hackers Likely Exploited MS Exchange 0-Days Against ~10 Organizations

The true costs of a breach — and does your business really have to pay the ransom?

This is a list of hacker cases most emblematic of their millionaire figures

‘We’re deeply sorry’: Optus publishes grovelling full-page newspaper ad apologising for cyberattack

What businesses need to know about investigating, remediating and reporting a data breach

What Is SIM Jacking and What Can You Do to Protect Yourself?

What Is Consent Phishing and Why Is It Dangerous?

30th September

6 Ways Enterprises Can Secure Private Blockchains

7 Ways to Prevent a Smartphone Data Breach

90% of companies affected by ransomware in 2022

2,857 Geisinger patients affected by 3rd-party data breach

Are you inundated by a never-ending stream of cyberattacks?

Attackers use novel technique, malware to compromise hypervisors and virtual machines

Australia: Prime Minister Anthony Albanese has announced that Optus will cover the cost of passport replacements

BlackCat said they breached US Department of Defense contractor and went offline

Business Email Compromise (BEC) – One of the most common yet Dangerous Attacks

Capital One to pay $190m to settle a class-action lawsuit on 2019 data breach

CISA: Hackers exploit critical Bitbucket Server flaw in attacks

City council's planning system back up and running nine months after hack

Country Doctor Community Clinic Files Official Notice of a Data Breach with the Federal Government

Cyber attack: Gloucester City Council planning site mostly restored

Cyber Attacks Against Middle East Governments Hide Malware in Windows logo

Cyber attacks cost retailers millions and lessons from a ‘PR Nightmare’

Cybercriminals See Allure in BEC Attacks Over Ransomware

Data breach at border agency contractor involved up to 1.38 million licence plates

Data breach fears make older borrowers reluctant to share home loan data online

Data breach involving Cornwall border part of larger Canada Border Services Agency (CBSA) cache

Fake US government job offers push Cobalt Strike in phishing attacks

Financial Phishing Attacks Increased in Kenya, Nigeria in Q2, 2022

Financial phishing still on the rise

Geisinger patients notified of data breach incident

Germany arrests hacker for stealing €4 million via phishing attacks

Hacker groups assist Iranian protestors

Hackers are using open source software and fake jobs in phishing attacks

Hackers Backdoor Pirated Windows OS With Cryptominer and Xtreme RAT

Hackers Hide Malware in Windows Logo, Target Middle East Governments

Hackers Use Telegram, Signal, Dark Web to Help Iranian Protesters

Hacking Attack Narrowly Misses Davenport, Iowa, School District

Healthcare workers remain on the front line: Now against cyber threats

Hospitals, Utilities Face Highest Exposure to Risk of Cyber Attacks: Moody’s

Hotel booking app ordered to compensate 300 customers for data breach

How a Data Breach Could Sink an SME

How cybersecurity frameworks apply to web application security

How Public Agencies Can Reduce Risk of Data Breaches

How to protect your computer from BBBW Malware?

HSE cyber attack cost taxpayers at least €101m, with a further €657m to be spent safeguarding against repeat attacks

Huge win for millions caught up in Optus data breach

If you get an email warning your info is on the Dark Web, here’s what to do

Insider Threat Awareness Month – one click is all it takes

Internal Revenue Service (IRS) reports significant increase in texting scams; warns taxpayers to remain vigilant

Iran and Cybersecurity: What Technologists Need to Know

Lazarus-Associated Hackers Weaponize Open-Source Tools Against Several Countries

LeakBase Announces Swachhata Platform Breached, 16 Million User PII Records Exposed

Lone Star College System sees rise in cyber attacks, continuing pandemic trend

Los Angeles School District Ransomware Attackers Now Threaten to Leak Stolen Data

Magellan Health settles for $1.43M after data breach, delayed notification

Manufacturers Failing to Address Cybersecurity Vulnerabilities Liable Under New European Rules

MI5 website briefly knocked offline by possible cyber attack

Microsoft Confirms 2 New Exchange Zero-Day Flaws Being Used in the Wild

Microsoft confirms new Exchange zero-days are used in attacks

Microsoft Confirms Two 0-Days Being Exploited Against Exchange Servers

Microsoft Confirms Two Exchange Zero-Day Vulnerabilities

Microsoft Exchange Server Vulnerabilities CVE-2022-41040 and CVE-2022-41082

Mysterious Optus hacker suddenly DISAPPEARS from the site where they posted their chilling threats after issuing a grovelling apology to the telco

National Cyber Security Centre (NCSC): UK Organizations Can Learn from Ukraine's Impressive Cyber Defenses

Neurology Center of Nevada Reports Recent Data Breach Affecting 11k+ Patients

New Exchange Server zero-day vulnerabilities are being used in cyberattacks: Protect your network now

New Malware Campaign Targeting Job Seekers with Cobalt Strike Beacons

New Malware Families Found Targeting VMware ESXi Hypervisors

New Unpatched Microsoft Exchange Zero-Day Under Active Exploitation

North Korean Hackers Weaponizing Open-Source Software in Latest Cyber Attacks

Northern California Fertility Medical Center Announces Data Breach Leaking Patients’ Protected Health Information

Okta ‘Breaches’ Weren’t Really Breaches

One out of four employees fall for phishing attacks

Optus breach victims will get "supercharged" fraud protection

Optus Cyber Attack Potentially Exposed Personal Data of up to 40% Of Australians, Negligence Suspected

Optus data breach: federal police launch ‘Operation Guardian’ to protect identity of 10,000 victims

Optus to pay for New Australian passports for those affected by cyber attack

Optus to pay for new passports

Optus victims issued warning over vile text and email scams

Organizations Battle Ransomware Targeting Supply Chains

Over 145,000 customers' data was exposed in agency data breach incident

Pakistan: Audio leaks - All eyes on dark web ‘hacker’ who announced to release secret conversations today

Physician’s Business Office Files Notice of Data Breach Affecting Over 196k Patients

Pro-Russia hacker group stops cyberattacks on Japan due to money woes

Quantifying the risk of cybersecurity

Ransomware, identity theft and virtual attacks fast becoming growing threats in Asia

SaaS Data targetted by half of Ransomware Attacks in last 12 months

Scamwatch urgently warning Australians to be on the lookout for increased scam activity following Optus data breach

Seattle Children's notifies 6,750 patients of third-party data breach

Secure Software Factory: Protecting Your Supply Chain

Solana PayPal Invoice Scam

South Korea: ATM Withdrawals Capped to Thwart Phishing Scams

Texas healthcare provider FMC Services suffers a ransomware attack

The 5-Question Test to Assess Your Readiness to Manage Insider Threats

The Coeur Group notifies patients of data breach

The ‘Optus hacker’ claims they’ve deleted the data. Here’s what experts want you to know

The Psychological Effects of Getting Your Data Leaked That No One Talks About

Toolkit, formerly employed for cybersecurity is now made accessible to hacker communities

Top Amazon scams to avoid in 2022

Top issues driving cybersecurity: Growing number of cybercriminals, variety of attacks

Two Microsoft Exchange zero-days exploited by attackers (CVE-2022-41040, CVE-2022-41082)

Vice Society raises ransomware pressure on Los Angeles school district

Warning over new ‘Erbium’ malware that steals credit card details and personal data

We now know the 200 most used passwords, and hacking them is pretty easy

What Proof of Stake Means for the Future of Blockchain Security

29th September

4 Top Ransomware Detection Techniques To Keep Your Data Safe

5 Things You Need To Know About Data Privacy

6-Point cyber hygiene checklist for enterprises to prevent data breach

8 things a business can do online to be more secure

65% of companies are considering adopting VPN alternatives

75% of Australian companies had cloud security incident in past year

81% of organizations suffered a cloud security incident last year

American Airlines breach was gold mine for identity thieves

Anxious wait: Optus victims unsure of data hack fallout

Australia: Assistant Treasurer Stephen Jones says Optus hacker 'appears' to be individual criminal amid massive data breach

Australia: Companies don't need to keep identification data after it's been verified, attorney-general says

Australia flags tough new data protection laws this year

Australia's massive data breach risks eroding Singtel's profits

Australian Electoral Commissioner (AEC) says no need to update enrolment information after Optus data breach

Backup as last line of defense against Hong Kong ransomware threats

Black Friday shoppers warned to be vigilant as online scams are on the rise

Brazilian Prilex Hackers Resurfaced With Sophisticated Point-of-Sale Malware

Business Email Compromise (BEC) attacks: Most victims aren't using multi-factor authentication – apply it now and stay safe

Canberrans most at risk to receive new, free driver licence

Chaos IoT malware taps Go language to harvest Windows, Linux for DDoS attacks

Crypto.com Targeted in Latest Round of Lazarus Group's Fake Job Scams

Crypto-Thieves Cost Victims 53 Times What They Make

Cyber Attack Temporarily Cripples Promo Supplier’s Systems

Cybersecurity Awareness Month 2022: 5 Tips for Consumers

Cybersecurity expertise needs to be incorporated into Bangladeshi company boards

Data of 72% of local, state government bodies encrypted after ransomware attacks

Data breach at border agency contractor involved up to 1.38 million licence plates

Data for 70,000 students accessed in summer cyber attack, public board reports

Data security trends: 7 statistics you need to know

'Disgruntled insider' shared REvil information with researchers, helped law enforcement

DJVU: The Ransomware That Seems Strangely Familiar

Effects of Optus breach will linger

Fake CISO Profiles on LinkedIn Target Fortune 500s

Fancy Bear Hackers Distributing Graphite Malware using PowerPoint Files

Fast Company Data Breach: Hackers Sent Offensive And Racist Push Notifications to Users

Fears of long impact from Optus breach

Financial Phishing Cyberattacks Significantly Increase in Kenya and Nigeria in Q2 of 2022

Fired admin cripples former employer's network using old credentials

Former Virgin Mobile, Gomo customers could also be victims of Optus data hack

Government, Union-Themed Lures Used to Deliver Cobalt Strike Payloads

GTA 6 Hacker Allegedly Sold GTA 5 Source Code Before Arrest

Hackers Aid Protests Against Iranian Government with Proxies, Leaks and Hacks

Hackers Experimenting with Deploying Destructive Malware

Hackers turn to Signal, Telegram and Dark Web to assist Iranian protestors

Hacking group hides backdoor malware inside Windows logo image

Half of adults in England and Wales receive ‘phishing’ messages, Office for National Statistics (ONS) data reveals

Holiday Inn owner says booking systems fully restored after cyber attack

Hong Kong, Aoyuan Healthy Life Group hit by PT_Moisha ransomware group

How a massive data breach has exposed Australia

How is SOVA virus infecting your phone? State Bank of India (SBI), Punjab National Bank (PNB) customers beware

How To Protect Businesses Against A Series Of Cyber Attacks

Ignorance isn’t bliss: How tech users lack fundamental cybersecurity knowledge

India's Initiatives To Fight The Menace Of Cyber Attacks

Indonesia: Bjorka Returns with Personal Info of BSSN Chief

Internal Revenue Service (IRS): Text Phishing Scams Have Risen ‘Exponentially’

Internal Revenue Service (IRS) reports significant increase in texting scams

Internal Revenue Service (IRS) Warns of "Industrial Scale" Smishing Surge

It takes the average hacker less than 10 hours to find vulnerabilities

Lazarus Hacker Group Targets MacOS Users Through Crypto Jobs

Lazarus Hackers Attack MacOS Users by impersonating Crypto[.]com

LeakBase: India Swachhata Platform Breached, 16 Million User PII Records Exposed

Magellan Health settles data breach lawsuit for $1.43M

Malware builder uses fresh tactics to hit victims with Agent Tesla RAT

Matrix: Install security update to fix end-to-end encryption flaws

Microsoft: Lazarus hackers are weaponizing open-source software

Microsoft’s CISO on why cloud matters for security response

Mid Sussex councillor calls for Housing Ombudsman to investigate Clarion Housing Association after cyber attack

Mobile, Cloud and Email Are Top Threat Vectors For 2023

Moody's says hospitals, utilities face high hacking risks

More Than Half of Security Pros Say Risks Higher in Cloud Than On Premise

Multifactor authentication isn't perfect, passwordless is better

Nearly 75% of local and state government organizations attacked by ransomware had their data encrypted

New Chaos malware spreads over multiple architectures

New malware backdoors VMware ESXi servers to hijack virtual machines

New Microsoft Exchange zero-days reportedly exploited in attacks

New Royal Ransomware emerges in multi-million dollar attacks

New Threat Spotlight Shows Ransomware Attacks Continue to Grow

Nigeria and Kenya Records High Rate of Financial Phishing Cyberattacks in Q2 of 2022

Noberus Amps Its Tactics: How IT Leaders Can Keep Up with Evolving Ransomware

Office exploits continue to spread more than any other category of malware

Optus cyber attack intensifies calls to address cyber insurance gaps

Optus tells former Virgin Mobile and Gomo customers they could also be part of data breach

Parents warned about text scam with fraud concerns rife amid Optus data breach

Personal App Use on the Rise – And So Are Cloud Security Risks

Phishing attacks are on the rise: Key actions to take

Police say hacker concealed ID in Australian privacy breach

Ransomware attack on Suffolk County heightens importance of cybersecurity for local municipalities

Researchers Discover Chaos, a Golang Multipurpose Botnet

Researchers Uncover Covert Attack Campaign Targeting Military Contractors

Robinhood data breach class action settlement

Russian hackers' lack of success against Ukraine shows that strong cyber defences work, says cybersecurity chief

SaaS data was the target of half of recent ransomware attacks

Scam warning: The IRS isn't texting anyone

Singapore firms see 54 cybersecurity incidents daily, struggle to keep up

Small businesses in India at highest ransomware risk

Sussex MPs warn about energy bills phishing scam

Swachh City Platform Suffers Data Breach Leaking 16 Million User Records

T-Mobile to pay millions to settle class-action suit over data breach

The Increasing Concern of Public-Sector Cybersecurity in State and Local Government

The rise of the dark web corporation

Too much data collection means we're more at risk of having personal details stolen, expert says

Training can help swing odds against ransomware in favor of financial industry

Trend Micro blocked and detected over 55 million threats in Saudi Arabia

UK is a top three ransomware target

UK Suffers Third Highest Rate of Ransomware Attacks in the World

Upgraded Prilex Point-of-Sale malware bypasses credit card security

US Defense Contractor Victimized by Ransomware Attack

What Is Vishing? And How to Protect Against It

What Telcos Should Learn from the Optus Breach

What the Securing Open Source Software Act does and what it misses

White House Releases Software Supply Chain Security Guidance

28th September

2K Games Help Desk Platform Hacked to Spread Info-stealing Malware

3 types of attack paths in Microsoft Active Directory environments

20% of All Reported Ransomware Attacks Occurred in the Last 12 Months

American Airlines Data Breach Linked to a Phishing Campaign Exposed Sensitive Customer and Employee Personal Information

API Security Incidents Rise, Despite Confidence in Protection

Are You (Legally) Prepared For Cyber-Attacks?

Australia: Anthony Albanese says ‘Optus should pay’ for new passports for data breach victims

Australia: Government ‘particularly concerned’ over Medicare leak in Optus data breach

Australia government wants Optus to pay for data breach

Auth0 warns that some source code repos may have been stolen

Bansley & Kiener data breach $900K class action settlement

Bosnia Remains Silent on Hacker Attack on Parliament

Businesses find remote work security risks less daunting than before

Cost of a Data Breach: Infrastructure

Critical WhatsApp Bugs Could Have Let Attackers Hack Devices Remotely

Cryptominers hijack $53 worth of system resources to earn $1

Cyber Criminals Using Quantum Builder Sold on Dark Web to Deliver Agent Tesla Malware

Cyber Threat Detection: 5 Top Priorities for Critical Infrastructure Security Leaders

Cyber-Threats Top Business Leaders' Biggest Concerns

Cyberattacks and Changing Consumer Behavior - What You Need to Know?

Data breaches in the financial sector

DuPage Medical Group data breach $3M class action settlement

Ethernet VLAN Stacking flaws let hackers launch DoS, MiTM attacks

Facebook Shuts Down Covert Political 'Influence Operations' from Russia and China

FMC Services, LLC Announces Data Breach Affecting More than 230k People’s Sensitive Information

Fremont County, Colorado, in ‘Recovery Phase’ After Cyber Attack

GTA 6 hacker heads to court, pleads Not Guilty

GTA 6 teen hacker pleads not guilty in court

Hacker Breaches Fast Company Apple News Account, Sends Racist Messages

Hacker breaches Fast Company systems to send offensive Apple News notifications

Hacker Groups take to Telegram, Signal and Darkweb to assist Protestors in Iran

Hacker shares how they allegedly breached Fast Company’s site

Hackers are making DDoS attacks sneakier and harder to protect against

Hackers LeakBase attacks swachh.city platform

Hackers now sharing cracked Brute Ratel post-exploitation kit online

Hackers seek to help — and profit from — Iran protests

Hackers Use Telegram and Signal to Assist Protestors in Iran

Hackers Using PowerPoint Mouseover Trick to Infect System with Malware

How Can Cybersecurity Professionals Account for Vulnerabilities in Fleet Data?

How To Protect Your Reputation After A Hack Or Data Breach

IceFire ransomware gang ramping up attacks

ICO Reprimands UK Organizations for GDPR Failings

Illinois School District Purges Old Tech After Cyber Attack

Initial access brokers: The new face of organized cybercrime

Initial Access Brokers and Blocking the Continued March of Ransomware

Intruder alert! How one hacker infiltrated Uber

IRS warns Americans of massive rise in SMS phishing attacks

Know Thy Enemy: Why RagnarLocker Remains a Significant Threat to Critical Infrastructure

Leaked LockBit 3.0 builder used by ‘Bl00dy’ ransomware gang in attacks

Magellan Health data breach $1.43M class action settlement

Maximal Extractable Value (MEV) bot earns $1M but loses everything to a hacker an hour later

Meta Takes Down Russian "Smash-and-Grab" Disinformation Campaign

Microsoft 365 Email Hack Led to American Airlines Breach

Mississauga, Oakville, Hamilton residents warned of email phishing scam

Montefiore Medical Center flash drive containing patient information stolen in 6th data breach in 2 years

Moving Security Technologies to the Cloud? 4 Tips for CISOs

Multi-platform Chaos malware threatens to live up to its name

Nearly 700 ransomware incidents traced back to wholesale access markets

New Chaos malware infects Windows, Linux devices for DDoS attacks

Open source software security act introduced

Optus attackers publish and then delete data

Optus confirms 14,900 active Medicare details exposed in data breach

Optus customers, not the company, are the real victims of massive data breach

Optus data breach: everything we know so far about what happened

Organizations Need New Approaches to Cybersecurity

Organized Credit Card Fraud Groups Create Fake Sites To Run Charges on Stolen Credit Cards

Paying the ransom is still the most common response to a ransomware attack

Phishing Attack Targets Microsoft Flaw to Deliver Cobalt Strike

Phishing Attacks Crushed Records Last Quarter, Driven by Mobile

Phishing Is More Common (and More Dangerous) Than Ever - Here's How to Stay Safe

Report Shows How Long It Takes Ethical Hackers to Execute Attacks

Researchers Warn of New Go-based Malware Targeting Windows and Linux Systems

Scylla Ad Fraud Attack on iOS and Android Users Halted by Apple and Google

Sophisticated Covert Cyberattack Campaign Targets Military Contractors

Stealthy hackers target military and weapons contractors in recent attack

The Evolution of Vulnerability Scanning and Pentesting

The Optus hacker is being treated as the real deal by the government. Its apology can’t be trusted

There's been a big rise in hackers targeting Google Chrome - doing this one thing can help protect you

These advanced phishing tactics should put all businesses on high alert

This Maximal Extractable Value (MEV) bot gained and lost over $1M in 1 hour

US senators aim to amend cybersecurity bill to include crypto

WatchGuard Report: Malware Decreases but Encrypted Malware Up in Q2 2022

What happened to the hacker behind gaming’s biggest GTA 6 leak?

What next to combat ransomware following the Optus attack?

What to do if you’re impacted by a data breach

27th September

10 statistics that show the cost of a data breach to companies

46 percent of ransomware attacks happen in the US but who are the targets?

Accused Grand Theft Auto 6 Hacker Pleads Not Guilty to Computer Misuse

Alleged hacker responsible for GTA 6 leak pleads not guilty to charges of computer misuse

Alleged Optus hacker apologises for data breach and drops ransom threat

Alleged Optus Hacker Apologizes, Deletes Customers' Exposed Data

Australian police probe purported hacker's ransom demand

BlackCat/ALPHV Gang Adds Wiper Functionality as Ransomware Tactic

Chilean Court System Hit With Ransomware Attack

CISOs Have Lost Confidence in Ability to Quash Ransomware

Defense firm Elbit Systems of America discloses data breach

Defense Giant Elbit Confirms Data Breach After Ransomware Gang Claims Hack

Digital forensic investigator's warning for Aussies after Optus data breach

Evolving ransomware requires a modern approach to data management and protection

Experts Uncover 85 Apps with 13 Million Downloads Involved in Ad Fraud Scheme

Extortion Economics: Ransomware’s New Business Model

Federal government under pressure to reveal Optus data breach plan as FBI called in to help

Fintech Company Suffers Data Breach

Fraudsters adapt phishing scams to exploit cost-of-living crisis

Fulcrum Utility Services hit by cyber attack but no data breached

Global Firms Deal with 51 Security Incidents Each Day

Hacker Behind Optus Breach Releases 10,200 Customer Records in Extortion Scheme

Hacker Gained Access to 2K Games Helpdesk System, Used Customer Service Tickets To Send Malware Links to Players

Hacker group publishes stolen data from French hospital

Hackers are testing a destructive new way to make ransomware attacks more effective

HHS Alerts Health Sector to Monkeypox-Themed Phishing Campaign

How to Protect Your Organisation from a Cyber Attack

Humana Discloses Third-Party Data Breach at Choice Health

Is Anonymous’ cyber attack on Iran ‘hacktivism’ or a nuisance?

Lazarus Group Targets MacOS Users Seeking Crypto Jobs

Lazarus hackers drop macOS malware via Crypto.com job offers

Legacy tech is undermining responses to ransomware in UK

Machines make up 43% of digital identities on enterprise networks

Making a business case for security in a world of tightening budgets

Malicious Oauth app enables attackers to send spam through corporate cloud tenants

Meaningful Learnings from the Uber Breach

Meta dismantles massive Russian network spoofing Western news sites

Microsoft Sway Pages Weaponized to Perform Phishing and Malware Delivery

MS SQL servers are getting hacked to deliver ransomware to orgs

New NullMixer dropper infects your PC with a dozen malware families

New NullMixer Malware Campaign Stealing Users' Payment Data and Credentials

North Korea's Lazarus Hackers Targeting macOS Users Interested in Crypto Jobs

Observing the Changing Nature of Security within Organizations

Open source projects under attack, with enterprises as the ultimate targets

Optus cyber attacks: New scams could dupe victims for a second time

Optus data breach: an update for Australian Prudential Regulation Authority (APRA) regulated entities

Optus data breach: FBI involved as hackers begin releasing customer records

Optus hacker apologizes and allegedly deletes all stolen data

Optus Hacker Apologizes to Australians Over Data Breach

Optus notifies customers about data breach impact

Optus to pay for licence replacements

Optus under further fire for cyber breach, purported hacker claims data deleted

Optus, Australian government clash over massive data breach

Oxford Health: Cyber attack continues to hit NHS trust's services

Phishing Attacks Are At Their Highest As Figures Quadruple From 2020, Claims New Study

Ransomware and the Severe Impact on K-12 Public Schools

Ransomware attacks continue to increase, with 20% of all reported attacks occurring in the last year

Ransomware Attacks Fall as Groups Restructure

Ransomware report finds reduction in percentage of organizations with disaster recovery plans in place

Ransomware Resiliency Starts with a Plan. What’s Yours?

Retail and Wholesale Saw Over 400% Increase in Phishing Attacks

RiskLens Fast Facts on Cyber Risk for Local Governments – Suffolk County, New York, Ransomware Attack

SaaS Data Was the Target of 51% of Ransomware Attacks in the Last 12 Months; More Than Half of These Attacks Were Successful

Suffolk County Data Breach Puts Contracts On Back Burner

Suspected Grand Theft Auto 6 hacker arrested by UK police

The Dire Warnings in the Lapsus$ Hacker Joyride

The Grand Tour’s Jeremy Clarkson Targeted By Russia-Based Hacker Group

The Guide To Dealing With A Ransomware Crisis For Businesses

The U.S. is the top target of ransomware attacks, report says

The various ways ransomware impacts your organization

TikTok Facing £27m UK Regulatory Fine

UK suffers third highest number of ransomware attacks globally

Ukraine Busts Pro-Russia Hackers Who Stole 30 Million Accounts of EU Citizens

Ukraine Predicts "Massive" Russian Cyber Assault

Ukraine Says Russia Planning Massive Cyberattacks on its Critical Infrastructures

US branch of Israeli defense contractor Elbit hit by data breach

What Exactly Is A Data Breach? Tips For Avoiding And Handling Leaks

What Is an Adversary-in-the-Middle Phishing Attack?

Why Continuous Security Testing is a Must for Organizations Today

Why zero trust should be the foundation of your cybersecurity ecosystem

26th September

3 ways to gauge your company’s preparedness to recover from data loss

5 Network Security Threats And How To Protect Yourself

5 Online Fraud Fighting Tips for Novices

6 Healthcare Cybersecurity, Operational Strategies For Successful CISOs

8 steps to take to protect yourself from email phishing

10 ways to increase your firm's resilience to a ransomware attack

75% of fraudulent online banking payments originate from trusted devices

A 17-year-old hacker, who leaked the gameplay of GTA 6, was arrested in Great Britain

A third of Irish firms surveyed have paid cyber ransoms, paying out an average of €22,773 each

A world without cybersecurity

Adware on Google Play and Apple Store installed 13 million times

American Airlines phishing attack involved unauthorized access to Microsoft 365

Apex Capital Corp. Reports Data Breach That Compromised Individuals’ Social Security Numbers

Australia: Ransomware bill reintroduced by Coalition

Australia flags privacy overhaul after huge cyber attack on Optus

Australia more at risk from cyberattacks, Thales says

Australia mulls tougher cybersecurity laws after data breach

Australia plans privacy rule changes after cyber attack at Singtel-owned Optus

BlackCat Ransomware Attackers Spotted Fine-Tuning Their Malware Arsenal

Calgary Parking investigation reveals more than 145,000 customers exposed during data breach

Caught up in the Optus data breach? Here's what to do immediately

Chinese Espionage Hackers Target Tibetans Using New LOWZERO Backdoor

Class-Action Lawsuit: Is There a Duty to Prevent Ransomware?

Criminals are using QR codes to scam people in restaurants!

Cyber scams on the rise in Zimbabwe

Decryptor Released for 'LockerGoga' Ransomware

Diodes Incorporated Confirms Recent Data Breach Affecting SSNs and Health Information

Fraud crimes up by 25% in two years, figures suggest

GTA 6 Hacker Previously Arrested & Violated Bail Conditions, UK Police Confirm

GTA 6 hacker update: Now charged with violation of bail and computer misuse

Hackers leak French hospital patient data in ransom fight

Hackers Use NullMixer and SEO to Spread Malware More Efficiently

Hackers use PowerPoint files for 'mouseover' malware delivery

HC3 Details APT41 Cyberattack Tactics, Risks to Healthcare Cybersecurity

How To: Keep Universities Secure in Today’s Cyber Threat Environment

How To Defend Against Ransomware Attacks: Where Security Automation Fits In

How to Tackle the Rising Prevalence of Insider Threats

INKY Finds New Phishing Attack Technique Spoofing Netflix

Ireland: ‘Don’t pay cyber ransoms’ – Garda warning as it’s revealed a third of SMEs have paid criminal groups this year

Lawsuit claims Mon Health didn't protect patients from data breach

Major Berry Producer, Reiter Affiliated Companies, LLC, Confirms Leaked SSNs in the Wake of Recent Data Breach

Microsoft SQL Server targeted by ransomware

Most orgs in Philippines are concerned about ransomware’s impact

Nearly 150K customer records accessed during 2021 data breach: Calgary Parking Authority

New Erbium password-stealing malware spreads as game cracks, cheats

No end in sight to NHS ransomware attacks?

North Macedonia Ministry Denies Covering up Ransomware Attack

Notice of Phishing Incident from CSI Laboratories

Online fraudsters adapt tactics to exploit UK cost of living crisis

Optus Faces $1 Million Ransom Due to Cloud Misconfiguration

Optus faces potential class action and pledges free credit monitoring to data-breach customers

Optus has not covered itself in glory in handling of breach

Optus suffers massive data breach putting millions at risk

Phishing Actors Are On The Rise And They’re Abusing LinkedIn’s ‘Smart Link’ Feature

Phishing attacks skyrocketing, over 1 million observed

Ransomware Affiliates Adopt Data Destruction

Ransomware attacks continue increasing: 20% of all reported attacks occurred in the last 12 months

Ransomware Attacks Surge

Ransomware Recovery: How to Respond to Ransomware Attacks

RCE in Sophos Firewall is being exploited in the wild (CVE-2022-3236)

ReasonLabs Unveils Multimillion Dollar Global Credit Card Scam

Researchers Identify 3 Hacktivist Groups Supporting Russian Interests

Richemont’s Watchfinder Reports Customer Data Breach

Russian hackers leak personal data of Ukraine intelligence agents

Security Priorities Are Shifting as 90% Of Organizations Fail To Address Cybersecurity Risks

Should We Consider the Maze Ransomware Extinct?

Simple Yet Vital Ways to Safeguard Yourself Against Online Threats

South Africa ill-equipped for cyberwarfare – with limited money, manpower, and tech expertise

SQL Server admins warned about Fargo ransomware

Suffolk Civil Service Exams Canceled For Saturday After Cyberattack

Suspected Grand Theft Auto 6 hacker set for court

T-Mobile has agreed to pay $350 million to settle complaints from last year’s data breach

The biggest cyber attacks of 2022

The case for an identity-first approach ‘Zero Trust’ privileged access management

The Optus Breach: How Bad Code Keeps Happening to Good Companies

TikTok may be fined £27m for failing to protect children

To encrypt or to destroy? Ransomware affiliates plan to try the latter

Tomorrow’s connected car technologies: risk or reward?

Uber Hack Not Just A Reputational Damage But Reveals Basic Security Flaws

UK phishing attacks targeting cost of living crisis on the rise

UK Teen Arrested on Computer Misuse Charges

Ukraine Arrests Cybercrime Group for Selling Data of 30 Million Accounts

Ukraine warns allies of Russian plans to escalate cyberattacks

Vanity Addresses in the Spotlight Again as Hacker Gets Away With $950,000

Vice Society claims ransomware attack that hit six UK schools in Scholars’ Education Trust

What Are Disassociation Attacks?

What does the Optus data breach mean for you and how can you protect yourself? A step-by-step guide

When Ransomware Meets IoT: What’s Next?

Why 2FA is failing and what should be done about it

Workers in these countries are the best prepared for phishing attacks

Ransomware Operator Claims - Week 38 2022

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 19th September and 25th September 2022, kindly provided by our partners.

Flag Icons created by Freepik and provided by Flaticon.

Monday, 19 September 2022

American Airlines: Texas Airline Suffers Email Data Breach Exposing Customers' And Employees' Personal Information

Rockstar: US Video Games Publisher's Cyber Attack Results In "GTA6" Development Gameplay Videos And Source Code Leaked Online

Data Breaches Digest - Week 38 2022

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 19th September and 25th September 2022.


25th September

3-2-1-1-0 rule to stay ahead of ransomware

Attackers impersonate CircleCI platform to compromise GitHub accounts

Australia: Cyber-attack on wireless firm exposes data belonging to 40% of this country's population

Australia: Federal government to unveil new security measures following massive Optus data breach

“BlackCat” attempts to up the pressure on Suffolk County; starts to leak data?

Covid antigen test results of 1.7m Indian and foreign nationals leaked online

GTA 6 and Uber hacker reportedly caught by London police

GTA 6 hack: UK police confirm they’ve charged teenager linked with breach

How Malware Hides in Images and What You Can Do About It

Metador: A New Hacking Group Hiding in Telecoms and ISPs For Months

New hacking group ‘Metador’ lurking in ISP networks for months

Noberus ransomware gets info-stealing upgrades, targets Veeam backup software

Optus data breach: Cybersecurity reforms expected to enable companies to rapidly inform financial institutions

Optus data breach: Hacker demands $1.5 million ransom, customer info leaked on dark web

Optus faces a customer exodus, calls for compensation amid anger over leaked data

Optus Under $1 Million Extortion Threat in Data Breach

Personal details of stars including Sir David Attenborough & Sarah Ferguson leaked after Russian cons hack organic shop

Ransomware data theft tool may show a shift in extortion tactics

The UK government has tightened its cybersecurity rules, your business should too

Tips for How to Avoid Identity Theft at Casinos

UK Police nab alleged 'GTA VI' footage leaker

Warning over scam Ofgem emails claiming to offer energy bill rebate

What is SIM Swapping and the best tips to avoid falling for this scam

24th September

15 Year Old Python Bug Let Hacker Execute Code in Code 350k Python Projects

American Airlines learned they were breached from phishing targets

Australia's Optus contacts customers caught in cyber attack

Criminals are using QR codes to target victims - how to avoid 'most insidious' scam

FBI Busts Russian-Linked Cybercrime Group Behind Colonial Pipeline Attack

Hackers Actively Exploiting New Sophos Firewall RCE Vulnerability

Israel Bolsters Digital Defense Amid Iran Cyber Threat

Landbank warns of phishing scam via Google Ads search

London Police Arrested 17-Year-Old Hacker Suspected of Uber and GTA 6 Breaches

Microsoft SQL servers hacked in TargetCompany ransomware attacks

Multi-Factor Authentication Fatigue Key Factor in Uber Breach

OneTouchPoint data breach investigation: Who’s affected?

Optus confirms customer data breach, says passport data may be affected

Optus hacking reminds us of digital danger

Optus issues data scam alert to customers

Personal data of celebrities including Jeremy Clarkson, the Duchess of York, and Sir David Attenborough is leaked on the dark web after Russian ransomware attack on luxury organic farm shop

Ransomware attacks on healthcare organizations have devastating results for providers & patients

Some Questions answered by the GTA 6 Leaks and others left hanging

Take-Two confirms cyber attack on 2K Games

TAP cyberattack: Portuguese president's personal data stolen

UK Teen Arrested Amid Uber and GTA 6 Hacking Saga

Watch out for this clever LinkedIn phishing attack

What is a cyber insurance policy? Should you buy one?

23rd September

9 Ways IT Can Do Proactive Cybersecurity

84% of U.S. citizens have experienced social engineering attacks

Accused Russian RSOCKS Botmaster Arrested, Requests Extradition to U.S.

Alleged Teenage ‘TeaPot’ Uber Hacker Arrested In England

Android Banking Users Targeted With Fake Rewards Phishing Scam

APT41 spear-phishing, supply chain campaigns target pharma, healthcare

As Cyberattacks Intensify, Orgs Don’t Report Incidents

Birth of Ransomware

Bjorka, the Online Hacker Trying To Take Down the Indonesian Government

British Columbia regional government acknowledges cyber attack

British police arrest teenager over “Grand Theft Auto” hack

Canada joins condemnation of Iran’s cyber attack on Albania

CISA Warns of Hackers Exploiting Recent Zoho ManageEngine Vulnerability

Colonial Pipeline ransomware group using new tactics to become more dangerous

Critical ManageEngine RCE flaw is being exploited (CVE-2022-35405)

Crypto Scams of the Week: Theta Network Scams & MetaMask Phishing

Cyber attack secrecy must end

Cyber Mercenary Group Void Balaur Continues Hack-For-Hire Campaigns

Data breach leaves Optus customers vulnerable

Data of millions of users exposed in Australia’s 2nd-largest telecom firm breach

Details of Over 300,000 Russian Reservists Leaked, Anonymous Claims

Fake Indian Banking Rewards Apps Targeting Android Users with Info-stealing Malware

From phishing emails to call centres and beyond...

Google’s Mandiant finds evidence of Russia coordinating with hackers

GTA 6 Hacker Possibly Arrested In London

Hackers Deploy Malicious OAuth Apps to Compromise Email Servers, Spread Spam

Hackers Using Fake CircleCI Notifications to Hack GitHub Accounts

Hackers Using Malicious OAuth Apps to Take Over Email Servers

How does identity crime affect victims?

How Technology Can Mitigate Cybersecurity Risks To Infrastructure

How to find out if you will get anything from T-Mobile’s $350 million data breach settlement

How To Protect Your Startup Against Cyber Attacks?

How to secure your hybrid workforce

Humana Announces Reports Third-Party Data Breach Involving Data Security Incident at Choice Health

Landbank warns clients, public vs. phishing scam using Google Ads

Legacy technology undermines ransomware response

LinkedIn Smart Links are being used to send users to phishing sites

Malicious OAuth applications used to control Exchange tenants in sweepstakes scam

Microsoft Issues Out-of-Band Patch for Flaw Allowing Lateral Movement, Ransomware Attacks

MIT Report Validates Impact Of Deep Learning For Cybersecurity

Mitigating the cybersecurity crisis for the school year ahead

Multi-million dollar credit card fraud operation uncovered

New ransomware variants, tactics rattle financial industry

New security vulnerability in Oracle Cloud Infrastructure discovered

New Spam Attack Abusing OAuth Apps to Target Microsoft Exchange Servers

Nigerian Communications Commission (NCC) advises users on Zoom’s data breach

No agency '100 per cent safe' from cybercrime, Australian Competition & Consumer Commission (ACCC) warns after Optus hack

npm packages used by crypto exchanges compromised

NSA and CISA: Here's how hackers are going after critical systems, and what you need to do about it

NSA Reveals "Hackers' Playbook" for Operational Technology (OT) Attacks

Optus cyber-attack: how do you know if your identity has been stolen and what will happen to your data?

Optus Cyber-attack - What You Need to Know

Optus cyber-attack could involve customers dating back to 2017

Optus cyber-attack leaves customers feeling ‘powerless’ over risk of identity theft

Oxfordshire teen arrested in police hacking investigation

Payday lender Cash Express reports data breach affecting 100,000 customers

Phishing Campaign Targets GitHub Accounts: Cybercriminals are Impersonating CircleCI

Phishing For A Victim; Avoid Falling Prey To Scams

Phishing scams steal private information from unsuspecting students

Portsmouth Guildhall website crashed by 'malicious' cyber attack as Mickey Flanagan tickets go on sale

Researchers Uncover New Metador APT Targeting Telcos, ISPs, and Universities

Risk management focus shifts from external to internal exposure

Scam warning to Revolut customers after cyber attack

Scammers stole tens of millions since 2019 using online credit card scheme

Seven-Year Mobile Surveillance Campaign Targets Uyghurs

So you think cross-site scripting isn’t a big deal?

Sophos warns of new firewall RCE bug exploited in attacks

Successor to ransomware used in Colonial Pipeline attack observed using new tools

The Top Questions Every Agribusiness Should Be Asking About Cyberattacks

The value of an adversary-focused approach to cybersecurity

This 17-year-old hacker arrested in the UK may have been behind Grand Theft Auto VI leaks

U-Haul class action accuses company of neglect that led to data breach

Uber hack challenges popular login security practices

Uber investigates huge data breach

UK Police arrests teen believed to be behind Uber, Rockstar hacks

Ukraine: The SBU neutralized a hacker group that “hacked” almost 30 million accounts of Ukrainian and EU citizens

Ukraine dismantles hacker gang that stole 30 million accounts

Void Balaur Hackers-for-Hire Targeting Russian Businesses and Politics Entities

Warning: Watch out for fake texts offering you help with your energy bills - it's a scam

What Cyberattacks Do Businesses Commonly Face?

What is Data Privacy & What Can You Do About It?

Why Are Small Businesses Suffering for Steep Cyber Insurance Premiums?

Why MFA matters: These attackers cracked admin accounts then used Exchange to send spam

Wintermute Asks Hacker To Return Stolen Funds — Or Face Legal Action

22nd September

15-Year-Old Unpatched Python Vulnerability Potentially Affects Over 350,000 Projects

350,000 open source projects at risk from Python vulnerability

Account takeover attacks on the rise, impacting almost 25% of people in the US

ALPHV/BlackCat ransomware family becoming more dangerous

Are QR Codes a Great Invention or a Cybersecurity Threat?

Australia phones cyber-attack exposes personal data

Authorized Push Payments Surge to 75% of Banking Fraud

Bayern rewards hacker for exposing club website flaws

BlackCat ransomware’s data exfiltration tool gets an upgrade

CircleCI, GitHub Users Targeted in Phishing Campaign

CISA warns of critical ManageEngine RCE bug used in attacks

Colonial Pipeline hackers add startling new capabilities to ransomware operation

Criminals are using QR codes to scam people in restaurants with 'QR phishing' on the rise

Critical Magento vulnerability targeted in new surge of attacks

Customers’ personal data stolen as Optus suffers massive cyber-attack

Cyber-attack cost Safestyle UK £4m and underlying profit

Cybersecurity expert raises alarm over increasing data leaks in Malaysia

Data Stolen: TAP Air Portugal Suffers Cyberattack

Denver Suburb Says ‘No Deal’ to $5M Ransomware Demands

Developer Leaks LockBit 3.0 Ransomware-Builder Code

Email blunder sees school send details of vulnerable children to all pupils

Fake Banking Rewards Apps Install Info-stealing RAT on Android Phones

Financial firms increasingly held hostage by advanced ransomware attacks

Google Chrome users looking to download pirated software at risk of new malware infection

Grant County email hit by phishing attack

Hackers stealing GitHub accounts using fake CircleCI notifications

Hackers Targeting Unpatched Atlassian Confluence Servers to Deploy Crypto Miners

HC3 Alerts Healthcare Sector of Monkeypox-Themed Phishing Scheme

How to have fun negotiating with a ransomware gang

How to Prevent Ransomware as a Service (RaaS) Attacks

Iranian Hackers Hid in Albanian Networks for Over a Year

IT Security Takeaways from the Wiseasy Hack

Laws questioned after Optus cyber attack

LinkedIn’s Smart Links abused in phishing attack targeting Slovakian users

Lithuanian Watchdog Launches Probe Into Revolut Data Breach

Los Angeles school district receives ransom demand from Labor Day weekend cyberattacker

Los Angeles school official says hackers targeted district in ransomware attack

Malicious NPM Package Caught Mimicking Material Tailwind CSS Package

Microsoft Exchange servers hacked via OAuth apps for phishing

Morgan Stanley Fined $35m By SEC For Data Security Lapse

National Security Agency (NSA) shares guidance to help secure OT/ICS critical infrastructure

Nelnet loan service data breach: What you should know

Netflix-style Ransomware Makes Your Organisation’s Data The Prize In A Dark Subscription Economy

New Report Highlights Surprising Ransomware Trends

Nigerian Authorities Raid Cybercrime Training Centers

OpIran – Anonymous Hits Iranian State Sites, Hacks Over 300 CCTV Cameras

Optus attack exposes customer information

Optus customer data hit in cyber attack

Optus data breach: who is affected, what has been taken and what should you do?

Optus Hit By Cyber-Attack, Breach Affects Nearly 10 Million Customers

Optus says it has been hit by a cyber attack that has compromised customer information

Optus warns cyberattack may have exposed Australian client details

Optus, Australia’s second largest telco, says customer data exposed in data breach

Preventing the Recruitment of Insider Threat Actors

Python tarfile vulnerability affects 350,000 open-source projects (CVE-2007-4559)

Ransomware operators might be dropping file encryption in favor of corrupting files

Researchers Disclose Critical Vulnerability in Oracle Cloud Infrastructure

Researchers Uncover Years-Long Mobile Spyware Campaign Targeting Uyghurs

Revolut data breach exposes data of 50K+ clients

Russia-Based Hackers FIN11 Impersonate Zoom to Conduct Phishing Campaigns

SMBs vs. large enterprises: Not all compromises are created equal

TAP Air Portugal hit by cyber attack, passenger data stolen

The fake phishing websites stealing your Crypto

The tools and strategies schools need for ransomware defense

Threat actors have their insider threats, too

Three Iranian Nationals Charged in Critical Services Scheme

Twitter Password Reset Bug Exposed User Accounts

Uber hack reveals key security lapses; here’s how firms can avoid them

Up to 9 million Aussies affected in major Optus data breach

US Agency Broke Into China’s Telecom Networks, State Media Says

US' NSA infiltrates China's telecom infrastructure in attack on leading Chinese aviation university

Waterloo Region District School Board (WRDSB) lawyer clarifies police timeline in cyber attack

Westchester EMS Provider Hacked in One of the Largest U.S. Healthcare Ransomware Attacks of 2022

What could be the cause of growing API security incidents?

What Happens if the Rockstar Hacker Leaks the Grand Theft Auto 6 (GTA6) Source Code

What you need to know about Evil-Colon attacks

What’s the worst that could happen in a data breach? Lessons from the Okta data breach

21st September

2K Games Discloses Startling Security Breach, Tells Players Not To Open Support Emails

2K Games Support Desk Hacked, Phishing Emails Sent To Certain Players

2K Warns Customers Of Security Breach And Phishing Scam

2K warns of cyber attack of its customer support

20/20 visibility is paramount to network security

350K Open-Source Projects At Risk of Supply Chain Vulnerability

Aliens Closer to Home Than Desired – Malware Discovered in James Webb Telescope Images

American Airlines confirms data breach exposing some customers’ data

American Airlines Says Data Breach Affected Some Customers, Employees

American Airlines suffers data breach

‘Anonymous’ hackers knock Iran state websites offline amid nationwide protests

AttachMe - Oracle Patches “Severe” Vulnerability in its Cloud Infrastructure

Behind the priorities of tech and cybersecurity leaders

Berry, Dunn, McNeil & Parker, LLC Reports Data Breach Following Compromised Employee Email Account

Best practices to bolster software supply chain security

Biometric authentication use in US businesses tripled over 3 years to tackle cyber threats

ChromeLoader, what took you so long? Malvertising irritant now slings ransomware

Companies Without Zero Trust Could Lose $1M More During a Data Breach

‘Convincing’ Phishing Campaign Impersonates Government Agencies

Critical Remote Hack Flaws Found in Dataprobe's Power Distribution Units

Crypto Market Maker Wintermute Hacked, $160 Million Stolen

Crypto Trading Firm Wintermute Loses $160 Million in Hacking Incident

Domain shadowing becoming more popular among cybercriminals

Elden Ring publisher Bandai Namco admits "possibility" customer details exposed in July hack

FBI: Iranian hackers lurked in Albania’s government network for 14 months

Former Uber security chief details hunt for hackers behind 2016 data breach

Grand Theft Auto (GTA) Publisher Take-Two's Awful Week Gets Worse With Another Disastrous Hack

Great Cyber Hygiene Starts with a Culture of Security Awareness

Hackers using monkeypox phishing scheme to target healthcare organizations, HHS warns

How DKIM records reduce email spoofing, phishing and spam

Intercontinental Hotels Group class action claims hotel giant let hackers access company network

Iowa Eye Clinic Adds 543K to Eye Care Leaders Data Breach Tally

Iran’s central bank target of cyber attack amid nationwide protests

Iranian State Actors Conduct Cyber Operations Against the Government of Albania

LinkedIn Smart Links abused in evasive email phishing attacks

LockBit ransomware builder leaked online by “angry developer”

Los Angeles Unified School District (LAUSD) receives unspecified ransom demand over cyber attack

Michigan School District Cancels Classes After Cyber Attack

Microsoft Learns a Lesson From Cybercrime Sting

Microsoft office 365 phishing campaign impersonates U.S. agencies

Morgan Stanley to pay $35M after hard drives with 15M customers’ personal data turn up in auction

Multiple Vulnerabilities Discovered in Dataprobe's iBoot-PDUs

National Cyber Security Centre (NCSC): British Retailers Need to Move Beyond Passwords

National Cyber Security Centre (NCSC) publishes cyber guidance for retailers

New York Racing Association confirms hack by Hive ransomware group

New York Racing Association Reports Data Breach Following Hive Ransomware Attack

Ninety Percent of Organizations Struggle with Ransomware

Okta: Credential stuffing accounts for 34% of all login attempts

Open Source Repository Attacks Soar 700% in Three Years

Optus security breach compromises customers' passport details

Over 39,000 Unauthenticated Redis Instances Found Exposed on the Internet

Pay-per-install services provide access to thousands of compromised computers

Protecting Healthcare Organizations from Ransomware Attacks

Ransomware: The Latest Chapter

Ransomware Groups Turn to Intermittent Encryption to Speed Attack Times

Ransomware is (slightly) on the decline, cyber insurance company claims

Record DDoS Attack with 25.3 Billion Requests Abused HTTP/2 Multiplexing

Revolut data breach exposes information for more than 50,000 customers

Revolut falls victim to “highly targeted” cyber-attack

Scammers using QR codes to target people with restaurant menus among ways to be caught by them

SEC fines Morgan Stanley Smith Barney $35 million over failure to secure customer data

Security lessons to learn after the Uber data breach

Social media account takeovers increased over 1000% in 2021

South Redford Schools closed again after cyber attack

Southwell confirms cybersecurity incident after report claims it negotiated with ransomware group

Stolen single sign-on credentials for major firms available for sale on dark web

Suffolk County services crippled by cyber attack

Suffolk County Will Notify Anyone Whose Data Was Compromised In Cyber Attack

Survey Reveals the Severity of Cloud Security Challenge

T-Mobile data breach $350M class action settlement

Take-Two says hacker accessed 2K Games' help desk

Technical Analysis of Crytox Ransomware

The cybersecurity lifecycle: how to put security first at every step

The Multi-Cloud is The New Normal, But Creates Key Security Challenges

The rise of ‘PhaaS’ - and a roadmap to mitigate ‘Phishing-as-a-Service’

Third-party risk: What it is and how CISOs can address it

Two-Fifths of US Consumers Suffer Personal Data Theft

U-Haul Data Breach Exposed Sensitive Customer Data of More Than 2 Million Clients Over 5 Months

Uber links cyber attack to LAPSUS$, says sensitive user data remains protected

Unpatched 15-year old Python bug allows code execution in 350k projects

Untrained Employees Pose Major Risk to Organizations Due to Uncertainty of Security Reporting

Video Game Publisher Admits Helpdesk Was Hijacked

What is a phishing text message?

What Is Cryptojacking? How It Works and How to Protect Against It

What Is Ransomware? A Guide to Ransomware Prevention and Removal

Whether You’re A Startup Or Large Enterprise, Know How To Defend Your Data

Who Attacked Montenegro? The Moral And Strategic Hazards of Misassigning Blame

Why humans are the top gateway to cyber compromise

Why Manufacturing Struggles With Cloud Security

Why You Should Level Up The Security Of Your Business-Critical Systems

20th September

2K game support hacked to email RedLine info-stealing malware

2K Games says hacked help desk targeted players with malware

2K warns of phishing scam

A Ransomware Defense Is Not Enough: Organizations Also Need a Recovery Strategy

American Airlines Breach Exposes Customer and Staff Information

American Airlines hit by data breach

American Airlines says data breach affected some customers, employees

Canada: Police now investigating school board cyber attack

Cash Express, LLC Files Notice of Data Breach Following Unauthorized Access to the Company’s IT Network

City Furniture, Inc. Files Notice of Data Breach

Critical Vulnerability in Oracle Cloud Infrastructure Allowed Unauthorized Access

Cyber Threat Detection: The First Layer of Defence in Depth

Digital Bank Revolut's Data Breach May Have Affected 50,000 Customers

Europol and Bitdefender Jointly Release LockerGoga Decryptor

Game developer 2K’s support site hacked to push malware via fake tickets

Grand Theft Auto Publisher Rockstar Games Hacked

Grand Theft Auto VI footage leaked by hacker

Hackers Admit Destroying InterContinental Hotels Group's Data 'For Fun'

Hackers steal $162 million from Wintermute crypto market maker

Healthcare Ransomware Attacks are Increasing: How to Prepare

HHS alerts health sector to monkeypox-themed phishing campaign

Hive ransomware claims attack on New York Racing Association

How To: Defend the Legal Sector from Insider Threats

How to Detect a Cyber Attack

How to Dodge New Ransomware Tactics

Imperva mitigated long-lasting, 25.3 billion request DDoS attack

Indonesia finally passes personal data protection law

Kiwi Farms Website Hacked! Admin Warns of Data Leak

Latest Uber Data Breach Caused by Hacker Tricking Worker

MFA Fatigue: Hackers’ new favorite tactic in high-profile breaches

Open-source software usage slowing down for fear of vulnerabilities, exposures, or risks

Organizations Lack Visibility Into Cloud Access

Phishing attacks targeting US government have evolved in sophistication, Confense reports

Ransomware as a Service: A new wrinkle on an old threat

Ransomware attacks have nearly doubled since 2020, according to GetApp

Ransomware is growing despite company investments

Ransomware is (slightly) on the decline, cyberinsurance company says

Revolut Breach May Have Hit 50,000+ Customers

Revolut data breach: 50,000+ users affected

Ripple effects of ransomware attack against Suffolk County continue more than a week later

Russian Sandworm Hackers Impersonate Ukrainian Telecoms to Distribute Malware

Social Engineering: How A Teen Hacker Allegedly Managed To Breach Both Uber And Rockstar Games

SpyCloud Report: Despite Increased Spend on Ransomware Mitigation, 90% of Companies Affected in the Last Year

Survey Shows CISOs Losing Confidence in Ability to Stop Ransomware Attacks

Take cybersecurity out to where employees and data are coming together

The Types of Phishing Attacks and How to Dodge All of Them

Third-Party Risk in the Cloud

This Microsoft 365 phishing campaign is using some crafty US government lures

Thousands of customers affected in Revolut data breach

Uber Blames Lapsus$ for Breach

Uber Blames LAPSUS$ Hacking Group for Recent Security Breach

Uber exposes Lapsus$ extortion group for security breach

Uber pins security breach on Lapsus$ ransomware group

Uber says Lapsus$ gang is behind the recent breach

Uber Says Lapsus$-Linked Hacker Responsible for Breach

While Hackers Eye Small Businesses, Ransomware Attacks Decline

Why More Users Mean More Problems With Ransomware Attacks

Wide-Ranging Philippines Phishing Scams Are Sending Out Millions of Messages, SIM Card Registration Bill Proposed as a Solution

19th September

Akamai APJ Ransomware Report H1 2022 - Summary

American Airlines discloses data breach after employee email compromise

Been hit by LockerGoga ransomware? A free fix is now out

Bosnia and Herzegovina investigating alleged ransomware attack on parliament

ChromeLoader can overload systems with malware and lead to ransomware attack

Cisco admits that the Yanluowang ransomware gang stole data from its network

Countering the Future Growth of Ransomware

Critical Infrastructure Takes Center Stage

Crypto giveaway scams continue to escalate

Emotet Botnet Started Distributing Quantum and BlackCat Ransomware

Empress EMS Announces Data Breach Leaking the Sensitive Information of 318,558 People

Europol and Bitdefender Release Free Decryptor for LockerGoga Ransomware

Google, Meta FINED about US$72 million in South Korea for data breach

Grand Theft Auto 6 Hacker May Be Trying To Make A Deal With Rockstar

Grand Theft Auto (GTA) 6 in-development footage leaked, hack still unconfirmed

Grand Theft Auto VI footage leaked after hack, developer Rockstar confirms

GTA 6 leaked: Hacker leaks over 90 gameplay videos showcasing alleged build

Hackers targets gamers in South Africa, Kenya

High severity vulnerabilities found in Harbor open-source artifact registry

How to Know if You’ve Been Caught up in a Data Breach, and What You Can Do About It

How to protect your organization’s single sign-on credentials from compromise

Hunt on for hacker who leaked over one billion Indonesians’ data

Indonesia hunts for Bjorka, hacker selling 1.3 billion SIM card users’ data, taunting officials

It’s 2022 – Are Passwords Still Important?

LastPass publishes details of the cyber attack it received

LastPass Says No User Data Compromised in Cyberattack

Microsoft 365 phishing attacks impersonate U.S. government agencies

Microsoft Teams' GIFShell Attack: What Is It and How You Can Protect Yourself from It

Microsoft Warns of Large-Scale Click Fraud Campaign Targeting Gamers

Most critical security gaps in the public cloud

No More Ransom Offers Free Decryptor to LockerGoga Ransomware Victims

Pacific Asia Travel Association (PATA) cautions on mailing list scam

Prevention remains best strategy when dealing with cyber risks

Revolut Bank reveals that it has suffered a data breach on its data security

Revolut hack exposes data of 50,000 users, fuels new phishing wave

Rockstar Games Confirms Hacker Stole Early Grand Theft Auto VI Footage

Russian Sandworm hackers pose as Ukrainian telcos to drop malware

SaaS Security Issues Driven by Sprawl, Lack of Visibility

Some residents' personal information possibly compromised in Quincy cyberattack

Starbucks Singapore involved in data breach

The benefits of digital trust

The Security Awareness Of People Is The Important Firewall In IT

Trend Micro warns of attack surge, targets more sectors

Uber blames security breach on Lapsus$, says it bought credentials on the dark web

Uber Hacker Claims To Have Hacked Rockstar Games, Releases GTA 6 Videos

Uber Hacker Targets Rockstar Games, Leaks Trove of GTA 6 Data

Uber ‘in contact with the FBI’ over potential GTA 6 hacker

Uber links breach to Lapsus$ group, blames contractor for hack

Uber says compromised credentials of a contractor led to data breach

VMware, Microsoft warn of widespread Chromeloader malware attacks

What do SOC analysts need to be successful?

Ransomware Operator Claims - Week 37 2022

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 12th September and 18th September 2022, kindly provided by our partners.

Flag Icons created by Freepik and provided by Flaticon.