Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label data security. Show all posts

ICE Can Now Buy Your Credit Card Information

Every time you apply for a credit card or update your account details, you may be sharing your data with ICE.

A research by 404 Media said that personal information stored by credit card firms can sail through a network of data brokers and can become accessible to US Immigration and Customs Enforcement (ICE). ICE can then search and investigate your personal data without any warrant. 

“No one signing up for a credit card thinks they’re giving data brokers a thumbs-up to sell their personal information to ICE. Not only is it an outrageous violation of our privacy, [but] it’s impossible for Americans to opt out,” Senator Ron Wyden said to 404 Media in a statement. 

What private information is compromised?

According to 404 media, when someone opens a credit card or updates their personal data, credit card firms share that data with credit bureaus. 

The personal information consists of Social Security numbers, addresses and email addresses, names, and phone numbers. Contrary to credit reports, this data does not have robust legal security. 

Personal information is then sent to credit bureaus, who give the data to Thompson Reuters. From there, the data is incorporated into CLEAR, the firm’s investigative data product. Thomson Reuters sells access to CLEAR to law enforcement authorities, including ICE.

After gaining access to CLEAR, ICE can search through personal information without a warrant. "404 Media has mapped out this supply of data by reviewing U.S. government procurement records and internal documents from companies providing the information." The platform is also combined with a tool that suggests ICE to decide which neighbourhoods to raid. 

"Anytime we update our home addresses on these accounts, credit bureaus get the updates within 24 hours and share it broadly with other data brokers, thanks to legal loopholes that leave our personal information open to misuse and abuse," Just Futures attorney Laura Rivera said to 404 Media.

Thomson Reuters providing personal data to US government

Another report enquired Thompson Reuter’s increasing role in providing personal data to the US Government.

The Department of Homeland Security (DHS) is planning to pay Thomson Reuters $125 million to give access to its databases as part of enquiries into suspected immigration fraud and voter fraud. The agreement will be worth $25 million annually for five years respectively.

GrapheneOS Duress Feature Puts Digital Privacy and Evidence Laws to the Test

 

A federal case concerning a local Atlanta activist is fueling controversy over privacy issues relating to cell phone searches and whether simply wiping data from a device qualifies as destroying evidence. The case involves GrapheneOS, an open-source privacy-focused customized Android OS that utilizes the so-called duress PIN/password to permanently delete data from a phone if the correct code is entered by investigators. 

GrapheneOS developers describe their creation’s features on the project’s website, noting that it includes a “duress PIN/password” that causes the phone to immediately wipe all user data and any eSIMs from the device when the “wrong” passcode is entered at the time of credential prompt. According to court records, and reports by the press, in January 2025, Samuel Tunick, an Atlanta-based activist, was taken into custody by the US Customs and Border Protection (CBP) agents at the airport in Atlanta upon his return from the Dominican Republic. 

It seems Tunick was questioned by the customs officials several times and eventually gave them a password to his phone. His phone was wiped immediately after he entered the code. Samuel now faces charges brought by federal prosecutors who alleged that he “conspired to destroy property of the United States.” The defense is arguing that the search was not lawful; the activist was not informed of his constitutional rights and was not allowed to contact a lawyer. 

Additionally, Samuel’s attorney points out that Tunick was accused of possessing child sexual abuse material, and the only reason why he was searched was because of his activism surrounding the Stop Cop City movement. It is worth noting that privacy and security specialists have raised concerns regarding the matter and regard it as an important precedent. The GrapheneOS Foundation, an entity that maintains the software, has stated that it believed that its customized Android OS features “security capabilities that are appropriate and legitimate.” 

Some experts suggest that even if Tunick did wipe his phone, there is no way investigators could prove that he did not do so because of his decision to employ GrapheneOS. The case creates grounds for debate about the potential for cell phone software to create challenges for law enforcement. In particular, the case’s outcome will set a legal precedent about whether a device owner’s intentional interference with a search (by wiping data) constitutes evidence tampering. 

GrapheneOS itself is a valid privacy-centric OS, but the case concerning the Atlanta activist will shape the jurisprudence surrounding the wiping of cell phone data by users and the extent to which such action may be regarded as obstructing law enforcement.

Canadian Hacker Pleads Guilty for Stealing Data and Extortion


A Canadian man recently pleaded guilty in a U.S. federal court in planning one of the largest data theft campaigns in recent times, to his involvement in retrieving organization accounts at cloud storage provider company Snowflake. He stole data from 165 companies in an attempt to extort millions of dollars from the targets. 

Connor Riley Moucka is 26-yr old, and also worked under aliases Waifu and Alexander Moucka, was arrested on October 30, 2024, for stealing information from millions of people from organizations that used Snowlake’s storage features. Moucka admitted to four charges: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count, out of an original 11-count indictment.

How did the attacks happen?

Between February and October 2024, Moucka and his partner John Erin Binns, also arrested for these attacks, accessed Snowflake accounts. Rather than exploiting a flaw in Snowflake's platform itself, the pair relied on credentials harvested through infostealer malware to log into customer accounts. They stole accounts that were not secured by multi-factor authentication (MFA) via login credentials through an infostealer malware.

Without MFA protection, the hackers only needed the right usernames and passwords to sign into customer accounts. After gaining access, the hackers only needed custom-built software to sail through cloud storage incidents for important information.

The illegal access was used for identifying important information such as user roles, IP addresses, and organization name in cloud storage incidents that used Snowflake services.

The accused tried to blackmail various firms after stealing TBs of data from their Snowflake user accounts and got around $2.5 million in bitcoin from three targets.

Scale of the campaign

According to the prosecutors, the campaign exploited data linked to over 100 million individuals and resulted in $9.5 million losses for organizations. The list of impacted companies include: Ticketmaster, Santander, AT&T, Advance Auto Parts, Los Angeles Unified School District, Pure Storage, QuoteWizard/LendingTree, and Neiman Marcus.

Moucka allegedly stole around $495,000 from ransom payments. AT&T paid around $370,000 to avoid future leaks of text records and customer calls. 

“In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data,” the US Department of Justice said in a press release. 

“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.” 

Greatness PhaaS Uses Phishing Code to Escape 2FA and Attacks Microsoft 365 Users


The commercial phishing-as-a-service (PhaaS) toolkit called Greatness, distributed via Telegram that uses token theft with device code and adversary-in-the-middle (AiTM) credential phishing in single operator products, has become a latest crimeware tool for the threat actors. 

About the campaign

Experts found a live campaign that abused spoofed customer-side safe sender exclusions and RingCentral emails to escape email gateway checks and send phishing traps attacking Microsoft 365 accounts. 

"Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBec, who discovered the campaign, said in a report. 

"The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems."

The phishing platform was first found by Cisco Talos in May 2023, showing how hackers are including it in their campaigns to attack Microsoft 365 business users since May 2022.

About the subscription

Built to ease cybercrime, access to Greatness is given through a subscription available on Telegram channel called @GreatnessPage having over 3,250 subscribers and works as a central hub for feature updates and announcements. Hackers can get a subscription at $289 per month, rising from $120 per month from January 2024. The subscription offers access to an operator that consists of a dashboard with CAPTCHA selection, domain configuration, campaign statistics, and more than 11 downloadable trap templates including QR codes, voicemail, and document sharing. 

How is Telegram used?

The operators of Telegram channel in November 2025 said that Greatness keeps stolen cookies secure through one-way hash protection and the information can be taken out only by the customers via their Telegram account two factor authentication code.

Threat actors that buy a subscription by giving their bot API token and Telegram chat ID can use the panel via an “O365 Panel” login page that needs a 9-character license key and a user ID. Once registered, customers are shown a dashboard and an operator-particular domain.

The dashboard is a standard place that provides campaign statistics such as heat map of victims and captured cookies. "Observed templates include: AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, and additional variants. "Each template contains pre-built HTML, PDF redirectors, SVGs, and letter templates, lowering the barrier to entry so operators do not need to build lures from scratch." 

RansomHouse Claims Responsibility for Cyberattack Disrupting Nichirei Operations in Japan

 

Japanese frozen-food and logistics company Nichirei is currently dealing with an unknown cyberattack that caused the disruption of the firm’s nationwide operations after ransomware group RansomHouse claimed responsibility for the breach. The ransomware group’s attack impacted refrigerated warehouses, frozen food deliveries, and other related logistic chains that supply Japan’s restaurants, supermarkets, and school lunch programs. 

According to cybersecurity researchers, RansomHouse published a statement on the dark web claiming that it stole internal data from the targeted company during the ransomware attack. The message was confirmed by one of Japan’s local cybersecurity companies, S&J, whose President Nobuo Miwa verified the ransomware group’s publication. Meanwhile, Nichirei remains unsure whether the ransomware group’s accusations are real or not. 

The Japanese logistics and food distributor company confirmed that the ransomware attack was ongoing on July 13th. The issue arose when employees could not access the company’s system due to unauthorized intervention. Initially, the firm’s spokesperson reported that the attack was only on the organization’s system; however, the message changed when the company acknowledged that its servers were hit with ransomware. This ransomware attack disrupted the firm’s logistics network, impacting businesses that have Kentucky Fried Chicken Japan and other restaurants and supermarket chains as its suppliers. 

The disruption of the national logistic chain of frozen food and storage caused an unprecedented inconvenience to these businesses as the ransomware attack created a significant challenge to KFC Japan. In particular, Kentucky Fried Chicken Japan stated that its restaurant stores were forced into stockouts, had to limit their food offerings, and temporarily close several of its establishment due to the interruption of its frozen-food deliveries from Nichirei. The company further stated that its logistic network currently operates normally as the freezing warehouses and logistic chains of Nichirei are gradually opening. 

Nichirei announced that its operations started to resume on the morning of July 17th and will completely reopen in the coming week. In general, the ransomware group of RansomHouse is infamous for its attacks on companies in Japan, with the ransomware group being notorious for targeting both local and international corporations. In particular, RansomHouse often steals critical data from the targeted companies by encrypting their software or threatening to publish the information if the ransomware victims do not comply with the ransom demands.  

Therefore, as reported by local Japanese news outlets, the ransomware group of RansomHouse is infamous for its attacks on various logistic chains. Earlier this year, the ransomware group was reported to infiltrate the system of office supply retailer Askul. This occurred in October, disrupting the operation of Askul for a few days. Additionally, RansomHouse is also infamous for publishing customer and business partner information of Askul after targeting the company with ransomware. 

With that, experts suggest that critical supply chains and those managing logistics and other transportation infrastructures are advised to ensure that their network security system is resistant to ransomware. Moreover, these companies should also formulate an efficient data backup procedure and response plan in case of an attack.

Chick-fil-A Warns Customers After Credential Stuffing Attack Compromises User Accounts

 

Chick-fil-A notifies customer about personal information exposure after data breach occurred due to credential stuffing attack Chick-fil-A company has announced that personal and account information about some of its customers may have been exposed due to a data breach. This breach occurred through the use of credential stuffing, which is not a vulnerability within the corporation’s website or mobile application.

As explained in the company note to customers, unauthorized access attempts came from bad actors using credentials stolen elsewhere. The company discovered unauthorized access attempts to customer accounts after noticing anomalous activity in the login database, and the phishing campaign occurred between June 17-19, 2026, targeting Chick-fil-A One loyalty program accounts. The corporation concluded its investigation on July 13 th and established that attackers had used compromised credentials to access the account information of some customers. 

The information available to bad actors and potentially at risk of being misused varies depending on the customer’s account. It may include names, contact information, mailing addresses, phone numbers, dates of birth, and Chick-fil-A One account information like ID or QR code and mobile payment credentials. Moreover, attackers may have gained access to reward balances, gift card balances, and the last four digits of payment cards. Although the corporation has not revealed the number of affected clients, the number exceeds several thousand. 

According to the documents filed with the state, 2,182 Texas residents and 39 Massachusetts residents were impacted by the breach. However, there are also other states affected, as notifications to state attorney generals in charge of consumer protection have also been filed, including the District of Columbia. After discovering the issue, the corporation remediated the security risks and notified the affected clients. 

Moreover, Chick-fil-A took measures to enhance account security for all customers, including allowing password reset, account logout, and removing payment methods in the application. Some customers also received bonus points on their accounts as compensation for the issues experienced. Chick-fil-A corporation acknowledges the concern caused by the data breach and assures clients that it takes customer account security seriously. Moreover, the company has recommended that customers change passwords to strong and unique words or phrases not used for other accounts. 

Credential stuffing works only when the same or similar passwords are used across different accounts, so changing them to unique ones decreases the chances of experiencing another breach. Chick-fil-A data breach demonstrates once more that it is crucial to make sure that each online account, including email, banking, and social media accounts, uses a unique and strong password. 

If one suspects that an account may have been compromised, it should be changed to a strong password immediately. Also, it is essential to use multi-factor authentication when available and to monitor account activity regularly for unauthorized transactions or unauthorized access attempts.

HollowGraph Malware Abuses Microsoft 365 Calendars for Covert Command-and-Control

 

The malware component HollowGraph is using Microsoft 365 mailbox calendars to hide its C2 channels and traffic, enabling the bad actors to communicate with the malware and exfiltrate the data. Group-IB researchers note that HollowGraph is a part of the Cavern command-and-control framework used by the Iranian nation-state actor previously observed targeting Israeli organizations. Researchers note that at least 12 Microsoft 365 mailboxes were compromised using HollowGraph, and three of them established communication with the attackers’ C2 servers between June 3 and July 9. 

Additionally, based on the infrastructure and victims’ location, Group-IB experts suggest that Israel is the likely target of this malware. The HollowGraph malware component is designed to self-register in the Microsoft Graph API using the credentials stolen from the Microsoft 365 mailbox. It stores the configuration data in the logAzure.txt file, which contains the Microsoft Entra ID information, client credentials, mailbox addresses of the victims, domains controlled by the attackers, and keys required to communicate with the C2 infrastructure. 

The attackers have taken measures to ensure that this file is not suspicious; specifically, it is placed in the known location used by Microsoft Entra ID and has the standard log file name. The malware communicates with its C2 server using the Microsoft 365 calendars. Specifically, HollowGraph creates events scheduled on May 13, 2050, and uses their titles and attachments to exchange data with the attackers. There are two types of such events: GET and SEND. The first one is used to retrieve the encrypted commands by extracting the contents of the event’s title. 

In turn, the SEND type of events is used to exfiltrate the stolen data by adding it as an attachment. Researchers note that the mailbox calendars are used as a “dead drop” to store the data; hence, HollowGraph does not use traditional C2 servers to avoid detection. It implements a strong encryption scheme to protect the command and data exfiltration channels and uses a combination of RSA and AES_256_GCM encryption algorithms. The RSA public key is embedded into the calendar event, whereas the HollowGraph malware uses the AES key to encrypt the data. 

Besides the Microsoft Graph API, HollowGraph also uses the Domain Name System (DNS) to communicate with its C2 servers. Specifically, the malware resolves the domains controlled by the attackers to extract the IPv6 AAAA records, which contains the updated Microsoft Entra ID credentials required to maintain persistence on the compromised mailboxes. Similar to the information stored in the logAzure.txt file, these credentials include the Microsoft Entra ID tenant, client ID and secret, and the mailbox information. 

All of these credentials are extracted from the DNS responses and stored in the malware configuration. Group-IB researchers conclude that HollowGraph is a sophisticated backdoor that utilizes various cybersecurity technologies to compromise targeted Microsoft 365 mailboxes and remain undetected for as long as possible. While the technical capabilities of this malware component overlaps with the ones attributed to the Lyceum Iranian nation-state actor, the researchers are not certain about its origin. 

Nevertheless, Group-IB experts note that there is a high likelihood that HollowGraph belongs to the Cavern framework used by Lyceum. To detect and prevent similar attacks, the cybersecurity experts recommend that organizations monitor the Microsoft Graph API activity and Microsoft 365 audit logs for any suspicious activities related to the creation of the calendar events. Specifically, defenders should pay attention to the events created by applications using the Microsoft Graph API scheduled far in the future, with the suspicious subjects and attachments. 

The researchers also recommend that organizations add the cloudlanecdn[.]com domain to their threat intelligence platforms and continuously monitor their Microsoft 365 environments for any unauthorized OAuth client credential applications. In addition, Group-IB experts note that Microsoft Entra ID Conditional Access policies and outbound DNS traffic should be reviewed to detect and block similar恶意 activities, such as DNS tunneling. This report highlights the importance of the growing threat landscape in cloud environments caused by the increasing reliance on the collaborative software in enterprise networks. 

Malware components like HollowGraph demonstrate that the attackers do not limit themselves to traditional network security tools and can use the trusted infrastructure to launch attacks against various organizations. In particular, the attackers utilize the cloud infrastructure as a part of their mitigation strategy. In turn, the defenders should shift their focus from traditional network perimeter security to inspecting individual hosts and applications for detecting malicious activities.

HollowFrame Loader and Matryoshka Malware Used in Spear-Phishing Attack

Experts discovered a recently undocumented Go-based loader framework termed HollowFrame and a Rust-based malware strain called Matryoshka.

Spear-phishing for attacks

Blackpoint Cyber said that the hack starts with a spear-phishing message consisting of a link to an encoded archive, which contains a Windows Shortcut (LNK). Running a file prompts a multi-level strain that consists of privilege escalation, compromising Microsoft Defender protections, while downloading extra payloads.

About Matryoshka

Matryoshka is available in two versions: one that supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery. HollowFrame is launched via a DLL side-loading pair consisting of the legitimate Python binary ("python.exe") and a rogue DLL ("python311.dll").

"Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling. These capabilities could support credential theft, lateral movement, and broader domain compromise through additional tools delivered after initial access,” Blackpoint experts Nevan Beal and Sam Decker said.

Attack tactic

The multi-stage hack attacks two endpoints at an unknown law firm. The LNK file mimicked to be Case Documents to lure the victim into opening and triggering a command sequence that deploys PowerShell to get next-stage components from a remote server.

Hollowframe works as a modular loader and persistent framework that assists multiple tactics to deploy auxiliary components, while performing anti-analysis diagnosis to escape running inside sandboxed environments. This is decided based on installed memory, cursor movement, file count in the user profile, and system uptime. Persistence is gained by setting up a scheduled task.

Matryoshka ("version.dll"), a Rust-based backdoor that talks with its C2 server ("45.158.196[.]184:8888") over HTTP to spawn a shell and provide additional tooling, is deployed by unpacking the encrypted container that the Go loader comes with.

Another DLL gained in association with the same activity has been labeled as a version of Matryoshka that uses a private GitHub repository for polling target-specific commands, submitting results, and fetching payloads.

"The repository functioned as a collection of per-host mailboxes, with each victim assigned a dedicated <computer>_<username> directory. These directories contained beacon.json, cmd.json, result.json, and, in some cases, an upload/ tree for file delivery,” Blackpoint said.  

Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability

 

Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. 

According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident. Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. 

Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees. After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information. 

Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. 

The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. 

It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface. In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security.

Fitness Trackers Can Expose Your Health Data, EFF Warns

 

Fitness trackers have become part of everyday life, helping people monitor steps, sleep, heart rate, stress, and workouts with impressive convenience. But a recent investigation highlighted a serious privacy issue: much of the health data collected by popular wearables is not protected under federal health privacy law, which means it can be exposed through legal requests far more easily than many users realize. 

Among the major brands reviewed, Apple stands out because its health data can be protected with end-to-end encryption, giving users a stronger layer of control over sensitive information. The core concern is that most wearable devices rely on cloud storage, where the company that makes the device often holds the keys to the data. That setup may feel secure because the information is encrypted while being transferred and stored, but it is not the same as true end-to-end encryption. If the company can access the data, then law enforcement may also be able to obtain it through a subpoena. 

For users, that means intimate details such as sleep patterns, location history, menstrual cycles, and heart-rate trends may be accessible outside the privacy protections many people assume apply.  This issue matters because wearable health data is highly revealing. A fitness tracker can create a detailed picture of daily routines, physical condition, and even emotional stress patterns. In legal disputes, such records have already been used to challenge alibis, verify movements, and support claims in civil cases. 

As wearable adoption continues to grow, the volume of personal information collected will only increase, making privacy protections more important than ever. Many consumers buy these products for wellness, but they may not realize they are also generating a persistent data trail. Apple’s approach is different because its Health ecosystem supports end-to-end encryption when properly configured. 

That means the company cannot read the protected health data, and a subpoena would not produce the same level of information that cloud-based systems can reveal. Apple also allows users to limit syncing and keep more data local, which adds another privacy advantage. For users who want the strongest protection, this makes Apple Watch and Apple Health a standout option compared with most other wearable brands. 

Before buying a fitness tracker, consumers should look beyond features like battery life, workout tracking, and smartwatch functions. Privacy policies, transparency reports, local storage options, and encryption standards should matter just as much as design and price. In an era where health data is constantly collected, the best wearable is not only the one that tracks well, but the one that protects personal information responsibly.

Microsoft Warns of Rising ACR Stealer Campaigns Targeting Enterprise Credentials

 

Microsoft has observed an uptick in attacks using the ACR Stealer information-stealing malware family. Attackers distributed the malicious payload targeting enterprise users and compromising browser data, authentication tokens, and sensitive business files between late April and mid-June 2026. 

The malware operators used ClickFix social engineering, WebDAV servers, and Microsoft HTML Application Host utilities to deliver the payload to the target systems. Microsoft notes that ACR Stealer is a malware-as-a-service (MaaS) that likely represents repackaged Amatera Stealer. It is a remote-access tool that steals credentials and sensitive data from the target systems and uses various methods to avoid detection. Microsoft reported that there are two main attack chains that the attackers used to distribute ACR Stealer. 

The first one began with a ClickFix lure诱导 users to run a command that triggered a remote WebDAV server. Specifically, the malicious command used rundll32.exe, a legitimate Windows process, to execute a DLL file located on the remote server. The attackers used WebDAV to host the payload because the file system structure of the server was similar to the standard Windows file system, which helped the malicious traffic to blend in with network traffic. 

After establishing a connection to the command-and-control (C2) server, the attackers delivered an obfuscated PowerShell script that initiated the malware installation process. It downloaded the malware payload as a Python loader, installed scheduled tasks to maintain persistence, and attempted to clear the event logs, PowerShell history, and other tracking mechanisms. The malware also used process injection to execute itself in memory, evading detection by security software. Some ACR Stealer variants used blockchain-based dead-drop resolvers to receive updates or C2 addresses. 

In this technique, the attackers used publicly accessible blockchain addresses to store encryption keys and other data needed to retrieve the payload, also known as EtherHiding. The second attack chain also began with a ClickFix lure but used MSHTA to execute the payload. In this method, the attackers tricked the users into launching a Microsoft HTML Application that delivered an obfuscated PowerShell downloader to the target system. The downloader then retrieved an encrypted payload from a public steganographic JPEG image and executed it in memory. 

In both attack chains, the malware maintained persistence by installing scheduled tasks, encrypting and decrypting browser credentials using Windows Data Protection API (DPAPI), and injecting itself into processes. It also stole browser data, including cookies, tokens, and passwords, by targeting the Chromium database used by Google Chrome and Microsoft Edge browsers. 

Additionally, the malware scanned the target system for PDF files, Microsoft 365 documents, and files stored in the Desktop, Downloads, and other folders and enterprise file-sharing platforms such as OneDrive and SharePoint. Microsoft notes that the observed attacks only represent a subset of the initial ACR Stealer delivery methods. The tech giant added that the malware operators could use various other attack chains to compromise enterprise systems. 

Microsoft advises users never to copy commands from websites that claim to repair errors or confirm their human identity, as attackers often use such websites to deliver malware. It also recommends that organizations limit user access to unnecessary online resources and deny access to domains associated with new and suspicious websites. 

The company also advises organizations to use application control policies to block PowerShell, Python, MSHTA, rundll32.exe, and other utilities from running obfuscated scripts or downloading content from remote or user-controlled sites. Microsoft also published a list of mitigation measures and indicators of compromise (IOCs) that can help organizations detect ACR Stealer attacks.

Ernst & Young Notifies Clients Following Third-Party Support Platform Data Breach

 

The company Ernst & Young (EY) has sent out notices to the affected clients about the data breach involving the third-party support ticket platform, which EY’s employees used, and therefore, potentially exposed documents with sensitive tax details to hackers. EY is one of the world’s largest accounting firms that is known to have faced a cybersecurity incident when the unauthorized party gained access to the third-party support ticket platform used by EY’s IT staff on March 28, 2026, and removed several documents from it, reported on April 23, 2026. 

A company statement noted, after reviewing the activity within its environment with the help of outside cybersecurity experts, that the threat actors accessed the EY environment between March 28, 2026, and April 12, 2026. As per the breach notification letter, the documents removed from the support platform could include personal information or financial information, as well as details provided to EY’s support teams during the process of submitting the tickets or in connection with the preparation of the clients’ tax returns. 

EY acknowledges that tax-related information may have been involved in the data security incident but chose not to identify what specific details were affected, as the breach notification letters also include placeholders for the affected customers’ personal information. The company also declined to indicate how many clients were affected by the breach or whether it was limited to the U.S., as there are other EY entities around the globe. EY announced that after detecting the issue, the company took measures to secure the affected systems by cutting down the unauthorized access, and notified the appropriate federal agencies. 

Furthermore, EY has found no evidence that the information from the breach had been deployed or that any particular individuals were the specific targets. Nevertheless, the firm offered its affected clients with credit monitoring and identity theft protection services for 24 months for free from Experian. The customers whose data was at risk were encouraged to sign up for the monitoring services by October 31, 2026. 

At the moment of the announcement, neither ransomware gangs nor data extortionists have claimed responsibility for the cyberattack, nor did any bad actors leak the data or sell it on the dark web. The attack involving the third-party support ticket platform yet again demonstrated the challenges organizations face regarding their ability to protect clients’ data and ensure that their vendors and partners do the same. 

Experts note that companies should invest in making sure their third-party vendors have reliable security practices in place, monitor their activity on a regular basis, and avoid storing any sensitive data on the platforms that can be accessed by numerous individuals, as in the case of EY’s tickets system, to mitigate the risks of supply chain breaches and data leakage incidents.

UK Biobank Data Breach Rekindles Debate Over Research Data Security

 

A recent case concerning the UK Biobank has once again brought up the topic of securing medical research databases, as well as the importance of keeping research data both accessible and private. Professor of Cancer Medicine at the University of Oxford David Kerr pointed out that while sharing scientific data is important, it is also essential to maintain the trust of the general public and ensure the privacy of those whose data is being used. 

UK Biobank is one of the biggest biomedical research databases in the world, established in the early 2000s. It consists of the medical information of half a million people aged between 40 and 69, who volunteered to participate in the program from 2006 to 2010. The database contains genetic, imaging, metabolic, and clinical data on each of the volunteers, making it extremely useful for research into cancer, heart disease, brain conditions, and many other illnesses. Scientists from various corners of the world can apply to use the anonymized data of the UK Biobank volunteers for research purposes. 

According to Professor Kerr, the data from the database has been used to facilitate over 18,000 scientific publications to date. The information contained in the database is anonymized, meaning that the names and other obvious personal identifiers of the donors are removed. However, their ages and sexes are still available for scientific use. The data is invaluable to scientific research, as it has been found to be instrumental in facilitating major medical breakthroughs. 

However, the controversy involving the UK Biobank occurred when three scientists who had accessed the data were accused of trying to sell a part of the database containing the information on thousands of anonymous donors through Alibaba, an international Chinese online marketplace. It is reported that both the UK and Chinese authorities managed to remove the data from the marketplace before any purchases had been made. 

As a result, the three scientists lost their access to the database, and an investigation is currently underway to determine the full extent of the breach and whether personal information has been compromised. UK Biobank has issued a formal apology, calling the security breach a serious matter and stating that they are currently reviewing their security measures. 

According to Professor Kerr, while the database contains a wealth of information that has led to unprecedented international collaboration and research opportunities, such data has to be protected at all times. He noted that with the growing importance of biomedical research, large-scale health data sets have become targets for similar breaches, which has raised multiple concerns for the general public. 

Therefore, both the UK Biobank and the wider scientific community must continue working on protecting medical data sets while allowing unrestricted international collaboration and research.

Helix Data Extortion Group Targets Microsoft SharePoint Using Vishing and MFA Abuse

 

Cybersecurity researchers have discovered a new data extortion group called Helix that has been targeting companies by using user credentials rather than software vulnerabilities. Helix has been employing voice phishing (vishing), device code phishing, and multi-factor authentication (MFA) abuse to target Microsoft 365 and steal data from the company’s SharePoint service. 

According to the researchers at ReliaQuest, Helix has been attacking the company by first calling an employee and posing as their manager or another executive and tricking them into approving device code authentication and granting access to their Microsoft accounts. In some cases, the attackers used the manager’s name or changed the caller ID to disguise their location as the manager’s office. The attackers then register their own MFA Authenticator application on the victim’s account to ensure continued access to the Microsoft 365 platform even if the user changes their password. 

The intruders then proceed to conduct reconnaissance on the SharePoint servers, enumerating and downloading all the available data, including documents, before the company detects the breach. The data is then used to demand ransom from the victim organization by threatening to publish the information if the company does not pay a certain amount of cryptocurrency. In some instances, the attackers sell the data to other bad-actor groups. 

Researchers have noted that Helix’s automated SharePoint discovery has been one of the group’s most identifiable features. In one of the attacks, the attackers used automated search queries to find the SharePoint content before launching a large-scale data exfiltration campaign from the same IP address using a Python Requests user agent. ReliaQuest researchers suspect that Helix may be linked to the ShinyHunters and BlackFile data extortion groups due to the similarity in attack techniques. 

Although there is no conclusive evidence that the groups are connected, researchers have discovered similar infrastructure and tactics used by Helix and ShinyHunters. Some of the organizations that have fallen victim to Helix include Medtronic, Nissan, the National Association of Insurance Commissioners (NAIC), Kodak, Infinite Campus, and the University of Nottingham. These companies were previously targeted by the ShinyHunters group and confirmed the breach on their websites. 

In addition, ReliaQuest researchers discovered that one of the Helix’s exfiltration servers was hosted on an autonomous system previously used by the BlackFile infrastructure. Since BlackFile’s servers were shut down earlier this year, researchers suspect that Helix may have links to the BlackFile group or be an offshoot of the former group. However, other data extortion groups such as Pink and Redact may also be linked to BlackFile. 

The campaign that targets Microsoft 365 is similar to the ShinyHunters ransomware attack in several ways, including impersonating employees, targeting the Microsoft 365 platform, stealing data from SharePoint servers, and using social engineering to trick employees into giving access to the company’s network. Researchers have also discovered that Helix uses the NICENIC domain registrar, which has been used in some of the ShinyHunters attacks. 

Experts recommend that organizations disable device code authentication if possible and only allow managed devices to access the Microsoft SharePoint service. In addition, the company should monitor Microsoft 365 authentication activities and restrict all communications except those from trusted domains to protect their data from being exfiltrated by Helix or other cybercriminal groups. 

The discovery of the Helix campaign shows how cybercriminals are increasingly targeting user credentials to access sensitive information rather than exploiting software vulnerabilities.

Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned

 

The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for Atomic Energy Jitendra Singh stated that the breach did not affect any sensitive nuclear facility or infrastructure. 

Singh stated during an interaction with reporters on the sidelines of the press conference on July 16 that there was no need for an immediate security review since the breach did not concern nuclear activities or reactors. Nuclear Power Corporation of India Limited (NPCIL), which manages the Kudankulam plant, claimed that the data breach incident did not disclose any sensitive information about reactors. 

“In the given scenario, the data breach is related to the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant (BoP) package for Units 3 and 4 under Implementation Agreement 7 (IA-7),” the NPCIL stated. It added that the EPC contract is signed with Reliance Infrastructure via a public tender process in 2018 for Kudankulam NPP. “The balance of plant involves many elements such as auxiliary systems, services, and infrastructure like cooling towers, which are comparable to those in conventional thermal power stations,” NPCIL noted.

It added that the BoP does not contain any nuclear power plant equipment or components or safety and security features. “In this context, NPCIL is not contemplating any First Information Report (FIR) as the cyber-attack was on the data of Reliance Infrastructure,” an NPCIL spokesperson said. They added that the information shared with Reliance Infrastructure during the tendering procedure included indicative drawings and technical specifications on the common services balance of plant, typically provided to all bidders. “This information did not include any sensitive nuclear safety information,” the spokesperson added. 

NPCIL stated that Reliance Infrastructure develops engineering drawings using the technical specifications and drawings provided by NPCIL in coordination with original equipment manufacturers (OEMs) for the approval process. The breach of data came after Reuters reported that ransomware group World Leaks exfiltrated more than 19,000 files from servers hosting Kudankulam Nuclear Power Plant, covering the 2016 fiscal year through mid-2025. 

According to the report, the documents contain details on control, cooling, and ventilation systems, suppliers, inspections conducted by Indian and Russian personnel, meeting records, and insurance data. The breach was attributed to a server managed by data centre infrastructure provider Yotta, hosted by third-party Reliance Group, which was responsible for the EPC contract for the Kudankulam NPP, admitting that the attack resulted in a partial data breach. 

Tamil Nadu-based Kudankulam Nuclear Power Plant currently operates two 1,000 MW VVER reactors and is set to commission four more reactors under the Russian technical collaboration agreement. The project aims to make Kudankulam one of India’s largest nuclear power parks with a total capacity of 6,000 MW. The data breach incident does not appear to affect the nuclear security or safety of the nation, as the government and NPCIL continue to emphasize. 

The breach did, however, raise concerns about the safety of digital assets and data security in various contracts, including those of critical infrastructure like Kudankulam NPP.

Japan's Largest Taxi Service Goes Offline After Cyberattack


Nihon Kotsu, Japan’s largest taxi operator, said that its systems were impacted in a cyberattack, causing the company to close down some of its infrastructure.

The incident happened last week and impacted business operations such as the company’s taxi dispatch system, currently offline.

Nihon Kotsu has an annual revenue of around $1 billion.

The company has 18,228 employees and has 8,588 taxis and over 2000 chauffeur vehicles.

Nihon Kotsu said in a statement, “We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)”. It further added that “immediately after detecting the unauthorized access, we implemented emergency measures, such as disconnecting systems to prevent further damage.”

The impact

The company has closed down systems to offline to stop the threat but it has widely caused disruption in services.

The incident has disrupted web booking, car hire, reservation management, few internal systems, and telephone dispatch service.

Nihon Kotsu advised people to use the ‘GO’ taxi app instead, or use a taxi stand for booking a Nihon Kotsu vehicle. It is a major operational damage for a company that has one of  Tokyo’s biggest fleets but the manual working is still operational. The hire car reservation system is offline.

In a different announcement, Nihon Kotsu said that the “labor taxi” service for pregnant women is shut down in a few areas.

Investigation

The firm has brought in external cybersecurity experts to assist in investigating if there has been a data leak. The internal network has been separated to limit further spread.

Currently, no data leak has been confirmed and Nihon Kotsu will provide updates via official channels. “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law,” Nihon Kotsu said.

What next

Customers of Nihon Kotsu are cautioned not to click on any links in suspicious communications purporting to be from the company and not to open anything they receive. 

Zimbra Urges Immediate Update to Fix Critical Classic Web Client XSS Vulnerability

 

Zimbra has released a security update to address a critical vulnerability in the Zimbra Classic Web Client that could allow malicious actors to compromise user accounts and execute unauthorized code. The company recommends that customers install the latest update to mitigate the threat. The flaw is a stored cross-site scripting (XSS) vulnerability that could allow an unauthenticated attacker to execute malicious JavaScript in the browser of a user viewing a specially crafted email message. 

The problem exists in the Classic Web Client component of Zimbra Collaboration Suite. While no CVE identifier has been assigned yet, Zimbra warned that successful exploitation of the vulnerability would lead to the exposure of mailbox content and settings, as well as session details. A stored XSS vulnerability occurs when the application stores user-supplied input without proper sanitization and later displays it to other users. 

In this case, an attacker could utilize this flaw to deliver specially crafted email messages that would execute arbitrary JavaScript code in the browser of a user who opens this message in the Zimbra Classic Web Client. The malicious script would then steal the victim’s session and potentially access their mailbox content, modify account settings, or perform other actions. While Zimbra has not reported any confirmed attacks using this vulnerability, several similar XSS flaws in the Zimbra Collaboration Suite have been actively exploited in the past. 

Attackers have targeted the webmail platform multiple times to hijack the accounts of high-profile organizations, including the Brazilian military, with no success, according to Zimbra. Previously exploited flaws affecting the product are CVE-2025-27915, CVE-2023-37580, and CVE-2024-27443. Therefore, organizations must ensure they have applied the latest security update to address the newly discovered vulnerability. 

The Zimbra Collaboration Suite 10.1.19 release notes mention the fix for the stored XSS in the Classic Web Client. Users must always access the updated version of the webmail platform via HTTPS to avoid man-in-the-middle attacks and other threats. Moreover, security analysts recommend monitoring the email traffic for any signs of suspicious activity and reviewing account access logs for unauthorized changes. 

Users must not open any attachments or links in emails that seem suspicious as these may contain malicious scripts that target webmail clients. Organizations must ensure they apply all security updates to their collaboration platforms as they provide critical protection against potential threats. 

In this case, the newly discovered vulnerability is yet another reminder of the importance of timely software updates. Attackers will continue targeting collaboration platforms such as Zimbra webmail to compromise user accounts by exploiting flaws such as XSS.

Meta Faces Privacy Questions After Employee Data Exposure Report


 

After sensitive employee information was reportedly made available throughout the organization, Meta has suspended an internal employee monitoring initiative intended to assist in the development of artificial intelligence systems. 

Initially introduced in April, the Model Capability Initiative was intended to collect workplace activity data to assist Meta in improving its artificial intelligence models through the collection of work activity data. The system was reportedly used by employees to monitor interactions across various workplace applications including Gmail, Google Chat, and Meta’s AI assistant, as well as capture screenshots and usage patterns. 

In response to concerns about privacy and consent, the initiative quickly drew criticism from employees. More than 1,600 Meta employees, including engineers, researchers, and designers, have signed a petition advocating the discontinuation of this program. Prior to the latest incident, the monitoring initiative had already been under scrutiny. A Reuters report reported that the program collected more information than originally indicated and stored some of the data unencrypted, raising concerns among employees about privacy. 

In internal discussions, employees were also concerned that personal information, including tax and medical records accessed from work devices, could be disclosed, despite assurances that the data would be protected and used solely for legitimate business purposes. According to the petition, employees argued that responsible AI development should not be compromised by individual privacy concerns. 

A company's stated commitment to building trustworthy and responsible artificial intelligence systems is in conflict with the company's collection of workplace data without meaningful consent. Following reports that sensitive employee information had been accessed internally by employees, the controversy became more intense. 

According to information cited in media reports, the exposed data could have included private communications, AI prompts, transcriptions, as well as performance data. The incident has sparked an internal investigation, though there is no evidence of the information being improperly accessed or misused. Meta, according to Reuters, suspended the initiative after filing an internal security incident (SEV) in response to employee data being widely accessible within the organization. 

As indicated in internal documentation, this information included artificial intelligence prompts and transcriptions, private conversations, personnel records, and classifications of data sensitivity. This incident raised new concerns regarding the collection, storage, and protection of employee information. The Meta program has been suspended while the matter is being investigated. 

A company spokesperson confirmed the initiative was designed with privacy safeguards and stressed the absence of any indication of unauthorized access during the investigation. As of the time of the investigation, Meta had not announced when the initiative might resume, and executives of Meta indicated that it would remain halted while the investigation continued. As Meta stated, the Model Capability Initiative will be suspended gradually and might not reach all employees immediately. 

A source familiar with the matter told Reuters that the monitoring tool was still recording employee activity on Monday afternoon while the company attempted to disable it across all its systems. An additional clarification of the incident was provided by Meta Chief Technology Officer Andrew Bosworth in a later interview, in which he stated that the incident was not the result of an external security breach. Bosworth reported that employee information generated through the program initially could only be accessed by a small number of authorized employees, but was accidentally stored in an internal location incorrectly by a researcher. 

According to Meta, there was no evidence of malicious activity found, and the incident was an internal error that caused the company to suspend the initiative while investigating the matter. The development indicates growing tensions between rapid advancement of artificial intelligence and employee privacy rights. The majority of technology companies are exploring new sources of training data to enhance the performance of their models, as well as investing heavily in artificial intelligence. 

Despite increasing competition in the AI industry, Meta is expected to spend more than $135 billion on infrastructure in 2018. According to leaked audio from an internal Meta meeting, Mark Zuckerberg was in favor of using employee-generated data for AI training, asserting that highly skilled employees could serve as valuable examples for AI systems. It has been criticized by privacy advocates, however. 

Digital rights experts have argued that extensive workplace monitoring raises serious concerns about employee consent and transparency. According to the incident report, maintaining employee trust and protecting sensitive information are critical challenges that organizations should not overlook as they accelerate the development of artificial intelligence. 

A growing concern is how to strike a balance between rapid AI innovation and employee privacy and data security, as exemplified by the incident. As Meta continues its internal investigation, the outcome will likely influence how organizations approach AI training, workplace monitoring, and responsible data governance in the years to come.

Sovereign File Architecture Gains Importance as Enterprises Rethink Cloud Data Control

 

Cloud computing changed enterprise IT by enabling organizations to achieve significant storage scalability and cost savings. Companies quickly embraced the idea of storing data in the cloud because of its flexibility and accessibility. However, because information remains on physical servers, companies are discovering that data is stored in a specific location subject to local legislation. 

This led to the concept of sovereign file architecture, one of the strategies by which organizations seek to store information considering jurisdiction as a critical factor. The data storage strategy is now focused on achieving file sovereignty and residency rather than convenience. Data sovereignty differs from privacy in that the former concerns the primary authority that possesses the right to store and access information, while the latter relates to its geographic location. 

While the early cloud computing innovators placed their data with the most accessible and cost-effective infrastructure, there was little information on where exactly it was stored. This created a sovereignty gap, as the organizations had limited insight into who could access the information and the applicable legal frameworks. At the same time, there are more data residency and sovereignty risks today as countries impose strict regulations and trade barriers while dealing with cybersecurity threats and geopolitical tensions. 

Data residency is a crucial consideration for many organizations, particularly those dealing with sensitive data and operating at a multinational level. Disasters, government restrictions, or geopolitical tensions may render some servers inaccessible, thus necessitating the need to store data in different jurisdictions. Enterprises are now prioritizing storage solutions that give them the most control by allowing them to migrate or place their information as they see fit. 

These factors are driving companies to adopt sovereign file architecture, which is designed to decouple file management from storage. By doing so, organizations satisfy the need to store data in several jurisdictions and maintain flexibility regarding where to store sensitive or non-sensitive information. Enterprises can also utilize a hybrid strategy consisting of private and public storage methods, thus balancing costs and file security. 

Sovereign file architecture allows organizations to remain compliant with the increasingly stringent data residency and sovereignty laws enforced by governments worldwide. Consequently, there is now a growing preference for sovereign file architectures over other options when considering factors such as transparency, legal protection, and control.

Anubis Ransomware Gang Attacks Again, Exploit Remote Access


Hackers linked with Anubis ransomware operation were found abusing the Citrix Bleed 2 (CVE-2025-5777) flaw to find initial access. 

According to Arctic Wolf, the techniques vary among different affiliates, and few patterns surfaced in tradecraft via authentic Remote Management and Monitoring (RMM) tooling, hands-on-keyboard procedures and credential access. 

Anubis also exploited authentic remote access and admin tools such as MeshAgent, Total Software Deployment, ScreenConnect, UltraVNC, and Zoho Assist to merge with usual IT operations while handling control of target systems.

About Anubis 

Anubis is a RaaS gang that first surfaced in late 2024 as a spinoff of Sphinx ransomware. The ransomware campaign was first disclosed on the Ransomware and Advanced Malware Protection (RAMP) darkweb forum in February last year. As per the data from Ransomware.Live, the cybercrime gang has taken responsibility for 91 victims on its data leak website, with 11 targets in June 2026.

Areas impacted

Some significant areas attacked are business services, technology, financial services, healthcare, and technology. Above 50% of the targets are based in the U.S, then U.K, Australia, France, and Canada.

Rubrik Zero Labs published a report in July 2025 which said Anubis promotes promising profit splits, which offers 80% of the ransom paid, and combines it with a data wiping (irresistible) feature to further blackmail the victims to pay upfront.

Experts at Rubrik said that “when Anubis's /WIPEMODE module is activated, files remain in directories but are reduced to a 0 KB size regardless of ransom payment.” The experts added that when “Anubis changes ransomware’s traditional strategic calculus, it creates powerful incentives for motivated threat actors to deploy Anubis in pursuit of lucrative returns.”

The impact

Commenting on the severity of the attack, Rubrik said that, “Knowing threat actors can revert victims' environments to this scorched-earth state with a single command significantly increases pressure on victims to pay before the wiper is fully activated.”

The ransomware incidents in 2026 consist both exploitation of CVE-2025-5777 (CVSS score: 9.3), a severe flaw affecting Citrix Net and valid VPN credential use.

The source of VPN credentials in these attacks is unknown, but experts say that they are likely to be collected after the first compromise, or via credential stuffing, initial access brokers (IABs), or information stealer operations.