Every time you apply for a credit card or update your account details, you may be sharing your data with ICE.
A research by 404 Media said that personal information stored by credit card firms can sail through a network of data brokers and can become accessible to US Immigration and Customs Enforcement (ICE). ICE can then search and investigate your personal data without any warrant.
“No one signing up for a credit card thinks they’re giving data brokers a thumbs-up to sell their personal information to ICE. Not only is it an outrageous violation of our privacy, [but] it’s impossible for Americans to opt out,” Senator Ron Wyden said to 404 Media in a statement.
According to 404 media, when someone opens a credit card or updates their personal data, credit card firms share that data with credit bureaus.
The personal information consists of Social Security numbers, addresses and email addresses, names, and phone numbers. Contrary to credit reports, this data does not have robust legal security.
Personal information is then sent to credit bureaus, who give the data to Thompson Reuters. From there, the data is incorporated into CLEAR, the firm’s investigative data product. Thomson Reuters sells access to CLEAR to law enforcement authorities, including ICE.
After gaining access to CLEAR, ICE can search through personal information without a warrant. "404 Media has mapped out this supply of data by reviewing U.S. government procurement records and internal documents from companies providing the information." The platform is also combined with a tool that suggests ICE to decide which neighbourhoods to raid.
"Anytime we update our home addresses on these accounts, credit bureaus get the updates within 24 hours and share it broadly with other data brokers, thanks to legal loopholes that leave our personal information open to misuse and abuse," Just Futures attorney Laura Rivera said to 404 Media.
Another report enquired Thompson Reuter’s increasing role in providing personal data to the US Government.
The Department of Homeland Security (DHS) is planning to pay Thomson Reuters $125 million to give access to its databases as part of enquiries into suspected immigration fraud and voter fraud. The agreement will be worth $25 million annually for five years respectively.
Connor Riley Moucka is 26-yr old, and also worked under aliases Waifu and Alexander Moucka, was arrested on October 30, 2024, for stealing information from millions of people from organizations that used Snowlake’s storage features. Moucka admitted to four charges: computer fraud, wire fraud, aggravated identity theft, and a related conspiracy count, out of an original 11-count indictment.
Between February and October 2024, Moucka and his partner John Erin Binns, also arrested for these attacks, accessed Snowflake accounts. Rather than exploiting a flaw in Snowflake's platform itself, the pair relied on credentials harvested through infostealer malware to log into customer accounts. They stole accounts that were not secured by multi-factor authentication (MFA) via login credentials through an infostealer malware.
Without MFA protection, the hackers only needed the right usernames and passwords to sign into customer accounts. After gaining access, the hackers only needed custom-built software to sail through cloud storage incidents for important information.
The illegal access was used for identifying important information such as user roles, IP addresses, and organization name in cloud storage incidents that used Snowflake services.
The accused tried to blackmail various firms after stealing TBs of data from their Snowflake user accounts and got around $2.5 million in bitcoin from three targets.
According to the prosecutors, the campaign exploited data linked to over 100 million individuals and resulted in $9.5 million losses for organizations. The list of impacted companies include: Ticketmaster, Santander, AT&T, Advance Auto Parts, Los Angeles Unified School District, Pure Storage, QuoteWizard/LendingTree, and Neiman Marcus.
Moucka allegedly stole around $495,000 from ransom payments. AT&T paid around $370,000 to avoid future leaks of text records and customer calls.
“In at least one instance, Moucka re-extorted a victim with threats of further disclosure of the victim’s stolen data,” the US Department of Justice said in a press release.
“Moucka used the stolen data of a government officer and members of a then-former government officer’s immediate family in this re-extortion attempt.”
Experts found a live campaign that abused spoofed customer-side safe sender exclusions and RingCentral emails to escape email gateway checks and send phishing traps attacking Microsoft 365 accounts.
"Greatness supports AiTM [adversary-in-the-middle] credential and token theft, device code phishing, and OAuth consent abuse, all from the same operator panel and shared backend infrastructure," ZeroBec, who discovered the campaign, said in a report.
"The platform now supports AiTM token theft, device code phishing, OAuth consent abuse, and multiple target platforms, including iCloud, Yahoo, and Google Workspace. This evolution reflects the broader trend of PhaaS platforms expanding from simple credential harvesting to integrated attack ecosystems."
The phishing platform was first found by Cisco Talos in May 2023, showing how hackers are including it in their campaigns to attack Microsoft 365 business users since May 2022.
Built to ease cybercrime, access to Greatness is given through a subscription available on Telegram channel called @GreatnessPage having over 3,250 subscribers and works as a central hub for feature updates and announcements. Hackers can get a subscription at $289 per month, rising from $120 per month from January 2024. The subscription offers access to an operator that consists of a dashboard with CAPTCHA selection, domain configuration, campaign statistics, and more than 11 downloadable trap templates including QR codes, voicemail, and document sharing.
The operators of Telegram channel in November 2025 said that Greatness keeps stolen cookies secure through one-way hash protection and the information can be taken out only by the customers via their Telegram account two factor authentication code.
Threat actors that buy a subscription by giving their bot API token and Telegram chat ID can use the panel via an “O365 Panel” login page that needs a 9-character license key and a user ID. Once registered, customers are shown a dashboard and an operator-particular domain.
The dashboard is a standard place that provides campaign statistics such as heat map of victims and captured cookies. "Observed templates include: AudioLogin, ChatAssistance, WindowsExplorer, Voicemail, OneDrive, QR, VideoPlayer, and additional variants. "Each template contains pre-built HTML, PDF redirectors, SVGs, and letter templates, lowering the barrier to entry so operators do not need to build lures from scratch."
Blackpoint Cyber said that the hack starts with a spear-phishing message consisting of a link to an encoded archive, which contains a Windows Shortcut (LNK). Running a file prompts a multi-level strain that consists of privilege escalation, compromising Microsoft Defender protections, while downloading extra payloads.
Matryoshka is available in two versions: one that supports HTTP-based communication and command execution, and another that uses GitHub for command-and-control (C2), including beaconing, tasking, reconnaissance, file transfer, and secondary payload delivery. HollowFrame is launched via a DLL side-loading pair consisting of the legitimate Python binary ("python.exe") and a rogue DLL ("python311.dll").
"Together, HollowFrame and Matryoshka gave the actor a persistent foothold for remote command execution, Active Directory reconnaissance, file transfer, and deployment of follow-on tooling. These capabilities could support credential theft, lateral movement, and broader domain compromise through additional tools delivered after initial access,” Blackpoint experts Nevan Beal and Sam Decker said.
The multi-stage hack attacks two endpoints at an unknown law firm. The LNK file mimicked to be Case Documents to lure the victim into opening and triggering a command sequence that deploys PowerShell to get next-stage components from a remote server.
Hollowframe works as a modular loader and persistent framework that assists multiple tactics to deploy auxiliary components, while performing anti-analysis diagnosis to escape running inside sandboxed environments. This is decided based on installed memory, cursor movement, file count in the user profile, and system uptime. Persistence is gained by setting up a scheduled task.
Matryoshka ("version.dll"), a Rust-based backdoor that talks with its C2 server ("45.158.196[.]184:8888") over HTTP to spawn a shell and provide additional tooling, is deployed by unpacking the encrypted container that the Go loader comes with.
Another DLL gained in association with the same activity has been labeled as a version of Matryoshka that uses a private GitHub repository for polling target-specific commands, submitting results, and fetching payloads.
"The repository functioned as a collection of per-host mailboxes, with each victim assigned a dedicated <computer>_<username> directory. These directories contained beacon.json, cmd.json, result.json, and, in some cases, an upload/ tree for file delivery,” Blackpoint said.
The incident happened last week and impacted business operations such as the company’s taxi dispatch system, currently offline.
Nihon Kotsu has an annual revenue of around $1 billion.
The company has 18,228 employees and has 8,588 taxis and over 2000 chauffeur vehicles.
Nihon Kotsu said in a statement, “We have confirmed that our internal systems were subjected to unauthorized external access (malware infection)”. It further added that “immediately after detecting the unauthorized access, we implemented emergency measures, such as disconnecting systems to prevent further damage.”
The company has closed down systems to offline to stop the threat but it has widely caused disruption in services.
The incident has disrupted web booking, car hire, reservation management, few internal systems, and telephone dispatch service.
Nihon Kotsu advised people to use the ‘GO’ taxi app instead, or use a taxi stand for booking a Nihon Kotsu vehicle. It is a major operational damage for a company that has one of Tokyo’s biggest fleets but the manual working is still operational. The hire car reservation system is offline.
In a different announcement, Nihon Kotsu said that the “labor taxi” service for pregnant women is shut down in a few areas.
The firm has brought in external cybersecurity experts to assist in investigating if there has been a data leak. The internal network has been separated to limit further spread.
Currently, no data leak has been confirmed and Nihon Kotsu will provide updates via official channels. “We are currently conducting a detailed investigation with specialized agencies into whether and to what extent data has been leaked. At this time, no information leak has been confirmed. However, in the unlikely event that we discover any leak or potential leak of personal information of our customers or related parties, we will promptly make an official announcement and contact those affected individually, in accordance with the law,” Nihon Kotsu said.
Customers of Nihon Kotsu are cautioned not to click on any links in suspicious communications purporting to be from the company and not to open anything they receive.