Feds Link $150M Cyberheist to 2022 LastPass Hacks
Krebs on Security » Data Breaches
by BrianKrebs
1w ago
In September 2023, KrebsOnSecurity published findings from security researchers who concluded that a series of six-figure cyberheists across dozens of victims resulted from thieves cracking master passwords stolen from the password manager service LastPass in 2022. In a court filing this week, U.S. federal agents investigating a spectacular $150 million cryptocurrency heist said they had reached the same conclusion ..read more
Visit website
Fintech Giant Finastra Investigating Data Breach
Krebs on Security » Data Breaches
by BrianKrebs
4M ago
The financial technology firm Finastra is investigating the alleged large-scale theft of information from its internal file transfer platform, KrebsOnSecurity has learned. Finastra, which provides software and services to 45 of the world's top 50 banks, notified customers of a potential breach after a cybercriminal began selling more than 400 gigabytes of data purportedly stolen from the company.  ..read more
Visit website
An Interview With the Target & Home Depot Hacker
Krebs on Security » Data Breaches
by BrianKrebs
4M ago
In December 2023, KrebsOnSecurity revealed the real-life identity of Rescator, the nickname used by a Russian cybercriminal who sold more than 100 million payment cards stolen from Target and Home Depot between 2013 and 2014. Moscow resident Mikhail Shefel, who confirmed using the Rescator identity in a recent interview, also admitted reaching out because he is broke and seeking publicity for several new money making schemes ..read more
Visit website
Change Healthcare Breach Hits 100M Americans
Krebs on Security » Data Breaches
by BrianKrebs
5M ago
Change Healthcare says it has notified approximately 100 million Americans that their personal, financial and healthcare records may have been stolen in a February 2024 ransomware attack that caused the largest ever known data breach of protected health information ..read more
Visit website
Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach
Krebs on Security » Data Breaches
by BrianKrebs
5M ago
Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being "USDoD," a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI's InfraGard program and leaking contact information for 80,000 members. More recently, USDoD was behind a breach at the consumer data broker National Public Data that led to the leak of Social Security numbers and other personal information for a significant portion of the U.S. population ..read more
Visit website
National Public Data Published Its Own Passwords
Krebs on Security » Data Breaches
by BrianKrebs
7M ago
New details are emerging about a breach at National Public Data (NPD), a consumer data broker that recently spilled hundreds of millions of Americans' Social Security Numbers, addresses, and phone numbers online. KrebsOnSecurity has learned that another NPD data broker which shares access to the same consumer records inadvertently published the passwords to its back-end database in a file that was freely available for download from its homepage until today ..read more
Visit website
Low-Drama ‘Dark Angels’ Reap Record Ransoms
Krebs on Security » Data Breaches
by BrianKrebs
8M ago
A ransomware group called Dark Angels made headlines this past week when it was revealed the crime group recently received a record $75 million data ransom payment from a Fortune 50 company. Security experts say the Dark Angels have been around since 2021, but the group doesn't get much press because they work alone and maintain a low profile, picking one target at a time and favoring mass data theft over disrupting the victim's operations ..read more
Visit website
Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks
Krebs on Security » Data Breaches
by BrianKrebs
8M ago
At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week. Squarespace bought all assets of Google Domains a year ago, but many customers still haven’t set up their new accounts. Experts say malicious hackers learned they could commandeer any migrated Squarespace accounts that hadn’t yet been registered, merely by supplying an email address tied to an existing domain. Until this past weekend, Squarespace’s website had an option to log in via email. The Squarespace domain hijacks, which took place between July 9 and July 12, appear ..read more
Visit website
Alleged Boss of ‘Scattered Spider’ Hacking Group Arrested
Krebs on Security » Data Breaches
by BrianKrebs
10M ago
A 22-year-old man from the United Kingdom arrested this week in Spain is allegedly the ringleader of Scattered Spider, a cybercrime group suspected of hacking into Twilio, LastPass, DoorDash, Mailchimp, and nearly 130 other organizations over the past two years. The Spanish daily Murcia Today reports the suspect was wanted by the FBI and arrested in Palma de Mallorca as he tried to board a flight to Italy. A still frame from a video released by the Spanish national police shows Tylerb in custody at the airport. “He stands accused of hacking into corporate accounts and stealing critical infor ..read more
Visit website
Who Stole 3.6M Tax Records from South Carolina?
Krebs on Security » Data Breaches
by BrianKrebs
1y ago
For nearly a dozen years, residents of South Carolina have been kept in the dark by state and federal investigators over who was responsible for hacking into the state’s revenue department in 2012 and stealing tax and bank account information for 3.6 million people. The answer may no longer be a mystery: KrebsOnSecurity found compelling clues suggesting the intrusion was carried out by the same Russian hacking crew that stole of millions of payment card records from big box retailers like Home Depot and Target in the years that followed. Questions about who stole tax and financial data on rou ..read more
Visit website

Follow Krebs on Security » Data Breaches on FeedSpot

Continue with Google
Continue with Apple
OR