Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds. Meanwhile, the nonprofit entity that oversees […]
Category Archives: Krebs
Category Added in a WPeMatico Campaign
A Little Sunshine, AT&T, Boxfan, buttholio, Connor Riley Moucka, cyb3rph4nt0m, DDoS-for-Hire, John Erin Binns, Judische, Kiberphant0m, Krebs, Naver, Ne'er-Do-Well News, News, Proman557, ransomware, Reverseshell, Security, Shi-Bot, Snowflake, South Korea, telekomterrorist, The Coming Storm, Vars_Secc, Verizon, Waifu
Hacker in Snowflake Extortions May Be a U.S. Soldier
Two men have been arrested for allegedly stealing data from and extorting dozens of companies that used the cloud data storage company Snowflake, but a third suspect — a prolific hacker known as Kiberphant0m — remains at large and continues to publicly extort victims. However, this person’s identity may not remain a secret for long: […]
A Little Sunshine, Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, Joel Martin Evans, Joeleoli, Kingbob, Krebs, lastpass, Mailchimp, Namecheap, Ne'er-Do-Well News, News, Noah Michael Urban, ogusers, Okta, Oktapus, Scattered Spider, Security, SIM Swapping, Sosa, T-Mobile, Twilio, Tylerb
Feds Charge Five Men in ‘Scattered Spider’ Roundup
Federal prosecutors in Los Angeles this week unsealed criminal charges against five men alleged to be members of a hacking group responsible for dozens of cyber intrusions at major U.S. technology companies between 2021 and 2023, including LastPass, MailChimp, Okta, T-Mobile and Twilio. A visual depiction of the attacks by the SMS phishing group known […]
The financial technology firm Finastra is investigating the alleged large-scale theft of information from its internal file transfer platform, KrebsOnSecurity has learned. Finastra, which provides software and services to 45 of the world’s top 50 banks, notified customers of the security incident after a cybercriminal began selling more than 400 gigabytes of data purportedly stolen […]
A Little Sunshine, Aleksandr Ermakov, chronopay, Data Breaches, Dmitri Golubov, Helkern, Home Depot breach, Hydra Market, Krebs, MikeMike, Mikhail Lenin, Mikhail Shefel, Ne'er-Do-Well News, News, pavel vrublevsky, Peter Vrublevsky, Pharma Wars, Security, Sprut, Sugar ransomware, target breach
An Interview With the Target & Home Depot Hacker
In December 2023, KrebsOnSecurity revealed the real-life identity of Rescator, the nickname used by a Russian cybercriminal who sold more than 100 million payment cards stolen from Target and Home Depot between 2013 and 2014. Moscow resident Mikhail Shefel, who confirmed using the Rescator identity in a recent interview, also admitted reaching out because he […]
Microsoft today released updates to plug at least 89 security holes in its Windows operating systems and other software. November’s patch batch includes fixes for two zero-day vulnerabilities that are already being exploited by attackers, as well as two other flaws that were publicly disclosed prior to today. The zero-day flaw tracked as CVE-2024-49039 is […]
The Federal Bureau of Investigation (FBI) is urging police departments and governments worldwide to beef up security around their email systems, citing a recent increase in cybercriminal services that use hacked police email accounts to send unauthorized subpoenas and customer data requests to U.S.-based technology companies. In an alert (PDF) published this week, the FBI […]
A Little Sunshine, Advance Auto Parts, Alexander Antonin Moucka, AT&T breach, Atomwaffen Division, Austin Larsen, Bharat Sanchar Nigam Ltd, Breadcrumbs, Connor Riley Moucka, Court, IntelSecrets, IRDev, John Erin Binns, Judische, Kiberphant0m, Krebs, Leak Society, Lending Tree, Mandiant, Ne'er-Do-Well News, News, RapeLash, Satori, Security, SIM Swapping, Snowflake, Ticketmaster, UNC5537, Verizon, Waifu
Canadian Man Arrested in Snowflake Data Extortions
A 26-year-old man in Ontario, Canada has been arrested for allegedly stealing data from and extorting more than 160 companies that used the cloud data service Snowflake. Image: https://www.pomerium.com/blog/the-real-lessons-from-the-snowflake-breach On October 30, Canadian authorities arrested Alexander Moucka, a.k.a. Connor Riley Moucka of Kitchener, Ontario, on a provisional arrest warrant from the United States. Bloomberg first […]
A number of cybercriminal innovations are making it easier for scammers to cash in on your upcoming travel plans. This story examines a recent spear-phishing campaign that ensued when a California hotel had its booking.com credentials stolen. We’ll also explore an array of cybercrime services aimed at phishers who target hotels that rely on the […]
AlphV, Anthem Inc., BlackCat, Data Breaches, Equifax, Experian, HIPAA Journal, IDX, Krebs, Latest Warnings, News, RansomHub, Security, Sen. Mark Warner, Sen. Ron Wyden, The Coming Storm, TransUnion, U.S. Department of Health and Human Resources, United Health Group
Change Healthcare Breach Hits 100M Americans
Change Healthcare says it has notified approximately 100 million Americans that their personal, financial and healthcare records may have been stolen in a February 2024 ransomware attack that caused the largest ever known data breach of protected health information. Image: Tamer Tuncay, Shutterstock.com. A ransomware attack at Change Healthcare in the third week of February […]