Data Breaches
A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.
Hi, what are you looking for?
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets.
A mandatory filing to the Maine Attorney General says 69,461 customers nationwide were affected and dates the breach back to last December.
Combined with AI, polymorphic phishing emails have become highly sophisticated, creating more personalized and evasive messages that result in higher attack success rates.
A sophisticated phishing campaign abuses weakness in Google Sites to spoof Google no-reply addresses and bypass protections.
Agentic AI has improved spear phishing effectiveness by 55% since 2023, research shows.
‘PoisonSeed’ phishing campaign targets CRM and bulk email providers to distribute “crypto seed phrase” messages.
A threat actor tracked as Morphing Meerkat abuses DNS mail exchange (MX) records to deliver spoofed login pages.
A long-running campaign phishing for credentials through scareware recently switched to targeting macOS users.
Threat actors are abusing Microsoft 365 infrastructure in a BEC campaign, and target its users in two brand impersonation campaigns.
A cybercrime group named Storm-1865 has targeted hospitality organizations via fake Booking.com emails and the use of social engineering.
Researchers see dozens of fake DeepSeek websites used for credential phishing, cryptocurrency theft, and scams.
Business resilience must be the ultimate purpose of all the security controls and processes we employ, because we will never conclusively defeat or protect...
Noteworthy stories that might have slipped under the radar: several multi-million dollar settlements, CrowdStrike-themed phishing emails, and MITRE launches D3FEND 1.0.
Fortinet warns of a phishing campaign that uses legitimate links to take over the victims’ PayPal accounts.
General Dynamics says several benefits accounts were hacked after threat actors targeted employees in a phishing campaign.
Okta has warned customers that it has seen an increase in phishing attacks impersonating its support team.
Belgian and Dutch authorities arrested eight individuals for their alleged involvement in phishing, online scams, and money laundering operations.
Microsoft has seized 240 phishing-related websites and has disrupted the ONNX service, which the company says is run by an Egyptian man.
GoIssue is a new tool for cybercriminals that allows attackers to extract email addresses from GitHub profiles and send bulk emails to users.
Kolade Akinwale Ojelade was sentenced to 26 years in prison in the US for compromising email accounts through phishing and stealing millions.
Barracuda has observed a large-scale OpenAI impersonation campaign whose goal is to phish for ChatGPT credentials.