Skip to main content

Attack-pattern intelligence · rolling 90-day view

Phishing & Social Engineering: News, Attacks & Guidance

Phishing and social engineering manipulate people into revealing information, approving actions or granting access. This page tracks current, explicitly identified incidents and connects them to practical identity, process and awareness controls.

Practical overview

How does phishing & social engineering work, and what should defenders look for?

How does it work?

  • Attackers use email, messages, calls, fake login flows or trusted relationships to create urgency, authority or familiarity.
  • Spear-phishing targets a particular person or organization, while business email compromise often redirects payments or sensitive conversations.
  • Successful social engineering may lead to credential theft, session hijacking, malware delivery, fraudulent payments or follow-on intrusion.

Which organizations are targeted?

  • Finance, payroll, executives, help desks and administrators are frequent targets because they can approve money, access or identity changes.
  • Organizations with complex supplier relationships face impersonation risk across invoice and account-change workflows.
  • Public information about roles, projects and vendors helps attackers make targeted approaches more convincing.

What are the signs and impacts?

  • Unexpected login prompts, changed payment details, unusual mailbox rules and requests that bypass normal verification can indicate an attempt.
  • Impact can include account takeover, fraudulent payment, data disclosure, malware delivery and loss of trust in internal communications.
  • A reported campaign should be matched against the organization's channels, identities and transaction processes before conclusions are drawn.

How should organizations respond?

  • Reset or revoke compromised authentication factors and sessions, then review mailbox, identity and endpoint activity for follow-on access.
  • For suspected payment fraud, activate bank and counterparty escalation routes immediately and preserve the communication trail.
  • Use the incident to improve independent verification, phishing-resistant authentication and reporting paths—not only awareness messaging.

Current evidence

What phishing & social engineering incidents are being reported?

Explore all live cyber intelligence

Signals appear here only when the title, summary or a sufficiently specific VERIS value supports this classification. The feed is current reporting, not a measure of total incident prevalence.

Dropbox logoPhishing
High

Dropbox Suffers Data Breach in Phishing Attack Targeting GitHub Account

Dropbox, a cloud storage company, experienced a data breach when its GitHub account was compromised on October 13. The attackers gained access to 130 code repositories containing sensitive data, including API keys used by Dropbox developers. The incident was a result of a successful email phishing campaign that targeted Dropbox employees, impersonating CircleCI, a continuous integration and delivery platform. The phishing emails directed victims to a fake login page where they were prompted to enter their GitHub credentials and a One-Time Password (OTP) from their hardware authentication key. Dropbox was notified of the potential breach by GitHub on October 14. While the attackers accessed some credentials and API keys, Dropbox stated that customer accounts, passwords, or payment information were not compromised, nor were its core apps or infrastructure. The data accessed also included the names and email addresses of a few thousand Dropbox employees, current and past customers, sales leads, and vendors. In response, Dropbox is enhancing its security by implementing WebAuthn and hardware tokens or biometrics.

Dropbox
Axios logoInfostealer
Medium

Axios npm package compromised in supply chain attack on July 23, 2026

On July 23, 2026, the Axios npm package, a widely used JavaScript HTTP client, was compromised in a sophisticated supply chain attack. The attackers hijacked a maintainer account and injected a malicious dependency, `plain-crypto-js`, into versions `axios@1.14.1` and `axios@0.30.4`. This malicious dependency was designed to download multi-stage payloads, including a remote access trojan, onto developer machines and CI/CD pipelines globally. The compromise was detected and the malicious packages were removed from npm within approximately three hours. The attack was characterized by its operational sophistication, bypassing standard security controls like MFA through a targeted social engineering campaign against the maintainer. The malicious code was capable of breaching major operating systems including Windows, macOS, and Linux. CISA issued an alert providing guidance for detection and remediation, urging organizations to monitor code repositories, CI/CD pipelines, and developer machines, and to rotate credentials that may have been exposed. Google Threat Intelligence Group publicly attributed the compromise to UNC1069, a North Korea-nexus, financially motivated threat actor. The incident highlights the significant risks associated with software supply chain attacks and the importance of robust security measures for open-source dependencies.

Axios
Digicert logoInfostealer
High

DigiCert Security Incident Linked to GoldenEyeDog Subgroup CylindricalCanine

DigiCert's security incident in April 2026 has been attributed to CylindricalCanine, a subgroup of the China-linked cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group). The attackers compromised a support employee's device using malware delivered via a phishing lure disguised as a screenshot or document sent through DigiCert's support-ticket workflow. This intrusion granted the threat actors access to initialization codes for customers renewing code-signing certificates. By intercepting these codes, the attackers were able to obtain 27 fraudulent code-signing certificates, which were then used to sign malware, including the "Zong Stealer" campaign. DigiCert identified the incident through third-party reports of certificates being used in malware and subsequently revoked 60 certificates by April 17, with 27 explicitly linked to the attackers. The company emphasized that its root certificates were never compromised, and the breach was limited to a finite set of certificates. DigiCert has since blocked high-risk file types at ingestion, removed malicious files from Salesforce cases and chat records, and is working on sandboxing controls for inbound support attachments.

Digicert
Doordash logoPhishing
High

DoorDash Confirms Data Breach After Social Engineering Attack

DoorDash, the popular food delivery platform, publicly acknowledged a cybersecurity incident that compromised the personal information of an undisclosed number of users. The breach, which occurred on October 25, was a result of a social engineering attack targeting a company employee. This allowed an unauthorized third party to gain access to DoorDash's internal systems. The compromised data varied by individual but potentially included first and last names, phone numbers, email addresses, and physical addresses of customers, Dashers (delivery drivers), and merchants across the United States, Canada, Australia, and New Zealand. DoorDash emphasized that no sensitive financial information, such as Social Security numbers, government-issued IDs, driver's license details, bank information, or payment card data, was accessed. The company's security team identified and shut down the unauthorized access shortly after its detection, launched an internal investigation, and notified law enforcement. DoorDash has also implemented multiple security enhancements, including upgraded security systems and additional employee training programs focused on social engineering awareness. While the company has stated there is no indication the data has been misused for fraud or identity theft, affected users are advised to be cautious of unsolicited communications requesting personal information. This incident marks DoorDash's third known cybersecurity incident in six years, highlighting the persistent threat of social engineering attacks.

Doordash
Lidl logoPhishing
High

Lidl Online Shop Customer Data Stolen in IT Security Incident

Lidl, the popular retail chain, announced on July 11, 2026, that it experienced a security incident involving an external IT service provider, resulting in the theft of customer data from its online shop. Unidentified attackers gained temporary access to a separate file containing customer information. The compromised data includes customers' titles, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl has confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts remain secure. The company has stated that there is currently no concrete evidence of the stolen data being misused, but it has proactively warned affected customers about potential phishing attempts and identity theft. Lidl advises customers to be extra cautious with communications from unknown sources. The IT service provider involved has taken immediate steps to restore security, strengthen system protection, and has filed a criminal complaint. IT experts are also involved in the investigation to enhance future data protection. The Office for Personal Data Protection has been informed and is monitoring the case.

Lidl
Lidl logoPhishing
High

Lidl Czech Republic E-shop Customer Data Breach

Lidl Czech Republic announced a security incident on July 10, 2026, affecting its e-shop customers. Attackers gained access to a separately stored file containing customer data from an IT service provider. The compromised data includes customers' salutations, first and last names, phone numbers, email addresses, dates of birth, and customer numbers. Lidl confirmed that passwords, billing and delivery addresses, bank details, or other payment information were not affected, and customer accounts were not compromised. The company stated that it currently has no concrete evidence of data misuse but has proactively warned affected customers about potential phishing attempts or identity theft. The IT service provider involved has taken measures to restore system security, filed a criminal complaint, and engaged IT experts for the investigation. The Office for Personal Data Protection was also informed of the incident. Lidl began notifying affected customers via email after discovering the incident earlier in the week.

Lidl
Sla logoRansomware
High

Singapore Land Authority Data Breach Exposes 70,000 Records via IBM Testing Environment

Singapore Land Authority data breach exposes 70,000 records after IBM testing environment compromised SINGAPORE, July 3 — Personal data belonging to about 70,000 individuals has been compromised in a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by IBM. SLA said the breach stemmed from unauthorised access to a dataset created for vendor development and systems integration testing, CNA reported. IBM oversees the testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS), which are used to submit property transfer and caveat documents. Preliminary checks showed the dataset, first created in 1998 and updated periodically, was intended to contain only mock and anonymised records. It was later discovered to include real information such as names, NRIC numbers and past property addresses of around 70,000 people. SLA stressed that the affected environment is separate from its live operational systems, adding that property ownership and lodgment records in STARS and ELS remain secure. IBM has revoked access to the compromised system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on assistance measures. The authority said it is working with IBM, the Government Technology Agency of Singapore and the Cyber Security Agency of Singapore to investigate the incident and implement remedial steps. According to CNA, a police report has been lodged and the Personal Data Protection Commission has been notified. SLA has not yet disclosed when the breach occurred or how many affected individuals have been contacted. Singapore’s first dedicated hospital for native wildlife opens at Mandai Singapore bookie aged 69 jailed for illegal betting on Hong Kong horse races Fatal dispute between Singapore Redhill flat neighbours leads to murder charge PDRM prepares security operations for Negeri Sembilan state election Defence weighs AGC appeal for driver in fatal Klang crash Amirudin: Pakatan banks on micro-campaign strategy to win over Negeri Sembilan voters ÑеÑгей ÑаÑанÑÑа - stock.adobe.com The Singapore Land Authority (SLA) has revealed that the personal information of about 70,000 individuals was exposed following unauthorised access to a cloud environment managed by IBM, its technology supplier. IBM was appointed to support and maintain SLA’s Singapore Titles Automated Registration System (Stars) and eLodgment System (ELS), which underpin property title registration and the lodgement of property documents in the city-state. As part of that work, the supplier managed the development and systems integration testing environment for the two systems. In a statement on 3 July 2026, SLA said it had been informed by IBM of the incident, with preliminary investigations indicating that a dataset created solely for development and testing purposes had been accessed without authorisation. The dataset, created in 1998 and updated periodically over the years, was meant to contain only mock and anonymised testing data based on property ownership and lodgement records. However, SLA said it has since uncovered that the dataset also contained the names, National Registration Identity Card (NRIC) numbers and property addresses of the affected individuals at the time. “This information should have been anonymised but was not,” the agency said, adding that investigations are ongoing to determine how this occurred. SLA noted that the affected environment is “distinct and separate” from its operational systems, with no connection to, or compromise of, the live systems that run Stars, ELS or any other SLA systems. Property ownership and lodgement records remain secure and unaffected, it added. IBM has revoked access associated with the affected environment to prevent further unauthorised access, while SLA has identified the individuals whose information was contained in the dataset, and has begun notifying them and advising them on how to seek further information and assistance. Singapore mobilised over 100 cyber defenders to neutralise a sophisticated APT actor which infiltrated Singtel, StarHub, M1 and Simba networks in the country’s  largest coordinated cyber incident response to date . Japan’s Nikkei has confirmed a major data breach that potentially  exposed the personal information of more than 17,000 employees  and business partners after hackers infiltrated its internal Slack messaging platform. Australian privacy commissioner warns that the  human factor is a growing threat  as notifications caused by staff mistakes rose significantly even as total breaches declined 10% from a record high. Philippine bank  BDO is shoring up its cyber security capabilities  to protect its data and systems as it moves more services to the cloud and expands its physical presence into remote areas of the archipelago. The agency is working with IBM, the Government Technology Agency and the Cyber Security Agency of Singapore (CSA) to establish the full facts and ensure remedial measures are taken. It has also lodged a police report and notified the Personal Data Protection Commission, and urged the public to remain vigilant against phishing emails, websites, text messages and phone calls from parties claiming to represent government agencies or other organisations. “We apologise for the concern and inconvenience this incident may cause,” the SLA said. The incident underscores the long-standing risk of real personal data finding its way into development and test environments , which are typically less closely guarded than production systems – a risk that is compounded when those environments are operated by third parties. It is also the latest in a series of supply chain security incidents in Singapore in recent years. In April 2025, Toppan Next Tech, a printing supplier for DBS Bank and the Singapore branch of Bank of China, was hit by a ransomware attack that saw customer data stolen by the threat actor . Some 8,200 DBS customers – mostly holders of DBS Vickers trading accounts and Cashline loans – and around 3,000 Bank of China customers were potentially affected. A year earlier, in August 2024, a hacker who gained unauthorised access to Mobile Guardian , a mobile device management platform then deployed across Singapore’s schools, remotely wiped the iPads and Chromebooks of about 13,000 students from 26 secondary schools. The Ministry of Education subsequently removed the software from all student devices and terminated its contract with the supplier.

Sla
Xsolis logoPhishing
High

Xsolis Data Breach Exposes 1.4 Million Patient Records Across Eight Health Systems

A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolis’s IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 — roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health — Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint — from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records — making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHS’s Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendor’s client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health system’s own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendor’s security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it — a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24–48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization — Rochester Regional Health — had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes

Xsolis
Xsolis logoRansomware
Medium

Healthcare AI Company Xsolis Suffers Data Breach Impacting 1.4 Million Individuals

Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information.  While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals.  The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519.  Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The company’s disclosure indicates that it’s “not aware of any actual or attempted misuse of information because of this incident”. It’s not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts.  Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolis’s hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.

Xsolis
Fedcapgroup logoPhishing
Medium

The Fedcap Group Confirms Data Breach, Social Security Numbers Compromised

Attorneys working with ClassAction.org are looking into whether a class action lawsuit can be filed in light of the The Fedcap Group data breach. As part of their investigation, they need to hear from individuals who had their information exposed in the incident , including those who received notice of the The Fedcap Group data breach or otherwise believe they are affected. The Fedcap Group Security Incident: What Happened? The Fedcap Group, which operates a network of international nonprofit affiliates, has confirmed a data breach in a June 22, 2026  report submitted to the Vermont Attorney General's Office . The report revealed that Social Security numbers were among the information compromised in The Fedcap Group data breach. A sample notification letter is pictured below. What You Can Do After the The Fedcap Group Data Breach If your information was exposed in the The Fedcap Group data breach, attorneys want to hear from you. You may be able to start a class action lawsuit to recover compensation for loss of privacy, time spent dealing with the breach, out-of-pocket costs, and more. A successful case could also force The Fedcap Group to ensure they take proper steps to protect the information they were entrusted with. Affected by the The Fedcap Group data breach? Fill out the form on this page today. If you believe your information was exposed in the The Fedcap Group data breach, fill out the form on this page to get in touch with us. An attorney or legal representative may then reach out to you to explain more about this investigation and ask you a few questions. Remember, there is no cost to get in touch, and you are under no obligation to take action after speaking to someone. New cases and investigations, settlement deadlines, and news straight to your inbox. Whitfield Regional Hospital Data Breach 2026 Community Health Center of Buffalo Data Breach 2026 Advantage Home Health Care Data Breach 2026 Unlimited Technology Systems Data Breach 2026 Heart Care Centers of Illinois Data Breach 2026 Clover Health Investments Data Breach 2026 Morris Communications Company Data Breach 2026 Brown Health Medical Group-MA Data Breach 2026 Case & Associates Properties Data Breach 2026 Date occurred: January 7, 2026 - January 30, 2026 Source of breach: Insider threat (employee) Data types: Names, addresses, phone numbers, dates of birth, social security numbers, account numbers, and transactional data Status: Confirmed; reported on June 15, 2026. Severity: Medium; the exposure of social security numbers and account data significantly increases the risk of financial fraud and identity theft. TD (td.com) reported a data breach involving customer information on June 15, 2026. The incident was classified as an insider breach, where an employee accessed sensitive data without authorization between January 7 and January 30, 2026. The compromised information includes highly sensitive details such as names, social security numbers, and bank account numbers. This medium-severity incident is currently being investigated internally, and the bank is implementing measures to enhance its data protection protocols. The exposure of such comprehensive personal and financial data typically increases the risk of identity theft and fraudulent account activity. The attacker or cause of the incident has not been identified. Affected customers face significant risks due to the exposure of social security numbers and account details. This information could be leveraged by malicious actors for identity theft, opening fraudulent accounts, or conducting unauthorized financial transactions. Additionally, the availability of phone numbers and addresses increases the likelihood of targeted phishing or social engineering attempts. Typically, incidents of this nature lead to heightened scrutiny of internal security policies and potential regulatory oversight. Affected individuals should monitor their financial statements closely, consider placing a credit freeze, and remain vigilant against suspicious communications. Transparency regarding the breach helps customers take proactive steps to secure their personal data. How to protect against similar security incidents Following the insider breach at TD involving sensitive financial data and social security numbers, customers should take immediate steps to secure their personal and financial information. Monitor financial accounts and credit reports. Review bank statements and credit reports for any unauthorized activity or unfamiliar transactions. Set up real-time transaction alerts on your bank accounts to detect suspicious movements immediately. Implement a credit freeze or fraud alert. Contact major credit bureaus to place a freeze on your credit file, preventing unauthorized accounts from being opened. Alternatively, place a fraud alert to ensure lenders verify your identity before extending credit. Strengthen account security with MFA. Enable multi-factor authentication (MFA) on all financial and personal accounts where available. Use phishing-resistant MFA methods, such as hardware keys or authenticator apps, rather than SMS-based codes. Deploy internal security monitoring. For organizations, implement robust internal access controls and continuous monitoring to detect anomalous employee behavior. Utilize attack surface management tools to identify and mitigate vulnerabilities across the digital infrastructure. Taking proactive measures is essential to mitigating the long-term risks associated with the exposure of sensitive personal identifiers. What happened in the TD security breach? On June 15, 2026, TD (td.com) disclosed a security breach. According to initial reports, an employee compromised the personal information of customers between January 7 and January 30, 2026, including names, social security numbers, and account details. The TD breach was publicly reported on June 15, 2026. The exact date of the attack has not been disclosed. The breach exposed customer names, physical addresses, phone numbers, dates of birth, social security numbers, bank account numbers, and transactional data. If you have a relationship with TD, there is a risk that your personal data was compromised in this breach. Because the incident involved identifiers like social security numbers and bank account details, it is important to stay alert for suspicious activity and take proactive steps to protect your financial identity. What steps should companies take after being breached? TD is investigating the incident internally, notifying affected parties, and taking measures to enhance its data protection protocols and review internal security measures.

Fedcapgroup
Londonhydro logoRansomware
Medium

London Hydro Discloses Data Breach Affecting Customer Information

Canadian electricity provider London Hydro is investigating a data breach that potentially impacted the personal and account information of its customers. London Hydro is a local distribution company serving the City of London, Ontario. It serves roughly 170,000 residential, institutional, commercial, and industrial customers. On June 20, the electricity provider announced that hackers had broken into its systems and that customers’ data was likely accessed. “London Hydro and the appropriate authorities are currently investigating a data security incident which may have impacted a portion of personal information on some accounts,” the company said . The potentially affected data includes personal information such as names, addresses, email addresses, and phone numbers. Account information, including account and billing numbers, service addresses, pricing plans, contract dates, and meter numbers and types, might have been impacted as well. Advertisement. Scroll to continue reading. According to London Hydro, no financial or other sensitive information might have been compromised in the data breach.   “The incident did not involve access to financial information or other sensitive categories of information, such as your date of birth, government identification numbers, payment card details, or banking information,” the company said. London Hydro urges customers to be wary of suspicious activity related to their accounts and personal information, including phishing messages, emails, or phone calls. It’s unclear who is responsible for the attack. No known cybercrime group appears to have taken credit for hacking London Hydro. Related: North Korean Hackers Blamed for Mastra NPM Supply Chain Attack Related: More Cybersecurity Firms Disclose Impact From Klue Hack Related: What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks Related: Texas Parks & Wildlife Data Breach Affects 3 Million Individuals Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack Clover Health Investments Discloses Data Breach Zimbra Update Patches Critical Vulnerabilities OpenSSL Silently Fixes ‘HollowByte’ DoS Vulnerability Ernst & Young Data Breach Affects Personal, Financial Information Hugging Face Hacked in Autonomous AI Attack Chrome 150 Update Patches Severe Memory Safety Bugs Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

Londonhydro
Kodak logoInfostealer
High

Kodak Confirms Data Breach After ShinyHunters Extortion Threat

24 billion stolen records exposed online. Here’s what to do A newly discovered database containing 24 billion stolen records is a reminder that personal information from data breaches, phishing campaigns, and infostealer infections continues to circulate online. The collection was exposed on the internet before being taken offline. While researchers can’t confirm exactly whose information was included, the discovery is a good opportunity to check whether your email addresses, passwords, or other personal data have already been exposed. Researchers at Cybernews found a publicly exposed database holding more than 8.3 TB of data. The data, consisting of 24 billion credential records, reportedly came from 36 sources, including numerous Telegram channels, prior breach compilations, collections of infostealer logs, and some datasets apparently exported directly from live servers. Because the data came from different sources there are some differences in what the records contain and how they are organized. Some records were structured infostealer logs containing usernames, email addresses, and plaintext passwords, and the associated login URL. Infostealers are a type of malware designed to steal sensitive information from infected devices, such as your home computer. An infostealer log from a single infected device can include passwords stored across all browsers, active session cookies and tokens (including those that bypass multi-factor authentication), autofill data, device fingerprints, and sometimes crypto wallets or messaging accounts. The complete bundle is what ends up in logs such as those seen by the Cybernews researchers. Roughly 1.7 billion of the records came from hacking-related Telegram channels, mainly English and Russian, including at least one that was focused on stolen credit card data. The exposed database was hosted on an Elasticsearch cluster. Elasticsearch is a tool used to quickly store and search lots of data. If an Elasticsearch server lacks passwords,  authentication , or network restrictions, it can be accessed by anyone who finds it online. Without protections such as passwords or a firewall, anyone can read, copy, change, or even delete its data. Other documents in the dataset contained information about known vulnerabilities, articles about breaches, and social media posts about cyberattacks. This suggests the owner actively monitors security news and vulnerabilities and enriches the credential hoard with fresh breach information, either for a commercial “monitoring” service or for offensive use. A few years ago, we wrote about what was called the “mother of all breaches,” where the source of the dataset was later identified as data breach search engine Leak-Lookup. This newly discovered 24 billion record exposure is in the same league as that previous mega‑dump, but appears more heavily weighted toward fresh infostealer logs, rather than older, static breach data. Since the data was taken out of public view soon after the discovery, the researchers were unable to fully retrace everything they had found or determine how many duplicate records it contained. That’s reassuring because it reduces the chances of cybercriminals finding the database, but reused passwords may still put accounts at risk. And we still don’t know the purpose for the data collection in the first place. It’s good to be aware of how much information about you is out there and who’s gathering it, but it’s even more important to know exactly which information they have, since that is what they can use against you. 1. Check if your data has been exposed online using our Digital Footprint Portal . 2. If you discover exposed passwords, change them immediately and make sure you aren’t reusing the same password across multiple accounts. Prioritize updating your important accounts such as email, banking, shopping, and social media accounts. 3. Turn on multi-factor authentication (MFA) wherever possible, since it can help protect accounts even if a password has been exposed. Infostealers often spread through malicious ads, fake browser updates, and one-click downloads. Avoid clicking sponsored ads, and instead visit official websites directly. Download software only from trusted sources such as official vendor sites or app stores. Another increasingly popular technique is  ClickFix , a social engineering attack that tricks users into infecting their own devices. Never run commands or scripts copied from websites, emails, or messages unless you trust the source and understand what they do. Pirated software, game cheats, cracked tools, and shady browser extensions remain common sources of infostealer infections. Stick to reputable software and extensions, and be wary of anything asking for excessive permissions. Lastly, phishing emails are still a major threat. Be cautious of unexpected attachments, links, and urgent requests. If you’re unsure whether a message is legitimate, verify it through the company’s official website rather than the link in the message. You can also use Malwarebytes Scam Guard to check individual messages. Just upload a screenshot and we’ll let you know if it’s a scam. Breaches happen every day. Don’t be the last to know. President Gives China Gift Towards AI Leadership CISA Issues BOD on Patching Because, Apparently, Agencies Don’t Patch Is Your AI Infrastructure Ready for AI in Production? Claude Fable 5 – their most powerful model ever released to the public Are AI agents the new weakest link in the security chain? Our MSP has one userid that they share across their techs. Is this okay? Cyber Insurance Rates Down, but so is Coverage Is this the new norm thanks to AI? Microsoft releases over 200 patches this week Oracle Warns of Bug That Hackers Used to Breach Over 100 Companies OOPSIE. Japanese Energy Firm LOSES Drive with 10.9 Million Client’s Data Prez says he is considering “investing” in AI companies People becoming more thoughtful about AI UK tells big tech to block nudes – in 3 months Security News for the week ending June 12, 2026 – EU turns to Russian alternative to Microsoft Office, former twitter engineer who warned about Grok’s safety was fired and is now suing, Senate votes to not create new Pentagon branch, Cyber Force, feds shut down a couple of deep fake porn sites – call it groundbreaking and FISA section 702 lapses (lapsed) at Midnight (Friday).

Kodak
Tchap logoInfostealer
Medium

French Government Messaging Service Tchap Breached via Hijacked Account

More 70,000 French government employees had personal details stolen. Why and by whom? On June 8, 2026, DINUM announced that the official French government chat service (Tchap) had been breached on June 7. At the same time, a threat actor calling itself ‘ misere ’ claimed responsibility. DINUM is the French government’s interministerial digital directorate in charge of Tchap.  Tchap is a ‘secure’ sovereign instant messaging service for French government employees designed to combine the principle of data sovereignty with increased security over third-party foreign systems. It includes secure chat rooms that are end-to-end encrypted, and ‘public’ chat rooms that are not encrypted. Misere is… unknown. There is no public record of a threat actor known as ‘misere’. DINUM says the system was compromised following account hijacking, and states, “Of the more than 825,000 registered agents, 73,467 are reportedly affected by this incident, representing less than 9% of registered users.” Advertisement. Scroll to continue reading. Misere supposedly claimed almost precisely the same: theft of more than 70k accounts (aligning with DINUM’s statement); but added that it stole 13.5GB of files across more than 643,000 messages. However, we cannot verify misere’s claim because it was reported rather than published by the OSINT FrenchBreaches community, and the original misere claim is not or no longer available on the internet. So, we’re left with a conundrum. An official announcement states the breach occurred (not was discovered but occurred) on June 7 and was limited to 9% of the users. Classic, but not inaccurate, downplaying. But almost immediately, an unknown threat actor agrees with the number of affected accounts but claims theft of 13.5GB of actual data. We cannot verify this latter detail since we only have reports of a report – but if we assume accuracy and honesty, is it realistic to believe that this amount of data can be gathered and exfiltrated in a single day by an otherwise unknown threat actor? For additional insights into the cause and effect, we talked to Ilia Kolochenko , a qualified attorney, and CEO, founder and chief architect at ImmuniWeb. ImmuniWeb operates a dark web monitoring and threat intelligence service for its clients and sees thousands of different incidents daily. Could misere be a pseudonym adopted by a state actor for this small and relatively innocuous breach – for example, Russia embarrassing France over its pro Ukraine position; or the US doing the same for its anti-Iran war position? Kolochenko doesn’t think so, “Because it’s a little trivial. This is too small for large power intelligence agencies to bother with.” Before 2024, he had seen state actors compromise systems and rapidly act on the compromise. “But since 2024,” he continued, “state actors tend to infiltrate and lay low. What is alarming now is a new trend with state actors breaching critical national infrastructure and its suppliers silently. They just backdoor everything to get control of a nation’s infrastructure. They just go deeper and deeper and deeper, trying to get access to as many critical systems as possible.” The motivation is to pre-position with the ability to bring down multiple if not all the critical industries in an enemy nation simultaneously. This is cyberwar in preparation for or defense against a possible kinetic war. Nor does he think that the suggestion that the breach was an account take-over event is informative. It could be as simple as a hacker getting the credentials from stealer logs; but if it were an advanced hacker, that would not be necessary. “In today’s cloud and AI world, you don’t need to steal cookies with infostealers. You don’t need zero days. You just send a legitimate request to an API, and you’ll get all the records of a governmental institution or a private company, and everything will be on your hard drive within several hours.” Such an hypothesis could explain how misere could exfiltrate 3.5GB on the same day as the breach was discovered. Does the name misere give any clue to the actor or motivation? Again, no. “The name given to this actor is meaningless,” suggested Kolochenko. “Sometimes a hacker or group wants to protect a reputation for doing more meaningful hacks and adopts a ‘burner’ identity. Sometimes one group will impersonate another group that might be considered a rival or affiliated with a different adversarial nation.” The fact that the name is unknown does not mean that the actor is unknown. Overall, this attack by an unknown hacker against a secure government chat system does not present itself as an APT attack. But that could even be the purpose. After all, it involves 70,000 government employees. DINUM specifies in its breach disclosure announcement, “The potentially exposed user account data includes, at a minimum: first and last name, email address, affiliated entity, and avatar.” The affiliated entity would expose which government department is involved, the email address is provided, and Misere further claimed to have scraped 640,000 (plaintext) chat messages. This combination would be a treasure trove for subsequent targeted spear-phishing, valuable to both financially motivated cyber gangs and state actors ultimately targeting not Tchap but the ministries employing the Tchap users. But – and this is the point of this discussion – we just don’t know the truth: everything is conjecture. Frankly, trying to understand the cause and motivation behind any cyber incident is based on conjecture with little known truth. Related : Maine Disables Data Breach Portal Due to Fake Submissions Related : University of Nottingham Confirms Breach After Hackers Leak Data Related : 174,000 Impacted by Lansing Community College Data Breach Related : Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Tchap
Dinum logoPhishing
Medium

French government messaging platform Tchap breached via compromised user account

DINUM, the French government's digital affairs directorate, warned that hackers breached Tchap, France's encrypted messaging platform for public sector workers, using a compromised user account. The incident was detected by ANSSI, after which the affected account was blocked and an investigation launched into what conversations and data may have been accessed. DINUM has notified France's data protection authority, CNIL, due to the potential exposure of personal data. A threat actor claimed responsibility, alleging they used social engineering to access an education-related account and scrape messages, account information, and files, including 13.5GB of data from the French tax authority and other civil servants.

Dinum
Nottingham logoRansomware
Medium

University of Nottingham Data Breach Affects Over 450,000 Students

The University of Nottingham in the UK has confirmed suffering a data breach after the notorious ShinyHunters hacker collective leaked files stolen from the university’s systems. The University of Nottingham is a major research university in the UK, ranked among the world’s top 100 institutions and home to more than 35,000 students on its UK campuses, plus thousands more at its international branches in China and Malaysia. The ShinyHunters group listed the organization on its leak website and published gigabytes of files allegedly stolen from its systems. The hackers claimed to have obtained financial information pertaining to all of the university’s campuses.  University of Nottingham hacked by ShinyHunters An analysis of the leaked files by the account breach notification service Have I Been Pwned showed that they contain roughly 455,000 unique email addresses, along with other types of personal information such as usernames, names, addresses, phone numbers, passport numbers, genders, and details on ethnicity, disabilities, academic enrolment, c itizenship status, and fee payments. In a statement issued on Wednesday, the University of Nottingham confirmed that hackers accessed “a significant amount of data” in its student record system. The university says the data breach impacts current students and alumni. “We are working to understand the data that has been accessed and have contacted those students and alumni affected directly. We are working closely with Action Fraud, the Information Commissioner’s Office, and other regulatory bodies,” the organization said.  Advertisement. Scroll to continue reading. Related : Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools Related : 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Related : 3.5 Million Affected by University of Phoenix Data Breach Related : University of Sydney Data Breach Affects 27,000 Individuals Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches — And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. For the latest discoveries in cyber research for the week of 15th June, please download our Threat Intelligence Bulletin. The University of Nottingham, a UK research university, has suffered a data breach after ShinyHunters accessed its student records system. The incident affected about 454,600 current and former students and exposed contact details, passport numbers, enrollment information, and fee payment records later appeared online. According to analysts, this breach is part of a larger wave of attacks targeting more than 100 organizations by ShinyHunters, exploiting CVE-2026-35273, a critical zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Check Point IPS provides protection against this threat (Oracle PeopleSoft Enterprise PeopleTools Server-Side Request Forgery (CVE-2026-35273)) Mackay Sugar, Australia’s second-largest sugar producer, has been hit by a cyberattack that disrupted operations and shut down its Farleigh and Racecourse mills in Queensland. The company instructed growers to stop harvesting and suspended cane haulage while temporary measures were deployed to maintain essential operations. Danish pharmaceutical giant Novo Nordisk has disclosed a breach after attackers accessed internal IT systems and copied pseudonymized clinical trial data from research systems. The exposed information included patient IDs, trial participation details, limited health data, and some healthcare professionals’ contact information. Check Point Research has demonstrated exploitable flaws in LangGraph, an open-source framework for stateful AI agents. Researchers chained SQL injection and unsafe deserialization issues to achieve remote code execution, with patches issued for SQLite, core, and Redis checkpointer components in affected deployments. Check Point IPS provides protection against this threat (LangChain LangGraph SQL Injection (CVE-2026-27022)) Researchers highlighted a China-based phishing-as-a-service network, Outsider, that allegedly used Gemini to generate fake websites and support SMS phishing campaigns. Google filed a lawsuit after linking the operation to thousands of phishing sites, more than 1.5 million URLs, and large-scale victim targeting. Researchers warned that prompt-injection attacks against Anthropic’s Claude Code GitHub Action could leak CI/CD workflow secrets. Malicious issue or pull request text can instruct the agent to read environment variables and expose API keys, enabling workflow abuse and impersonation inside software repositories. Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. Attacks began in May and increased in early June, affecting a limited number of organizations, with one case tied to Qilin ransomware activity. Check Point IPS provides protection against this threat (IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751)) Microsoft released its largest Patch Tuesday update to date, addressing more than 200 Windows and Defender vulnerabilities amid an AI-driven surge in vulnerability discovery. The fixes include CVE-2026-45657, a critical Windows flaw with a CVSS score of 9.8 that could enable network-based propagation, CVE-2026-41091, which has been actively exploited to gain full system control, and CVE-2026-50507, a BitLocker bypass vulnerability.

Nottingham
Numerique logoInfostealer
Medium

French Government Messaging Service Tchap Compromised

More 70,000 French government employees had personal details stolen. Why and by whom? On June 8, 2026, DINUM announced that the official French government chat service (Tchap) had been breached on June 7. At the same time, a threat actor calling itself ‘ misere ’ claimed responsibility. DINUM is the French government’s interministerial digital directorate in charge of Tchap.  Tchap is a ‘secure’ sovereign instant messaging service for French government employees designed to combine the principle of data sovereignty with increased security over third-party foreign systems. It includes secure chat rooms that are end-to-end encrypted, and ‘public’ chat rooms that are not encrypted. Misere is… unknown. There is no public record of a threat actor known as ‘misere’. DINUM says the system was compromised following account hijacking, and states, “Of the more than 825,000 registered agents, 73,467 are reportedly affected by this incident, representing less than 9% of registered users.” Advertisement. Scroll to continue reading. Misere supposedly claimed almost precisely the same: theft of more than 70k accounts (aligning with DINUM’s statement); but added that it stole 13.5GB of files across more than 643,000 messages. However, we cannot verify misere’s claim because it was reported rather than published by the OSINT FrenchBreaches community, and the original misere claim is not or no longer available on the internet. So, we’re left with a conundrum. An official announcement states the breach occurred (not was discovered but occurred) on June 7 and was limited to 9% of the users. Classic, but not inaccurate, downplaying. But almost immediately, an unknown threat actor agrees with the number of affected accounts but claims theft of 13.5GB of actual data. We cannot verify this latter detail since we only have reports of a report – but if we assume accuracy and honesty, is it realistic to believe that this amount of data can be gathered and exfiltrated in a single day by an otherwise unknown threat actor? For additional insights into the cause and effect, we talked to Ilia Kolochenko , a qualified attorney, and CEO, founder and chief architect at ImmuniWeb. ImmuniWeb operates a dark web monitoring and threat intelligence service for its clients and sees thousands of different incidents daily. Could misere be a pseudonym adopted by a state actor for this small and relatively innocuous breach – for example, Russia embarrassing France over its pro Ukraine position; or the US doing the same for its anti-Iran war position? Kolochenko doesn’t think so, “Because it’s a little trivial. This is too small for large power intelligence agencies to bother with.” Before 2024, he had seen state actors compromise systems and rapidly act on the compromise. “But since 2024,” he continued, “state actors tend to infiltrate and lay low. What is alarming now is a new trend with state actors breaching critical national infrastructure and its suppliers silently. They just backdoor everything to get control of a nation’s infrastructure. They just go deeper and deeper and deeper, trying to get access to as many critical systems as possible.” The motivation is to pre-position with the ability to bring down multiple if not all the critical industries in an enemy nation simultaneously. This is cyberwar in preparation for or defense against a possible kinetic war. Nor does he think that the suggestion that the breach was an account take-over event is informative. It could be as simple as a hacker getting the credentials from stealer logs; but if it were an advanced hacker, that would not be necessary. “In today’s cloud and AI world, you don’t need to steal cookies with infostealers. You don’t need zero days. You just send a legitimate request to an API, and you’ll get all the records of a governmental institution or a private company, and everything will be on your hard drive within several hours.” Such an hypothesis could explain how misere could exfiltrate 3.5GB on the same day as the breach was discovered. Does the name misere give any clue to the actor or motivation? Again, no. “The name given to this actor is meaningless,” suggested Kolochenko. “Sometimes a hacker or group wants to protect a reputation for doing more meaningful hacks and adopts a ‘burner’ identity. Sometimes one group will impersonate another group that might be considered a rival or affiliated with a different adversarial nation.” The fact that the name is unknown does not mean that the actor is unknown. Overall, this attack by an unknown hacker against a secure government chat system does not present itself as an APT attack. But that could even be the purpose. After all, it involves 70,000 government employees. DINUM specifies in its breach disclosure announcement, “The potentially exposed user account data includes, at a minimum: first and last name, email address, affiliated entity, and avatar.” The affiliated entity would expose which government department is involved, the email address is provided, and Misere further claimed to have scraped 640,000 (plaintext) chat messages. This combination would be a treasure trove for subsequent targeted spear-phishing, valuable to both financially motivated cyber gangs and state actors ultimately targeting not Tchap but the ministries employing the Tchap users. But – and this is the point of this discussion – we just don’t know the truth: everything is conjecture. Frankly, trying to understand the cause and motivation behind any cyber incident is based on conjecture with little known truth. Related : Maine Disables Data Breach Portal Due to Fake Submissions Related : University of Nottingham Confirms Breach After Hackers Leak Data Related : 174,000 Impacted by Lansing Community College Data Breach Related : Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Numerique
Charter logoMisconfiguration or publishing error
Medium

Charter Communications Data Breach by ShinyHunters Exposes Millions of Records

Telecommunications giant Charter Communications (Spectrum) suffered a data breach attributed to the ShinyHunters hacking group. The group posted data on a dark web leak site after ransom negotiations failed. While Charter stated no sensitive data was stolen, ShinyHunters claimed to have released 42 million records, including 13 million customer records and nearly 27,000 employee records. The compromised data allegedly includes full names, email addresses, home and company addresses, and support ticket details for customers, and work emails, job titles, and home addresses for employees. The initial breach occurred around April 1, 2026, via a vishing attack on an employee's Microsoft Entra account, with the data leak and significant reporting occurring on June 5, 2026.

Charter
Carnivalcorp logoPhishing
Medium

Carnival Cruise Lines Data Breach Exposes Information of Nearly 6 Million Passengers

Carnival Cruise Lines disclosed a data breach affecting nearly 6 million passengers. The breach was discovered in mid-April 2026 after an employee fell victim to a social engineering attack, granting hackers access to the company's IT system. Although Carnival acted quickly, attackers managed to steal significant customer information, including names, addresses, contact information, birth dates, and government ID numbers (such as passport and driver's license numbers). Affected passengers are being notified and offered credit monitoring. While an initial disclosure may have occurred in late May, new details and significant reporting made this a top headline on June 5, 2026.

Carnivalcorp

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently classified as phishing & social engineering. Counts describe this reporting set, not overall incident prevalence.

Which Shadow Tier articles add context?

Questions answered

Questions about phishing & social engineering

What is the difference between phishing and social engineering?

Social engineering is the broader manipulation technique; phishing is a common delivery method using deceptive digital communications or websites.

Phishing can be broad or highly targeted, while social engineering also includes phone calls, impersonation, physical approaches and abuse of trusted processes. Understanding the requested action is often more useful than focusing only on the communication channel.

How does spear-phishing differ from mass phishing?

Spear-phishing uses details about a selected person or organization, while mass phishing sends a more generic lure to many recipients.

Targeted messages may reference real colleagues, suppliers, projects or tools, making simple visual cues less reliable. Controls should combine secure authentication, independent verification and rapid reporting with technical detection of unusual identity and mailbox activity.

What is business email compromise?

Business email compromise is fraud or intrusion that abuses a trusted business identity or mailbox to manipulate payments, data or access.

The attacker may compromise a real account or imitate one convincingly. Payment-change, invoice, payroll and executive requests are common scenarios, so organizations need verification controls that remain effective even when a message appears to come from a legitimate mailbox.

Which employees are most exposed to social-engineering attacks?

People who can approve payments, reset access, manage sensitive information or act with executive authority face especially consequential targeting.

Exposure is determined by process authority as well as job title. Mapping high-impact actions to roles, verification requirements and escalation routes helps teams focus protection on the decisions an attacker is most likely to manipulate.

What signs can reveal a sophisticated phishing attempt?

Signals include unexpected authentication, subtle domain changes, unusual urgency, changed transaction details and requests that bypass established channels.

Well-crafted messages may have perfect spelling and familiar branding. Recipients need a safe way to pause and verify the requested action, while defenders correlate reported messages with domain, mailbox, identity and endpoint evidence.

How should a company respond after credentials are phished?

Revoke active sessions and tokens, reset affected factors, inspect identity and mailbox changes, and investigate any access performed with the account.

Changing a password alone may leave sessions, application grants, forwarding rules or enrolled authentication methods under attacker control. Response should establish the access window and examine connected systems for persistence or data activity.

Which controls reduce phishing and social-engineering risk?

Phishing-resistant authentication, independent transaction verification, protected help-desk processes and fast reporting reduce both likelihood and impact.

Training supports recognition but should not be the only barrier. Durable protection makes high-impact actions difficult to complete from one message or one compromised identity and gives responders the telemetry needed to contain mistakes quickly.