According to a report by threat intelligence firm Hudson Rock, the initial access was likely gained using employee credentials harvested by prevalent info-stealing malware like RedLine, Lumma, and Vidar, often delivered via malvertising or "ClickFix" attacks.
The alleged leak included Salesforce API keys, Jira tokens, and source code from over 10 databases. A screenshot displayed data structures but lacked clear links to NordVPN's production systems.
The Crimson Collective asserted in late December that it had accessed and stolen the personal information of more than 1 million Brightspeed customers.
Cognizant Technology Solutions has been accused of failing to properly secure sensitive healthcare data and waiting nearly a year to notify affected individuals in the multiple US class-action lawsuits filed following a data breach at its TriZetto Provider Solutions subsidiary, reports GBHackers News.
SecurityWeek reports that Massachusetts-based Covenant Health had data from 478,188 people stolen in a May data breach previously claimed by the Qilin ransomware gang.
Major U.S. electric utilities American Electric, Duke Energy Florida, and Tampa Electric Company had nearly 139 GB of engineering data purportedly pilfered following a cyberattack against Florida-based engineering firm Pickett and Associates peddled for 6.5 bitcoin, or nearly $585,000, The Register reports.
The researcher, operating anonymously, infiltrated WhiteDate and utilized a custom AI chatbot for social engineering to extract over 8,000 user profiles and approximately 100 GB of data.