Skip to main content

Tag: account takeover

65 articles

Person sitting at laptop in quiet home office with blurred screen.

Anthropic Disrupts AI Token Mining by Hijacked User Accounts

Anthropic swiftly took action against compromised accounts, logging users out and removing payment methods to prevent stolen sessions from being exploited for paid AI usage. The company assured users that its investigation found no link between the malware and its AI model, Claude.

Analyst 207
A generic login screen on a laptop in a quiet, institutional setting with soft daylight.

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover

A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

Analyst 207
Blurred laptop screen on cluttered office desk with hand hovering over keyboard.

AI Compresses Identity Attacks, Forces Device Trust Reassessment

Identity security is buckling under the strain of increasingly sophisticated threats, with stolen credentials remaining a top vulnerability - a whopping 44.7% of breaches involve compromised login details. AI is now compressing the time and effort attackers need to launch identity attacks, forcing a urgent reevaluation of device trust.

Analyst 207
Laptop and smartphone on cluttered desk with blurred screen and malware code on nearby paper.

Malware Exploits Google Passkey Ecosystem for Account Takeover

Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

Analyst 207
Smartphone on a plain surface with a blurred background and a hint of a computer screen.

Illinois Hacker Sentenced for Exploiting Snapchat Accounts

A 26-year-old Illinois man, Kyle Svara, has been sentenced to 76 months in prison for hacking over 750 Snapchat accounts, using social engineering tactics to phish access codes and trading stolen images online. He'll also face three years of supervised release after serving his time.

Analyst 207
Busy Chick-fil-A restaurant with customers, phone and laptop on table.

Chick-fil-A Exposes Customer Data in Credential Stuffing Breach

Chick-fil-A is alerting customers to a credential stuffing breach that compromised some of its website and mobile app accounts between June 17 and June 19, 2026, using stolen account credentials from a third-party source. If you have a Chick-fil-A One account, you should check your email for a notification from the company and take immediate action to secure your account.

Analyst 207
Law enforcement officials stand near seized computer equipment in a brightly lit facility.

Authorities Disrupt Kratos Phishing Platform in Global Operation

In a major global crackdown, authorities have shut down Kratos, a notorious phishing-as-a-service platform that helped cybercriminals create fake Microsoft login pages to steal sensitive info. The takedown has disrupted a key tool used by over 1,800 customers to commit crimes like business email compromise and data theft.

Analyst 207
Laptop screen with blurred interface on a neutral background, faint network cable visible.

Zoom Patches Flaw That Could Enable Account Takeover

Zoom just patched a critical security flaw that could let hackers hijack your account - and you need to update your software ASAP to stay safe! This vulnerability, tracked as CVE-2026-53412, could allow anyone on your network to take over your Zoom account.

Analyst 207
Cluttered office desk with a brightly-lit Windows desktop computer and blurred laptop screen in the background.

Zoom Discloses High-Severity Account Takeover Vulnerability

Zoom has warned users of a high-severity vulnerability in its Windows desktop client and software development kit that could let hackers hijack accounts without authentication. This critical flaw, tracked as CVE-2026-53412, has a severity score of 9.8 out of 10.

Analyst 207
Person sitting at desk with laptop, hands poised over keyboard in modern office setting.

Account Takeover Attacks Target Verification Step as New Battleground

As more people and companies switch to passkeys, a new battleground emerges in the fight against account takeover attacks - the verification step. Attackers are now targeting these previously trusted processes, like account recovery and device re-enrollment, to gain control of accounts.

Analyst 207
Bank teller sits at desk with laptop, hinting at security vulnerability.

Banks Expose Accounts to Thieves by Making MFA Optional

Leaving multi-factor authentication optional has left countless bank accounts vulnerable to theft, with devastating consequences - just ask the 84-year-old victim who lost nearly $30,000 when thieves exploited this security gap. By making MFA optional, banks are inadvertently rolling out the red carpet for thieves.

Analyst 207
Texas Parks and Wildlife Department office with subtle digital system hint.

Texas Hunting License Data Breach Exposes Millions

A recent data breach at the Texas Parks and Wildlife Department may have exposed over three million hunting and fishing license customers, putting sensitive information like driver's license numbers and passport data at risk of being used for account takeover, synthetic identity fraud, and targeted phishing. This breach is just the beginning, as stolen data can be used for a range of malicious activities.

Analyst 207
Cramped, dimly lit room with cluttered desk, laptop, and scattered papers, surrounded by old computer equipment.

Threat Actors Monetize Stolen Credentials with Searchable Underground Services

Cybercriminals are cashing in on stolen credentials with a new breed of underground services that allow buyers to search and purchase specific, verified login details. This emerging market acts as a middleman between hackers who steal sensitive info and those who want to use it to take over accounts.

Analyst 207
Rows of rack-mounted servers with a network administrator in the background.

phpBB Flaw Enables Instant Account Takeover

A single HTTP request can give an attacker instant access to any user's account, including administrator accounts, without needing a password - a vulnerability rated 9.4 on the CVSS scale that's affecting phpBB versions up to 3.3.16 and 4.0.0 alpha.

Analyst 207
Smartphone on a neutral surface with blurred cityscape or office background.

Meta Exposes Flaw in AI Support System Used to Hijack 20,000 Instagram Accounts

Meta revealed that over 20,000 Instagram accounts were hijacked after attackers exploited a vulnerability in its AI-powered support system, allowing them to reset passwords and gain unauthorized access. The flaw was found in a system called High Touch Support, an AI-assisted account recovery tool designed to help users regain control of their accounts.

Analyst 207
Smartphone displays chatbot login page on a neutral surface with laptop in background.

Meta's AI Chatbot Exposed to Account Takeover Vulnerability

A recent vulnerability in Meta's AI chatbot has raised red flags about the security of LLM chatbots, which can be exploited through various tactics that are difficult to block. This alarming weakness was demonstrated in a video showing an attacker taking over an Instagram account by simply interacting with Meta's AI support chatbot.

Analyst 207

Meta AI Exploited to Hijack High-Value Instagram Accounts

A shocking security breach has hit Instagram, where hackers exploited Meta's AI-powered support system to hijack high-value accounts, leaving users helpless and zero humans in the loop to fix the issue. Attackers cleverly tricked Meta's AI into thinking they were the legitimate owners by using an AI-generated video, bypassing automated checks and taking control of rare or valuable accounts.

Analyst 207
Smartphone displaying a login page on a neutral surface with a blurred office background.

Hackers Exploit Meta's AI Bot to Hijack Instagram Accounts

This weekend, hackers exploited a vulnerability in Meta's AI-powered customer support tool to hijack high-profile Instagram accounts, highlighting the platform's notoriously poor human support infrastructure. A simple sequence of steps, documented in a video circulated on Telegram, allowed attackers to add a new email address to an account and seize control.

Analyst 207
Laptop and smartphone with blurred interfaces sit on a desk in a bright office space surrounded by paperwork.

Zapier Fixes Bug Chain That Exposed Millions to Account Takeover Risk

A security firm recently uncovered a chain of five weaknesses in popular workflow automation service Zapier that could have put millions of users at risk of account takeover - and thankfully, the issue has now been fixed. The vulnerabilities were surprisingly easy to exploit, requiring only a free Zapier account to potentially gain unauthorized access to user accounts.

Analyst 207
Laptop on office desk with papers and supplies, subtle hint of phishing attempt nearby.

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Accounts

Beware of Kali365, a sneaky phishing service that's hijacking Microsoft 365 accounts by exploiting a legitimate authentication flow - and it's happening fast, with the platform emerging as recently as April 2026. This clever trick uses a short code to trick victims into handing over control of their accounts.

Analyst 207
Non-profit office workspace with computer workstation hinting at digital vulnerability.

GoDaddy Domain Transfer Exposes Non-Profit to Security Risks

A shocking security breach occurred when a 27-year-old domain was transferred from a GoDaddy account to another customer without any authentication checks, putting a non-profit at risk. The alarming transfer was completed in just four minutes, raising serious concerns about GoDaddy's domain transfer process.

Analyst 207
Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Multifaceted Phishing Scheme Stunningly Damages Bitpanda

Thousands of Bitpanda users are reeling after a sophisticated phishing campaign spun up convincing lookalike sites—with disposable domains and SSL certificates—to harvest credentials and fuel criminal markets. The attack shows how industrialized phishing‑as‑a‑service turns takedown efforts into whack‑a‑mole, leaving customers, companies and regulators scrambling to restore digital trust.

Analyst 207
Chrome extensions Exclusive: Malicious AI steal API keys

Chrome extensions Exclusive: Malicious AI steal API keys

Before you add that shiny AI assistant to Chrome, pause: researchers found 30+ extensions secretly siphoning API keys, emails and other sensitive data from hundreds of thousands of users. What promised convenience turned into a fast track for credential theft and account takeover.

Analyst 207
Password Reuse: Exclusive Risks of Effortless Workarounds

Password Reuse: Exclusive Risks of Effortless Workarounds

Password reuse is the digital equivalent of leaving a master key under the mat—effortless workarounds and recycled credentials give attackers a straightforward path to account takeover. Even helpful conveniences like autofill and brittle browser extensions can betray reused passwords, turning everyday browsing into a security shortcut.

Analyst 207