Skip to main content

Tag: data exfiltration

158 articles

Two men in formal attire stand in a courtroom with electronic devices on a table, surrounded by subtle police emblems and…

Australia Charges Two in TeamPCP Cybercrime Case Tied to Supply Chain Attacks

In a major breakthrough, the Australian Federal Police charged two men with 14 offences for their alleged roles in the notorious TeamPCP cybercrime syndicate, which compromised over 1,000 organizations worldwide and stole more than 500,000 credentials. The suspects, aged 23 and 21, were arrested and appeared in court after a joint operation seized electronic devices for forensic analysis.

Analyst 207
Devices scattered on a graffiti-covered wall, connected by faint lines suggesting Bluetooth or Wi-Fi signals.

Manic Android Malware Exploits Nearby Devices for Data Exfiltration

Meet Manic, a sneaky new Android malware that's using a clever fallback strategy to steal sensitive data from nearby devices, even when they have no internet connection. It captures credentials and in-app secrets by combining spyware, banking fraud, and remote-control capabilities into one powerful payload.

Analyst 207
Rows of racked servers and storage equipment in a brightly-lit data center with IT staff in the background.

Azure Exfiltration Campaign Exposes 3.6 Million Records

A shocking data breach has hit major players like McDonald's and Gap Inc., with a hacker claiming to have made off with a staggering 3.6 million Azure account records, including 1.7 million sensitive employee records from McDonald's alone. The breach exposes names, emails, addresses, and more, serving as a stark reminder that traditional security perimeters just aren't enough.

Analyst 207
Brightly-lit industrial control system terminal on a rack in a factory setting.

Clop Ransomware Operation Exploits Windchill Flaw with Custom Web Shell

The Clop ransomware operation has exploited a critical flaw in PTC Windchill and FlexPLM servers, deploying a custom web shell that allows for easy credential theft and massive data exfiltration. This sneaky move gives attackers a direct path to sensitive data, with no extra tools needed.

Analyst 207
Dimly lit server room with multiple computer servers, network equipment, and monitors.

Microsoft Uncovers 30+ Domains Linked to MacSync Stealer Infrastructure

Microsoft's investigation has uncovered a sneaky operation: over 30 domains are secretly linked to MacSync Stealer, a notorious macOS information stealer, and are actively siphoning off sensitive data. The company confirmed that data exfiltration is happening in real-time, not just sending out distress signals.

Analyst 207
Laptop on a desk with a blurred background and a suspicious link on paper.

Microsoft Copilot Flaws Expose One-Click Data Exfiltration Risk

Researchers uncovered a set of flaws in Microsoft Copilot, dubbed CoSnitch, that could allow attackers to exploit a user's session with just one click, potentially leading to data exfiltration. A single crafted link could trigger actions inside a signed-in user's assistant session, putting sensitive information at risk.

Analyst 207
Blurred office interior with rows of workstations and a single laptop screen on a desk.

Wesco Probes Data Exfiltration After ExfilSquad Leak Claim

Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.

Analyst 207
Developer workstation with laptop and monitor on a clean desk, code editor open on screen.

Open VSX Eradicates Malicious Extensions Exfiltrating Developer Data

A shocking discovery by Manifold Security revealed that 77 malicious extensions on Open VSX were secretly siphoning off sensitive data from developers' machines between July 26 and August 1, 2026. These fake extensions, masquerading as legitimate tools, were swiftly removed by Open VSX on August 3, 2026.

Analyst 207
Developer workstation with laptop and monitor showing code, hinting at vulnerability.

Open VSX Extensions Exfiltrate Developer Data in "Evil Twin" Campaign

Beware of fake developer tools on Open VSX! A recent "evil twin" campaign revealed 77 malicious extensions that masqueraded as legitimate tools, secretly collecting and transmitting sensitive data about your system and development environment.

Analyst 207
Medical office setting with scattered records and equipment, laptop on desk in foreground.

Amgen Discloses Cloud Data Breach Exposing Patient Health Info

Amgen recently discovered a cloud data breach that compromised patient health information, prompting immediate action to contain and investigate the incident. The breach, detected in July 2026, involved unauthorized access to multiple cloud systems operated by third-party service providers, resulting in the theft of sensitive data, including proprietary information and protected health records.

Analyst 207
Hospital corridor with people walking, subtle hint of digital setup in foreground.

Craneware Data Breach Exposes Healthcare Sector Risks

A recent data breach at Craneware, a software provider for healthcare, has exposed the sector to new risks, highlighting that the initial compromise is just the beginning of a larger story. The breach, which involved unauthorized access to a subset of data, has already revealed a significant volume of sensitive file names were viewed and exfiltrated.

Analyst 207
Rows of file cabinets and servers in a brightly-lit data storage area with scattered papers on a nearby table.

Craneware Discloses Data Theft in Cyber Incident

A recent cyber incident at healthcare finance software provider Craneware exposed a significant volume of sensitive data, including customer and business partner records, highlighting the ease with which determined attackers can carry out data exfiltration. Even seemingly low-severity incidents can pose a real risk of data exposure.

Analyst 207
Rows of computer servers and network equipment in a dimly lit server room with organized cables and wires.

GoSerpent Malware Evolves with Advanced Data Exfiltration Tactics

In late 2025, a new wave of malicious activity emerged, led by the evolved GoSerpent malware, which has been quietly lurking in the shadows since at least 2021. This stealthy backdoor has upgraded its data exfiltration tactics, putting organizations on high alert.

Analyst 207
Person working on laptop in cozy setting with Terminal window open.

macOS Malware Exploits User Trust to Steal Sensitive Data

Beware of a sneaky new macOS malware that tricks you into stealing your own sensitive data - all it needs is for you to paste a single command into Terminal. Dubbed ClickLock Stealer, this clever con artist has already duped at least 100 victims across 33 countries.

Analyst 207
Help desk area with technician and employees in a retail setting.

FBI Traces Scattered Spider Hacker via Persistent Windows Device ID

In a brazen ransom email, the attackers boldly declared, "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY," leaving no doubt about their malicious intentions. The hackers infiltrated the retailer's network through a clever help-desk ploy, tricking staff into resetting passwords and gaining control of critical accounts.

Analyst 207
Laptop screen shows generic browser homepage with subtle hint of malicious mod installation in background.

Opera GX Flaw Enables Sites to Auto-Install Malicious Mods

A critical flaw in Opera GX allowed websites to secretly install malicious customization mods, which could then siphon sensitive data from other sites you visited - and it took a $5,000 bounty and a May 8 patch to fix the issue. This sneaky exploit let attackers install mods without your consent, putting your online security at risk.

Analyst 207
Close-up of a video cable connected to a monitor with blurred background.

TrojPix Exploits Video Cables to Leak Air-Gapped Data

Meet TrojPix, a sneaky technique that can stealthily siphon air-gapped data at lightning-fast speeds of up to 1 megabyte per second - fast enough to exfiltrate a 100MB file in under two minutes while the monitor appears dark and inactive.

Analyst 207
Laptop on a desk in a modern office with a blurred screen and subtle shadow.

Microsoft Warns AI Agents Can Leak Data via Poisoned Tool Descriptions

A single line of plain text can unwittingly turn a helpful AI agent into a stealthy data thief, exposing sensitive information through a vulnerability in the Model Context Protocol (MCP). This fast-growing attack surface has Microsoft warning of a potentially disastrous trust boundary breach.

Analyst 207

UK Cyber Monitoring Centre Probes Canvas Breach Impact

The UK's Cyber Monitoring Centre is investigating a massive breach of Canvas, a popular learning management system, that exposed sensitive data at nearly 160 UK universities and colleges, as part of a global incident affecting around 9,000 educational institutions. The breach was caused by a notorious cybercrime group that exploited vulnerabilities on April 29 and again on May 7.

Analyst 207
Laptop screen displays Microsoft 365 Copilot interface in office setting.

Microsoft 365 Copilot Flaw Exposes Sensitive Data to One-Click Attack

A single click on a seemingly trustworthy Microsoft link could have put sensitive information like emails, calendar details, and files at risk of being exposed to attackers, thanks to a flaw in Microsoft 365 Copilot Enterprise Search. This vulnerability, known as SearchLeak, highlights the importance of staying vigilant even with trusted sources.

Analyst 207
Laptop on office desk surrounded by papers and supplies with a blurred screen.

Microsoft 365 Copilot Exploited in 1-Click Data Theft Attack

A critical vulnerability in Microsoft 365 Copilot Enterprise, known as SearchLeak, could be exploited with just one click to steal sensitive data from mailboxes, OneDrive, and SharePoint. Fortunately, Microsoft has patched the flaw, CVE-2026-42824, and no user action is required to stay safe.

Analyst 207
Person working on laptop in minimalist office with blurred screen, focused expression.

OpenAI Bolsters ChatGPT with Lockdown Mode to Curb Data Exfiltration Risks

OpenAI is stepping up ChatGPT's security game with Lockdown Mode, a powerful setting that limits connections to the web and external services to prevent data exfiltration - a game-changer for those handling sensitive information. This advanced feature is now rolling out to eligible accounts, offering stricter protection guarantees.

Analyst 207
Concerned individuals walk down a modern office corridor lined with server racks and filing cabinets, with a focused laptop…

Cyber Extortion Economy Shifts Away From Ransomware Encryption

The cyber extortion landscape is undergoing a seismic shift, with threat actors ditching ransomware encryption in favor of data-only extortion - and they're moving at lightning speed, with one case seeing data exfiltration in just 39 seconds. This trend is driven by improved backup and recovery methods, leaving attackers to focus on stealing sensitive data.

Analyst 207
Receptionist sitting at desk with phone and laptop, screens glowing blue.

Cybercriminals Impersonate IT Personnel in Targeted Attacks

Cybercriminals are now masquerading as IT personnel to launch targeted attacks, with the FBI warning that law firms and professional sectors are prime targets. This new tactic allows groups like the Silent Ransom Group to swiftly access and exfiltrate sensitive data, often without encrypting systems.

Analyst 207