Skip to main content

Tag: data theft

113 articles

Rows of computer servers and network equipment in a brightly-lit office server room.

PaperCut Zero-Days Exploited in Data Theft Attacks

Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

Analyst 207
Rows of shelved medical supplies in a distribution center with employees checking a laptop.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack

McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Analyst 207
Brightly-lit office setting with desk, chair, phone, and computer workstation.

ReliaQuest Foils ShinyHunters' Data-Theft Attack via Social Engineering

ReliaQuest swiftly foiled a sneaky social engineering attack by ShinyHunters, who tried to trick employees into spilling sensitive info, but thankfully, only had view-only access and didn't touch customer data. The company's quick response contained the threat, protecting its systems and customers from harm.

Analyst 207
Empty office setting with a laptop on a desk, screen facing away, surrounded by blurred office furniture and soft natural…

Microsoft Copilot Flaw Uncovered Through AI Model Manipulation

Researchers uncovered a concerning vulnerability in Microsoft Copilot, dubbed CoSnitch, which can be exploited with just one click to steal sensitive data without triggering obvious security alerts. The flaw was unusually revealed by Copilot itself during a normal interaction, highlighting the need for organizations to treat AI assistants with greater caution and scrutiny.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit data center with concerned businesspeople in the background.

Clop Ransomware Targets GE, Philips in Data Theft Attacks

Major companies like Philips, General Electric, and Shell are investigating claims by the Clop ransomware gang that their systems were breached, with Philips confirming a contained breach of an internal server that didn't affect customers. The incidents are a stark reminder of the growing threat of ransomware attacks on businesses.

Analyst 207
Public sector office interior with subtle digital infrastructure and blurred people in the background.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft

A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Analyst 207
Smartphone on a lab surface with blurred technical instruments in the background.

Malicious SIMs Expose Devices to Data Theft and 2G Downgrade Attacks

Imagine a SIM card, typically just a simple piece of tech that connects you to your network, being turned against you - allowing hackers to steal your data and even downgrade your device to a vulnerable 2G connection. Researchers have created a toolkit to test the limits of these malicious SIM attacks, and the results are eye-opening.

Analyst 207
Laptop screen on a plain desk in a blurred office setting with a faint shadow.

Metabase Zero-Day Exploited in Data-Theft Attacks

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.

Analyst 207
Dairy production facility with stainless steel equipment and milk bottles on a conveyor belt.

Coca-Cola Discloses Data Theft in Fairlife Ransomware Attack

Coca-Cola has confirmed that its dairy subsidiary, Fairlife, was hit by a ransomware attack, resulting in data theft by hackers. The company is working to restore impacted systems and operations, with most US production now back online.

Analyst 207
Industrial facility interior with computer workstations, machinery, and a laptop screen, with daylight through large windows.

Clop Ransomware Targets PTC Windchill in Data Theft Attacks

A critical vulnerability, CVE-2026-12569, with a near-perfect CVSS score of 9.3 is being exploited by Clop ransomware attackers to breach PTC Windchill and FlexPLM systems, putting sensitive data at risk. Security patches are available, but urgent action is needed to prevent data theft.

Analyst 207
Law enforcement officials stand near seized computer equipment in a brightly lit facility.

Authorities Disrupt Kratos Phishing Platform in Global Operation

In a major global crackdown, authorities have shut down Kratos, a notorious phishing-as-a-service platform that helped cybercriminals create fake Microsoft login pages to steal sensitive info. The takedown has disrupted a key tool used by over 1,800 customers to commit crimes like business email compromise and data theft.

Analyst 207
Rows of file cabinets and servers in a brightly-lit data storage area with scattered papers on a nearby table.

Craneware Discloses Data Theft in Cyber Incident

A recent cyber incident at healthcare finance software provider Craneware exposed a significant volume of sensitive data, including customer and business partner records, highlighting the ease with which determined attackers can carry out data exfiltration. Even seemingly low-severity incidents can pose a real risk of data exposure.

Analyst 207
Business setting with laptop on desk, papers and supplies nearby, and CRM system on screen.

Microsoft Tracks ShinyHunters' Salesforce Data Theft Via OAuth Flaws

Microsoft uncovered a sneaky year-long operation by the ShinyHunters extortion group, who exploited trust in Salesforce's OAuth system to steal sensitive data, using clever vishing tactics to trick employees into granting access to a malicious app. The attackers posed as IT support, convincing victims to authorize a fake Data Loader tool that allowed them to make API calls and search for valuable credentials.

Analyst 207
Dutch National Police officer stands in formal briefing room with agency emblem and cityscape in background.

Dutch Police Expose Suspects in Odido Hacking Case

The Dutch National Police have cracked the Odido hacking case, revealing that suspects impersonated an IT employee in a phone call with customer service, tricking the company into divulging sensitive info through phishing. This clever ruse led to a massive data theft in February.

Analyst 207
Browser window with muted notification bar on a computer screen in a quiet indoor setting.

Opera GX Flaw Enables Silent Mod Installs to Steal User Data

Researchers have discovered a security flaw in Opera GX that allows for silent mod installs, potentially putting user data at risk, and surprisingly, this vulnerability can be exploited with just a single page visit. This alarming issue enables malicious mods to be installed without user consent, highlighting a concerning gap in the browser's security.

Analyst 207
Developer workspace with laptop, monitor, and notes, overlooking cityscape through window.

North Korea-Linked npm Packages Target Developers with Stealthy Data Theft

Malicious npm packages, linked to North Korean threat actors, are impersonating popular tools to trick developers into handing over sensitive data. These sneaky packages masquerade as legitimate polyfill tools, making them hard to spot during a quick review.

Analyst 207
Person interacting with laptop in modern workspace with blurred background.

BioShocking Attack Exploits AI Browsers for Data Theft

Researchers have uncovered a chilling new attack, dubbed BioShocking, that exploits AI browsers to steal sensitive data by cleverly tricking them into treating real actions as fictional. This ingenious technique uses a simple game to condition AI agents into accepting fake actions as valid, putting even the most secure systems at risk.

Analyst 207
Hospital corridor with people in background, medical device and laptop on table.

Novo Nordisk Discloses Cyberattack, Patient Data Stolen

Novo Nordisk revealed that a cyberattack has compromised patient data, specifically information related to clinical-trial participants, though assured that the data is not directly linked to patients by name or other identifiers. The company is working with outside experts to investigate and contain the breach.

Analyst 207
Rows of computer servers and database systems in a brightly-lit, empty office or server room.

Oracle Discloses Zero-Day Flaw in PeopleSoft Exploited in Data Theft Attacks

A critical zero-day flaw in Oracle PeopleSoft, known as CVE-2026-35273, has been exploited by hackers to steal sensitive data from over 100 organizations, with a staggering 300 instances affected. Oracle has issued emergency mitigations and is working on a patch to address this highly vulnerable issue.

Analyst 207
Modern office space with scattered papers and an open file cabinet, hinting at disruption.

Ransomware Attacks Shift to Data Theft Tactics

Ransomware attacks have taken a sinister turn, with a growing number of hackers ditching decryption keys and instead using stolen data to extort their victims. In fact, a recent report found that a whopping 87% of ransomware claims now involve data theft, with encryption becoming a thing of the past.

Analyst 207
Rows of computer servers and equipment in a brightly-lit server room with a single out-of-focus laptop screen in the…

ShinyHunters Targets Oracle PeopleSoft Servers in Widespread Data Theft Attacks

ShinyHunters, a notorious extortion group, has launched a massive data theft campaign targeting Oracle PeopleSoft servers, compromising over 300 instances across 100+ organizations, with a significant impact on the education sector. The attackers have brazenly claimed responsibility, boasting of their exploits in a chilling conversation with BleepingComputer.

Analyst 207
Blurred computer workstation and file cabinet in a brightly-lit office interior, with a cityscape visible through the window.

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

Analyst 207
Laptop on a cluttered office desk with papers and supplies nearby.

China-Linked TA4922 Expands Phishing Attacks Globally

Meet TA4922, a China-linked group rapidly expanding its phishing attacks worldwide, with a financially motivated agenda to infiltrate and exploit victim environments for data theft, fraud, and more. This threat actor is now targeting organizations globally, from the UK to Germany, Italy, and South Africa.

Analyst 207
Industrial control room with rows of systems, networking equipment, and monitoring stations under fluorescent lighting.

CISA Warns of Data Theft Bug in NSA-Built OT Networking Tool

A critical vulnerability, CVE-2026-6807, has been discovered in an NSA-built networking tool that could allow hackers to steal sensitive information by exploiting an XML parsing weakness. If left unpatched, this flaw could lead to devastating data breaches.

Analyst 207