Skip to main content

Tag: identity theft

343 articles

Empty office cubicle with computer and papers, suggesting recent use.

Hasbro Breach Compromises Employee Data

A single compromised employee account led to a massive data breach at Hasbro, exposing sensitive employee information, including Social Security numbers and financial data. The alarming incident highlights the importance of robust cybersecurity measures to prevent such breaches.

Analyst 207
Busy office corridor with people walking, large blank screen in foreground.

Data Breaches Surge, Threaten 2026 Record

Data breaches are surging out of control, with 1,803 compromises reported in the first half of 2026 alone, putting the year on track to shatter the 2025 record of 3,321 breaches. If this pace continues, 2026 could see a staggering 3,600 data compromises.

Analyst 207
Windows laptop with login screen sits next to YubiKey device on a modern desk.

Passkey Defenses Targeted in Novel Attacks

Researchers at Black Hat USA 2026 revealed a shocking vulnerability in passkey defenses, demonstrating how attackers can bypass FIDO2 cryptography and exploit a flaw in Windows Event Logging Service (CVE-2026-34348) to defeat passkey protections. This security gap was found to allow unauthorized users to access and replay sensitive YubiKey signatures.

Analyst 207
Laptop on a beige office desk with a blurred screen in a cubicle near a window.

Malware Exploits Windows Hello for Business Keys to Gain Persistent Entra ID Access

Malware can quietly hijack your Windows Hello for Business key to gain long-term access to your Entra ID account, allowing hackers to register a new device and add extra authentication methods. To stay safe, Entra ID researcher Dirk‑jan Mollema advises monitoring unexpected device registrations.

Analyst 207
Young man sits in courtroom with somber expression, hands clasped together.

Canadian Hacker Pleads Guilty to Snowflake Extortion Scheme

A 26-year-old Canadian hacker has pleaded guilty to masterminding a massive Snowflake extortion scheme that compromised over 100 million AT&T customers' sensitive call and text history records. Connor Riley Moucka faces up to 30 years in prison for his role in the cross-border hacking and extortion operation.

Analyst 207
Defendant sits in federal courtroom with lawyer, hands restrained.

Snowflake Breaches Expose 100 Million People as Hacker Pleads Guilty

A massive data breach at Snowflake has left a staggering 100 million people vulnerable, after hackers exploited stolen credentials to access sensitive records at over 165 organizations. The mastermind behind the breach, Connor Riley Moucka, has pleaded guilty to multiple charges, including computer fraud and identity theft.

Analyst 207
Maksim Silnikau sits in defendant's chair in a federal courthouse with a judge's bench and Department of Justice seal in…

Ransom Cartel Creator Sentenced to 16 Years for Global Cyberattacks

Meet Maksim Silnikau, the mastermind behind the notorious Ransom Cartel, who's now facing 16 years behind bars for masterminding a global cyberattack spree that targeted at least 18 companies and raked in millions for him. The US Department of Justice brought him to justice, sentencing him for conspiracy, wire fraud, and identity theft.

Analyst 207
Laptop on a desk in a bright office setting displays a notification on a Microsoft Teams interface.

Phishing Campaign Exploits Microsoft Authentication

Cyber attackers have found a sneaky new way to steal corporate accounts by exploiting Microsoft's authentication process, making it harder to spot fake requests. They've been sending emails that look like Microsoft Teams notifications, leading victims to a legitimate Microsoft URL that tricks them into granting access.

Analyst 207
University hallway with open doors, symbolizing vulnerabilities in single sign-on security.

SSO Security Requires Proactive Defense Against Credential Attacks

A single compromised SSO account can become a master key, unlocking a vast array of sensitive services and putting millions of individuals at risk, as seen in the 2025 University of Pennsylvania breach where 1.2 million people's data was stolen. Proactive defense against credential attacks is crucial to protecting your organization's security.

Analyst 207
Dimly lit server room with rows of computer servers and networking equipment showing signs of disarray and potential…

Synthetic Identity Fraud Targets Machine Identities

Imagine a new kind of identity theft where attackers create fake machine identities from scratch, blending real and invented attributes to fly under the radar. These fabricated Non-Human Identities can go undetected, allowing cybercriminals to wreak havoc without triggering the usual alerts that catch stolen accounts.

Analyst 207
Person sitting at laptop with concerned expression, surrounded by papers and notes in a home office with natural daylight.

Identity Theft Exposes Vulnerability in Email Account Security

Giving a scammer a two-factor authentication code can have devastating consequences, as one unfortunate account owner discovered when it allowed the scammer to take over their email address. This simple mistake opened the door to a broader security risk, highlighting a vulnerability in email account security.

Analyst 207
Blurred computer screen amidst ordinary office equipment and decor suggests disruption.

Ransomware Attacks Exploited Compromised Identities in 79% of Incidents

Ransomware attacks are often sparked by something surprisingly simple: 79% of incidents start with compromised identities, highlighting the vulnerability of legitimate user logins and credentials. This means that in nearly 8 out of 10 cases, attackers gain a foothold using stolen or hijacked identities rather than complex hacking techniques.

Analyst 207
Person working on laptop with blurred screen in home office setting.

Microsoft Warns of Device Code Phishing Attacks via Legitimate Website

Beware of device code phishing attacks that can trick you into giving away access to your accounts, even on legitimate websites. Hackers are using a clever tactic that exploits Microsoft's authentication endpoint to steal your credentials.

Analyst 207
Person holds credit card, looking concerned in front of blurred retail store background.

Card Data Theft Exposes Persistent US Consumer Vulnerability

Nearly half of US consumers are on high alert for card data theft, naming it their top fraud worry. A recent Capco survey found 46% of respondents citing card and card data theft as their biggest concern, beating out identity theft and other financial security threats.

Analyst 207
A dimly lit office interior with a single wooden desk and chair, papers and folders scattered on the surface, illuminated…

Amazon Fined $2.25M for Withholding Fraud Evidence

Amazon has been fined $2.25 million for allegedly blocking identity-theft victims from accessing records of fraudulent transactions, violating the Fair Credit Reporting Act. The company reportedly told some consumers that they couldn't access the requested records, adding to the frustration of those trying to recover from scams.

Analyst 207
Passport lies on a plain surface surrounded by blurred cannabis dispensary items, hinting at a security breach.

Massive Passport Leak Exposes Sensitive Traveler Data

A staggering leak of almost a million passport records from around the world has put sensitive traveler data at risk. The breach, linked to a low-security ID verification system for cannabis dispensaries, exposed passports as a vulnerable weak point in authentication processes.

Analyst 207
Multi-layered city infrastructure with payment terminal in foreground.

Fraud Prevention Strategies Target Multiple Elevation Levels

Fraudsters are constantly evolving, and a single-layer defense just won't cut it - that's why IPQS advocates for a layered approach to fraud prevention, because what may seem like a secure transaction to you might be just the tip of the iceberg to a sophisticated scammer. By monitoring at multiple levels, you can stay one step ahead of even the most cunning attackers.

Analyst 207
Person sitting at desk with laptop and smartphone, surrounded by papers in a blurred office setting.

Identity Crimes Evolve into Multi-Layered Fraud Schemes

Identity crimes are no longer standalone incidents, but rather gateways to multiple, simultaneous frauds that can wreak havoc on victims' lives. A staggering 25.6% of victims now face two or more concurrent events, a 23.5% surge from the previous year.

Analyst 207
Darkened underground digital marketplace with rows of screens displaying abstract data.

Cyberattacks Expose AI Agents' Vulnerability to Phishing Risks

A staggering 3.3 billion identity records are now circulating on illicit markets, thanks to a whopping 11.1 million devices infected with infostealers last year - a digital threat landscape that's more vulnerable than ever. This alarming trend highlights the urgent need for robust protection against AI agents' vulnerability to phishing risks.

Analyst 207
Person sits at cluttered desk with concerned expression, surrounded by papers and laptop.

Identity Crime Incidents Multiply for Victims, ITRC Data Reveals

The alarming rise in identity crime incidents is not just about the numbers, but also the disturbing pattern of recurrence, with nearly 26% of victims experiencing multiple concurrent incidents, according to the Identity Theft Resource Center's 2026 Trends in Identity Report. This growing multi-layered crisis sees single compromises snowballing into additional incidents across accounts and institutions.

Analyst 207
Dimly lit server room with rows of computer servers and a blurred technician screen.

Hackers Exploit Active Directory Flaw to Harvest Passwords

Storing passwords in Active Directory description fields is a rookie mistake that hackers are eager to exploit, and one hacker did just that with alarming ease. It was disturbingly simple for them to get their hands on sensitive information.

Analyst 207
Elderly man stands somberly in front of a nondescript government building backdrop.

Elder Data Trafficker Draws 10-Year Sentence

A massive data scam that compromised the personal info of over 7 million elderly Americans has landed its mastermind, 57-year-old Troy Murray, a 10-year prison sentence - a major victory in the fight against these heartless crimes. Murray, who went by the alias "Steve Dixon," was found guilty of running a scheme that sold sensitive data, including names, phone numbers, and addresses, to overseas scammers.

Analyst 207
Courthouse interior with judge's bench and computer in foreground.

Romanian Hacker Sentenced for Breaching Oregon Govt Network

A Romanian hacker has been sentenced to 56 months in prison for breaking into Oregon's state emergency-management network, stealing sensitive personal data, and selling it to buyers in the US. Catalin Dragomir, 46, pleaded guilty to aggravated identity theft and computer intrusion charges.

Analyst 207
A dimly lit office cubicle with scattered papers and a hand reaching for a wallet near a laptop and login credentials list.

Employees Willingly Sell Work Credentials

A shocking 13% of employees admit to selling their work logins or knowing someone who has, revealing a surprisingly casual attitude towards protecting sensitive work credentials. This statistic raises serious concerns about workplace security and the vulnerability of company data.

Analyst 207