Tag: ransomware
1069 articles

PaperCut Zero-Days Exploited in Data Theft Attacks
Hackers are actively exploiting two zero-day vulnerabilities in PaperCut NG and MF, using them to bypass authentication and steal sensitive data from vulnerable print management servers. Attackers have already been spotted chaining these flaws to launch data theft attacks, prompting emergency patches from PaperCut Software.

McKesson Discloses Data Theft After ShinyHunters Extortion Attack
McKesson has confirmed a data theft incident following a cyberattack by ShinyHunters, but has assured customers that its business and distribution centers are up and running with no ongoing unauthorized activity. The company sprang into action, activating incident response protocols and launching an investigation to minimize disruption.

Cyberattacks Disrupt Healthcare Firms, Compromise Patient Data
Millions of patient records are at risk and remote monitoring for newly implanted cardiac devices has been crippled after two major healthcare firms, Boston Scientific and McKesson, fell victim to separate cyberattacks. Boston Scientific's hack has left new pacemakers and heart devices unable to transmit vital data remotely, putting patients' health and privacy in immediate jeopardy.

ATF Cyber Breach Exposes Investigative Targets
The ATF's response to the Qilin ransomware gang's claim of a breach reveals how prepared - or unprepared - the agency was to tackle the incident. A cyber breach at the ATF potentially puts sensitive investigative targets at risk, but details on the incident remain scarce.

FulcrumSec Hack Exposes 86 GB of Manchester Airports Data
Manchester Airports Group swiftly sprang into action after a hack, reassuring customers that they've taken robust measures to safeguard their info and reaching out to those affected, including those with upcoming bookings, to offer extra support. Meanwhile, hackers FulcrumSec claimed responsibility, boasting of swiping 86 GB of sensitive data.

Manchester Airports Breach Exposes 8.7M Customer Records
A recent data breach at Manchester Airports Group exposed a whopping 8.7 million customer records, including emails, contact info, and vehicle registrations, after hackers demanded a ransom that was wisely refused. The breach is a stark reminder that public networks can put your data at risk, no matter how secure they seem.

Ransomware Actors Exploit AI Tool in Sophisticated Attacks
Ransomware attackers are now using AI tools like Claude Sonnet to supercharge their assaults, with one group successfully exploiting the technology to target 10 victims in just a few weeks. By leveraging advanced tools like SpaceX's Cursor Agent, these cybercriminals are refining their tactics and getting bolder.

CRPx0 Ransomware Service Rapidly Expands, Targets 48 Organizations
CRPx0's ransomware service has exploded onto the scene, rapidly expanding its reach to target a staggering 48 organizations - a number that's skyrocketed from fewer than 10 just a few months ago. This alarming growth follows the group's shift from a basic hacking service to a full-fledged, white-label ransomware operation.

ATF Probes Ransomware Gang's Claims of Major Cybersecurity Breach
A ransomware gang has claimed responsibility for a major cybersecurity breach, prompting a swift response from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The ATF is investigating the incident, but few details have been released so far.

ShinyHunters Breach Exposes 12.9 Million Carhartt Accounts
A massive data breach at Carhartt has exposed a staggering 12.9 million customer accounts, compromising sensitive information and putting millions of people at risk. The breach, attributed to the ShinyHunters extortion group, included a treasure trove of customer, employee, and corporate data.

Boston Scientific Disrupts Global Operations After Cyber Incident
Boston Scientific's global operations have been significantly disrupted due to a cyber incident, affecting access to key systems and applications, including order processing and shipping. The incident has caused a major network outage, impacting the company's ability to operate normally worldwide.

ATF Breach Exposes Federal System to Qilin Ransomware Gang
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a major breach of a standalone system, which was swiftly isolated to prevent further damage, and is now teaming up with the Department of Justice to investigate the Qilin Ransomware Gang's involvement. The incident appears to be contained, with no impact on the ATF's main enterprise network or other critical systems.

Boston Scientific Cyberattack Disrupts Global Operations
A delayed shipment of a life-saving cardiac device can have devastating consequences, like a cancelled surgery - and that's exactly what's at risk when a cyberattack hits a medical device manufacturer like Boston Scientific. The recent attack has disrupted the company's global operations, causing order-processing delays that can have a ripple effect on patients' lives.

Boston Scientific Hit by Global Cyberattack Disruption
Boston Scientific is facing significant disruptions to its operations after a global cyberattack hit its IT systems, limiting access to crucial business applications and hindering its ability to process and ship customer orders. The company is working closely with third-party experts to investigate and restore its systems, but a timeline for full recovery remains uncertain.

Carhartt Breach Reveals 12.9M Affected, Exposes ShinyHunters' Data Padding Tactics
The Carhartt data breach just got a reality check: an analysis by Troy Hunt revealed that around 12.9 million accounts were genuinely affected, not nearly as many as initially claimed by the hackers. Turns out, you can't always take cybercriminals at their word!

Boston Scientific Hit by Cyberattack Disrupting Global Operations
Boston Scientific's global operations have been disrupted by a cyberattack, causing significant hiccups in processing and shipping customer orders due to limited access to key information systems and business applications. The incident was detected on August 25, prompting an immediate response to mitigate the impact.

ReliaQuest Exposes ShinyHunters' Social Engineering Tactics
ReliaQuest sets the record straight: claims of a ransomware attack or breach are completely false. The company recently thwarted a social engineering scheme by ShinyHunters, swiftly investigating and publicly rebutting the misinformation.

Medusa Ransomware Gang Targets Over 500 Organizations, Experts Warn
The Medusa Ransomware gang has hit over 500 organizations since June 2021, and experts are sounding the alarm. This active and rapidly expanding Ransomware-as-a-Service campaign has prompted urgent warnings from top US security agencies.

Ransomware Affiliate Exploits Fellow Extortionists with 'Recovery' Scam
In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

Ransomware Affiliate Exploits Trust with Fake Recovery Firm Tactics
Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

Ransomware Affiliate Exploits Trust with Fake Recovery Service
A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

Clop Exploits PTC Zero-Day in Large-Scale Data Theft Spree
Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

Hackers Exploit 2,000 WordPress Sites in StopAndProtect Malware Campaign
This sneaky malware campaign, known as StopAndProtect, has already hacked nearly 2,000 WordPress sites, using a powerful toolkit that encrypts files, steals sensitive documents, and even lets attackers chat with their victims in real-time. The damage is widespread, with over 6,000 unique IP addresses affected worldwide.

Ransom Busters Emerges as New Player in Ransomware Extortion Economy
Meet Ransom Busters, a newcomer to the ransomware extortion economy that's shaking things up with its bold approach: offering to delete stolen data from ransomware groups' servers for a fee of $20,000 to $60,000. This third-party player claims to have been infiltrating ransomware-as-a-service operations for over three years.