✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Consumer Services
Breach intelligence, attack campaigns, and threat reports targeting the Consumer Services sector.
Explore Other Sectors
Consumer Services Threat Reports
Grubhub 2024 Data Breach: Hackers Steal Sensitive Customer Information
In June 2024, Grubhub, a major food delivery platform, experienced a significant data breach after hackers gained unauthorized access to its internal systems. According to official statements and media reports, the attackers stole sensitive customer data, including contact details and potentially account credentials. The incident led to extortion demands from the threat actors, prompting Grubhub to initiate incident response protocols and notify affected users. The breach highlighted the attackers’ ability to navigate network defenses, exfiltrate data, and potentially disrupt business operations with ransom threats. This incident is particularly relevant amid a surge in data breaches targeting large consumer platforms and the continued evolution of extortion-based attacks. With regulatory scrutiny increasing and attackers using sophisticated lateral movement tactics, organizations must reassess data protection, segmentation, and threat detection strategies.
6 months ago
Kill Chain
Browser-in-Browser Phishing Surge: Facebook Credential Thefts Expose New Risks in 2024
In early 2024, cybercriminals dramatically escalated the use of the 'browser-in-browser' (BitB) attack technique to steal Facebook login credentials. This method mimics a legitimate browser popup within the user's real window, tricking individuals into entering their login details on phishing sites that look identical to authentic Facebook authentication dialogs. Attackers lure victims through targeted ads, social engineering, and cleverly crafted phishing emails. The impact includes widespread account compromise, enabling follow-on fraud, spam campaigns, and potential data exfiltration from the compromised users' profiles. Facebook, along with the wider cybersecurity community, is warning users and rolling out alerts in response, but overall threat exposure remains high. The BitB phishing approach reflects a concerning trend of attackers using more advanced visual deceptions to bypass user awareness and established security controls. Its prevalence highlights a widening capability gap in traditional anti-phishing technologies, reinforcing the need for robust anomaly response and continuous education amid shifting adversary tactics.
6 months ago
Kill Chain
ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data
In June 2024, adult content platform PornHub became the target of a significant data breach when the ShinyHunters extortion group claimed to have stolen search and viewing history data linked to the site’s Premium members. Attackers reportedly exploited Mixpanel analytics integrations to exfiltrate sensitive user data, including logs of user activity, then threatened public release unless a ransom was paid. PornHub’s operations and brand reputation face heightened scrutiny, especially given the highly sensitive nature of the data involved, with many users fearing exposure and potential blackmail. This incident underscores the ongoing threats facing organizations that handle sensitive personal data, especially as extortion groups increasingly target user activity logs for leverage. Regulatory and reputational risks are amplified by attackers’ focus on analytics platforms, and similar tactics are expected to proliferate across other high-traffic digital properties in 2024.
6 months ago
Kill Chain
Leroy Merlin Customer Data Breach Exposes Personal Information in France
In June 2024, French home improvement retailer Leroy Merlin disclosed a security incident impacting its French customer base. Attackers gained unauthorized access to customer accounts and personal data, including names, email addresses, physical addresses, phone numbers, and order histories. While no financial data or passwords were compromised, the company became aware of unusual activity and swiftly launched an internal investigation and incident response procedures. Affected users were notified and advised to remain vigilant against phishing attempts. The incident has triggered regulatory attention and widespread concern among customers. The breach at Leroy Merlin highlights the increasing frequency of attacks targeting customer data in the retail sector. As organizations digitize more customer interactions, they face mounting regulatory pressure to safeguard personal information and promptly report security incidents to minimize reputational and financial risk.
6 months ago
Kill Chain
Jingle Thief: How Hackers Exploited Cloud to Steal Millions in Retail Gift Cards (2025)
In October 2025, a cybercriminal group known as Jingle Thief orchestrated a sophisticated financial fraud campaign targeting retail and consumer services organizations operating in cloud environments. Leveraging phishing and smishing tactics to obtain employee credentials, the attackers gained access to cloud-based systems responsible for managing digital gift card issuance. Once inside, they exploited weak east-west traffic controls and lack of adequate segmentation to move laterally and automate gift card theft at scale, resulting in losses worth millions of dollars and significant operational disruption to affected businesses. This incident highlights an ongoing escalation in targeted cloud infrastructure attacks, especially towards retail functions involving financial assets like digital gift cards. The use of cloud-native attack vectors and credential phishing underscores the urgency for enhanced zero trust practices, robust detection controls, and strict policy enforcement to protect sensitive assets in distributed environments.
6 months ago
Kill Chain
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
6 months ago
Kill Chain
Inside the 2025 Co-op Scattered Spider Cyberattack: Lessons and Impact
In April 2025, the Co-operative Group (Co-op), a major UK member-owned retailer, experienced a sophisticated cyberattack attributed to Scattered Spider affiliates linked to the DragonForce ransomware operation. The attack targeted Co-op’s IT infrastructure, forcing the group to shut down critical systems, causing major disruptions to back-office and call-center operations, and necessitating rapid manual workarounds. Although Co-op's incident response prevented data encryption, attackers stole sensitive personal information of all 6.5 million current and past members, including names and contact details. The breach resulted in significant operational outages, with £80 million ($107 million USD) in immediate financial losses and longer-term revenue reduction due to impacted retail operations and customer trust. This incident highlights the evolving threat of identity-driven ransomware attacks and the increasing willingness of threat actors to disrupt critical infrastructure for financial gain. The scale and impact of the Co-op breach underscore the need for advanced security controls and segmented, resilient architectures to counter modern ransomware groups.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports