The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Higher Education/Acadamia
Breach intelligence, attack campaigns, and threat reports targeting the Higher Education/Acadamia sector.
Explore Other Sectors
Higher Education/Acadamia Threat Reports
Ryuk Ransomware Architect Sentenced: Lessons for Modern Enterprise Security
Karen Serobovich Vardanyan, a 35-year-old Armenian national known online as 'Maneeken' or 'Karl Lagerfeld,' was sentenced to 24 months in prison for his role in Ryuk ransomware attacks between March 2019 and June 2020. Vardanyan specialized in gaining initial access to corporate networks, helping his cybercriminal group breach multiple U.S. organizations including companies in Michigan, Texas, and Oregon. The group collected over $15 million in ransom payments, with one Michigan company alone paying 200 BTC worth over $1.1 million. Vardanyan was extradited from Ukraine in 2025 and pleaded guilty in July 2026. This sentencing highlights the ongoing global law enforcement efforts to prosecute ransomware operators, even years after attacks occurred. As ransomware groups continue to evolve and fragment into smaller units, the Ryuk-to-Conti evolution demonstrates how cybercriminal organizations adapt and rebrand while maintaining similar attack methodologies.
23 hours ago
Kill Chain
Microsoft Takes Down EvilTokens: How AI-Powered Phishing Services Threaten Enterprise Identity Security
In September 2026, Microsoft successfully disrupted EvilTokens, a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992. The AI-powered cybercrime service facilitated device code phishing attacks targeting Microsoft 365 accounts, compromising over 12,000 inboxes across 10,000+ organizations worldwide. Microsoft seized 50 websites and disabled 150+ domains, while UK authorities arrested two suspects. EvilTokens distinguished itself by automating device code authentication abuse at scale, using AI to craft tailored phishing lures, analyze compromised inboxes for high-value targets, and streamline business email compromise campaigns sold for $1,500 upfront plus $500 monthly via Telegram. This incident highlights the alarming evolution of phishing-as-a-service platforms leveraging AI to democratize sophisticated attacks. As threat actors increasingly weaponize legitimate authentication mechanisms and AI capabilities, organizations face unprecedented challenges in defending against automated, scalable identity-based attacks that bypass traditional security controls.
1 day ago
Kill Chain
ShinyHunters Claims FBI Breach: Zero-Day Attack on Law Enforcement
In September 2026, the ShinyHunters cybercrime group claimed to have breached the FBI's systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly stealing sensitive data on current and former FBI employees and job applicants. The attackers defaced the FBI jobs website and claimed access to Criminal Justice, HR, and Medlink services. This attack was reportedly conducted in retaliation for an FBI public service announcement warning against paying the group's ransom demands following their Canvas LMS attacks in May 2026. This incident highlights the escalating boldness of cybercriminal groups directly targeting law enforcement agencies and exploiting enterprise software vulnerabilities. The targeting represents a significant shift in threat actor behavior, moving beyond traditional corporate victims to challenge government authority directly.
1 day ago
Kill Chain
Macfinger ClickFix Campaign Deploys AMOS Stealer Through Social Engineering
The Macfinger ClickFix campaign represents a sophisticated social engineering attack targeting macOS users through compromised legitimate websites. Attackers inject malicious JavaScript that displays fake bot verification pages, tricking users into executing commands that download and install AMOS (Atomic macOS) Stealer malware. The campaign uses fingerprinting techniques to specifically target macOS environments, with victims' systems subsequently exfiltrating credentials and sensitive data to command-and-control servers at 95.163.153.80. Post-infection analysis reveals persistent credential harvesting through API endpoints designed to steal stored passwords, browser data, and system information. This incident highlights the growing sophistication of social engineering attacks targeting macOS users, who have traditionally been less targeted than Windows environments. The campaign's use of legitimate compromised websites and convincing fake verification pages represents an evolution in ClickFix techniques, making detection more challenging for users and security tools alike.
1 day ago
Kill Chain
EvilTokens Exposed: How Storm-2992's AI-Powered PhaaS Bypassed MFA at Scale
EvilTokens emerged in February 2026 as a sophisticated phishing-as-a-service (PhaaS) platform operated by threat actor Storm-2992, compromising over 12,000 inboxes across 10,000+ organizations worldwide. The platform exploited OAuth device code authentication flows through AI-powered phishing campaigns, enabling cybercriminals to bypass multifactor authentication and steal authentication tokens at scale. EvilTokens featured 44 customizable phishing templates, automated AI assistants for crafting targeted lures, and multi-stage delivery pipelines designed to evade traditional email security controls. This incident highlights the industrialization of token-based attacks as organizations increasingly adopt MFA, forcing threat actors to evolve beyond credential theft toward authentication bypass techniques that exploit legitimate OAuth flows and cloud service integrations.
1 day ago
Kill Chain
ShinyHunters Escalates to FBI Attack: When Ransomware Groups Target Law Enforcement
In December 2024, the notorious cybercrime group ShinyHunters claimed responsibility for attacking FBI systems, specifically targeting the FBIjobs.gov website and temporarily defacing the jobs portal. The group alleged they stole sensitive data on nearly all FBI agents and job applicants, marking a direct escalation against federal law enforcement. The attack was reportedly motivated by ShinyHunters' dispute with an FBI public service announcement that contained what they claimed were false allegations about their operations. This incident represents a significant escalation in the group's targeting strategy, moving from typical corporate victims to directly confronting law enforcement agencies. This attack highlights the growing boldness of ransomware groups in 2024, as threat actors increasingly target critical infrastructure and government entities. The incident underscores the evolving threat landscape where cybercriminals are willing to directly challenge law enforcement, potentially signaling a shift toward more brazen attacks on government systems.
1 day ago
Kill Chain
SideCopy APT Expands to Target Indian Academic Institutions with Advanced ReverseRAT Campaign
The Pakistan-linked APT group SideCopy has expanded its targeting beyond Indian government entities to include academic institutions through sophisticated spear-phishing campaigns in 2026. The threat actors utilize weaponized ZIP archives containing malicious LNK files that abuse mshta.exe to execute obfuscated HTML applications, ultimately deploying the ReverseRAT malware for data exfiltration and remote access. The attack chain employs multi-stage obfuscation, anti-forensic self-deletion routines, and encrypted command-and-control communications to evade detection while harvesting system metadata, credentials, and sensitive documents from compromised networks. This incident highlights the evolving threat landscape where state-sponsored groups are diversifying their target profiles to include educational institutions, recognizing their value as repositories of intellectual property and research data. The sophistication of SideCopy's techniques demonstrates the growing challenge organizations face in defending against adaptive APT groups that continuously refine their tradecraft.
1 day ago
Kill Chain
EvilTokens PhaaS Platform Disrupted After Compromising 12,000 Microsoft Accounts
In September 2026, Microsoft's Digital Crimes Unit successfully disrupted the EvilTokens phishing-as-a-service platform that had compromised over 12,000 Microsoft accounts across 10,000+ organizations since February 2026. The platform specialized in device-code phishing attacks that bypassed multi-factor authentication by abusing OAuth 2.0 device authorization flows, targeting wholesale distribution, construction, financial services, healthcare, and education sectors. Two suspected administrators were arrested in the UK, though the threat remains active with affiliates creating clone platforms. This incident highlights the escalating sophistication of phishing-as-a-service operations and the growing threat of device-code authentication abuse, which has seen a 37x surge in attacks as cybercriminals adopt AI-powered tools for enhanced targeting and evasion.
1 day ago
Kill Chain
ShinyHunters Targets FBI: Zero-Day PeopleSoft Attack Exposes Government Cloud Vulnerabilities
In September 2026, the ShinyHunters extortion gang claimed to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft, allegedly accessing FBI-managed AWS GovCloud infrastructure and stealing 2-3TB of sensitive data including employee and job applicant information. The threat actors defaced the FBI Jobs website and claimed access to Criminal Justice, HR, and Medlink services before the FBI quickly took affected systems offline. ShinyHunters stated the attack was retaliation against an FBI FLASH report published in May 2026 that detailed the group's activities and demanded corrections within one week. This incident highlights the growing trend of threat actors targeting government infrastructure through supply chain vulnerabilities and using high-profile breaches as leverage against law enforcement agencies. The exploitation of zero-day vulnerabilities in enterprise applications like PeopleSoft demonstrates the critical need for enhanced security measures in government cloud environments.
2 days ago
Kill Chain
Sweden Imposes $183K GDPR Fine on Miljödata After Ransomware Breach Affects 2.2M Citizens
In August 2025, Swedish IT systems provider Miljödata suffered a cyberattack that compromised sensitive data of 2.2 million people across over 200 municipalities. The attackers demanded 1.5 Bitcoin ransom but published the stolen data on the dark web under "Datacarry" when payment was not made. The breach exposed personal identity numbers, contact information, sickness absence records, rehabilitation data, and school incidents involving minors. Sweden's data privacy regulator IMY subsequently fined Miljödata $183,000 for GDPR violations, citing inadequate security measures including insufficient software validation and lack of automated real-time monitoring. This incident highlights the escalating regulatory enforcement of GDPR compliance following ransomware attacks, as European authorities increasingly impose substantial penalties for security negligence that enables data breaches affecting millions of citizens.
2 days ago
Kill Chain
EvilTokens Takedown: How AI Transformed Phishing-as-a-Service in 2026
In September 2026, Microsoft coordinated a global takedown of EvilTokens, a sophisticated phishing-as-a-service platform that leveraged artificial intelligence throughout its attack chain. The Storm-2992 threat group operated this commercial cybercrime service, which exploited OAuth 2.0 device authorization flows to compromise over 12,000 email inboxes across 10,000 organizations worldwide. EvilTokens featured an AI-powered chatbot that analyzed victim inboxes to identify trusted relationships and recommend fraud strategies, significantly lowering the technical barriers for business email compromise attacks. The platform generated approximately $1.1 million in revenue and targeted organizations across wholesale distribution, construction, financial services, healthcare, and education sectors. This incident highlights the dangerous convergence of AI technology with cybercrime infrastructure, demonstrating how threat actors are weaponizing artificial intelligence to automate and scale sophisticated social engineering attacks at an unprecedented level.
2 days ago
Kill Chain
SharePoint CVE-2026-65660: When Microsoft Gets Vulnerability Classification Wrong
CVE-2026-65660 is a SharePoint Server vulnerability that Microsoft initially misclassified as a spoofing flaw with a CVSS score of 6.5, but actually enables authenticated remote code execution with a score of 8.8. Discovered by Viettel Cyber Security researcher Dinh Ho Anh Khoa, the flaw affects SharePoint Server 2016, 2019, and Subscription Edition through improper SafeControls list validation. The vulnerability allows attackers to inject malicious directives and execute arbitrary .NET classes via XamlServices.Parse() deserialization, potentially leading to in-memory webshell deployment. While patches were released on August 11, 2026, the initial misclassification as a moderate spoofing issue may have led organizations to deprioritize patching. This incident highlights the critical importance of accurate vulnerability classification and the ongoing targeting of SharePoint environments by sophisticated threat actors, particularly following recent exploitation of SharePoint flaws by Chinese state-backed groups.
2 days ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports