The Containment Era is here. →Explore

Industry Category

Human Resources/HR

Breach intelligence, attack campaigns, and threat reports targeting the Human Resources/HR sector.

30 threat reports
Page 2 of 3

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Human Resources/HR Threat Reports

Showing 1324 / 30 reports
Starbucks 2026 Data Breach: Credential Theft via Phishing
Impact· MEDIUM

Starbucks 2026 Data Breach: Credential Theft via Phishing

In early 2026, Starbucks experienced a data breach affecting 889 employees after attackers gained unauthorized access to Partner Central accounts. The breach, discovered on February 6, 2026, involved threat actors obtaining login credentials through phishing websites impersonating the Partner Central portal. Exposed information included names, Social Security numbers, dates of birth, and financial account details. Starbucks promptly initiated an investigation, notified law enforcement, and offered affected employees two years of free identity theft protection and credit monitoring services. This incident underscores the persistent threat of credential theft via phishing attacks, emphasizing the need for robust security measures and employee awareness training to prevent unauthorized access to sensitive information.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
BlackSanta EDR Killer: A New Threat to HR Departments in 2026
Impact· HIGH

BlackSanta EDR Killer: A New Threat to HR Departments in 2026

In March 2026, a sophisticated cyberattack campaign was uncovered targeting human resources (HR) departments. Russian-speaking threat actors distributed malware via spear-phishing emails containing ISO image files disguised as resumes. Upon execution, these files initiated a multi-stage infection chain, culminating in the deployment of 'BlackSanta,' an Endpoint Detection and Response (EDR) killer. BlackSanta disabled security solutions by terminating antivirus processes, shutting down EDR agents, and suppressing system logging, allowing attackers to exfiltrate sensitive data undetected. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/?utm_source=openai)) This incident underscores a growing trend of cybercriminals exploiting HR workflows to infiltrate organizations. The use of advanced evasion techniques, such as steganography and DLL sideloading, highlights the increasing sophistication of these attacks. Organizations must enhance security measures within HR processes to mitigate such threats. ([darkreading.com](https://www.darkreading.com/threat-intelligence/blacksanta-edr-killer-hr-workflows?utm_source=openai))

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(low)
Read Report
BlackSanta Malware: A New Era of Targeted Cyber Threats in HR Workflows
Impact· HIGH

BlackSanta Malware: A New Era of Targeted Cyber Threats in HR Workflows

In early 2026, Russian-speaking threat actors initiated the 'BlackSanta' campaign, targeting human resources (HR) workflows to deploy sophisticated malware capable of disabling endpoint detection and response (EDR) systems. The attack begins with resume-themed ISO files delivered through recruitment channels, which, when opened, execute malicious shortcuts that trigger a multi-stage infection chain. This chain includes obfuscated PowerShell commands extracting payloads from steganographic images and sideloading malicious DLLs via legitimate applications. Once executed, the malware performs extensive validation to evade analysis environments before deploying the 'BlackSanta' EDR killer. This component loads legitimate but exploitable kernel drivers to gain low-level system access, subsequently disabling security protections, including antivirus processes, EDR agents, and system logging. This enables attackers to exfiltrate sensitive data over encrypted HTTPS channels with minimal detection risk. The campaign underscores the increasing sophistication of cyber threats targeting operational business workflows, particularly in HR environments. Organizations are advised to apply rigorous security measures to HR systems, including enhanced endpoint protections, monitoring for unusual activity, and increasing security awareness among recruiting teams to mitigate such attacks.

4 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Wynn Resorts Data Breach 2026: ShinyHunters' Latest Target
Impact· HIGH

Wynn Resorts Data Breach 2026: ShinyHunters' Latest Target

In February 2026, Wynn Resorts, a prominent Las Vegas-based hospitality company, confirmed a data breach involving unauthorized access to employee information. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of data affecting over 800,000 individuals. The compromised information reportedly includes names, email addresses, phone numbers, positions, salaries, start dates, and birth dates. ShinyHunters demanded a ransom of 23.34 Bitcoin (approximately $1.55 million) by February 23, 2026, threatening to release the data on the dark web if their demands were not met. Analysts suggest the breach may have exploited a vulnerability in Oracle PeopleSoft software, potentially through a compromised employee account. ([techradar.com](https://www.techradar.com/pro/security/top-las-vegas-hotel-is-the-latest-shinyhunters-ransomware-victim-hackers-demand-usd1-5-million-to-not-leak-data?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who employ advanced social engineering techniques such as voice phishing (vishing) to infiltrate organizations. The breach highlights the critical need for robust cybersecurity measures, including regular system updates, comprehensive employee training on phishing tactics, and the implementation of multi-factor authentication to safeguard sensitive data.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
WhatsApp Rolls Out Lockdown Security for High-Risk Users After Spyware Attacks
Impact· medium

WhatsApp Rolls Out Lockdown Security for High-Risk Users After Spyware Attacks

In early 2026, WhatsApp introduced a new 'Strict Account Settings' feature to defend high-risk users such as journalists and public figures against highly targeted spyware attacks. This rollout followed a series of incidents in recent years where advanced zero-click exploits—many attributed to government-linked actors—were used to deploy spyware like NSO Group’s Pegasus and Paragon Graphite onto users’ devices via messaging platforms. Exploits leveraged zero-day vulnerabilities in WhatsApp’s iOS and macOS clients, enabling attackers to compromise devices without user interaction, raising severe risks to privacy and personal safety for individuals facing nation-state targeting. This event is particularly relevant as threat actors increasingly adopt sophisticated, zero-click methods to compromise high-value targets. Security and privacy expectations for messaging apps are under heightened scrutiny, with regulators and civil society urging greater protections and rapid incident response to curtail such threats.

5 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates
Impact· low

Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates

In early 2024, a major payroll provider experienced a sophisticated social engineering breach orchestrated by attackers dubbed the 'Payroll Pirates.' The threat actors engineered convincing phishing campaigns targeting payroll staff, tricking them into divulging critical credentials. Once initial access was secured, the attackers leveraged lateral movement techniques to escalate privileges and manipulate internal payroll processes, ultimately leading to fraudulent fund transfers and sensitive data exposure. Rapid detection efforts limited further impact, but the breach resulted in financial losses, operational disruption, and increased scrutiny over internal controls. This incident underscores the resurgence of highly targeted social engineering attacks, specifically in the payroll and finance sectors. As attackers blend human manipulation with advanced technical tactics, organizations must prioritize zero trust architectures, staff awareness, and continuous threat monitoring to defend against this evolving risk landscape.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack
Impact· medium

Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack

In January 2026, cybersecurity researchers uncovered a campaign involving five malicious Google Chrome extensions that impersonated enterprise platforms such as Workday, NetSuite, and SuccessFactors. These extensions worked in unison to steal authentication tokens, disrupt incident response procedures, and seize control of victim user accounts. Attackers leveraged the trust users place in HR and ERP browser tools, exploiting their position to achieve data exfiltration and persistent account takeover across corporate environments. The attack’s main impact included unauthorized access to sensitive business systems and increased potential for widespread lateral movement within organizations. This incident underscores the growing sophistication of browser-based threats as attackers increasingly mimic legitimate business tools to infiltrate organizations. With a rise in social engineering and token theft techniques targeting identity and SaaS workflows, enterprises face heightened risk to cloud and hybrid environments, necessitating additional focus on endpoint, browser, and application-layer defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
STAC6565 & Gold Blade Exploit Recruitment Platforms in Canadian Ransomware Assault (2025)
Impact· high

STAC6565 & Gold Blade Exploit Recruitment Platforms in Canadian Ransomware Assault (2025)

Between February 2024 and August 2025, a financially-motivated threat group tracked as STAC6565 (with strong overlaps to the Gold Blade/RedCurl actor cluster) orchestrated a series of nearly 40 targeted cyberattacks, predominantly on Canadian organizations. The attackers utilized spear-phishing campaigns, delivering weaponized resumes via legitimate recruitment platforms to HR staff to gain initial access. Once inside, the group deployed a multi-stage attack chain using custom loaders and tools like RedLoader, RPivot, and Chisel, culminating in QWCrypt ransomware deployment on high-value endpoints including hypervisors. Data theft and extortion were observed, with a clear pattern of operational sophistication and periods of dormancy followed by refined attack waves. This incident highlights the increasing adoption of "hack-for-hire" models, hybrid attacks combining espionage and ransomware, and the innovative abuse of legitimate business platforms to sidestep conventional email security. Organizations globally—particularly those with HR exposures and reliance on virtualized infrastructure—face heightened risk as attackers rapidly iterate on TTPs to maximize impact and evade detection.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?
Impact· high

Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?

In June 2024, French public agency Pajemploi, responsible for social security management for parents and home childcare providers, suffered a large-scale data breach. Attackers exploited a flaw in the agency's online system that enabled them to access personal data belonging to approximately 1.2 million individuals, including names, addresses, social security numbers, bank details, and tax identification data. The breach was discovered after abnormal activity was detected, and Pajemploi acted swiftly to close the vulnerability, notify affected users, and inform regulatory authorities, including France's data privacy regulator CNIL. The incident temporarily restricted access to certain online services for impacted users. This breach highlights the ongoing targeting of government and public-sector databases holding sensitive citizen data. With regulatory requirements such as GDPR placing heavy penalties on agencies that fail proper controls, the Pajemploi incident underscores the urgency of robust data protection, zero trust segmentation, and advanced anomaly detection across Europe’s digital public services.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
Impact· high

The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024

In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers
Impact· high

GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers

GlobalLogic, a subsidiary of Hitachi, suffered a significant data breach after the Clop ransomware group exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. The breach, which began on July 10, 2024, went undetected for months and resulted in the theft of sensitive human resources data for nearly 10,500 current and former employees. Attackers accessed items such as names, SSNs, salary and bank details, passport information, and more, ultimately issuing extortion demands and threatening to leak the stolen data. GlobalLogic promptly initiated incident response actions, notified regulators, and applied Oracle's critical software patches to mitigate the threat after discovering the breach on October 9, 2024. This incident is part of a broader campaign targeting multiple Oracle customers, with ransom demands reaching as high as $50 million and almost 30 organizations named as victims on Clop’s data leak site. This attack underscores the ongoing threat of ransomware groups exploiting enterprise application vulnerabilities and highlights the growing risks posed by sophisticated supply chain and zero-day attacks. Organizations relying on popular ERP software must increase vigilance and prioritize patch management, while regulators and security leaders raise concern over attackers' speed, stealth, and extortion tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise
Impact· high

GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise

In early June 2024, GlobalLogic—a Hitachi-owned provider of digital engineering services—disclosed a significant data breach involving its Oracle E-Business Suite (EBS) platform. Attackers gained unauthorized access to EBS, resulting in the theft of sensitive data for over 10,000 current and former employees. The organization responded by launching an investigation, notifying affected individuals, and collaborating with Oracle and security experts to identify the root cause and contain the intrusion. The breach's exposure meant threat actors likely accessed personally identifiable information including names, addresses, and payroll details, elevating the risk of identity theft and further compromise. This incident highlights the ongoing vulnerabilities in complex legacy applications like Oracle EBS, especially as attackers increasingly target enterprise resource systems with sophisticated intrusion techniques. With regulatory scrutiny on employee data protection intensifying, organizations must prioritize robust segmentation, encryption, and visibility controls to counter evolving attack patterns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports