✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Human Resources/HR
Breach intelligence, attack campaigns, and threat reports targeting the Human Resources/HR sector.
Explore Other Sectors
Human Resources/HR Threat Reports
Starbucks 2026 Data Breach: Credential Theft via Phishing
In early 2026, Starbucks experienced a data breach affecting 889 employees after attackers gained unauthorized access to Partner Central accounts. The breach, discovered on February 6, 2026, involved threat actors obtaining login credentials through phishing websites impersonating the Partner Central portal. Exposed information included names, Social Security numbers, dates of birth, and financial account details. Starbucks promptly initiated an investigation, notified law enforcement, and offered affected employees two years of free identity theft protection and credit monitoring services. This incident underscores the persistent threat of credential theft via phishing attacks, emphasizing the need for robust security measures and employee awareness training to prevent unauthorized access to sensitive information.
4 months ago
Kill Chain
BlackSanta EDR Killer: A New Threat to HR Departments in 2026
In March 2026, a sophisticated cyberattack campaign was uncovered targeting human resources (HR) departments. Russian-speaking threat actors distributed malware via spear-phishing emails containing ISO image files disguised as resumes. Upon execution, these files initiated a multi-stage infection chain, culminating in the deployment of 'BlackSanta,' an Endpoint Detection and Response (EDR) killer. BlackSanta disabled security solutions by terminating antivirus processes, shutting down EDR agents, and suppressing system logging, allowing attackers to exfiltrate sensitive data undetected. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-blacksanta-edr-killer-spotted-targeting-hr-departments/?utm_source=openai)) This incident underscores a growing trend of cybercriminals exploiting HR workflows to infiltrate organizations. The use of advanced evasion techniques, such as steganography and DLL sideloading, highlights the increasing sophistication of these attacks. Organizations must enhance security measures within HR processes to mitigate such threats. ([darkreading.com](https://www.darkreading.com/threat-intelligence/blacksanta-edr-killer-hr-workflows?utm_source=openai))
4 months ago
Kill Chain
BlackSanta Malware: A New Era of Targeted Cyber Threats in HR Workflows
In early 2026, Russian-speaking threat actors initiated the 'BlackSanta' campaign, targeting human resources (HR) workflows to deploy sophisticated malware capable of disabling endpoint detection and response (EDR) systems. The attack begins with resume-themed ISO files delivered through recruitment channels, which, when opened, execute malicious shortcuts that trigger a multi-stage infection chain. This chain includes obfuscated PowerShell commands extracting payloads from steganographic images and sideloading malicious DLLs via legitimate applications. Once executed, the malware performs extensive validation to evade analysis environments before deploying the 'BlackSanta' EDR killer. This component loads legitimate but exploitable kernel drivers to gain low-level system access, subsequently disabling security protections, including antivirus processes, EDR agents, and system logging. This enables attackers to exfiltrate sensitive data over encrypted HTTPS channels with minimal detection risk. The campaign underscores the increasing sophistication of cyber threats targeting operational business workflows, particularly in HR environments. Organizations are advised to apply rigorous security measures to HR systems, including enhanced endpoint protections, monitoring for unusual activity, and increasing security awareness among recruiting teams to mitigate such attacks.
4 months ago
Kill Chain
Wynn Resorts Data Breach 2026: ShinyHunters' Latest Target
In February 2026, Wynn Resorts, a prominent Las Vegas-based hospitality company, confirmed a data breach involving unauthorized access to employee information. The cybercriminal group ShinyHunters claimed responsibility, alleging the theft of data affecting over 800,000 individuals. The compromised information reportedly includes names, email addresses, phone numbers, positions, salaries, start dates, and birth dates. ShinyHunters demanded a ransom of 23.34 Bitcoin (approximately $1.55 million) by February 23, 2026, threatening to release the data on the dark web if their demands were not met. Analysts suggest the breach may have exploited a vulnerability in Oracle PeopleSoft software, potentially through a compromised employee account. ([techradar.com](https://www.techradar.com/pro/security/top-las-vegas-hotel-is-the-latest-shinyhunters-ransomware-victim-hackers-demand-usd1-5-million-to-not-leak-data?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who employ advanced social engineering techniques such as voice phishing (vishing) to infiltrate organizations. The breach highlights the critical need for robust cybersecurity measures, including regular system updates, comprehensive employee training on phishing tactics, and the implementation of multi-factor authentication to safeguard sensitive data.
5 months ago
Kill Chain
WhatsApp Rolls Out Lockdown Security for High-Risk Users After Spyware Attacks
In early 2026, WhatsApp introduced a new 'Strict Account Settings' feature to defend high-risk users such as journalists and public figures against highly targeted spyware attacks. This rollout followed a series of incidents in recent years where advanced zero-click exploits—many attributed to government-linked actors—were used to deploy spyware like NSO Group’s Pegasus and Paragon Graphite onto users’ devices via messaging platforms. Exploits leveraged zero-day vulnerabilities in WhatsApp’s iOS and macOS clients, enabling attackers to compromise devices without user interaction, raising severe risks to privacy and personal safety for individuals facing nation-state targeting. This event is particularly relevant as threat actors increasingly adopt sophisticated, zero-click methods to compromise high-value targets. Security and privacy expectations for messaging apps are under heightened scrutiny, with regulators and civil society urging greater protections and rapid incident response to curtail such threats.
5 months ago
Kill Chain
Inside the 2024 Payroll Social Engineering Breach: Lessons from the Payroll Pirates
In early 2024, a major payroll provider experienced a sophisticated social engineering breach orchestrated by attackers dubbed the 'Payroll Pirates.' The threat actors engineered convincing phishing campaigns targeting payroll staff, tricking them into divulging critical credentials. Once initial access was secured, the attackers leveraged lateral movement techniques to escalate privileges and manipulate internal payroll processes, ultimately leading to fraudulent fund transfers and sensitive data exposure. Rapid detection efforts limited further impact, but the breach resulted in financial losses, operational disruption, and increased scrutiny over internal controls. This incident underscores the resurgence of highly targeted social engineering attacks, specifically in the payroll and finance sectors. As attackers blend human manipulation with advanced technical tactics, organizations must prioritize zero trust architectures, staff awareness, and continuous threat monitoring to defend against this evolving risk landscape.
6 months ago
Kill Chain
Malicious Chrome Extensions Target Workday and NetSuite Users in Coordinated Attack
In January 2026, cybersecurity researchers uncovered a campaign involving five malicious Google Chrome extensions that impersonated enterprise platforms such as Workday, NetSuite, and SuccessFactors. These extensions worked in unison to steal authentication tokens, disrupt incident response procedures, and seize control of victim user accounts. Attackers leveraged the trust users place in HR and ERP browser tools, exploiting their position to achieve data exfiltration and persistent account takeover across corporate environments. The attack’s main impact included unauthorized access to sensitive business systems and increased potential for widespread lateral movement within organizations. This incident underscores the growing sophistication of browser-based threats as attackers increasingly mimic legitimate business tools to infiltrate organizations. With a rise in social engineering and token theft techniques targeting identity and SaaS workflows, enterprises face heightened risk to cloud and hybrid environments, necessitating additional focus on endpoint, browser, and application-layer defenses.
6 months ago
Kill Chain
STAC6565 & Gold Blade Exploit Recruitment Platforms in Canadian Ransomware Assault (2025)
Between February 2024 and August 2025, a financially-motivated threat group tracked as STAC6565 (with strong overlaps to the Gold Blade/RedCurl actor cluster) orchestrated a series of nearly 40 targeted cyberattacks, predominantly on Canadian organizations. The attackers utilized spear-phishing campaigns, delivering weaponized resumes via legitimate recruitment platforms to HR staff to gain initial access. Once inside, the group deployed a multi-stage attack chain using custom loaders and tools like RedLoader, RPivot, and Chisel, culminating in QWCrypt ransomware deployment on high-value endpoints including hypervisors. Data theft and extortion were observed, with a clear pattern of operational sophistication and periods of dormancy followed by refined attack waves. This incident highlights the increasing adoption of "hack-for-hire" models, hybrid attacks combining espionage and ransomware, and the innovative abuse of legitimate business platforms to sidestep conventional email security. Organizations globally—particularly those with HR exposures and reliance on virtualized infrastructure—face heightened risk as attackers rapidly iterate on TTPs to maximize impact and evade detection.
6 months ago
Kill Chain
Pajemploi Data Breach Exposes 1.2 Million French Citizens: What Went Wrong?
In June 2024, French public agency Pajemploi, responsible for social security management for parents and home childcare providers, suffered a large-scale data breach. Attackers exploited a flaw in the agency's online system that enabled them to access personal data belonging to approximately 1.2 million individuals, including names, addresses, social security numbers, bank details, and tax identification data. The breach was discovered after abnormal activity was detected, and Pajemploi acted swiftly to close the vulnerability, notify affected users, and inform regulatory authorities, including France's data privacy regulator CNIL. The incident temporarily restricted access to certain online services for impacted users. This breach highlights the ongoing targeting of government and public-sector databases holding sensitive citizen data. With regulatory requirements such as GDPR placing heavy penalties on agencies that fail proper controls, the Pajemploi incident underscores the urgency of robust data protection, zero trust segmentation, and advanced anomaly detection across Europe’s digital public services.
6 months ago
Kill Chain
The Washington Post Oracle Supply Chain Breach: Lessons on Third-Party Risk in 2024
In June 2024, The Washington Post began notifying nearly 10,000 employees and contractors that their personal and financial information had been exposed following a breach involving Oracle-managed systems. The incident stemmed from an attack on a third-party vendor, believed to be tied to the widespread theft of cloud-stored data, which granted unauthorized access to sensitive HR and payroll details. The compromise was discovered post-incident, and affected individuals include current and former staff spanning back several years. Although there is no evidence of active misuse, the breach has prompted heightened security reviews. This breach exemplifies escalating risks inherent in supply-chain and third-party systems, with attackers increasingly targeting service providers to access large pools of critical enterprise data. Organizations across all sectors are now under pressure to strengthen controls around third-party integrations to reduce exposure.
6 months ago
Kill Chain
GlobalLogic's 2024 Ransomware Breach: Clop Hits Oracle E-Business Suite Customers
GlobalLogic, a subsidiary of Hitachi, suffered a significant data breach after the Clop ransomware group exploited a zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite. The breach, which began on July 10, 2024, went undetected for months and resulted in the theft of sensitive human resources data for nearly 10,500 current and former employees. Attackers accessed items such as names, SSNs, salary and bank details, passport information, and more, ultimately issuing extortion demands and threatening to leak the stolen data. GlobalLogic promptly initiated incident response actions, notified regulators, and applied Oracle's critical software patches to mitigate the threat after discovering the breach on October 9, 2024. This incident is part of a broader campaign targeting multiple Oracle customers, with ransom demands reaching as high as $50 million and almost 30 organizations named as victims on Clop’s data leak site. This attack underscores the ongoing threat of ransomware groups exploiting enterprise application vulnerabilities and highlights the growing risks posed by sophisticated supply chain and zero-day attacks. Organizations relying on popular ERP software must increase vigilance and prioritize patch management, while regulators and security leaders raise concern over attackers' speed, stealth, and extortion tactics.
6 months ago
Kill Chain
GlobalLogic Employee Data Breach: Lessons from the 2024 Oracle EBS Compromise
In early June 2024, GlobalLogic—a Hitachi-owned provider of digital engineering services—disclosed a significant data breach involving its Oracle E-Business Suite (EBS) platform. Attackers gained unauthorized access to EBS, resulting in the theft of sensitive data for over 10,000 current and former employees. The organization responded by launching an investigation, notifying affected individuals, and collaborating with Oracle and security experts to identify the root cause and contain the intrusion. The breach's exposure meant threat actors likely accessed personally identifiable information including names, addresses, and payroll details, elevating the risk of identity theft and further compromise. This incident highlights the ongoing vulnerabilities in complex legacy applications like Oracle EBS, especially as attackers increasingly target enterprise resource systems with sophisticated intrusion techniques. With regulatory scrutiny on employee data protection intensifying, organizations must prioritize robust segmentation, encryption, and visibility controls to counter evolving attack patterns.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports