Information Technology/IT
Breach intelligence, attack campaigns, and threat reports targeting the Information Technology/IT sector.
Explore Other Sectors
Information Technology/IT Threat Reports
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
8 months ago
Kill Chain
Discord 2024 Breach: Third-Party Support Attack Exposes User Data
In early March 2024, Discord disclosed a data breach after threat actors compromised a third-party customer service provider’s systems. Attackers gained access to customer support tickets, exposing partial payment information, names, email addresses, and government-issued IDs of Discord users who had interacted with support. The breach occurred through unauthorized access to the provider’s internal systems, allowing exfiltration of sensitive, personally identifiable information linked to support requests. Discord promptly investigated, notified affected users, and terminated the third party’s access to its systems. This incident highlights the increasing risks associated with third-party vendors handling sensitive data, especially as social engineering and supply chain attacks become more common. Growing scrutiny from regulators and customers underscores the need for robust supply chain security and continuous monitoring of vendor access.
8 months ago
Kill Chain
Palo Alto Networks Faces Massive Surge in Login Portal Recon Scans
In early October 2025, cybersecurity firm GreyNoise detected a sharp 500% spike in reconnaissance scans targeting Palo Alto Networks GlobalProtect and PAN-OS login portals. Over 1,285 unique suspicious IP addresses, predominantly from the U.S., but also from the UK, Canada, the Netherlands, and Russia, launched automated probes against these authentication portals. The campaign appeared targeted, leveraging data from public scanning platforms like Shodan and Censys. No verified exploit or compromise has been confirmed, with Palo Alto Networks asserting their systems remain secure and attributing much of the observed activity to external fingerprinting, not internal breach. This incident highlights a broader escalation in focused reconnaissance tactics against major infrastructure platforms, often preceding attempts to weaponize new vulnerabilities. Organizations should remain vigilant about emerging threats, monitor authentication endpoints, and proactively patch known and zero-day-related risks.
8 months ago
Kill Chain
ShinyHunters Extorts 39 Firms in Salesforce OAuth Supply Chain Breach
In October 2025, the extortion group known as 'Scattered Lapsus$ Hunters'—a coalition including ShinyHunters, Scattered Spider, and Lapsus$—launched a data leak site to extort 39 companies after a coordinated campaign exploiting Salesforce OAuth integrations. The attackers used sophisticated voice phishing to trick employees into connecting malicious OAuth apps to corporate Salesforce instances, enabling unauthorized database access. Stolen data included sensitive customer records from major global brands such as FedEx, Disney, Google, and Marriott, with threat actors demanding ransom to prevent broader public disclosure. Salesforce stated there was no compromise of its platform, but investigations continue. This incident highlights the rising threat of supply chain and identity-based attacks targeting SaaS platforms, exploiting user trust and third-party integrations. With the growing adoption of SaaS solutions and increasing regulatory focus (e.g., GDPR), enterprises face mounting pressure to implement robust identity, access governance, and monitoring controls to defend against mass-scale data exfiltration and extortion.
8 months ago
Kill Chain
Renault and Dacia UK 2025: Customer Data Breach Highlights Supply Chain Risks
In October 2025, Renault and Dacia UK notified customers of a data breach resulting from a cyberattack at an undisclosed third-party provider. The breach exposed sensitive information including full names, gender, phone numbers, email and postal addresses, as well as vehicle identification and registration numbers. While no financial data was compromised, this incident potentially increases the risk of phishing, scams, and targeted social engineering. Renault confirmed that the third-party provider contained the incident and regulatory authorities, including the UK’s Information Commissioner's Office, were notified as part of standard response. This event highlights the persistent risks posed by supply chain vulnerabilities, where companies are exposed through third-party relationships. As cyberattackers increasingly target vendors to bypass primary defenses, organizations must intensify scrutiny of their supply chains and enhance segmentation, monitoring, and incident response to align with evolving regulatory and threat landscapes.
8 months ago
Kill Chain
Cavalry Werewolf APT Hits Russian Agencies with FoalShell and StallionRAT in 2025
In October 2025, a sophisticated threat actor known as Cavalry Werewolf, believed to share links with the YoroTrooper group, orchestrated targeted cyber attacks against Russian public sector agencies. Utilizing custom malware families FoalShell and StallionRAT, the attackers infiltrated key government systems, establishing covert access for potential espionage and data theft. Security firm BI.ZONE detected the activity, noting operational overlaps with other known clusters such as SturgeonPhisher and Comrade Saiga. The cyber-espionage campaign leveraged a mix of spear-phishing, credential theft, and advanced persistence techniques to evade detection and conduct lateral movement within critical infrastructure environments. This incident highlights a continuing trend of state-aligned espionage campaigns that exploit zero trust gaps, advanced malware, and blended tactics to compromise sensitive government data. The increasing frequency and sophistication of such attacks elevate the urgency for robust segmentation and monitoring strategies within public sector networks.
8 months ago
Kill Chain
Detour Dog Exposes DNS-Powered Stealer Risk: A 2025 Campaign Analysis
In October 2025, threat intelligence researchers revealed that the actor known as Detour Dog orchestrated wide-scale campaigns to deliver the Strela Stealer information stealer using DNS-powered malware infrastructure. Detour Dog’s operation involved maintaining control over a network of malicious domains, enabling initial delivery of a backdoor named StarFish, which then facilitated deployment of Strela Stealer. This campaign leveraged covert DNS traffic and evasion techniques, making threat detection and containment difficult for enterprise defenders. Victimized organizations faced increased risk of credential theft, data exfiltration, and operational disruption as a result. This incident highlights the rising trend of weaponizing benign protocols like DNS for malware delivery and lateral movement, as well as the emergence of advanced information stealers targeting enterprise networks and cloud environments. Organizations must adapt controls and detection strategies to defend against increasingly sophisticated, protocol-abusing threats.
8 months ago
Kill Chain
Microsoft AI Voice Cloning: A New SaaS Security Exposure in 2024
In early 2024, Microsoft’s ‘Speak for Me’ AI-powered voice cloning technology emerged as a significant security risk when researchers and privacy advocates highlighted its potential for abuse. Attackers could exploit the deep integration of this feature into productivity platforms like Teams, enabling the creation of near-perfect voice replicas for use in live calls or AI-driven agent interactions across SaaS environments. The risk is compounded by the platform’s capability to reproduce voices without comprehensive enrollment checks, opening avenues for sophisticated impersonation attacks and social engineering, ultimately undermining trust in corporate communications and user authentication. This incident underscores an urgent trend: as generative AI technologies become embedded in mainstream communications platforms, attackers are adopting new TTPs focused on identity and voice deception. Enterprises must address these risks proactively, with regulatory scrutiny growing over AI misuse in both authentication and privacy contexts.
8 months ago
Kill Chain
UAT-8099 Hijacks IIS Servers: SEO Fraud and Data Theft Exposed
In early 2024, the Chinese-language cybercrime group UAT-8099 orchestrated a sophisticated series of attacks targeting Internet Information Services (IIS) web servers belonging to reputable organizations worldwide, including technology firms, telecoms, and universities. Exploiting insecure internet-facing servers with weak file upload controls, the attackers established footholds using open source web shells. They escalated privileges, enabled remote access with OSS reverse proxy tools, and deployed 'BadIIS' implants to perform SEO poisoning, redirecting search engine traffic to fraudulent gambling and scam sites. Simultaneously, the threat actors exfiltrated credentials, configuration files, and certificates, setting the stage for future attacks or data sales on darknet markets. This campaign demonstrates the threat actor's multi-pronged approach, blending fraud and espionage in ways that evade immediate detection. The incident highlights a growing global trend where SEO manipulation and credential theft converge, exposing organizations to operational, reputational, and regulatory risks amidst rising regulatory scrutiny around digital trust and supply chain integrity.
8 months ago
Kill Chain
Jaguar Land Rover Ransomware Breach: 2024 Supply Chain Disruption Case Study
In early 2024, Jaguar Land Rover (JLR) suffered a disruptive ransomware attack that exposed the company’s vulnerability to advanced persistent threats. Attackers, suspected to be Medusa ransomware operators, leveraged residual access from a prior breach to re-enter JLR’s systems, eventually encrypting sensitive data and disrupting operations across its supply chain. The breach forced significant production slowdowns, delayed supplier payments, and prompted the company to enact emergency IT protocols and notify regulatory authorities. This incident highlights the growing threat of repeat ransomware campaigns targeting global manufacturers and their digital supply chains. It underscores the critical need for continuous detection, east-west network visibility, and rigorous post-breach remediation in defending against evolving ransomware tactics.
8 months ago
Kill Chain
Clop Ransomware Targets Oracle E-Business Suite Customers in 2025 Extortion Campaign
In late September 2025, the Clop ransomware group launched a targeted extortion campaign against Oracle E-Business Suite customers. Using compromised third-party email accounts, attackers sent personalized emails to executives, claiming to have exfiltrated sensitive corporate data via known vulnerabilities in Oracle's ERP software. The emails provided 'proof' offers, imposed a payment deadline, and threatened public exposure or resale of stolen data if demands were not met. Oracle acknowledged the incident, referencing vulnerabilities patched in the July 2025 update, but did not confirm direct data exfiltration or specify the flaws under exploitation. This incident highlights the evolution of ransomware-as-a-service models that blend data theft, psychological pressure, and supply-chain targeting. It underscores urgent enterprise risk around unpatched ERP systems, the danger of credential compromise, and the increasing sophistication of financially motivated threat actors such as Clop.
8 months ago
Kill Chain
Android Spyware Masquerades as Messaging Apps in UAE: ESET Uncovers 2024 Mobile Threats
In June 2024, ESET researchers uncovered two Android spyware campaigns—ProSpy and ToSpy—masquerading as popular messaging apps Signal and ToTok, specifically targeting residents in the United Arab Emirates. The malware was distributed via third-party websites impersonating legitimate app stores, such as the Samsung Galaxy Store, and required users to manually install them. Upon installation, the spyware requested extensive permissions, gaining access to contacts, messages, stored files, audio, images, and more, enabling extensive data exfiltration. The campaigns utilized regional delivery tactics to focus on UAE users, exploiting trusted local app brands. These findings highlight a persistent threat trend: attackers disguising malware as legitimate communication apps to bypass official channels and exploit regional trust. With increased scrutiny on privacy and secure messaging, such campaigns pose heightened operational and compliance risks for organizations and individuals alike, underscoring the urgent need for enhanced mobile security measures and user awareness.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports