The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Marketing/Advertising/Sales

Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.

172 threat reports
Page 10 of 15

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Marketing/Advertising/Sales Threat Reports

Showing 109–120 / 172 reports
LLM-Assisted Deanonymization: A New Era of Online Privacy Challenges
Impact· MEDIUM

LLM-Assisted Deanonymization: A New Era of Online Privacy Challenges

In February 2026, researchers from ETH Zurich and Anthropic demonstrated that large language models (LLMs) can effectively deanonymize pseudonymous online users by analyzing unstructured text data. Their method involved extracting identity-relevant features from anonymous posts, searching for candidate matches via semantic embeddings, and reasoning over top candidates to verify matches. This approach achieved up to 68% recall at 90% precision, significantly outperforming traditional methods. The study highlights the diminishing effectiveness of online pseudonymity and raises concerns about privacy and data protection in the digital age. ([arxiv.org](https://arxiv.org/abs/2602.16800?utm_source=openai)) This research underscores the urgent need for enhanced privacy measures and regulatory frameworks to protect individuals' online identities. As LLMs become more sophisticated, the potential for misuse in deanonymizing users poses significant risks, necessitating proactive strategies to safeguard personal information.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
1Campaign: The Cloaking Service Fueling Malicious Google Ads
Impact· MEDIUM

1Campaign: The Cloaking Service Fueling Malicious Google Ads

In February 2026, cybersecurity researchers uncovered '1Campaign,' a sophisticated cloaking service that enables threat actors to run malicious Google Ads while evading detection. Managed by a developer known as 'DuppyMeister,' 1Campaign has been active for at least three years. The platform allows attackers to display benign content to security researchers and automated scanners, while serving malicious content to real users. This technique prolongs the lifespan of malicious ads, facilitating phishing and crypto-draining campaigns. The service offers a user-friendly dashboard for real-time visitor filtering based on geography, ISP, and device characteristics, effectively blocking over 99% of non-targeted traffic. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/1campaign-platform-helps-malicious-google-ads-evade-detection/?utm_source=openai)) The emergence of 1Campaign highlights a growing trend in cybercrime where attackers leverage advanced cloaking techniques to bypass traditional security measures. This development underscores the need for enhanced detection capabilities and adaptive security strategies to counteract increasingly sophisticated malvertising campaigns.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Optimizely's 2026 Data Breach: A Case Study in Vishing Attacks
Impact· MEDIUM

Optimizely's 2026 Data Breach: A Case Study in Vishing Attacks

In February 2026, Optimizely, a New York-based ad tech company, experienced a data breach initiated through a sophisticated voice phishing (vishing) attack. The attackers, identified as the ShinyHunters group, impersonated internal IT staff to deceive employees into divulging single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. This social engineering tactic granted unauthorized access to Optimizely's systems, leading to the exfiltration of basic business contact information. The breach was confined to certain internal business systems, records in the customer relationship management (CRM) platform, and a limited set of internal documents used for back-office operations. There is no evidence that sensitive customer data or personal information beyond basic business contact information was accessed. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/?utm_source=openai)) This incident underscores a significant escalation in the operations of the ShinyHunters group, which has been actively targeting organizations through vishing attacks to compromise SSO credentials. The group's tactics have evolved to include harassment of victim personnel and other aggressive measures. ([itpro.com](https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns?utm_source=openai))

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Keenadu Malware: A 2026 Android Supply Chain Attack
Impact· HIGH

Keenadu Malware: A 2026 Android Supply Chain Attack

In early 2026, security researchers discovered 'Keenadu,' a sophisticated malware embedded within the firmware of various Android devices. This malware, introduced through a supply chain attack, integrates into the Android 'Zygote' process, allowing it to infect every application on the device. Once active, Keenadu grants attackers extensive control, enabling actions such as hijacking browser searches, committing ad fraud, and potentially accessing sensitive user data. The malware was found pre-installed on devices from multiple manufacturers, including the Alldocube iPlay 50 mini Pro tablet, and was also distributed through compromised applications on official app stores. As of February 2026, approximately 13,000 devices across countries like Russia, Japan, Germany, Brazil, and the Netherlands have been affected. ([darkreading.com](https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting firmware, highlighting the need for rigorous security measures throughout the manufacturing and software development processes. The ability of Keenadu to operate at the firmware level makes detection and removal particularly challenging, emphasizing the importance of proactive security practices and the use of trusted devices and software sources.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Uncovers AI Recommendation Poisoning Threat
Impact· MEDIUM

Microsoft Uncovers AI Recommendation Poisoning Threat

In February 2026, Microsoft disclosed a new cyber threat termed 'AI Recommendation Poisoning,' where businesses embed hidden instructions within 'Summarize with AI' buttons on their websites. When users click these buttons, the AI assistant's memory is manipulated via URL prompt parameters to favor certain companies or products in future recommendations. Over a 60-day period, Microsoft identified over 50 unique prompts from 31 companies across 14 industries, raising concerns about the integrity of AI-driven insights. This technique mirrors traditional search engine optimization (SEO) manipulation but targets AI systems directly, potentially leading to biased recommendations in critical areas such as health, finance, and security without user awareness. The emergence of AI Recommendation Poisoning underscores the evolving landscape of cyber threats targeting artificial intelligence systems. As AI becomes increasingly integrated into decision-making processes, ensuring the neutrality and reliability of AI outputs is paramount. Organizations must implement robust security measures to detect and prevent such manipulations to maintain trust in AI-driven recommendations.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Flickr's 2026 Data Breach: A Wake-Up Call for Third-Party Security
Impact· MEDIUM

Flickr's 2026 Data Breach: A Wake-Up Call for Third-Party Security

In early February 2026, Flickr, a prominent photo-sharing platform, identified a security vulnerability within a third-party email service provider's system. This flaw potentially exposed user data, including names, email addresses, usernames, account types, IP addresses, general locations, and Flickr activity. Importantly, passwords and payment card information remained secure. Upon discovery on February 5, Flickr promptly disabled access to the compromised system and initiated a comprehensive investigation to assess the breach's scope and impact. ([forbes.com](https://www.forbes.com/sites/daveywinder/2026/02/06/photo-sharing-platform-flickr-issues-data-breach-warning/?utm_source=openai)) This incident underscores the critical importance of robust security measures and vigilant monitoring of third-party service providers. As organizations increasingly rely on external vendors, ensuring these partners adhere to stringent security protocols is essential to safeguard sensitive user information and maintain trust.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Substack's 2025 Data Breach: A Wake-Up Call for Security Monitoring
Impact· MEDIUM

Substack's 2025 Data Breach: A Wake-Up Call for Security Monitoring

In October 2025, Substack, a prominent newsletter platform, experienced a data breach where an unauthorized third party accessed user data, including email addresses, phone numbers, and internal metadata. The breach was not detected until February 3, 2026, leading to a four-month delay in notification. Importantly, sensitive information such as passwords, credit card numbers, and financial data remained secure. ([techcrunch.com](https://techcrunch.com/2026/02/05/substack-confirms-data-breach-affecting-email-addresses-and-phone-numbers/?utm_source=openai)) This incident underscores the critical need for robust security monitoring and rapid breach detection mechanisms. The prolonged detection period highlights potential vulnerabilities in Substack's security infrastructure, emphasizing the importance of timely incident response to protect user data and maintain trust.

7 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Iron Mountain's 2026 Data Breach: A Closer Look
Impact· LOW

Iron Mountain's 2026 Data Breach: A Closer Look

In February 2026, Iron Mountain, a global leader in information management services, experienced a security incident involving unauthorized access to a single folder on a public-facing file-sharing site. The Everest ransomware group claimed responsibility, alleging the theft of 1.4 TB of internal documents containing client information. However, Iron Mountain clarified that the breach was limited to marketing materials, accessed through a compromised login credential, with no evidence of ransomware deployment or further system compromise. This incident underscores the persistent threat posed by ransomware groups like Everest, which have increasingly targeted organizations across various sectors. Their tactics often involve exploiting compromised credentials to gain unauthorized access, emphasizing the need for robust access controls and vigilant monitoring to prevent such breaches.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Instagram's 2026 Private Profile Photo Leak: A Privacy Wake-Up Call
Impact· MEDIUM

Instagram's 2026 Private Profile Photo Leak: A Privacy Wake-Up Call

In October 2025, security researcher Jatin Banga discovered a vulnerability in Instagram's private account feature, where private profile photos and captions were embedded in publicly accessible server responses. This flaw allowed unauthenticated users to access content intended for approved followers. Banga reported the issue to Meta on October 12, 2025, and although Meta initially classified it as a CDN caching problem, the exploit ceased functioning around October 16, 2025. However, Meta later closed the case as 'not applicable,' stating the vulnerability could not be reproduced. This incident underscores the critical importance of rigorous authorization checks in web applications to prevent unauthorized data exposure. Organizations must ensure that private content remains inaccessible to unauthorized users, as such vulnerabilities can lead to significant privacy breaches and erode user trust.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Malicious Chrome Extensions Compromise User Security by Hijacking Affiliate Links and Stealing ChatGPT Tokens
Impact· HIGH

Malicious Chrome Extensions Compromise User Security by Hijacking Affiliate Links and Stealing ChatGPT Tokens

In January 2026, cybersecurity researchers uncovered a series of malicious Google Chrome extensions designed to hijack affiliate links and steal OpenAI ChatGPT authentication tokens. Notably, the 'Amazon Ads Blocker' extension, uploaded by '10Xprofit' on January 19, 2026, claimed to block Amazon ads but covertly injected the developer's affiliate tag into product links, replacing existing ones. This extension was part of a larger cluster targeting e-commerce platforms like AliExpress, Amazon, Best Buy, Shein, Shopify, and Walmart. Additionally, 16 other extensions masquerading as ChatGPT productivity tools were found to exfiltrate ChatGPT session tokens, granting attackers full access to users' conversation histories and associated data. This incident underscores the growing trend of malicious browser extensions exploiting the popularity of AI tools and e-commerce platforms. The deceptive nature of these extensions, often appearing legitimate and even bearing 'Featured' badges, highlights the need for heightened vigilance among users and stricter vetting processes by browser extension stores to prevent such security breaches.

7 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
AI-Powered Android Malware Unleashes New Click-Fraud Wave via Xiaomi App Store
Impact· high

AI-Powered Android Malware Unleashes New Click-Fraud Wave via Xiaomi App Store

In January 2026, cybersecurity researchers at Dr.Web uncovered a sophisticated new Android malware family distributed via Xiaomi’s GetApps, popular third-party APK sites, and messaging platforms like Telegram and Discord. This malware leverages AI-driven image analysis using Google’s TensorFlow.js to identify and autonomously click on hidden browser ads within compromised apps, particularly games, simulating user behavior without obvious signs to victims. The malware is delivered through legitimate-looking apps, which update with malicious payloads post-installation. Impacts include increased battery consumption, higher data charges, and indirect monetization for attackers. This incident exemplifies the evolution of mobile ad fraud TTPs, as attackers increasingly deploy AI/ML for advanced automation and evasion. The trend signals rising risks to mobile advertising integrity and higher scrutiny for app stores’ vetting processes, especially on third-party and OEM-specific app markets.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
North Korean PurpleBravo Fakes Job Interviews to Breach Global Firms: 2026 Incident Analysis
Impact· low

North Korean PurpleBravo Fakes Job Interviews to Breach Global Firms: 2026 Incident Analysis

In January 2026, the North Korean-aligned PurpleBravo threat group orchestrated a sophisticated social engineering campaign targeting more than 3,000 unique IP addresses. The attackers posed as recruiters from leading firms to lure victims, primarily within AI, cryptocurrency, financial services, IT, marketing, and software development, into fake job interviews. Exploiting trust through convincing communications, PurpleBravo gained access to targeted organizations across Europe, South Asia, the Middle East, and Central America, compromising data and exposing confidential operational environments. This campaign underscores the evolution of nation-state social engineering methods, leveraging supply chain trust and exploiting interest in career mobility. As geopolitical tensions rise and attackers continually refine techniques, organizations must double down on identity-centric security and awareness to mitigate evolving social engineering risks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(low)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports