The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Marketing/Advertising/Sales

Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.

171 threat reports
Page 13 of 15

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Marketing/Advertising/Sales Threat Reports

Showing 145–156 / 171 reports
Spear-Phishers Impersonate Tesla & Red Bull Recruiters in Targeted Job Scam (2024)
Impact· high

Spear-Phishers Impersonate Tesla & Red Bull Recruiters in Targeted Job Scam (2024)

In early 2024, cyber attackers launched a coordinated spear-phishing campaign targeting social media influencers and digital marketing professionals by impersonating talent recruiters from popular brands such as Tesla and Red Bull. The threat actors distributed convincing fake job offers via email and LinkedIn, luring victims to share personal information, credentials, and résumé files. The adversaries’ primary objectives were data theft and potential follow-up attacks leveraging stolen credentials and information, causing reputational damage and exposing a sensitive subset of professionals. This incident highlights the growing use of sophisticated social engineering tactics against targeted individuals in the digital marketing and influencer space. Similar attacks have proliferated across industries, underlining the urgent need for heightened workforce awareness, advanced email security, and robust identity controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ICTBroadcast RCE Vulnerability: Hackers Gain Remote Shell Access via Cookie Exploit in 2025
Impact· medium

ICTBroadcast RCE Vulnerability: Hackers Gain Remote Shell Access via Cookie Exploit in 2025

In October 2025, a critical remote code execution vulnerability (CVE-2025-2611, CVSS 9.3) in ICTBroadcast's autodialer platform was actively exploited by threat actors. By leveraging improper input validation in the application's session cookie handler, attackers achieved unauthenticated remote shell access to internet-exposed servers. This exploit enabled malicious actors to execute arbitrary system commands, potentially compromising sensitive data and business operations for organizations using ICTBroadcast. The incident required immediate patching and forensic investigation to contain the breach and restore normal operations. This breach highlights the persistent risk posed by zero-day vulnerabilities in widely used communications software, especially as remote access vector attacks surge. It underscores the strategic shift among attackers toward supply chain and software-specific exploits, which remain difficult to rapidly mitigate across diverse deployment environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack
Impact· low

Adobe AEM 2025 Breach: CISA Flags Critical Application Flaw Under Active Attack

In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) raised alarms about a critical misconfiguration vulnerability (CVE-2025-54253) impacting Adobe Experience Manager (AEM). This flaw, assigned a CVSS score of 10.0, allows remote unauthenticated attackers to achieve arbitrary code execution on vulnerable AEM instances. Active exploitation was confirmed as attackers leveraged the bug to gain foothold, escalate privileges, and deploy malware on targeted organizations, potentially exposing sensitive data and compromising internal operations. The incident highlights the risks of unpatched enterprise software within digital supply chains and data-driven organizations. The AEM vulnerability is currently notable due to increased exploitation by multiple threat actors, coinciding with a larger trend of critical zero-day application flaws being used in advanced persistent attacks. Regulatory agencies and security experts underscore the urgency for patching exposed business applications given the frequency and sophistication of exploitation campaigns in 2025.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
131 Chrome Extensions Hijack WhatsApp Web: The 2025 Brazilian Spam Campaign
Impact· high

131 Chrome Extensions Hijack WhatsApp Web: The 2025 Brazilian Spam Campaign

In October 2025, a coordinated cyberattack was uncovered where 131 malicious Chrome browser extensions—clones of a popular WhatsApp Web automation tool—were used to hijack users’ sessions and launch an automated spam campaign targeting Brazilian users. Researchers from security company Socket found that these plugins, sharing an identical codebase and infrastructure, infected over 20,000 users by enticing them to install seemingly legitimate add-ons, enabling attackers to take control of browser sessions, inject spam messages, and exfiltrate private data at scale. The incident underscores the risks associated with browser extension supply chain threats, exposing enterprises and individuals to large-scale account compromise and privacy breaches. This breach is particularly significant as it demonstrates the adaptability and persistence of threat actors in abusing browser supply routes and leveraging rebranded extensions to evade traditional security controls. The campaign’s targeting of WhatsApp Web also signals a shift toward exploiting widely-used communication channels for coordinated spam and fraud, spotlighting the critical need for proactive browser extension vetting and user awareness.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
TikTok-Delivered Infostealer: ClickFix Campaign Compromises Credentials
Impact· medium

TikTok-Delivered Infostealer: ClickFix Campaign Compromises Credentials

In October 2025, a widespread campaign leveraged TikTok videos masquerading as free activation guides for popular software titles—including Windows, Adobe products, and Spotify—to distribute information-stealing malware. Attackers used "ClickFix" social engineering to instruct viewers to run obfuscated PowerShell commands, delivering the Aura Stealer infostealer and an additional payload via Cloudflare-hosted executables. The attack enabled threat actors to harvest browser credentials, authentication cookies, and wallet data from victims, leading to high risk of account compromise and data theft. Infection occurred after users were tricked into executing single-line commands under the guise of software activation or fixes. This incident highlights the increasing weaponization of social media platforms as initial access vectors for malware and demonstrates the growing sophistication of infostealer campaigns. The trend underscores the urgent need for organizations to address social engineering risks and update awareness programs as attackers rapidly innovate their distribution methods.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
MANGO Data Breach 2024: Third-Party Vendor Incident Exposes Customer Data
Impact· medium

MANGO Data Breach 2024: Third-Party Vendor Incident Exposes Customer Data

In April 2024, Spanish fashion retailer MANGO reported that a data breach exposed customer personal information after one of its marketing vendors was compromised. The incident came to light when MANGO began notifying affected customers, stating that data such as names, contact details, and potentially other identifiers had been accessed without authorization. The intrusion was possible due to attackers breaching the marketing service provider’s environment, reflecting a concerning third-party risk. MANGO responded by collaborating with the vendor, investigating the incident, notifying authorities, and reinforcing security controls. This breach underscores a growing trend in supply-chain attacks where threat actors exploit weaker security in trusted partners. It highlights the urgent need for stringent vendor management, robust segmentation, and continuous monitoring, especially as regulatory focus intensifies on safeguarding consumer data throughout the supply chain.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Hackers Exploit Auth Bypass in Service Finder WordPress Theme (CVE-2025-5947)
Impact· medium

Hackers Exploit Auth Bypass in Service Finder WordPress Theme (CVE-2025-5947)

In the autumn of 2025, a critical authentication bypass vulnerability (CVE-2025-5947) was discovered and actively exploited in the Service Finder WordPress theme, affecting versions 6.0 and older. Attackers leveraged improper validation in the 'service_finder_switch_back()' function, allowing them to impersonate any user—including administrators—simply by sending HTTP requests with a crafted cookie or query parameter. The flaw enabled threat actors to gain full administrative control over thousands of websites, with over 13,800 exploitation attempts recorded by Wordfence since August 1. Attackers could then create or modify site content, add malicious code, or export sensitive data undetected, putting site owners and users at risk. This breach is particularly relevant as it illustrates the continued targeting of WordPress ecosystems with privilege escalation exploits, highlighting growing risks from vulnerable third-party themes and plugins. It underscores the urgency of rapid patching, improved logging, and continuous monitoring to defend against evolving web application threats.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023
Impact· high

Salesloft Drift Supply Chain Breach: How Okta and Zscaler Responded in 2023

In August 2023, a sophisticated supply chain attack targeting Salesloft and Drift exposed the vulnerabilities of OAuth token management in SaaS integrations. Threat actor group UNC6395 compromised Salesloft's GitHub and later leveraged compromised OAuth tokens from the Drift platform, affecting over 700 customers—including security leaders Okta and Zscaler. While Okta’s proactive use of IP restrictions blocked malicious API requests and prevented data loss, Zscaler experienced a significant breach, exposing both customer and internal data. The campaign unfolded rapidly, relying on automated scripts for widespread data extraction via legitimate channels before defenses were activated. This incident underscores the growing pipeline threat of API- and token-driven attacks across integrated SaaS ecosystems. As organizations increasingly rely on third-party applications, traditional security mechanisms and risk due diligence are proving insufficient against lateral supply-chain intrusion tactics and the automated exploitation of tokenized access.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Adobe Analytics 2025 Bug Exposes Cross-Tenant Tracking Data
Impact· high

Adobe Analytics 2025 Bug Exposes Cross-Tenant Tracking Data

In September 2025, an ingestion bug in Adobe Analytics caused cross-tenant data exposure, allowing customer tracking data from some organizations to appear in the analytics reports of others for nearly a day. The incident began on September 17 due to a performance optimization update that led to incorrect data values surfacing in Analysis Workspace reports. Approximately 3-5% of collected data—across Data Feeds, Live Stream, and scheduled reports—was impacted, with some fields being overwritten by data from other tenants. Adobe promptly reverted the change on September 18 and undertook remediation to cleanse datasets, advising customers to purge affected data from systems and backups to prevent further exposure. This incident underscores the risk posed by inadvertent data exposure within multi-tenant SaaS platforms and the criticality of robust data segregation and validation controls. With regulatory scrutiny over data privacy at an all-time high, such events illustrate how operational changes, even absent malicious intent, can have significant compliance and business ramifications for all affected customers.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Harrods Suffers Major Supply Chain Breach: 430,000 Customer Records Exposed in 2025
Impact· high

Harrods Suffers Major Supply Chain Breach: 430,000 Customer Records Exposed in 2025

In September 2025, UK luxury retailer Harrods disclosed a major cybersecurity incident after attackers exploited a vulnerability in a third-party supplier, leading to the exposure of 430,000 e-commerce customer records. The breach, unrelated to earlier attacks by Scattered Spider, leveraged a supply chain vector similar to the widespread Salesloft OAuth attack, allowing data exfiltration from connected Salesforce environments. Compromised data included names, contact information, and internal marketing labels, but excluded financial data and passwords. Harrods responded by promptly notifying affected customers and authorities, while refusing to engage with extortion attempts by the threat actor. This incident illustrates the growing risk of supply chain compromise in the retail and e-commerce sector, where attackers increasingly exploit third-party platforms for large-scale data theft. As regulatory scrutiny intensifies and similar attacks proliferate, organizations must reevaluate supply chain security controls and customer notification protocols.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data
Impact· medium

Salesforce Agentforce 2024: ForcedLeak AI Prompt Injection Breach Exposes CRM Data

In June 2024, researchers at Noma Security identified a severe vulnerability in Salesforce's Agentforce AI agents, termed 'ForcedLeak'. By exploiting prompt injection via web-to-lead forms, attackers were able to manipulate Agentforce into exfiltrating sensitive CRM data, including PII, corporate secrets, and transactional details, to unauthorized locations. The vulnerability hinged on whitelist misconfigurations of trusted domains and the agent’s overly broad prompt interpretation, leading to an attacker-controlled data leak chain. Salesforce addressed data exfiltration by patching URL restrictions and acquiring an expired trusted domain but ongoing risks persist with agentic AI’s prompt processing logic. The incident underscores the growing challenges as mainstream SaaS platforms rapidly integrate autonomous GenAI features, often lacking robust input validation and security boundaries. High CVSS-scored issues like ForcedLeak exemplify the urgent need for zero trust guardrails and more resilient AI security frameworks given the increasing velocity and sophistication of prompt injection attacks.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach
Impact· medium

Salesforce AI Prompt Injection Bug Exposes CRM Data in 2025 Breach

In September 2025, security researchers at Noma Security identified a critical vulnerability, termed ForcedLeak (CVSS 9.4), in Salesforce Agentforce, an AI-powered platform for constructing automation agents. The flaw allowed threat actors to launch indirect prompt injection attacks against Agentforce’s integration with Salesforce’s CRM, opening avenues for exfiltration of sensitive customer relationship data. The attack leveraged manipulated AI prompts that bypassed input validation, ultimately resulting in confidential business and customer information being at risk of exposure until Salesforce deployed a rapid patch. This incident highlights the growing risks stemming from AI prompt injection vulnerabilities as more enterprises embrace AI-integrated SaaS for customer-facing processes. The Salesforce episode underscores regulatory and security urgency to address trust boundaries around rapidly-evolving AI within business-critical platforms.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports