The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Outsourcing/Offshoring
Breach intelligence, attack campaigns, and threat reports targeting the Outsourcing/Offshoring sector.
Explore Other Sectors
Outsourcing/Offshoring Threat Reports
Supply Chain Breach Hits Italian Rail Group via Almaviva: 2.3TB Data Stolen in 2024
In early June 2024, a threat actor claimed responsibility for breaching the Italian railway operator FS Italiane Group by targeting its IT services provider, Almaviva, resulting in the exfiltration of 2.3TB of sensitive data. The attackers reportedly gained initial access through compromised internal systems and leveraged this infiltration to move laterally, eventually accessing and downloading a vast trove of corporate documents, contracts, and possibly personal information related to employees and customers. The incident exposed Italy's transportation sector to significant risk of espionage, operational disruption, and data loss, igniting widespread concern among critical infrastructure operators. This breach highlights the mounting threat posed by attacks on trusted IT service providers, which serve as gateways to high-value targets. With the proliferation of supply chain and third-party compromise incidents globally, organizations in critical industries must reassess their lateral movement controls, segmentation, and third-party risk governance.
8 months ago
Kill Chain
Conduent’s 2024 Data Breach: Over 10 Million Records Stolen in Major BPO Attack
In June 2024, business process outsourcing giant Conduent confirmed a major data breach after attackers gained unauthorized access to its systems, exposing sensitive information of approximately 10.5 million individuals across the United States. The breach came to light following regulatory disclosures and was attributed to exploitation of a third-party vulnerability, allowing attackers to access personal data used in Conduent's healthcare and government services contracts. Impacted data reportedly includes names, social security numbers, addresses, and related identifiers tied to outsourced processing for public sector and healthcare organizations. This breach underscores persistent risks faced by organizations managing data at scale for critical sectors, with attackers increasingly targeting supply chain or third-party gaps. Growing regulatory scrutiny and rising consumer awareness are amplifying the urgency for improved data protection, robust access controls, and ongoing monitoring against sophisticated threat behaviors.
8 months ago
Kill Chain
Capita Hit by Black Basta Ransomware: 6.6 Million Impacted in 2023 Breach
In March 2023, UK outsourcing giant Capita suffered a major data breach after an employee downloaded a malicious file, giving threat actors access to internal systems. The Black Basta ransomware gang exploited delayed response and weak access controls to maintain persistence for 58 hours, move laterally, and exfiltrate nearly a terabyte of sensitive data covering 6.6 million individuals, including customers of over 325 pension providers. The attackers deployed ransomware, resetting passwords and disrupting access, forcing Capita to take some systems offline and ultimately resulting in a £14 million regulatory fine after failing to meet key security requirements. This breach highlights the growing menace of ransomware operations targeting supply chain and service providers, with regulatory authorities emphasizing rapid response, robust access controls, and continuous security testing. Organizations face increased scrutiny to maintain strong cybersecurity baselines as attackers evolve tactics and exploit internal weaknesses.
8 months ago
Kill Chain
How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach
In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release. This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.
8 months ago
Kill Chain
Brickstorm Backdoor: UNC5221’s Stealthy Edge Device Supply Chain Attack (2024)
In a sophisticated cyber-espionage campaign uncovered in 2024, the China-linked group UNC5221 systematically compromised edge network appliances—such as firewalls, VPNs, and virtualization hosts—unable to run traditional EDR agents. By deploying a newly evolved backdoor known as 'Brickstorm,' the attackers gained highly persistent, stealthy access to organizations in technology, legal, SaaS, and outsourcing sectors. The malware, enhanced with delayed activation and strong obfuscation, leveraged unique command-and-control domains per victim and often exploited both zero-day and publicly known vulnerabilities. High-value credential harvesting and lateral movement to strategic systems, such as VMware vCenter, enabled the threat actor to maintain undetected access for an average of 393 days, facilitating both data theft and potential downstream customer compromise. This incident highlights the evolving risk posed by state-sponsored actors targeting blind spots in infrastructure—especially unmanaged or agentless edge devices critical to supply chains and cloud access. With ongoing innovation in stealth tactics and platform abuse, the Brickstorm campaign marks a serious escalation in the complexity and duration of modern supply chain threats.
8 months ago
Kill Chain
UNC5221 Breach: BRICKSTORM Backdoor Hits U.S. Legal & Tech Sectors (2025)
In September 2025, a sophisticated cyber espionage operation targeting U.S.-based legal services, SaaS providers, BPOs, and technology firms was attributed to UNC5221, a suspected China-nexus threat actor. The attackers leveraged the BRICKSTORM backdoor as their primary access mechanism, gaining initial entry through spear-phishing campaigns and exploiting software vulnerabilities. Once inside, they focused on lateral movement, data gathering, and exfiltration, leveraging encrypted channels to avoid detection. The incident resulted in exposure of sensitive legal documents, business data, and intellectual property, highlighting the advanced TTPs of nation-state actors targeting critical professional sectors. This breach exemplifies the growing prevalence of targeted espionage campaigns against high-value service and technology industries. It underscores the urgency for organizations to adopt advanced threat detection, zero trust segmentation, and strong encrypted communication controls in the face of persistent, well-resourced adversaries and heightened regulatory scrutiny.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports