Scania experienced a cybersecurity breach where threat actors used stolen credentials to access and leak sensitive insurance claim documents. The incident involved extortion attempts and data selling on underground forums, highlighting vulnerabilities in third-party system security. #Scania #InfostealerMalware
Keypoints
- Threat actors exploited compromised external IT partner credentials to breach Scaniaโs insurance system.
- Stolen data, including insurance claim documents, was used for extortion and sold on hacking forums.
- The attack was carried out using credentials stolen by an infostealer malware on May 28, 2025.
- Scaniaโs response included shutting down the affected application and notifying privacy authorities.
- The breach highlights the risks of third-party vulnerabilities and credential theft in industrial sectors.