ShinyHunters Leak Alleged Data of Millions From SoundCloud, Crunchbase and Betterment

ShinyHunters claim to have leaked tens of millions of records from SoundCloud, Crunchbase, and Betterment after failed extortion attempts, publishing alleged partial databases on a new dark web .onion leak site. The group has also claimed responsibility for an Okta SSO vishing campaign, and researchers and the affected companies are investigating…

Read More
Crims hit the easy button for IT helpdesk scams

Custom voice-phishing kits sold on dark web forums and messaging platforms provide real-time, phone-assisted tools that help criminals intercept credentials and multi-factor authentication codes for Google, Microsoft, and Okta accounts. These “impersonation-as-a-service” offerings mimic authentication flows, forward harvested credentials (often via Telegram), recruit native-English callers for helpdesk scams, and have enabled…

Read More
Manage My Health Data Breach Sparks Warnings Over Impersonation and Phishing Attempts

Manage My Health has contained a late‑2023 cyberattack that accessed documents in its “My Health Documents” feature and has notified most potentially affected users. The company warns fraudsters are impersonating the patient portal to send phishing messages while it works with regulators, the High Court, and partners like IDCARE to monitor…

Read More
December 2025 Security Issues in Korean & Global Financial Sector

The report documents major financial-sector incidents including a 3-million-record database leak from Indonesia’s largest bank sold on DarkForums by the actor BreachLaboratory and a ransomware breach by INC Ransom that published roughly 100GB of stolen data. It additionally analyzes a phishing email campaign targeting financial institutions, lists top malware strains affecting…

Read More
PurpleBravo’s Targeting of the IT Software Supply Chain

Recorded Future / Insikt Group documents PurpleBravo, a North Korean-linked campaign that uses fraudulent developer/recruiter personas and malicious GitHub repositories to deliver infostealers and multi-platform RATs (BeaverTail, GolangGhost/PylangGhost, InvisibleFerret) targeting software developers—especially in the cryptocurrency sector and South Asia. The report details obfuscated JavaScript (Base64 + XOR), RC4/MD5 C2 protocols, registry Run-key persistence, Chrome credential-theft techniques (including DPAPI and app-bound bypasses), extensive C2 infrastructure (dozens of IPs and Astrill VPN nodes), and overlap with PurpleDelta activity. #PurpleBravo #BeaverTail

Read More