CNO Services: Sicherheitsvorfall

Vishing-Angriffe kompromittieren Daten von 10 Personen.

Compliance Essentials GmbH

Luna Moth incassa 20 milioni di dollari da Weil Gotshal & Manges: il gruppo entra fisicamente negli uffici per rubare dati

La prestigiosa law firm americana Weil, Gotshal & Manges ha pagato tra i 18 e i 20 milioni di dollari al gruppo di estorsione Luna Moth (Silent Ransom Group) per impedire la pubblicazione di documenti riservati dei clienti. L'FBI ha emesso un alert FLASH documentando per la prima volta l'escalation tattica del gruppo, che ora invia operativi fisici negli uffici delle vittime quando le tecniche di accesso remoto falliscono.

https://insicurezzadigitale.com/luna-moth-incassa-20-milioni-di-dollari-da-weil-gotshal-manges-il-gruppo-entra-fisicamente-negli-uffici-per-rubare-dati/

UNC3753 Escalates: From Vishing Calls to Physical Office Intrusions at US Legal and Financial Firms

UNC3753 phones staff posing as IT, hijacks screen sessions, steals sensitive legal files, and now sends operatives physically into offices to plug in USB drives.

Security Affairs

Threat Actors Exploit Vishing, Physical Intrusions in US Data Extortion Campaign

Meet UNC3753, a notorious group of threat actors using clever voice phishing and social engineering tactics to infiltrate US corporate environments and steal sensitive data. Their deceitfully simple attacks start with a phone call or email and quickly escalate into rapid data theft and ransom demands.

https://osintsights.com/threat-actors-exploit-vishing-physical-intrusions-in-us-data-extortion-campaign?utm_source=mastodon&utm_medium=social

#DataExtortion #Vishing #SocialEngineering #Unc3753 #ChattySpider

Threat Actors Exploit Vishing, Physical Intrusions in US Data Extortion Campaign

Learn how UNC3753 threat actors exploit vishing and physical intrusions in US data extortion campaigns and protect your organization now with expert insights.

OSINTSights
Before you continue

Silent Ransom Group targets law firms via vishing — fake IT support calls, no malware needed at first contact. The attack surface here is human: caller trust, urgency framing, and helpdesk impersonation. Technical controls matter, but this vector thrives where security awareness training hasn't reached. #infosec #socialengineering #vishing
https://www.bleepingcomputer.com/news/security/silent-ransom-group-targets-law-firms-with-fake-it-support-calls/
Silent Ransom Group targets law firms with fake IT support calls

The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant.

BleepingComputer

📣🚨 Cybersecurity researchers are warning businesses about #Pink Extortion Group, a new cybercrime group that uses voice phishing to bypass multi-factor authentication and steal files from cloud environments.

Read: https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/

#CyberSecurity #CyberCrime #Extortion #Scam #Vishing

New Pink Extortion Group Targets Microsoft 365 Cloud Data Via Vishing Scams

Cybersecurity researchers are warning businesses about Pink Extortion Group, a new threat actor that uses voice phishing to bypass MFA to steal cloud data.

Hackread - Cybersecurity News, Data Breaches, AI and More

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Beware of UNC3753, a notorious group that's been stealing sensitive data from US law firms and other professional services, using clever vishing tactics and lightning-fast intrusions to extort their victims. In some cases, they can go from initial contact to data theft in under an hour.

https://osintsights.com/mandiant-exposes-unc3753s-us-law-firm-data-heist-tactics?utm_source=mastodon&utm_medium=social

#DataTheft #Extortion #Vishing #SocialEngineering #Unc3753

Mandiant Exposes UNC3753's US Law Firm Data Heist Tactics

Learn how UNC3753 executes US law firm data heists via vishing and extortion, and protect your organization from these financially motivated attacks today.

OSINTSights

Ransomware Gang Pink Exploits Helpdesk Calls to Steal Credentials

Meet Pink, a notorious ransomware gang that's exploiting helpdesk calls to steal sensitive credentials using clever tactics like vishing and IT impersonation. They're using these stolen secrets to exfiltrate valuable data from enterprise cloud storage and productivity systems, leaving victims with a tough choice: pay up or face the consequences.

https://osintsights.com/ransomware-gang-pink-exploits-helpdesk-calls-to-steal-credentials?utm_source=mastodon&utm_medium=social

#Ransomware #Pink #MfaBypass #Vishing #ItImpersonation

Ransomware Gang Pink Exploits Helpdesk Calls to Steal Credentials

Learn how Pink ransomware gang exploits helpdesk calls to steal credentials and extort victims, and take action to protect your enterprise from this threat now.

OSINTSights

Měla povědomí o podvodech po telefonu (takzvanému vishingu) a znala i možné varovné signály, podle kterých lze podvod rozeznat. Přesto šejdíři ženu z Prahy 6 během 24 hodin připravili o 600 000 korun, než si uvědomila, že se stala obětí rafinované psychologické manipulace.

Tón: : mírně negativní
#česko #gdelt #podvod #podvodníci #vishing(voicePhishing)

https://www.novinky.cz/clanek/internet-a-pc-bezpecnost-kdyz-varovne-signaly-chybi-vishing-je-stale-rafinovanejsi-40581209