Major Cloud Provider Discloses Breach Affecting 8.4 Million Accounts
Attackers exploited a misconfigured API gateway to harvest customer records over a period of several weeks before detection.
Attackers exploited a misconfigured API gateway to harvest customer records over a period of several weeks before detection.
Billions of login attempts fueled by recycled passwords led to account takeovers, loyalty-point theft and fraudulent purchases.
A systems administrator monetized privileged credentials through darknet brokers before an undercover purchase exposed the scheme.
The dataset, offered for sale with samples, appears to stem from an unreported breach at a global hospitality group.
Attackers accessed payroll data affecting employees at over 600 client companies, redirecting salary deposits in some cases.
Ironically insecure, the spyware company leaked data from both its paying customers and the people they covertly monitored.
Source code and internal documentation were accessed, but the company says customer vaults remain protected by zero-knowledge encryption.
Attackers patiently escalated from a single infected endpoint to the exchange's hot wallet infrastructure, stealing $95 million.