Phishing

Broomfield Skilled Nursing and Rehabilitation Center settles breach-related charges with Colorado Attorney General

Colorado Attorney General Phil Weiser recently announced a settlement with Broomfield Skilled Nursing and Rehabilitation Center, LLC stemming from a 2021 data breach. The following is the state’s press release: Sept. 22, 2023 (DENVER) – Attorney General Phil Weiser announced today a settlement with Broomfield Skilled Nursing and Rehabilitation Center, LLC., for failing to protect the...

New AtlasCross hackers use American Red Cross as phishing lure

It seems we are finding out about new groups on a daily basis recently.  Now Bill Toulas reports on another one: A new APT hacking group named ‘AtlasCross’ targets organizations with phishing lures impersonating the American Red Cross to deliver backdoor malware. Cybersecurity firm NSFocus identified two previously undocumented trojans, DangerAds and AtlasAgent, associated...

Facebook Messenger phishing wave targets 100K business accounts per week

Bill Toulas reports: Hackers use a massive network of fake and compromised Facebook accounts to send out millions of Messenger phishing messages to target Facebook business accounts with password-stealing malware. The attackers trick the targets into downloading a RAR/ZIP archive containing a downloader for an evasive Python-based stealer that grabs cookies and passwords stored...

Why is .US Being Used to Phish So Many of Us?

Brian Krebs reports: Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows. This is noteworthy because .US is overseen by the U.S. government, which is frequently the target of phishing domains ending in .US. Also, .US domains are...

EvilProxy Cyberattack Flood Targets Execs via Microsoft 365

Elizabeth Montalbano reports: Attackers have unleashed an EvilProxy phishing campaign to target thousands of Microsoft 365 user accounts worldwide, sending a flood of 120,000 phishing emails to more than 100 organizations across the globe in the three-month period between March and June alone. The goal? To take over C-suite and other executive accounts, in order...

CT: New Haven Board of Education victim of $6 million cyber theft

Doug Stewart reports: The city of New Haven suffered a $6 million theft in a cyber attack earlier this year it was announced Thursday. To date, law enforcement officials have recovered over half the money. Officials said the cyber attack targeted the Board of Education’s Chief Executive Officer and Chief Operating Officer in what was...

Notorious phishing platform shut down, arrests in international police operation

From Interpol, this week: SINGAPORE – A notorious ‘phishing-as-a-service’ (PaaS) platform known as ‘16shop’ has been shut down in a global investigation coordinated by INTERPOL, with Indonesian authorities arresting its operator and one of its facilitators, with another arrested in Japan. The three arrests, which concluded with actions against a suspect last month, was...