Bill Toulas reports: Russian state hackers APT28 (Fancy Bear/Forest Blizzard/Sofacy) breached a U.S. company through its enterprise WiFi network while being thousands of miles away, by leveraging a novel technique called “nearest neighbor attack.” The threat actor pivoted to the target after first compromising an organization in a nearby building within the WiFi range. The attack…
Category: Of Note
What You Need to Know about China’s Regulations on the Management of Network Data Security
Clyde & Co write: The new Regulations on the Management of Network Data Security (《网络数据安全管理条例》) [1] (the “Regulations”) were issued by the State Council of the People’s Republic of China (“China”) on 24 September 2024 and will come into force on 1 January 2025. With a focus on network data [2], the Regulations supplemented and…
JP: Yakuza Helpline Leak Sparks Fears for Victim Safety
Here’s today’s reminder that it’s not always the huge-number breaches that pose the most risk or actual physical danger to people. Anosha Shariq reports: A helpline for Yakuza victims faces a shocking data breach, exposing personal details of 2,500 individuals and sparking fears of retaliation and safety risks. A tragic irony has unfolded as the…
Tesla data breach falsely claimed by IntelBroker, third-party EV charging firm actually breached
Daniel Croft reports: The incident was claimed by CyberN—–s members IntelBroker and EnergyWeaponUser, who originally said it was a Tesla EV charging station database containing files that belonged to Tesla. However, thanks to a tipoff by researcher DarkWebInformer and IntCyberDigest, the threat actors amended the listing to say it was a “random 3rd party company…
Ransomware Group Cooperation: A Growing Challenge in the Fight Against Cybercrime
Marco A. De Felice (aka @amvinfe) of SuspectFile and DataBreaches have often shared information with each other about threat actors or incidents, including what may appear to be second attacks or maybe just a re-listing of a previous attack. He has recently taken a look at listings of data claimed by two or more groups to…
Cyberattack at French hospital exposes health data of 750,000 patients
Bill Toulas reports: A data breach at an unnamed French hospital exposed the medical records of 750,000 patients after a threat actor gained access to its electronic patient record system. A threat actor using the nickname ‘nears’ (previously near2tlg) claimed to have attacked multiple healthcare facilities in France, alleging that they have access to the patient…

