Clifford Lo reports: Hong Kong police have cracked the local operation of an international phishing syndicate that used 563 bogus mobile applications to spy on phones globally and steal information. Officers also tracked down 258 servers around the world that were linked with the apps, according to Senior Superintendent Raymond Lam Cheuk-ho of the force’s…
Category: Phishing
Heads up: Highmark Health will be notifying 300,000 patients of a phishing incident. Watch for your mail this month.
Highmark Health defines itself as a “national, blended health organization” that includes the Highmark Health Plan (a Blue Cross Blue Shield insurer); a regional hospital and physician network; and companies that offer dental solutions, reinsurance solutions, population health management, and technology solutions. Letters have not gone out yet and will not be going out in…
Hackers are using this new trick to deliver their phishing attacks
Danny Palmer reports: Cyber criminals are using uniquely crafted phishing emails to infect victims with malware — and they’re doing so by experimenting with a new method of delivering the malicious payload. According to analysis by Proofpoint, there’s been a rise in cyberattackers attempting to deliver malware using OneNote documents, a digital notebook signified by .one extensions that is part…
Microsoft disables verified partner accounts used for OAuth phishing
Bill Toulas reports: Microsoft has disabled multiple fraudulent, verified Microsoft Partner Network accounts for creating malicious OAuth applications that breached organizations’ cloud environments to steal email. In a joint announcement between Microsoft and Proofpoint, Microsoft says the threat actors posed as legitimate companies to enroll and successfully be verified as that company in the MCPP…
The U.N. Committee on Human Rights asks Morocco NOT to extradite Raoult
A small and somewhat bitter update to the Sébastien Raoult case. Sébastien’s father contacted DataBreaches tonight to say that they had just received a response from the Human Rights Committee of the United Nations. In response to Raoult’s appeal submitted on January 17, the committee responded by asking Morocco not to extradite Raoult while Raoult’s…
Baltimore schools cyber attack cost nearly $10M: State IG
ABC News reports: Baltimore County Public Schools failed to act on several state recommendations to help mitigate cyber attacks before a hack disrupted school operations and cost the school system millions of dollars in damages and repairs, according to a report from a state inspector general. BCPS was hacked using a phishing email in November 2020 —…