Krebs on Security

Krebs on Security In-depth security news and investigation

  • Booking.com Phishers May Leave You With Reservations
    by BrianKrebs on November 1, 2024 at 9:12 pm

    A number of cybercriminal innovations are making it easier for scammers to cash in on your upcoming travel plans. This story examines a recent spear-phishing campaign that ensued when a California hotel had its booking.com credentials stolen. We’ll also explore an array of cybercrime services aimed at phishers who target hotels that rely on the world’s most visited travel website.

  • Change Healthcare Breach Hits 100M Americans
    by BrianKrebs on October 30, 2024 at 1:34 pm

    Change Healthcare says it has notified approximately 100 million Americans that their personal, financial and healthcare records may have been stolen in a February 2024 ransomware attack that caused the largest ever known data breach of protected health information.

  • The Global Surveillance Free-for-All in Mobile Ad Data
    by BrianKrebs on October 23, 2024 at 11:30 am

    Not long ago, the ability to remotely track someone’s daily movements just by knowing their home address, employer, or place of worship was considered a powerful surveillance tool that should only be in the purview of nation states. But a new lawsuit in a likely constitutional battle over a New Jersey privacy law shows that anyone can now access this capability, thanks to a proliferation of commercial services that hoover up the digital exhaust emitted by widely-used mobile apps and websites.

  • Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach
    by BrianKrebs on October 18, 2024 at 12:33 pm

    Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking contact information for 80,000 members. More recently, USDoD was behind a breach at the consumer data broker National Public Data that led to the leak of Social Security numbers and other personal information for a significant portion of the U.S. population.

  • Sudanese Brothers Arrested in ‘AnonSudan’ Takedown
    by BrianKrebs on October 17, 2024 at 2:17 pm

    The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan (a.k.a. AnonSudan), a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of hospitals, news websites and cloud providers. One of the brothers is facing life in prison for allegedly seeking to kill people with his attacks.

  • Lamborghini Carjackers Lured by $243M Cyberheist
    by BrianKrebs on October 9, 2024 at 5:36 pm

    The parents of a 19-year-old Connecticut honors student accused of taking part in a $243 million cryptocurrency heist in August were carjacked a week later, while out house-hunting in a brand new Lamborghini. Prosecutors say the couple was beaten and briefly kidnapped by six young men who traveled from Florida as part of a botched plan to hold the parents for ransom.

  • Patch Tuesday, October 2024 Edition
    by BrianKrebs on October 8, 2024 at 10:21 pm

    Microsoft today released security updates to fix at least 117 security holes in Windows computers and other software, including two vulnerabilities that are already seeing active attacks. Also, Adobe plugged 52 security holes across a range of products, and Apple has addressed a bug in its new macOS 15 “Sequoia” update that broke many cybersecurity tools.

  • A Single Cloud Compromise Can Feed an Army of AI Sex Bots
    by BrianKrebs on October 3, 2024 at 1:05 pm

    Organizations that get relieved of credentials to their cloud environments can quickly find themselves part of a disturbing new trend: Cybercriminals using stolen cloud credentials to operate and resell sexualized AI-powered chat services. Researchers say these illicit chat bots, which use custom jailbreaks to bypass content filtering, often veer into darker role-playing scenarios, including child sexual exploitation and rape.

  • Crooked Cops, Stolen Laptops & the Ghost of UGNazi
    by BrianKrebs on September 30, 2024 at 9:33 pm

    A California man accused of failing to pay taxes on tens of millions of dollars allegedly earned from cybercrime also paid local police officers hundreds of thousands of dollars to help him extort, intimidate and silence rivals and former business partners, a new indictment charges. KrebsOnSecurity has learned that many of the man’s alleged targets were members of UGNazi, a hacker group behind multiple high-profile breaches and cyberattacks back in 2012.

  • U.S. Indicts 2 Top Russian Hackers, Sanctions Cryptex
    by BrianKrebs on September 26, 2024 at 2:54 pm

    The United States today unveiled sanctions and indictments against the alleged proprietor of Joker’s Stash, a now-defunct cybercrime store that peddled tens of millions of payment cards stolen in some of the largest data breaches of the past decade. The government also indicted a top Russian cybercriminal known as Taleon, whose cryptocurrency exchange Cryptex has evolved into one of Russia’s most active money laundering networks.

Share Websitecyber