ShinyHunters has claimed responsibility for an Okta voice-phishing campaign during which the extortionist crew allegedly gained access to Crunchbase and Betterment.
On Friday, the criminals leaked data allegedly stolen from market-intel broker Crunchbase, streaming platform SoundCloud, and financial-tech firm Betterment, and confirmed to The Register that they gained access to two of the three – Crunchbase and Betterment – by voice-phishing Okta single-sign-on codes. SoundCloud in December confirmed it had been breached and the crooks accessed data belonging to about 20 percent of its users, which translates to about 28 million people, based on the company’s publicly available customer count.
Read more…
Source: The Register
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Australian horse riding organisations caught up in cyber attack impacting 10,000 people
July 6, 2023
Cyber criminals have targeted yet another Australian small business by stealing and leaking the data of 10,000 people. Last month, the data of a little-known company called Event Secretary was published on an online forum. Unfortunately, Event Secretary was the platform that several major Australian horse riding organisations used to book and enter into equestrian competitions ...
- Microsoft Denies Major 30 Million Customer-Breach
July 4, 2023
Microsoft has hit back at claims from a shadowy hacktivist outfit that it managed to breach the company and obtain account access for tens of millions of customers. Anonymous Sudan, which has been linked in the past to pro-Kremlin groups like Killnet, posted the details of its alleged raid on Telegram. Read more… Source: Infosecurity Magazine
- ‘Pay and benefits compromised’ in Dublin Airport cyber attack
July 3, 2023
The pay and benefits details of nearly 2,000 staff members of daa, which operates Dublin Airport, were compromised due to a recent cyber attack on professional service provider Aon, the Sunday Times reported. A spokesperson said that as a result of a recent cyber attack on Aon, a third-party provider, data relating to some employees’ pay ...
- More sensitive Optus data leaked in major cyberattack on law firm
July 1, 2023
Optus has been caught up in another major cyberattack, with sensitive information about a privacy watchdog investigation into the mobile-phone company breached by Russian hackers. The Office of the Australian Information Commissioner is one of dozens of government departments and agencies scrambling to find out how much of their data has been breached in a hack ...
- UK: Hacking gang BlackCat says it stole data trove from the Barts Health NHS Trust
June 30, 2023
A gang of cybercriminals says it has breached one of the UK’s largest hospital groups and is threatening to publish a trove of its confidential data. The gang, known as ALPHV or BlackCat, posted a statement on Friday claiming it had obtained seven terabytes of internal documents from the Barts Health NHS Trust, which manages five ...
- Hackers threaten to leak 80GB of confidential data stolen from Reddit
June 19, 2023
Hackers are threatening to release confidential data stolen from Reddit unless the company pays a ransom demand – and reverses its controversial API price hikes. In a post on its dark web leak site, the BlackCat ransomware gang, also known as ALPHV, claims to have stolen 80 gigabytes of compressed data from Reddit during a February ...

