“Termite” ransomware group claims responsibility for the Blue Yonder attack


On Friday, the “Termite” ransomware group claimed responsibility for the attack on its dark web leak site. In a post seen by TechCrunch, the gang claims to have stolen 680 gigabytes of data from Blue Yonder, including documents, reports, insurance documents and email lists, which Termite says it intends to use “for future attacks.”

In a statement given to TechCrunch, Blue Yonder spokesperson Marina Renneke said the company was “aware of who has claimed responsibility.” “We are aware that an unauthorized third party claims to have taken certain information from our systems,” Renneke said. “We are working diligently with external cybersecurity experts to address these claims. The investigation remains ongoing.”

Read more…
Source: MSN News


Sign up for our Newsletter


Related:

  • CareCloud confirms 3.7M patients had their medical records stolen in data breach

    August 19, 2026

    Hackers have stolen the personal information and medical records of more than 3.75 million people in a data breach at health data giant CareCloud, the company has confirmed with federal regulators. The disclosure marks the first confirmation of the scale of the data breach, which is now confirmed to be the fifth-largest theft of health ...

  • ‘Proactive SIM’ cards can hijack smartphones, IoT devices and even EV chargers

    August 18, 2026

    A malicious SIM card can instruct the device it sits in to run commands of an attacker’s choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over. Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated ...

  • Mitigating large-scale credential attacks

    August 18, 2026

    Identity has effectively become the new perimeter, where cybercriminals are increasingly choosing to log in rather than break in. To accomplish this, attackers frequently gather previously leaked username and password pairs. Gathering these credentials can then allow them to pivot to password spraying against services exposed to the internet, gaining credentials for other products and ...

  • Hunting MacSync Stealer infrastructure through behavioral pivots

    August 18, 2026

    MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure. Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors ...

  • ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators

    August 17, 2026

    An unprecedented number of Apple customers have reported receiving a recent threat notification alerting them to suspected spyware attacks targeting their devices, according to experts who investigate these types of incidents. Several people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in ...

  • Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline

    August 17, 2026

    Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the ...