Ransomware groups added data exfiltration to the encryption play around 2020 and never looked back. We track the active leak sites, the families targeting Swiss and EU SMBs, and the incident-response checklist Mythos runs against newly disclosed indicators.
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000-$60,000. Researchers at...
Steam hardware buyers across Europe are being warned: a cyberattack on logistics provider CEVA Logistics exposed names, home addresses, phone numbers, and order details for anyone who received a...
The NCSC Switzerland warns of a sharp rise in compromised legitimate websites (over 100,000 globally) that display fake CAPTCHA verification pop-ups. Instead of a normal "I am not a robot" check,...
Cybercriminals linked to the BlackFile extortion group are calling employees on their personal mobile phones, spoofing the corporate IT helpdesk, and asking them to enroll in passkeys or update...
Attackers are calling employees directly through Microsoft Teams, pretending to be internal IT support, to trick victims into granting remote access. Once inside, they deploy Chaos ransomware,...
Fast-food chain Chick-fil-A has confirmed that 13,322 customers had personal data stolen during credential stuffing attacks against its Chick-fil-A One loyalty platform between June 17 and 19, 2026....
Fast-food chain Chick-fil-A has disclosed a credential stuffing attack that hijacked customer loyalty accounts between June 17-19, 2026. Attackers used usernames and passwords leaked from other...
Cybercriminals are exploiting trust in video conferencing platforms by sending fake Zoom invitations that prompt victims to download a supposed "required update." In reality, the installer delivers...
Sextortion scammers are impersonating the ShinyHunters hacking group, using email addresses harvested from recent data breaches (Amtrak, Hallmark, ADT, Substack, and others) to send fake blackmail...
Kaspersky researchers have uncovered dozens of malicious wallpapers circulating on Steam Workshop, distributed via the popular Wallpaper Engine app. Attackers, mainly targeting gamers in China and...
A phishing email carrying an attachment that looks like a PDF actually drops a malicious Chrome extension designed to steal browser session cookies and take over your logged-in accounts — even those...
Operation Endgame dismantled the SocGholish (FakeUpdates) framework, which hijacked ~15,000 legitimate WordPress sites to serve convincing fake browser and software update prompts to everyday...
Summary : Cybercriminals are sending fake voicemail notifications by email, spoofing Microsoft branding to either harvest Office 365 / Outlook login credentials on phishing pages or trick victims...
Researchers have discovered a publicly exposed database containing roughly 24 billion stolen credential records, gathered from 36 sources including infostealer logs, Telegram channels, and prior...
Attackers are disguising Windows malware as legitimate retro-console homebrew plugins on GitHub, preying on the trust built inside modding communities. A fake project called EQVita mimicked a real PS...
The Canadian Anti-Fraud Centre (CAFC) maintains a navigational catalog of fraud types that commonly target individuals across Canada. The list spans dozens of categories — from phishing, romance...
Job seekers are increasingly being targeted by cybercriminals who exploit the urgency and emotional vulnerability of a job hunt. Attackers use phishing emails, classic advance-fee scams, and...
The FTC is warning about a phishing scam disguised as a familiar CAPTCHA verification popup. Real CAPTCHAs ask you to type distorted letters or pick images of traffic lights and fire hydrants. Fake...