#credentialtheft
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction #CameronWagenius #CredentialTheft #CyberExtortion
Hacking and Extortion Operation Targeting U.S. Official Ends in Conviction
A former U.S. Army soldier, Cameron John Wagenius, has been sentenced to 70 months in prison for participating in a hacking and extortion campaign which exposed sensitive information and targeted telecommunication companies. According to the U.S. Department of Justice, Wagenius has also been ordered to pay $294,978 in restitution. Wagenius was involved in the cybercrime operation while serving as an active duty military member.  In April 2023 and December 2024, he and other conspirators obtained credentials allowing them to access protected networks belonging to at least ten organizations. The stolen information was then used to extort victims by threatening publication or sale of the data without their payment. Investigators have stated Wagenius was an online hacker known as “kiberphant0m” and he contributed to the development of the hacking tool SSH Brute, which was used to obtain login credentials. To exchange stolen credentials and coordinate access to victim networks, the group communicated via Telegram. Additionally, public threats were made on cybercrime forums. Stolen information was made available for sale on platforms including BreachForums and Wagenius published two posts in November 2024 that contained stolen non-content call detail records associated with a former US government official and relatives of another former official. As part of the threats, the Justice Department also stated that additional confidential records would be released if a ransom was paid. One of the posts indicated that the activity may be partly motivated by retaliation for the arrest of another cybercriminal. There have been several attacks involving major telecommunications companies and other companies. According to cybersecurity researchers, Wagenius' possession of data was related to broader attacks targeting Snowflake customer environments. Several companies were affected by the campaign, including AT&T, Ticketmaster, Advance Auto Parts, and Santander.  Wagenius pleaded guilty in separate proceedings filed in the Western District of Washington in support of the charges. A conviction for wire fraud, extortion using computers, and aggravated identity theft was obtained in July 2025. Prior to this, he had pleaded guilty to two counts of unlawfully transferring confidential phone records related to the same operation in March 2025. Additionally, Wagenius appears to be tied to the wave of attacks against organizations using Snowflake cloud environments that took place in 2024.  According to AT&T, attackers accessed call and text records covering nearly all of its mobile customers in December 2022. The stolen information was later associated with extortion activity involving several cyber criminals. Moreover, court records and the investigation report indicate that Wagenius attempted to sell stolen information to an email address he believed was affiliated with a foreign military intelligence service. Moreover, the prosecution alleges that he searched the Internet for information about leaving the United States for Russia.  The intelligence services involved have not yet been publicly identified by the government. Based on the findings of the investigation, the hacking operation was primarily a result of the use of stolen credentials, rather than an exploit of a specific software vulnerability. The credentials were used by Wagenius and his associates to gain access to company networks and cloud environments, using Telegram to communicate access details and coordinate further intrusions.  After invading victim networks, the group aimed at obtaining data to be monetized. In some cases, information was provided to other criminals, whereas other records were used for fraud schemes, such as SIM swapping. Additionally, extortion demands were extorted through private communications as well as public postings on cybercrime forums.  The FBI, Defense Criminal Investigative Service, and other law enforcement agencies investigated these activities. A warrant was issued for Wagenius' arrest in December 2024, bringing to a close the hacking activities he allegedly conducted for more than a year while remaining an active duty soldier.
dlvr.it
September 27, 2026 at 1:31 PM
Malicious MemTensor packages deliver sckit credential-stealer via npm & PyPI—update and rotate secrets now. #SupplyChain #Malware #OpenSourceSecurity #CredentialTheft #CI/CD #MemTensor thedailytechfeed.com/memtensor-su...
September 23, 2026 at 2:13 PM
September 23, 2026 at 5:40 AM
Revolut Data Breach: 680 Customers Exposed After Fake Italian Government Requests
https://www.osintinvestigate.com A major Revolut data breach allegedly exposed the personal and financial information of around 680 customers after hackers impersonated an Italian government agency. The operation reportedly lasted about five months, using compromised government email credentials to send fraudulent data requests to Revolut Bank UAB. The stolen information may include passports, identity documents, phone numbers, email addresses and financial data. A threat actor known as “IAmNotAVillain” has publicly demanded $3 million and threatened to sell the allegedly stolen information. Revolut says it has not received any direct ransom demand from the alleged attackers. Italian authorities are investigating the incident, which also involves claims of more than 147GB of data stolen from an Italian law-enforcement agency. This episode examines what happened, how the attack allegedly worked, what information may have been exposed, and why compromised government identities and trusted communication channels represent a serious cybersecurity risk.
www.spreaker.com
September 18, 2026 at 3:00 PM
~Cofense~
Fake ChatGPT billing emails steal OpenAI credentials and payment data.
-
IOCs: 9527db6e1a[.]nxcli[.]io, e83cedb076[.]nxcli[.]io
-
#CredentialTheft #Phishing #ThreatIntel
ChatGPT Phishing Campaign
cofense.com
September 17, 2026 at 4:02 PM
That 'overdue ChatGPT bill' email? The payment button hides behind a legit Google redirect. https://intel.threadlinqs.com/threat/TL-2026-2548 #ThreatIntel #ChatGPT #Phishing #CredentialTheft
September 17, 2026 at 1:54 PM
September 17, 2026 at 10:24 AM
📰 Malware KREMLIN Bypass Proteksi Browser untuk Memasang Ekstensi Chrome dan Edge

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/17/malware-kremlin-pasang-ekstensi-chrome-edge/

#bankingMalware #browser #browserExtension #chrome #credentialTheft #cyberSecurity #dataTheft #ether
September 17, 2026 at 6:45 AM
Your Company's Phishing Tests Are Measuring the Wrong Thing #CredentialTheft #cybersecurityresearch #financialservices
Your Company's Phishing Tests Are Measuring the Wrong Thing
  When a phishing simulation returns a low click rate, security teams tend to relax. Leadership checks a compliance box. The program gets renewed. But a major new study suggests that sense of relief may be completely misplaced. Oslo-based cybersecurity firm Pistachio released its Phishing Behaviour Report 2026 this week, built from 2.47 million simulated phishing attacks sent to more than 123,000 employees across 1,200-plus organizations between June 2025 and May 2026. The finding that runs through all of it: the click rate, which most phishing programs live and die by, is the wrong thing to measure. "A low click rate can create a false sense of security," said Joe Jones, CEO and co-founder of Pistachio. "What matters more is what happens next: does the employee hand over credentials, recognize the attack and stop, or report it so the wider business can act?" A click alone does nothing. Credentials do. Clicking a phishing link causes no damage on its own. The actual risk begins when an employee submits a password or other sensitive information into a fake login page after clicking. That is the moment a simulated test becomes a real-world breach scenario, and it is largely what most phishing programs do not track. On their very first simulated phishing exercise, more employees in the Pistachio study reported the suspicious email than clicked it. That sounds like good news. The problem is that 1.57% handed over their credentials anyway. In a company with 500 employees, that works out to roughly eight people who will submit login details to a convincing enough lure with zero prior exposure. Click rate metrics would not flag any of them. Tech workers are not the safe bet they are assumed to be One of the more uncomfortable findings in the report concerns employees who are expected to know better. Tech development workers clicked at least one simulated phishing attempt at a rate of 30.27%. IT workers were not far behind at 28.53%. The assumption that technical employees carry lower phishing risk because they understand how attacks work does not hold up against the data. Understanding how phishing operates and catching a convincing one under inbox pressure are two different things. Construction carries the most risk. Financial services carry the least. The gap between industries was wider than most organization-wide risk scores would suggest. Construction workers showed the highest click rate of any department at 41.31% and the highest credential leak rate at 16.47%. Design workers, by contrast, clicked at just 26.35%. Financial services employees topped every resilience category in the study, which carries some irony. Financial services accounted for 27.7% of all observed phishing attempts in 2025, making it one of the most targeted sectors on the internet. That sustained pressure, combined with strict regulatory requirements and mandatory security training, appears to have produced genuinely more vigilant employees at the individual level. Health workers showed the lowest reporting rate of any department at 13.17%, despite a relatively low click rate. Logistics workers combined an above-average click rate with a below-average reporting rate of 17.11%. In both cases, the click rate alone would present a more reassuring picture than the full data supports. Things get worse before they get better Organizations running 12-month programs saw click rates and credential submission rates both rise through the first six months before declining. That initial rise reflects harder and more frequent testing rather than employees regressing. At the six-month mark, employees were receiving an average of 3.5 simulations per person, with 50.4% classified as hard difficulty. From that six-month peak to the 12-month stage, clicks declined by 27% and credential leaks by 41%. The report-to-click ratio increased from 1.3 at three months to 1.8 at 12 months, indicating that suspicious messages were reported nearly twice as often as they were clicked by the end of the program.  Organizations that run a single phishing simulation and judge the program from that result are drawing conclusions from the noisiest and least reliable moment in the entire training cycle. What to track instead The report does not argue that click rates should be dropped entirely. It argues they should sit alongside credential submission rates and reporting rates, which together give a far more accurate picture of actual resilience. Making it easy for employees to report suspicious emails, through one-click tools and fast confirmation, converts the workforce into an active detection channel rather than a passive one. NIST research found that 72% of organizations use phishing simulation click rates to gauge training effectiveness. By that measure, nearly three quarters of corporate security awareness programs are optimizing for an incomplete signal, in a threat environment where AI-driven phishing has pushed click rates among untrained employees to a record high of 54% in 2026.  The click rate was never the whole story. At this point, relying on it alone is a liability.
dlvr.it
September 14, 2026 at 4:21 PM
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device #Credential #Credentialstealing #CredentialTheft
Florida Says Motor Vehicle Data Breach Tied to Credentials Stolen From Officer's Personal Device
 Officials in Florida confirmed Thursday that the state Department of Motor Vehicles suffered a data breach after credentials were stolen from a police officer who had stored login information on a personal device. The ShinyHunters cybercriminal organization claimed on Monday that it had obtained access to data from the Florida Department of Highway Safety and Motor Vehicles (FLHSMV).  The department did not respond to repeated requests for comment throughout the week but publicly confirmed the breach's legitimacy on Thursday night. Officials said they first learned of the breach on September 4 and initially attributed it to an unnamed "international cybercriminal organization."  According to the department, an investigation determined that a criminal actor exploited a single Plant City Police Department user's credentials, which had been improperly stored on the employee's personal electronic device. Plant City is a small suburb outside Tampa. FLHSMV has since notified other Florida government offices and is partnering with the Florida Digital Service to investigate the incident.  As proof of access, ShinyHunters shared alleged photos of a DMV record tied to American financier and convicted child sex offender Jeffrey Epstein. When claims of the breach first surfaced, some cybersecurity experts speculated it might be connected to the recently confirmed breach involving 153 million driver's licenses leaked by identity verification firm IDScan. ShinyHunters had previously attempted to purchase the ID database from the hackers behind the IDScan breach. The group has recently claimed responsibility for attacks on bank IT provider Jack Henry, as well as pharmaceutical and healthcare technology company McKesson, which told regulators that data from its oncology and surgical business units had been stolen. ShinyHunters also caused widespread disruption across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after targeting the world's largest medical device company in April.  Other victims linked to the group include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar. In a related development, artificial intelligence company Anthropic released a report Thursday stating that suspected affiliates of ShinyHunters used AI to scan for credentials, map unfamiliar systems, and steal data from victims for extortion purposes.  The report noted that in one case, an operator escalated from a stolen developer token to full administrative access over a victim's cloud environment in approximately three hours. Incident responders at Google also confirmed last week that members of the group are using Anthropic's AI tools at various stages of their attacks.  The Florida breach adds to a growing list of incidents tied to ShinyHunters, underscoring the group's persistent targeting of both government systems and major corporations, as well as its evolving use of AI tools to accelerate and scale its intrusions.
dlvr.it
September 13, 2026 at 3:38 PM
@huntress.com
Stolen credentials enable lateral movement, account takeover, BEC, and ransomware; phishing-resistant MFA and identity monitoring help mitigate risk.
-
IOCs: Mimikatz
-
#CredentialTheft #Phishing #ThreatIntel
Credential Theft Fuels Breaches
www.huntress.com
September 11, 2026 at 8:03 PM
Blob URLs + Teams phishing campaign fools logins inside your browser—beware false redirects. #Phishing #BlobURL #CyberSecurity #MicrosoftTeams #CredentialTheft #OAuthReplay thedailytechfeed.com/hackers-expl...
September 10, 2026 at 2:36 PM
PEEP Turns Chrome and Edge Into Hidden Backdoors #BrowserSecurity #ChromeBackdoor #CredentialTheft
PEEP Turns Chrome and Edge Into Hidden Backdoors
 Cybersecurity researchers have uncovered PEEP, a Chromium-based post-exploitation toolkit that turns Chrome and Edge into stealthy backdoors after an attacker already has access to a system. The malware poses as a bookmarks extension and uses browser trust to slip past ordinary checks.  PEEP is built to operate after compromise rather than to break in on its own, which means it depends on some earlier intrusion or code execution step. Once installed, it injects itself into browser profiles and forges Chromium Secure Preferences values to bypass warnings, making it harder for users and defenders to notice.  The extension continuously checks its command server for tasks and quietly sends back browsing history, active tabs, cookies, and other session details. It can also steal credentials, hijack sessions, alter web pages, and use a native-messaging helper to run host-level commands and manage files outside the browser sandbox.  Researchers say PEEP appears to be based on RedExt, an open-source browser analysis and red-teaming framework, but it adds stronger persistence and more operational features. It uses multiple delivery and survival methods, including sideloading, enterprise force-install policies, preference tampering, and scripts such as install_silent.ps1, patch_secure_prefs.ps1, and force_enable.ps1.  The safest response is to treat unexpected browser extensions as a serious incident signal, especially if they appear outside the Chrome Web Store or are installed through policy or sideloading. Security teams should inspect browser profiles, review extension force-install settings, monitor for suspicious native-messaging hosts, and check for abnormal outbound traffic to unknown command servers; users should keep browsers updated, remove unknown extensions, use least-privilege accounts, and report signs of session theft or credential abuse immediately.
dlvr.it
September 8, 2026 at 3:15 PM
🔴 PaperCut attacks are moving beyond RCE

Attackers exploiting CVE-2026-81578 and CVE-2026-82078 are now stealing credentials, targeting SAM/LDAP secrets and using compromised print servers

stemshop.top/blog/papercu...

#CVE #CVE202681578 #CVE202682078 #PaperCut #CredentialTheft #RCE #CyberSecurity
PaperCut Attacks Shift to Credential Theft — CVE-2026-81578 + CVE-2026-82078
Attackers exploiting PaperCut CVE-2026-81578 and CVE-2026-82078 are now harvesting Windows credentials, searching for LDAP secrets and deploying Meterpreter.
stemshop.top
September 6, 2026 at 11:25 PM
September 5, 2026 at 4:46 PM
FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses #CredentialTheft #CyberSecurity #DataBreach
FBI Investigates Dark Web Service Offering 153 Million Driver’s Licenses
  The FBI has opened an investigation into an apparent breach involving identity verification provider IDScan.net after a newly launched dark web service began advertising access to more than 153 million U.S. and Canadian driver’s license records. The service, named Nexus, appeared on the Russian cybercrime forum Exploit on August 31, claiming access to identity documents belonging to more than 170 million people across North America. Its advertised database includes more than 153 million driver’s licenses, over 10 million identification cards, more than three million travel or international identity documents, and at least 579,000 medical cards. An examination of the service indicates that the claimed volume may be credible. A search without filters reportedly produced about 11.5 million pages of records, with approximately 15 results per page. Canadian licenses accounted for roughly 1.1 million results, including 473,673 records from Ontario, while most listings originated from the United States. The dataset also contains marijuana dispensary cards, commercial driver’s licenses and records marked “CAC,” potentially referring to U.S. government Common Access Cards. Nexus operators claim the information is being obtained through an ongoing compromise of a major identity verification company serving Fortune 500 customers. They claim to have continuously extracted new records for more than a year. Evidence examined by KrebsOnSecurity also indicates that the database may still be receiving stolen information. The number of available driver’s license records reportedly increased by nearly 400,000 within 24 hours. The exposed records are unusually detailed. One license examined by Krebs contained six image files showing the front and back of the document, including standard, infrared and ultraviolet captures. Each file carried a timestamp. In several cases, those timestamps corresponded closely with victims’ real-world activities. Krebs tested the apparent pattern by obtaining permission to search for licenses belonging to more than a dozen acquaintances. Nine licenses were located, and each individual confirmed travelling on or around the dates associated with the image timestamps. Further comparison with rental records indicated the timestamps appeared consistent with Greenwich Mean Time. The evidence initially pointed toward airports, but that theory weakened because the database contained no passports and several individuals had not presented their licenses at airport security. Two federal employees who appeared in the dataset said they used other government identification at airport checkpoints, but later handed their state licenses to Hertz when renting vehicles. A particularly revealing comparison involved Krebs’ own license and his mother’s. Their records carried timestamps only seconds apart, corresponding to the time both licenses were handed to a Hertz representative. Another exposed license belonged to security researcher Zach Edwards, whose timestamp matched a trip to Las Vegas for DEF CON. Edwards said he showed his license to TSA, his hotel and Planet 13, but identified the dispensary as the only location that definitely scanned it. That connection is notable because Planet 13 announced in 2022 that it had deployed IDScan.net’s VeriScan technology across 16 check-in stations at its Las Vegas SuperStore. The system captures government-issued identification, performs document authentication and can use white-light, infrared and ultraviolet imagery. IDScan.net says its technology performs more than 21 million identity verifications each month across more than 20,000 locations. IDScan.net also publicly lists major organizations using its technology, including Hertz, Target, FedEx and Caesars Entertainment. Its current platform supports ID scanning, document authentication, data parsing and integrations through APIs and software development kits. IDScan.net told KrebsOnSecurity that it was investigating but had not provided a substantive public explanation of the suspected incident. Its documentation shows that its systems can retain raw files generated during scans, while its security documentation describes encryption for data at rest and in transit. The FBI’s New Orleans field office subsequently opened an official investigation into the suspected breach. The development adds a law-enforcement dimension to an incident that could expose highly sensitive identity information at unprecedented scale. The potential consequences extend beyond conventional credential theft. Driver’s license information is legally recognized as identifying information, and stolen identity data can be used to open accounts, obtain services, commit financial fraud or impersonate victims. The incident also exposes a difficult security trade-off in modern identity verification. Organizations increasingly depend on third-party systems to scan government credentials for travel, rentals, retail, financial services and age verification. TSA began enforcing REAL ID requirements for domestic air travel in May 2025, further embedding government-issued identification into everyday verification processes. For now, the precise intrusion path, affected customers and total number of compromised individuals remain unconfirmed. However, the combination of detailed document images, matching timestamps, apparent fresh data collection and the FBI investigation makes Nexus a serious warning about the risks created when sensitive identity documents are concentrated within third-party verification infrastructure.
dlvr.it
September 2, 2026 at 4:59 PM
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing #AISecurity #CredentialTheft #CVE20260768
Attackers Turn Langflow and Rails Flaws Into Entry Points for Credential Probing
Observations have shown that threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails, with attacks moving beyond vulnerability testing to credential discovery and reconnaissance, according to threat intelligence firm VulnCheck.  The CVE-2026-0768 vulnerability, which has a CVSS score of 9.8, affects Langflow, a low-code platform used to develop artificial intelligence applications. It is a vulnerability in which user-controlled input is not adequately validated and can allow attackers to execute arbitrary Python code with root privileges on vulnerable systems.  Trend Micro's Zero Day Initiative initially disclosed this vulnerability in January 2026. CVE-2026-66066, also known as KindaRails2Shell, affects Ruby on Rails and has a CVSS score of 9.5. This flaw can be exploited by unauthenticated attackers to gain access to arbitrary files, to expose data regarding Rails processes, and to retrieve sensitive information, including secrets_key_base, Rails master key, database credentials, cloud storage credentials and API tokens. Such access can ultimately lead to remote code execution.  Exploitation of CVE-2026-66066 is facilitated by a parsing inconsistency between Rails Active Storage and the libvips image processing library. Attackers can submit specially crafted images to applications that utilize libvips for Active Storage processing and accept uploads from untrusted users in order to exploit the vulnerability Successful exploitation depends on the vulnerable configuration of the affected application.  During the first few hours on August 30, VulnCheck reported more than 50 detections, but the number increased to about 360 by Monday afternoon. Based on observed activity, attackers may be inspecting environments and searching for credentials and other sensitive information on compromised or exposed systems.  VulnCheck vice president of threat research Caitlin Condon commented on observed requests including retrieving Langflow environment variables associated with administrator credentials, OpenAI API keys, and AWS access credentials. A number of other files were examined by the attackers, including the /root/.cache/langflow/secret_key file, access information related to SSH, and .bash_history.  Telemetry indicated that most of the source traffic was originating from Russia, but the initial attacks were observed only against VulnCheck canary systems in the United Kingdom. It has been noted that subsequent activity has expanded to additional locations, indicating that the exploitation process is no longer limited to those initially targeted.  The Langflow platform has previously been attacked only in limited instances during the period 2026, as reported by VulnCheck. However, 11 additional vulnerabilities have been identified and are currently being exploited in the wild. Langflow has historically seen limited exploitation activity. More than 15,000 successful attacks against instances affected by CVE-2026-0769, CVE-2025-3248, and CVE-2026-5027 have been recorded. This activity shows that Langflow compromises can extend beyond the platform itself as well.  Attackers were reported to have combined an unauthenticated remote code execution vulnerability, CVE-2026-33017, with an insecure direct object reference vulnerability, CVE-2026-55255, in a campaign observed on June 25, 2012. This campaign targeted approximately 7,000 servers to obtain API keys for OpenAI and Anthropic, as well as credentials for Amazon Web Services, Google Cloud, and Microsoft Azure, and connection details to the database.  Through such activities, exposed AI application infrastructure is an excellent source of credentials, which can allow access to cloud services, databases, and model providers. By incorporating sensitive tokens into AI workflows, an initial compromise may have a greater impact, particularly when those credentials are reused across a variety of services.  Langflow has also gained increasing attention as an integral part of the enterprise attack surface rather than being an isolated development tool as a result of the increasing number of attacks. Security teams monitoring deployments are therefore expected to account for credentials, configuration files and connected services which can be accessed upon successful compromise.  This ongoing exploitation illustrates the growing security concerns associated with internet-facing artificial intelligence infrastructure. An organization should closely monitor Langflow deployments, secure sensitive credentials, and limit unnecessary external exposure in order to reduce the impact of a successful attack.
dlvr.it
September 2, 2026 at 2:26 PM
📢 Compromission de l'infrastructure Cloudflare de Coder : paquets malveillants servis via un registre non autorisé

Le 1er septembre 2026, Coder a publié un avis de sécurité critique (GHSA-vx42-ghc9-gw65) sur…

🟡 vérification factuelle moyenne
#CloudflareCompromise #CredentialTheft #Cyberveille
Compromission de l'infrastructure Cloudflare de Coder : paquets malveillants servis via un registre non autorisé
Le 1er septembre 2026, Coder a publié un avis de sécurité critique (GHSA-vx42-ghc9-gw65) sur GitHub concernant une compromission de son infrastructure Cloudflare ayant conduit à la distribution de paquets malveillants via son registre officiel de modules (registry.coder.com).
cyberveille.ch
September 2, 2026 at 3:00 AM
A stolen API key was used for about three weeks to consume AI credits worth roughly $600,000.

METR also faced an agent-assisted campaign using credential stuffin…

https://en.hacks.gr/metr-klemmeno-api-key-odigise-se-chrisi-ai-credits-axias-peripoy-600-000-dolarion/

#Cybersecurity #CredentialTheft
September 1, 2026 at 12:55 PM
Threat actors are posing as AI crawlers to hunt for exposed credentials

🔗 Read more: www.helpnetsecurity.com/2026/08/31/a...

#AI #CredentialTheft #Cybersecurity
Threat actors are posing as AI crawlers to hunt for exposed credentials - Help Net Security
Attackers are impersonating AI crawlers from OpenAI, Anthropic, Google and others while scanning websites for exposed credentials.
www.helpnetsecurity.com
August 31, 2026 at 2:44 PM