Up to 1.2 million GoDaddy customers’ data exposed in breach

Data connected with up to 1.2 million GoDaddy customers may have been accessed by an unauthorized party, the company reported to the U.S. Securities and Exhcnage Commission Monday. GoDaddy, a behemoth in the commercial web hosting and domain registrar space, reported that it discovered the apparent intrusion on Nov. 17, and that the improper access dated back to Sept. 6. Using a compromised password, an unknown party accessed a GoDaddy system dedicated to managed WordPress services, where the company offers customers hosting and other content management features. Up to 1.2 million active and inactive customers’ email addresses and customer numbers were exposed, which could set them up for phishing attacks, Demetrius Comes, the company’s chief information security officer, wrote in the notice. “We are sincerely sorry for this incident and the concern it causes for our customers,” Comes wrote. “We, GoDaddy leadership and employees, take our responsibility to protect customers’ data […]

The post Up to 1.2 million GoDaddy customers’ data exposed in breach appeared first on CyberScoop.

Continue reading Up to 1.2 million GoDaddy customers’ data exposed in breach

Two Iranian hackers charged in sprawling effort to interfere in 2020 U.S. election

Two Iranian nationals engaged in a sprawling effort to interfere in the 2020 U.S. elections — including by gaining access to confidential voter information from at least one state election website and attempting to access 11 states in total — according to a federal indictment unsealed Thursday. The defendants, Seyyed Mohammad Hosein Musa Kazemi, 24, and Sajjad Kashian, 27, face charges of computer fraud, voter intimidation and transmission of interstate threats. Part of the campaign was allegedly sending emails to Democratic voters purportedly from the Proud Boys, a right wing nationalist hate group, demanding that they vote for former President Trump. That effort was quickly identified by journalists and the U.S. government as a likely Iranian interference effort. The initial reporting on the Proud Boys emails painted a picture of a crude campaign that was almost immediately unmasked. But Thursday’s indictment suggests a much more complex operation. Officials told reporters […]

The post Two Iranian hackers charged in sprawling effort to interfere in 2020 U.S. election appeared first on CyberScoop.

Continue reading Two Iranian hackers charged in sprawling effort to interfere in 2020 U.S. election

Previously unreported North Korean espionage part of busy 2021 for country’s hackers

A North Korean cyber espionage group known primarily for targeting think tanks, advocacy groups, journalists and others related to Pyongyang’s adversaries around the world has been quite prolific in 2021, according to email security firm Proofpoint. The stepped-up action includes launching near-weekly attacks, among them two previously unreported campaigns. In findings published Thursday, the firm examined the activities of a group it refers to as TA406, which it considers to be one of the components of an organization known more broadly as Kimsuky that’s been active since at least 2012. The U.S. government issued a public alert to the private sector in October 2020 about Kimsuky, warning of spearphishing, watering hole attacks and other methods designed to steal credentials. TA406 targets research, education, government, media and other organizations for credential theft, Proofpoint analysts Darien Huss and Selena Larson wrote. The group’s other activities involve financial crimes and sextortion, and an increased use […]

The post Previously unreported North Korean espionage part of busy 2021 for country’s hackers appeared first on CyberScoop.

Continue reading Previously unreported North Korean espionage part of busy 2021 for country’s hackers

Mandiant links Belarus to Ghostwriter campaign, which leaked stolen data and pushed disinformation

The Belarusian government is partially responsible for a years-long influence operation targeting Latvia, Lithuania and Poland, according to research published Tuesday. Operation “Ghostwriter,” a propaganda campaign that has pushed fabricated narratives about the North Atlantic Treaty Organization and COVID-19, among other topics, is the work of people in Belarus, including the country’s military, as part of an overall effort to hack and leak information, pollute political discourse with amplified narratives, and collect intelligence, according to the threat intelligence firm Mandiant, which has tracked the group for years. Investigators, including from the European Union, previously suggested that the operation aligned with Russian interests, as the social media campaigns apparently sought to sow mistrust in NATO’s military presence in Eastern Europe, a frequent goal of the Kremlin. The findings show that complex information operations once associated with Russia and China have become more common, Ben Read, director of Mandiant’s cyber espionage team, told […]

The post Mandiant links Belarus to Ghostwriter campaign, which leaked stolen data and pushed disinformation appeared first on CyberScoop.

Continue reading Mandiant links Belarus to Ghostwriter campaign, which leaked stolen data and pushed disinformation

TikTok scammers tried hacking 125 targets that followed famous accounts, researchers find

More than 125 people and businesses associated with large TikTok accounts based around the world were targeted as part of a recent phishing campaign, according to research published Tuesday. Emails warned that targeted accounts were either in danger of being deleted for copyright violations or eligible for a verification badge. If victims replied to a message, attackers directed them to click a link to a WhatsApp chat, where a purported TikTok representative would confirm their accounts. While it remains unclear if any accounts were breached, the campaign is the latest to demonstrate how TikTok’s popularity makes its mot visible users targets for scammers. In addition to individual account holders, the latest campaign targeted talent agencies, brand-consultant firms, social media production studios, influencer management firms, according to Rachelle Chouinard, a threat intelligence analyst at email security firm Abnormal Security, which shared its findings with CyberScoop. Crane Hassold, the director of threat […]

The post TikTok scammers tried hacking 125 targets that followed famous accounts, researchers find appeared first on CyberScoop.

Continue reading TikTok scammers tried hacking 125 targets that followed famous accounts, researchers find

Hundreds of Twitter accounts aimed to suppress vote weeks before Honduran presidential election

Hundreds of fake Twitter accounts targeted opposition candidates and urged citizens not to vote in an upcoming Honduran presidential election, according to research published Wednesday. The 317 accounts appear to be part of an effort to influence the Nov. 28 Honduran presidential election by denigrating two of opposition candidates running against the incumbent National Party of Honduras’ candidate, Nasry Asfura, according to Nisos, the threat intelligence firm that published its findings Wednesday. The network of profiles in some cases used authentic photos from Peruvian Facebook accounts in an attempt to aid legitimacy, some cases apparently using computer-generated images as avatars. Twitter removed the accounts in November upon learning of the inauthentic behavior observed by Nisos. The company did not respond to questions prior to press time. The influence operation would be just the latest example of coordinated inauthentic political messaging on social media in Honduras and its regional neighbors. A […]

The post Hundreds of Twitter accounts aimed to suppress vote weeks before Honduran presidential election appeared first on CyberScoop.

Continue reading Hundreds of Twitter accounts aimed to suppress vote weeks before Honduran presidential election

US charges 2, seizes more than $6 million as part of dragnet against REvil ransomware gang

The U.S. government announced a sweeping set of actions Monday targeting alleged REvil ransomware attackers in Europe, including an arrest, an indictment, seizure of more than $6 million in stolen money, and new sanctions against a cryptocurrency exchange service and companies that support it. Yaroslav Vasinksyi, 22 a Ukrainian national, was arrested Oct. 8 as he crossed the border into Poland at the behest of US authorities, CyberScoop first reported Nov. 2. Vaskinskyi is accused of writing the code behind REvil malware, also known as Sodinokibi, which has become among the most virulent ransomware strains in use. U.S. Attorney General Merrick Garland said the malware has been “deployed” against roughly 175,000 computers worldwide, generating at least $200 million in extortion fees. U.S. officials also announced criminal charges against Yevgeniy Polyanin, a Russian national. Along with the charges of conspiracy to commit fraud in connection with computers, intentional damage to a […]

The post US charges 2, seizes more than $6 million as part of dragnet against REvil ransomware gang appeared first on CyberScoop.

Continue reading US charges 2, seizes more than $6 million as part of dragnet against REvil ransomware gang

Suspected REvil scammers arrested amid ongoing crackdown on ransomware

Two cybercrime suspects accused of launching 5,000 ransomware attacks and netting roughly $579,000 were arrested by Romanian authorities, Europol announced Monday. The suspects allegedly used the REvil ransomware strain, the malware variant associated with a notorious Russian cybercrime gang that’s been used in a recent string of high-profile international ransomware incidents. REvil was, until recently, perhaps the most commonly used ransomware generating hundreds of millions in revenue for attackers and affiliates. The Europol arrests coincide with the U.S. Department of Justice’s seizure of $6 million in ransomware payments in connection with REvil activity, according to CNN. Authorities have charged Yevgeniy Polyanin, a Russian national, and Ukrainian Yaroslav Vasinskyi, who’s arrest was first reported by CyberScoop, in connection with deploying REvil ransomware. The arrests mark the sixth and seventh arrests in an ongoing international law enforcement crackdown on ransomware operators. Since February, Europol said, three REvil affiliates have been arrested, along […]

The post Suspected REvil scammers arrested amid ongoing crackdown on ransomware appeared first on CyberScoop.

Continue reading Suspected REvil scammers arrested amid ongoing crackdown on ransomware

Ukraine exposes expansive Russian hacking operation targeting its government, infrastructure

Ukraine’s top law enforcement agency published a detailed analysis Thursday outing what it says are Russian hackers and “traitors who sided with the enemy” behind a sweeping campaign that began in 2014. The hackers, according to the Security Service of Ukraine, are responsible for more than 5,000 cyberattacks on Ukrainian state entities and critical infrastructure that attempted to “infect” more than 1,500 government computer systems. The report says the Russian intelligence agency the Federal Security Service (FSB) is behind the “Armageddon” group, known more broadly outside Ukrainian borders as Gamaredon or Primitive Bear. It’s distinct from other Russian intelligence and military hacking groups behind attacks on targets around the world, including the infamous hacks of the Democratic National Committee and Hillary Clinton’s campaign ahead of the 2016 elections. Armageddon dates back to 2013 or 2014, the Ukrainian report says, making it “relatively young,” but nevertheless worthy of attention and “able […]

The post Ukraine exposes expansive Russian hacking operation targeting its government, infrastructure appeared first on CyberScoop.

Continue reading Ukraine exposes expansive Russian hacking operation targeting its government, infrastructure

Suspect in scheme to breach major Twitter accounts is now charged with hacking crypto executives

Federal prosecutors on Wednesday unsealed an indictment against a 22-year-old British man accused of stealing $784,000 in cryptocurrency from a Manhattan-based holding company. U.S. attorneys in the Southern District of New York say Joseph James O’Connor and his associates SIM-swapped three executives between March and May in 2019 at a company that maintained cryptocurrency wallet infrastructure for various international exchanges. SIM-swapping occurs when an attacker takes control of a victim’s phone number by linking the number to a device controlled by the attacker. CyberScoop could not immediately locate an attorney for O’Connor. The operation netted the group various amounts of litecoin, ethereum, and bitcoin totaling roughly $784,000. The indictment, originally filed on Aug. 25, charges O’Connor with conspiracy to commit computer hacking, conspiracy to commit wire fraud, aggravated identity theft and conspiracy to commit money laundering. O’Connor — also known as “PlugWalkJoe” — was arrested in Spain in July after […]

The post Suspect in scheme to breach major Twitter accounts is now charged with hacking crypto executives appeared first on CyberScoop.

Continue reading Suspect in scheme to breach major Twitter accounts is now charged with hacking crypto executives