credential theft news
8 stories
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
France's tax administration recently experienced a significant data breach, where an attacker reportedly used stolen staff passwords to access sensitive tax data. The incident, which impacted hundreds of thousands of individuals and businesses, went undetected for seven weeks. The breach was only brought to light after the attacker publicly claimed responsibility online, prompting an…

Attackers Exploit Collaboration Tools for Identity Theft
Cybersecurity researchers have observed a significant increase in threat actors exploiting enterprise collaboration platforms for identity-focused attacks, including phishing, impersonation, credential theft, and malware delivery. Over the past year, alerts related to malicious activity involving these tools have quadrupled, indicating a growing trend in their misuse.

Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
A security researcher has demonstrated a series of webmail client vulnerabilities that leverage Cascading Style Sheets (CSS) to steal credentials, hijack sessions, and manipulate AI tools integrated with user inboxes. The research, conducted by Gareth Heyes of PortSwigger, details attack chains against major webmail services including Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL…

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
A sophisticated threat actor, identified as Storm-2945, a sub-cluster of the group known as Midnight Blizzard, has reportedly initiated a global campaign dubbed "CaptiveCrunch." This operation specifically targets travelers by exploiting captive portal networks to facilitate malware delivery and credential theft. The threat actor is said to manipulate network traffic to achieve these…

North Korean hackers use fake coding interviews to steal developer credentials
North Korean state-sponsored hackers are employing a sophisticated new tactic, dubbed "Contagious Interview," to compromise developers by embedding malware within seemingly benign coding challenges. The campaign, tracked as REF9403, leverages steganography to hide multi-stage payloads within SVG image files, which have gone undetected by all major antivirus vendors.

Texas Parks and Wildlife, WordPress Plugin Vendor Hit by Data Breaches
The Texas Parks and Wildlife Department has confirmed a data breach affecting its hunting and fishing license system vendor, exposing personal information for over 3 million customers. Separately, ShapedPlugin, a vendor of WordPress plugins, suffered a supply chain attack that delivered malicious updates to its paid plugins.

Cybercriminals Are Targeting the FIFA World Cup 2026
Cybercriminals are actively targeting the upcoming FIFA World Cup 2026, establishing infrastructure and launching various scams to exploit the event's global appeal, according to research from FortiGuard Labs. The tournament, set to begin on June 11, 2026, is expected to attract significant attention and drive a high volume of digital transactions, creating a fertile ground for malicious actors.

Cloud Worm PCPJack Steals Credentials and Evicts TeamPCP Artifacts
A newly identified cloud worm, dubbed PCPJack, is actively targeting exposed cloud infrastructure to steal credentials and remove any artifacts associated with the threat actor group TeamPCP. SentinelLabs researchers discovered the framework, which operates as a credential theft toolset that propagates across cloud environments.