Ransomware: aktuelle Erpressungs- und Datenleck-Faelle
Ransomware-Gruppen ergaenzen die Verschluesselung seit 2020 mit Datenexfiltration. Wir verfolgen die aktiven Leak-Sites und die Familien, die Schweizer und EU-KMU angreifen.
E-Mail droht mit der Veroeffentlichung eines angeblichen Webcam-Videos und nennt zusaetzlich Name, Strasse und Bank-IBAN (aus Data Breaches, z.B. MOVEit 2023, Telekom 2024). Bitcoin-Forderung...
A new malware family called SynkLoader is being delivered through fraudulent Microsoft Teams messages. Attackers impersonate colleagues or IT staff and send chats that contain links or attachments...
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000-$60,000. Researchers at...
Steam hardware buyers across Europe are being warned: a cyberattack on logistics provider CEVA Logistics exposed names, home addresses, phone numbers, and order details for anyone who received a...
The NCSC Switzerland warns of a sharp rise in compromised legitimate websites (over 100,000 globally) that display fake CAPTCHA verification pop-ups. Instead of a normal "I am not a robot" check,...
Cybercriminals linked to the BlackFile extortion group are calling employees on their personal mobile phones, spoofing the corporate IT helpdesk, and asking them to enroll in passkeys or update...
Attackers are calling employees directly through Microsoft Teams, pretending to be internal IT support, to trick victims into granting remote access. Once inside, they deploy Chaos ransomware,...
Fast-food chain Chick-fil-A has confirmed that 13,322 customers had personal data stolen during credential stuffing attacks against its Chick-fil-A One loyalty platform between June 17 and 19, 2026....
Fast-food chain Chick-fil-A has disclosed a credential stuffing attack that hijacked customer loyalty accounts between June 17-19, 2026. Attackers used usernames and passwords leaked from other...
Cybercriminals are exploiting trust in video conferencing platforms by sending fake Zoom invitations that prompt victims to download a supposed "required update." In reality, the installer delivers...
Sextortion scammers are impersonating the ShinyHunters hacking group, using email addresses harvested from recent data breaches (Amtrak, Hallmark, ADT, Substack, and others) to send fake blackmail...
Kaspersky researchers have uncovered dozens of malicious wallpapers circulating on Steam Workshop, distributed via the popular Wallpaper Engine app. Attackers, mainly targeting gamers in China and...
A phishing email carrying an attachment that looks like a PDF actually drops a malicious Chrome extension designed to steal browser session cookies and take over your logged-in accounts — even those...
Operation Endgame dismantled the SocGholish (FakeUpdates) framework, which hijacked ~15,000 legitimate WordPress sites to serve convincing fake browser and software update prompts to everyday...
Summary : Cybercriminals are sending fake voicemail notifications by email, spoofing Microsoft branding to either harvest Office 365 / Outlook login credentials on phishing pages or trick victims...
Researchers have discovered a publicly exposed database containing roughly 24 billion stolen credential records, gathered from 36 sources including infostealer logs, Telegram channels, and prior...
Attackers are disguising Windows malware as legitimate retro-console homebrew plugins on GitHub, preying on the trust built inside modding communities. A fake project called EQVita mimicked a real PS...
The Canadian Anti-Fraud Centre (CAFC) maintains a navigational catalog of fraud types that commonly target individuals across Canada. The list spans dozens of categories — from phishing, romance...