Ransomware: casi recenti di estorsione e data breach
I gruppi ransomware hanno aggiunto l'esfiltrazione dei dati al gioco di cifratura intorno al 2020. Tracciamo i leak site attivi, le famiglie che colpiscono PMI svizzere ed europee, e la checklist di incident response.
La Polizia Postale italiana ha lanciato un allarme contro una truffa online molto diffusa: email che si fingono comunicazioni ufficiali delle Forze di Polizia, con loghi, intestazioni e firme false...
Una nuova campagna malware combina le tecniche ClickFix e EtherHiding per colpire utenti aziendali e consumer. Dopo la compromissione di siti web legittimi, gli attaccanti iniettano script offuscati...
Il CSIRT Italia ha rilevato una campagna di phishing massiva veicolata tramite PEC (Posta Elettronica Certificata) con allegati ZIP contenenti una pagina HTML malevola a tema "Fattura Elettronica"....
Email simula notifica vocemail da PBX aziendale (Mitel/Cisco/RingCentral) con allegato 'voicemail.html' o 'voicemail.zip'. L'allegato è un downloader di malware (Emotet, Qakbot, IcedID). Indicatori:...
A new malware family called SynkLoader is being delivered through fraudulent Microsoft Teams messages. Attackers impersonate colleagues or IT staff and send chats that contain links or attachments...
A threat actor calling itself "Ransom Busters" is contacting ransomware victims before attacks become public, claiming it can decrypt files and delete stolen data for $20,000-$60,000. Researchers at...
Steam hardware buyers across Europe are being warned: a cyberattack on logistics provider CEVA Logistics exposed names, home addresses, phone numbers, and order details for anyone who received a...
The NCSC Switzerland warns of a sharp rise in compromised legitimate websites (over 100,000 globally) that display fake CAPTCHA verification pop-ups. Instead of a normal "I am not a robot" check,...
Cybercriminals linked to the BlackFile extortion group are calling employees on their personal mobile phones, spoofing the corporate IT helpdesk, and asking them to enroll in passkeys or update...
Attackers are calling employees directly through Microsoft Teams, pretending to be internal IT support, to trick victims into granting remote access. Once inside, they deploy Chaos ransomware,...
Fast-food chain Chick-fil-A has confirmed that 13,322 customers had personal data stolen during credential stuffing attacks against its Chick-fil-A One loyalty platform between June 17 and 19, 2026....
Fast-food chain Chick-fil-A has disclosed a credential stuffing attack that hijacked customer loyalty accounts between June 17-19, 2026. Attackers used usernames and passwords leaked from other...
Cybercriminals are exploiting trust in video conferencing platforms by sending fake Zoom invitations that prompt victims to download a supposed "required update." In reality, the installer delivers...
Sextortion scammers are impersonating the ShinyHunters hacking group, using email addresses harvested from recent data breaches (Amtrak, Hallmark, ADT, Substack, and others) to send fake blackmail...
Kaspersky researchers have uncovered dozens of malicious wallpapers circulating on Steam Workshop, distributed via the popular Wallpaper Engine app. Attackers, mainly targeting gamers in China and...
A phishing email carrying an attachment that looks like a PDF actually drops a malicious Chrome extension designed to steal browser session cookies and take over your logged-in accounts — even those...
Operation Endgame dismantled the SocGholish (FakeUpdates) framework, which hijacked ~15,000 legitimate WordPress sites to serve convincing fake browser and software update prompts to everyday...
Summary : Cybercriminals are sending fake voicemail notifications by email, spoofing Microsoft branding to either harvest Office 365 / Outlook login credentials on phishing pages or trick victims...