2026-03-25
[vendor] FBI Director Kash Patel personal email account
Vector: Handala — an Iranian state-linked hacktivist group operating as a persona for Iran's IRGC (Islamic Revolutionary Guard Corps) — obtained access to FBI Director Kash Patel's personal email account and/or cloud storage through unknown means, likely credential theft, SIM swapping, or exploitation of a third-party service
In late March 2026, Handala — an Iranian state-linked hacktivist group that has previously conducted operations attributed to Iran's IRGC — published photographs and alleged …
2026-03-20
Vector: A suspected cyberespionage campaign targeted a Libyan oil refinery using commodity malware, maintaining persistent access over multiple months for industrial intelligence collection
A multi-month cyberespionage campaign targeted a Libyan oil refinery in 2026, using commodity (commercially
available) malware to maintain persistent covert access for intelligence …
2026-01-19
[vendor] Starbucks Partner Central (employee HR/payroll portal)
Vector: Attackers used phishing — fake websites mimicking the Starbucks Partner Central employee portal — to steal employee login credentials, then used those credentials to access the portal and exfiltrate employee PII
Between January 19 and February 11, 2026, attackers used phishing pages cloning the Starbucks Partner Central portal to steal employee credentials. Starbucks detected the …
2025-01-01
Vector: Insider threat: cybercriminals bribed overseas customer support contractors (via TaskUs vendor) to exfiltrate customer data from internal support tools
Attackers bribed at least one overseas customer support agent contracted through third-party vendor TaskUs to access and steal Coinbase customer data from internal support systems. …
2024-10-16
[vendor] Safe Wallet (multi-sig infrastructure)
[malware] InletDrift
Vector: North Korean UNC4736 (Citrine Sleet/Lazarus sub-group) delivered InletDrift malware via malicious PDF on Telegram, posing as a trusted ex-contractor; malware compromised at least 3 developer hardware wallets by replacing Safe Wallet front-end display while submitting malicious transactions for signing
On 16 October 2024, attackers executed transferOwnership on Radiant Capital's Pool Provider contract using 3 collected malicious signatures, gaining control of all lending pool …
2024-07-18
[vendor] Liminal Custody (multi-sig wallet infrastructure)
[malware] Safe Wallet front-end manipulation / transaction substitution
Vector: Lazarus Group (North Korea) compromised WazirX multi-signature wallet by social engineering developers and manipulating Safe Wallet front-end; malware replaced legitimate transaction displays to collect hardware wallet signatures
$234.9 million in crypto assets stolen from Indian exchange WazirX on 18 July 2024. Attributed to North Korea's Lazarus Group by joint US/Japan/South Korea statement in January …
2024-05-31
[vendor] Ginco (crypto wallet provider)
Vector: TraderTraitor (North Korean) social engineering of an employee at crypto wallet company Ginco; attackers gained access to Ginco communications systems and intercepted a legitimate DMM Bitcoin transaction
North Korean TraderTraitor hackers stole 4,502.9 BTC (~$308 million) from Japanese crypto exchange DMM Bitcoin on 31 May 2024 — the third-largest crypto theft in history. FBI, DC3, …
2024-03-01
[vendor] Roku streaming platform
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (credential stuffing using credentials stolen from third-party breaches)
Second Roku credential stuffing incident of 2024 (first: ~15,000 accounts in March). Attackers used username/password pairs from prior unrelated breaches to authenticate against …
2024-01-01
[vendor] Microsoft 365 and Google Workspace tenants (targeted via Tycoon2FA phishing kit)
[malware] Tycoon2FA phishing kit
Vector: Tycoon2FA is a phishing-as-a-service (PhaaS) platform that implements adversary-in-the-middle (AiTM) techniques using reverse proxy infrastructure to intercept and steal session cookies from Microsoft 365 and Google Workspace users, bypassing multi-factor authentication in real time
Tycoon2FA is a sophisticated phishing-as-a-service platform discovered in 2023 and analysed in depth by Sekoia.io in March 2024. The platform operates as a reverse proxy between …
2023-11-01
[vendor] Microsoft corporate Office 365 email / source code repositories
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (password spray attack against a legacy non-production test tenant account lacking MFA)
Midnight Blizzard (Russian SVR, also known as Nobelium/Cozy Bear/APT29) conducted a password spray attack against a legacy Microsoft test tenant account with no MFA enabled in …
2022-10-09
[vendor] MyDeal CRM system
Vector: Attacker used compromised user credentials to access MyDeal's CRM system, which contained customer data; the compromised credentials allowed the attacker to extract approximately 2.2 million customer records
On 9 October 2022, MyDeal — an Australian online retail marketplace owned by Woolworths Group (acquired in 2022 for A$217 million) — was breached via compromised user credentials …
2022-09-15
[vendor] Uber corporate network / Thycotic PAM
Vector: CWE-1390: Weak Authentication (MFA push notification fatigue / bombing combined with social engineering via WhatsApp)
18-year-old Lapsus$-affiliated attacker purchased stolen contractor VPN credentials from dark web. Bypassed Duo MFA by bombing target with push notifications for >1 hour then …
2022-09-11
[vendor] Revolut internal customer support database
Vector: Targeted social engineering attack against a Revolut employee who was tricked into granting the attacker access to Revolut's internal customer support database; the attacker used the employee's legitimate credentials and access to query and exfiltrate customer records
On 11 September 2022, an attacker used a sophisticated social engineering technique to gain access to Revolut's customer support system through a Revolut employee. The attacker …
2022-09-11
Vector: Social engineering — a threat actor used targeted phishing/social engineering techniques against a Revolut employee to obtain credentials, gaining unauthorized access to Revolut's internal database systems
On September 11, 2022, Revolut — a UK/EU-based neobank and fintech company with over 20 million customers — suffered a brief but significant data breach via a social engineering …
2022-06-01
[vendor] Marriott International employee workstation / local property data
Vector: Attacker used social engineering to trick a Marriott employee at a Maryland property into granting remote access to their workstation; once access was established, approximately 20GB of data was exfiltrated over a period prior to detection
In June 2022, Marriott International suffered its third significant data breach in four years (after the 2018 Starwood breach affecting 383M guests and the 2020 employee credential …
2022-05-24
[vendor] Cisco corporate network / VPN
Vector: Yanluowang ransomware affiliate gained access to a Cisco employee's personal Google Chrome profile that had Cisco VPN credentials saved; the employee's personal Google account was compromised, exposing the saved credentials; the attacker then conducted extensive MFA push fatigue attacks and vishing calls impersonating Cisco IT support to convince the employee to approve MFA push notifications
On 24 May 2022, a Yanluowang ransomware affiliate (linked to UNC2447/Lapsus$ connections) compromised Cisco Systems through a combination of credential theft from a personal Google …
2022-03-20
[vendor] Microsoft Azure DevOps
Vector: LAPSUS$ (DEV-0537) compromised a single Microsoft employee account and used it to access Microsoft's Azure DevOps source code repositories
On March 20, 2022, LAPSUS$ posted a screenshot on Telegram showing they had access to Microsoft's internal Azure DevOps environment, including source code repositories for Bing, …
2022-02-23
Vector: LAPSUS$ gained access to NVIDIA's network (method not fully disclosed, believed to involve compromised employee VPN credentials and an employee whose personal computer was infected with malware connecting to corporate systems)
On February 23, 2022, LAPSUS$ — a cybercriminal extortion group — gained access to NVIDIA's internal systems and exfiltrated approximately 1TB of data. NVIDIA was alerted to the …
2021-11-03
Vector: Attacker called a Robinhood customer support phone line and social-engineered a support employee into providing access to the customer support system, then used that access to exfiltrate customer records
On November 3, 2021, an attacker called Robinhood's customer support line and socially engineered a customer support employee into granting them unauthorized access to the customer …
2021-09-06
[vendor] GoDaddy Managed WordPress
Vector: Attacker used a compromised password to gain access to GoDaddy's Managed WordPress provisioning system; the password granted access since at least September 6, 2021 — giving the attacker 2+ months of undetected access
On September 6, 2021, an attacker used a compromised password to access GoDaddy's Managed WordPress hosting provisioning system, where they maintained access for over two months …
2020-09-01
[vendor] Spotify
Vector: Credential stuffing — attackers used a database of approximately 380 million records (username/password pairs from unrelated third-party breaches) to systematically attempt logins on Spotify accounts; valid credential matches were used for account takeover
In November 2020, security researchers at vpnMentor discovered an unsecured Elasticsearch database containing approximately 380 million records including usernames, passwords, and …
2020-07-15
[vendor] Twitter internal admin tools ('God Mode')
Vector: Vishing (voice phishing) calls targeting Twitter employees not in the office due to COVID-19; attackers impersonated Twitter IT staff to trick employees into providing credentials to a fake VPN portal, then used those credentials to access Twitter's internal admin tools
On July 15, 2020, attackers hijacked approximately 130 high-profile Twitter accounts including Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple, Uber, Jeff Bezos, Kanye West, …
2020-06-17
[vendor] MEDNAX Microsoft Office 365 / patient data systems
Vector: A phishing attack compromised the Microsoft Office 365 email accounts of multiple MEDNAX employees; the attackers used the compromised email accounts to access MEDNAX's business systems and then exfiltrated patient data from the company's healthcare platforms
In June 2020, MEDNAX — a national health solutions company providing physician services management, including neonatology and pediatric subspecialty care, to approximately 120,000 …
2020-06-01
Vector: Unauthorized database access by ShinyHunters threat group; exact initial access vector not disclosed by Wattpad; database exfiltrated containing 268M user account records
In approximately June 2020, ShinyHunters — a prolific cybercrime group responsible for multiple major 2020 breaches (Tokopedia, Dave.com, Microsoft GitHub repos) — breached Wattpad …
2020-04-04
[vendor] Service NSW staff email accounts / customer correspondence
Vector: Phishing emails compromised the email accounts of 47 Service NSW staff members; from the compromised email accounts, attackers were able to access customer data processed through Service NSW email correspondence and attached documents
In April 2020, 47 Service NSW employee email accounts were compromised through a phishing attack, allowing unauthorized access to customer data processed through those email …
2020-04-01
[vendor] Nintendo Account / Nintendo Network ID (NNID) system
Vector: Attackers used credential stuffing — username and password combinations from other data breaches — to log into Nintendo accounts via the legacy Nintendo Network ID (NNID) login system; the NNID system was being deprecated and allowed third-party login to Nintendo accounts
In April 2020, Nintendo disclosed that approximately 160,000 Nintendo accounts had been accessed without authorisation using a credential stuffing attack against the Nintendo …
2020-03-01
[vendor] Nintendo Network ID (NNID) / Nintendo Account
Vector: Credential stuffing — attackers used previously leaked username/password combinations to log into Nintendo Network IDs (NNIDs) via a legacy login portal; successful logins allowed attackers to access linked Nintendo Accounts and make fraudulent purchases via saved payment methods
In April 2020, Nintendo disclosed that approximately 160,000 Nintendo Network IDs (NNIDs) — a legacy login system from the Nintendo 3DS and Wii U era — had been compromised via …
2020-02-19
Vector: CWE-285: Improper Authorisation (malicious actors gained access to T-Mobile employee email accounts, which contained customer information)
T-Mobile disclosed a breach on March 5 2020 affecting approximately 200,000 customers. Attackers had accessed some T-Mobile employee email accounts containing customer proprietary …
2020-01-01
[vendor] Marriott guest services application
Vector: An attacker used the login credentials of two Marriott employees at a franchise property to access a Marriott application used to provide services to guests; the attacker accessed guest data through the legitimate employee login for approximately two months before detection
In March 2020, Marriott International disclosed a second data breach (separate from the 2018 Starwood breach affecting 383 million guests) in which an attacker used the login …
2019-11-01
Vector: Unauthorized access to T-Mobile systems containing prepaid customer data; specific access vector not disclosed publicly; distinct from the 2021 John Binns breach affecting 54M records
In November 2019, T-Mobile's cybersecurity team identified and shut down unauthorized access to systems containing prepaid customer account information. Approximately 1.26 million …
2019-05-24
Vector: Unauthorized database access by threat actor GnosticPlayers; attacker claimed to have exploited a vulnerability in Canva's systems (exact vector not publicly confirmed by Canva); affected database contained user account records including bcrypt-hashed passwords
On May 24, 2019, Canva — the Australian graphic design SaaS platform — suffered a data breach in which threat actor GnosticPlayers exfiltrated approximately 137 million user …
2019-03-14
Vector: Credential stuffing / account takeover — unauthorized parties used lists of phone number and PIN combinations (likely from prior breaches) to access Boost Mobile customer accounts through the customer portal
On March 14, 2019, unauthorized parties used credential stuffing techniques — using phone numbers as usernames combined with account PINs — to access an unknown number of Boost …
2018-10-31
[vendor] Dunkin Donuts DD Perks loyalty program
Vector: Cybercriminals used credential stuffing — testing large volumes of username/password combinations stolen from other data breaches — against Dunkin' Donuts's DD Perks rewards program; the attack targeted the mobile app login and successfully authenticated using previously compromised credentials from unrelated breaches
In late October 2018, Dunkin Donuts — one of the world's largest coffee and baked goods chains — suffered a credential stuffing attack against its DD Perks loyalty rewards program. …
2018-07-04
[vendor] Timehop cloud production environment / user database
Vector: An attacker used a compromised cloud environment credential (lacking multi-factor authentication) to access Timehop's production cloud environment; from there, the attacker accessed Timehop's production database and social network access tokens
On 4 July 2018 (US Independence Day), an attacker used a compromised cloud environment credential — which lacked multi-factor authentication — to access Timehop's production cloud …
2018-03-14
[vendor] UnityPoint Health employee email / patient data systems
Vector: Business email compromise (BEC) phishing — a sophisticated email fraud campaign impersonating a UnityPoint Health executive directed employees to click a link and enter credentials, compromising multiple employee email accounts; the attacker used compromised email accounts to access patient data and attempt additional payroll and wire fraud
In March and May 2018, UnityPoint Health — a major Iowa-based health system operating approximately 32 hospitals and 280 clinics in Iowa, Illinois, and Wisconsin — suffered two …
2018-01-01
Vector: Compilation of data from 2,000+ previously breached databases, aggregated into a single 87GB credential collection and posted on MEGA cloud storage and hacking forums, designed for use in credential stuffing attacks at scale
On January 17, 2019, Troy Hunt (creator of HaveIBeenPwned) disclosed 'Collection #1' — an 87GB aggregated credential dump that had appeared on MEGA cloud storage and hacking …
2017-06-23
[vendor] Microsoft Outlook Web Access (OWA)
Vector: Sustained brute-force attack against UK Parliament's internet-facing Outlook Web Access (OWA) email portal; attackers targeted accounts where MPs and staff used weak passwords without multi-factor authentication enforced on remote access
On June 23–24, 2017, an unknown attacker conducted a sustained brute-force attack against the UK Parliament's Outlook Web Access (OWA) email portal at Westminster. Parliament's IT …
2017-05-01
[malware] BOOSTWRITE / POS malware (FIN7)
Vector: FIN7 cybercrime syndicate (affiliated with Joker's Stash carding marketplace) deployed POS malware across all Lord & Taylor stores and 83 Saks Fifth Avenue locations in North America; malware captured payment card Track data from magnetic stripe readers at physical retail locations
Between approximately May 2017 and March 2018 (approximately 10 months), the FIN7 cybercriminal organization's Joker's Stash carding marketplace operators deployed POS malware …
2017-04-03
[malware] POS malware
Vector: POS malware exploiting disabled or non-functioning point-to-point encryption (P2PE) on Forever 21 payment terminals; malware captured plaintext card data at terminals where encryption was not active, and also accessed completed transaction logs stored on POS devices
Between approximately April 3 and November 18, 2017 (~7 months), POS malware infected Forever 21 retail store locations in the United States. Forever 21 issued an initial public …
2017-03-24
[malware] POS malware (Track data scraper)
Vector: POS malware installed on payment devices at the majority of Chipotle Mexican Grill restaurant locations; malware searched for and captured Track 1 and Track 2 magnetic stripe data as it was routed through POS processing systems
Between March 24 and April 18, 2017, POS malware infected the majority of approximately 2,250 Chipotle Mexican Grill restaurant locations across 47 U.S. states and Washington D.C., …
2017-01-01
[malware] POS malware
Vector: POS malware deployed across Sonic Drive-In restaurant locations; malware copied payment card data at each swipe from magnetic stripe readers and exfiltrated it to attacker infrastructure
In September 2017, security journalist Brian Krebs reported that a large batch of approximately 5 million stolen payment cards linked to Sonic Drive-In locations had appeared on …
2016-10-25
[malware] POS malware (Track 1/Track 2 scraper)
Vector: POS malware deployed on corporate-owned Arby's restaurant systems (not franchise locations); malware captured Track 1 and Track 2 magnetic stripe data as it transited infected POS devices
Between approximately October 25, 2016 and January 19, 2017, POS malware infected corporate-owned Arby's restaurant locations across the United States. Franchise locations were not …
2016-08-10
[vendor] Sabre SynXis Central Reservations System
Vector: Attacker compromised an administrator-level account in Sabre's SynXis central reservations system; the admin password was stored in plaintext within the system; the attacker used the admin account to access payment processing pages and exfiltrate card data daily over approximately 7 months
Between approximately August 10, 2016 and March 9, 2017, an attacker used a compromised administrator account in Sabre Corporation's SynXis Hospitality Solutions central …
2016-08-01
[malware] POS malware (Track data scraper)
Vector: POS malware deployed on restaurant and bar point-of-sale systems at IHG franchise hotel locations; malware searched for and captured Track 1 and Track 2 payment card data as it transited affected POS servers
Between approximately August 1 and December 29, 2016, POS malware was deployed at IHG franchise hotel properties across the United States and Puerto Rico. IHG (InterContinental …
2016-03-19
[vendor] Google Gmail (Podesta) / DNC internal network
[malware] X-Agent, X-Tunnel, Mimikatz, PlugX
Vector: Russian GRU Unit 26165 (Fancy Bear / APT28) sent spear-phishing emails to Democratic National Committee (DNC) staff and John Podesta (Clinton campaign chairman) that harvested their Google account credentials via a fake Google security alert page; access to Podesta's Gmail was obtained after a staffer incorrectly characterised the phishing email as 'legitimate'
Beginning in March 2016, Russian military intelligence operatives from GRU Unit 26165 (Fancy Bear/APT28) and Unit 74455 (Sandworm) conducted a comprehensive hacking campaign …
2016-02-26
[vendor] Snapchat HR / payroll systems
Vector: An attacker impersonated Snapchat's CEO Evan Spiegel in a phishing email sent to a Snapchat payroll employee, requesting payroll information; the employee complied and sent payroll data for a number of current and former employees to the attacker — a classic CEO fraud / business email compromise (BEC) attack
On 26 February 2016, a Snapchat payroll department employee received an email purportedly from CEO Evan Spiegel requesting payroll information for employees. The employee complied …
2015-10-01
[malware] POS malware (two distinct strains)
Vector: Attackers compromised remote access credentials belonging to a third-party service provider with access to Wendy's franchisee POS systems, then installed POS malware across multiple franchise locations; a second distinct malware strain was also discovered affecting additional locations
Between approximately fall 2015 and spring 2016, POS malware was deployed at Wendy's franchise restaurant locations in the United States. Wendy's first disclosed the breach in May …
2015-08-13
[malware] POS malware
Vector: POS malware installed on payment processing computers at Hyatt-managed hotels, primarily targeting restaurant and food/beverage outlet POS terminals; malware harvested cardholder names, card numbers, expiration dates, and internal verification codes as data was processed
Between approximately August 13 and December 8, 2015, POS malware infected payment processing systems at 250 Hyatt-managed hotels across 50 countries, including 100 hotels in 26 …
2015-01-01
[vendor] IRS Get Transcript online application
Vector: Sophisticated crime ring (attributed to Russian-speaking criminal syndicate) used previously stolen personal data (Social Security numbers, dates of birth, addresses, filing status) obtained from external sources to pass the IRS Get Transcript application's authentication questions and access prior-year tax returns for use in fraudulent refund claims
Between January and May 2015, a sophisticated crime ring accessed the IRS's 'Get Transcript' online application — which allowed taxpayers to retrieve prior-year tax returns — and …
2014-09-01
[vendor] Kmart (Sears Holdings Corporation)
[malware] POS RAM-scraping malware (specific variant not publicly named)
Vector: Point-of-sale (POS) malware installed on Kmart store payment terminals; the malware was undetected by Kmart's and Sears Holdings' antivirus systems for approximately one month before discovery; the precise initial intrusion vector (how malware was installed on the POS systems) was not disclosed
On October 10, 2014, Sears Holdings announced that Kmart stores had been the victim of a data breach involving malware installed on point-of-sale systems. The company stated that …
2013-09-01
[malware] POS malware (FIN6)
Vector: FIN6 cybercrime group deployed POS malware on P.F. Chang's restaurant payment systems; malware captured Track 1 and Track 2 magnetic stripe data from in-store transactions over approximately 9 months
P.F. Chang's China Bistro, a US casual dining restaurant chain, confirmed in June 2014 that its payment systems had been compromised by POS malware for approximately 9 months …
2013-09-01
[malware] POS RAM-scraping malware
Vector: POS malware — attackers compromised P.F. Chang's corporate network and installed RAM-scraping malware on point-of-sale systems at restaurant locations; the specific initial network intrusion vector was not fully disclosed
P.F. Chang's China Bistro, a national casual dining restaurant chain, confirmed in June 2014 that it had suffered a payment card breach after KrebsOnSecurity reported that a large …
2013-05-08
[malware] POS malware (Track data scraper)
Vector: POS malware deployed on payment systems at Michaels arts and crafts stores and Aaron Brothers stores; initial access likely via compromised third-party vendor credentials; malware captured Track 1 and Track 2 magnetic stripe data
Michaels Stores, the US arts and crafts retail chain, confirmed in April 2014 that a data breach between May 8, 2013 and January 27, 2014 (approximately 9 months) had compromised …
2013-05-08
[malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on point-of-sale terminals at Michaels Stores and Aaron Brothers (subsidiary) retail locations, capturing full payment card track data as cards were swiped at checkout
Michaels Stores, the large arts and crafts retail chain, disclosed in January 2014 that it was investigating a potential data security breach involving payment cards used at its …
2012-12-01
[malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on Schnucks' point-of-sale systems at multiple grocery store locations, capturing payment card track data during checkout transactions
Schnucks, a regional Midwestern grocery chain headquartered in St. Louis, Missouri, with approximately 100 store locations, disclosed in March 2013 that it had suffered a payment …
2012-08-01
Vector: Physical tampering — attackers installed hardware skimming devices (including PIN capture overlays) on PIN pad terminals at 63 Barnes & Noble stores across 9 states; tampered terminals captured both the magnetic stripe data and PIN from debit card transactions
Barnes & Noble, the US bookseller, disclosed in October 2012 that PIN pad payment terminals at 63 retail stores across 9 states had been physically tampered with — skimming devices …
2012-06-01
Vector: Physical PIN pad tampering — attackers physically installed hardware skimmers or modified PIN pad devices at Barnes & Noble retail checkout terminals in 63 stores across nine US states; the tampered devices captured payment card magnetic stripe data and PINs
Barnes & Noble disclosed in October 2012 that criminals had tampered with at least one PIN pad terminal at each of 63 of its retail bookstore locations across nine states …
2012-05-01
Vector: Database breach — attackers gained unauthorized access to eHarmony's member database and extracted hashed passwords; eHarmony stored passwords as unsalted MD5 hashes, making them highly susceptible to rainbow table and brute-force cracking
On June 6, 2012, eHarmony confirmed that a subset of its member passwords had been compromised and posted to an online password cracking forum. Approximately 1.5 million password …
2012-05-01
Vector: Unauthorized access to eHarmony's user database; attackers obtained and published approximately 1.5 million unsalted MD5 password hashes online
eHarmony, the US online dating service, disclosed on June 6, 2012 that a subset of its member passwords had been compromised and posted online. Approximately 1.5 million unsalted …
2012-03-01
Vector: Database breach — attackers obtained Last.fm's user credential database; the passwords were stored as unsalted MD5 hashes, enabling mass cracking; the breach was not discovered publicly until 2016 when the database appeared on underground markets
Last.fm, the music discovery and social listening service (owned by CBS Interactive from 2007), suffered a breach of its user database that occurred around 2012 but was not …
2011-01-01
[malware] POS keylogger/scraping malware
Vector: Remote desktop protocol (RDP) intrusion — a Romanian criminal group remotely accessed franchise-owned Subway POS systems using weak or default RDP credentials; many Subway franchise locations ran their POS software on Windows computers with RDP enabled and inadequate passwords
A Romanian cybercrime group compromised point-of-sale systems at approximately 150 Subway franchise restaurants across the United States, stealing over 80,000 payment card numbers …
2009-01-05
Vector: Automated brute-force attack against Twitter's administrative control panel using common passwords; Twitter had no account lockout policy or rate limiting on administrative login attempts, allowing unlimited password guesses
In January 2009, a hacker gained access to Twitter's administrative control panel by guessing the password of a Twitter admin account using automated brute force — Twitter had …
2008-11-04
[vendor] RBS WorldPay payment processing network
Vector: Eastern European cybercriminals (Sergei Tsurikov et al.) exploited vulnerabilities in RBS WorldPay's payment processing network, broke the encryption protecting payroll debit card account data, raised withdrawal limits on 44 compromised accounts, and cloned cards for distribution to a global network of ATM 'cashers'
RBS WorldPay, the US payment processing division of the Royal Bank of Scotland (distinct from the later Worldpay/FIS entity), suffered a coordinated cyberattack in early November …
2002-08-01
Vector: Centralized underground internet forum enabling buying, selling, and trading of stolen credit card data, identity documents, and malware tools; supplied by members conducting phishing, skimming, malware deployment, and SQL injection attacks against financial institutions and retailers
ShadowCrew was an underground carding forum operating from August 2002 until its takedown on October 26, 2004 in Operation Firewall — a joint US Secret Service operation involving …
1999-12-01
Vector: Attacker (known only as 'Maxus,' believed to be an Eastern European teenager) exploited a vulnerability in CD Universe's payment processing software to access the customer credit card database
In December 1999, an attacker known only as 'Maxus' (believed to be a ~19-year-old Eastern European) exploited a vulnerability in the payment processing systems of CD Universe, an …