The saga of Breach Forums continues with twists and turns. Just when the FBI thought they'd scored another victory by seizing the infamous Breach Forums and arresting its co-administrator Baphomet, the remaining admin pulled a digital rabbit out of the hat. Despite the initial seizure of both the clear-net and Tor domains, as well as the Telegram channel, the FBI's victory was short-lived. Mere hours after the domain was seized and added to the FBI's account, the account was suspended, and the domain fell back into the hands of the elusive threat actor. Emails between the FBI and the domain registrar detailing this blunder have since surfaced online.
The apparent end of Breach Forums was, in fact, just the beginning of a new chapter. In less than two weeks, a new admin known as Shiny Hunters resurrected the forum from old backups, launching a new Tor domain and fresh Telegram group. Not only is the clear-net site back up and running, but Shiny Hunters has also made headlines by offering the entire Live Nation/Ticketmaster database—containing 560 million users—for a cool $500k USD. The identity of the buyer remains unknown, adding another layer of intrigue to this unfolding story.
In another development, a breach impacting several American government agencies, including the US armed forces, has surfaced on dark web platforms. The notorious threat actor IntelBroker, known for his swift and effective hacks, claimed to have accessed sensitive data from the breached site in just "10–15 minutes." The compromised company, established to address the evolving landscape of maritime domain awareness, now finds itself at the centre of a significant data leak.
Meanwhile, a well-known threat actor group has announced a dramatic shift in focus. Declaring their departure from financially motivated cybercrime, they have pledged to return to their roots in hacktivism and political hacking. Their latest leak, though unverified, promises to be substantial. The group claims to have exposed sensitive information affecting various Mexican cartels, including the Sinaloa and Jalisco cartels. This leak allegedly stems from a variety of sources, including government sites, cartel-supported centres, and shops. The data dump also includes an in-depth research writeup detailing cartel operations and locations. Our team is currently sifting through the data to verify the claims and assess the implications.
It's been an action-packed month for cybersecurity professionals, and as always, the landscape continues to evolve with each passing day.
Breach Exposure Monitoring | Dark Web Monitoring + Surface Web Monitoring
Scan Any Domain for Free https://breachaware.com/scan
THIS MONTHS SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINES
Threat actors will find this kind of data pretty handy.
https://breachaware.com/research/threat-actors-will-find-this-kind-of-data-pretty-handy
A total of 24 breaches were found and analysed resulting in 4,340,106 leaked accounts containing a total of 23 different data types. The breaches found publicly and freely available included Kringle Cash, Stealer Log 0462, Games Nord, Money Man and NOSIS.
USDoD says that they're bringing Breach Forums back!
https://breachaware.com/research/usdod-says-that-theyre-bringing-breach-forums-back
A total of 25 breaches were found and analysed resulting in 61,491,599 leaked accounts containing a total of 25 different data types. The breaches found publicly and freely available included The Post Millennial, Share This, Book 24, Stealer Log 0457 and Stealer Log 0459.
Hacker boasts it took “10–15 minutes” to steal data that included US armed forces.
https://breachaware.com/research/hacker-boasts-it-took-10-15-minutes-to-steal-data-that-included-us-armed-forces
A total of 35 breaches were found and analysed resulting in 4,063,408 leaked accounts containing a total of 26 different data types. The breaches found publicly and freely available included ESN, Stealer Log 0456, SVR Labs, Kuchenland and Stealer Log 0455.
French clothing retailer has suffered a major cyber attack.
https://breachaware.com/research/french-clothing-retailer-has-suffered-a-major-cyber-attack
A total of 19 breaches were found and analysed resulting in 6,573,110 leaked accounts containing a total of 22 different data types. The breaches found publicly and freely available included Rendez-Vous, Stealer Log 0454, boAt Lifestyle, Expandia and Intergroup Gold.
BreachAware Insight
THE LATEST CURATED INTEL FROM OUR RESEARCH CENTREListen to our podcast, where Andrew, the visionary CEO of BreachAware, sits down with unsung heroes of the cyber security industry. Get ready to uncover the stories and insights of industry trailblazers you might not have heard of before, as they share their experiences, opinions, and insider intel. But beware, it's not all serious talk—expect a healthy dose of humour (and the odd cussing) sprinkled throughout the conversation.
Weekly Summary
SPOTLIGHT, VULNERABILITY CHAT & PRIVACY HEADLINESGlobal News Feed
POPULAR CYBERSECURITY PUBLICATIONSA massive data leak linked to the MOVEit vulnerability has exposed millions of employee records from major companies. Learn about the impact of this leak, the role of the "data vigilante" Nam3L3ss.