#account-takeover

[ follow ]
Information security
fromThe Hacker News
5 days ago

How Can Retailers Cyber-Prepare for the Most Vulnerable Time of the Year?

Holiday shopping peaks concentrate automated credential-stuffing and account-takeover attacks that monetize stored payment tokens while third-party credentials enlarge breach impact.
Law
fromKIRO 7 News Seattle
6 days ago

Tacoma woman sentenced to prison for bank fraud scheme

A Tacoma credit union employee stole account data from 23 customers, enabling a group to steal $345,014 and was sentenced to just over two years.
fromMail Online
1 week ago

FBI issues warning to all Gmail users over email scam robbing users

Officials are urging people not to click on suspicious links or attachments in emails, websites, or social media posts, warning that a single click can install malware on a device. 'Phishing scams and similar crimes get you to click on links and give up personal information like your name, password, and bank account number,' the FBI said. 'Be especially wary if a company asks you to update your password or account information. 'Look up the company's phone number on your own and call the company.'
Information security
Information security
fromAdExchanger
1 week ago

Google Ad Buyers Are (Still) Being Duped By Sophisticated Account Takeover Scams | AdExchanger

Scammers hijack agency Google Ads and Merchant Center accounts to drain client funds, erase data, and lock admins out, using phishing and Gmail-based attacks.
#phishing
fromTheregister
3 months ago

Google, Microsoft account takeover made easy via VoidProxy

The phishes target any Google and Microsoft accounts, from small businesses to large enterprises, we're told. And while Okta didn't have a confirmed victim count, "we have observed high-confidence account takeovers in multiple entities," the threat intel team told us. "By extension, we expect Microsoft and Google will have observed a larger number of ATO events, given that VoidProxy proxies non-federated users directly with Microsoft and Google servers."
Information security
fromThe Hacker News
3 months ago

Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

"A potential attacker could take over customer accounts in Adobe Commerce through the Commerce REST API," Adobe said in an advisory issued today. The issue impacts the following products and versions - Adobe Commerce (all deployment methods): 2.4.9-alpha2 and earlier 2.4.8-p2 and earlier 2.4.7-p7 and earlier 2.4.6-p12 and earlier 2.4.5-p14 and earlier Adobe Commerce B2B: 1.5.3-alpha2 and earlier 1.5.2-p2 and earlier 1.4.2-p7 and earlier
E-Commerce
Information security
fromTheregister
3 months ago

Pentagon left livestream keys exposed, hijack risk included

Pentagon publicly posted streaming platform stream keys on DVIDS, exposing military social accounts to hijacking; the vulnerability has been addressed with new keys and fixes.
Information security
fromThe Hacker News
3 months ago

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

Threat actors exploit Axios and Microsoft Direct Send to spoof trusted senders, bypass gateways, and drive highly successful phishing and account takeover campaigns across industries.
#cybersecurity
fromThe Hacker News
6 months ago
Growth hacking

Over 80,000 Microsoft Entra ID Accounts Targeted Using Open-Source TeamFiltration Tool

The UNK_SneakyStrike campaign poses a significant threat to Microsoft Entra ID accounts through sophisticated attacks.
TeamFiltration tool enables attackers to perform account takeovers efficiently.
fromThe Hacker News
7 months ago
Privacy professionals

Customer Account Takeovers: The Multi-Billion Dollar Problem You Don't Know About

Account takeover attacks are widespread, impacting numerous industries and often resulting from weak passwords.
Session hijacking poses a significant security risk, allowing bypassing of multi-factor authentication.
[ Load more ]