Threats Tagged 'data-theft'
View all threats tagged with 'data-theft'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'data-theft'
Click on any threat for detailed analysis and mitigation recommendations
ACRStealer, a sophisticated Malware as a Service, has evolved with enhanced evasion techniques and C2 communication strategies. It employs low-level syscalls and AFD for stealthy operations, bypassing user-mode hooks. The malware uses layered communication, establishing raw TCP connections followed by SSL/TLS over SSPI. ACRStealer's data-stealing capabilities are extensive, targeting browsers, Steam accounts, and performing victim fingerprinting. It can execute secondary payloads and capture screenshots. The malware shows an active infection pattern in countries like the USA, Mongolia, and Germany, communicating with specific IP addresses and domains. Recent developments indicate a shift to LummaStealer, suggesting ongoing threat actor activities targeting gaming platforms and social media. Join the discussion | AlienVault OTX General | 03/17/2026, 10:55:52 UTC Added: 03/17/2026, 11:27:29 UTC |
The Clop ransomware group has been observed targeting Gladinet CentreStack servers to conduct data theft and extortion attacks. By compromising these file-sharing and cloud storage platforms, attackers exfiltrate sensitive data before deploying ransomware, increasing pressure on victims to pay. This threat is significant due to the critical role CentreStack plays in enterprise file synchronization and sharing, potentially exposing large volumes of corporate data. The attacks do not yet have known public exploits, but the high severity rating reflects the impact of combined data theft and ransomware. European organizations using CentreStack should be vigilant, as the threat could disrupt business operations and lead to data breaches. Mitigation requires specific hardening of CentreStack deployments, network segmentation, and enhanced monitoring for unusual activity. Countries with high adoption of cloud collaboration tools and significant enterprise sectors, such as Germany, France, and the UK, are likely to be most affected. Given the ease of exploitation and the severe consequences of data loss and operational disruption, this threat is assessed as high severity. Defenders must prioritize detection and response capabilities tailored to CentreStack environments to reduce risk. Join the discussion | Reddit InfoSec News | 12/18/2025, 21:33:25 UTC Added: 12/18/2025, 21:41:23 UTC |
The Space Bears ransomware group claims to have stolen data from Comcast via a breach involving the Quasar remote access trojan. This incident involves ransomware coupled with data theft, indicating a potential double-extortion attack. Although technical details are limited and no confirmed exploits are reported, the threat is considered high severity due to the nature of the targeted organization and the potential impact of leaked sensitive data. European organizations, especially those in telecommunications and critical infrastructure sectors, could face indirect risks from similar tactics or supply chain impacts. Mitigation requires enhanced endpoint detection, network segmentation, and proactive threat hunting for RAT activity like Quasar. Countries with significant telecom infrastructure and Comcast business ties, such as the UK, Germany, and France, are more likely to be affected. The threat is assessed as high severity given the potential confidentiality breach, ease of exploitation via RATs, and the high-profile nature of the victim. Defenders should prioritize monitoring for ransomware indicators, securing remote access tools, and preparing incident response plans for data breach scenarios. Join the discussion | Reddit InfoSec News | 12/08/2025, 13:14:11 UTC Added: 12/08/2025, 13:26:40 UTC |
The Qilin ransomware group has claimed responsibility for a data theft incident targeting the Church of Scientology. This ransomware variant is associated with encrypting victim data and exfiltrating sensitive information to extort victims. Although the technical details and exploitation methods remain sparse, the attack highlights ongoing risks of ransomware combined with data theft. No confirmed exploits or vulnerabilities have been publicly disclosed yet. The threat is assessed as medium severity due to the potential confidentiality impact and extortion risk, but limited public technical details and minimal discussion reduce immediate exploitation concerns. European organizations with similar profiles or using related infrastructure should remain vigilant. Mitigation should focus on robust backup strategies, network segmentation, and monitoring for ransomware indicators. Countries with higher exposure to ransomware attacks and significant presence of targeted organizations, such as the UK, Germany, and France, are more likely to be affected. Overall, defenders must prioritize detection and response capabilities to mitigate potential ransomware and data theft incidents. Join the discussion | Reddit InfoSec News | 12/04/2025, 22:17:02 UTC Added: 12/04/2025, 22:22:18 UTC |
The Everest ransomware group claims to have breached ASUS, stealing approximately 1TB of data including camera source code. This incident involves data theft and ransomware activities, potentially exposing sensitive intellectual property and customer information. The breach reportedly includes remote code execution (RCE) capabilities exploited by the attackers. Although no CVSS score is assigned, the threat is assessed as high severity due to the scale of data theft, potential impact on confidentiality and integrity, and the ransomware nature of the attack. European organizations using ASUS products or related camera technologies could face indirect risks from this breach, including supply chain vulnerabilities and exposure to ransomware campaigns. Mitigation requires enhanced monitoring of ASUS-related infrastructure, strict access controls, and incident response readiness. Countries with significant ASUS market penetration and technology sectors, such as Germany, France, and the UK, are likely to be most affected. Defenders should prioritize detection of ransomware indicators, secure firmware and software updates, and prepare for potential secondary attacks leveraging stolen data. Join the discussion | Reddit InfoSec News | 12/02/2025, 18:15:30 UTC Added: 12/02/2025, 18:20:50 UTC |
The Everest ransomware group has claimed a significant breach of Spain’s national airline, Iberia, reportedly stealing 596 GB of data. This incident involves ransomware activity combined with data exfiltration, indicating a double-extortion tactic where attackers encrypt systems and threaten to leak stolen data. The breach highlights vulnerabilities in critical infrastructure sectors such as aviation, which are highly sensitive and impactful. Although no specific exploited vulnerabilities or affected software versions are disclosed, the attack's scale and target underscore a high-risk scenario. European organizations, especially in Spain and neighboring countries, face increased risks from similar ransomware operations targeting critical transport and infrastructure sectors. Mitigation requires tailored incident response plans, enhanced network segmentation, and proactive threat hunting focused on ransomware behaviors. Spain is the most directly affected country, but given Iberia's international operations, other European countries with strong aviation ties may also be at risk. The threat is assessed as high severity due to the large data theft, potential operational disruption, and the critical nature of the airline sector. Defenders must prioritize monitoring for ransomware indicators, securing remote access, and ensuring robust data backup and recovery capabilities. Join the discussion | Reddit InfoSec News | 11/25/2025, 17:14:51 UTC Added: 11/25/2025, 17:23:35 UTC |
Salesforce is investigating a data breach involving Gainsight, a customer success platform, which has resulted in the theft of customer data. The breach reportedly allowed unauthorized access potentially through a remote code execution (RCE) vulnerability, leading to exposure of sensitive information. Although no confirmed exploits are currently known in the wild, the incident is considered high severity due to the nature of the data involved and the trust placed in these platforms. European organizations using Salesforce and Gainsight services may face risks related to confidentiality breaches and regulatory compliance violations. Mitigation requires immediate review of third-party integrations, enhanced monitoring of access logs, and strict validation of vendor security postures. Countries with high adoption of Salesforce and cloud-based CRM solutions, such as the UK, Germany, France, and the Netherlands, are likely to be most affected. Given the breach involves data theft and potential RCE, the suggested severity is high. Defenders should prioritize incident response readiness, vendor communication, and data access audits to limit impact. Join the discussion | Reddit InfoSec News | 11/20/2025, 20:30:32 UTC Added: 11/20/2025, 20:33:04 UTC |
The Cline Bot AI Agent, a coding assistant tool, has been identified with vulnerabilities that could lead to unauthorized data theft and remote code execution. These flaws potentially allow attackers to access sensitive information processed by the bot and execute arbitrary code within the environment where the bot operates. Although no known exploits are currently active in the wild, the medium severity rating indicates a tangible risk that requires attention. The threat primarily concerns organizations using this AI coding assistant, especially those handling confidential or proprietary code. Mitigation involves restricting the bot's access to sensitive data, applying strict input validation, and monitoring for unusual activity. European organizations relying on AI coding tools should prioritize evaluating their exposure to this vulnerability. Countries with significant tech sectors and AI adoption, such as Germany, France, and the UK, are more likely to be impacted. Given the potential for data compromise and code execution without requiring user interaction, the threat severity is assessed as high. Immediate security reviews and hardening of AI agent deployments are recommended to prevent exploitation. Join the discussion | Reddit InfoSec News | 11/19/2025, 12:03:04 UTC Added: 11/19/2025, 12:11:47 UTC |
Eurofiber, a European telecommunications infrastructure provider, confirmed a cyberattack on November 13 involving unauthorized access, data theft, and an extortion attempt. The breach was publicly disclosed via a security news source and Reddit InfoSec community, highlighting the incident's recent and newsworthy nature. Although specific technical details about the attack vector or exploited vulnerabilities are not provided, the incident involves data exfiltration and extortion, indicating a ransomware or data leak scenario. No known exploits or patches are currently reported. The attack poses significant risks to confidentiality and potentially availability of Eurofiber's services. European organizations relying on Eurofiber's infrastructure could face service disruptions or data exposure. Mitigation requires enhanced monitoring, incident response readiness, and verification of supply chain security. Countries with high Eurofiber market presence and critical infrastructure dependency, such as the Netherlands, Belgium, and Germany, are most at risk. Given the high impact on confidentiality and extortion elements, the threat severity is assessed as high. Defenders should prioritize containment, forensic analysis, and communication strategies to mitigate reputational and operational damage. Join the discussion | Reddit InfoSec News | 11/19/2025, 11:04:52 UTC Added: 11/19/2025, 11:17:00 UTC |
GlobalLogic has disclosed a data breach resulting from a security incident involving Oracle, leading to the theft of personal data affecting approximately 10,000 GlobalLogic employees. The breach stems from an Oracle-related compromise, though specific technical details about the vulnerability or attack vector have not been publicly disclosed. This incident highlights risks associated with third-party software supply chain security and the potential exposure of sensitive employee information. European organizations with ties to GlobalLogic or using Oracle products should be alert to similar risks. The breach could lead to identity theft, phishing attacks, and reputational damage. Mitigation requires enhanced monitoring of Oracle environments, employee awareness training, and verification of third-party security postures. Countries with significant Oracle and GlobalLogic presence, such as the UK, Germany, France, and the Netherlands, are likely to be most impacted. Given the scale and sensitivity of the data theft, the severity is assessed as high. Defenders should prioritize incident response, data protection, and supply chain risk management to mitigate further exposure. Join the discussion | Reddit InfoSec News | 11/11/2025, 17:51:26 UTC Added: 11/11/2025, 17:56:12 UTC |
Showing 1 to 10 of 24 results