A phishing-led compromise affecting close to six million guests, including passport numbers a passenger could never have declined to provide.
More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.
An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.
Princeton was compromised. The difference was what happened in the next twenty-four hours.
There is no version of “monitor your accounts” that helps somebody who has already taken the call.
Twenty-four hours is not an improvement on 102 days. It is a different regime.
The reached system is almost never the one the security programme was built around.
There is no packet to inspect and no domain to block. The output of the call is a legitimate action by an authorised person.
A wealth capacity assessment is an estimate of what somebody could afford, recorded about them, which they have never seen.
What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.
An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.
A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.
Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.
For most organisations, most of the time, the answer is a phishing email. The rest is what happens to those worth the effort.
A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.
No lookalike domain and no spoofed sender. The message came from a real colleague’s real account.
Once the seeds live in an account protected by the same identity, there is one factor wearing two names.
The blast radius was tiny because the targeting was precise, not because the access was limited.
The only demand in this database attaching a condition unrelated to payment. Nobody repeated it.
It held the information, had the means to publish, and every commercial reason not to.
The fallback kept the state running, and put a month of government correspondence in consumer mailboxes.
Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.
Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.
Voice phishing into identity providers, then leak-site extortion. Active since 2020.