Category: Krebs On Security

  • ICANN Launches Service to Help With WHOIS Lookups

    ICANN Launches Service to Help With WHOIS Lookups

    More than five years after domain name registrars started redacting personal data from all public domain registration records, the non-profit organization overseeing the domain industry has introduced a centralized online service designed to make it easier for researchers, law enforcement and others to request the information directly from registrars. In May 2018, the Internet Corporation…

  • Okta: Breach Affected All Customer Support Users

    Okta: Breach Affected All Customer Support Users

    When KrebsOnSecurity broke the news on Oct. 20, 2023 that identity and authentication giant Okta had suffered a breach in its customer support department, Okta said the intrusion allowed hackers to steal sensitive data from fewer than one percent of its 18,000+ customers. But today, Okta revised that impact statement, saying the attackers also stole…

  • ID Theft Service Resold Access to USInfoSearch Data

    ID Theft Service Resold Access to USInfoSearch Data

    One of the cybercrime underground’s more active sellers of Social Security numbers, background and credit reports has been pulling data from hacked accounts at the U.S. consumer data broker USinfoSearch, KrebsOnSecurity has learned. Since at least February 2023, a service advertised on Telegram called USiSLookups has operated an automated bot that allows anyone to look…

  • Alleged Extortioner of Psychotherapy Patients Faces Trial

    Alleged Extortioner of Psychotherapy Patients Faces Trial

    Prosecutors in Finland this week commenced their criminal trial against Julius Kivimäki, a 26-year-old Finnish man charged with extorting a once popular and now-bankrupt online psychotherapy practice and thousands of its patients. In a 2,200-page report, Finnish authorities laid out how they connected the extortion spree to Kivimäki, a notorious hacker who was convicted in…

  • Microsoft Patch Tuesday, November 2023 Edition

    Microsoft Patch Tuesday, November 2023 Edition

    Microsoft today released updates to fix more than five dozen security holes in its Windows operating systems and related software, including three “zero day” vulnerabilities that Microsoft warns are already being exploited in active attacks. The zero-day threats targeting Microsoft this month include CVE-2023-36025, a weakness that allows malicious content to bypass the Windows SmartScreen…

  • It’s Still Easy for Anyone to Become You at Experian

    It’s Still Easy for Anyone to Become You at Experian

    In the summer of 2022, KrebsOnSecurity documented the plight of several readers who had their accounts at big-three consumer credit reporting bureau Experian hijacked after identity thieves simply re-registered the accounts using a different email address. Sixteen months later, Experian clearly has not addressed this gaping lack of security. I know that because my account…

  • Who’s Behind the SWAT USA Reshipping Service?

    Who’s Behind the SWAT USA Reshipping Service?

    Last week, KrebsOnSecurity broke the news that one of the largest cybercrime services for laundering stolen merchandise was hacked recently, exposing its internal operations, finances and organizational structure. In today’s Part II, we’ll examine clues about the real-life identity of “Fearless,” the nickname chosen by the proprietor of the SWAT USA Drops service. Based in…

  • Russian Reshipping Service ‘SWAT USA Drop’ Exposed

    Russian Reshipping Service ‘SWAT USA Drop’ Exposed

    The login page for the criminal reshipping service SWAT USA Drop. One of the largest cybercrime services for laundering stolen merchandise was hacked recently, exposing its internal operations, finances and organizational structure. Here’s a closer look at the Russia-based SWAT USA Drop Service, which currently employs more than 1,200 people across the United States who…

  • .US Harbors Prolific Malicious Link Shortening Service

    .US Harbors Prolific Malicious Link Shortening Service

    The top-level domain for the United States — .US — is home to thousands of newly-registered domains tied to a malicious link shortening service that facilitates malware and phishing scams, new research suggests. The findings come close on the heels of a report that identified .US domains as among the most prevalent in phishing attacks…

  • NJ Man Hired Online to Firebomb, Shoot at Homes Gets 13 Years in Prison

    NJ Man Hired Online to Firebomb, Shoot at Homes Gets 13 Years in Prison

    A 22-year-old New Jersey man has been sentenced to more than 13 years in prison for participating in a firebombing and a shooting at homes in Pennsylvania last year. Patrick McGovern-Allen was the subject of a Sept. 4, 2022 story here about the emergence of “violence-as-a-service” offerings, where random people from the Internet hire themselves…

  • Okta: Breach Affected All Customer Support Users

    Hackers Stole Access Tokens from Okta’s Support Unit

    Okta, a company that provides identity tools like multi-factor authentication and single sign-on to thousands of businesses, has suffered a security breach involving a compromise of its customer support unit, KrebsOnSecurity has learned. Okta says the incident affected a “very small number” of customers, however it appears the hackers responsible had access to Okta’s support…

  • The Fake Browser Update Scam Gets a Makeover

    The Fake Browser Update Scam Gets a Makeover

    One of the oldest malware tricks in the book — hacked websites claiming visitors need to update their Web browser before they can view any content — has roared back to life in the past few months. New research shows the attackers behind one such scheme have developed an ingenious way of keeping their malware…