article thumbnail

U.S. authorities charged an Iranian national for long-running hacking campaign

Security Affairs

Nasab utilized the stolen identity of an actual individual to register a server and email accounts used in the attacks. “In addition to spearphishing, the conspirators utilized social engineering, which involved impersonating others, generally women, in order to obtain the confidence of victims. ” continues the DoJ.

Hacking 102
article thumbnail

A threat actor is selling access to Facebook and Instagram’s Police Portal

Security Affairs

Gal speculates that either Meta was the victim of a social engineered attack that tricked an employee into giving attackers access to the portal or the threat actor had credentials for a legitimate law enforcement account. ” Gal told Security Affairs. The access to the official META Law Enforcement Portal.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Don’t use AI-based apps, Philippine defense ordered its personnel

Security Affairs

The order remarks that these AI-based applications pose significant privacy and security risks. This seemingly harmless and amusing AI-powered application can be maliciously used to create fake profiles that can lead to identity theft, social engineering, phishing attacks and other malicious activities,” Teodoro said.

article thumbnail

Data Breach at Britain JD Sports leaks 10 million customers

CyberSecurity Insiders

Accessed information includes data related to phone numbers, email accounts, addresses, names, the location where the order was delivered, and the final 4 digits of bank cards. JD Sports has assured that hackers accessed no passwords related to their accounts and issued an apology for failing to protect the customer info.

article thumbnail

New LinkedIn breach exposes data of 700 Million users

Security Affairs

He claims the data was obtained by exploiting the LinkedIn API to harvest information that people upload to the site.” Data available for sale exposes 700+ million people at risk of cybercriminal activities, including identity theft, phishing and social engineering attacks, and account hijacking.

article thumbnail

Misconfigured WBSC server leaks thousands of passports

Security Affairs

According to the team, having passport data exposed puts individuals at risk of identity theft. Since passports contain a significant amount of personal information, including full names, date of birth, and a unique passport number, cyber criminals could use them to impersonate victims and steal their identities,” the team said.

article thumbnail

Saudi Ministry exposed sensitive data for 15 months

Security Affairs

With access to government SMTP credentials, attackers can impersonate government officials or employees to conduct social engineering attacks. They may attempt to deceive victims into disclosing additional sensitive information, perpetrating fraud, or gaining access to other systems or resources,” researchers said.