Over Security

Over Security

34848 bookmarks
Custom sorting
Interview #10 diencracked (BreachForums owner)
Interview #10 diencracked (BreachForums owner)
The following interview, which we publish in full, was conducted in May 2026 by me, fastfire. "BreachForums" (often referred to as "Breached") is an English-language cybercriminal forum. It functioned as a clear-net marketplace and platform for threat actors to trade stolen databases, tools, access credentials, and other illicit services. A few days ago, the forum
·deepdarkcti.com·
Interview #10 diencracked (BreachForums owner)
The Metric to Anchor Your Agentic SOC Evaluation On
The Metric to Anchor Your Agentic SOC Evaluation On
There's one question that, once it anchors how we evaluate these products, makes the difference between picking a triage tool and picking a detection partner. The global median dwell time, days from first attacker foothold to the moment someone noticed, came in at 14 days. Triage speed doesn't close it. The IBM 2025 Cost of a Data Breach Report puts mean time to identify at around 181 days globally, down from 194 the year before. But the directional signal is consistent: detection completeness is where the next layer of value lives. Dwell time is the metric. Days from foothold to detection. What we measure today, what we don't measure yet The agentic-SOC category has standardized on a set of performance metrics that are easy to measure cleanly: per-ticket investigation time, alert closure rate, response latency on already-detected incidents. That's a different kind of measurement than triage speed, and it's the one the category hasn't fully built out yet. Here's the distinction, side by side: Metric category What it measures What it tells you about the product Triage-speed metrics (broadly available) How fast the system processes alerts that already fired How efficient your SOC becomes at handling known signal Detection-completeness metrics (still maturing) Whether the system surfaces threats it didn't already have a rule for Whether the product is meaningfully shortening attacker dwell time Both matter. That said, there's a meaningful distinction between triage speed and detection completeness, and understanding it helps you get full value from the agentic wave. The way to make sure the right 60% survives is to measure outcomes that map to the actual threat: how many days did the attacker have before detection, and did that number go down? Here's the question to anchor on: "Show me your customers' median dwell time before deployment and after. Dwell time." Pay attention to what happens next. If they pivot to triage speed, they're likely early on the measurement maturity curve, which is where most of the category is right now. If they say "dwell time is a lagging indicator that's hard to attribute to a single tool," they're being honest about a genuinely hard problem. Products built around that metric are the ones most likely to deliver on what this category can genuinely do: meaningfully shorten the time between an attacker's first move and the moment someone stops them.
·binarydefense.com·
The Metric to Anchor Your Agentic SOC Evaluation On
Interview #9 MedusaLocker
Interview #9 MedusaLocker
The following interview, which we publish in full, was conducted in May 2026 by Erez, a member of the deepdarkCTI community. The MedusaLocker ransomware gang is a persistent cybercriminal operation first observed in late 2019. It operates primarily as a Ransomware-as-a-Service (RaaS) model, where developers provide the malware to affiliates in exchange for a percentage
·deepdarkcti.com·
Interview #9 MedusaLocker
Interview #10 diencracked (BreachForums owner)
Interview #10 diencracked (BreachForums owner)
The following interview, which we publish in full, was conducted in May 2026 by me, fastfire. "BreachForums" (often referred to as "Breached") is an English-language cybercriminal forum. It functioned as a clear-net marketplace and platform for threat actors to trade stolen databases, tools, access credentials, and other illicit services. A few days ago, the forum
·deepdarkcti.com·
Interview #10 diencracked (BreachForums owner)
Carnival - 7,531,359 breached accounts
Carnival - 7,531,359 breached accounts
In April 2026, the notorious hacking collective ShinyHunters claimed they had obtained a substantial volume of data belonging to the Carnival cruise operator and attempted to extort the organisation to prevent the data from being leaked. The following week, the group published the data publicly, which contained 8.7M records with 7.5M unique email addresses. The data contained fields indicating it related to the Mariner Society loyalty program run by Holland America, a cruise line brand under Carnival, and included names, dates of birth, genders and data relating to status within the loyalty program. Carnival acknowledged a phishing incident involving a single user account and advised they were working to better understand the scope of the unauthorised activity.
·haveibeenpwned.com·
Carnival - 7,531,359 breached accounts
Udemy - 1,401,259 breached accounts
Udemy - 1,401,259 breached accounts
In April 2026, online training company Udemy was the victim of a “pay or leak” extortion attempt perpetrated by the ShinyHunters group. The data was subsequently leaked publicly and contained 1.4M unique email addresses belonging to customers and instructors. The data also included names, physical addresses, phone numbers, employer information and instructor payout methods including PayPal, cheque and bank transfer.
·haveibeenpwned.com·
Udemy - 1,401,259 breached accounts
ADT - 5,488,888 breached accounts
ADT - 5,488,888 breached accounts
In April 2026, home security firm ADT confirmed a data breach by ShinyHunters, which listed the company on its website as part of a "pay or leak" extortion attempt. The breach impacted 5.5M unique email addresses along with names, phone numbers and physical addresses. ADT also advised that "in a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included" and that it had contacted all affected people.
·haveibeenpwned.com·
ADT - 5,488,888 breached accounts
Pitney Bowes - 8,243,989 breached accounts
Pitney Bowes - 8,243,989 breached accounts
In April 2026, the hacking collective ShinyHunters claimed to have obtained data from Pitney Bowes as part of a broader extortion campaign that also named several other organisations. After negotiations allegedly failed, the group publicly released the data which included 8.2M unique email addresses, along with names, phone numbers and physical addresses. A subset of the data also included Pitney Bowes employee records with job titles.
·haveibeenpwned.com·
Pitney Bowes - 8,243,989 breached accounts
Aman - 215,563 breached accounts
Aman - 215,563 breached accounts
In April 2026, the ultra-luxury hotel brand Aman was named by ShinyHunters as the target of a "pay or leak" extortion campaign, with the data allegedly obtained from their Salesforce CRM. The data was subsequently leaked publicly and contained over 200k unique email addresses. Whilst not present on all records, the data also included genders, physical addresses, phone numbers, nationalities, dates of birth, spouse names and VIP status codes.
·haveibeenpwned.com·
Aman - 215,563 breached accounts
ZenBusiness - 5,118,184 breached accounts
ZenBusiness - 5,118,184 breached accounts
In March 2026, the hacker and extortion group "ShinyHunters" claimed to have obtained a substantial corpus of data from ZenBusiness, a business formation and compliance platform. The group claimed the data had been exfiltrated from platforms including Snowflake, Mixpanel and Salesforce, and threatened to publish it if a ransom was not paid. The following month, after claiming payment had not been made, ShinyHunters publicly released the data. The collection amounted to many terabytes across thousands of files that appeared to originate from multiple systems and business functions, including leads, support records and other CRM-related data. The data contained approximately 5M unique email addresses, often accompanied by name and phone number depending on the source file.
·haveibeenpwned.com·
ZenBusiness - 5,118,184 breached accounts
Marcus & Millichap - 1,837,078 breached accounts
Marcus & Millichap - 1,837,078 breached accounts
In April 2026, the commercial real estate brokerage firm Marcus & Millichap was named as one of multiple alleged victims of the ShinyHunters hacking and extortion group. Data alleged to have been obtained from the company was subsequently released publicly and included 1.8M unique email addresses, along with names, phone numbers and employment-related information including employer, job title and physical company address. In their disclosure notice, Marcus & Millichap advised that data which may have been accessed appeared limited to "company forms, templates, marketing materials, and general contact information".
·haveibeenpwned.com·
Marcus & Millichap - 1,837,078 breached accounts
Reborn Gaming - 126 breached accounts
Reborn Gaming - 126 breached accounts
In April 2026, the gaming community Reborn Gaming suffered a data breach due to a vulnerability in cPanel and WebHost Manager (WHM). The breach exposed 126 unique email addresses along with IP addresses and Steam IDs. Reborn Gaming self-submitted the data to Have I Been Pwned.
·haveibeenpwned.com·
Reborn Gaming - 126 breached accounts
Vimeo - 119,167 breached accounts
Vimeo - 119,167 breached accounts
In April 2026, the ShinyHunters extortion group listed Vimeo on their extortion portal as part of their "pay or leak" campaign. They subsequently published hundreds of gigabytes of data, predominantly consisting of video titles, technical data and metadata. The data also included 119k unique email addresses, sometimes accompanied by names. Vimeo attributed the exposure to a breach of Anodot, a third-party analytics vendor, and advised the incident does not include "Vimeo video content, valid user login credentials, or payment card information".
·haveibeenpwned.com·
Vimeo - 119,167 breached accounts
LegionProxy - 10,144 breached accounts
LegionProxy - 10,144 breached accounts
In April 2026, the commercial residential and ISP proxy network LegionProxy suffered a data breach. The incident exposed 10k email addresses, bcrypt password hashes, names and purchases.
·haveibeenpwned.com·
LegionProxy - 10,144 breached accounts
Woflow - 447,593 breached accounts
Woflow - 447,593 breached accounts
In March 2026, the AI-driven merchant data platform Woflow was named as a victim by the ShinyHunters data extortion group. The group subsequently published tens of thousands of files allegedly obtained from the company, comprising more than 2TB of data. The trove included hundreds of thousands of email addresses, names, phone numbers and physical addresses, with the data indicating it related to Woflow customers and, in turn, the customers of merchants using their platform.
·haveibeenpwned.com·
Woflow - 447,593 breached accounts
Zara - 197,376 breached accounts
Zara - 197,376 breached accounts
In April 2026, the fashion brand Zara was among a number of organisations targeted by the ShinyHunters extortion group as part of their "pay or leak" campaign. The group claimed the breach was related to a compromise of the Anodot analytics platform and subsequently published a terabyte of data allegedly including 95M support ticket records. The data contained 197k unique email addresses alongside product SKUs, order IDs and the market the support ticket originated in. Zara's parent company Inditex advised that the incident didn't affect passwords or payment information.
·haveibeenpwned.com·
Zara - 197,376 breached accounts
Cushman & Wakefield - 310,431 breached accounts
Cushman & Wakefield - 310,431 breached accounts
In May 2026, the real estate services firm Cushman & Wakefield was the target of a "pay or leak" extortion campaign by the ShinyHunters group. Following the threat, the group publicly published data they alleged had been obtained from the firm, consisting mostly of C&W email addresses along with tens of thousands of external email addresses and corporate contact records. The exposed data was primarily business information, including names, job titles, company addresses and phone numbers.
·haveibeenpwned.com·
Cushman & Wakefield - 310,431 breached accounts
Canada Life - 237,810 breached accounts
Canada Life - 237,810 breached accounts
In April 2026, Canada Life was the victim of a "pay or leak" extortion campaign by the ShinyHunters group. The group subsequently published the data which contained over 200k unique email addresses along with names, phone numbers, physical addresses and, in some cases, customer support tickets. In their disclosure notice, Canada Life advised that "it is a small proportion of our customers who may have been impacted". In the wake of the incident, Canada Life also published an alert cautioning customers to be wary of phishing attacks, a pattern often seen after the public release of breached data.
·haveibeenpwned.com·
Canada Life - 237,810 breached accounts
Abrigo - 711,099 breached accounts
Abrigo - 711,099 breached accounts
In April 2026, the fintech software company Abrigo was targeted in a "pay or leak" extortion attempt by the ShinyHunters group. Shortly after, data allegedly taken from the company's Salesforce instance was published publicly and contained over 700k unique email addresses belonging to both Abrigo staff and external contacts. Whilst separate from Abrigo's Salesforce compromise via the Drift application connector the previous year, the data fields described in that incident are consistent with the ShinyHunters data, namely that it was "business contact information" including "institution name, employee name, email addresses, and phone numbers".
·haveibeenpwned.com·
Abrigo - 711,099 breached accounts
18-year-old NGINX vulnerability allows DoS, potential RCE
18-year-old NGINX vulnerability allows DoS, potential RCE
An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.
·bleepingcomputer.com·
18-year-old NGINX vulnerability allows DoS, potential RCE