Incidents

228 incidents

2017-09
🇳🇵 Nepal
#Finance #FinancialGain
2017-09
🇰🇷 Korea, Republic of
#Travel #DataBreach #NetClient
2017-06
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain #DataBreach
2017-05
ZZZ, 🇷🇺 Russian Federation, 🇯🇵 Japan, 🇬🇧 United Kingdom, 🇫🇷 France, 🇰🇷 Korea, Republic of, 🇮🇳 India, 🇨🇳 China, 🇩🇪 Germany, 🇪🇸 Spain, 🇮🇩 Indonesia, 🇧🇷 Brazil, 🇺🇸 United States
#FinancialGain
2017-05
🇰🇷 Korea, Republic of
#Wateringhole #Finance
2017-04
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2017-03
🇰🇷 Korea, Republic of
#Finance #ATM #FinancialGain #DataBreach
2017-02
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2016-12
🇹🇷 Türkiye
#Finance #FinancialGain
2016-10
🇺🇾 Uruguay
#Wateringhole #Finance
2016-08
🇰🇷 Korea, Republic of
#DataBreach #Espionage #Defense
2016-07
🇳🇬 Nigeria
#Finance #SWIFT #FinancialGain
2017-09
Group-IB listed Nepal’s NIC Asia Bank among 2017–2018 SWIFT and local interbank transfer incidents in a broader set of Lazarus and Cobalt bank-theft activity. The available linked evidence supports a Nepal bank theft or attempt involving about $4.4 millio…
🇳🇵 Nepal
#Finance #FinancialGain
2017-09
Hanatour suffered a 2017 personal-data breach after an unidentified attacker compromised a NetClient server, distributed malware to work PCs and servers, gathered internal information, and used plaintext contractor credentials to access the security netwo…
🇰🇷 Korea, Republic of
#Travel #DataBreach #NetClient
2017-06
Bithumb disclosed that a 2017 hacking incident involving an employee personal PC exposed customer personal information, with later company reporting describing about 30,000 affected users and exposed names, email addresses, and phone numbers while stating…
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain #DataBreach
2017-05
The WannaCry ransomware attack (May 2017) was a global cryptoworm outbreak that exploited the leaked NSA-developed EternalBlue vulnerability in Microsoft Windows SMBv1, enabling it to self-propagate automatically across networks without user interaction; …
ZZZ, 🇷🇺 Russian Federation, 🇯🇵 Japan, 🇬🇧 United Kingdom, 🇫🇷 France, 🇰🇷 Korea, Republic of, 🇮🇳 India, 🇨🇳 China, 🇩🇪 Germany, 🇪🇸 Spain, 🇮🇩 Indonesia, 🇧🇷 Brazil, 🇺🇸 United States
#FinancialGain
2017-05
Operation GoldenAxe described suspected North Korean watering-hole activity from June 2016 to May 2017 that compromised more than ten South Korean organization websites tied to diplomacy, aviation, North Korea affairs, unification, parliament, labor, and …
🇰🇷 Korea, Republic of
#Wateringhole #Finance
2017-04
Yapizon was listed among South Korean cryptocurrency exchange hacking incidents in reporting on unauthorized withdrawals and unresolved investigations, with authorities emphasizing the difficulty of tracing thefts through decentralized and anonymous block…
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2017-03
Chongho Easycash/VANXATM involved cyber-enabled payment-card and ATM fraud in South Korea, with copied cards used for cash withdrawals and purchases after financial transaction information was stolen and distributed. Financial Security Institute’s Rifle r…
🇰🇷 Korea, Republic of
#Finance #ATM #FinancialGain #DataBreach
2017-02
In February 2017, about $7 million in virtual currency was stolen from South Korean cryptocurrency exchange Bithumb. UN Panel reporting later said Bithumb was attacked by DPRK cyber actors multiple times, with the first two attacks in February and July 20…
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2016-12
Group-IB's 2018 financial-sector threat reporting lists AkBank in Turkey as a December 2016 SWIFT theft attributed to Lazarus, with the loss shown as $4 million. The incident appears in the report's timeline of SWIFT and local interbank transfer attacks, …
🇹🇷 Türkiye
#Finance #FinancialGain
2016-10
Banco República/BROU was included in the same global banking watering-hole activity that used compromised financial-sector websites to target a small set of selected IP addresses belonging mostly to banks and related organizations. The linked analyses des…
🇺🇾 Uruguay
#Wateringhole #Finance
2016-10
The CNBV-related activity was part of a broader financial-sector watering-hole campaign in which compromised regulator and banking websites in Poland, Mexico, and Uruguay redirected selected visitors toward malicious infrastructure. Reporting connected th…
🇺🇾 Uruguay
#Wateringhole #Finance
2016-10
The KNF incident centered on a watering-hole compromise of the Polish Financial Supervision Authority website, where modified JavaScript redirected selected financial-sector visitors through sap.misapor[.]ch and eye-watch[.]in toward exploit and payload d…
🇵🇱 Poland
#Wateringhole #Finance
2016-08
DESERTWOLF involved a compromise of South Korean defense-network systems after attackers abused weaknesses in the military internet antivirus system and distributed malware through an internet antivirus relay server. Investigators found malware on defense…
🇰🇷 Korea, Republic of
#DataBreach #Espionage #Defense
2016-07
Union Bank of India appears in UN Panel reporting as part of a wider set of financial-institution and cryptocurrency-exchange incidents used to illustrate DPRK cyber-enabled theft and sanctions-evasion revenue generation. The linked evidence supports only…
🇮🇳 India
#Finance #SWIFT #FinancialGain
2016-07
The Nigerian Bank incident is listed among DPRK-linked BangSwift financial operations in broad U.S. indictment and UN sanctions reporting that described North Korean RGB-associated actors, including activity associated in security reporting with Lazarus G…
🇳🇬 Nigeria
#Finance #SWIFT #FinancialGain
2017-05
ZZZ, 🇷🇺 Russian Federation, 🇯🇵 Japan, 🇬🇧 United Kingdom, 🇫🇷 France, 🇰🇷 Korea, Republic of, 🇮🇳 India, 🇨🇳 China, 🇩🇪 Germany, 🇪🇸 Spain, 🇮🇩 Indonesia, 🇧🇷 Brazil, 🇺🇸 United States
#FinancialGain