Incidents

228 incidents

2021-05
🇺🇸 United States
#Healthcare #FinancialGain
2021-04
🇮🇳 India
#Cryptocurrency #FinancialGain
2020-11
🇰🇷 Korea, Republic of
#SupplyChain #Technology
2020-11
🇬🇧 United Kingdom
#Cryptocurrency #FinancialGain
2020-10
🇦🇷 Argentina, 🇧🇷 Brazil, 🇧🇩 Bangladesh, 🇧🇦 Bosnia and Herzegovina, 🇧🇬 Bulgaria, 🇨🇱 Chile, 🇨🇷 Costa Rica, 🇪🇨 Ecuador, 🇬🇭 Ghana, 🇮🇳 India, 🇮🇩 Indonesia, 🇯🇵 Japan, 🇯🇴 Jordan, 🇰🇪 Kenya, 🇰🇼 Kuwait, 🇲🇾 Malaysia, 🇲🇹 Malta, 🇲🇽 Mexico, 🇲🇿 Mozambique, 🇳🇵 Nepal, 🇳🇮 Nicaragua, 🇳🇬 Nigeria, 🇵🇰 Pakistan, 🇵🇦 Panama, 🇵🇪 Peru, 🇵🇭 Philippines, 🇸🇬 Singapore, 🇿🇦 South Africa, 🇰🇷 Korea, Republic of, 🇪🇸 Spain, 🇹🇼 Taiwan, 🇹🇿 Tanzania, United Republic of, 🇹🇬 Togo, 🇹🇷 Türkiye, 🇺🇬 Uganda, 🇺🇾 Uruguay, 🇻🇳 Viet Nam, 🇿🇲 Zambia
#Finance #FinancialGain
2020-10
🇪🇪 Estonia
#Cryptocurrency #FinancialGain
2020-09
🇸🇬 Singapore
#Cryptocurrency #FinancialGain
2020-09
🇩🇪 Germany
#Cryptocurrency #FinancialGain
2020-09
🇸🇰 Slovakia
#Cryptocurrency #FinancialGain
2020-08
🇨🇦 Canada
#Cryptocurrency #FinancialGain
2020-08
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2020-07
🇰🇷 Korea, Republic of
#Wateringhole #Healthcare #DataBreach
2020-02
🇮🇩 Indonesia
#Finance #FinancialGain
2021-05
A Kansas hospital was among the U.S. healthcare targets in the alleged Andariel conspiracy charged by the U.S. Justice Department, which linked North Korean national Rim Jong Hyok and co-conspirators to Maui ransomware attacks against hospitals and health…
🇺🇸 United States
#Healthcare #FinancialGain
2021-04
EasyFi lost about $6 million in stablecoins and roughly $53 million in EASY tokens after mnemonic keys tied to administrative transfer capability were compromised, with evidence pointing to a compromised machine and weak operational controls rather than a…
🇮🇳 India
#Cryptocurrency #FinancialGain
2020-11
Lazarus abused the WIZVERA VeraPort software distribution workflow used by South Korean government and banking sites, compromising supported websites and replacing legitimate bundled installers with malware. The attack relied on VeraPort accepting any val…
🇰🇷 Korea, Republic of
#SupplyChain #Technology
2020-11
Nexus Mutual founder Hugh Karp's wallet was drained of 370,000 NXM tokens, which were converted into wrapped NXM and sent through attacker-controlled Ethereum addresses. Later analysis included Nexus Mutual among cryptocurrency thefts traced to Lazarus Gr…
🇬🇧 United Kingdom
#Cryptocurrency #FinancialGain
2020-10
CISA, Treasury, FBI, and USCYBERCOM attributed FASTCash 2.0 ATM cash-out activity to North Korea's BeagleBoyz, a HIDDEN COBRA subset overlapping with Lazarus, APT38, Bluenoroff, and Stardust Chollima. The campaign targeted financial institutions and payme…
🇦🇷 Argentina, 🇧🇷 Brazil, 🇧🇩 Bangladesh, 🇧🇦 Bosnia and Herzegovina, 🇧🇬 Bulgaria, 🇨🇱 Chile, 🇨🇷 Costa Rica, 🇪🇨 Ecuador, 🇬🇭 Ghana, 🇮🇳 India, 🇮🇩 Indonesia, 🇯🇵 Japan, 🇯🇴 Jordan, 🇰🇪 Kenya, 🇰🇼 Kuwait, 🇲🇾 Malaysia, 🇲🇹 Malta, 🇲🇽 Mexico, 🇲🇿 Mozambique, 🇳🇵 Nepal, 🇳🇮 Nicaragua, 🇳🇬 Nigeria, 🇵🇰 Pakistan, 🇵🇦 Panama, 🇵🇪 Peru, 🇵🇭 Philippines, 🇸🇬 Singapore, 🇿🇦 South Africa, 🇰🇷 Korea, Republic of, 🇪🇸 Spain, 🇹🇼 Taiwan, 🇹🇿 Tanzania, United Republic of, 🇹🇬 Togo, 🇹🇷 Türkiye, 🇺🇬 Uganda, 🇺🇾 Uruguay, 🇻🇳 Viet Nam, 🇿🇲 Zambia
#Finance #FinancialGain
2020-10
CoinMetro was included among cryptocurrency hacks that ZachXBT traced to Lazarus Group, also described in the evidence as Bluenoroff or APT38, within a broader August 2020 to October 2023 laundering investigation. The linked evidence says the campaign aff…
🇪🇪 Estonia
#Cryptocurrency #FinancialGain
2020-09
KuCoin suffered a September 2020 exchange breach in which attackers gained access to hot-wallet private keys and stole cryptocurrency, with reported losses ranging from at least $150 million to roughly $275-$280 million. Chainalysis attributed the hack to…
🇸🇬 Singapore
#Cryptocurrency #FinancialGain
2020-09
Unibright reported unexpected token movements after unauthorized access led to calls against token lock-contract transfer functions targeting addresses tied to a company HD wallet. ZachXBT later included Unibright among cryptocurrency hacks traced to Laza…
🇩🇪 Germany
#Cryptocurrency #FinancialGain
2020-09
Slovakian cryptocurrency exchange Eterbase was compromised in September 2020, with attackers stealing about $5.4 million from six internet-connected hot wallets holding Bitcoin, Ethereum, XRP, Tezos, Algorand, and TRON. Reuters reported that Lazarus used …
🇸🇰 Slovakia
#Cryptocurrency #FinancialGain
2020-08
CoinBerry was described in linked evidence as a reported hot-wallet incident around 2020-08-24 in which approximately 8.33 BTC was allegedly taken, followed by a pause in withdrawals and later resumed use of the same wallet address. ZachXBT later included…
🇨🇦 Canada
#Cryptocurrency #FinancialGain
2020-08
ESRC linked an HDAC-themed cryptocurrency-wallet campaign to Thallium, describing Android and Windows components disguised as legitimate domestic wallet firmware or update software. The activity targeted wallet passcodes and used modified configurations o…
🇰🇷 Korea, Republic of
#Cryptocurrency #FinancialGain
2020-08
The U.S. Justice Department indictment described North Korean RGB-linked programmers, associated in security reporting with Lazarus Group and APT38, as conducting a long-running conspiracy involving destructive attacks, financial theft, extortion, and cry…
🇺🇸 United States
#Cryptocurrency #FinancialGain
2020-07
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence found the MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. The campaign used victim-specific spreading utilitie…
ZZZ
#FinancialGain
2020-07
The KAMS incident involved a malicious HWP document distributed through a notice associated with the Korea healthcare sector, with linked metadata classifying the activity as a watering-hole-style compromise and data-breach event. The available evidence s…
🇰🇷 Korea, Republic of
#Wateringhole #Healthcare #DataBreach
2020-02
Bank Rakyat Indonesia was reported to have been targeted by Lazarus in February 2020. Carnegie's financial-sector incident timeline says attackers likely gained access to the bank's networks using BEEFEATER, malware previously associated with the Banglade…
🇮🇩 Indonesia
#Finance #FinancialGain
2020-10
🇦🇷 Argentina, 🇧🇷 Brazil, 🇧🇩 Bangladesh, 🇧🇦 Bosnia and Herzegovina, 🇧🇬 Bulgaria, 🇨🇱 Chile, 🇨🇷 Costa Rica, 🇪🇨 Ecuador, 🇬🇭 Ghana, 🇮🇳 India, 🇮🇩 Indonesia, 🇯🇵 Japan, 🇯🇴 Jordan, 🇰🇪 Kenya, 🇰🇼 Kuwait, 🇲🇾 Malaysia, 🇲🇹 Malta, 🇲🇽 Mexico, 🇲🇿 Mozambique, 🇳🇵 Nepal, 🇳🇮 Nicaragua, 🇳🇬 Nigeria, 🇵🇰 Pakistan, 🇵🇦 Panama, 🇵🇪 Peru, 🇵🇭 Philippines, 🇸🇬 Singapore, 🇿🇦 South Africa, 🇰🇷 Korea, Republic of, 🇪🇸 Spain, 🇹🇼 Taiwan, 🇹🇿 Tanzania, United Republic of, 🇹🇬 Togo, 🇹🇷 Türkiye, 🇺🇬 Uganda, 🇺🇾 Uruguay, 🇻🇳 Viet Nam, 🇿🇲 Zambia
#Finance #FinancialGain