Email – INDIA NEWS https://www.indiavpn.org News Blog Wed, 20 Mar 2024 08:25:30 +0000 en-US hourly 1 https://wordpress.org/?v=6.7 Ukraine Arrests Trio for Hijacking Over 100 Million Email and Instagram Accounts https://www.indiavpn.org/2024/03/20/ukraine-arrests-trio-for-hijacking-over-100-million-email-and-instagram-accounts/ https://www.indiavpn.org/2024/03/20/ukraine-arrests-trio-for-hijacking-over-100-million-email-and-instagram-accounts/#respond Wed, 20 Mar 2024 08:25:30 +0000 https://www.indiavpn.org/2024/03/20/ukraine-arrests-trio-for-hijacking-over-100-million-email-and-instagram-accounts/ [ad_1]

Mar 20, 2024NewsroomCybercrime / Dark Web

Hacking Email and Instagram Accounts

The Cyber Police of Ukraine has arrested three individuals on suspicion of hijacking more than 100 million emails and Instagram accounts from users across the world.

The suspects, aged between 20 and 40, are said to be part of an organized criminal group living in different parts of the country. If convicted, they face up to 15 years in prison.

The accounts, authorities said, were taken over by carrying out brute-force attacks, which employ trial-and-error methods to guess login credentials. The group operated under the direction of a leader, who distributed the hacking tasks to other members.

Cybersecurity

The cybercrime group subsequently monetized their ill-gotten credentials by putting them up for sale on dark web forums.

Other threat actors who purchased the information used the compromised accounts to conduct a variety of fraudulent schemes, including those in which scammers reach out to the victim’s friends to urgently transfer money to their bank account.

“You can protect your account from this method of hacking by setting up two-factor authentication and using strong passwords,” the agency said.

As part of the operation, officials conducted seven searches in Kyiv, Odesa, Vinnytsia, Ivano-Frankivsk, Donetsk, and Kirovohrad, confiscating 70 computers, 14 phones, bank cards, and cash worth more than $3,000.

The development comes as a U.S. national pleaded guilty to breaching over a dozen entities in the U.S., including a medical clinic in Griffin, and exfiltrating the personal information of more than 132,000 individuals. He is scheduled for sentencing on June 18, 2024.

Robert Purbeck (aka Lifelock or Studmaster) “aggravated his crimes by weaponizing sensitive data in an egregious attempt to extort his victims,” U.S. Attorney Ryan K. Buchanan said.

Cybersecurity

According to the U.S. Department of Justice (DoJ), Purbeck, who pleaded guilty today to federal charges of computer fraud and abuse, purchased access to the clinic’s computer server from the darknet in 2017, leveraging it to siphon medical records and other documents that contained data pertaining to over 43,000 individuals, such as names, addresses, birthdates, and social security numbers.

The defendant also bought credentials associated with the City of Newnan, Georgia, Police Department server on an underground marketplace. He then plundered records consisting of police reports and documents that had information belonging to no less than 14,000 people.

As part of the plea agreement, Purbeck agreed to pay more than $1 million in restitution to the impacted 19 victims. He was indicted by a federal jury in March 2021.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
https://www.indiavpn.org/2024/03/20/ukraine-arrests-trio-for-hijacking-over-100-million-email-and-instagram-accounts/feed/ 0
Alert: CISA Warns of Active ‘Roundcube’ Email Attacks https://www.indiavpn.org/2024/02/13/alert-cisa-warns-of-active-roundcube-email-attacks/ https://www.indiavpn.org/2024/02/13/alert-cisa-warns-of-active-roundcube-email-attacks/#respond Tue, 13 Feb 2024 05:25:33 +0000 https://www.indiavpn.org/2024/02/13/alert-cisa-warns-of-active-roundcube-email-attacks/ [ad_1]

Feb 13, 2024NewsroomVulnerability / Email Security

Email Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Roundcube email software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The issue, tracked as CVE-2023-43770 (CVSS score: 6.1), relates to a cross-site scripting (XSS) flaw that stems from the handling of linkrefs in plain text messages.

“Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages,” CISA said.

Cybersecurity

According to a description of the bug on NIST’s National Vulnerability Database (NVD), the vulnerability impacts Roundcube versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3.

The flaw was addressed by Roundcube maintainers with version 1.6.3, which was released on September 15, 2023. Zscaler security researcher Niraj Shivtarkar has been credited with discovering and reporting the vulnerability.

It’s currently not known how the vulnerability is being exploited in the wild, but flaws in the web-based email client have been weaponized by Russia-linked threat actors like APT28 and Winter Vivern last year.

U.S. Federal Civilian Executive Branch (FCEB) agencies have been mandated to apply vendor-provided fixes by March 4, 2024, to secure their networks against potential threats.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
https://www.indiavpn.org/2024/02/13/alert-cisa-warns-of-active-roundcube-email-attacks/feed/ 0