
Loading summary
A
Hotel wifi hijacked to steal Microsoft 365 accounts six years in prison for the man who fished women's accounts sextortion scammers are borrowing a famous breach gang's name, ransomware freezes a Japanese food giant and Chick Fil A gets stuffed again, then apologizes in chicken this is Cybersecurity today and I'm your host David Shipley. Lets get started. ReliaQuest published research on Thursday on a campaign turning hotel and conference wi fi into credential harvesting infrastructure. The game is to take over the captive portal gateways and own DNS for every guest. From there they forge responses and Anyone reaching for Microsoft 365 lands on a lookalike instead of the real thing. This attack didn't have a phishing email. The There was no malicious attachment and nothing touched the endpoint. Researchers found compromise gateways across multiple US Cities, plus India and Saudi Arabia, and they've been active since at least June. Victim traffic spanned finance, legal, healthcare, energy, and retail. This wasn't a sector specific targeted campaign it just went after traveling employees wherever they connected. Some got more than just a captive portal. The attackers paired the redirected login page with Microsoft's device code flow. If the user authorized it, it handed over a valid OAuth token for the attacker to start a valid session. MFA wouldn't have stopped this attack. Attackers could capture and relay MFA requests. ReliaQuest sees tradecraft overlap with APT28 in this attack, but but stop short of specific attribution. This whole campaign highlights the risks of telling people not to worry about certain cybersecurity issues. November's Hacker Lore Letter, signed by more than 100 prominent cybersecurity leaders, told people to retire avoid public WI fi as good advice. Their argument was encryption protects traffic on open networks and browsers will warn you about untrusted connections. In this case, it wasn't about the encryption. It didn't matter. Nobody attacked the encrypted tunnel. They attacked the DNS address book, and no browser would have warned anyone in this attack. The certificates on those fake login pages were valid, but they were valid for the attacker domains. I've been critical of hackerlore since it came out in November, particularly the bad advice on public WI fi and QR codes. I'm not holding my breath for a correction on hacker lore. ReliaQuest's own remediation advice tells organizations to train employees to be careful about Hotel Wi Fi and to make sure they're paying attention to URLs, VPNs still matter and are good practice for individuals, SMBs and enterprise. Staying vigilant about public WI fi still matters, as does staying vigilant about QR codes. Technology controls have improved when it comes to cybersecurity, but it doesn't mean you don't need to be careful. That's the whole message around awareness. An Illinois man was sentenced Tuesday to 76 months in prison, six years and four months plus three years of supervised release for fishing his way into the Snapchat accounts of more than 750 women. Bleeping Computer reports that Kyle Svara, 26, was charged in December and admitted to crimes in February. Between May 2020 and February 2021, he approached more than 4,500 victims posing as a SNAP representative and contacting them from anonymized numbers, trying to talk them into handing over their account access codes. He got into roughly 517 accounts and downloaded nude and semi nude photos. Then he switched on two factor authentication, locking each woman out of her own account on the way out the door. Investigators found about 530 images and 600 videos, including child sex abuse material in his Mega account. Asked about all of it, he told them he knew nothing about hacking Snapchat and had no interest in that material. Justice Department filings say he collected, distributed and solicited it. This was a business he advertised online, offered to get into accounts on request, pointed prospective clients to kick and traded and sold what he took. One of his clients was Steve Waithe, then a track and field coach at Northeastern University, who hired him to get into the accounts belonging to Northeastern students and members of the women's track and soccer teams. Waithe was convicted of targeting at least 128 women and taking thousands of explicit photos from more than 100 of them. He got five years in prison in March 2024. Between paid jobs, Zavarra continued his criminal campaign in Plainfield, Illinois, all on his own. He targeted neighbors, family, friends, classmates, his own friends and students at Colby College in Maine. This is why it's so important to continue to educate people about online crimes, both at work and at home. There's a sextortion campaign running on the back of Shiny Hunters leaks. The emails claim Shiny Hunters got into the recipients devices months ago, named the breach their address came from and demand $2,000 in Bitcoin inside 48 hours. The emails contain the standard sextortion threat that the attackers had somehow turned on cameras, microphones, had recorded screenshots, keystrokes and that they had the victim's contact list and threatened to send intimate videos to families and colleagues. None of it was real. Knowing an email address was in a breach doesn't get you onto full control of a device. The details about Shiny Hunter breaches that they're using, though, are real. Bleeping Computer confirmed addresses hid in the campaign genuinely appeared in the leaked data. That email Amtrak Hallmark substack, Betterment, CarGurus, ADT, Panera Bread, McGraw Hill Shiny Hunters told Bleeping Computer they had nothing to do with this extortion campaign, and the irony is not lost here. An extortion gang is doing brand protection. This extortion campaign started in April. Betterment has already gone public, telling clients to delete the emails and not to pay. Extortion crews like Shiny Hunters routinely warn companies that refusing to pay puts their customers at risk once the data goes out. Here, that promise was kept by someone else entirely. Sextortion mail cleared over $50,000 a week when it first showed up in 2018, and even though less than a fraction of a percentage point of recipients respond, attackers still reap millions. It's vital we keep educating people about these scams, and as IT professionals and cybersecurity experts, we continue to show up with empathy when people reach out after receiving one of these notes. Nichiri, a Japanese frozen food supplier and logistics operator, is recovering from a ransomware attack that cut shipments and and left Kentucky Fried Chicken franchises across Japan warning of shortages and shortened hours. Nichiri has about 5,000 customers and roughly 7,000 refrigerated vehicles running out of 141 logistics centers and warehouses. Ransom House, a newer Russia linked crew known for double extortion reportedly claimed credit and posted some Nishiri data. The company has confirmed personal data was stolen and and Japanese media reported a subset is already online. Nishri severed its internal networks in response. That's the textbook move when encryption or lateral movement is running. But it's also the move that empties shelves in a just in time chain built with almost no buffer inventory. In a July 22 statement, the Japanese company said all locations should be back to normal within the week and that it won't discuss specifics while it coordinates its response with police. We covered another ransomware attack on the food supply chain last week with the hit on Coca Cola's fairlife dairy unit last Monday. That attack resulted in production being suspended in Michigan after it was ransomware. We've also seen other hits on the food sector. British Grocery learned some of these same harsh lessons at scale after scattered spider attacks. Marks and Spencer Co op were hit in 2025, resulting in bare shelves and grocery stores tracking stock on paper. Marks and Spencer put the operating profit hit at 300 million pounds. The co op landed at 120 million for the year. Plus data on all 6.5 million members was leaked. Another Japanese food producer, beer maker asai, was hit by the Killin gang last October. It didn't finish rebuilding until February. The Ag Food ISAC says it's had more than 200 cyber incidents so far this year, and it looks like the trend on attacks on food aren't going anywhere anytime soon. Chick Fil? A confirmed Friday that credential stuffing hit its website and mobile app between June 17th and 19th, exposing data on 13,322 people. The company spotted suspicious logins to its chick fil A1 loyalty accounts. Attackers ran automated tools against them using credentials the company describes as obtained from a third party source. That's the polite way of saying its customers may have reused passwords that leaked from somewhere else. What came out Names, email addresses, membership numbers, loyalty balances, mobile pay numbers and the last four digits of the card on file. Birth dates, phone numbers and addresses too. Whenever customers had provided them, Chick Fil? A logged out every affected account, stripped the save payment methods, restored the loyalty balances and told affected customers to change their passwords. It also added rewards to the affected accounts as an apology. So instead of the typical 12 months of credit monitoring, which is the standard Cyber Band Aid, 13,000 people are getting free chicken. Honestly, it's probably an upgrade. That's not to say there's no value in credit monitoring. It's just people should have had that before the breach. So getting more credit monitoring on top of what you will probably already have from a number of other breaches isn't really going to do much for you. At least for those affected by this breach, they get a free meal. Chick Fil? A has been here before. In March 2023, the company disclosed a nearly identical campaign. Automated logins targeting loyalty accounts and credentials were used, likely from somewhere else, running from December 2022 through February 2023. That one hit 71,000 customers. Unique passwords, a password manager to hold them, passkeys where you can, and MFA on anything that matters are all sound advice. And this breach is the bill for ignoring that kind of advice. And that's Cybersecurity today for Monday, July 27, 2020 26. I've been your host, David Shipley. Thanks for listening. We appreciate all of your feedback. Feel free to reach out to us@technewsday.com or CA. Or you can leave a comment under the YouTube video I'm recording this week from Cambridge, Massachusetts, where I'm at the Harvard Kennedy School for their executive education program on cybersecurity and public policy. I'll be headed to Las Vegas next week to cover Black Hat and defcon. I'll be back on Wednesday with the latest headlines. Until then, I hope you have a great week and stay safe.
Host: David Shipley
Episode Highlights: Hotel Wi-Fi Hijacking, Sextortion Scams, Global Food Logistics Ransomware, Chick-fil-A Credential Stuffing
This episode of Cybersecurity Today covers a range of recent cybersecurity threats impacting businesses globally. The host, David Shipley, unpacks the details behind a sophisticated hotel Wi-Fi hijack campaign targeting Microsoft 365 users, a sextortion campaign leveraging old data breach names, a major ransomware attack on a Japanese food logistics company, and yet another credential stuffing incident at Chick-fil-A. The episode stresses the ongoing importance of maintaining vigilance in security practices, both organizationally and personally.
Timestamps:
Timestamps:
Timestamps:
Timestamps:
Timestamps:
Next Episode:
David Shipley will report from Las Vegas during Black Hat and DEFCON with more cybersecurity headlines and analysis.