ZeroHour

Source: The Record

10 stories in the last 7d

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

US Coast Guard and FBI boarded an oil tanker after foreign hackers compromised its network; VL Prosperity reportedly lost communications for 30 hours.

The US Coast Guard confirmed that a specialized team including USCG Cyber Protection Team members and FBI Cyber Action Team operators boarded a tanker on August 21 after indications its network was compromised by foreign cyber actors. Bloomberg identified one vessel as VL Prosperity; Iranian state-linked outlet Mehr reported it lost communications for 30 hours after an August 7 attack while transiting the Strait of Gibraltar, with a crew member alleging attackers increased engine speed and disabled fuel and engine-oil tanks. No operational disruptions or environmental impacts were reported, no group has claimed responsibility, and Russian analysts linked the incident to US-Iran tensions. A day before the alleged attack, North Carolina Ports reported a cyberattack that forced a shift to manual operations.

The Record · 15h agoData breach in the wild 2 sources

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

ShinyHunters breached Florida's DMV using credentials stolen from a police officer's personal device; the state confirmed the breach and is investigating.

Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach after ShinyHunters obtained DMV data using credentials a criminal actor took from a Plant City police officer's personal electronic device. The department learned of the breach on September 4, is investigating with the Florida Digital Service, and ShinyHunters shared a DMV record of Jeffrey Epstein as proof of access. Experts initially speculated a link to the IDScan breach of 153 million driver's licenses. Anthropic reported that suspected ShinyHunters affiliates use AI to scan credentials, map systems, and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours.

The Recordupdated · 15h agofirst · 5d agoData breach in the wild 3 sources

Anthropic caught Russia-linked spies using Claude in hacking operations

Anthropic disrupted Russia-linked APT29 using Claude in espionage against 20+ organizations, including Ukrainian government targets and a military drone maker whose vision SDK was stolen.

Anthropic's threat report covering December 2025 to August 2026 attributes the campaign to Midnight Blizzard (APT29/Cozy Bear, Storm-2945), which it links to Russia's SVR. The group compromised hotel Wi-Fi providers, altered DNS records to redirect travelers, accessed mailboxes at two drone-component manufacturers, and stole a proprietary SDK for a drone vision system, which it reverse-engineered using Claude. The group also used Claude to monitor whether security products detected its implants and to modify and redeploy flagged artifacts. The report also covers ShinyHunters affiliates using AI for credential scanning and extortion, a Chinese-speaking group's autonomous zero-day research, and a French-speaking hacktivist.

The Recordupdated · 16h agofirst · 5d agoThreat actor in the wild 20 sources1

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

UK, US, and Dutch agencies expose CHOSEN BRICK spyware used by Iranian MOIS hackers to surveil dissidents, journalists, and activists via fake MRI lures.

The UK NCSC, FBI, and Dutch AIVD jointly warned that Iranian state-sponsored hackers deploy CHOSEN BRICK Windows spyware against dissidents, activists, and journalists since at least 2025. Operators build rapport over WhatsApp and Telegram, often posing as known contacts or tech support, then deliver malicious files disguised as an MRI scan or installers for Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, and KeePass. The malware steals contacts, emails, and social media messages, captures screen content and microphone audio, adds Microsoft Defender exclusions, and uses per-victim Telegram bots for command and control. The FBI attributes the tradecraft to Iran's Ministry of Intelligence and Security, including the 'Handala Hack' persona, and stolen data has surfaced on pro-Iranian leak sites.

The Record · 1d agoThreat actor in the wild1

Electric and gas utility CenterPoint Energy warns of data breach after dark web post

CenterPoint Energy confirmed hackers stole customer personal data from an external-facing system after a dark web post claimed 7.5 million records.

Texas utility CenterPoint Energy filed an SEC 8-K disclosing that a dark web post claimed to sell data stolen from the company, and an investigation confirmed personal information was taken from an external-facing system. The criminal post claims about 7.5 million records including customer names, account information, last four Social Security digits and billing data. Electric and gas service was not impacted; the company serves 7 million customers across Indiana, Minnesota, Ohio and Texas, and previously disclosed a 2023 breach via a file-sharing platform.

The Record · 1d agoData breach

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

Kaspersky links pro-Ukraine hacktivist group Hacking Cat to Gorilla RAT and Monkey Ransomware in destructive attacks on Russian targets.

Kaspersky reports that pro-Ukraine group Hacking Cat, active since February 2024, has shifted from defacements to destructive encryption attacks, using a previously undocumented Gorilla RAT remote-access tool and Monkey Ransomware, which appends the .monkey extension to files. Initial access in some attacks came from exploited Microsoft Exchange vulnerabilities, and rapid multi-language malware variants suggest possible generative AI assistance. Shared tools like Nemo Wiper across groups including Ukrainian Cyber Alliance complicate attribution, and targets include Rosatom contractor and heating provider Donbassteploenergo.

The Record · 2d agoThreat actor in the wild

Revolut handed customer data to fraudsters using government email account

Revolut handed sensitive KYC data of high-net-worth crypto customers to fraudsters submitting fake emergency data requests from a compromised government email domain.

Revolut confirmed it disclosed sensitive customer data—including passport and driver's license copies, verification selfies, bank statements, IBANs, and Bitcoin transaction histories—to attackers who submitted fraudulent emergency data requests from a legitimate government agency email account, apparently an Italian domain. Targets were high-net-worth individuals involved in crypto, including Marc Karpelès and entrepreneur Marc Zeller. A Telegram account claiming responsibility posted stolen data as proof and demanded an extortion payment; the account has since been suspended. Revolut says only a limited number of customers were affected and has alerted the relevant government agency, law enforcement, and regulators. The technique mirrors 2021-2022 Lapsus$-linked fraudulent emergency data request scams against Apple, Meta, and Discord.

The Record · 2d agoData breach

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

FinCEN urged banks to report cyber scams after a study found $12.7 billion stolen from US victims of crypto investment scams since 2023.

FinCEN analyzed more than 33,000 cyber fraud incident reports filed by roughly 1,300 financial institutions between September 2023 and December 2025, finding about $12.7 billion in losses to cryptocurrency investment scams across all 50 states. Traditional banks reported about $6.4 billion in suspected scam activity and crypto firms about $5.5 billion. Scam activity is growing, with monthly reports rising nearly 11% as centers expand beyond Myanmar, Cambodia, and Laos. The US later sanctioned Xinbi Guarantee, a Telegram-based marketplace used to launder over $36 billion.

The Record · 6d agoPhishing & fraud

IDScan confirms breach after hackers offer 153 million driver’s license scans for sale

IDScan confirmed hackers accessed customer data in its cloud after scans of roughly 153 million driver's licenses surfaced for sale on a dark web marketplace.

IDScan.net published a breach notice on September 4, after learning around September 1 that an unauthorized third party may have accessed or copied customer information in its cloud platform, potentially including full names and government-issued ID numbers. KrebsOnSecurity tied the incident to Nexus, a Russia-linked dark web marketplace selling access to over 153 million US and Canadian driver's license scans, plus 10 million ID cards, more than 3 million travel documents, and at least 579,000 medical cards. The company did not disclose how many customers were affected, is offering free credit monitoring, faces multiple lawsuits, and the FBI has opened an inquiry. IDScan's government ID authentication is widely used by banks, cannabis retailers, and gun stores.

The Record · 6d agoData breach in the wild

Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers

Russian e-commerce giant Wildberries says a DDoS attack and subsequent security measures delayed seller payments, leaving roughly $240 million unpaid.

Wildberries, one of Russia's largest online marketplaces, said a distributed denial-of-service attack on systems used to track and withdraw seller earnings delayed payments, with funds to be transferred after technical procedures complete. The Russian Union of Marketplace Sellers reported about 20 billion rubles ($240 million) unpaid, and 95.6% of nearly 2,000 surveyed sellers had not received expected payments. Ukraine's military intelligence (HUR) previously claimed an operation with the hacker group Cyber Corps disrupted Wildberries' payment and customer service systems, though the company has not confirmed whether the DDoS attacks were connected.

The Record · 6d agoThreat actor in the wild