Large team working on screens with cloud symbols, locks, warning icons, shields, and security threats above

Daily Dose of Cybersecurity News - October 2, 2025

Clop Extortion Emails Claim Theft of Oracle E-Business Suite Data

High

What happened

Executives at multiple companies received extortion emails claiming that sensitive data was stolen from their Oracle E-Business Suite systems. The emails are being sent from numerous compromised accounts, some previously linked to FIN11, a financially motivated threat group known for deploying ransomware and engaging in extortion.

Who is affected

Organizations utilizing Oracle E-Business Suite systems are targeted, with executives receiving the extortion emails.

Why it matters

The campaign indicates a potential shift in tactics by threat actors, leveraging compromised email accounts to disseminate extortion messages. The involvement of FIN11 suggests a high level of sophistication and the possibility of actual data breaches.

How it could have been prevented

Implementing multi-factor authentication (MFA) for email accounts, regularly monitoring for unusual access patterns, and ensuring Oracle E-Business Suite systems are up-to-date with the latest security patches.

Relevant professional terms

FIN11
A financially motivated cyber threat group known for deploying ransomware and conducting extortion campaigns.
Oracle E-Business Suite
A comprehensive suite of integrated business applications for enterprise resource planning (ERP).

Recommended reading: Clop ransomware gang starts extorting MOVEit data-theft victims

Motility Software Solutions Ransomware Attack Exposes 766,000 Clients' Data

High

What happened

Motility Software Solutions experienced a ransomware attack on August 19, 2025, leading to the encryption of certain systems and potential exfiltration of files containing personal data.

Who is affected

Approximately 766,000 customers of Motility Software Solutions, a provider of dealer management software to 7,000 dealerships across the United States.

Why it matters

The breach exposes sensitive personal information, increasing the risk of identity theft and fraud for a significant number of individuals associated with automotive dealerships nationwide.

How it could have been prevented

Implementing robust endpoint detection and response (EDR) solutions to detect and mitigate ransomware attacks, and conducting regular security audits to identify and address vulnerabilities.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system until a sum of money is paid.
Data Exfiltration
The unauthorized transfer of data from a computer or network.

Recommended reading: CISA Stop Ransomware

Adobe Analytics Data Ingestion Bug Exposes Customer Data

High

What happened

An ingestion bug in Adobe Analytics caused data from some organizations to appear in the analytics instances of others for approximately one day.

Who is affected

Adobe Analytics customers globally, including applications dependent on Adobe Analytics data.

Why it matters

The incident led to the exposure of customer tracking data between organizations, potentially including sensitive information like email addresses and session hashes, raising significant privacy and compliance concerns.

How it could have been prevented

Implementing more rigorous testing and validation procedures for performance optimization changes to prevent unintended data exposure.

Relevant professional terms

Data Ingestion
The process of importing, transferring, loading, and processing data for later use or storage in a database.
Data Exposure
The unintended release or sharing of sensitive information to unauthorized parties.

Recommended reading: Adobe Privacy Policy

Klopatra Android Trojan Exploits VNC for Remote Control

High

What happened

A new Android banking and remote access trojan (RAT) named Klopatra has infected over 3,000 devices across Europe. Disguised as an IPTV and VPN app, it utilizes Virtual Network Computing (VNC) to grant attackers real-time control over infected devices.

Who is affected

Android users in Europe who have downloaded the malicious "Modpro IP TV + VPN" app from unofficial sources.

Why it matters

Klopatra's capabilities allow attackers to steal banking credentials, exfiltrate sensitive data, and perform unauthorized transactions, posing significant financial and privacy risks to users.

How it could have been prevented

Avoid downloading apps from unofficial sources and refrain from granting Accessibility Service permissions to untrusted applications.

Relevant professional terms

Virtual Network Computing (VNC)
A graphical desktop-sharing system that uses the Remote Frame Buffer protocol to remotely control another computer.
Overlay Attack
A method where a malicious application displays a window over a legitimate app to trick users into entering sensitive information.

Recommended reading: Cleafy Analysis of Klopatra Trojan

WestJet Data Breach Exposes Personal Information of 1.2 Million Passengers

High

What happened

WestJet, Canada's second-largest airline, experienced a cyberattack in June 2025, leading to the unauthorized access and theft of personal information from approximately 1.2 million passengers. The compromised data includes names, dates of birth, postal addresses, travel documents (such as passports and government-issued IDs), and details related to customer rewards accounts.

Who is affected

Approximately 1.2 million WestJet passengers, including 240 residents of Maine, USA, have had their personal information compromised.

Why it matters

The exposure of sensitive personal information, including travel documents and rewards account details, increases the risk of identity theft, fraud, and targeted phishing attacks against affected individuals. Additionally, the breach highlights the aviation industry's vulnerability to sophisticated cyberattacks.

How it could have been prevented

Implementing robust multi-factor authentication (MFA) protocols, conducting regular security audits, and providing comprehensive employee training on recognizing and preventing social engineering attacks could have mitigated the risk of unauthorized access.

Relevant professional terms

Social Engineering
A manipulation technique that exploits human error to gain private information, access, or valuables.
Multi-Factor Authentication (MFA)
A security system that requires more than one method of authentication from independent categories of credentials to verify the user's identity.

Recommended reading: TechCrunch

ShinyHunters Exploit Social Engineering to Breach Salesforce Instances

High

What happened

The cybercriminal group ShinyHunters, also known as UNC6040, has been conducting vishing attacks to gain unauthorized access to organizations' Salesforce environments. By impersonating IT support personnel, they trick employees into installing malicious applications or divulging credentials, leading to data breaches.

Who is affected

Organizations utilizing Salesforce, including major corporations like Google, have been targeted by these attacks.

Why it matters

These incidents highlight the effectiveness of social engineering tactics in compromising cloud-based platforms, emphasizing the need for robust identity verification and employee training to prevent unauthorized access.

How it could have been prevented

Implementing multi-factor authentication (MFA), conducting regular employee training on social engineering threats, and establishing strict identity verification protocols for IT support interactions can mitigate such risks.

Relevant professional terms

Vishing
A form of social engineering where attackers use phone calls to deceive individuals into revealing sensitive information.
Multi-Factor Authentication (MFA)
A security process that requires users to provide multiple forms of verification to access an account, enhancing security.

Recommended reading: darkreading.com

US Government Shutdown Disrupts Cyber Threat Intelligence Sharing

High

What happened

The U.S. federal government shutdown, initiated on October 1, 2025, has led to the expiration of the Cybersecurity Information Sharing Act of 2015 (CISA 2015), disrupting cyber threat intelligence sharing between the private sector and government agencies.

Who is affected

Private sector companies, federal, state, and local government agencies, and the Cybersecurity and Infrastructure Security Agency (CISA) are all impacted by the cessation of legal protections and potential furloughs.

Why it matters

The lapse of CISA 2015 removes legal safeguards that encouraged the voluntary exchange of cyber threat indicators, potentially hindering collaborative efforts to identify and mitigate cyber threats. Additionally, mass furloughs at CISA could impair the agency's ability to execute its mission, increasing vulnerabilities across critical infrastructure.

How it could have been prevented

Timely reauthorization of CISA 2015 by Congress and the avoidance of a government shutdown would have maintained continuous legal protections and operational capabilities for cyber threat intelligence sharing.

Relevant professional terms

Cyber Threat Intelligence
Information about potential or current attacks that threaten an organization, used to prepare and respond to cyber threats.
Furlough
A temporary leave of employees due to special needs of a company or government, often due to budgetary constraints.

Recommended reading: What the Government Shutdown Teaches Us about Cybersecurity