Multiple hackers around central shield with hacker icon surrounded by laptops, locks, and security threats

Daily Dose of Cybersecurity News - September 18, 2025

ShinyHunters Claims Theft of 1.5 Billion Salesforce Records via Drift OAuth Tokens

Critical

What happened

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies by exploiting compromised Salesloft Drift OAuth tokens. The attackers allegedly breached Salesloft's GitHub repository, extracted OAuth tokens, and used them to access and exfiltrate data from Salesforce instances.

Who is affected

Approximately 760 companies utilizing Salesforce, including major firms like Google, Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, and Palo Alto Networks, are reportedly impacted.

Why it matters

The breach exposes sensitive customer and business data, increasing the risk of further cyberattacks, identity theft, and corporate espionage. The scale and method of the attack highlight vulnerabilities in third-party integrations and the importance of securing OAuth tokens.

How it could have been prevented

Implementing strict access controls and regular audits of third-party integrations, securing and rotating OAuth tokens, and conducting thorough code reviews to detect and remove hardcoded secrets could have mitigated the risk.

Relevant professional terms

OAuth Token
A secure authorization token that allows third-party applications to access user data without exposing credentials.
Extortion Group
A cybercriminal organization that steals data or disrupts services to demand ransom from victims.

Recommended reading: Salesloft: March GitHub repo breach led to Salesforce data theft attacks

Insight Partners Ransomware Attack Exposes Sensitive Data

High

What happened

Insight Partners, a venture capital and private equity firm, experienced a ransomware attack initiated through a sophisticated social engineering tactic. The attackers infiltrated the company's network, exfiltrated sensitive data, and encrypted systems.

Who is affected

Thousands of individuals, including current and former employees, limited partners, and associated companies, had their personal and financial information compromised.

Why it matters

The breach exposes sensitive financial and personal data, increasing the risk of identity theft and financial fraud for affected individuals and entities. It also underscores the vulnerability of financial institutions to sophisticated cyberattacks.

How it could have been prevented

Implementing robust social engineering awareness training for employees and enforcing multi-factor authentication could have mitigated the risk of unauthorized access.

Relevant professional terms

Social Engineering
A manipulation technique that exploits human error to gain private information, access, or valuables.
Ransomware
Malicious software designed to block access to a computer system until a sum of money is paid.

Recommended reading: Insight Partners' Official Statement on Cyber Incident

Evolving Threat Actor Techniques: From ClickFix to MetaStealer

High

What happened

Threat actors have advanced their social engineering tactics by combining ClickFix-style lures with sophisticated infection chains, notably deploying MetaStealer malware through deceptive AnyDesk installers and fake PDF files.

Who is affected

Organizations and individuals targeted by these evolving phishing campaigns, particularly those susceptible to social engineering attacks.

Why it matters

The integration of familiar social engineering methods with advanced malware deployment techniques increases the risk of successful infections, leading to potential data breaches and system compromises.

How it could have been prevented

Implementing user education programs to recognize and avoid phishing attempts, and enforcing strict policies against executing unverified scripts or software.

Relevant professional terms

ClickFix
A social engineering tactic where users are tricked into executing malicious code by clicking on deceptive "fix" prompts.
MetaStealer
A type of malware designed to steal sensitive information from infected systems.

Recommended reading: State-sponsored hackers embrace ClickFix social engineering tactic

Microsoft and Cloudflare Disrupt RaccoonO365 Phishing Service

High

What happened

Microsoft and Cloudflare collaborated to dismantle RaccoonO365, a Phishing-as-a-Service (PhaaS) operation that facilitated the theft of thousands of Microsoft 365 credentials. The operation involved seizing 338 websites and associated accounts linked to the phishing service.

Who is affected

Organizations and individuals across 94 countries, including over 2,300 U.S. organizations and more than 20 U.S. healthcare entities, were targeted by RaccoonO365 phishing campaigns.

Why it matters

The stolen credentials were used in financial fraud, extortion, and as initial access for further attacks, posing significant risks to public safety and organizational security. The disruption of RaccoonO365 highlights the growing threat of PhaaS platforms that lower the barrier for cybercriminals.

How it could have been prevented

Implementing multi-factor authentication (MFA) across all accounts and conducting regular security awareness training to recognize phishing attempts are critical steps in mitigating such threats.

Relevant professional terms

Phishing-as-a-Service (PhaaS)
A subscription-based model where cybercriminals offer phishing tools and services to other attackers, enabling them to conduct phishing campaigns with minimal technical expertise.
Multi-Factor Authentication (MFA)
A security process that requires users to provide two or more verification factors to gain access to a resource, enhancing account security beyond just a password.

Recommended reading: Microsoft Security Blog

AI-Powered Sign-up Fraud Escalates

High

What happened

Cybercriminals are leveraging artificial intelligence to automate the creation of fraudulent accounts on sign-up pages, exploiting promotional offers and overwhelming customer acquisition processes.

Who is affected

Organizations offering online sign-up incentives, particularly in the retail and e-commerce sectors, are primary targets of these AI-driven fraudulent activities.

Why it matters

The surge in AI-powered sign-up fraud leads to significant financial losses, disrupts marketing strategies, and undermines the integrity of customer databases, posing substantial risks to businesses.

How it could have been prevented

Implementing advanced bot detection mechanisms, enhancing identity verification processes during sign-up, and monitoring for unusual registration patterns can mitigate the risk of such fraudulent activities.

Relevant professional terms

Credential Stuffing
A cyberattack method where stolen account credentials are used to gain unauthorized access to user accounts.
Multifactor Authentication (MFA)
A security process that requires users to provide multiple forms of verification to access an account, enhancing security beyond just a password.

Recommended reading: Fighting AI-Powered Fraud: Let the Battle of the Machines Begin

Raven Stealer Exploits Telegram for Data Exfiltration

High

What happened

A new lightweight infostealer named Raven has emerged, targeting data from Chromium-based browsers and other applications. It employs Telegram for real-time data exfiltration to evade detection.

Who is affected

Users of Chromium-based browsers and applications who download software from underground forums or use cracked software are at risk.

Why it matters

Raven's use of Telegram for data exfiltration represents an evolution in stealth tactics for commodity infostealers, making detection and mitigation more challenging.

How it could have been prevented

Avoid downloading software from untrusted sources and refrain from using cracked software. Implement endpoint protection solutions capable of detecting and blocking unauthorized data exfiltration methods.

Relevant professional terms

Infostealer
A type of malware designed to gather sensitive information from a victim's system.
Data exfiltration
The unauthorized transfer of data from a computer or network.

Chinese APT41 Impersonates US Lawmaker in Phishing Campaign

High

What happened

Chinese state-sponsored hacking group APT41 conducted a phishing campaign impersonating US Representative John Moolenaar to target organizations involved in US-China relations. The attackers used emails with malicious links to establish persistent remote access via Visual Studio Code remote tunnels.

Who is affected

US government agencies, think tanks, and academic institutions engaged in US-China relations, international trade, and economic policy.

Why it matters

This campaign highlights the sophisticated tactics employed by nation-state actors to infiltrate sensitive organizations, posing significant risks to national security and policy-making processes.

How it could have been prevented

Implementing robust email filtering to detect and block phishing attempts, conducting regular security awareness training for staff, and employing multi-factor authentication to secure access points.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information or executing malicious actions.
Remote Access Trojan (RAT)
A type of malware that allows unauthorized remote control over an infected computer.

Recommended reading: securityweek.com