
Daily Dose of Cybersecurity News - September 3, 2025
Hackers Attempt $130M Theft via Breach of Fintech Firm's Pix System
HighWhat happened
Hackers gained unauthorized access to Sinqia S.A.'s systems, a Brazilian subsidiary of Evertec, and attempted to steal $130 million through Brazil's real-time payment system, Pix.
Who is affected
Sinqia S.A., a financial software and IT services provider in Brazil, and its parent company, Evertec, a major transaction processor in Latin America.
Why it matters
This incident highlights the vulnerabilities in real-time payment systems and the significant financial risks posed by cyberattacks on fintech companies.
How it could have been prevented
Implementing robust access controls, continuous monitoring of transaction activities, and regular security audits of payment systems.
Relevant professional terms
- Real-time payment system
- A financial system that allows instant transfer of funds between banks and financial institutions.
- Unauthorized access
- Gaining entry into a computer system or network without permission, often leading to data breaches or financial theft.
Recommended reading: Employee gets $920 for credentials used in $140 million bank heist
Cloudflare Data Breach via Salesloft Drift Supply Chain Attack
HighWhat happened
Cloudflare experienced a data breach when attackers exploited vulnerabilities in the Salesloft Drift integration, gaining unauthorized access to Cloudflare's Salesforce instance and exfiltrating 104 API tokens.
Who is affected
Cloudflare and its customers who shared sensitive information, such as logs, tokens, or passwords, through Cloudflare's support system.
Why it matters
The breach underscores the risks associated with third-party integrations and the potential for supply chain attacks to compromise sensitive customer data, leading to further security incidents.
How it could have been prevented
Implementing stricter security controls and regular audits for third-party integrations, along with prompt revocation and rotation of compromised credentials, could mitigate such risks.
Relevant professional terms
- Supply Chain Attack
- A cyberattack that targets an organization by compromising elements within its supply chain, such as third-party services or software.
- OAuth Token
- A credential used to authorize access to resources on behalf of a user, commonly used in third-party integrations.
Recommended reading: Cloudflare's Official Response to the Incident
Cloudflare Mitigates Record-Breaking 11.5 Tbps DDoS Attack
CriticalWhat happened
Cloudflare successfully mitigated the largest recorded volumetric distributed denial-of-service (DDoS) attack, which peaked at 11.5 terabits per second (Tbps). The attack was a UDP flood originating primarily from Google Cloud and lasted approximately 35 seconds.
Who is affected
Cloudflare and its clients were the primary targets of this massive DDoS attack.
Why it matters
This unprecedented attack underscores the escalating scale and sophistication of DDoS threats, highlighting the critical need for robust mitigation strategies to protect online services from significant disruptions.
How it could have been prevented
Implementing advanced DDoS mitigation solutions, maintaining up-to-date security protocols, and conducting regular network traffic analysis can help prevent or minimize the impact of such large-scale attacks.
Relevant professional terms
- Volumetric DDoS Attack
- A type of DDoS attack where the attacker overwhelms the target with massive amounts of data to consume bandwidth and exhaust system resources.
- UDP Flood
- A DDoS attack method that involves sending a large number of User Datagram Protocol (UDP) packets to random ports on a target machine, causing it to become overwhelmed and unresponsive.
Recommended reading: Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider
Jaguar Land Rover Cyberattack Severely Disrupts Production
HighWhat happened
Jaguar Land Rover (JLR) experienced a cyberattack that led to the proactive shutdown of certain systems, resulting in significant disruption to its production and retail operations.
Who is affected
JLR's global production facilities, retail operations, and associated employees and dealers are impacted by the incident.
Why it matters
The disruption underscores the vulnerability of critical manufacturing infrastructure to cyber threats, potentially leading to operational downtime, financial losses, and reputational damage.
How it could have been prevented
Implementing robust cybersecurity measures, including regular system audits, employee training on phishing and social engineering attacks, and establishing comprehensive incident response plans, could mitigate such risks.
Relevant professional terms
- Proactive Shutdown
- The deliberate deactivation of systems to prevent further damage during a cyber incident.
- Incident Response Plan
- A structured approach outlining procedures for detecting, responding to, and recovering from cybersecurity incidents.
Recommended reading: CISA Stop Ransomware
Ransomware Attack Disrupts Pennsylvania Attorney General's Office Operations
HighWhat happened
The Pennsylvania Attorney General's Office experienced a ransomware attack that encrypted files and disrupted services, including the public website, email accounts, and landline phones. The office refused to pay the ransom demanded by the attackers.
Who is affected
The Pennsylvania Attorney General's Office, its staff, and stakeholders involved in ongoing criminal and civil cases.
Why it matters
The attack led to significant operational disruptions, causing delays in court proceedings and necessitating time extensions for various cases.
How it could have been prevented
Implementing robust cybersecurity measures, including regular system updates, employee training on phishing attacks, and maintaining secure backups, could have mitigated the risk and impact of such an attack.
Relevant professional terms
- Ransomware
- A type of malicious software designed to block access to a computer system or data until a sum of money is paid.
- Phishing
- A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Recommended reading: National Association of Attorneys General: Ransomware
Palo Alto Networks Data Breach Exposes Customer Information and Support Cases
HighWhat happened
Attackers exploited compromised OAuth tokens from the Salesloft Drift breach to access Palo Alto Networks' Salesforce instance, leading to the exposure of customer data and support cases.
Who is affected
Palo Alto Networks and its customers, whose sensitive information, including IT details and passwords shared in support cases, were exposed.
Why it matters
The breach underscores the risks associated with third-party integrations and supply chain vulnerabilities, potentially leading to unauthorized access to sensitive customer information.
How it could have been prevented
Regularly auditing third-party integrations for security vulnerabilities and implementing stringent access controls to limit the impact of compromised credentials.
Relevant professional terms
- OAuth tokens
- Authorization credentials used to grant access to resources without sharing passwords.
- Supply chain attack
- A cyberattack that targets less secure elements in the supply chain to gain access to a larger network.
Recommended reading: Zscaler Data Breach Exposes Customer Info After Salesloft Drift Compromise
Amazon Disrupts APT29 Credential Theft Campaign
HighWhat happened
APT29, a threat group linked to Russian intelligence, launched a credential theft campaign by compromising legitimate websites to redirect users to fake security verification pages, exploiting Microsoft's device authentication system to gain unauthorized access to user accounts.
Who is affected
Government and military organizations, NGOs, tech firms, and think tanks in the US and Europe were targeted in this campaign.
Why it matters
The campaign highlights the evolving tactics of state-sponsored actors in exploiting trusted authentication systems, posing significant risks to sensitive information and national security.
How it could have been prevented
Implementing multi-factor authentication (MFA) across all accounts and educating users to recognize and avoid phishing attempts can mitigate such threats.
Relevant professional terms
- Watering Hole Attack
- A strategy where attackers compromise a website frequently visited by a target group to distribute malware.
- Device Code Authentication
- A method allowing users to authenticate devices without entering credentials directly on the device, often used in phishing attacks.
Recommended reading: Beware of Device Code Phishing