Multiple hackers around large laptop displaying data streams with shields, locks, code, and security threats

Daily Dose of Cybersecurity News - September 3, 2025

Hackers Attempt $130M Theft via Breach of Fintech Firm's Pix System

High

What happened

Hackers gained unauthorized access to Sinqia S.A.'s systems, a Brazilian subsidiary of Evertec, and attempted to steal $130 million through Brazil's real-time payment system, Pix.

Who is affected

Sinqia S.A., a financial software and IT services provider in Brazil, and its parent company, Evertec, a major transaction processor in Latin America.

Why it matters

This incident highlights the vulnerabilities in real-time payment systems and the significant financial risks posed by cyberattacks on fintech companies.

How it could have been prevented

Implementing robust access controls, continuous monitoring of transaction activities, and regular security audits of payment systems.

Relevant professional terms

Real-time payment system
A financial system that allows instant transfer of funds between banks and financial institutions.
Unauthorized access
Gaining entry into a computer system or network without permission, often leading to data breaches or financial theft.

Recommended reading: Employee gets $920 for credentials used in $140 million bank heist

Cloudflare Data Breach via Salesloft Drift Supply Chain Attack

High

What happened

Cloudflare experienced a data breach when attackers exploited vulnerabilities in the Salesloft Drift integration, gaining unauthorized access to Cloudflare's Salesforce instance and exfiltrating 104 API tokens.

Who is affected

Cloudflare and its customers who shared sensitive information, such as logs, tokens, or passwords, through Cloudflare's support system.

Why it matters

The breach underscores the risks associated with third-party integrations and the potential for supply chain attacks to compromise sensitive customer data, leading to further security incidents.

How it could have been prevented

Implementing stricter security controls and regular audits for third-party integrations, along with prompt revocation and rotation of compromised credentials, could mitigate such risks.

Relevant professional terms

Supply Chain Attack
A cyberattack that targets an organization by compromising elements within its supply chain, such as third-party services or software.
OAuth Token
A credential used to authorize access to resources on behalf of a user, commonly used in third-party integrations.

Recommended reading: Cloudflare's Official Response to the Incident

Cloudflare Mitigates Record-Breaking 11.5 Tbps DDoS Attack

Critical

What happened

Cloudflare successfully mitigated the largest recorded volumetric distributed denial-of-service (DDoS) attack, which peaked at 11.5 terabits per second (Tbps). The attack was a UDP flood originating primarily from Google Cloud and lasted approximately 35 seconds.

Who is affected

Cloudflare and its clients were the primary targets of this massive DDoS attack.

Why it matters

This unprecedented attack underscores the escalating scale and sophistication of DDoS threats, highlighting the critical need for robust mitigation strategies to protect online services from significant disruptions.

How it could have been prevented

Implementing advanced DDoS mitigation solutions, maintaining up-to-date security protocols, and conducting regular network traffic analysis can help prevent or minimize the impact of such large-scale attacks.

Relevant professional terms

Volumetric DDoS Attack
A type of DDoS attack where the attacker overwhelms the target with massive amounts of data to consume bandwidth and exhaust system resources.
UDP Flood
A DDoS attack method that involves sending a large number of User Datagram Protocol (UDP) packets to random ports on a target machine, causing it to become overwhelmed and unresponsive.

Recommended reading: Cloudflare blocks record 7.3 Tbps DDoS attack against hosting provider

Jaguar Land Rover Cyberattack Severely Disrupts Production

High

What happened

Jaguar Land Rover (JLR) experienced a cyberattack that led to the proactive shutdown of certain systems, resulting in significant disruption to its production and retail operations.

Who is affected

JLR's global production facilities, retail operations, and associated employees and dealers are impacted by the incident.

Why it matters

The disruption underscores the vulnerability of critical manufacturing infrastructure to cyber threats, potentially leading to operational downtime, financial losses, and reputational damage.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system audits, employee training on phishing and social engineering attacks, and establishing comprehensive incident response plans, could mitigate such risks.

Relevant professional terms

Proactive Shutdown
The deliberate deactivation of systems to prevent further damage during a cyber incident.
Incident Response Plan
A structured approach outlining procedures for detecting, responding to, and recovering from cybersecurity incidents.

Recommended reading: CISA Stop Ransomware

Ransomware Attack Disrupts Pennsylvania Attorney General's Office Operations

High

What happened

The Pennsylvania Attorney General's Office experienced a ransomware attack that encrypted files and disrupted services, including the public website, email accounts, and landline phones. The office refused to pay the ransom demanded by the attackers.

Who is affected

The Pennsylvania Attorney General's Office, its staff, and stakeholders involved in ongoing criminal and civil cases.

Why it matters

The attack led to significant operational disruptions, causing delays in court proceedings and necessitating time extensions for various cases.

How it could have been prevented

Implementing robust cybersecurity measures, including regular system updates, employee training on phishing attacks, and maintaining secure backups, could have mitigated the risk and impact of such an attack.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system or data until a sum of money is paid.
Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.

Recommended reading: National Association of Attorneys General: Ransomware

Palo Alto Networks Data Breach Exposes Customer Information and Support Cases

High

What happened

Attackers exploited compromised OAuth tokens from the Salesloft Drift breach to access Palo Alto Networks' Salesforce instance, leading to the exposure of customer data and support cases.

Who is affected

Palo Alto Networks and its customers, whose sensitive information, including IT details and passwords shared in support cases, were exposed.

Why it matters

The breach underscores the risks associated with third-party integrations and supply chain vulnerabilities, potentially leading to unauthorized access to sensitive customer information.

How it could have been prevented

Regularly auditing third-party integrations for security vulnerabilities and implementing stringent access controls to limit the impact of compromised credentials.

Relevant professional terms

OAuth tokens
Authorization credentials used to grant access to resources without sharing passwords.
Supply chain attack
A cyberattack that targets less secure elements in the supply chain to gain access to a larger network.

Recommended reading: Zscaler Data Breach Exposes Customer Info After Salesloft Drift Compromise

Amazon Disrupts APT29 Credential Theft Campaign

High

What happened

APT29, a threat group linked to Russian intelligence, launched a credential theft campaign by compromising legitimate websites to redirect users to fake security verification pages, exploiting Microsoft's device authentication system to gain unauthorized access to user accounts.

Who is affected

Government and military organizations, NGOs, tech firms, and think tanks in the US and Europe were targeted in this campaign.

Why it matters

The campaign highlights the evolving tactics of state-sponsored actors in exploiting trusted authentication systems, posing significant risks to sensitive information and national security.

How it could have been prevented

Implementing multi-factor authentication (MFA) across all accounts and educating users to recognize and avoid phishing attempts can mitigate such threats.

Relevant professional terms

Watering Hole Attack
A strategy where attackers compromise a website frequently visited by a target group to distribute malware.
Device Code Authentication
A method allowing users to authenticate devices without entering credentials directly on the device, often used in phishing attacks.

Recommended reading: Beware of Device Code Phishing