zerofox logo
Advisories

ZeroFox Cyber Intelligence Daily Brief - January 28, 2024

|by Alpha Team

banner image

ZeroFox Cyber Intelligence Daily Brief - January 28, 2024

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • ZeroFox Intelligence Flash Report - New BEC Campaign Set to Target Western Countries
  • Mother of All Breaches Reveals 26 Billion Records
  • SEC Confirms X Account Hack

ZeroFox Intelligence Flash Report - New BEC Campaign Set to Target Western Countries

ZeroFox has recently observed the announcement of a new Business Email Compromise (BEC) campaign set to target Western states that promises affiliates substantial monetary profit. There is a roughly even chance that organizations face a heightened threat from BEC attacks in 2024 due to an increase in attacks and the continual diversification of techniques, tactics and procedures (TTPs). BEC is a type of cyberattack that enables the threat actor to gain unauthorized access to a personal or organizational email account before socially engineering victims. Threat actors—who are usually financially-motivated—leverage threat vectors such as account compromise and CEO or vendor impersonation to elicit fraudulent payment or data theft from unsuspecting victims.

Mother of All Breaches Reveals 26 Billion Records

A massive data leak has been uncovered, containing a staggering 12 terabytes of data from numerous past breaches, totaling 26 billion records. This extensive leak encompasses user data from platforms like LinkedIn, Weibo, Tencent, and others. Reportedly, Tencent’s data amounted to 1.5 billion records leaked followed by the second largest, Weibo — 504 million records. This breach consolidates records from thousands of meticulously compiled and reindexed leaks and privately traded databases. The database contains both old and new, undisclosed information, indicating that the unknown threat actor could be a data-broker service or a malicious actor using this information for identity theft, sophisticated phishing schemes, targeted cyberattacks, and more.

SEC Confirms X Account Hack

The U.S. Securities and Exchange Commission (SEC) has confirmed unauthorized access and activity on its @SECGov X account, revealing that the breach resulted from a SIM swap attack on the associated cell phone number. In this attack, the unauthorized party gained control of the phone number through the telecom carrier. However, there is no evidence suggesting access to SEC systems, data, devices, or other social media accounts. Law enforcement is currently investigating how the unauthorized party convinced the carrier to change the SIM and how they identified the specific phone number associated with the SEC account.

Tags: DIB, tlp:green