ZeroFox Weekly Intelligence Brief – February 12, 2024
|by Alpha Team

ZeroFox Weekly Intelligence Brief – February 12, 2024
ZeroFox’s Weekly Intelligence Briefing highlights the major developments and trends across the cyber threat landscape. ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on February 9, 2024; per cyber hygiene best practices, caution is advised when clicking on any third-party links.
Read the Brief
View the full report here
Hong Kong Company Loses USD 25 Million to Deepfake Scam Targeting an Employee
What happened: The Hong Kong branch of a multi-national company suffered a loss of USD 25 million after scammers used deepfake technology to trick one of its employees. The targeted finance department employee reportedly received a message from an individual claiming to be the company’s UK-based chief financial officer (CFO). They then attended a video conference with deepfake versions of the company’s CFO and other company employees. Acting on instructions received on the video call, the employee then reportedly made 15 transactions to various Hong Kong bank accounts, transferring USD 25.6 million in total. No arrests have been made at the time of reporting.
Millions of User Records Stolen from 65 Websites via SQL Injection Attacks
What happened: A hacking group known as “ResumeLooters” carried out a cyberattack, stealing over two million email addresses and other personal information from at least 65 websites in November and December 2023. The group reportedly used SQL injection attacks and sold the stolen data on Chinese-speaking, hacking-themed Telegram groups. Their targets were mainly in India, Taiwan, Thailand, Vietnam, and China, but ResumeLooters also hit sites in other countries, including Australia, the Philippines, South Korea, Japan, the United States, Brazil, Russia, and Italy. The group focused on compromising retail and recruitment websites, although victims in various other sectors were also identified.
Verizon Insider Data Breach Hits Over 63,000 Employees
What happened: Over 63,000 employees from Verizon Communications have been affected by an insider data breach that exposed their sensitive information. The exposed data varies per employee and includes full name, physical address, social security number, national ID, gender, union affiliation, date of birth, and compensation information.
Tags: tlp:green