Cyberattack – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 29 Jul 2025 23:57:22 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Cyberattack – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Minnesota activates National Guard after St. Paul cyberattack https://earlybirdsinvest.com/minnesota-activates-national-guard-after-st-paul-cyberattack/ https://earlybirdsinvest.com/minnesota-activates-national-guard-after-st-paul-cyberattack/#respond Tue, 29 Jul 2025 23:57:22 +0000 https://earlybirdsinvest.com/minnesota-activates-national-guard-after-st-paul-cyberattack/

St. Paul Minnesota

Minnesota Governor Tim Walz has activated the National Guard in response to a crippling cyberattack that struck the City of Saint Paul, the state’s capital, on Friday.

The city is currently working with local, state, and federal partners to investigate the attack and restore full functionality, and says that emergency services have been unaffected.

However, online payments are currently unavailable, and some services in libraries and recreation centers are temporarily unavailable.

“While many city services remain available, some may be temporarily delayed or disrupted due to limited system access. We appreciate your patience and understanding as we work to bring systems fully back online,” the city says.

The attack has persisted through the weekend, causing widespread disruptions across the city after affecting St. Paul’s digital services and critical systems.

“St. Paul officials have been working around the clock since discovering the cyberattack, closely coordinating with Minnesota Information Technology Services and an external cybersecurity vendor. Unfortunately, the scale and complexity of this incident exceeded both internal and commercial response capabilities,” reads an emergency executive order signed on Tuesday.

“As a result, St. Paul has requested cyber protection support from the Minnesota National Guard to help address this incident and make sure that vital municipal services continue without interruption.”

Cyberattack alert on St. Paul's website
Cyberattack alert on St. Paul’s website (BleepingComputer)

​The decision to deploy cyber protection support from the Minnesota National Guard comes at the city’s request, after the cyberattack’s impact exceeded St. Paul’s incident response capacity.

This will ensure the continuity of vital services for Saint Paul residents, as well as their security and safety while ongoing disruptions are being mitigated.

“We are committed to working alongside the City of Saint Paul to restore cybersecurity as quickly as possible,” Governor Walz said on Tuesday.

“The Minnesota National Guard’s cyber forces will collaborate with city, state, and federal officials to resolve the situation and mitigate lasting impacts.”

Minnesota’s capital city has a population of over 311,000 and is the state’s second-largest city, after Minneapolis.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/minnesota-activates-national-guard-after-st-paul-cyberattack/feed/ 0 50395
Iran-based crypto exchange hacked for $48M amid cyberattack claims by Israel-linked group https://earlybirdsinvest.com/iran-based-crypto-exchange-hacked-for-48m-amid-cyberattack-claims-by-israel-linked-group/ https://earlybirdsinvest.com/iran-based-crypto-exchange-hacked-for-48m-amid-cyberattack-claims-by-israel-linked-group/#respond Wed, 18 Jun 2025 10:37:40 +0000 https://earlybirdsinvest.com/iran-based-crypto-exchange-hacked-for-48m-amid-cyberattack-claims-by-israel-linked-group/

Iranian crypto exchange Nobitex has suffered a major security breach, resulting in the loss of over $48 million.

The company confirmed the attack via an X post on June 18, revealing that the incident targeted its hot wallets. It stated:

“This morning our technical team detected signs of unauthorized access to a portion of our reporting infrastructure and hot wallet. Immediately upon detection, all access was suspended and our internal security teams are closely investigating the extent of the incident.”

The drained funds were Tether’s USDT via the Tron network, according to blockchain sleuth ZachXBT.

Despite the hack, Nobitex tried to reassure its users that their funds in its cold wallet remained safe and promised to reimburse them.

It added:

“Nobitex accepts full responsibility for this incident and assures users that all damages will be compensated through the insurance fund and Nobitex resources.” 

The platform’s website and mobile app have been taken offline while the investigation continues.

Israel-linked group claims responsibility

A group identifying itself as Gonjeshke Darande, translated as “Predatory Sparrow,” has claimed responsibility for the hack. Reuters and the Israel Times have described the group as “Israel-linked.” However, while the group has a history of attacking Iran-based infrastructure, no official confirmation of state sponsorship has been made.

In a public message on the social media platform X, the group accused Nobitex of aiding Iran’s military operations and helping users circumvent global sanctions.

It stated:

“The Nobitex exchange is at the heart of the regime’s efforts to finance terror worldwide, as well as being the regime’s favorite sanctions violation tool. We, ‘Gonjeshke Darande,’ conducted cyberattacks against Nobitex.”

They alleged that the platform is not only ignoring sanctions but also actively instructing users on how to bypass them.

The group further claimed that employment at Nobitex qualifies as military service under Iranian law, implying the exchange is part of the country’s defense and intelligence infrastructure.

As part of the threat, the group warned it would release Nobitex’s source code and internal data within 24 hours. They cautioned users that any assets left on the platform could be at risk.

Predatory Sparrow has previously taken credit for cyberattacks on other Iranian institutions, including Bank Sepah, citing similar reasons.

The breach comes during a period of escalating tensions between Israel and Iran, marked by recent missile exchanges between both countries.

Mentioned in this article
]]>
https://earlybirdsinvest.com/iran-based-crypto-exchange-hacked-for-48m-amid-cyberattack-claims-by-israel-linked-group/feed/ 0 42698
Mobile carrier Cellcom confirms cyberattack behind extended outages https://earlybirdsinvest.com/mobile-carrier-cellcom-confirms-cyberattack-behind-extended-outages/ https://earlybirdsinvest.com/mobile-carrier-cellcom-confirms-cyberattack-behind-extended-outages/#respond Tue, 20 May 2025 21:51:48 +0000 https://earlybirdsinvest.com/mobile-carrier-cellcom-confirms-cyberattack-behind-extended-outages/

Cellcom

Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025.

The incident disrupted voice and SMS services for customers across Wisconsin and Upper Michigan, leaving subscribers unable to make phone calls or send text messages.

Today, after days of just calling it a technical outage, Cellcom CEO Brighid Riordan has confirmed what was already suspected: that the company suffered a cyberattack.

“We experienced a cyber incident. While this is unfortunate, it’s not something we were unprepared for,” reads a letter from Cellcom CEO Brighid Riordan.

“We have protocols and plans in place for exactly this kind of situation. From the start, we’ve followed those plans — including engaging outside cybersecurity experts, notifying the FBI and Wisconsin officials, and working around the clock to bring systems safely back online.”

“The incident was concentrated on an area of our network separate from where we store sensitive information related to you, our Cellcom/ Nsight family. We have no evidence that personal information related to you, your name, your addresses, your financial information, is impacted by this event.”

Cellcom initially claimed the disruption was caused by a technical issue, stating that data services, iMessage, RCS messaging, and 911 emergency services remained operational.

However, users became increasingly frustrated with the loss of service and the inability to port their numbers to other carriers due to Cellcom’s platforms having issues.

On May 19, Cellcom began bringing some of its services back online, including SMS text messaging and making and receiving phone calls to other Cellcom subscribers.

However, the company says that while they can’t promise when services will be restored, they are trying to restore full service by the end of the week.

“While we would like to provide a timeline for full restoration, we are unable to share exact milestones with complete confidence. Our team continues to build on the progress shared yesterday and our best estimate is that full service will be restored by or before the end of this week,” reads a service updates page on Cellcom’s site.

For Cellcom subscribers having issues recovering services, it is recommended that they enable airplane mode for 10 seconds and then disable it again. If that does not work, subscribers should power down their phones and start them up again to attempt to initiate services.

Yesterday, BleepingComputer contacted Cellcom with questions about the disruption caused by a ransomware attack or another cyber incident, but did not receive replies to our questions.

Cellcom CEO Brighid Riordan also shared a video for subscribers to explain the situation and what they are doing to recover from services.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/mobile-carrier-cellcom-confirms-cyberattack-behind-extended-outages/feed/ 0 37371
Massive X Cyberattack: Here’s Who’s Responsible https://earlybirdsinvest.com/massive-x-cyberattack-heres-whos-responsible/ https://earlybirdsinvest.com/massive-x-cyberattack-heres-whos-responsible/#respond Wed, 12 Mar 2025 05:04:22 +0000 https://earlybirdsinvest.com/massive-x-cyberattack-heres-whos-responsible/

A widespread outage hit X on Monday which affected users across the world. Many experienced connectivity problems early in the day, with error messages appearing on their screens. Downdetector tracked a peak of 40,000 complaints as the service remained unstable for several hours.

A hacker group with alleged Russian ties, known as Dark Storm, has now claimed responsibility for the cyberattack that temporarily crippled the social media platform.

Hackers’ IPs Traced to Ukraine Region

The attack, identified as a distributed denial-of-service (DDoS) assault, left thousands unable to access the platform before functionality was swiftly restored.

Cybersecurity firm SpyoSecure reported that Dark Storm’s leader had announced the attack in a now-deleted Telegram post. Before its removal, the message boasted about taking X offline, with screenshots showing widespread connection failures across multiple locations. While the group’s Telegram channel has been shut down for violating the platform’s policies, evidence of the attack continues circulating online.

For instance, Ed Krassenstein, an entrepreneur, and a social media commentator who also happens to be the co-founder of NFT marketplace NFTz.me, weighed in and claimed direct communication with Dark Storm’s leader. According to Krassenstein’s tweet, the hackers described their actions as a show of force rather than an operation driven by political motives.

However, Dark Storm’s history suggests otherwise. The group, which has been active since 2023, has a track record of targeting NATO countries and is known for its pro-Palestinian stance.

Meanwhile, Elon Musk confirmed the attack in an interview and noted that his team traced the origin of the hackers’ IP addresses to the “Ukraine area” without elaborating any further.

Political Firestorm

The latest development comes amidst the “Take Down Tesla” movement, as Tesla facilities nationwide have become hotspots for protests and vandalism, fueled by opposition to Elon Musk’s Department of Government Efficiency (DOGE), which has been eliminating government agencies. Demonstrators are reacting to Musk’s political influence within the Trump administration.

He has publicly accused five activist groups – Troublemakers, Disruption Project, Rise & Resist, Indivisible Project, and Democratic Socialists of America – of orchestrating the growing wave of demonstrations.

The post Massive X Cyberattack: Here’s Who’s Responsible appeared first on CryptoPotato.

]]>
https://earlybirdsinvest.com/massive-x-cyberattack-heres-whos-responsible/feed/ 0 24651