exposed – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 12 Aug 2025 09:30:52 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 exposed – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 North Korean Kimsuky hackers exposed in alleged data breach https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/ https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/#respond Tue, 12 Aug 2025 09:30:51 +0000 https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/

North Korea

The North Korean state-sponsored hackers known as Kimsuky has reportedly suffered a data breach after two hackers, who describe themselves as the opposite of Kimsuky’s values, stole the group’s data and leaked it publicly online.

The two hackers, named ‘Saber’ and ‘cyb0rg,’ cited ethical reasons for their actions, saying Kimsuky is “hacking for all the wrong reasons,” claiming they’re driven by political agendas and follow regime orders instead of practicing the art of hacking independently.

“Kimsuky, you are not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda,” reads the hackers’ address to Kimsuky published in the latest issue of Phrack, which was distributed at the DEF CON 33 conference.

“You steal from others and favour your own. You value yourself above the others: You are morally perverted.”

The hackers dumped a portion of Kimsuky’s backend, exposing both their tooling and some of their stolen data that could provide insight into unknown campaigns and undocumented compromises.

The 8.9GB dump currently hosted on the ‘Distributed Denial of Secrets” website contains, among others:

  • Phishing logs with multiple dcc.mil.kr (Defense Counterintelligence Command) email accounts.
  • Other targeted domains: spo.go.kr, korea.kr, daum.net, kakao.com, naver.com.
  • .7z archive containing the complete source code of South Korea’s Ministry of Foreign Affairs email platform (“Kebi”), including webmail, admin, and archive modules.
  • References to South Korean citizen certificates and curated lists of university professors.
  • PHP “Generator” toolkit for building phishing sites with detection evasion and redirection tricks.
  • Live phishing kits.
  • Unknown binary archives (voS9AyMZ.tar.gz, Black.x64.tar.gz) and executables (payload.bin, payload_test.bin, s.x64.bin) not flagged in VirusTotal.
  • Cobalt Strike loaders, reverse shells, and Onnara proxy modules found in VMware drag-and-drop cache.
  • Chrome history and configs linking to suspicious GitHub accounts (wwh1004.github.io, etc.), VPN purchases (PureVPN, ZoogVPN) via Google Pay, and frequent use of hacking forums (freebuf.com, xaker.ru).
  • Google Translate use for Chinese error messages and visits to Taiwan government and military sites.
  • Bash history with SSH connections to internal systems.

The hackers note that some of the above are already known or previously documented, at least partially.

However, the dump gives a new dimension to the data and provides interlinking between Kimsuky’s tools and activities, exposing and effectively “burning” the APT’s infrastructure and methods.

BleepingComputer has contacted various security researchers to confirm the veracity of the leaked documents and its value and will update the story if we receive a response.

While the breach will likely not have long-term impact on Kimsuky’s operations, it could lead to operational difficulties for Kimsuky and disruptions to ongoing campaigns.

The latest issue of Phrack (#72) is currently only available in a limited physical copy, but the online version should be ready for people to read for free in the following days from here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/feed/ 0 52797
Google confirms data breach exposed potential Google Ads customers’ info https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/ https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/#respond Mon, 11 Aug 2025 01:20:14 +0000 https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/

Google Ads

Google has confirmed that a recently disclosed data breach of one of its Salesforce CRM instances involved the information of potential Google Ads customers.

“We’re writing to let you know about an event that affected a limited set of data in one of Google’s corporate Salesforce instances used to communicate with prospective Ads customers,” reads a data breach notification shared with BleepingComputer.

“Our records indicate basic business contact information and related notes were impacted by this event.”

Google says the exposed information includes business names, phone numbers, and “related notes” for a Google sales agent to contact them again.

The company says that payment information was not exposed and that there is no impact on Ads data in Google Ads Account, Merchant Center, Google Analytics, and other Ads products.

The breach was conducted by threat actors known as ShinyHunters, who have been behind an ongoing wave of data theft attacks targeting Salesforce customers.

While Google has not shared how many individuals were impacted, ShinyHunters says the stolen information contains approximately 2.55 million data records. It is unclear if there are duplicates within these records.

ShinyHunters further told BleepingComputer that they are also working with threat actors associated with “Scattered Spider, who are responsible for first gaining initial access to targeted systems.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

The threat actors are now referring to themselves as “Sp1d3rHunters,” to illustrate the overlapping group of people who are involved in these attacks.

As part of these attacks, the threat actors conduct social engineering attacks against employees to gain access to credentials or trick them into linking a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

The threat actors then download the entire Salesforce database and extort the companies via email, threatening to release the stolen data if a ransom is not paid.

These Salesforce attacks were first reported by the Google Threat Intelligence Group (GTIG) in June, with the company suffering the same fate a month later.

Databreaches.net reported that the threat actors have already sent an extortion demand to Google. After publishing the story, ShinyHunters told BleepingComputer that they demanded 20 Bitcoins, or approximately $2.3 million, from Google to not leak the data.

“I don’t care about ransoming Google anyway, I just sent them a bogus email for the lulz of it,” said the threat actor.

ShinyHunters says they have since switched to a new custom tool that makes it easier and quicker to steal data from compromised Salesforce instances.

In an update, Google recently acknowledged the new tooling, stating that they have seen Python scripts used in the attacks instead of the Salesforce Data Loader.

Update 8/9/25: Added further information about the extortion demand.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/feed/ 0 52579
Bitcoin developers proposing quantum upgrade warn 25% of total BTC supply exposed to attack risk https://earlybirdsinvest.com/bitcoin-developers-proposing-quantum-upgrade-warn-25-of-total-btc-supply-exposed-to-attack-risk/ https://earlybirdsinvest.com/bitcoin-developers-proposing-quantum-upgrade-warn-25-of-total-btc-supply-exposed-to-attack-risk/#respond Wed, 16 Jul 2025 14:27:21 +0000 https://earlybirdsinvest.com/bitcoin-developers-proposing-quantum-upgrade-warn-25-of-total-btc-supply-exposed-to-attack-risk/

A group of experienced Bitcoin developers has outlined a new proposal to prepare the network for the inevitable threat of quantum computing.

The initiative, led by Jameson Lopp, Christian Papathanasiou, Ian Smith, Steve Vaile, and Pierre-Luc Dallaire-Demers, focuses on safeguarding vulnerable Bitcoin held in older address types that may be compromised by future quantum breakthroughs.

25% of Bitcoin faces quantum computing risk

The proposal noted that around 25% of all Bitcoin eventually could be at risk if a cryptographically capable quantum computer emerges.

According to the developers, these assets are held in addresses that have already exposed their public keys, making them potential targets for these sophisticated computing machines.

Due to this, the developers stressed that this is not a hypothetical issue for the distant future but a serious risk that requires proactive mitigation.

They warned that a successful quantum attack wouldn’t just impact market value; it could severely undermine trust in the network’s ability to function securely. They stressed:

“An attack on Bitcoin may not be economically motivated – an attacker may be politically or maliciously motivated and may attempt to destroy value and trust in Bitcoin rather than extract value. There is no way to know in advance how, when, or why an attack may occur. A defensive position must be taken well in advance of any attack.”

Three-phase strategy for a quantum-safe transition

To prepare for this threat, the team has laid out a three-phase plan to gradually migrate users from quantum-vulnerable addresses to post-quantum secure alternatives.

The first phase would allow Bitcoin to be sent only to new address types called P2QRH, thereby nudging the network toward quantum resilience. This transition is expected to begin three years after the implementation of BIP-360.

The second phase would invalidate all spends from legacy cryptographic signatures, effectively freezing unupdated addresses after a predetermined block height. According to the developers, this could be roughly five years after phase one begins.

The third and final phase would provide a method for users who missed the migration window to recover their legacy funds using zero-knowledge proofs tied to their seed phrases. However, this step is still under research and would be optional.

Community reaction

Jacob Youngman, a Bitcoin commentator, expressed concern that the changes might lead to the confiscation of inactive or legacy-held coins, possibly including those linked to Satoshi Nakamoto.

According to him:

“The best we can do would be to give users an opt-in solution that protects them from quantum computers.”

However, Lopp addressed the criticism, stating that inactive wallets are just as likely to be exploited by malicious quantum actors if no action is taken.

Mentioned in this article
]]>
https://earlybirdsinvest.com/bitcoin-developers-proposing-quantum-upgrade-warn-25-of-total-btc-supply-exposed-to-attack-risk/feed/ 0 47965
‘123456’ password exposed chats for 64 million McDonald’s job applicants https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/ https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/#respond Sat, 12 Jul 2025 02:51:12 +0000 https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/

McDonald's sign

Cybersecurity researchers discovered a vulnerability in McHire, McDonald’s chatbot job application platform, that exposed the chats of more than 64 million job applicants across the United States.

The flaw was discovered by security researchers Ian Carroll and Sam Curry, who found that the ChatBot’s admin panel utilized a test franchise that was protected by weak credentials of a login name “123456” and a password of “123456”.

McHire, powered by Paradox.ai and used by about 90% of McDonald’s franchisees, accepts job applications through a chatbot named Olivia. Applicants can submit names, email addresses, phone numbers, home addresses, and availability, and are required to complete a personality test as part of the job application process.

Once logged in, the researchers submitted a job application to the test franchise to see how the process worked.

During this test, they noticed that HTTP requests were sent to an API endpoint at /api/lead/cem-xhr, which used a parameter lead_id, which in their case was 64,185,742.

The researchers found that by incrementing and decrementing the lead_id parameter, they were able to expose the full chat transcripts, session tokens, and personal data of real job applicants that previously applied on McHire.

This type of flaw is called an IDOR (Insecure Direct Object Reference) vulnerability, which is when an application exposes internal object identifiers, such as record numbers, without verifying whether the user is actually authorized to access the data.

“During a cursory security review of a few hours, we identified two serious issues: the McHire administration interface for restaurant owners accepted the default credentials 123456:123456, and an insecure direct object reference (IDOR) on an internal API allowed us to access any contacts and chats we wanted,” Carroll explained in a writeup about the flaw.

“Together they allowed us and anyone else with a McHire account and access to any inbox to retrieve the personal data of more than 64 million applicants.”

In this case, incrementing or decrementing a lead_id number in a request returned sensitive data belonging to other applicants, as the API failed to check if the user had access to the data.

Exploiting the IDOR bug to see McDonald's job applications
Exploiting the IDOR bug to see McDonald’s job applications

The issue was reported to Paradox.ai and McDonald’s on June 30.

McDonald’s acknowledged the report within an hour, and the default admin credentials were disabled soon after.

“We’re disappointed by this unacceptable vulnerability from a third-party provider, Paradox.ai. As soon as we learned of the issue, we mandated Paradox.ai to remediate the issue immediately, and it was resolved on the same day it was reported to us,” McDonald’s told Wired in a statement about the research.

Paradox deployed a fix to address the IDOR flaw and confirmed that the vulnerability was mitigated. Paradox.ai has since stated that it is conducting a review of its systems to prevent similar big issues from recurring.

Paradox also told BleepingComputer that the information exposed would be any chatbot interaction, such as clicking on a button, even if no personal information was entered.

Update 7/11/25: Added information from Paradox.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/123456-password-exposed-chats-for-64-million-mcdonalds-job-applicants/feed/ 0 47142
Crypto Fraud Exposed: 2 Londoners Get 12 Years For $2M Scam https://earlybirdsinvest.com/crypto-fraud-exposed-2-londoners-get-12-years-for-2m-scam/ https://earlybirdsinvest.com/crypto-fraud-exposed-2-londoners-get-12-years-for-2m-scam/#respond Tue, 08 Jul 2025 23:54:06 +0000 https://earlybirdsinvest.com/crypto-fraud-exposed-2-londoners-get-12-years-for-2m-scam/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Crypto scammers continue to believe they can get away with their dirty tactics. Two residents of Greater London have been sent to prison after swindling more than £1.54 million—about $2.1 million—from at least 65 people.

Sentences of over five years for Raymondip Bedi and six years for Patrick Mavanga came down this week. According to a press release from the UK’s Financial Conduct Authority, the duo ran a sham crypto scheme between February 2017 and June 2019 that left dozens out of pocket.

FCA Uncovers Massive Fake Crypto Platform

Based on reports from the FCA, Bedi and Mavanga cold‑called potential investors and directed them to a website that promised big returns on digital assets. The site looked legit, but it was entirely fake.

Victims were shown graphs and figures that never existed. Money went straight into the pair’s accounts. No real crypto trades happened.

Victims Misled With Promises Of High Returns

Individuals who responded to those calls were informed they could double, even triple their money within months. It was an easy sell. Easy money, no risk. But subsequent bank statements revealed funds vanished into shell firms owned and run by the two men.

Bedi pleaded guilty in May 2023 to conspiracy to defraud, contrary to the Financial Services and Markets Act 2000, and money laundering. Mavanga pleaded guilty in June 2023 to the same offenses along with possession of false ID documents.

BTCUSD now trading at $108,785. Chart: TradingView

Court Hears Details Of The Scheme

At a hearing this week, prosecutors noted that the pair made cold calls day after day. They targeted 65 investors in total. Some lost as little as £5,000; others gave up to £200,000.

All were told they’d get at least 10% returns every month. But no payouts ever arrived. The FCA’s joint executive director of enforcement, Steve Smart, said the sentences send a clear warning: crime won’t pay.

Victims Urged To Stay Alert

Smart added that genuine investment firms don’t ring out of the blue with guaranteed profits. He urged anyone approached with such deals to hang up and check the FCA’s register.

He reminded people: if it sounds too good to be true, it probably is. The watchdog has tightened its oversight in recent years, tracking down dozens of crypto‑related frauds.

A Wake‑Up Call For Crypto Investors

This case shows that regulators are watching digital assets as closely as traditional markets. It also highlights how the phone remains a tool for crooks.

Investors should always verify who they’re dealing with. Look up companies on the FCA website, ask for official paperwork, and never rush into a deal.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/crypto-fraud-exposed-2-londoners-get-12-years-for-2m-scam/feed/ 0 46552
Survey finds gaps in mainstream Bitcoin coverage, leaving institutional investors exposed https://earlybirdsinvest.com/survey-finds-gaps-in-mainstream-bitcoin-coverage-leaving-institutional-investors-exposed/ https://earlybirdsinvest.com/survey-finds-gaps-in-mainstream-bitcoin-coverage-leaving-institutional-investors-exposed/#respond Tue, 08 Jul 2025 23:31:51 +0000 https://earlybirdsinvest.com/survey-finds-gaps-in-mainstream-bitcoin-coverage-leaving-institutional-investors-exposed/

A second-quarter survey of 18 mainstream news outlets logged 1,116 Bitcoin (BTC) stories and measured sentiment at 31% positive, 41% neutral, and 28% negative, according to Bitcoin analysis firm Perception.

The data reveal a significant gap between finance-focused media that cover the market extensively and legacy publications that rarely address it.

Sparse coverage

Perception counted two Bitcoin articles in The Wall Street Journal, 11 in the Financial Times, and 11 in The New York Times. These totals trailed every finance-oriented title in the sample and even lagged mid-tier general outlets. 

Audiences that rely on these newspapers for market intelligence received almost no information on an asset that outperformed broad indexes again in the quarter. The report referred to this mismatch as an “editorial blind-spot risk” because institutional investors may base their portfolio decisions on incomplete information.

High-volume business channels drove the most constructive coverage. Forbes produced 194 Bitcoin stories with a positive-to-negative ratio of roughly 1.8:1. At the same time, CNBC published 141 items at 2.5:1; and Fortune filed 117 pieces that leaned modestly positive.

These outlets focused on adoption metrics, exchange-traded funds (ETFs), treasury allocations, and mining economics, presenting Bitcoin as a viable macro asset rather than a novelty.

Negative framing clustered elsewhere. The Independent ran 45 stories with a 2.3:1 negative tilt, while Fox News and Barron’s delivered smaller volumes but similar skepticism, focusing on crime, cybersecurity breaches, and price volatility. 

Perception grouped coverage into three narrative blocs: enthusiastic adoption (Forbes, CNBC), willful minimalism (WSJ, FT, NYT), and persistent skepticism led by traditional general interest outlets.

Information asymmetry

According to the report, the divergence matters because large-cap digital assets now trade with liquidity comparable to some G-10 currencies, and exchange-listed spot ETFs cleared record volumes during the quarter. 

Asset managers that monitor only the low-volume publications may miss regulatory developments, fund flow data, and corporate treasury moves that the high-volume cohort documents in near real-time.

The report concluded that the coverage split creates both risk and opportunity: risk for institutions that depend on undersupplied channels and opportunity for readers who follow the outlets that closely track market mechanics. 

With sentiment and story counts quantifiable every quarter, portfolio teams can benchmark media exposure against price action and adjust their information sources accordingly.

]]>
https://earlybirdsinvest.com/survey-finds-gaps-in-mainstream-bitcoin-coverage-leaving-institutional-investors-exposed/feed/ 0 46543
War Wallets Exposed: 60 Crypto Operators Under Ukraine’s Gun https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/ https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/#respond Tue, 08 Jul 2025 06:30:22 +0000 https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

In a defiant move, Ukraine strikes at crypto routes fueling Russia’s war machine. The war-torn European country has unleashed a dramatic wave of sanctions designed to choke off the digital pipelines that have been fueling Russia’s military campaign.

President Volodymyr Zelenskyy signed Decree No. 465/2025, effectively freezing the assets and banning operations of 60 crypto firms—55 based in Russia and five scattered across Cyprus, Kazakhstan and the UAE.

This sweeping action is meant to send a strong message: crypto won’t be a safe haven for money that bankrolls conflict.

Sanctions Span Exchange Miners And Issuers

According to the decree, five crypto exchanges are accused of moving funds for sanctioned Russian entities. Nineteen mining operations have been caught processing coins linked to sanctioned individuals.

Seventeen platforms that issue digital assets already under US restrictions are now blocked in Ukraine. Another 19 companies—from makers of payment terminals to brokers arranging international transfers—face asset freezes and activity bans.

Ukraine didn’t stop at companies. The sanctions list also names 73 individuals, all Russian citizens, including high‑ranking central bank officials.

Based on reports from Ukraine’s National Security and Defense Council, these measures will be shared with allies like the EU and the US. That way, they can mirror the bans and tighten the grip on every channel Russia uses.

Total crypto market cap currently at $3.3 trillion. Chart: TradingView

Coordination With Allies Aims To Close Loopholes

Vladyslav Vlasiuk, Ukraine’s commissioner for Sanctions Policy, said Kyiv will urge its partners to adopt matching rules. The goal is to close every loophole Russia uses to fund its military.

Zelenskyy revealed that one single firm moved “several billion dollars” since January to support Russia’s military‑industrial complex. That figure shows why digital channels have become critical for sanctioned players.

New Stablecoin Highlights Growing Risks

Based on reports by the Financial Times and the Centre for Information Resilience, Russia’s crypto use is on the rise. A new stablecoin called A7A5, pegged to the ruble, moved over $9 billion in just four months on the Grinex exchange.

More than 12 billion A7A5 tokens now float in circulation, backed by roughly $156 million in reserves held at the US‑sanctioned Promsvyazbank. Only a few wallets handled most of that volume, showing how a small group can steer vast sums.

Meanwhile, five non‑Russian companies also made the list: Token Trust Holdings Limited in Cyprus, EXMO RBC Limited in Kazakhstan, AWX Solutions and Crypto Explorer DMCC in the UAE, and Bitpapa IC FZC in the UAE.

All five are already under US restrictions. Their inclusion highlights how sanctions evasion often relies on a global network of service providers.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/feed/ 0 46407
Billion-Dollar Bank Handing Thousands of Dollars To Data Breach Victim After Cybersecurity Incident Exposed Names, Social Security Numbers, Account Details https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/ https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/#respond Sat, 05 Jul 2025 18:07:43 +0000 https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/

Victims of a bank data breach are set to receive up to $3,000 each after a settlement was reached in a class action lawsuit.

According to the settlement administration portal, impacted customers at Arizona-based Evolve Bank & Trust who file a claim and provide documentary evidence of losses resulting from the data breach stand to receive up to $3,000.

A flat cash payment of $20 will also be available but claimants can only choose one or the other, not both.

“In addition to selection one of the Cash Payment options, Settlement Class Members may elect one (1) year of monitoring that will provide the following benefits: Credit Monitoring, real-time alerts, and insurance coverage for up to $1,000,000 for identity theft.”

Claims must be filed by October 30th. A final approval hearing of the settlement will be held on November 14th.

The lawsuit against Evolve Bank & Trust was filed in January and alleges that cybercriminals infiltrated the billion-dollar lender’s information systems and gained access to sensitive and confidential information.

In a notice to customers in July of 2024, Evolve Bank said the data breach had occurred between February and May of 2024.

“…it appears the criminals downloaded information from our databases and a file share that included names, Social Security numbers, bank account numbers, and contact information for most of our personal banking customers, as well as customers of our Open Banking partners. We have also learned that personal information relating to our employees was also likely affected.”

Evolve Bank & Trust, which started as First State Bank in 1925, is headquartered in West Memphis, Arizona. It boasts of around $1.6 billion in total assets and has five branches in the US.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/billion-dollar-bank-handing-thousands-of-dollars-to-data-breach-victim-after-cybersecurity-incident-exposed-names-social-security-numbers-account-details/feed/ 0 45953
16 Billion Exposed Passwords Give Hackers Blueprint to Drain Wallets – Crypto Security Alert https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/ https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/#respond Thu, 19 Jun 2025 21:43:02 +0000 https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/

Journalist

Hassan Shittu

Journalist

Hassan Shittu

About Author

Hassan, a Cryptonews.com journalist with 6+ years of experience in Web3 journalism, brings deep knowledge across Crypto, Web3 Gaming, NFTs, and Play-to-Earn sectors. His work has appeared in…

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

A recent data breach has exposed over 16 billion login credentials from online platforms, including Apple, Google, Facebook, Telegram, and GitHub.

The Cybernews research team, which uncovered the leak, described it as one of the largest credential dumps ever recorded, with serious implications for online users, crypto security, and digital asset management.

16B Login Records Leaked in Alarming Wave of Fresh Malware-Based Breaches

According to researchers, the breach is not a single incident but a combination of datasets collected from infostealer malware, credential stuffing attacks, and previously unreported leaks.

Some of these datasets contained up to 3.5 billion entries on their own, with the average dataset holding around 550 million records. The researchers have been tracking the data since early 2024, uncovering at least 30 exposed sets, many of them never publicly disclosed before.

“This is not just a leak—it’s a blueprint for mass exploitation,” the Cybernews team stated.

“With over 16 billion login records exposed, cybercriminals now have unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing,” they added.

The structure and recency of the data make the breach especially dangerous. Unlike older, recycled leaks, much of this data was harvested recently by modern info-stealing malware, posing an urgent crypto security threat to users.

The data typically includes login details organized by URL, along with associated usernames, passwords, cookies, and even tokens.

Some datasets point to specific services, such as Telegram, which was linked to a 60 million record dump.

Another, allegedly tied to the Russian Federation, held more than 455 million records. A number of entries also appear related to cloud services, government portals, and business accounts.

Most of the data was found in unsecured Elasticsearch databases and object storage instances. Though these were exposed for only a short period, it was long enough for researchers to copy the contents.

The origin of the datasets remains unclear, but experts believe that at least some were compiled by criminal actors.

Massive Credential Leaks cRaise Alarm for Crypto Users Amid Dark Web Sales

At this scale, credential leaks are a direct threat to crypto security. Attackers can deploy phishing scams, ransomware, business email compromise tactics, and unauthorized access to crypto wallets and trading platforms.

Users without multi-factor authentication (MFA) are especially vulnerable.

“The inclusion of both old and recent infostealer logs—often with tokens, cookies, and metadata—makes this data particularly dangerous for organizations lacking multi-factor authentication or credential hygiene practices,” researchers added.

While the full number of people affected is impossible to determine due to overlapping records, the scale means even a small success rate could translate into millions of compromised accounts.

Crypto users, in particular, are advised to act quickly. Since wallet services and exchanges often rely on credentials linked to mainstream email providers or cloud services, any breach could lead directly to asset theft.

Cybernews stressed the importance of basic cyber hygiene. Users should change passwords immediately, turn on MFA wherever possible, and scan their devices for malware.

“There’s little impact users can have on the existence of these leaks,” the research team noted, “but staying proactive with your own security remains the best defense.”

At the time of reporting, no single actor has claimed responsibility for the leaked databases.

But with new datasets emerging every few weeks, researchers say this reflects a growing trend of sophisticated infostealer operations that threaten the entire crypto security ecosystem.

For now, the leak stands as a stark reminder of how exposed digital life can be and how quickly stolen credentials can turn into real-world consequences.

This reminder can be corroborated with the recent incident of threat actors on the dark web allegedly selling personal data from users of major crypto exchanges Gemini and Binance, according to a March 27 report by cyber threat tracker Dark Web Informer.

A threat actor known as “AKM69” is claiming to offer 100,000 Gemini records, including names, emails, phone numbers, and location data, mostly from the U.S., U.K., and Singapore.

Another seller, “kiki88888,” listed 132,000 alleged Binance user records, though the source appears to be infostealer malware, not an exchange breach.

Though there’s no confirmed breach of the exchanges themselves, the incident shows the evolving threat to crypto security, with stolen credentials often repurposed for phishing, fraud, and wallet recovery scams.


]]>
https://earlybirdsinvest.com/16-billion-exposed-passwords-give-hackers-blueprint-to-drain-wallets-crypto-security-alert/feed/ 0 42989
147,116 Americans Hit by Massive Data Breach – Firm Says Unknown Attacker May Have Exposed Names, Addresses, Social Security Numbers and More https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/ https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/#respond Mon, 16 Jun 2025 11:18:35 +0000 https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/

A major cybersecurity incident at a healthcare firm may have exposed the sensitive personal and health records of more than 100,000 Americans.

In a new filing with the Office of the Maine Attorney General, North Carolina-based optical care firm Asheville Eye Associates says it discovered a serious data breach affecting 147,116 people.

In a statement, the firm says that an unknown attacker breached its systems and siphoned patient data from its network, including names, addresses, Social Security numbers, medical treatment reports and health insurance records.

“On January 31, 2025, Asheville Eye Associates (AEA) notified individuals that it had detected and stopped a network security incident. An unauthorized party gained access to our network and acquired certain files from our systems. We quickly engaged third-party specialists to assist us with securing the network environment and investigating the incident.

Since that time, AEA has completed a comprehensive review and investigation of the potentially affected records and systems. Through that subsequent investigation, which concluded on April 14, 2025, we identified additional individuals whose personal information was contained in the affected records.”

Asheville Eye Associates is a firm specializing in ophthalmology services, offering cataract surgery, laser surgery for glaucoma and diabetes, LASIK and other procedures to treat ophthalmic disorders.

The firm says it abruptly sent letters of notification to impacted individuals to provide more information about the cybersecurity incident, while offering access to free credit monitoring services to people whose Social Security numbers were compromised.

For now, Asheville Eye Associates says it has not detected any instance of identity theft related to the data breach.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/147116-americans-hit-by-massive-data-breach-firm-says-unknown-attacker-may-have-exposed-names-addresses-social-security-numbers-and-more/feed/ 0 42332