Stealing – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sun, 14 Sep 2025 22:57:24 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.9 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Stealing – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/ https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/#respond Sun, 14 Sep 2025 22:57:24 +0000 https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/

FBI cyber

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” reads the FBI’s FLASH advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”

UNC6040 was first disclosed by Google Threat Intelligence (Mandiant) in June, who warned that since late 2024, threat actors were using social engineering and vishing attacks to trick employees into connecting malicious Salesforce Data Loader OAuth apps to their company’s Salesforce accounts.

In some cases, the threat actors impersonated corporate IT support personnel, who used renamed versions of the application called “My Ticket Portal.”

Once connected, the threat actors used the OAuth application to mass-exfiltrate corporate Salesforce data, which was then used in extortion attempts by the ShinyHunters extortion group.

In these early data theft attacks, ShinyHunters told BleepingComputer that they primarily targeted the “Accounts” and “Contacts” database tables, which are both used to store data about a company’s customers.

These data theft attacks were widespread, impacting large and well-known companies, such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.

Later data theft attacks in August also targeted Salesforce customers, but this time utilized stolen Salesloft Drift OAuth and refresh tokens to breach customers’ Salesforce instances.

This activity is tracked as UNC6395 and is believed to have occurred between August 8th and 18th, with the threat actors using the tokens to target the company’s support case information that was stored in Salesforce.

The exfiltrated data was then analyzed to extract secrets, credentials, and authentication tokens shared in support cases, including AWS keys, passwords, and Snowflake tokens. These credentials could then be used to pivot to other cloud environments for additional data theft.

Salesloft worked with Salesforce to revoke all Drift tokens and required customers to reauthenticate to the platform.

It was later revealed that the threat actors also stole Drift Email tokens, which were used to access emails for a small number of Google Workspace accounts.

An investigation by Mandiant determined the attack originated in March, when Salesloft’s GitHub repositories were compromised, allowing attackers to ultimately steal the Drift OAuth tokens.

Like the previous attacks, these new Salesloft Drift data theft attacks impacted numerous companies,  including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and many more.

While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves “Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to “go dark” and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI’s E-Check background check system and Google’s Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/feed/ 0 58467
Private Banker Faces Lifetime Industry Ban After Allegedly Stealing $3,437,536 From Customer Accounts Over Three Years: OCC https://earlybirdsinvest.com/private-banker-faces-lifetime-industry-ban-after-allegedly-stealing-3437536-from-customer-accounts-over-three-years-occ/ https://earlybirdsinvest.com/private-banker-faces-lifetime-industry-ban-after-allegedly-stealing-3437536-from-customer-accounts-over-three-years-occ/#respond Sat, 21 Jun 2025 18:01:43 +0000 https://earlybirdsinvest.com/private-banker-faces-lifetime-industry-ban-after-allegedly-stealing-3437536-from-customer-accounts-over-three-years-occ/

The Office of the Comptroller of the Currency (OCC) is taking action against a former bank employee who allegedly stole millions of dollars from customer accounts.

The OCC says it’s issuing an order of prohibition against William Shane Garrow, the former senior vice president of private banking for a subsidiary of BOK Financial in Tulsa, Oklahoma.

Says the OCC,

“Between approximately March 17, 2021 and March 12, 2024, respondent misappropriated approximately $3,437,536 from multiple customers’ accounts under the bank’s custody for his personal benefit, without the customers’ knowledge or authorization.”

According to the OCC, Garrow engaged in unsafe and unsound practices and violations of law that resulted in significant losses for the bank.

The regulator has now banned Garrow from working at insured depository institutions, including banks and credit unions. The former bank executive is consenting to the issuance of the order without admitting or denying the OCC’s findings.

The OCC action comes after Garrow pleaded guilty to bank fraud and willfully making and subscribing a false Federal income tax return. Garrow was sentenced last month to 71 months in prison. He was also ordered to pay $3.86 million in restitution and $1.519 million to the IRS.

Prosecutors said Garrow directed fraudulent wire transfers and cashier’s checks from at least 16 client accounts to entities and bank accounts that he controlled. If a client asked about the transactions, Garrow blamed it on a banking error and would return the funds stolen or transfer money from another victim’s account.

Said US Attorney Clint Johnson last month,

“Garrow deceived people for over 12 years, and his actions wreaked havoc on banking personnel who were tasked with correcting his wrongs. This was not a simple banking error or an accident, but rather a criminal scheme. Garrow abused the trust given to him by the bank and its customers.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/private-banker-faces-lifetime-industry-ban-after-allegedly-stealing-3437536-from-customer-accounts-over-three-years-occ/feed/ 0 43333
Hackers now pose as security companies to frame victims while stealing private keys https://earlybirdsinvest.com/hackers-now-pose-as-security-companies-to-frame-victims-while-stealing-private-keys/ https://earlybirdsinvest.com/hackers-now-pose-as-security-companies-to-frame-victims-while-stealing-private-keys/#respond Mon, 02 Jun 2025 11:02:25 +0000 https://earlybirdsinvest.com/hackers-now-pose-as-security-companies-to-frame-victims-while-stealing-private-keys/

Cybercriminals are adopting increasingly deceptive tactics to target crypto users, with some now posing as blockchain security companies.

Their aim is to steal assets and implicate their victims in the process, making it harder for them to seek redress.

This evolution comes amid a sharp rise in crypto-related losses. In May 2025 alone, hackers and fraudsters drained over $244 million from users, according to blockchain security firm PeckShield.

That brings total year-to-date losses to more than $2 billion, underlining just how effective these schemes have become.

Security companies impersonators

Yu Xian, founder of blockchain security firm SlowMist, raised the alarm on June 1 after exposing a list of fraudulent X (formerly Twitter) accounts.

These accounts, he said, pretend to represent trusted security services while secretly working to compromise their targets.

He added:

“These are criminal gangs that claim to be able to help users solve security issues such as wallet theft, but then cause users to suffer secondary harm.”

These fraudsters often lure victims by commenting under public threads where users report wallet thefts. They then direct them to fake signature-checking tools.

The fake tools often mimic platforms like Revoke, creating confusion and urgency among users. Even when they cross-check with legitimate services, they might still fall victim, believing the phishing tool uncovered something the others missed.

SlowMist noted that these impersonators also copy the profiles of real security experts, such as ZachXBT, to gain trust. Their strategy relies on speed, panic, and believability, leaving little room for victims to think critically.

Considering this, Xian advised:

“I hope everyone will not be robbed. If you are accidentally robbed, you must remain calm and do not trust anyone easily.”

Victims are now being framed

Beyond stealing funds, some attackers now try to implicate their victims in their illicit activities.

Xian noted that scammers sometimes plant misleading clues to make the victim appear involved in fraudulent activity. According to him, these tactics are designed to frustrate law enforcement efforts and cause additional trauma for victims.

To counter this, Xian recommended that victims publicly share their wallet addresses, either fully or partially masked. Doing so could help investigators verify ownership and prevent misidentification during probes.

Mentioned in this article
]]>
https://earlybirdsinvest.com/hackers-now-pose-as-security-companies-to-frame-victims-while-stealing-private-keys/feed/ 0 39678
Hacker ‘NullBulge’ pleads guilty to stealing Disney’s Slack data https://earlybirdsinvest.com/hacker-nullbulge-pleads-guilty-to-stealing-disneys-slack-data/ https://earlybirdsinvest.com/hacker-nullbulge-pleads-guilty-to-stealing-disneys-slack-data/#respond Fri, 02 May 2025 02:23:16 +0000 https://earlybirdsinvest.com/hacker-nullbulge-pleads-guilty-to-stealing-disneys-slack-data/

Disney

A California man who used the alias “NullBulge” has pleaded guilty to illegally accessing Disney’s internal Slack channels and stealing over 1.1 terabytes of internal company data.

According to the U.S. Department of Justice, a 25-year-old named Ryan Kramer created a malicious program in early 2024 that was promoted as an AI image generation tool on GitHub and other platforms.

However, the DOJ says this program was actually malware that allowed Kramer to access the computer of those who installed it to steal data and passwords from the device.

According to the Wall Street Journal, one of the people who downloaded the program was a Disney employee, Matthew Van Andel, who executed it on his computer. This gave Kramer access to his device, including the passwords stored in his 1Password password manager.

Using Van Andel’s stolen credentials, Kramer gained access to Disney’s Slack channels, where he downloaded 1.1TB of corporate data.

“By accessing M.V.’s Disney Slack account, defendant gained access to non-public Disney Slack channels, and in or around May 2024, defendant downloaded approximately 1.1 terabytes of confidential data from thousands of Disney Slack channels,” reads a plea agreement seen by BleepingComputer.

The Department of Justice says that Kramer then contacted Van Andel, posing as a Russian hacktivist group called “NullBulge,” warning that his personal information and Disney’s stolen Slack data would be published if he didn’t cooperate.

After receiving no response, NullBulge posted a message on the BreachForums hacking forum on July 12, 2024, titled “DISNEY INTERNAL SLACK,” where he claimed to have breached Disney and leaked the 1.1TB of stolen data, including Van Andel’s personal info.

“1.1TiB of data. almost 10,000 channels, every message and file possible, dumped. Unreleased projects, raw images and code, some logins, links to internal api/ web pages, and more! Have fun sifting through it, there is a lot there,” reads the forum post.

In July 2024, defendant contacted M.V. via email and the online messaging platform Discord, pretending to be a member of a fake Russia-based hacktivist group called “NullBulge.” The emails and Discord message contained threats to leak M.V.’s personal information and Disney’s Slack data. One message defendant sent to M.V. on July 8, 2024, threatened that in order to “ensure this information remains undisclosed, I need your cooperation,” and warned that if M.V. contacted anyone about the message, “we will drop our data publicly and loudly without so much as a warning.” Defendant also threatened that this would be a “major, major mistake” for M.V.’s “information and career at Disney.” Another email sent to M.V. on July 12, 2024, with the subject line “You sure that’s how you want to play?”, stated, in part, “Respond, do what we want, or end up on the net. Your choice. We will not contact you again.”  On July 12, 2024, after M.V. did not respond to defendant’s threats, defendant publicly released the stolen Disney Slack files, as well as M.V.’s bank, medical, and personal information on multiple
Kramer’s Disney post on the BreachForum hacking forum
Source: BleepingComputer

Kramer has pleaded guilty to one count of accessing a computer and obtaining information and one count of threatening to damage a protected computer. Each charge carries a statutory maximum sentence of five years in federal prison.

He has also confirmed that two additional people downloaded his malware, allowing him to gain access to their computers. The FBI is currently investigating these additional people.

His initial court appearance in Los Angeles federal court is expected to be in the coming weeks.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/hacker-nullbulge-pleads-guilty-to-stealing-disneys-slack-data/feed/ 0 33905
Bitcoin Theft: UK NCA Officer Charged For Stealing 50 BTC https://earlybirdsinvest.com/bitcoin-theft-uk-nca-officer-charged-for-stealing-50-btc/ https://earlybirdsinvest.com/bitcoin-theft-uk-nca-officer-charged-for-stealing-50-btc/#respond Sun, 16 Mar 2025 00:46:22 +0000 https://earlybirdsinvest.com/bitcoin-theft-uk-nca-officer-charged-for-stealing-50-btc/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

The UK Crown Persecution Service (CPS) has filed charges against a law enforcement agent for allegedly stealing 50 Bitcoin (BTC) in 2017. This development comes amidst continuous efforts by the UK Government to deliver a crypto legislative framework.

National Crime Agency Officer Faces Jail Time Over £60,000 Bitcoin Theft

In a recent news post, Head of the CPS Special Crimes Division Malcolm McHaffie announced an indictment against National Crime Agency (NCA) officer Paul Chowles for the alleged theft of crypto assets worth £60,000 ($75,000). 

Chowles, a 42-year-old man from Bristol, is accused by Merseyside Police of misappropriating 50 Bitcoin during an active probe into online organized crime in 2017. Following the sporadic growth of the BTC market in recent years, the reported loot of 50 BTC is now valued at £3.2 million ($4.2 million).

According to a statement by McHaffie, the defendant now faces 15 counts of crime relating to this offence and is expected to appear at the Liverpool Magistrates’ Court on 25 April 2025.

The CPS Division Chief said:

Mr.Chowles, 42, is due to be charged with 11 offences of concealing, disguising, or converting criminal property, three offences of acquiring, using or possessing converting criminal property and a single count of theft. The Crown Prosecution Service reminds all concerned that criminal proceedings against this defendant are now active and that he has the right to a fair trial. It is extremely important that there should be no reporting, commentary or sharing of information online which could in any way prejudice these proceedings.

According to UK regulations, each count of money laundering i.e. concealing, disguising, or converting criminal property could result in a maximum penalty of 14 years in prison. Similarly, a single charge of acquiring, using, or possessing criminal property also carries a potential 14-year sentence. However, a conviction for theft carries a maximum sentence of seven years.

Therefore, If found guilty of the charges presented, Chowles could be looking at over 200 years in prison theoretically. Albeit, that is not unlikely as typical judicial rulings usually favor concurrent sentencing.

UK To Begin Consultation On Stablecoins

In other news, the UK Financial Conduct Authority (FCA) is expected to release consultation papers on stablecoin regulations before Q1 2025 in line with its crypto policy roadmap released in 2024. This initiative is to gain valuable insights on stablecoin concepts such as redemption and asset backing as the HM Treasury moves to introduce new regulated activities for fixed digital assets.

Amidst this exercise, the FCA will also release discussion papers on key concepts including lending, trading platforms, and staking as the UK continues to formulate its crypto regulatory framework which is planned for implementation in 2026.

At the time of writing, Bitcoin was trading at $84,391 following a 4.30% gain in the past day. 

Bitcoin
BTC trading at $84,475 on the daily chart | Source: BTCUSDT chart on Tradingview.com

Featured image from iStock, chart from Tradingview

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/bitcoin-theft-uk-nca-officer-charged-for-stealing-50-btc/feed/ 0 25375