<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Intruvent Edge]]></title><description><![CDATA[Intruvent Edge delivers clear, actionable Cyber Threat Intelligence (CTI) and defense insights so you can stay ahead of evolving cyber risks.]]></description><link>https://edge.intruvent.com</link><image><url>https://substackcdn.com/image/fetch/$s_!0A6w!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7bac430a-1ed6-4e39-8ade-7653ec098646_1024x1024.png</url><title>Intruvent Edge</title><link>https://edge.intruvent.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 25 May 2026 04:50:04 GMT</lastBuildDate><atom:link href="https://edge.intruvent.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Sig Murphy - Intruvent]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[intruvent@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[intruvent@substack.com]]></itunes:email><itunes:name><![CDATA[Sig Murphy]]></itunes:name></itunes:owner><itunes:author><![CDATA[Sig Murphy]]></itunes:author><googleplay:owner><![CDATA[intruvent@substack.com]]></googleplay:owner><googleplay:email><![CDATA[intruvent@substack.com]]></googleplay:email><googleplay:author><![CDATA[Sig Murphy]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Prevent This: Your Car Selling Your Driving Data]]></title><description><![CDATA[Welcome to Prevent This, our weekly community newsletter covering cybersecurity for everyone.]]></description><link>https://edge.intruvent.com/p/prevent-this-your-car-selling-your</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-your-car-selling-your</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 19 May 2026 16:48:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!kByA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Prevent This, our weekly community newsletter covering cybersecurity for everyone. If you found us through Intruvent Edge, our bi-weekly technical deep dive, welcome. Both live on the same Substack. Feel free to share either one. We&#8217;re glad you&#8217;re here.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p>Your car knows where you go, how fast you drive, how hard you brake, and what time you get home at night. And in millions of cases, your car manufacturer has been quietly selling that information to data brokers, who pass it to insurance companies, who use it to raise your premiums.</p><p>You probably did not agree to this. You may not even know it is happening. <strong>82% of connected car drivers have no idea how much data their vehicle collects.</strong> The FTC just took action against General Motors for doing exactly this. And GM is far from the only brand involved.</p><h2><strong>What Happened?</strong></h2><p>On January 14, 2026, the Federal Trade Commission finalized a consent order against General Motors and its OnStar subsidiary. The FTC found that GM had been collecting detailed driving behavior data from more than <strong>14 million vehicles</strong> and selling it to data brokers, specifically Verisk Analytics and LexisNexis Risk Solutions. Those data brokers then made the information available to insurance companies.</p><p>The data was granular. OnStar recorded <strong>precise geolocation every 3 seconds</strong>, hard braking, hard acceleration, speeding (anything over 80 mph was flagged), late-night driving patterns, trip times, and seatbelt usage. GM earned approximately <strong>$20 million </strong>from selling this data. Honda sold similar data for about $0.26 per car. The financial incentive for the manufacturer is modest. The financial impact on the driver can be anything but.</p><p>Your car is not the only device in your life with this problem. Smart TVs, fitness trackers, doorbell cameras, thermostats, and yes, even smart refrigerators collect data about your daily habits and routines. Your car just happens to be the one the FTC caught selling it to your insurance company. The principle is the same across every connected device you own: if it is connected to the internet, it is collecting data. The question is who else is seeing it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kByA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kByA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 424w, https://substackcdn.com/image/fetch/$s_!kByA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 848w, https://substackcdn.com/image/fetch/$s_!kByA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 1272w, https://substackcdn.com/image/fetch/$s_!kByA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kByA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:292063,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/198411709?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kByA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 424w, https://substackcdn.com/image/fetch/$s_!kByA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 848w, https://substackcdn.com/image/fetch/$s_!kByA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 1272w, https://substackcdn.com/image/fetch/$s_!kByA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F260172d2-6f39-40e2-a27f-42a180dd203d_1200x896.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>What Happened to Real People</strong></h3><p>When the New York Times investigated in 2024, they found consumers whose insurance premiums had increased by <strong>21% and 80%</strong> after their driving data was shared without their knowledge. One driver reported being <strong>rejected by seven insurers</strong>. Another discovered a <strong>258-page LexisNexis report</strong> documenting every trip they had taken for months.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6L41!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6L41!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6L41!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6L41!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6L41!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6L41!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:958957,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/198411709?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6L41!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!6L41!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!6L41!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!6L41!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdcfc040d-9748-4c92-a3fe-b57463883361_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A 2024 study found that only <strong>31% of drivers who participated in telematics programs</strong> (voluntarily or not) saw lower premiums. <strong>24% paid more.</strong> The rest saw no change, meaning the data collection provided no benefit to them but still created a permanent record of their driving behavior in a third-party database.</p><h2><strong>Why Should You Care?</strong></h2><p>This affects most people who drive a car manufactured in roughly the last decade. The Mozilla Foundation evaluated 25 major car brands for privacy in 2023. <strong>Every single one failed. </strong>Mozilla called cars &#8220;the worst product category for privacy we have ever reviewed.&#8221; For example, Nissan&#8217;s privacy policy claims the right to collect &#8220;sexual activity&#8221; and &#8220;genetic data.&#8221; Most brands reserve the right to share data with law enforcement without a warrant.</p><ul><li><p><strong>82%</strong> of connected car drivers don&#8217;t know how much data their car collects</p></li><li><p><strong>40%</strong> don&#8217;t even know they have connected services active in their vehicle</p></li><li><p><strong>96%</strong> of consumers say they should own the data their car generates</p></li><li><p>A modern connected car transmits <strong>1 to 1.5 gigabytes per day</strong> to the manufacturer&#8217;s cloud</p></li></ul><h2><strong>How Does This Work?</strong></h2><p>Think of your car as a smartphone on wheels. It has a cellular connection, a GPS receiver, and dozens of sensors. Every time you drive, the car records where you went, how you got there, and how you drove along the way. That data is transmitted to the manufacturer through the car&#8217;s built-in cellular connection.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B5f0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B5f0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B5f0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1028360,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/198411709?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B5f0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!B5f0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdad57975-a68a-4155-a5f9-e7e77bee40f9_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Historically, this data was used for services like navigation, crash detection, and remote diagnostics. Those are legitimate functions. The problem is that manufacturers began selling the same data to third parties, particularly data brokers who aggregate driving records and sell &#8220;risk profiles&#8221; to insurers.</p><p>Here is how the pipeline works:</p><ol><li><p><strong>Your car collects driving data</strong> (speed, braking, location, time of day) and transmits it to the manufacturer&#8217;s cloud.</p></li><li><p><strong>The manufacturer sells or shares the data</strong> with a data broker like Verisk or LexisNexis.</p></li><li><p><strong>The data broker builds a driving profile</strong> on you, which may include a risk score, trip history, and behavioral patterns.</p></li><li><p><strong>Your insurance company purchases or accesses the profile</strong> and uses it to adjust your premium at renewal, sometimes without telling you why your rate changed.</p></li></ol><p>The consent you gave was typically buried in the terms of service you accepted when you set up OnStar, FordPass, or Toyota Connected Services. The FTC found that GM&#8217;s enrollment process was designed to obscure the data-sharing, with consent bundled into multi-step flows that most consumers clicked through without reading.</p><h3><strong>Which Brands Are Doing This?</strong></h3><p>The brands that have been <strong>confirmed</strong> selling or sharing driving data with insurance-related data brokers include:</p><ul><li><p><strong>General Motors</strong> (OnStar, sold to Verisk and LexisNexis)</p></li><li><p><strong>Honda</strong> (sold to Verisk)</p></li><li><p><strong>Hyundai</strong> (shared with Verisk)</p></li><li><p><strong>Kia</strong> (shared with LexisNexis)</p></li><li><p><strong>Subaru</strong> (shared with LexisNexis)</p></li><li><p><strong>Mitsubishi</strong> (shared with LexisNexis)</p></li><li><p><strong>Ford</strong> (shared with Verisk)</p></li></ul><p>Verisk announced in early 2025 that it would stop collecting driving data from automakers. LexisNexis continues to operate its driving data program.</p><p>Toyota, Tesla, BMW, Mercedes-Benz, and other brands collect extensive driving data but the specifics of their third-party sharing arrangements are less well-documented. Their privacy policies broadly reserve the right to share data with &#8220;business partners&#8221; and &#8220;affiliates.&#8221;</p><h2><strong>What Can You Do?</strong></h2><h3><strong>Step 1: Find Out What Data Brokers Already Have on You</strong></h3><p>You have a legal right under the Fair Credit Reporting Act to request a free copy of your consumer file from data brokers. Two reports to request:</p><ul><li><p><strong>LexisNexis Consumer Disclosure:</strong> <a href="https://consumer.risk.lexisnexis.com/request">consumer.risk.lexisnexis.com/request</a>. This is the report that has documented 258-page driving histories for some consumers. Request it and see what they have.</p></li><li><p><strong>Verisk Consumer Report:</strong> <a href="https://fcra.verisk.com/">fcra.verisk.com</a>. Even though Verisk says they stopped collecting new data from automakers, they may still have your historical records.</p></li></ul><p>Both reports are free. They take about 15 minutes to request and typically arrive within 30 days.</p><h3><strong>Step 2: Check Your Vehicle&#8217;s Privacy Settings</strong></h3><p>You can also check what your specific car is sharing using <strong>Privacy4Cars</strong>, a free tool at <a href="https://vehicleprivacyreport.com/">VehiclePrivacyReport.com</a>. Enter your VIN and it tells you what data your car collects and shares.</p><h3><strong>Step 3: Opt Out of Data Sharing</strong></h3><p>Most manufacturers provide a way to opt out, though they do not make it easy. Here is how to do it for the most common brands:</p><ul><li><p><strong>GM/OnStar:</strong> Call OnStar (1-888-466-7827) or go to your OnStar account settings and disable &#8220;Connected Vehicle Data Sharing.&#8221; Under the FTC consent order, GM must now provide clear opt-out mechanisms and honor deletion requests.</p></li><li><p><strong>Ford:</strong> Open the FordPass app, go to Settings, then Privacy, and disable data sharing. You can also call Ford customer service.</p></li><li><p><strong>Toyota:</strong> Call Toyota Connected Services (1-800-331-4331) and request deactivation of data sharing. You can also manage settings through the Toyota app.</p></li><li><p><strong>Honda:</strong> Call 1-800-999-1009 and request opt-out from data sharing programs.</p></li><li><p><strong>Tesla:</strong> Go to Controls &gt; Software &gt; Data Sharing on the touchscreen and toggle off.</p></li><li><p><strong>Hyundai/Kia:</strong> Call Hyundai (1-800-633-5151) or Kia (1-800-333-4542) and request opt-out. You can also manage through the Bluelink or Kia Connect apps.</p></li></ul><p>A word of caution: opting out of data sharing may disable some connected features you use, like remote start, stolen vehicle tracking, or automatic crash notification. You will need to decide which features are worth the trade-off.</p><h3><strong>Step 4: Dispute Inaccurate Driving Data With Your Insurer</strong></h3><p>If you discover that a data broker has inaccurate driving data about you, or if your insurance premium increased and you suspect it was based on vehicle telematics data, you have the right to dispute it. Under the FCRA, both the data broker and the insurer must investigate disputes and correct inaccuracies. Contact your insurance company and ask directly: &#8220;Are you using telematics or driving behavior data in my rate calculation?&#8221;</p><h3><strong>Step 5: Wipe Your Data When You Sell Your Car</strong></h3><p>When you sell or trade in your vehicle, your personal data goes with it unless you manually remove it. Connected cars can store saved addresses (including your home and workplace), Wi-Fi passwords, contacts synced from your phone, garage door codes, credit card information from in-car payment systems, and your complete trip history.</p><p>Before handing over the keys:</p><ol><li><p>Perform a factory reset through the car&#8217;s settings menu</p></li><li><p>Remove the car from your manufacturer account (OnStar, FordPass, Toyota app, etc.)</p></li><li><p>Un-pair your phone from the Bluetooth system</p></li><li><p>Delete your home address and saved locations from the navigation system</p></li><li><p>Remove any stored garage door opener codes</p></li></ol><h2><strong>A Note on the Law</strong></h2><p>Three states have now banned this practice outright: <strong>Maryland</strong> (2024), <strong>Oregon </strong>(January 2026), and <strong>Virginia</strong> (effective July 2026). California imposed a $12.75 million CCPA penalty on GM, the largest CCPA penalty ever. The Texas Attorney General sued multiple automakers over data collection affecting 45 million Americans. There is no federal law prohibiting this. If you do not live in one of those three states, opting out directly with the manufacturer is your only protection.</p><p><strong>One more thing: rental cars.</strong> Roughly 90% of rental vehicles have GPS tracking and store the data for months. When you return a rental, disconnect your phone from Bluetooth, delete your navigation history, and sign out of any accounts on the infotainment system.</p><h2><strong>The Bottom Line</strong></h2><p>Your car is one of the most prolific data collectors in your life, and until recently, most manufacturers were sharing that data without meaningful consent. The FTC&#8217;s action against GM is a start, but it only covers one company. The driving data that has already been collected and sold is sitting in broker databases and may already be influencing your insurance rates.</p><p>Four things to do to address this:</p><ol><li><p><strong>Request your LexisNexis report</strong> at <a href="https://consumer.risk.lexisnexis.com/request">consumer.risk.lexisnexis.com/request</a>. Find out what they have on you. It is free.</p></li><li><p><strong>Check your car&#8217;s privacy settings</strong> using <a href="https://vehicleprivacyreport.com/">VehiclePrivacyReport.com</a>. Enter your VIN.</p></li><li><p><strong>Opt out of data sharing</strong> through your manufacturer&#8217;s app or by calling them directly.</p></li><li><p><strong>Ask your insurer</strong> whether they are using telematics or driving behavior data in your rate calculation.</p></li></ol><p>You probably gave your car permission to do this when you tapped &#8220;Agree&#8221; on a screen during setup. Now you know what you agreed to. Share this with anyone who drives.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-your-car-selling-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-your-car-selling-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-your-car-selling-your?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><div><hr></div><h2><strong>Sources</strong></h2><ul><li><p><a href="https://www.ftc.gov/news-events/news/press-releases/2026/01/ftc-finalizes-order-settling-allegations-gm-onstar-collected-sold-geolocation-data-without-consumers">FTC: Order settling GM/OnStar geolocation data allegations</a> (January 14, 2026)</p></li><li><p><a href="https://foundation.mozilla.org/en/privacynotincluded/categories/cars/">Mozilla Foundation: Privacy Not Included, Cars</a> (2023)</p></li><li><p><a href="https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html">New York Times: Carmakers Are Sharing Driver Data With Insurers</a> (March 2024)</p></li><li><p><a href="https://consumer.risk.lexisnexis.com/request">LexisNexis: Consumer Disclosure Request</a></p></li><li><p><a href="https://fcra.verisk.com/">Verisk: Consumer Report Request</a></p></li><li><p><a href="https://vehicleprivacyreport.com/">Privacy4Cars: Vehicle Privacy Report</a></p></li><li><p><a href="https://consumer.ftc.gov/consumer-alerts/2026/05/new-trends-reports-imposter-scams">FTC: New Trends in Imposter Scams</a> (May 7, 2026)</p></li></ul><div><hr></div><p><em>Prevent This is a weekly cybersecurity newsletter from Intruvent Technologies. Each week, we break down one cyber threat in plain language and give you the tools to protect yourself and the people you care about. For our bi-weekly technical deep dive, check out <a href="https://edge.intruvent.com/">Intruvent Edge</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[Intruvent EDGE: The First AI-Generated Zero-Day Just Dropped. Here’s What We Know.]]></title><description><![CDATA[A zero-day discovered by AI, written by AI, and deployed in the wild. Welcome to the new timeline.]]></description><link>https://edge.intruvent.com/p/intruvent-edge-the-first-ai-generated</link><guid isPermaLink="false">https://edge.intruvent.com/p/intruvent-edge-the-first-ai-generated</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 14 May 2026 19:31:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Z4-8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Intruvent Edge, our bi-weekly technical deep dive into a current cyber threat. If you found us through Prevent This, our weekly community newsletter covering cybersecurity for everyone, you&#8217;re in the right place. Both live on the same Substack. Feel free to share either one. We&#8217;re glad you&#8217;re here.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>The Short Version</strong></p><p><strong>For the first time, a criminal hacking group used artificial intelligence to find a security flaw that nobody knew existed, write the code to exploit it, and deploy that code against real targets.</strong> The AI tool handled the entire exploit lifecycle by itself.  Google&#8217;s security team caught it, worked with the affected software vendor to fix the flaw, and shut the operation down.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z4-8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z4-8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z4-8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:138304,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197729511?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z4-8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!Z4-8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9585abd1-41b1-4754-a84d-77ea2417a560_1024x1024.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>This matters because it changes the math on how quickly attackers can move. Finding and exploiting unknown security flaws used to require deep expertise and significant time. AI compresses both</strong>. If you run a business, manage IT infrastructure, or make decisions about technology risk, this article explains what happened, what it means, and what you should be paying attention to going forward.</p><h2><strong>Some Quick Definitions</strong></h2><p>Before we go further, a few terms that will come up throughout:</p><ul><li><p><strong>Zero-day:</strong> A security flaw in software that the software maker does not yet know about. The name comes from the idea that developers have had &#8220;zero days&#8221; to fix it. These are the most dangerous type of vulnerability because there is no patch available when attackers start using them.</p></li><li><p><strong>Exploit:</strong> A piece of code designed to take advantage of a specific flaw. Think of the flaw as an unlocked window. The exploit is the burglar who knows exactly which window and how to climb through it.</p></li><li><p><strong>Two-factor authentication (2FA):</strong> The second verification step when you log in, typically a code sent to your phone or generated by an app. The flaw in this case allowed attackers to skip that second step entirely.</p></li><li><p><strong>CVE:</strong> A standardized ID number assigned to known security flaws, like a case number. When the security community refers to &#8220;CVE-2026-31431,&#8221; everyone knows exactly which flaw is being discussed.</p></li><li><p><strong>APT (Advanced Persistent Threat):</strong> A government-sponsored hacking team. These are professional, well-funded groups that conduct cyber operations on behalf of nation-states. They are named and tracked by the security industry the way intelligence agencies track foreign operatives.</p></li></ul><h2><strong>What Happened</strong></h2><p>On May 11, 2026, Google&#8217;s Threat Intelligence Group (their security research division, often shortened to GTIG) published a report tracking how threat actors are using AI. Among dozens of findings, one stood out: <strong>a criminal hacking group used an AI model to discover a previously unknown security flaw and write a working exploit for it.</strong></p><p>The exploit is a Python script that bypasses two-factor authentication on a popular, widely used system administration tool. The underlying flaw is a hard-coded trust assumption in the software&#8217;s login process. In plain terms: the software was programmed to trust certain login attempts automatically, skipping the second verification step. The AI found that blind spot and wrote the code to walk through it.</p><p>Google identified the exploit in active use, coordinated with the software vendor to get the flaw patched, and disrupted the operation before it could spread further.</p><h3><strong>How Did Google Know AI Was Involved?</strong></h3><p>The exploit code contained telltale signs of AI authorship, the digital equivalent of a forged painting that uses pigments that did not exist when the original was supposedly created. Specifically:</p><ul><li><p><strong>Excessive documentation:</strong> The code included detailed explanatory notes throughout, the kind a teacher would write for a student. Real attackers do not document their exploits. They want their code to be hard to understand, not easy.</p></li><li><p><strong>A fabricated severity score:</strong> The code included a CVSS score (a standardized severity rating, like a hurricane category for software flaws) that the AI made up. The score did not correspond to any real entry in the vulnerability database.</p></li><li><p><strong>Textbook code structure:</strong> The code was organized with a precision and readability that prioritized clarity over stealth. Human exploit developers optimize for evasion. AI optimizes for correctness.</p></li><li><p><strong>Built-in help menus:</strong> The exploit included usage instructions. No human attacker builds a help menu into their attack tool.</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Jfie!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Jfie!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Jfie!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:367240,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197729511?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Jfie!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Jfie!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F290dfe27-5353-4392-8e62-4d27385a1bbc_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Google stated there was no evidence that its own Gemini AI was used, and assessed with high confidence that an AI model was involved. The specific model and the specific group remain undisclosed.</p><h2><strong>Three Findings, Three Actors: Getting the Story Right</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dpbP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dpbP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dpbP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1030672,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197729511?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dpbP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!dpbP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f431a0f-f318-4a45-bc6b-e2fd0a523621_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Several publications reported this story as &#8220;North Korea used AI to build a zero-day.&#8221; That is not what Google said. The GTIG report contains three distinct findings involving three different groups doing three different things. Conflating them creates a misleading picture. Here is what actually happened:</p><p><strong>Finding 1: The AI-generated zero-day.</strong> An unnamed group of cybercrime actors used an AI model to discover a zero-day and write a working exploit. Google caught it in active use and shut it down. The group, the model, and the target product remain undisclosed. This is the headline finding.</p><p><strong>Finding 2: North Korea&#8217;s APT45 using AI to research vulnerabilities at scale. </strong>Separately, Google found that a North Korean government hacking team called APT45 (also known as Andariel) sent &#8220;thousands of repetitive prompts&#8221; to AI models, asking them to analyze known security flaws and validate whether existing proof-of-concept exploits actually work. Think of it as using AI to do the research grunt work: reading thousands of vulnerability reports and testing whether the published attack code is functional. This is a serious capability, but it is vulnerability research, not zero-day creation. APT45 did not produce the AI-generated zero-day in Finding 1.</p><p><strong>Finding 3: China&#8217;s APT27 using AI to build operational tools.</strong> A Chinese government hacking team called APT27 (also known as Threat Group-3390) used Google&#8217;s Gemini to write a fleet management application for their proxy network. A proxy network is a series of relay points that attackers route their traffic through to hide their real location, like forwarding mail through multiple PO boxes so the return address cannot be traced. APT27 used AI to build the software that manages those relay points. This is software engineering, not exploit development.</p><p><strong>The distinction matters.</strong> One unnamed criminal group created an AI-generated zero-day. A North Korean government team is using AI to accelerate vulnerability research. A Chinese government team is using AI to build infrastructure tools. All three are significant. None of them should be described as the same thing.</p><h2><strong>Why This Matters</strong></h2><p>The security industry has debated whether AI would be used for exploit development since ChatGPT launched in late 2022. That debate is settled. The question now is how fast this scales.</p><p>Three dynamics make this consequential for anyone who manages technology risk:</p><h3><strong>1. The Clock Is Faster Now</strong></h3><p>When a security flaw is discovered and publicly disclosed, a race begins. Defenders race to install the patch. Attackers race to build an exploit before the patch is applied. Historically, building a working exploit took days to weeks of skilled manual work. AI compresses that timeline.</p><p>In April, a security research team demonstrated this directly: they used AI-assisted analysis to turn a newly disclosed Linux kernel vulnerability (the &#8220;Copy Fail&#8221; flaw we covered in our <a href="https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root-a">April 30 newsletter</a>) into a complete attack chain in approximately one hour. Google&#8217;s finding confirms that criminal groups are achieving similar speeds.</p><p>For organizations that patch on a monthly cycle, this is a problem. When the time from disclosure to exploit drops from weeks to hours, a monthly patch schedule means spending most of the month exposed.</p><h3><strong>2. The Expertise Barrier Is Lower</strong></h3><p>Building exploits used to require rare, specialized skills. Google&#8217;s report describes APT45&#8217;s approach as &#8220;thousands of repetitive prompts&#8221; rather than sophisticated engineering. That is not an elite technique. It is a volume play, like running a thousand internet searches instead of crafting one perfect query.</p><p>The AI artifacts in the zero-day exploit (the help menus, the documentation, the fabricated severity score) suggest the developer leaned heavily on the AI&#8217;s raw output rather than refining it. That implies someone with moderate technical skills, not a world-class exploit developer, produced a working zero-day with AI assistance.</p><p>The analogy in other fields: it is the difference between needing a board-certified specialist for a procedure versus a general practitioner with the right diagnostic tool. The tool does not replace expertise entirely, but it lowers the bar for who can produce a competent result.</p><h3><strong>3. The Trajectory Is Clear and Accelerating</strong></h3><p>Google has now published three AI Threat Tracker reports. Each one documents capabilities that were theoretical in the previous edition:</p><ul><li><p><strong>Early 2024:</strong> Attackers used AI mostly for writing phishing emails and generating basic code. Think of this as using AI as a research assistant.</p></li><li><p><strong>November 2025:</strong> Google discovered experimental malware called PROMPTFLUX that queried an AI model to rewrite its own code hourly, changing its appearance to avoid detection. The malware was still in testing, but it proved the concept of using AI as a live mutation engine.</p></li><li><p><strong>April 7, 2026:</strong> Anthropic (the company behind the Claude AI) disclosed that its Mythos model discovered over 2,000 previously unknown security flaws in seven weeks during internal testing, including bugs that had gone undetected for 17 and 27 years. Anthropic restricted Mythos&#8217;s release because of its offensive potential.</p></li><li><p><strong>May 11, 2026:</strong> Google confirmed the first AI-assisted zero-day exploit used in a real-world criminal operation.</p></li></ul><p>Each milestone arrived faster than the previous one. The gap between Anthropic&#8217;s controlled testing disclosure and a real-world AI-generated exploit in the wild was approximately one month.</p><h2><strong>What Else Was in the Report</strong></h2><p>The zero-day was the headline, but Google&#8217;s full report documents AI being integrated across every phase of cyberattack operations:</p><ul><li><p><strong>Autonomous phone malware:</strong> Android malware called PROMPTSPY uses an AI model to navigate a phone&#8217;s screen and replay biometric data without human guidance. This is malware that can operate your phone by itself.</p></li><li><p><strong>AI-generated decoy documents:</strong> Russian-linked actors are using AI to produce convincing fake documents for phishing campaigns targeting Ukraine. AI makes the lure material faster and more believable at scale.</p></li><li><p><strong>AI voice cloning for impersonation:</strong> A pro-Russia influence operation used AI-generated voice clones to impersonate journalists.</p></li><li><p><strong>Software supply chain attacks:</strong> A group called TeamPCP compromised popular security scanning tools (Trivy, Checkmarx, LiteLLM), affecting over 1,000 business software environments.</p></li><li><p><strong>Autonomous reconnaissance:</strong> Chinese actors deployed AI-powered tools called Hexstrike and Strix that can scan and map target networks without human direction.</p></li></ul><p>The pattern is consistent. AI is not being used for one thing. It is being used for everything: research, reconnaissance, exploit development, malware creation, phishing, impersonation, and infrastructure management.</p><h2><strong>The Actors Behind This</strong></h2><h3><strong>APT45 / Andariel (North Korea)</strong></h3><p>APT45 is a hacking team that operates under North Korea&#8217;s military intelligence agency, the Reconnaissance General Bureau. The security industry also tracks them as Andariel, Silent Chollima, and Onyx Sleet. They are a sub-unit of the Lazarus Group, the umbrella organization behind North Korea&#8217;s most prominent cyber operations (Intruvent Codex; MITRE ATT&amp;CK G0138).</p><p>APT45 has been active since at least 2015. Their primary mission is generating revenue for North Korea&#8217;s weapons programs through ransomware, cryptocurrency theft, and extortion. They target defense contractors, financial institutions, and government agencies. They have also targeted hospitals with ransomware (the Maui campaign) and conducted espionage against nuclear research programs.</p><p>Google&#8217;s report reveals that APT45 is now using AI at an industrial scale to analyze security flaws and test whether published exploits actually work. Their approach (sending thousands of repetitive prompts, using automated testing tools in practice environments) suggests they have built AI into their standard research workflow. This is not an experiment. It is how they operate now.</p><h3><strong>APT27 / Threat Group-3390 (China)</strong></h3><p>APT27 is a Chinese government espionage group that has been active since at least 2010. The security industry tracks them under a long list of names: Threat Group-3390, Emissary Panda, BRONZE UNION, Iron Tiger, and LuckyMouse (Intruvent Codex; MITRE ATT&amp;CK G0027). The US Department of Justice indicted members of the group in 2020.</p><p>APT27 is one of the more technically sophisticated state-sponsored groups. The Intruvent Codex maps them to 57 distinct attack techniques and 24 malware families. They target defense, government, energy, manufacturing, and technology organizations.</p><p>Google&#8217;s finding that APT27 used Gemini to build a proxy network management tool is significant because it shows AI being used for operational plumbing, not just flashy capabilities. They needed a piece of software to manage their network of relay servers (which disguise the origin of their attacks by routing traffic through multiple hops, including consumer-grade 4G/5G connections). Instead of writing it from scratch, they had an AI build it. It is the cyber equivalent of hiring a contractor through an app instead of building the addition yourself.</p><h2><strong>What Should Organizations Do?</strong></h2><h3><strong>Patch Faster</strong></h3><p>If your organization patches software on a monthly cycle, this report is a signal to reassess. When AI can analyze a published security flaw and produce an exploit in hours, a 30-day patch window means spending most of the month with a known, exploitable weakness. For systems that face the internet (web servers, VPNs, email gateways, login portals), the target should be patching critical flaws within 24 to 72 hours of disclosure, not 30 days.</p><h3><strong>Know What AI-Written Exploits Look Like</strong></h3><p>The AI fingerprints Google identified (excessive documentation, fabricated severity scores, textbook code structure, help menus) are a temporary detection opportunity. If your security team investigates an incident and finds exploit code on a compromised system, these patterns can help determine whether AI was involved. Think of it like identifying a counterfeiter: the first generation of AI-generated exploits has tells that experienced analysts can spot. Those tells will fade as attackers learn to clean up after their AI, but right now, they are useful.</p><h3><strong>Audit Your Two-Factor Authentication</strong></h3><p>The specific zero-day exploited a flaw in how a product implemented two-factor authentication. The software had a built-in exception that trusted certain login attempts without requiring the second step. These kinds of shortcuts are common in software development (they make testing easier, or they accommodate legacy systems), and they are exactly the kind of subtle flaw that AI is good at finding.</p><p>Ask your IT team or security vendor: are there any conditions under which our two-factor authentication can be bypassed? Is there a fallback path that skips the second factor? Are there API endpoints (programmatic access points) that do not enforce it?</p><h3><strong>Prepare for More Exploits, Faster</strong></h3><p>APT45&#8217;s &#8220;thousands of repetitive prompts&#8221; approach is a preview. When vulnerability research becomes a volume game played by AI, the number of working exploits for known flaws will increase and the time between a flaw being disclosed and an exploit being available will decrease. Your security team should be planning for a world where every major vulnerability has a working exploit within days of disclosure, not weeks or months.</p><h2><strong>The Bigger Picture</strong></h2><p>The security industry has spent three years debating whether AI would be used to build cyberweapons. Google&#8217;s report ends that debate. It is happening. The first AI-assisted zero-day was caught in active use. The next one may not be caught at all.</p><p>The trajectory from Anthropic&#8217;s controlled disclosure of 2,000+ AI-discovered flaws in April to a real-world AI-generated exploit in May is a one-month gap. The trajectory from APT45&#8217;s brute-force approach to something more refined is measured in AI model generations, not years. The models themselves are improving faster than defensive tooling is adapting.</p><p>There is a silver lining. The exploit Google caught was identifiable precisely because AI leaves fingerprints that human developers do not. The help menus, the documentation, the fabricated scores: these are artifacts of an AI trying to be helpful in a context where helpfulness is a tell. That detection window is real, but it is closing. As models improve and attackers learn to strip the artifacts, the fingerprints will fade.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-the-first-ai-generated?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-the-first-ai-generated?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/intruvent-edge-the-first-ai-generated?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>For decision-makers, the takeaway is straightforward: the speed and scale at which attackers can find and exploit security flaws just changed. The organizations that adapt their patching speed, their detection capabilities, and their risk models to reflect this new reality will be in a stronger position than those that treat it as a future problem. The future arrived last Sunday.</p><div><hr></div><h2><strong>Sources</strong></h2><ul><li><p><a href="https://thehackernews.com/2026/05/hackers-used-ai-to-develop-first-known.html">The Hacker News: Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation</a> (May 11, 2026)</p></li><li><p>Google Threat Intelligence Group, <em>AI Threat Tracker, Third Edition</em> (May 11, 2026)</p></li><li><p><a href="https://thehackernews.com/2025/11/google-uncovers-promptflux-malware-that.html">The Hacker News: Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly</a> (November 5, 2025)</p></li><li><p><a href="https://thehackernews.com/2026/04/anthropics-claude-mythos-finds.html">The Hacker News: Anthropic&#8217;s Claude Mythos Finds Thousands of Zero-Day Flaws</a>(April 7, 2026)</p></li><li><p>Intruvent Technologies, <em>Golden CTI Database (Codex)</em>: Andariel (G0138), Threat Group-3390 (G0027), Lazarus Group (G0032), queried May 14, 2026</p></li><li><p>MITRE ATT&amp;CK: <a href="https://attack.mitre.org/groups/G0138/">Andariel (G0138)</a>, <a href="https://attack.mitre.org/groups/G0027/">Threat Group-3390 (G0027)</a></p></li><li><p><a href="https://xint.io/blog/copy-fail-linux-distributions">Xint Code: Copy Fail, 732 Bytes to Root</a> (April 29, 2026)</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Prevent This: The Phishing Email That Actually Comes From Apple]]></title><description><![CDATA[Scammers found a way to send phishing emails from Apple's own servers. Here's how to spot them.]]></description><link>https://edge.intruvent.com/p/prevent-this-the-phishing-email-that</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-the-phishing-email-that</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 12 May 2026 16:30:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KXqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Welcome to Prevent This, our weekly community newsletter covering cybersecurity for everyone.</strong> If you found us through Intruvent Edge, our bi-weekly technical deep dive, welcome. Both live on the same Substack. Feel free to share either one. We&#8217;re glad you&#8217;re here.  Please share this newsletter if you find it useful.</p><div><hr></div><p>You know the drill. <strong>You get a suspicious email, you check the sender address, and if it looks fake, you delete it.</strong> That one simple habit has protected millions of people from phishing scams for years.</p><p><strong>It doesn&#8217;t work anymore.</strong></p><p>Scammers have figured out how to send phishing emails that genuinely come from Apple&#8217;s own servers. The sender address is real. The email authentication checks all pass. Your spam filter waves it right through. And the message inside tells you that someone just bought an $899 iPhone with your Apple account.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Your heart rate spikes. You call the number in the email. And now you&#8217;re talking to a scammer.</p><h2><strong>What Happened?</strong></h2><p>In April 2026, security researchers at BleepingComputer and Malwarebytes documented a phishing technique that abuses Apple&#8217;s own notification system to deliver scam emails from Apple&#8217;s legitimate email address: <strong>appleid@id.apple.com</strong>.</p><p><strong>These emails are not spoofed. They are not faked. They are real Apple notifications, triggered by real Apple systems, delivered from real Apple servers.</strong> Every email authentication check (SPF, DKIM, DMARC, for the technically curious) passes with flying colors. Gmail, Outlook, Yahoo, and every other email provider treat them as legitimate because they are.</p><p>The scam has already cost people real money. Dorothy, a woman in her 60s, received one of these emails in early April. A scammer who already knew her personal details convinced her over the phone that her accounts had been compromised. He coached her through a series of steps and told her to drive to the bank to withdraw $15,000. A bank teller recognized the signs and intervened before Dorothy handed over the cash.</p><p>Not everyone is that lucky.</p><h2><strong>Why Should You Care?</strong></h2><ul><li><p>Apple has <strong>2.5 billion active devices</strong> worldwide. If you own an iPhone, iPad, Mac, or Apple Watch, you are a potential target.</p></li><li><p>Apple is now the <strong>#2 most impersonated brand</strong> in phishing attacks, accounting for 11% of all phishing attempts in Q1 2026 (Check Point Research).</p></li><li><p>At least <strong>five distinct Apple scam campaigns</strong> were running concurrently in April 2026.</p></li><li><p>Tech support scams (the category this falls into) cost Americans <strong>$924.5 million in 2023</strong> alone (FTC). Vishing (voice phishing) attacks increased <strong>442%</strong> in 2024.</p></li><li><p>Apple has <strong>not acknowledged or patched</strong> the flaw that makes this possible.</p></li></ul><h2><strong>How Does This Work?</strong></h2><p>Think of Apple&#8217;s notification system like an automated receptionist. When you update your account information, the receptionist sends you a polite confirmation email: &#8220;Hi [Your Name], your Apple Account was updated.&#8221;</p><p>The receptionist doesn&#8217;t check what your name actually says. It just reads whatever is in the name field and puts it in the email.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KXqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KXqy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KXqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:968195,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197356027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KXqy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!KXqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaed697-f2ef-4eb6-8be3-565bc0e1ccbd_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Scammers figured this out. Here&#8217;s what they do:</p><ol><li><p><strong>Create a new Apple ID</strong> using a throwaway email address.</p></li><li><p><strong>Set the first name</strong> to something like: &#8220;User 899 USD iPhone Purchase Via&#8221;</p></li><li><p><strong>Set the last name</strong> to something like: &#8220;Pay-Pal To Cancel Call 1-802-353-0761&#8221;</p></li><li><p><strong>Change the shipping address</strong> on the account. This triggers Apple&#8217;s automated notification system.</p></li><li><p>Apple&#8217;s servers dutifully send out an email that reads: <strong>&#8220;Dear User 899 USD iPhone Purchase Via Pay-Pal To Cancel Call 1-802-353-0761, your Apple Account was used to sign in...&#8221;</strong></p></li></ol><p>The email lands in your inbox looking like a legitimate Apple alert. Because it is one. The scam message is smuggled inside Apple&#8217;s own greeting line.</p><p>If you call the number, you reach a scammer running a tech support con. They will tell you your account has been compromised. They will ask you to install remote access software, hand over login credentials, or (like Dorothy&#8217;s case) withdraw cash.</p><p><strong>The reason this works so well is that it weaponizes the one thing you were taught to trust: the sender address.</strong> Every guide, every tip sheet, every cybersecurity awareness training tells you to &#8220;check the sender.&#8221; When the sender is actually Apple, that advice breaks down.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1VcC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1VcC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1VcC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:313414,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197356027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1VcC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!1VcC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa669002a-cdd3-4f6a-9d58-5667c2237ef6_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>What Can You Do?</strong></h2><h3><strong>Step 1: Never Call a Phone Number From an Email</strong></h3><p>This is the single most important rule. Apple will <strong>never</strong> put a phone number in an email and ask you to call it. Neither will your bank, the IRS, or any legitimate company. If an email includes a phone number and urgency, treat it as a scam by default. If you want to call Apple, go to <a href="https://support.apple.com/">support.apple.com</a> and find the number yourself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I3hH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I3hH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I3hH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:50223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/197356027?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I3hH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!I3hH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fde6287-3ec0-4a5c-b581-f1cccda8ba96_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3><strong>Step 2: Check Your Actual Purchases</strong></h3><p>If you get an email claiming someone bought a $899 iPhone with your account, do not click anything in the email. Instead:</p><ul><li><p><strong>On your iPhone or iPad:</strong> Open Settings, tap your name at the top, tap Subscriptions or Media &amp; Purchases. Check your purchase history directly.</p></li><li><p><strong>On a computer:</strong> Go to <a href="https://reportaproblem.apple.com/">reportaproblem.apple.com</a> and sign in. This shows every real purchase on your account.</p></li><li><p><strong>Check your bank or credit card statement.</strong> If there&#8217;s no $899 charge, there was no $899 purchase. Close the email.</p></li></ul><h3><strong>Step 3: Read the Email Carefully</strong></h3><p>Even though these emails come from a real Apple address, the scam text is stuffed into the greeting line. Legitimate Apple emails address you by your actual name. If the greeting reads like a sentence fragment about a purchase or a phone number to call, that is the tell. Real Apple notifications say &#8220;Dear [Your Name],&#8221; not &#8220;Dear User 899 USD iPhone Purchase Via Pay-Pal.&#8221;</p><h3><strong>Step 4: Turn On Two-Factor Authentication</strong></h3><p>If you have not already, enable two-factor authentication on your Apple account. This protects you even if a scammer somehow gets your password.</p><ul><li><p><strong>iPhone/iPad:</strong> Settings &#8594; [Your Name] &#8594; Sign-In &amp; Security &#8594; Two-Factor Authentication</p></li><li><p><strong>Mac:</strong> System Settings &#8594; [Your Name] &#8594; Sign-In &amp; Security &#8594; Two-Factor Authentication</p></li></ul><h3><strong>Step 5: Report It</strong></h3><p>Forward phishing emails to <strong>reportphishing@apple.com</strong>. Apple does investigate these reports, and enough reports from users may push them to fix the name-field vulnerability that makes this attack possible.</p><p>You can also report the scam to the FTC at <a href="https://reportfraud.ftc.gov/">reportfraud.ftc.gov</a>.</p><h2><strong>The Bottom Line</strong></h2><p>&#8220;Check the sender address&#8221; used to be reliable advice. For this scam, the sender address is legitimate. The email is legitimate. The only thing that is fake is the message smuggled into the greeting line.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-the-phishing-email-that?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-the-phishing-email-that?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-the-phishing-email-that?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>Three things to remember:</p><ol><li><p><strong>Never call a phone number from a suspicious email.</strong> Look up the number yourself.</p></li><li><p><strong>Verify purchases directly.</strong> Check your account or your bank statement, not the email.</p></li><li><p><strong>Read the greeting line.</strong> If your name looks like a sentence about a purchase, delete the email.</p></li></ol><p>Apple has 2.5 billion devices in the world and has not yet fixed this flaw. Until they do, you are your own last line of defense. Share this with anyone who uses Apple products.</p><div><hr></div><h2><strong>Sources</strong></h2><ul><li><p><a href="https://www.bleepingcomputer.com/news/security/apple-account-change-alerts-abused-to-send-phishing-emails/">BleepingComputer: Apple account change alerts abused to send phishing emails</a> (April 2026)</p></li><li><p><a href="https://www.malwarebytes.com/blog/news/2026/04/real-apple-notifications-are-being-used-to-drive-tech-support-scams">Malwarebytes: Real Apple notifications used to drive tech support scams</a> (April 2026)</p></li><li><p><a href="https://www.tomsguide.com/computing/online-security/scammers-are-weaponizing-apples-own-notifications-in-a-dangerous-new-phishing-attack-dont-fall-for-this">Tom&#8217;s Guide: Scammers weaponizing Apple&#8217;s own notifications</a> (April 2026)</p></li><li><p><a href="https://www.techrepublic.com/article/news-apple-phishing-scam-fake-899-iphone-purchase-alert/">TechRepublic: Apple phishing scam, fake $899 iPhone purchase alert</a> (April 2026)</p></li><li><p><a href="https://www.foxnews.com/tech/apple-pay-text-scam-almost-cost-15000">Fox News: Apple Pay scam nearly cost woman $15,000</a> (April 8, 2026)</p></li><li><p><a href="https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice">Check Point Research: Most impersonated brands Q1 2026</a></p></li><li><p><a href="https://support.apple.com/en-us/102568">Apple Support: Recognize and avoid phishing</a></p></li><li><p><a href="https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-data-show-more-four-fold-increase-reports-impersonation-scammers-stealing-tens-even-hundreds">FTC: Impersonation scam losses</a></p></li></ul><div><hr></div><p><em>Prevent This is a weekly cybersecurity newsletter from Intruvent Technologies. Each week, we break down one cyber threat in plain language and give you the tools to protect yourself and the people you care about. For our bi-weekly technical deep dive, check out <a href="https://edge.intruvent.com/">Intruvent Edge</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Someone Just Stole Your Kid's School Records]]></title><description><![CDATA[The Canvas breach is big. The real risk is the phishing that comes next.]]></description><link>https://edge.intruvent.com/p/prevent-this-someone-just-stole-your</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-someone-just-stole-your</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 05 May 2026 17:25:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pu6J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pu6J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pu6J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 424w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 848w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 1272w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pu6J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png" width="1024" height="792" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:792,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1322391,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196563238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b6fd164-539f-40cb-a7b0-74ee32fb7630_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pu6J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 424w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 848w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 1272w, https://substackcdn.com/image/fetch/$s_!pu6J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f9ab7a8-ed02-49c5-84f9-2ebaa2016322_1024x792.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If your child has done homework online in the past few years, there is a good chance they used Canvas. It is one of the most widely used learning management systems in the country and the dominant platform in higher education, where it holds nearly 40% market share. Teachers post assignments on it. Students submit work through it. Parents log in to check grades. And <strong>last week, hackers broke into Canvas, stealing student data and school information.</strong></p><p>The <strong>hackers claim the breach affects 275 million users across roughly 9,000 schools.</strong> <strong>Instructure, the company that owns Canvas, has confirmed the breach</strong> but has not confirmed those numbers. What we know for certain is that <strong>the stolen data includes names, email addresses, student IDs, and private messages.</strong> If you are reading this newsletter and have a school aged child, there is a real probability that your family&#8217;s data is in that pile.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Here is the good news: your passwords, Social Security numbers, and credit card information were almost certainly not taken. Here is the bad news: what the hackers did get might be more useful to them than you think.</p><h2><strong>What Happened?</strong></h2><p>On April 30, 2026, Instructure (the company that owns Canvas) detected service disruptions on their platform. By May 1, their Chief Information Security Officer confirmed that a criminal threat actor had breached their network. <strong>On May 3, a hacking group called ShinyHunters claimed responsibility, posting a sample of the stolen data on their leak site</strong> and giving Instructure until May 6 to respond before publishing everything.</p><p>ShinyHunters claims to have stolen <strong>3.65 terabytes</strong> of data. TechCrunch independently verified a sample of the stolen data, confirming records from at least two U.S. schools (one in Massachusetts, one in Tennessee) containing names, email addresses, phone numbers, and student messages. <strong>ShinyHunters describes the message archive as &#8220;several billion&#8221; private messages exchanged between students, teachers, and parents within the Canvas platform.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!I_7-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!I_7-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!I_7-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:434805,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196563238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!I_7-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!I_7-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F852fe6e9-7993-44e7-9efd-8989f6c41381_1024x1024.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is not the first time Instructure has been hit. In September 2025, the same group, ShinyHunters, compromised Instructure&#8217;s Salesforce instance through social engineering. That breach exposed customer support data. This time, the attackers accessed the Canvas platform itself. Two breaches by the same group in eight months.</p><p>Instructure has confirmed the breach and published guidance at their <a href="https://www.instructure.com/security-incident">security incident page</a>. A law firm has already opened a class action investigation.</p><h2><strong>The Good News (What Was Not Taken)</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9Svy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9Svy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9Svy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:976131,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196563238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9Svy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9Svy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c66765b-eca7-4765-a6be-aee72f8370f8_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Before the panic sets in, here is what Instructure says the hackers <strong>did not</strong> get:</p><ul><li><p><strong>Passwords.</strong> <strong>Canvas did not store your child&#8217;s password in a way the attackers could access.</strong> Many school districts use what is called Single Sign-On (SSO), meaning students log into Canvas through their school&#8217;s Google or Microsoft account. Canvas never sees or stores that password. If your child logs into Canvas through a Google or Clever login page, their password was never in Canvas&#8217;s system to begin with. <strong>However, see the important caveat about student IDs below.</strong></p></li><li><p><strong>Social Security numbers.</strong> Schools store SSNs in their Student Information Systems (PowerSchool, Infinite Campus, etc.), not in Canvas. Canvas is a learning tool, not an enrollment database.</p></li><li><p><strong>Financial information.</strong> Canvas does not process payments. If your school charges fees, that goes through a separate payment system.</p></li><li><p><strong>Dates of birth.</strong> Also stored in the student information system, not Canvas.</p></li></ul><p><strong>So the most sensitive categories of personal data appear to be out of scope. That matters, and it is worth taking a breath over.</strong></p><h3><strong>One Important Caveat: Student IDs Are More Than ID Numbers</strong></h3><p>Here is where the &#8220;good news&#8221; gets complicated. In many school districts, especially K-12, <strong>the student ID number is not just an identifier. It is the username.</strong> Your child might log into Canvas, PowerSchool, the lunch payment system, the library catalog, and the school&#8217;s Chromebook with the same student ID as their username.</p><p>And in a lot of districts, particularly for younger students, the password is something the district assigned using a predictable pattern: the child&#8217;s birthday, their initials plus a number, or (in the worst cases) the student ID itself with a simple modification. Teachers have to manage 25 to 30 kids who forget their passwords constantly, so many districts default to something simple and consistent.</p><p><strong>That means the exposed student ID might effectively be half the login credentials for every system your child&#8217;s school district uses.</strong> Not because Canvas stored passwords, but because the student ID is the key that unlocks the front door, and the password behind that door might be guessable if an attacker knows the district&#8217;s pattern.</p><p>This does not mean every student is at risk. Districts that use SSO through Google or Microsoft, where the child has a unique password managed through the district&#8217;s identity system, are in a much better position. But districts that still rely on student-ID-as-username with simple assigned passwords should be treating this breach as a credential exposure event, not just a data exposure event.</p><h2><strong>The Bad News (What Was Taken, and Why It Matters)</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RrpB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RrpB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 424w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 848w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 1272w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RrpB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png" width="1024" height="864" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:864,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1096864,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196563238?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa79059a8-aa62-412e-96cd-030b1fcf5354_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RrpB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 424w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 848w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 1272w, https://substackcdn.com/image/fetch/$s_!RrpB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e3b42a8-54f9-4a5b-b401-15040fa8c776_1024x864.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>What the hackers did get is a different kind of valuable. Instructure confirmed the breach exposed:</p><ul><li><p><strong>Names</strong> (student, teacher, and parent/observer names)</p></li><li><p><strong>Email addresses</strong> (institutional and, <strong>for parents, sometimes personal</strong>)</p></li><li><p><strong>Student ID numbers</strong></p></li><li><p><strong>Private messages</strong> (conversations between students, teachers, and parents within Canvas)</p></li></ul><p>On the surface, names and school email addresses might not sound alarming. But this data becomes dangerous when it is combined and used creatively. Here is what a motivated attacker can do with it:</p><h3><strong>1. Hyper-Targeted Phishing That Looks Like Your Child&#8217;s School</strong></h3><p><strong>Imagine getting an email from what appears to be your child&#8217;s teacher: &#8220;Hi [your name], I noticed [your child&#8217;s name] hasn&#8217;t submitted their assignment for [actual class name]. Please log in to review their grade.&#8221;</strong> That email contains your real name, your child&#8217;s real name, and a real class. The link goes to a fake login page that steals your Google or Microsoft credentials.</p><p>This is the difference between a generic phishing email and one that references your actual life. Because the hackers have access to real messages, real class names, and real teacher names, they can build phishing emails that are nearly impossible to distinguish from legitimate school communications.</p><h3><strong>2. Social Engineering Parents</strong></h3><p>Armed with parent email addresses, student names, school names, and teacher names, a scammer can impersonate school administrators. &#8220;We are updating our payment system for school lunch accounts. Please verify your payment method.&#8221; The email comes with enough real details about your child&#8217;s school that it feels trustworthy.</p><h3><strong>3. Child Identity Theft (The Longer-Term Risk)</strong></h3><p>A child&#8217;s name and student ID number, combined with their school and approximate age, gives an identity thief a building block. To be clear: <strong>this data alone is not enough to open a credit card or take out a loan</strong>. That requires a Social Security number, which was not exposed in this breach. But it is one more piece in a puzzle that gets assembled over time as breaches accumulate, and children are attractive targets because nobody checks their credit for years.</p><p>Javelin Strategy &amp; Research found that approximately <strong>1 in 50 children</strong> (about 1.25 million kids) experience identity fraud each year in the United States, costing families roughly $1 billion annually. Most of that fraud involves someone the child knows, not a hacker with breach data. But for older students, especially college students whose names, school emails, and course information are now exposed alongside years of private messages, the risk profile is more direct. A college student&#8217;s identity is closer to fully formed and more immediately useful to a thief.</p><h3><strong>4. Private Message Exposure</strong></h3><p>Canvas stores every message sent between users on the platform. For college students, this could include conversations about academic struggles, accommodation requests, personal disclosures to advisors, or sensitive communications with professors. For younger students, the content may be less sensitive, but the principle remains: private conversations between children and their teachers were never meant to be public.</p><h2><strong>What Can You Do?</strong></h2><h3><strong>Step 1: Find Out If Your School Uses Canvas</strong></h3><p>If you are not sure, ask your school&#8217;s front office or check your child&#8217;s school website. Look for references to &#8220;Canvas,&#8221; &#8220;Instructure,&#8221; or a login link that goes to a <strong>.instructure.com </strong>domain. Canvas is used by roughly 4,000 K-12 districts and 5,000 colleges in the United States. Chances are reasonable that at least one school your family has interacted with uses it.</p><h3><strong>Step 2: Ask Your District How Your Child Logs In</strong></h3><p>This is the most important step and it takes one phone call or email. Contact your school&#8217;s front office or IT department and ask two questions:</p><ol><li><p><strong>&#8220;Does my child&#8217;s student ID serve as their username for any school systems?&#8221;</strong></p></li><li><p><strong>&#8220;Are student passwords assigned by the district using a standard pattern, or does each student set their own?&#8221;</strong></p></li></ol><p>If the answer to both is yes, the student IDs exposed in this breach are effectively half a set of login credentials. Ask the district to <strong>reset your child&#8217;s password</strong> across all systems and, if possible, move to a unique password that does not follow a predictable pattern. If your district uses Google or Microsoft SSO with individual passwords, you are in better shape, but change that password anyway.</p><h3><strong>Step 3: Change the Passwords Around Canvas</strong></h3><p>Even if Canvas passwords were not directly compromised, secure the accounts connected to your child&#8217;s school life:</p><ul><li><p><strong>Your child&#8217;s school Google or Microsoft account.</strong> If their school uses SSO, this is the password that unlocks everything. Change it.</p></li><li><p><strong>Your parent portal account</strong> for your school district (PowerSchool, Infinite Campus, etc.). Change it.</p></li><li><p><strong>Your personal email</strong> if it is the same one linked to your parent/observer Canvas account.</p></li></ul><p>If any of these passwords are reused across other sites, change those too.</p><h3><strong>Step 4: If the Student is 18+, Consider Freezing Credit (Good Practice, Not Urgent)</strong></h3><p>This breach did not expose Social Security numbers, so it does not give attackers what they need to open accounts in your child&#8217;s name right now. But a credit freeze is one of the best long-term protections against child identity theft from any source, and it is free. If you have not done this already, this is a reasonable time to take care of it.</p><p><strong>For college students (18+):</strong> This is more directly relevant. Their identities are more fully formed and more immediately useful to a thief. They should freeze their own credit at all three bureaus:</p><ul><li><p><strong>Equifax:</strong> <a href="https://www.equifax.com/personal/credit-report-services/credit-freeze/">equifax.com/personal/credit-report-services/credit-freeze</a></p></li><li><p><strong>Experian:</strong> <a href="https://www.experian.com/freeze/center.html">experian.com/freeze/center.html</a></p></li><li><p><strong>TransUnion:</strong> <a href="https://www.transunion.com/credit-freeze">transunion.com/credit-freeze</a></p></li></ul><h3><strong>Step 5: Watch for Phishing Emails From &#8220;School&#8221;</strong></h3><p>For the next several months, treat any email that appears to come from your child&#8217;s school with extra caution, especially if it asks you to click a link, log in, update payment information, or download an attachment. If something looks off, call the school directly using the phone number from their website, not from the email.</p><p>This is especially true for end-of-year emails about report cards, summer programs, or registration for next year. Scammers will time their phishing to match the school calendar.</p><h3><strong>Step 6: Talk to Your Kids (Especially Teens and College Students)</strong></h3><p>Older students need to know that their Canvas messages may have been exposed. If your college student sent sensitive messages through Canvas (academic concerns, personal issues, accommodation requests), they should be aware that this information could surface. They should also watch for phishing emails impersonating their university and avoid clicking links in any email that references their courses by name.</p><h2><strong>A Note on FERPA</strong></h2><p>Student education records are protected under FERPA (the Family Educational Rights and Privacy Act). When those records are breached, your child&#8217;s <strong>school district</strong> holds the notification obligation, not Instructure. <strong>If your school uses Canvas, your district should be communicating with you about this breach and what they are doing about it. If they have not, ask them.</strong> You have a right to know.</p><h2><strong>The Bottom Line</strong></h2><p>The Canvas breach is real, large, and affects a population that deserves extra protection: children. The good news is that the most dangerous data categories (passwords, SSNs, financial info) were not part of it. The bad news is that the data that was taken (names, emails, student IDs, and private messages) gives attackers the raw material for highly convincing phishing campaigns targeting families.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-someone-just-stole-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-someone-just-stole-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-someone-just-stole-your?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>Three things to do this week:</p><ol><li><p><strong>Be skeptical of school emails</strong> that ask you to click, log in, or pay, especially if they reference your child by name and class. That specificity is exactly what this breach enables. Call the school directly to verify.</p></li><li><p><strong>Ask your district</strong> if your child&#8217;s student ID is used as a username, and whether passwords follow a standard pattern. If yes, request a password reset.</p></li><li><p><strong>Change the passwords</strong> on your child&#8217;s school Google/Microsoft account and your parent portal.</p></li></ol><p>This breach hit the system our kids use every single day. Share this with other parents at your school. They need to know.</p><div><hr></div><h2><strong>Sources</strong></h2><ul><li><p><a href="https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/">BleepingComputer: Instructure confirms data breach, ShinyHunters claims attack</a>(May 2026)</p></li><li><p><a href="https://techcrunch.com/2026/05/05/hackers-steal-students-data-during-breach-at-education-tech-giant-instructure/">TechCrunch: Hackers steal students&#8217; data during breach at Instructure</a> (May 2026)</p></li><li><p><a href="https://www.securityweek.com/edtech-firm-instructure-discloses-data-breach/">SecurityWeek: Edtech firm Instructure discloses data breach</a> (May 2026)</p></li><li><p><a href="https://www.fox9.com/news/canvas-data-breach-hackers-claim-info-275-million-users-across-9000-schools">FOX 9: Canvas data breach, hackers claim info of 275 million users</a> (May 2026)</p></li><li><p><a href="https://javelinstrategy.com/press-release/child-identity-fraud-costs-nearly-1-billion-annually-according-new-study-javelin">Javelin Strategy &amp; Research: Child Identity Fraud Study</a> (2021)</p></li><li><p><a href="https://www.equifax.com/personal/credit-report-services/credit-freeze/">Equifax: Credit Freeze</a></p></li><li><p><a href="https://studentprivacy.ed.gov/faq/what-ferpa">U.S. Department of Education: FERPA FAQ</a></p></li></ul><div><hr></div><p><em>Prevent This is a weekly cybersecurity newsletter from Intruvent Technologies. Each week, we break down one cyber threat in plain language and give you the tools to protect yourself and the people you care about. For any feedback or if your company is experiencing a breach and you need help, contact us at contact@intruvent.com</em></p><p></p>]]></content:encoded></item><item><title><![CDATA[Intruvent EDGE: 732 Bytes to Root. A Nine-Year Linux Kernel Bug Just Went Public]]></title><description><![CDATA[CVE-2026-31431 turns nine years of Linux kernels into a one-command root shell]]></description><link>https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root</link><guid isPermaLink="false">https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 30 Apr 2026 19:56:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!KKJv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Welcome to Intruvent Edge, our bi-weekly technical deep dive into a current cyber threat. If you found us through Prevent This, our weekly community newsletter covering cybersecurity for everyone, you&#8217;re in the right place. Both live on the same Substack. Feel free to share either one. We&#8217;re glad you&#8217;re here!</p><h2><strong>The Vulnerability</strong></h2><p>Yesterday, security researchers at Theori published a complete privilege escalation exploit for CVE-2026-31431, a logic bug in the Linux kernel&#8217;s cryptographic subsystem that has existed since August 2017. <strong>The exploit is a 10-line Python script. It requires no compiled payloads, no version-specific offsets, and no race conditions. It works on every major Linux distribution released in the past nine years.</strong></p><p><strong>Every. Major. Linux. Distribution. </strong></p><p>Linux runs approximately 96% of the world&#8217;s top one million web servers, the majority of cloud infrastructure, most containers and Kubernetes clusters, and billions of IoT and embedded devices. <strong>Conservative estimates place the affected device count in the billions.  With a B.</strong></p><p><strong>This one is bad, and needs your attention.</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The vulnerability, nicknamed &#8220;Copy Fail,&#8221; allows any unprivileged local user to gain a root shell in seconds. On a multi-tenant system, a shared Kubernetes cluster, or a CI/CD runner, that means any user with shell access can take complete control of the host.</p><p>A fully weaponized proof-of-concept is already public on GitHub. Exploitation at scale is now a matter of when, not if.  If your home or work uses any affected systems, please read on.  Please forward this to anybody who needs it.</p><h2><strong>How It Works</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KKJv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KKJv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KKJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:44379,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196020095?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KKJv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!KKJv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd2112898-d147-480c-a2d0-d2b667a3a358_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Caption suggestion: &#8220;CVE-2026-31431 exploitation flow: from AF_ALG socket to root shell in six steps.&#8221;</p><p>The bug lives in <code>algif_aead.c</code>, a component of the Linux kernel&#8217;s AF_ALG cryptographic socket interface. Specifically, it affects the <code>authencesn</code> algorithm, which handles authenticated encryption with sequence numbers for IPsec.</p><p>Three individually reasonable kernel changes created the vulnerability:</p><ol><li><p><strong>2011:</strong> The <code>authencesn</code> cryptographic wrapper was added for IPsec support</p></li><li><p><strong>2015:</strong> AF_ALG gained AEAD (Authenticated Encryption with Associated Data) socket support, allowing userspace programs to invoke kernel crypto operations</p></li><li><p><strong>2017 (kernel 4.14):</strong> An in-place optimization in commit <code>72548b093ee3</code> placed page cache pages directly into a writable scatterlist</p></li></ol><p>That third change is the fatal one. When the kernel performs an AEAD decrypt operation, <code>authencesn</code> writes a 4-byte sequence number (<code>seqno_lo</code>) past the output buffer boundary via <code>scatterwalk_map_and_copy()</code>. Because the optimization placed page cache pages in the writable scatterlist, those 4 bytes land directly in the page cache.</p><p>The page cache is the kernel&#8217;s in-memory copy of file contents. Every executable you run, every library you load, comes from the page cache. If you can write arbitrary bytes into it, you can corrupt any readable file&#8217;s in-memory representation without touching the on-disk copy.</p><p>The exploit sequence:</p><ol><li><p>Open an AF_ALG socket bound to <code>authencesn(hmac(sha256),cbc(aes))</code></p></li><li><p>Use <code>splice()</code> to feed page cache pages of a setuid binary (such as <code>/usr/bin/su</code>) into the crypto pipeline</p></li><li><p>Construct <code>sendmsg()</code> with shellcode bytes positioned in the AAD at offsets 4 through 7</p></li><li><p>Issue <code>recvmsg()</code>, which triggers AEAD decrypt. The <code>authencesn</code> algorithm writes past the output boundary into the mapped page cache page</p></li><li><p>The HMAC verification fails and returns <code>EBADMSG</code>, but the write has already occurred and persists</p></li><li><p>Execute the corrupted setuid binary. The kernel loads it from page cache. Shellcode runs as root.</p></li></ol><p>The entire sequence fits in 732 bytes of Python using only the <code>os</code>, <code>socket</code>, and <code>zlib</code>standard library modules.</p><h2><strong>Why This Is Worse Than Dirty Pipe</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a8mU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a8mU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a8mU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76213,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196020095?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a8mU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!a8mU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ac4e87-90d7-46e1-9b0f-a086c75afb9f_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>Security professionals will immediately compare CVE-2026-31431 to Dirty Pipe (CVE-2022-0847) and Dirty COW (CVE-2016-5195), the two most notorious Linux kernel privilege escalation vulnerabilities of the past decade. Copy Fail is worse than both.</p><p><strong>Dirty COW</strong> required winning a race condition. Exploitation was probabilistic and often crashed the target system. Copy Fail has no race condition. The exploit is deterministic and 100% reliable.</p><p><strong>Dirty Pipe</strong> required knowledge of specific kernel version offsets and was limited to kernels 5.8 through 5.16 (roughly an 18-month window). Copy Fail requires no offsets and works across a nine-year window of kernel versions, from 4.14 through current mainline.</p><p><strong>Both</strong> left forensic evidence that file integrity monitoring tools could detect. Copy Fail corrupts only the in-memory page cache. The page is never marked dirty for writeback, so the on-disk file remains pristine. Inotify sees nothing. AIDE sees nothing. OSSEC sees nothing. Tripwire sees nothing.</p><p>One additional dimension makes this especially dangerous in modern infrastructure: the page cache is shared across the entire host, including all containers running on that host. A process inside a Kubernetes pod can corrupt the page cache entry of a setuid binary on the host filesystem. Copy Fail functions as a container escape primitive that bypasses namespace isolation entirely.</p><h2><strong>What&#8217;s Affected</strong></h2><p>Every Linux distribution shipping a kernel from version 4.14 (August 2017) onward is vulnerable unless patched. Confirmed affected systems include:</p><ul><li><p><strong>Ubuntu 24.04 LTS</strong> (kernel 6.17.0-1007-aws)</p></li><li><p><strong>Amazon Linux 2023</strong> (kernel 6.18.8-9.213.amzn2023)</p></li><li><p><strong>RHEL 10.1</strong> (kernel 6.12.0-124.45.1.el10_1)</p></li><li><p><strong>SUSE 16</strong> (kernel 6.12.0-160000.9-default)</p></li><li><p><strong>Rocky Linux 9.7</strong> (confirmed independently by Solar Designer)</p></li><li><p><strong>Debian, Arch Linux, Fedora, Oracle Linux</strong></p></li><li><p>Embedded Linux distributions used in IoT, networking equipment, and industrial systems</p></li></ul><p><strong>Not affected:</strong> RHEL 6 and 7 (kernel versions predate the vulnerable commit), and Ubuntu 26.04 (Resolute) which ships a patched kernel.</p><p>Linux runs approximately 96% of the world&#8217;s top one million web servers, the majority of cloud infrastructure, most containers and Kubernetes clusters, and billions of IoT and embedded devices. Conservative estimates place the affected device count in the billions.</p><h2><strong>Detection Is Hard</strong></h2><p>Traditional security tooling is largely blind to this attack. The corruption happens entirely in kernel memory, with no disk writes, no file modifications, and no network traffic.</p><p><strong>Will NOT detect exploitation:</strong></p><ul><li><p>File integrity monitoring (AIDE, OSSEC, Tripwire, Samhain)</p></li><li><p>Inotify-based watchers</p></li><li><p>Hash-based allowlisting tools</p></li><li><p>Standard auditd file access rules</p></li></ul><p><strong>CAN detect exploitation:</strong></p><ul><li><p><strong>eBPF-based monitoring</strong> that tracks AF_ALG socket creation and <code>splice()</code> calls targeting setuid binaries</p></li><li><p><strong>Falco/Sysdig rules</strong> detecting SOCK_SEQPACKET AF_ALG socket creation from unexpected processes</p></li><li><p><strong>Auditd rules</strong> configured to audit <code>socket()</code> calls with AF_ALG family (family 38)</p></li><li><p><strong>Behavioral detection</strong> looking for <code>EBADMSG</code> return codes from AEAD operations followed by execution of setuid binaries</p></li></ul><p>A community detection toolkit is already available on <a href="https://github.com/kadir/copy-fail-CVE-2026-31431-IOC">GitHub</a>, including Falco rules, auditd configurations, and an eBPF monitor.</p><p>The key behavioral sequence to detect:</p><ol><li><p>AF_ALG socket creation by a non-root, non-crypto process</p></li><li><p><code>splice()</code> calls feeding a setuid binary into that socket</p></li><li><p><code>recvmsg()</code> returning EBADMSG</p></li><li><p><code>execve()</code> of the same setuid binary shortly after</p></li></ol><p>Any security operations team monitoring Linux hosts should deploy at minimum the auditd rule for AF_ALG socket creation today.</p><h2><strong>Patch and Mitigation</strong></h2><h3><strong>The Fix</strong></h3><p>The upstream kernel team committed the fix on April 1, 2026 (commit <code>a664bf3d603d</code>). The patch reverts <code>algif_aead.c</code> to out-of-place AEAD operation, permanently separating the TX scatterlist from the RX scatterlist so that page cache pages can never be placed in a writable context.</p><p>Patched kernel versions: 7.0+, 6.19.12+, 6.18.22+.</p><p>As of today, Debian, Ubuntu, and SUSE have issued patched packages. Red Hat initially deferred the patch but has since reversed course.</p><h3><strong>Interim Mitigation (If You Cannot Patch Immediately)</strong></h3><p>The simplest and most effective mitigation is to disable the <code>algif_aead</code> kernel module:</p><pre><code><code># Prevent the module from loading
echo "install algif_aead /bin/false" &gt; /etc/modprobe.d/disable-algif-aead.conf

# Unload if currently loaded
sudo rmmod algif_aead 2&gt;/dev/null</code></code></pre><p>This does NOT affect dm-crypt/LUKS, kTLS, IPsec/XFRM, OpenSSL, GnuTLS, NSS, or SSH. Most systems never load this module at all. The only software that uses AF_ALG AEAD sockets is <code>libkcapi</code> and a small number of specialized cryptographic testing tools.</p><p><strong>For containerized environments:</strong> Block AF_ALG socket creation via seccomp profiles on all pods, CI/CD runners, and container workloads. The exploit requires opening an AF_ALG socket as its first step; blocking that syscall prevents exploitation entirely.</p><pre><code><code>{
  "names": ["socket"],
  "action": "SCMP_ACT_ERRNO",
  "args": [
    {
      "index": 0,
      "value": 38,
      "op": "SCMP_CMP_EQ"
    }
  ]
}</code></code></pre><p>This blocks <code>socket(AF_ALG, ...)</code> calls. AF_ALG is protocol family 38.</p><h2><strong>Timeline</strong></h2><p><strong>DateEvent</strong>August 2017Vulnerable commit introduced in kernel 4.14March 23, 2026Theori reports vulnerability to Linux kernel security teamMarch 24, 2026Kernel team acknowledges the reportMarch 25, 2026Patches proposed and reviewedApril 1, 2026Fix committed to mainlineApril 22, 2026CVE-2026-31431 assignedApril 23, 2026NVD publishes CVE detailsApril 29, 2026Full public disclosure with proof-of-conceptApril 30, 2026CERT-EU publishes Security Advisory 2026-005</p><p>The 37-day window between the fix commit and public disclosure gave major distributions time to prepare patches. Whether your organization has applied them is another question.</p><h2><strong>Who Found It</strong></h2><p>Taeyang Lee of Theori, a South Korean security research firm, discovered the vulnerability. The Xint Code Research Team subsequently used AI-assisted analysis to scale the initial finding into a complete exploitation chain in approximately one hour, demonstrating how quickly modern tooling can weaponize a vulnerability once the root cause is understood.</p><p>Alexander Peslyak (Solar Designer), founder of the Openwall Project and one of the most respected voices in Linux security, independently confirmed exploitation on Rocky Linux 9.7.</p><h2><strong>What You Should Do Today</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fYuV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fYuV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fYuV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78667,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/196020095?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fYuV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!fYuV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4652020a-b032-4264-93b8-7ac9e55657b7_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p><strong>1. Check if you&#8217;re affected.</strong> Any system running a kernel from 4.14 onward that has not applied the latest security updates is vulnerable. Run <code>uname -r</code> and check against your distribution&#8217;s security advisory.</p><p><strong>2. Apply patches if available.</strong> Debian, Ubuntu, and SUSE have issued fixes. If patched packages are available, apply them immediately. A public PoC exists and exploitation is trivial.</p><p><strong>3. Deploy the module mitigation on unpatched systems.</strong> If you cannot patch within 24 hours, disable <code>algif_aead</code> with the modprobe rule above. This closes the attack vector at negligible operational cost.</p><p><strong>4. Harden container workloads.</strong> Add AF_ALG socket blocking to your seccomp profiles. If you operate Kubernetes clusters, update your PodSecurityPolicies or OPA/Gatekeeper constraints to block protocol family 38.</p><p><strong>5. Deploy detection.</strong> At minimum, add an auditd rule for AF_ALG socket creation. For higher-fidelity detection, deploy the eBPF monitor from the community toolkit.</p><p><strong>6. Audit multi-tenant systems first.</strong> Shared hosting environments, CI/CD runners, Kubernetes clusters, and any system where untrusted users have shell access are the highest-priority targets. The vulnerability requires only local access.</p><p><strong>7. Do not rely on file integrity monitoring.</strong> If your security strategy for Linux hosts depends primarily on hash-based FIM tools, this vulnerability bypasses that layer entirely. Update your detection architecture.</p><h2><strong>The Bigger Picture</strong></h2><p>Copy Fail is a reminder that kernel attack surface accumulates invisibly over time. The three code changes that created this vulnerability were each reasonable in isolation. The dangerous interaction between them went undetected for nine years, hidden behind a kernel subsystem that most security researchers never examine because &#8220;it&#8217;s just crypto plumbing.&#8221;</p><p>The exploit&#8217;s simplicity is the real story. A 10-line Python script with no dependencies achieving deterministic root on nine years of kernels is the kind of vulnerability that shifts the risk calculus for any organization running multi-tenant Linux infrastructure. Patch today.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/intruvent-edge-732-bytes-to-root?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p><strong>Sources</strong></p><ul><li><p><a href="https://xint.io/blog/copy-fail-linux-distributions">Xint Code: &#8220;Copy Fail: 732 Bytes to Root on Every Major Linux Distribution&#8221;</a> (original technical disclosure)</p></li><li><p><a href="https://cert.europa.eu/publications/security-advisories/2026-005/">CERT-EU Security Advisory 2026-005</a></p></li><li><p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31431">NVD: CVE-2026-31431</a></p></li><li><p><a href="https://www.sysdig.com/blog/cve-2026-31431-copy-fail-linux-kernel-flaw-lets-local-users-gain-root-in-seconds">Sysdig: CVE-2026-31431 Analysis</a></p></li><li><p><a href="https://www.helpnetsecurity.com/2026/04/30/copyfail-linux-lpe-vulnerability-cve-2026-31431/">Help Net Security: Nine-year-old Linux kernel flaw</a></p></li><li><p><a href="https://www.theregister.com/2026/04/30/linux_cryptographic_code_flaw/">The Register: Linux cryptographic code flaw offers fast route to root</a></p></li><li><p><a href="https://socradar.io/blog/cve-2026-31431-copy-fail-nine-year-linux-bug/">SOCRadar: CVE-2026-31431 Copy Fail Analysis</a></p></li><li><p><a href="https://www.bugcrowd.com/blog/what-we-know-about-copy-fail-cve-2026-31431/">Bugcrowd: What We Know About Copy Fail</a></p></li><li><p><a href="https://github.com/kadir/copy-fail-CVE-2026-31431-IOC">Community Detection Toolkit (GitHub)</a></p></li><li><p><a href="https://github.com/theori-io/copy-fail-CVE-2026-31431">Theori PoC Repository (GitHub)</a></p></li></ul><div><hr></div><h2><strong>Free Linux Security Assessment</strong></h2><p>Copy Fail is the latest in a growing list of Linux kernel privilege escalations (Dirty COW, Dirty Pipe, StackRot, and now Copy Fail) that bypass traditional detection. If your organization relies on Linux for production workloads, we can help you assess your exposure.</p><p><strong>Shoot us an email at: contact@intruvent.com to book a 30 minute assessment discussion.</strong></p><p>We also offer:</p><ul><li><p>Linux kernel vulnerability exposure assessments</p></li><li><p>Container security and Kubernetes hardening reviews</p></li><li><p>Detection engineering for kernel-level threats</p></li><li><p>Managed threat hunting across your Linux infrastructure</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Prevent This: Life Event Scams]]></title><description><![CDATA[Grief, divorce, illness, job loss. Scammers have a playbook for all of them. We have a playbook to counter it.]]></description><link>https://edge.intruvent.com/p/prevent-this-life-event-scams</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-life-event-scams</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 28 Apr 2026 19:14:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w8OP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w8OP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w8OP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w8OP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg" width="1024" height="679" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:679,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:119085,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/195785838?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcba9b8ef-b0ee-4909-a1f7-a57ad9f1616b_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w8OP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w8OP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0852b8f6-02d6-41df-a390-9d033b746cb6_1024x679.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A reader of this newsletter reached out to me this week with two stories that really hit home with me.</p><p>The first: <strong>several of her friends, all women in their 70s and 80s, have been targeted by scammers after their husbands passed away</strong>. Accounts taken over. Identities stolen. Fraud that started within days of the obituary going live. She wanted to know if this was a known pattern or just terrible luck.</p><p>It is a known pattern. A well-documented, growing, and organized one. We will get into the details below.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The second: <strong>she received a suspicious email claiming a close friend was in the hospital and needed help. When she responded, the person on the other end seemed to know a lot about her friend, enough that it felt real</strong>. They described the injury, referenced details that checked out. Then they asked her to send DoorDash gift cards to help cover expenses while her friend recovered.</p><p>That is where her training kicked in. As a reader of Prevent This, she recognized the gift card request for what it was: the unmistakable fingerprint of a scam. No hospital, no doctor, no friend in genuine need has ever asked for DoorDash gift cards. She did not send them.</p><p>But the experience shook her. <em>The scammer knew too much. The story was too specific</em>. <strong>And she asked the question that inspired this edition: what can I do right now, today, to make sure I do not become an actual victim?</strong></p><p>This newsletter is the answer. <strong>Part 1 covers the bereavement scam</strong> pattern and what to do if you or someone you love is going through a loss. <strong>Part 2 is a quick-start security checkup</strong>, the essentials that anyone can knock out today to raise their baseline protection.</p><p>Her friends&#8217; experiences are far from unique. Here is what the pattern looks like when it shows up in the news.</p><div><hr></div><h2>What Happened?</h2><p>A suburban Chicago widow published her husband&#8217;s obituary in January. By April, someone had quietly forwarded her mail to an unknown Chicago address without her knowledge. Fraudulent credit card charges started appearing: a hotel in Atlanta, tickets to the Atlanta Aquarium, $200 for cleaning services she never ordered. Scammers also attempted to open new credit cards in her name.</p><p><strong>She caught it. Many do not</strong>.</p><p>The U.S. Postal Inspection Service reversed the mail forwarding and opened an investigation, but the damage extended beyond dollars. As the victim told NBC Chicago: &#8220;The emotional impact of this, even though there wasn&#8217;t any financial impact, is not going to go away for a while.&#8221;</p><p>She is far from alone. A 77-year-old widow named Marjorie Bloom received a call from someone claiming to be a &#8220;fraud investigator&#8221; at her bank. Over the following weeks, at the caller&#8217;s instruction, she liquidated everything: savings, stocks, an annuity. The total: $661,000. The scammer told her not to tell anyone, including her children, claiming secrecy was necessary to protect the investigation. By the time she realized what had happened, her entire nest egg was gone.</p><p>In Georgia, identity thieves used an obituary to redirect a deceased man&#8217;s mail just two days after his death, then opened new lines of credit in his name before his family had finished planning the funeral.</p><p>These are not isolated incidents. They are a pattern, and the pattern is accelerating.</p><div><hr></div><h2>Why Should You Care?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!plkT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!plkT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!plkT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!plkT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!plkT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!plkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:78678,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/195785838?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!plkT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!plkT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!plkT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!plkT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9017ebf5-ef7d-4087-b294-e8cd52c0e196_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The numbers tell a grim story:</p><ul><li><p>$7.7 billion lost by Americans 60 and older to internet crime in 2025, up 60% from 2024 (FBI IC3)</p></li><li><p>2.5 million deceased Americans have their identities stolen annually (ID Analytics study, corroborated by TIME and NBC News)</p></li><li><p>167% increase in fraudulent mail forwarding between 2020 and 2021 (U.S. Postal Inspection Service)</p></li><li><p>$584 million in romance and confidence scam losses targeting older adults in 2025 alone (FBI IC3)</p></li><li><p>The FTC estimates actual elder fraud losses may reach $81.5 billion per year when accounting for unreported cases</p></li></ul><p>The FBI, FTC, AARP, multiple state attorneys general, and the VA have all issued specific warnings about scams targeting the recently bereaved. The FBI&#8217;s El Paso field office published a dedicated alert on &#8220;bereavement scams.&#8221; Michigan&#8217;s Attorney General warned the public about &#8220;obituary pirates&#8221; who scrape death notices. The LA County District Attorney&#8217;s office issued a fraud alert specifically about obituary-based targeting.</p><p>The pattern is organized, documented, and growing. And the people hit hardest are those least equipped to fight back: elderly widows navigating finances alone, often for the first time, during the worst period of their lives.</p><div><hr></div><h2>How Does This Work?</h2><p><strong>Think of it like reconnaissance before a burglary, except the reconnaissance is public and free.</strong></p><p><strong>The obituary is ground zero. A typical obituary contains the deceased&#8217;s full name, date and place of birth, mother&#8217;s maiden name, home city, surviving family members, workplace history, church and club memberships, and the date, time, and location of funeral services.</strong> That is enough information to answer most security questions, build a complete social engineering profile, and even plan a physical burglary of a home that will be empty during the service.</p><p>The Better Business Bureau has warned directly: &#8220;They&#8217;re putting too much info into obituaries, especially mother&#8217;s maiden names and things like that actually needed for identity theft.&#8221;</p><p>But obituaries are only the start. Scammers have multiple channels feeding them targets:</p><p><strong>Data brokers sell lists of the recently widowed</strong>. According to reporting from Komando.com and the Brennan Center for Justice, data brokers compile and sell categorized lists that include &#8220;Suffering Seniors&#8221; and lists sorted by life events, including bereavement. Scammers buy these lists because, as one analysis noted, &#8220;they assume there&#8217;s a life insurance payout and someone navigating money alone for the first time.&#8221; The CFPB proposed a rule in 2024 to restrict these sales. It was withdrawn in 2025. There is currently no federal regulation preventing this practice.</p><p><strong>Probate records are public.</strong> In most U.S. jurisdictions, probate filings include heir names and addresses, detailed asset inventories, property descriptions, and executor contact information. Scammers monitor these filings to build target lists.</p><p>Social media fills in the gaps. Memorial posts, condolence threads, and tribute pages provide additional personal details that supplement what the obituary reveals. They also give romance scammers a way to identify and contact the surviving spouse.</p><p><strong>AI makes all of this worse. According to Blackbird.AI research, threat actors now use language models to extract personal data from obituaries at scale</strong>, cross-reference it with news articles and social media, generate complete character profiles of plausible friends or acquaintances of the deceased, and craft messages with fabricated but contextually accurate &#8220;shared memories.&#8221; The FBI&#8217;s 2025 IC3 report documented over $893 million in AI-linked fraud losses, with older adults accounting for $352 million.</p><p>Once a target is identified, the attacks come in several forms:</p><p>&#8220;Ghosting&#8221; the deceased: Opening credit cards, taking loans, or filing tax returns using the dead person&#8217;s identity before financial institutions are notified. There is a gap between the time of death and when SSN databases are updated, and scammers exploit it.</p><p>Account takeover of the surviving spouse: Redirecting mail, resetting passwords, and draining accounts using obituary-sourced personal details and security question answers.</p><p>The Phantom Hacker: A three-phase scam where the victim is contacted first by a fake tech support agent, then by a fake bank representative, and finally by a fake government official, each reinforcing the last. This scam has stolen over $1 billion from seniors since 2024.</p><p>Romance scams: Scammers identify recently widowed individuals and initiate contact through dating sites, Facebook, or even &#8220;condolence&#8221; emails. They build emotional dependency over weeks or months before introducing financial requests.</p><p>Fake debt collectors: Callers claim the deceased had outstanding debts and pressure the surviving spouse for payment. In reality, the estate (not the survivor) generally bears liability for a deceased person&#8217;s debts unless the survivor was a co-signer or joint account holder.</p><div><hr></div><h2>What Can You Do?</h2><p>Whether you are the person grieving, or you are looking out for someone who is, these steps can close the gaps that scammers exploit.</p><h4>If You (or Someone You Know) Have Recently Lost a Loved One</h4><h4>In the first week:</h4><p>1. Contact the Social Security Administration (800-772-1213) to report the death. This starts the process of flagging the SSN.</p><p>2. Notify all three credit bureaus and request a death notice on the deceased&#8217;s credit file:</p><p>   Equifax: 800-525-6285</p><p>   Experian: 888-397-3742</p><p>   TransUnion: 800-680-7289</p><p>3. Notify every financial institution where the deceased held an account: banks, credit cards, investment accounts, insurance companies. Ask that closed accounts be listed as &#8220;Closed: Account holder is deceased.&#8221;</p><p>4. Send a copy of the death certificate to the IRS to flag the deceased&#8217;s tax account against fraudulent returns.</p><p>5. Secure the mail. Lock the mailbox. Monitor for unexpected forwarding notices. Consider a P.O. Box for sensitive mail during the transition.</p><p>6. Cancel the deceased&#8217;s driver&#8217;s license with the DMV to prevent it from being used as identification.</p><h4>In the first month:</h4><p>7. Pull a credit report for the deceased and review it for unfamiliar accounts. Pull another one in three to six months.</p><p>8. Monitor or memorialize the deceased&#8217;s social media accounts. Unmonitored accounts leak personal information and become targets for impersonation.</p><p>9. Close or secure the deceased&#8217;s email accounts. An active, unmonitored email address is a gateway to password resets on every linked service.</p><h4>Protect the Surviving Spouse</h4><p>10. Enable multi-factor authentication on every account: email, banking, social media. Authenticator apps are better than SMS, but SMS is better than nothing.</p><p>11. Set up credit monitoring and fraud alerts on your own accounts, not just the deceased&#8217;s.</p><p>12. Remove personal information from data broker sites. Services like DeleteMe or Privacy Duck handle this, or you can manually opt out from sites like Spokeo, WhitePages, and BeenVerified.</p><p>13. Treat every unsolicited contact with suspicion, especially anyone referencing the deceased, claiming to be from a bank, or presenting an urgent financial situation.</p><p>14. Never allow remote access to your computer based on a phone call, pop-up, or email you did not initiate.</p><p>15. Designate a &#8220;verification buddy.&#8221; Any financial request, transaction, or decision gets run past a trusted family member before you act. Scammers rely on isolation and secrecy; a second opinion breaks that cycle.</p><h4>Write a Safer Obituary</h4><p>16. Leave out: date of birth, mother&#8217;s maiden name, home address, specific funeral times and locations (use &#8220;private services&#8221; or share details only with those who call the funeral home directly).</p><p>17. Include instead: the person&#8217;s life story, accomplishments, and character. None of that information helps a scammer.</p><h4>For Family Members: Have the Conversation Now</h4><p>Do not wait until someone dies. Talk to your parents, grandparents, aunts, and uncles about these scams now, while the conversation is calm and theoretical.</p><p>Agree on a verification process for unexpected financial contacts.</p><p>Offer to review the obituary before it is published.</p><p>Set up monitoring on shared or connected accounts.</p><p>Know the reporting numbers (below) so you are not searching for them during a crisis.</p><div><hr></div><h2>Part 2: The Essentials, a Quick-Start Security Checkup</h2><p>This is the part our reader was really asking about. She spotted the DoorDash gift card scam because she knew the signs. But the fact that the scammer knew so much about her friend bothered her. Where did they get those details? How personalized can these attacks get? And what can she do right now to reduce the chances that she, or someone she cares about, becomes the next target?</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!7bM4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!7bM4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 424w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 848w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 1272w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!7bM4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:320016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/195785838?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!7bM4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 424w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 848w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 1272w, https://substackcdn.com/image/fetch/$s_!7bM4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff495d0bc-4dc8-498f-a8d0-584d0f6d11ff_1200x896.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The honest answer: there is no single checklist that makes you bulletproof. Digital security is layered, and a full lockdown covers far more ground than we can fit in one newsletter. But most account takeovers succeed not because the attacker was sophisticated, but because the victim reused a password from a breach they never knew about, or never turned on two-factor authentication. Those are basics, and basics matter.</p><p><strong>What follows are the highest-impact steps you can take today. Think of it as tightening the locks on the front door, not installing a full alarm system.</strong> It will not stop every threat, but it will stop the most common ones and make you a harder target than the person who skipped this section.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PBUP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PBUP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PBUP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:132637,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/195785838?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PBUP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 424w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 848w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 1272w, https://substackcdn.com/image/fetch/$s_!PBUP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F348857a1-81fe-4894-a32f-09f993224217_1024x1024.heic 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><h3>Step 1: Check Your Passwords for Breaches</h3><p>If you use an iPhone, iPad, or Mac, Apple has a built-in tool that does this for you. No downloads, no subscriptions required.</p><p>How to use Apple Passwords:</p><p>1. Open the Passwords app (iOS 18+ and macOS Sequoia) or go to Settings &gt; Passwords on older devices.</p><p>2. Look for the Security section at the top. Apple automatically flags three categories:</p><p>   Compromised Passwords: These appeared in a known data breach. Change them immediately.</p><p>   Reused Passwords: The same password used on multiple sites. If one site is breached, every account sharing that password is exposed.</p><p>   Weak Passwords: Short, predictable, or commonly used passwords that are easy to guess.</p><p>3. Tap any flagged entry. Apple provides a Change Password link that takes you directly to the site&#8217;s password reset page.</p><p>4. When you create the replacement, let Apple generate a strong password for you. It saves automatically to your keychain and syncs across your devices.</p><p>Not an Apple user? Google Password Manager (built into Chrome) has the same feature at passwords.google.com. Go to Password Checkup and it will flag compromised, reused, and weak passwords. Samsung users can check via Samsung Pass in device settings.</p><div><hr></div><h3>Step 2: Change Any Password Older Than One Year</h3><p>Even if a password has not appeared in a known breach, old passwords carry risk. Breaches are not always disclosed immediately, and some are never made public at all. A password that looks clean today may have been compromised months ago.</p><p>Work through your password manager and sort by &#8220;last changed&#8221; date. Any password older than 12 months should be updated. Prioritize these accounts first:</p><ul><li><p>Email (this is the master key to everything else; password resets flow through it)</p></li><li><p>Banking and financial accounts</p></li><li><p>Health insurance and medical portals</p></li><li><p>Government accounts (SSA, IRS, state tax portals)</p></li><li><p>Social media (Facebook, Instagram, LinkedIn)</p><p></p><p>Let your password manager generate each new password. Long, random, and unique to every site.</p></li></ul><div><hr></div><h3>Step 3: Turn On Two-Factor Authentication Everywhere</h3><p>A strong password alone is not enough. Two-factor authentication (2FA) adds a second layer: even if someone steals your password, they cannot get in without the second factor.</p><h4>Where to enable it (in priority order):</h4><p>1. Email (Gmail, iCloud, Outlook, Yahoo)</p><p>2. Banking and financial apps</p><p>3. Social media (Facebook, Instagram, LinkedIn, X)</p><p>4. Shopping accounts that store payment information (Amazon, PayPal)</p><p>5. Cloud storage (iCloud, Google Drive, Dropbox)</p><h4>Which 2FA method to use:</h4><p>Best: A hardware security key (YubiKey) or passkeys (supported by Apple, Google, and Microsoft). These are phishing-resistant.</p><p>Good: An authenticator app (Apple&#8217;s built-in Passwords app supports verification codes, as do Google Authenticator and Microsoft Authenticator).</p><p>Acceptable: SMS text codes. Vulnerable to SIM-swapping attacks, but still far better than no 2FA at all.</p><p>Apple Passwords tip: When you set up 2FA for a site, Apple Passwords can store and auto-fill your verification codes. During the 2FA setup process, choose &#8220;Set Up Verification Code&#8221; when you scan the QR code, and your codes will auto-fill alongside your passwords going forward. No separate authenticator app needed.</p><div><hr></div><h3>Step 4: Scan Your Devices for Malicious Software</h3><p>Scammers do not always ask for your information directly. Malware, keyloggers, and spyware can quietly capture passwords, banking credentials, and personal data in the background.</p><h4>On a Mac:</h4><p>Make sure your operating system is up to date (System Settings &gt; General &gt; Software Update). macOS includes built-in malware protection (XProtect) that updates silently, but it only works if your system is current.</p><p>Review your installed applications (Finder &gt; Applications). If you see anything you do not recognize or did not install, research it before keeping it.</p><p>Consider running a scan with Malwarebytes for Mac (free version available). It catches threats that slip past built-in protections.</p><h4>On an iPhone/iPad:</h4><p>Keep iOS updated (Settings &gt; General &gt; Software Update).</p><p>Review installed apps and delete anything unfamiliar.</p><p>Check Settings &gt; General &gt; VPN &amp; Device Management for any profiles you did not install. Unknown profiles can be a sign of compromise.</p><h4>On Windows:</h4><p>Run Windows Security &gt; Virus &amp; threat protection &gt; Quick scan.</p><p>Make sure Real-time protection is turned on.</p><p>Check your browser extensions and remove any you do not recognize.</p><p>For everyone:</p><p>Check your browser extensions (in Chrome: three dots menu &gt; Extensions; in Safari: Settings &gt; Extensions). Remove anything you did not install or no longer use. Malicious browser extensions are one of the most common ways attackers capture credentials.</p><div><hr></div><h3>The Quick-Start Checklist</h3><p>These are the essentials. Print this out. Tape it to the fridge. Hand it to your parents next time you visit.</p><ol><li><p><strong>Open Apple Passwords (or your password manager) and fix every flagged password</strong></p></li><li><p><strong>Change any password you have not updated in the past 12 months</strong></p></li><li><p><strong>Turn on two-factor authentication for email, banking, and social media</strong></p></li><li><p><strong>Run a malware scan on your computer</strong></p></li><li><p><strong>Review and remove unfamiliar browser extensions</strong></p></li><li><p><strong>Delete apps you no longer use from your phone</strong></p></li><li><p><strong>Check for unknown device management profiles on your phone</strong></p></li></ol><p>This is not a complete security overhaul. There is more you can do: removing your information from data broker sites, setting up credit monitoring and fraud alerts, reviewing your privacy settings on social media, and hardening your home network. We will cover those in future editions.</p><p>But these seven steps hit the highest-impact areas. Most attacks succeed because one of these basics was left undone. Fifteen minutes now raises the bar for anyone trying to get in.</p><p>Thanks for reading, I hope this newsletter helped you.  If it did, or if you know anyone who needs this info, please forward this to them!</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-life-event-scams?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-life-event-scams?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-life-event-scams?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p>Research Sources:</p><p>Intruvent CTI Cloud</p><p>FBI Internet Crime Complaint Center, 2025 Annual Report ($7.7B in elder fraud losses)</p><p>FBI El Paso Field Office, &#8220;Bereavement Scams&#8221; public warning</p><p>FTC, &#8220;Protecting Older Consumers 2024-2025&#8221; report to Congress</p><p>AARP Fraud Watch Network, &#8220;Obituary Scams Target Grieving Loved Ones&#8221;</p><p>Blackbird.AI, &#8220;AI-Powered Obituary Scams &amp; Targeted Phishing&#8221;</p><p>NBC Chicago, &#8220;Obit Scam: Illinois Widow Targeted&#8221; (case study)</p><p>CNBC, &#8220;How One Retired Woman Lost Her Life Savings&#8221; (Marjorie Bloom case)</p><p>Experian, &#8220;What You Need to Know About Obituaries and Identity Theft&#8221;</p><p>Komando.com / Brennan Center for Justice, data broker targeting practices</p><p>ID Analytics / TIME / NBC News, 2012 study on deceased identity theft (2.5M annually)</p><p>New York Department of State, &#8220;Ghosting&#8221; identity theft of the deceased</p><p>Aura, &#8220;Identity Theft of a Deceased Person&#8221; (Georgia widow case)</p><p>Michigan Attorney General, &#8220;Obituary Pirates&#8221; warning</p><p>LA County District Attorney, &#8220;Obituary Scams Target Grieving Families&#8221;</p><p>U.S. Department of Veterans Affairs, surviving family member scam warnings</p><p>Malwarebytes, &#8220;Data Broker Protection Rule Quietly Withdrawn by CFPB&#8221;</p><p>USPS Office of Inspector General, change-of-address fraud report (167% increase, 2020-2021)</p><p>Apple, &#8220;Passwords app&#8221; and iCloud Keychain documentation</p><p>Last Updated: April 28, 2026</p><p></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: They Stole Everything. They Encrypted Nothing]]></title><description><![CDATA[Ransomware attacks without ransomware. Data theft without detection. The threat actors are already changing their playbook. Can you keep up?]]></description><link>https://edge.intruvent.com/p/prevent-this-they-stole-everything</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-they-stole-everything</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 21 Apr 2026 18:17:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jst9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>What Happened?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jst9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jst9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 424w, https://substackcdn.com/image/fetch/$s_!jst9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 848w, https://substackcdn.com/image/fetch/$s_!jst9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 1272w, https://substackcdn.com/image/fetch/$s_!jst9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jst9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png" width="1024" height="592" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:592,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:996509,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194939987?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32fed796-d291-411b-b7b9-692e2d95d77f_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jst9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 424w, https://substackcdn.com/image/fetch/$s_!jst9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 848w, https://substackcdn.com/image/fetch/$s_!jst9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 1272w, https://substackcdn.com/image/fetch/$s_!jst9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1afbec2-e1cf-4b62-a109-543375c58514_1024x592.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In January 2026, the Clop ransomware group published 43 new victims to its leak site in a single 24-hour period. Among them: Hilton, The Weather Company, multiple law firms, managed service providers, financial institutions, and universities across the U.S., U.K., Europe, Canada, and New Zealand.</p><p><strong>The attackers never encrypted a single file. They did not need to.</strong> They exploited vulnerabilities in file transfer software, extracted sensitive data, and threatened to publish it. Pay up or your data goes public.</p><p>This was not an anomaly. It was the new playbook.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p>Clop pioneered this approach at scale with the MOVEit Transfer campaign in 2023, impacting approximately 2,000 organizations and 17 million individuals without deploying any encryption. They have continued refining the model ever since.</p><p>The BianLian group followed the same evolution. After a free decryptor neutralized their encryption capability in 2023, BianLian pivoted entirely to stealing data and demanding payment to keep it private. Their ransom demands have climbed from an average of $100,000 to $350,000 to around $3 million per victim. No encryption required.</p><p>And they are not alone. Karakurt. RansomHouse.  A growing number of threat actors have abandoned encryption entirely. They steal your data, send you a ransom note, and wait. If you do not pay, your files appear on a leak site for competitors, criminals, and regulators to find.</p><h2>Why Should You Care?</h2><p>The numbers show a dramatic shift:</p><p><strong>Elevenfold increase:</strong> Data extortion-only attacks rose from 2% of incident response cases to 22% between November 2024 and November 2025</p><ul><li><p><strong>6,182 extortion attacks</strong> occurred in 2025, a 23% increase over 2024, with data-theft-only attacks driving the growth</p></li><li><p><strong>6% of ransomware attacks</strong> in 2025 involved no encryption at all, double the 3% seen in 2024</p></li><li><p><strong>Average dwell time</strong> for exfiltration attacks can stretch to weeks or months, compared to hours or days for encryption attacks</p></li><li><p><strong>94% of leaked passwords </strong>are reused across multiple accounts, giving attackers easy paths from one breach to your network</p></li></ul><p>Here is what makes this worse: your backup strategy will not help you.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pPnB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pPnB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 424w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 848w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 1272w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pPnB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png" width="1024" height="823" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96343168-c16a-45df-8c14-83939615d5af_1024x823.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:823,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1037360,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194939987?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3d13687-5ff4-4615-b966-9f3951615089_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pPnB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 424w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 848w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 1272w, https://substackcdn.com/image/fetch/$s_!pPnB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96343168-c16a-45df-8c14-83939615d5af_1024x823.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Organizations have spent years building robust backup and recovery capabilities to survive ransomware. Attackers noticed. If your systems can be restored in hours, encryption loses its leverage. But stolen data cannot be &#8220;restored.&#8221; Once it is out, it is out. You cannot undo the leak of customer records, employee Social Security numbers, or proprietary business information.</p><p>This is why attackers are pivoting. Encryption was always just a means to an end. The real leverage is the data itself.</p><h2>How Does This Work?</h2><p>Think of it like a silent burglary versus a smash-and-grab.</p><p>Traditional ransomware is loud. Files stop opening. Ransom notes appear on every screen. Systems grind to a halt. Security teams scramble. Everyone knows something is wrong.</p><p><strong>Exfiltration-only attacks are quiet.</strong> The attacker gains access (often through stolen credentials or a vulnerable internet-facing system), moves laterally to find valuable data, and copies it out of the network. <strong>No files are modified. No services go offline. No alarms ring</strong>. The first indication that anything happened may be a ransom note in your inbox, weeks after the theft occurred.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rO1k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rO1k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rO1k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:446677,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194939987?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rO1k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!rO1k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8fb28eb6-7336-486c-955c-d9f63f4e5b75_1200x896.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The tools they use make detection even harder. Instead of obviously malicious software like Rclone or custom exfiltration tools, attackers increasingly use legitimate cloud utilities:</p><p><strong>Azure Copy (AzCopy)</strong> has become a favorite. It is Microsoft&#8217;s official utility for transferring data to Azure Blob storage. It is rarely blocked by endpoint detection and response (EDR) solutions. It uses standard HTTPS connections to *.blob.core.windows.net domains that are typically allowed through firewalls. And the destination is a fully legitimate cloud provider.</p><p>When an attacker uses AzCopy to upload your data to their Azure storage account, it looks almost identical to normal cloud operations. Security teams monitoring for &#8220;malicious&#8221; file transfers may never see it.</p><p>Other common exfiltration methods include:</p><ul><li><p><strong>Azure Storage Explorer:</strong> A GUI version of the same capability</p></li><li><p><strong>Standard cloud sync tools:</strong> Dropbox, OneDrive, Google Drive used to upload stolen data</p></li><li><p><strong>Archive utilities:</strong> Data compressed into smaller packages before transfer</p></li><li><p><strong>Living-off-the-land binaries:</strong> Built-in Windows tools repurposed for data theft</p></li></ul><p>The result: without an encryption event, there is no clear &#8220;moment of compromise&#8221; to trigger incident response. Attackers have days, weeks, or months to find and extract the most valuable data before anyone notices.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!m9jS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!m9jS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!m9jS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1090756,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194939987?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!m9jS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!m9jS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd78f9bd7-1acd-428b-a458-c516a3579782_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Can You Do?</h2><p>Defending against exfiltration-only attacks requires a different mindset than defending against traditional ransomware. Your backup strategy is necessary but not sufficient. You need to catch the theft before it happens.</p><h3>Step 1: Know What Data You Have and Where It Lives</h3><p>You cannot protect what you cannot find. Map your sensitive data:</p><ul><li><p>Where is personally identifiable information (PII) stored?</p></li><li><p>Where are financial records, intellectual property, and trade secrets?</p></li><li><p>Which systems have access to this data?</p></li><li><p>Who has credentials to those systems?</p></li></ul><p><strong>Data Loss Prevention (DLP) tools like Microsoft Purview</strong> can help identify and monitor sensitive data. The goal is visibility: if you do not know what is valuable, you will not notice when it leaves.</p><h3>Step 2: Monitor for Unusual Data Movement</h3><p>Exfiltration attacks create data movement patterns that differ from normal operations. Look for:</p><p><strong>Volume anomalies:</strong></p><ul><li><p>Large file transfers from servers that normally do not send data externally</p></li><li><p>Unusual compression activity (creating large archives before transfer)</p></li><li><p>Spikes in outbound traffic, especially outside business hours</p></li></ul><p><strong>Destination anomalies:</strong></p><ul><li><p>Connections to Azure Blob storage (*.blob.core.windows.net) from systems that do not normally use Azure</p></li><li><p>Data flowing to personal cloud storage accounts (Dropbox, Google Drive, OneDrive personal)</p></li><li><p>Transfers to IP addresses or domains with no business justification</p></li></ul><p><strong>Tool anomalies:</strong></p><ul><li><p>AzCopy or Azure Storage Explorer running on systems where cloud migration is not occurring</p></li><li><p>Archive utilities (7zip, WinRAR) compressing large volumes of files</p></li><li><p>PowerShell or command-line tools accessing sensitive file shares</p></li></ul><p>Configure alerts for these patterns. Endpoint detection tools, network monitoring, and SIEM platforms can all contribute.</p><h3>Step 3: Restrict Outbound Network Access</h3><p>Most servers do not need direct internet access. Lock it down:</p><ul><li><p>Implement egress filtering: servers should only reach the specific external endpoints they require (update servers, API endpoints, etc.)</p></li><li><p>Block or alert on connections to cloud storage providers from systems that do not have a legitimate business need</p></li><li><p>Use a proxy or secure web gateway for outbound traffic so you have visibility and control</p></li><li><p>Consider application allowlisting on critical servers to prevent unauthorized tools from running</p></li></ul><h3>Step 4: Harden Your Identity Layer</h3><p>Most exfiltration attacks begin with compromised credentials. Make initial access harder:</p><ul><li><p><strong>Phishing-resistant MFA everywhere:</strong> Hardware security keys (FIDO2/WebAuthn) are ideal. Authenticator apps are acceptable. SMS is better than nothing but vulnerable.</p></li><li><p><strong>Privileged access management:</strong> Admin accounts should have separate credentials, time-limited access, and enhanced monitoring.</p></li><li><p><strong>Credential hygiene:</strong> Audit for password reuse, default credentials, and service accounts with excessive permissions.</p></li><li><p><strong>Conditional access policies:</strong> Block logins from unexpected locations, devices, or risk levels.</p></li></ul><h3>Step 5: Segment Your Network</h3><p>If attackers gain access to one system, limit how far they can move:</p><ul><li><p>Separate sensitive data repositories from general user networks</p></li><li><p>Restrict lateral movement between segments</p></li><li><p>Apply the principle of least privilege: users and systems should only access what they need</p></li></ul><p>An attacker who compromises a workstation should not be able to reach your file servers, customer databases, or intellectual property repositories without triggering additional authentication or alerts.</p><h3>Step 6: Prepare for the Call</h3><p>Despite your best efforts, an exfiltration attack may still succeed. Have a plan:</p><p><strong>Legal counsel:</strong> Know who to call when you receive a ransom demand. Decisions about payment, disclosure, and law enforcement involvement require legal guidance.</p><p><strong>Incident response retainer:</strong> Have a relationship with an IR firm before you need one.</p><p><strong>Communication templates: </strong>Draft holding statements for customers, employees, regulators, and media.</p><p><strong>Data inventory:</strong> Know what was likely stolen based on what the attackers accessed. This will inform your disclosure obligations.</p><div><hr></div><h2>The Bottom Line</h2><p>Ransomware is evolving. The encryption that used to be the attack&#8217;s signature is becoming optional. Attackers have realized that stolen data is leverage enough, especially when victims have backups that make encryption pointless.</p><p>This shift has real implications. Your disaster recovery playbook will not help you. Your backups will not undo a data breach. And the quiet nature of exfiltration attacks means you may not know you have been compromised until the ransom note arrives.</p><p>The defense is detection: know your data, watch your network, and catch the theft before it is complete. Because once your data is in an attacker&#8217;s hands, your options narrow dramatically.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-they-stole-everything?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-they-stole-everything?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-they-stole-everything?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>Do not let the first sign of compromise be an email demanding millions to keep your data private.</p><div><hr></div><p><strong>Research Sources:</strong></p><ul><li><p>Intruvent Cloud CTI Engine (Codex)</p></li><li><p>Morphisec, &#8220;Ransomware Without Encryption: Why Pure Exfiltration Attacks Are Surging&#8221; (2026)</p></li><li><p>HIPAA Journal, &#8220;Elevenfold Increase in Data-only Extortion Attacks&#8221;</p></li><li><p> Industrial Cyber, &#8220;Ransomware Reaches Elevated New Normal&#8221; (2026)</p></li><li><p>BlackFog, &#8220;Clop&#8217;s New Extortion Wave Hits Oracle&#8221; (2026)</p></li><li><p> GuidePoint Security, &#8220;The Economics of Clop&#8217;s Zero-Day Campaigns&#8221;</p></li><li><p>CISA, &#8220;#StopRansomware Guide&#8221; and BianLian Advisory (AA23-136A)</p></li><li><p>Unit 42/Palo Alto Networks, &#8220;BianLian Threat Assessment&#8221;</p></li><li><p>Cisco Talos, &#8220;Everyday Tools, Extraordinary Crimes: The Ransomware Exfiltration Playbook&#8221;</p></li><li><p> FBI Internet Crime Complaint Center, 2025 Annual Report</p></li><li><p> Heimdal Security, &#8220;Password Breach Statistics 2026&#8221;</p></li></ul><p>Last Updated: April 21, 2026*</p>]]></content:encoded></item><item><title><![CDATA[Intruvent EDGE: CISA Confirms Iranian Disruption of US Critical Infrastructure]]></title><description><![CDATA[From default passwords to legitimate engineering tools: CyberAv3ngers have leveled-up their capabilities, and what Rockwell shops should do this week.]]></description><link>https://edge.intruvent.com/p/intruvent-edge-cisa-confirms-iranian</link><guid isPermaLink="false">https://edge.intruvent.com/p/intruvent-edge-cisa-confirms-iranian</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 16 Apr 2026 18:53:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ycny!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>What Happened</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ycny!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ycny!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 424w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 848w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 1272w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ycny!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:276227,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/heic&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194435892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ycny!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 424w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 848w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 1272w, https://substackcdn.com/image/fetch/$s_!Ycny!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf8f6a38-b747-42f9-82ce-a98c8223ae75_1376x768.heic 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On April 7, 2026, six federal agencies published joint advisory <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">AA26-097A</a> with two phrases that should concern every critical infrastructure operator in America: <strong>&#8220;operational disruption&#8221;</strong> and <strong>&#8220;financial loss.&#8221;</strong></p><p>The advisory, signed by the FBI, CISA, NSA, EPA, Department of Energy, and US Cyber Command, confirms that Iranian-affiliated cyber actors have actively disrupted programmable logic controllers across US water and wastewater systems, energy facilities, and government installations. Not &#8220;attempted to access.&#8221; Not &#8220;may have compromised.&#8221; Disrupted. With confirmed operational and financial impact.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-cisa-confirms-iranian?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-cisa-confirms-iranian?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/intruvent-edge-cisa-confirms-iranian?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p><strong>The threat actor is CyberAv3ngers, a persona operated by Iran&#8217;s Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC).</strong> The same group that compromised water utility PLCs in Pennsylvania in November 2023. The same group whose six operators were designated by the US Treasury in February 2024. The same group the State Department has offered a $10 million bounty on.</p><p><strong>They have advanced their tradecraft. </strong>Where earlier operations relied on internet-exposed devices with default credentials, <em>they are now targeting Rockwell Automation controllers, the most widely deployed industrial automation platform in North America, using legitimate Rockwell engineering software to establish connections that read as normal operator activity on most network sensors.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BKv4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BKv4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BKv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:239874,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194435892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BKv4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!BKv4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e93a977-5d48-4acd-b58e-2fdad19019b1_1376x768.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If your organization operates Rockwell CompactLogix or Micro850 PLCs, particularly in water, energy, or government sectors, this advisory is about you.</p><h2><strong>From Public Defacement to Legitimate Tooling: The CyberAv3ngers Evolution</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wU1g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wU1g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 424w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 848w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 1272w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wU1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png" width="1109" height="856" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:856,&quot;width&quot;:1109,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:174489,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194435892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wU1g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 424w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 848w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 1272w, https://substackcdn.com/image/fetch/$s_!wU1g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7c0ff0d1-cda4-4821-b75e-dedf11f86230_1109x856.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>CyberAv3ngers first surfaced in October 2020 on Telegram, claiming responsibility for power outages in Israel.</strong> The group&#8217;s early public activity emphasized messaging, and some claims were later correlated to imagery from separate incidents. Those years established the brand. The years that followed established the capability.</p><p><strong>In November 2023, the Municipal Water Authority of Aliquippa, Pennsylvania discovered that their Unitronics Vision Series PLC had been compromised and was displaying a defacement message.</strong> CISA confirmed the attack and published advisory <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">AA23-335A</a>. The operators took a pragmatic technical approach, exploiting internet-exposed PLCs running default credentials. Within weeks, CISA documented at least 75 similar compromises across multiple states. The target selection was deliberate: a specific vendor, in a specific sector, at a scale that demonstrated operational tempo.</p><p>The 2023 campaign confirmed CyberAv3ngers as a capable operational group with sustained interest in US critical infrastructure. The 2026 campaign shows where that capability has grown.</p><p><strong>According to AA26-097A, the operators are now using </strong><em><strong>&#8220;leased, third-party hosted infrastructure with configuration software, such as Rockwell Automation&#8217;s Studio 5000 Logix Designer software, to create an accepted connection to the victim&#8217;s PLC.&#8221;</strong></em> They are not exploiting a software vulnerability in the traditional sense. They are using the exact tools that legitimate engineers use to program and maintain these controllers, which means the resulting network traffic looks like engineering activity to most detection tooling.</p><p><strong>This is a meaningful escalation in capability.</strong> Studio 5000 Logix Designer is Rockwell&#8217;s professional engineering environment. Using it requires stolen credentials, a compromised engineering workstation, or exploitation of <strong>CVE-2021-22681</strong>, a cryptographic key vulnerability that permits an actor who obtains a specific key to authenticate to affected PLCs without valid credentials. CISA added CVE-2021-22681 to its Known Exploited Vulnerabilities catalog in March 2026, confirming active exploitation.</p><p>The target set has expanded in proportion to the capability. Rockwell Automation dominates the North American industrial automation market. CompactLogix and ControlLogix controllers run water treatment plants, power generation facilities, manufacturing lines, and oil and gas operations across the continent. Censys identified 5,219 internet-exposed hosts globally responding to EtherNet/IP protocols and identifying as Rockwell Automation devices. 74.6% of them, approximately 3,890 devices, are in the United States.</p><h2><strong>Inside the Attack Chain</strong></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QklY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QklY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 424w, https://substackcdn.com/image/fetch/$s_!QklY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 848w, https://substackcdn.com/image/fetch/$s_!QklY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 1272w, https://substackcdn.com/image/fetch/$s_!QklY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QklY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png" width="1388" height="1782" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1782,&quot;width&quot;:1388,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333267,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194435892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QklY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 424w, https://substackcdn.com/image/fetch/$s_!QklY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 848w, https://substackcdn.com/image/fetch/$s_!QklY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 1272w, https://substackcdn.com/image/fetch/$s_!QklY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7aa71a1e-5c7b-48e6-983e-72bdab08c8e0_1388x1782.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The AA26-097A advisory describes a multi-phase operation targeting specific ports on exposed Rockwell controllers:</p><ul><li><p><strong>Port 44818 (EtherNet/IP):</strong> The primary Rockwell Automation industrial protocol. This is how Studio 5000 communicates with CompactLogix and other Logix-family controllers.</p></li><li><p><strong>Port 2222:</strong> Used for OT configuration and some Rockwell-specific services.</p></li><li><p><strong>Port 102 (ISO-TSAP):</strong> The Siemens S7 communication protocol. Its presence in the advisory suggests the operators are scanning for multiple PLC vendors in parallel.</p></li><li><p><strong>Port 502 (Modbus TCP):</strong> A legacy industrial protocol still widely used. Many Rockwell controllers support Modbus for integration with third-party systems.</p></li><li><p><strong>Port 22 (SSH):</strong> Indicates deployment of persistent access mechanisms. Picus Security&#8217;s analysis of the campaign notes that &#8220;attackers deployed Dropbear SSH on victim endpoints, providing persistent remote access surviving PLC reboots.&#8221;</p></li></ul><p>Once connected, the operators performed two categories of post-access activity:</p><p><strong>Project file extraction.</strong> PLC project files (with .ACD extension in Rockwell environments) contain the ladder logic, control sequences, and configuration parameters that define how the controller operates. Extracting these files yields a complete blueprint of the target facility&#8217;s automation logic, useful for reconnaissance, follow-on operations, or potential kinetic effects.</p><p><strong>HMI/SCADA display manipulation.</strong> The operators modified data displayed on human-machine interfaces and SCADA systems. This is particularly consequential in critical infrastructure environments. If operators cannot trust what their screens tell them, they cannot safely run the facility. A manipulated display could show normal pressure readings while a tank overflows, or hide a dangerous temperature rise until equipment fails.</p><p>The advisory confirms that &#8220;some of the victims experienced operational disruption and financial loss.&#8221; The FBI declined to provide additional details about specific incidents.</p><h2><strong>Who Is CyberAv3ngers?</strong></h2><p>CyberAv3ngers is a state-sponsored program run by the IRGC-CEC, the cyber-electronic warfare arm of Iran&#8217;s Islamic Revolutionary Guard Corps. It is a well-resourced group with sustained access to infrastructure, tooling, and personnel, operating within an established national cyber program.</p><p>The US Treasury designated six IRGC-CEC officials in February 2024 for their roles in the group.  The State Department has offered a $10 million reward for information leading to the identification or location of any person who, while acting at the direction of a foreign government, participates in malicious cyber activities against US critical infrastructure.</p><p>The group is tracked under multiple names across the vendor community:</p><ul><li><p><strong>Storm-0784</strong> (Microsoft)</p></li><li><p><strong>Bauxite</strong> (Dragos)</p></li><li><p><strong>UNC5691</strong> (Mandiant)</p></li><li><p><strong>G1027</strong> (MITRE ATT&amp;CK)</p></li></ul><p>In January 2026, the group rebranded its Telegram channel from &#8220;CyberAv3ngers&#8221; to &#8220;Cyber4vengers.&#8221; The rebrand coincided with a shift toward more technically mature operations.</p><p>Leaked records from December 2025 confirmed operational connections between CyberAv3ngers and Moses Staff, another Iranian state-sponsored group known for destructive wiper operations. Check Point Research has documented approximately 60 affiliated pro-Iranian groups that adopt CyberAv3ngers techniques.</p><h2><strong>The IOCONTROL Connection</strong></h2><p>The Rockwell campaign is not the only active CyberAv3ngers toolset. A parallel thread in the group&#8217;s capability development was documented two years earlier.</p><p>In mid-2024, Claroty&#8217;s Team82 published analysis of a custom malware family called IOCONTROL, attributed to CyberAv3ngers. IOCONTROL is designed to run on a variety of IoT and OT devices, including PLCs, HMIs, routers, and IP cameras. The malware uses:</p><ul><li><p>MQTT over TLS on port 8883 for command and control</p></li><li><p>DNS-over-HTTPS to resolve C2 infrastructure, evading traditional DNS monitoring</p></li><li><p>AES-256-CBC encryption for all communications</p></li></ul><p>IOCONTROL marked a clear step beyond the 2023 Unitronics operations. Where the earlier work centered on public-facing defacement, IOCONTROL extended the toolkit to persistent access and programmatic manipulation of industrial processes across a broader range of device types. By 2024, the group was already investing in purpose-built OT malware, a year and a half before the Rockwell activity in AA26-097A surfaced publicly.</p><p>The relationship between the IOCONTROL work and the 2026 Rockwell exploitation is not explicitly stated in public reporting. Both lines of operation target overlapping sectors and reflect a consistent trajectory toward persistent, vendor-agnostic access to industrial control environments.</p><h2><strong>Why This Advisory Is Different</strong></h2><p>CISA has published many advisories about threats to critical infrastructure. Most describe potential risks or document intrusion attempts. AA26-097A is different because it confirms actual impact.</p><p>On March 18, 2026, the CISA Acting Director stated that CISA was operating at &#8220;steady state&#8221; regarding Iranian cyber threats, despite the ongoing military conflict between the US, Israel, and Iran. The implication at the time was that threat activity remained within normal parameters.</p><p>AA26-097A, published 20 days later, functionally updates that assessment. The advisory confirms that Iranian actors have not merely attempted to access critical infrastructure; they have disrupted it. Facilities have experienced operational impacts. Organizations have incurred financial losses.</p><p>This is also the first joint advisory of the current conflict signed by six federal agencies, including US Cyber Command&#8217;s Cyber National Mission Force. The breadth of signatories signals the severity of the threat and the confidence level in the attribution.</p><p>The geopolitical context matters. Since Operation Epic Fury began on February 28, 2026, the US and Israel have conducted sustained military operations against Iran. The Strait of Hormuz has been effectively closed for over a month. Iran&#8217;s Supreme Leader was killed in an early strike. This week, President Trump issued an ultimatum threatening to destroy &#8220;every bridge&#8221; and &#8220;every power plant in Iran&#8221; if the Strait is not reopened.</p><p>CyberAv3ngers is one of Iran&#8217;s primary instruments of asymmetric cyber operations. The confirmed disruptions in AA26-097A indicate that instrument is in active use against American infrastructure.</p><h2><strong>What You Should Do</strong></h2><div><hr></div><h3>A Note Before You Act</h3><p>The guidance below describes general defensive practices for OT and ICS environments. It is not prescriptive direction for your specific network.</p><p>Operational technology environments are safety-critical. Taking a PLC offline, altering network segmentation, disabling services, or changing keyswitch positions can produce consequences that extend well beyond IT, including process upsets, equipment damage, safety incidents, and regulatory exposure.</p><p>Before implementing any step in this section:</p><ol><li><p>Review the guidance with your OT engineering team, facility operators, and safety personnel.</p></li><li><p> Verify compatibility with your specific device models, firmware versions, and operational context.</p></li><li><p>Consult vendor documentation, including Rockwell Automation advisories, for device-specific procedures.</p></li><li><p> Coordinate changes through your organization&#8217;s change-management and outage-planning processes.</p></li><li><p> Where doubt exists, engage a qualified OT cybersecurity professional familiar with your environment.</p></li></ol><p>This newsletter is threat intelligence reporting, not engineering direction. Intruvent Technologies provides this information on an &#8220;as is&#8221; basis, without warranties of any kind, and accepts no liability for any operational, safety, financial, or other consequences arising from actions taken on the basis of this content. Decisions about your systems are yours to make, with your team, based on your knowledge of your environment.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q9-X!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q9-X!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 424w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 848w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 1272w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q9-X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png" width="1387" height="1669" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1669,&quot;width&quot;:1387,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:364706,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194435892?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!q9-X!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 424w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 848w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 1272w, https://substackcdn.com/image/fetch/$s_!q9-X!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8e9e7177-9c30-4c36-bdaa-d38849d8ae5b_1387x1669.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>Right Away</strong></h3><p><strong>Take internet-exposed PLCs offline.</strong> There is no legitimate reason for a PLC to be directly accessible from the public internet. Every Rockwell CompactLogix, Micro850, or similar controller that responds to public internet queries is a potential target. If your organization has exposed devices, disconnect them now. Remote access should be routed through secured gateways, jump servers, or VPNs with multi-factor authentication.</p><p><strong>Check the ports.</strong> Scan your external perimeter for services on TCP 44818 (EtherNet/IP), 2222, 102 (ISO-TSAP), 502 (Modbus), and 22 (SSH). Any inbound access to these ports from untrusted networks should be blocked.</p><p><strong>Set physical mode switches to RUN.</strong> CompactLogix controllers have a physical keyswitch that can be set to RUN mode, preventing remote programming changes. This is a simple, effective control that many operators overlook. An actor who gains network access to a controller in RUN mode cannot upload new logic without physical access to the device.</p><p><strong>Audit for Dropbear SSH.</strong> The advisory indicates operators deployed Dropbear SSH for persistence. Dropbear is a lightweight SSH server that does not belong on most PLCs. Search for unexpected SSH services on your OT devices.</p><h3><strong>This week</strong></h3><p><strong>Patch CVE-2021-22681.</strong> This cryptographic key vulnerability affects Rockwell Studio 5000 Logix Designer and enables authentication bypass. Rockwell has released mitigations, check them out.</p><p><strong>Review your cellular connectivity.</strong> Many PLCs in remote locations use cellular modems for remote access. These connections often bypass corporate firewalls and security controls. Audit which devices have cellular connectivity and whether that connectivity is necessary.</p><p><strong>Enable network monitoring at OT boundaries.</strong> If you do not have visibility into traffic entering and leaving your OT networks, you cannot detect this activity. Deploy network detection and response capabilities that understand industrial protocols like EtherNet/IP and Modbus.</p><h3><strong>Going forward</strong></h3><p><strong>Implement network segmentation.</strong> PLCs should sit on isolated network segments with controlled access points. Traffic between IT and OT networks should flow through monitored chokepoints. &#8220;Air gaps&#8221; that exist only on network diagrams provide no protection.</p><p><strong>Disable unnecessary services.</strong> VNC, Telnet, FTP, and HTTP management interfaces on PLCs provide additional attack surface. Disable anything not required for operation.</p><p><strong>Monitor for configuration changes.</strong> Establish baselines for PLC project files and alert on unexpected modifications. A change to ladder logic should trigger immediate investigation.</p><p><strong>Develop offline recovery procedures.</strong> If your PLCs are compromised, can you restore them from known-good backups? Are those backups stored offline where they cannot be modified by the same actor? Test your ability to rebuild a compromised controller from scratch.</p><h2><strong>Indicators of Compromise</strong></h2><p>The CISA advisory includes a STIX file with machine-readable indicators at <a href="https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml">https://www.cisa.gov/sites/default/files/2026-04/AA26-097A.stix_.xml</a>.</p><p><strong>Target ports:</strong></p><ul><li><p>TCP 44818 (EtherNet/IP)</p></li><li><p>TCP 2222 (OT configuration)</p></li><li><p>TCP 102 (ISO-TSAP)</p></li><li><p>TCP 502 (Modbus)</p></li><li><p>TCP 22 (SSH)</p></li></ul><p><strong>Affected devices:</strong></p><ul><li><p>Rockwell Automation CompactLogix</p></li><li><p>Rockwell Automation Micro850</p></li><li><p>Any Rockwell/Allen-Bradley device on EtherNet/IP</p></li></ul><p><strong>CVE:</strong></p><ul><li><p>CVE-2021-22681 (CVSS 9.8): Authentication bypass via insufficiently protected cryptographic key in Studio 5000 Logix Designer</p></li></ul><p><strong>Behavioral indicators:</strong></p><ul><li><p>Studio 5000 connections from non-engineering workstations</p></li><li><p>Dropbear SSH processes on PLC or HMI devices</p></li><li><p>Modified PLC project files (.ACD)</p></li><li><p>Inconsistencies between SCADA displays and physical process values</p></li><li><p>Outbound connections from OT devices to unexpected IP ranges</p></li></ul><h2><strong>Sources</strong></h2><ul><li><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a">CISA Advisory AA26-097A</a>, April 7, 2026</p></li><li><p><a href="https://www.picussecurity.com/resource/blog/cisa-alert-aa26-097a-iranian-affiliated-actors-target-plcs-across-us-critical-infrastructure">Picus Security Analysis of AA26-097A</a></p></li><li><p><a href="https://industrialcyber.co/industrial-cyber-attacks/censys-warns-systemic-exposure-of-rockwell-plcs-enable-iran-linked-targeting-of-critical-infrastructure-ot-networks/">Industrial Cyber: Censys Warns of Rockwell PLC Exposure</a></p></li><li><p><a href="https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure">Tenable: CyberAv3ngers FAQ</a></p></li><li><p><a href="https://www.theregister.com/2026/04/07/iran_hackers_disrupting_us_water_energy/">The Register: Iran Intruders Disrupting US Water, Energy Facilities</a></p></li><li><p><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a">CISA Advisory AA23-335A</a>, November 2023 Unitronics Campaign</p></li></ul><div><hr></div><h2><strong>More Iran Cyber Threat Intelligence</strong></h2><p>The CyberAv3ngers campaign is part of a broader pattern of Iranian cyber operations escalating alongside the ongoing military conflict. We&#8217;re tracking 16+ Iranian threat groups actively targeting US and allied infrastructure.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>For continuously updated threat actor profiles, IOC feeds, detection rules, and geopolitical context on the Iran cyber threat, visit the <strong><a href="https://intruvent.com/iran-cyber-threat/">Intruvent Iran Cyber Threat Intelligence Center</a></strong>.</p><p>Resources include:</p><ul><li><p>CyberAv3ngers, Handala, MuddyWater, and 13+ other Iranian APT profiles</p></li><li><p>Iran Conflict SITREP (updated bi-weekly)</p></li><li><p>OT/ICS-specific detection queries for Splunk and Microsoft Sentinel</p></li><li><p>Indicators of compromise with blocking guidance</p></li></ul><div><hr></div><p><em>Intruvent Edge is a bi-weekly threat intelligence newsletter from Intruvent Technologies. For monthly threat reporting and detection, visit <a href="https://intruvent.com/brace">intruvent.com/brace</a>.</em></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Getting Burned by Your Old Passwords]]></title><description><![CDATA[6 billion login attempts. Every month. Using passwords just like yours.]]></description><link>https://edge.intruvent.com/p/prevent-this-getting-burned-by-your</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-getting-burned-by-your</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 14 Apr 2026 16:33:07 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DBda!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DBda!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DBda!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DBda!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DBda!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DBda!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DBda!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1552590,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194119704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DBda!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DBda!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DBda!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DBda!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F848b1594-c104-44e8-8d2d-a6fb7f23dc71_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>What Happened?</h2><p>In March 2025, hackers hit five Australian superannuation funds (retirement accounts) simultaneously. Within 48 hours, they accessed over 20,000 customer accounts and stole AUD $500,000. The victims did nothing wrong. They never clicked a phishing link. They never downloaded malware. They never shared their passwords.</p><p>Their passwords had been stolen years earlier, from completely unrelated breaches, and they were still using them.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The attackers used a technique called <strong>credential stuffing</strong>: they took massive lists of usernames and passwords from old data breaches (LinkedIn 2012, Adobe 2013, Dropbox 2016, and hundreds of others) and systematically tried them against fresh targets. When people reuse passwords across sites, one old breach becomes the key to everything.</p><p>The Australian attack was not sophisticated. It was inevitable. When 109 million email addresses and passwords from a single &#8220;stealer log&#8221; collection appeared online earlier this year, followed by another 183 million from a separate dump, the raw material for these attacks has never been more abundant.</p><p>And it is not just happening in Australia. The FBI issued a public service announcement in March 2026 warning that credential stuffing attacks against financial institutions are surging, with attackers routing their attempts through residential proxy networks to evade detection.</p><div><hr></div><h2>Why Should You Care?</h2><p>The numbers are staggering:</p><ul><li><p><strong>26 billion</strong> automated login attempts happen every month using stolen credentials</p></li><li><p><strong>76% of leaked password</strong>/login combinations still work when tried against other sites</p></li><li><p><strong>83% of organizations</strong> experienced at least one account takeover last year</p></li><li><p><strong>$4.8 million</strong> is the average cost of a credential stuffing breach</p></li><li><p><strong>972 breached websites</strong> are currently tracked by HaveIBeenPwned, with billions of compromised accounts</p></li></ul><p>Here is the uncomfortable truth: if you have been using the internet for more than a few years, your credentials have almost certainly been exposed in at least one breach. The question is not whether your password is out there. The question is whether you are still using it.</p><p>Every dormant account you have ever created, that old forum from 2011, the streaming service free trial you forgot about, the shopping site you used once, is a liability. If that service gets breached (or already has been), your email and password are now in a database that attackers will use against your bank, your email, your work accounts.</p><p>Dormant accounts are 10 times less likely to have two-factor authentication enabled than active accounts. They are not monitored. Nobody notices when they are compromised. They sit there, waiting to be exploited.</p><p>According to a Beyond Identity survey, 10% of people are still using a password they first created as a teenager. That means somewhere out there, a bank account, an email inbox, or a corporate VPN is protected by the same password someone picked for their Neopets account in 2007. Which brings us to this week&#8217;s Oreo and Bean comic:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CK91!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CK91!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CK91!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CK91!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CK91!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CK91!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:433185,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194119704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CK91!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CK91!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CK91!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CK91!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ace4001-0c69-4aa3-ba85-f77305051e58_1200x896.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>How Does This Work?</h2><p>Think of it like a master key ring.</p><p>Every time a company gets breached, the attackers add another set of keys to the ring. LinkedIn breach? That is 117 million keys. Adobe breach? Another 153 million. Dropbox? 68 million more. These &#8220;combolists&#8221; (username/password combinations) circulate freely on criminal forums, often for free.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uwo5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uwo5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uwo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1287663,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/194119704?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uwo5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!uwo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d99452d-e034-43df-aa01-56251afe7ab1_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Attackers then run automated tools that try these credentials against valuable targets: banks, email providers, corporate VPNs, streaming services. They rotate through thousands of residential proxy IP addresses (rented from services like IPRoyal for as little as $4 per gigabyte) so their attempts look like they are coming from ordinary home internet connections all over the world, not a single attacker.</p><p>Rate limiting does not stop them, because each IP only makes a few attempts. Geographic blocking does not stop them, because the proxies are everywhere. Even &#8220;impossible travel&#8221; detection struggles, because the attackers are patient.</p><p>The attack is simple: if you used the same password for LinkedIn in 2012 that you use for your bank today, they are in.</p><div><hr></div><h2>What Can You Do?</h2><p>This is your credential cleanup checklist. Set aside 30 minutes this week and work through it.</p><h3>Step 1: Check What Has Been Exposed</h3><p>Go to <a href="https://haveibeenpwned.com">HaveIBeenPwned.com</a> and enter every email address you have ever used. Yes, that old Hotmail account too. The site will show you every known breach that included your email.</p><p>Do not panic at the list. The point is not to feel bad. The point is to know which passwords are definitely compromised so you can stop using them.</p><p><strong>Bonus:</strong> Check <a href="https://haveibeenpwned.com/Passwords">HaveIBeenPwned.com/Passwords</a> to see if any specific password you use has appeared in a breach. (The site uses a clever privacy technique so your actual password never leaves your device.)</p><h3>Step 2: Delete Accounts You Do Not Use</h3><p>This is the step most people skip, and it is the most important.</p><p>Every old account is an attack surface. If you are not using it, delete it. Here is how to find them:</p><p>1. <strong>Search your email</strong> for phrases like &#8220;welcome to,&#8221; &#8220;confirm your account,&#8221; &#8220;thanks for signing up,&#8221; or &#8220;verify your email.&#8221; This will surface accounts you have forgotten about.</p><p>2. <strong>Check your password manager</strong> (if you use one) for sites you have not visited in over a year.</p><p>3. <strong>Review &#8220;Sign in with Google/Apple/Facebook&#8221;</strong> connections in your account settings. Revoke access to apps and services you no longer use.</p><p>4. Use a service like <a href="https://justdeleteme.xyz">JustDeleteMe</a> to find the account deletion page for specific services. (Some make it deliberately hard to find.)</p><p>For each account you find: if you use it, update the password. If you do not use it, delete it. No exceptions.</p><h3>Step 3: Fix Your Password Hygiene</h3><p>You have heard this before, but here it is again, because it is the single most effective defense:</p><p>1. <strong>Use a password manager</strong>. Bitwarden (free), Apple Passwords, 1Password, Dashlane, or the one built into your browser. The specific tool matters less than actually using one.</p><p>2. <strong>Every account gets a unique password.</strong> Let the password manager generate random 16+ character passwords. You do not need to remember them.</p><p>3. <strong>Turn on two-factor authentication everywhere it is offered.</strong> Authenticator apps (Google Authenticator, Authy, Microsoft Authenticator) are better than SMS, but SMS is better than nothing.</p><p>4. <strong>Secure your password manager recovery.</strong> Your master password should be strong and unique. Store backup codes in a safe place (not a cloud document). If you use biometrics, make sure your backup method is also secure.</p><h3>Step 4: Secure Your Backup Codes</h3><p>Here is a detail most people miss: in the Australian superannuation attack, some victims had MFA enabled, but attackers used stolen backup codes to bypass it.</p><p>Backup codes are the &#8220;break glass in emergency&#8221; option for two-factor authentication. They are also often stored carelessly (in notes apps, cloud documents, or email drafts).</p><p>- Store backup codes in your password manager, or</p><p>- Print them and keep them in a physical safe, or</p><p>- Store them in an encrypted note</p><p>Never store them in plain text in the cloud.</p><div><hr></div><h2>The Bottom Line</h2><p><strong>Your passwords from 2015 are still circulating on criminal forums</strong>. Your dormant accounts from services you forgot about are still vulnerable. And attackers are running 26 billion automated attempts every month to see which old keys still open new doors.</p><p><strong>The good news: you can fix this in an afternoon.</strong> Check what has been exposed. Delete what you do not need. Update what remains. Turn on two-factor authentication. And stop reusing passwords.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-getting-burned-by-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-getting-burned-by-your?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-getting-burned-by-your?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>The Australian victims lost half a million dollars because they were still using passwords from years ago. Do not be the next case study.</p><div><hr></div><p>Sources: </p><p>FBI IC3 (March 2026), HaveIBeenPwned.com, HUMAN Security, Trend Micro, Bitdefender, Consumer Reports Security Planner*</p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Supply Chain Software Attacks]]></title><description><![CDATA[One compromised vendor. 823,548 bank customers exposed. Zero shots fired.]]></description><link>https://edge.intruvent.com/p/prevent-this-supply-chain-software</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-supply-chain-software</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 31 Mar 2026 16:31:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5JR5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>What Happened?</h2><p>Picture your building&#8217;s security company storing a copy of every tenant&#8217;s master key in a warehouse. A thief breaks into the warehouse, copies the keys, then robs 80 apartments. The tenants&#8217; locks were fine. The security company&#8217;s warehouse was the weak link.</p><p>That is almost exactly what happened to Marquis Software Solutions.</p><p>According to Marquis&#8217; lawsuit against SonicWall, In February 2025, attackers compromised SonicWall&#8217;s cloud portal and stole firewall configuration data, including emergency backup passcodes, for a subset of customers. Those passcodes were designed to bypass normal authentication in emergencies. The attackers sat on the stolen keys for months.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Then, in August 2025, they used those passcodes to walk straight into Marquis Software&#8217;s network. Marquis provides core banking software to community banks and credit unions across the country. Once inside, the attackers exfiltrated Social Security numbers, bank account details, and credit card numbers belonging to 823,548 people across 80 banks and credit unions, then deployed ransomware.</p><p>No bank was directly attacked. Every bank was affected.</p><p>This is a <strong>double supply chain attack</strong>: SonicWall (the firewall vendor) fell first, which enabled the breach of Marquis (the banking software vendor), which exposed data from 80+ financial institutions and their customers. Two links in the chain, hundreds of thousands of victims.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5JR5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5JR5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5JR5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b31169f-7421-4445-9859-49984876191e_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1230843,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192742003?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5JR5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!5JR5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b31169f-7421-4445-9859-49984876191e_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>And Marquis was not alone. In March 2026:</p><ul><li><p><strong>APT41</strong> (a Chinese state-backed group) was revealed to have been inside <strong>F5 Networks</strong> for over 12 months, potentially deploying backdoors on customer systems. F5 makes the access control software that banks, hospitals, and government agencies depend on.</p></li><li><p>The <strong>Trivy vulnerability scanner (covered last week)</strong>, a security tool used by thousands of enterprises, was itself compromised when attackers poisoned 76 of 77 release tags on GitHub. The tool organizations trusted to find vulnerabilities became the vulnerability.</p></li><li><p>The <strong>GlassWorm campaign</strong> planted malicious code in 433 packages, repositories, and IDE extensions across GitHub, npm, and VSCode marketplaces, hiding payloads in invisible Unicode characters.</p></li></ul><p>The good news is that there are steps that you can take to minimize the risk from your supply chain&#8230;. Like insisting on a Software Bill of Materials (SBOM) among other controls.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E4u2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E4u2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E4u2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:435542,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192742003?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E4u2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!E4u2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbef7267a-a1e5-46f4-82cb-114d6be38baa_1200x896.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div><hr></div><h2>Why Should You Care?</h2><p>Supply chain attacks are growing faster than almost any other category:</p><ul><li><p><strong>30% of all data breaches in 2025 involved a third-party vendor</strong>, double the rate from previous years (DeepStrike)</p></li><li><p><strong>Supply chain breaches cost $4.91 million on average</strong> and take the longest to detect, averaging 267 days from compromise to containment (IBM Cost of a Data Breach Report, 2025)</p></li><li><p><strong>877,522 malicious packages</strong> were detected in open-source software repositories in 2025, a 73% increase over 2024 (ReversingLabs/Sonatype)</p></li><li><p><strong>$60 billion</strong> in global losses from software supply chain attacks in 2025, projected to reach $138 billion by 2031 (Cybersecurity Ventures)</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PFCh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PFCh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PFCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1078945,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192742003?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PFCh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PFCh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F885eda27-6652-4dc8-b1a7-2700922a80f4_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Here is the part that makes supply chain attacks different from every other type: <strong>you can do everything right and still get hit.</strong> Your firewalls are configured correctly. Your employees passed phishing training. Your systems are patched. But if your software vendor, or your vendor&#8217;s vendor, gets compromised, the attackers ride in on trusted software through the front door.</p><div><hr></div><h2>How Does This Work?</h2><p>Think of it like a contaminated ingredient in a food supply. The restaurant did nothing wrong. The ingredient passed inspection. But everyone who eats the meal gets sick.</p><p>Software supply chains work the same way. Modern organizations depend on dozens (sometimes hundreds) of vendors, each of which depends on their own set of vendors, open-source libraries, cloud providers, and service partners. An attacker who compromises one link anywhere in that chain can reach every organization downstream.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PJVF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PJVF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PJVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192742003?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PJVF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!PJVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe81ba41d-418f-4f52-bbb8-7dd85881dd6b_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The most common supply chain attack patterns right now:</p><ol><li><p><strong>Vendor credential theft</strong> (the Marquis pattern): Steal login credentials or backup codes from a vendor&#8217;s systems, then use that access to reach their customers. The attackers never need to touch the target directly.</p></li><li><p><strong>Software update poisoning</strong> (the Trivy pattern): Inject malicious code into a legitimate software update or open-source package. Every organization that installs the update gets compromised automatically.</p></li><li><p><strong>Developer environment infiltration</strong> (the GlassWorm pattern): Plant malicious code in developer tools, IDE extensions, or code repositories. When developers use these tools, the malicious code harvests credentials and tokens that open doors to production systems.</p></li><li><p><strong>Cloud infrastructure compromise</strong> (the Resolv DeFi pattern): Target the cloud management layer, such as AWS key management or Microsoft Intune admin accounts, rather than the application itself. One privileged cloud key can unlock an entire organization.</p></li></ol><p>What makes these attacks so effective is trust. Organizations trust their vendors. Developers trust their tools. Automated systems trust signed updates. Attackers exploit that trust.</p><div><hr></div><h2>What Can You Do?</h2><h3>If You Run an Organization</h3><p><strong>1. Know your ingredient list.</strong><br>You cannot protect what you do not know about. Build and maintain a <strong>Software Bill of Materials (SBOM)</strong>, an inventory of every piece of software and every vendor your organization depends on. Our colleagues at <a href="https://www.netrise.io/">NetRise</a> have built an excellent platform for exactly this: their tools generate SBOMs from binaries, firmware, and containers, then map every component back to known vulnerabilities and, with their new <strong>Provenance</strong> feature (launched March 2026), trace which developers and organizations are behind each open-source component. If the Trivy compromise taught us anything, knowing what is inside your software stack is no longer optional.</p><p><strong>2. Verify your vendors&#8217; vendors.</strong><br>Third-party risk assessments should not stop at your direct vendors. Ask them: who are <em>your</em> critical vendors? How do you secure <em>their</em> access? According to Marquis, the Marquis breach happened because SonicWall&#8217;s cloud backup practices were inadequate. Marquis trusted SonicWall. Eighty banks trusted Marquis. The chain broke at the link nobody was watching.</p><p><strong>3. Lock down admin accounts like they are the crown jewels.</strong><br>Phishing-resistant multi-factor authentication (hardware keys, not SMS codes) on every administrative account. No exceptions. The Stryker wiper attack (200,000 devices destroyed in March 2026) started with a single compromised Microsoft Intune admin account.</p><p><strong>4. Segment your network so one breach cannot reach everything.</strong><br>If a vendor is compromised, limit what they can access. Your banking software vendor does not need access to your HR systems. Your HVAC vendor does not need access to your customer database.</p><p><strong>5. Plan for your vendor getting breached.</strong><br>Have an incident response plan that specifically addresses the scenario where a trusted vendor is compromised. Know which data is at risk, how to isolate affected systems, and who to call. Practice it.</p><h3>If You Are a Professional (Any Field)</h3><p><strong>1. Use a password manager and unique passwords everywhere.</strong><br>If one service is breached, reused passwords give attackers access to your other accounts. A password manager makes unique passwords easy.</p><p><strong>2. Turn on multi-factor authentication, and secure the backup codes.</strong><br>MFA is essential, but in the Marquis case, attackers bypassed it using stolen emergency backup passcodes. Store your backup codes in a secure location (a password manager or a physical safe), not in a cloud document.</p><p><strong>3. Be cautious with browser extensions and software add-ons.</strong><br>The GlassWorm campaign hid malicious code inside 72 fake VSCode extensions that mimicked popular developer tools. The same approach works with browser extensions, mobile apps, and plugins of all kinds. Stick to well-known, well-reviewed tools, and remove anything you are not actively using.</p><p><strong>4. Update deliberately, not blindly.</strong><br>Patching remains critical, but after the Trivy compromise, security experts recommend a brief waiting period (24 to 48 hours) before adopting updates from sources that are not critical security patches. This gives the community time to catch poisoned updates before they spread.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-supply-chain-software?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-supply-chain-software?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-supply-chain-software?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><h2>The Bottom Line</h2><p>The biggest cybersecurity risk to your organization may not be your own security. It may be your vendor&#8217;s. Supply chain attacks exploit the trust between organizations, and they are growing in frequency, sophistication, and impact. You cannot eliminate the risk, but you can reduce your exposure by knowing your software ingredients, verifying your vendors, and planning for the day one of them gets compromised.</p><div><hr></div><p><em>Research Sources:</em></p><p><em>Intruvent CTI Cloud</em></p><p>American Banker, &#8220;Marquis Breach Toll Rises to 80 Banks, 824,000 Consumers&#8221;</p><p>TechCrunch, &#8220;Marquis Sues SonicWall Over Ransomware Breach&#8221;</p><p>IBM, 2025 Cost of a Data Breach Report</p><p>DeepStrike, &#8220;Supply Chain Attack Statistics 2025&#8221;</p><p>Cybersecurity Ventures, &#8220;Software Supply Chain Attack Costs&#8221;</p><p>Microsoft Security Blog, &#8220;Trivy Supply Chain Compromise Guidance&#8221;</p><p>Intruvent Technologies, BRACE Threat Intelligence Reports, March 2026</p><p><em>Last Updated: March 31, 2026</em></p>]]></content:encoded></item><item><title><![CDATA[Your Vulnerability Scanner Just Became the Vulnerability]]></title><description><![CDATA[Trivy is a popular open-source vulnerability scanner. Last week, it was compromised and used to steal credentials from over 1,000 organizations that trusted it.]]></description><link>https://edge.intruvent.com/p/your-vulnerability-scanner-just-became</link><guid isPermaLink="false">https://edge.intruvent.com/p/your-vulnerability-scanner-just-became</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 26 Mar 2026 16:31:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!PThR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>What Happened</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PThR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PThR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 424w, https://substackcdn.com/image/fetch/$s_!PThR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 848w, https://substackcdn.com/image/fetch/$s_!PThR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 1272w, https://substackcdn.com/image/fetch/$s_!PThR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PThR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png" width="1024" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1378265,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192205276?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F74c3805c-2151-4b97-87c9-383f8b85d760_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PThR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 424w, https://substackcdn.com/image/fetch/$s_!PThR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 848w, https://substackcdn.com/image/fetch/$s_!PThR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 1272w, https://substackcdn.com/image/fetch/$s_!PThR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2def3928-e989-4e7e-99b1-eb3c78203b1b_1024x821.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>On March 19, 2026, a threat actor called TeamPCP compromised Trivy, one of the most widely used open-source vulnerability scanners in the world. The tool that thousands of organizations run inside their CI/CD pipelines to find security flaws was itself weaponized to steal credentials, backdoor developer machines, and spread laterally through cloud infrastructure.</p><p>Over 1,000 cloud environments have been confirmed infected. Aqua Security, Trivy&#8217;s maintainer, is still investigating the full scope. Microsoft, Palo Alto Unit 42, Wiz, Sysdig, GitGuardian, and Arctic Wolf have all published independent analyses. CVE-2026-33634 has been assigned with a CVSS score of 9.4.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>If your organization uses Trivy, GitHub Actions, or any npm packages updated in the last week, keep reading.</p><h1>How the Attack Unfolded</h1><p>The compromise happened in five phases, each building on the last. Understanding this chain matters because the same pattern can be replicated against any open-source project with CI/CD automation.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wYQk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wYQk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wYQk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:144447,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192205276?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wYQk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!wYQk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62058683-1332-47d6-a5c3-70ccf0953ff9_1024x1024.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Phase 1: A Misconfigured Workflow and an Incomplete Fix</h2><p>Sometime in late February 2026, an automated bot called &#8220;hackerbot-claw&#8221; found a misconfigured `pull_request_target` workflow in Trivy&#8217;s GitHub repository. This is a well-documented vulnerability in GitHub Actions: the `pull_request_target` event runs workflows with write access to the repository and makes secrets available to the workflow, even when triggered by a pull request from a fork.</p><p>The bot exploited this to steal a Personal Access Token (PAT) from Trivy&#8217;s CI environment. Aqua Security discovered the theft and rotated credentials, but the rotation was incomplete. According to GitGuardian&#8217;s analysis, residual access paths remained open. TeamPCP retained access to surviving tokens, including credentials for the `aqua-bot` service account, and waited.</p><h2>Phase 2: Binary Poisoning Through Official Channels</h2><p>On March 19 at 17:43 UTC, TeamPCP used the compromised service account to push a malicious Trivy release: version 0.69.4. The commits were crafted to spoof legitimate maintainer identities, reusing original author metadata and timestamps to create a deceptive Git history. The release triggered Aqua&#8217;s automated build pipelines, which published the infected binary to GitHub Releases, Docker Hub, GitHub Container Registry (GHCR), and Amazon ECR.</p><p>Two days later, on March 22, TeamPCP pushed additional malicious Docker images tagged 0.69.5 and 0.69.6 directly to Docker Hub, without corresponding GitHub releases. The last clean version is 0.69.3.</p><h2>Phase 3: Tag Poisoning Turns Every Pipeline into a Weapon</h2><p>This is where the attack scaled. TeamPCP force-pushed malicious commits to 75 of 76 version tags in the `trivy-action` GitHub Action and all 7 tags in `setup-trivy`. Because most GitHub Actions workflows reference actions by version tag (e.g., `@v0.28.0`) rather than by commit SHA, every CI/CD pipeline that referenced these actions began running TeamPCP&#8217;s code on its next execution. No workflow file changed. No pull request was created. The tag simply pointed somewhere new.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OpZv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OpZv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OpZv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:992632,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192205276?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OpZv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OpZv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b42ac5c-a381-409f-a374-9666972949b5_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The poisoned actions executed a three-step credential theft operation:</p><p><strong>Collection. </strong>The malware read directly from GitHub Actions Runner memory (`/proc/&lt;pid&gt;/mem`), bypassing GitHub&#8217;s log-masking to harvest credentials. Targeted secrets included SSH keys, AWS/GCP/Azure cloud credentials, Kubernetes tokens, Docker registry credentials, database passwords, TLS private keys, and cryptocurrency wallet files. It also scraped credentials from over 50 filesystem paths.</p><p><strong>Encryption. </strong>Stolen data was encrypted with AES-256-CBC wrapped in RSA-4096, making network-layer inspection ineffective.</p><p><strong>Exfiltration.</strong>  Primary exfiltration went to a typosquatted domain: `scan.aquasecurtiy[.]org` (note the misspelling of &#8220;security&#8221;), resolving to 45.148.10.212 (TECHOFF SRV LIMITED, Amsterdam). As a fallback, the malware used the victim&#8217;s own stolen GitHub PAT to create a public repository named `tpcp-docs` and uploaded the encrypted credential dump there, using trusted infrastructure as a dead drop.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aKh7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aKh7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aKh7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:993190,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192205276?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aKh7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!aKh7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d7e67d1-9100-414f-b4c1-34b52261cad1_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Phase 4: Persistent Backdoor via Blockchain C2</h2><p>When the malicious Trivy binary ran on developer workstations (not just in CI/CD), it installed a systemd service (`sysmon.py`) that polled an Internet Computer Protocol (ICP) blockchain canister every 50 minutes for command-and-control instructions. Because the C2 infrastructure lives on a decentralized blockchain, it resists DNS sinkholes, domain takedowns, and traditional network-based blocking. The low beacon frequency (every 50 minutes) was designed to evade statistical anomaly detection.</p><h2>Phase 5: CanisterWorm Spreads Through npm</h2><p>Using credentials stolen in Phase 3, TeamPCP launched CanisterWorm, a self-propagating worm that compromised 47+ npm packages across multiple scopes (including @emilgroup, @opengov, and @teale.io namespaces). Twenty-eight packages were compromised within 60 seconds. Later variants added token theft and malicious publishing in postinstall hooks, turning every developer or CI pipeline that installed an affected package into an unwitting propagation vector.</p><p>On March 22, TeamPCP also used a compromised long-lived PAT from the `Argon-DevOps-Mgt` bot account (created July 2023) to breach Aqua Security&#8217;s internal GitHub organization. Within a two-minute window (20:31-20:32 UTC), 44 internal repositories were renamed with a `tpcp-docs-` prefix, exposing Tracee source code, internal forks, CI/CD pipelines, and Kubernetes operators.</p><h1>The Kubernetes Wiper: &#8220;Kamikaze&#8221;</h1><p>One payload deserves special attention. TeamPCP deployed a Kubernetes wiper that deploys privileged DaemonSets across cluster nodes. The behavior is geographically targeted:</p><p><strong>On systems geolocated to Iran:</strong> executes `rm -rf / --no-preserve-root` and forces a system reboot via a container named &#8220;kamikaze&#8221;</p><p><strong>On all other systems:</strong> installs CanisterWorm as a systemd service for persistent backdoor access</p><p><em>The Iranian targeting is notable given the current geopolitical context, but attribution to any state actor has not been established.</em> TeamPCP&#8217;s motivations appear primarily criminal (credential theft, infrastructure compromise) with the Iranian wiper component potentially representing hacktivism, a false flag, or an unrelated vendetta. No vendor has attributed TeamPCP to a nation-state.</p><h1>Why This Matters</h1><p>This attack exploits a fundamental trust assumption: that security tools are trustworthy. Organizations run Trivy inside their most privileged environments (CI/CD pipelines with access to production credentials, cloud infrastructure tokens, and signing keys) precisely because it is a security tool. That trust relationship made the compromise devastatingly effective.</p><h3>Three structural problems made this possible:</h3><p><strong>1.</strong> <strong>Tag-based GitHub Action references are inherently fragile.</strong> If you reference `uses: aquasecurity/trivy-action@v0.28.0`, you are trusting that the tag will always point to the same commit. Tags can be force-pushed. There is no integrity guarantee. This is a known risk that the GitHub Actions ecosystem has not adequately addressed. The fix is to pin actions by full commit SHA, which is immutable.</p><p><strong>2.</strong> <strong>Incomplete credential rotation created the window. </strong>Aqua Security detected the initial PAT theft in late February and rotated credentials, but missed residual access paths. TeamPCP waited and re-entered through a surviving token. As GitGuardian&#8217;s analysis puts it: the core lesson extends beyond detection. Organizations must &#8220;trace blast radius, prioritize rotation, verify remediation, and prove that the same credential cannot be reused tomorrow.&#8221;</p><p><strong>3. Official distribution channels became the delivery mechanism. </strong>The malicious binary was published through GitHub Releases, Docker Hub, GHCR, and ECR. These are the channels organizations trust. There was no phishing email, no drive-by download, no exploitation of a vulnerability in the traditional sense. The attacker simply published a new version through legitimate automation.</p><h1>What You Should Do</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n0Ke!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n0Ke!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 424w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 848w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 1272w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n0Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png" width="1024" height="634" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:634,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:423744,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/192205276?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbec1ce57-805a-4469-a536-290a80a48811_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n0Ke!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 424w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 848w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 1272w, https://substackcdn.com/image/fetch/$s_!n0Ke!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14f1f4d3-70e3-4d4e-bff0-ed1cad32edb8_1024x634.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Immediate (today)</h2><p><strong>Check for affected Trivy versions.</strong> Search your environments for Trivy 0.69.4, 0.69.5, or 0.69.6. The last clean version is 0.69.3. Check GitHub Actions logs, Docker image registries, and developer workstations.</p><p><strong>Audit GitHub Actions workflow runs from March 19 onward.</strong> Review execution logs for `trivy-action` and `setup-trivy`. Look for unexpected network connections, repository creation (especially repositories prefixed with `tpcp-docs`), or credential access patterns.</p><p><strong>Rotate all secrets that were accessible to affected pipelines.</strong> If any pipeline ran a compromised action or binary after March 19, treat every secret accessible to that pipeline as compromised. This includes cloud provider credentials, Docker registry tokens, npm publish tokens, SSH keys, database credentials, and Kubernetes service account tokens.</p><p><strong>Search for persistence mechanisms. </strong>On Linux systems, look for suspicious systemd services: `sysmon.py`, `pgmon.py`, `pgmonitor.service`, `internal-monitor.service`. Check for outbound connections to the ICP canister endpoint (`tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io`) or the typosquatted domain (`scan.aquasecurtiy[.]org`).</p><h2>This week</h2><p><strong>Pin all GitHub Actions by full commit SHA. </strong>Replace every tag-based action reference in your workflows with the full 40-character commit hash. This is the single most effective mitigation against tag poisoning attacks. Yes, it makes updates harder. That friction is the point.</p><p><strong>Audit npm dependencies installed since March 19.</strong> Check for packages in the @emilgroup, @opengov, and @teale.io scopes. Review postinstall hooks in all recently updated packages.</p><p><strong>Review CI/CD pipeline permissions.</strong> Apply least privilege to workflow tokens. Restrict `GITHUB_TOKEN` permissions to the minimum required for each workflow. Eliminate long-lived PATs wherever possible and replace with short-lived, scoped tokens.</p><h2>Going forward</h2><p><strong>Treat CI/CD runners as production infrastructure.</strong> Monitor them with the same rigor you apply to production servers. Credential theft from a CI/CD runner can be more damaging than a production server compromise because runners have access to deployment credentials, signing keys, and cross-environment tokens.</p><p><strong>Implement secret scanning and rotation verification.</strong>  When you rotate credentials after an incident, verify the rotation was complete. Test that the old credential no longer works. GitGuardian, GitHub Advanced Security, and similar tools can help detect lingering exposure.</p><h1>Indicators of Compromise</h1><h3>Network:</h3><p>- `scan.aquasecurtiy[.]org` (typosquatted exfiltration domain)</p><p>- `45.148.10.212` (TECHOFF SRV LIMITED, Amsterdam)</p><p>- `tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0[.]io` (ICP blockchain C2)</p><p>- `plug-tab-protective-relay.trycloudflare.com` (Cloudflare tunnel exfil)</p><p>- `souls-entire-defined-routes.trycloudflare.com`</p><p>- `checkmarx[.]zone`</p><p>- `63.251.162.11`</p><p>- `23.142.184.129` (ICP blockchain infrastructure; monitor only, do not block as this serves legitimate traffic.)</p><p><strong>Note on Cloudflare tunnel domains: </strong>The `trycloudflare[.]com` subdomains above are ephemeral Cloudflare quick tunnels that may already be rotated or expired. Monitor for the pattern but do not rely on these as durable indicators.</p><p><strong>Note on checkmarx[.]zone: </strong>This is a typosquatted domain impersonating Checkmarx (legitimate domain: checkmarx.com). Confirmed as attacker infrastructure by Palo Alto Unit 42.</p><h3>Affected versions:</h3><p>- Trivy 0.69.4, 0.69.5, 0.69.6 (last clean: 0.69.3)</p><p>- trivy-action: 75 of 76 tags compromised</p><p>- setup-trivy: all 7 tags compromised</p><p>- 47+ npm packages across @emilgroup, @opengov, @teale.io scopes</p><h3>Persistence indicators:</h3><p>- systemd services: `sysmon.py`, `pgmon.py`, `pgmonitor.service`, `internal-monitor.service`</p><p>- Repositories prefixed with `tpcp-docs` in your GitHub organization</p><h3>File hashes (select):</h3><p>- `e9b1e069efc778c1e77fb3f5fcc3bd3580bbc810604cbf4347897ddb4b8c163b`</p><p>- `61ff00a81b19624adaad425b9129ba2f312f4ab76fb5ddc2c628a5037d31a4ba`</p><h1>The Bottom Line</h1><p>The Trivy compromise demonstrates that software supply chain attacks are no longer limited to obscure packages or niche tools. A security scanner used by thousands of organizations to protect their infrastructure was turned into a credential harvesting platform, a persistent backdoor, and a worm propagation vector, all distributed through official channels that defenders are conditioned to trust.</p><p>The fix is not complicated, but it requires discipline. Pin your actions by SHA. Rotate credentials completely. Monitor your CI/CD runners. And stop assuming that because a tool is designed to improve your security, it cannot be used to destroy it.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/your-vulnerability-scanner-just-became?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/your-vulnerability-scanner-just-became?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/your-vulnerability-scanner-just-became?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><p>*Research sources: Intruvent CTI Cloud, Microsoft Defender Security Research (March 24, 2026), Palo Alto Unit 42 Cloud Security (March 25, 2026), Wiz Research (March 20-23, 2026), GitGuardian (March 24, 2026), The Hacker News (March 25, 2026), Sysdig Threat Research (March 23, 2026), Arctic Wolf (March 24, 2026), Aqua Security formal advisory (March 23, 2026)*</p><p>For threat hunting queries and detection rules for your SIEM, visit the<strong><a href="https://intruvent.com/threat-intelligence/"> Intruvent Threat Intelligence Hub</a></strong> or for CTU related to the Iran conflict visit the <strong><a href="https://intruvent.com/iran-cyber-threat/">Intruvent Iran Cyber Threat Intelligence Center</a></strong> or contact us at contact@intruvent.com.</p><p>Want sector-specific threat intelligence for your organization? Check out our <strong><a href="https://intruvent.com/brace/#pricing">BRACE CTI platform</a></strong></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Approving Your Own Compromise]]></title><description><![CDATA[How Iranian APT groups steal sessions after you approve the login. And what actually stops them.]]></description><link>https://edge.intruvent.com/p/prevent-this-approving-your-own-compromise</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-approving-your-own-compromise</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 24 Mar 2026 16:30:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AJaq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div><hr></div><h1>What Happened?</h1><p>Last week, we published Threat Actor Profiles (TAPs) and Threat Hunting Guides (THGs) for Iran&#8217;s most dangerous cyber operators and the escalating threat they pose to Western organizations. If you haven&#8217;t seen them yet, our <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a> is the go-to resource for tracking every active Iranian threat group, complete with detection rules, hunting queries, and tactical guidance. Go check it out.</p><p><strong>One technique kept showing up across almost every group we profiled: bypassing multi-factor authentication.</strong></p><p>Not breaking it. Not cracking it. Bypassing it entirely.</p><p>Here&#8217;s how it works. You get an email that looks like it came from Microsoft or Google. The login page looks real. The URL looks close enough. You type your password, get the MFA prompt on your phone, and approve it. You did everything right. You followed the training. You used MFA.</p><p>And the attacker now has your session.</p><p>The page you logged into was running through a reverse proxy: a server sitting invisibly between you and the real Microsoft login. <strong>When you completed your MFA challenge, the proxy captured the session token that Microsoft issued after your successful authentication.</strong> The attacker takes that token, loads it into their own browser, and they&#8217;re in. <strong>Microsoft thinks they&#8217;re you.</strong> MFA never fires again because the token says authentication already happened.</p><p>This isn&#8217;t theoretical. <strong>This is the primary access technique for multiple Iranian state-sponsored groups operating right now.</strong></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>Why Should You Care?</h1><p>Because MFA has become the security equivalent of &#8220;I eat healthy&#8221; while surviving on protein bars and Diet Coke. It feels like you&#8217;re covered. The checkbox is checked. And for years, that was good enough.</p><p>It&#8217;s not good enough anymore.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AJaq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AJaq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AJaq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1449684,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191885579?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AJaq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!AJaq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e9cc165-077a-4266-a583-c6b21d63fd1b_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>APT42, the IRGC Intelligence Organization&#8217;s dedicated credential harvesting unit (also tracked as Charming Kitten and Mint Sandstorm), has built an industrial-scale phishing operation specifically designed to defeat MFA.</strong> Check Point Research documented over 130 phishing domains operated by the group, many running custom React-based phishing kits that intercept MFA tokens in real time. Their targets include journalists, academics, policy researchers, government officials, and cybersecurity professionals. They build trust over weeks of correspondence before sending the malicious link. By the time the phishing page loads, the victim has every reason to believe the interaction is legitimate.</p><p><strong>APT33 (Peach Sandstorm) takes a different approach to the same problem. Rather than sophisticated phishing proxies, they run massive password spraying campaigns against Azure AD and Microsoft 365 environments.</strong> The technique is blunt but effective: try common passwords across thousands of accounts. When they find one that works, they look for ways around MFA. Legacy authentication protocols like IMAP, POP3, and SMTP AUTH don&#8217;t support MFA at all. If your organization hasn&#8217;t explicitly blocked these protocols, an attacker with a valid password can walk right past your MFA controls using a protocol from 1996.</p><p>Then there&#8217;s the Stryker attack. Two weeks ago, <strong>Handala (a front for Iran&#8217;s MOIS destructive operations unit, Void Manticore) compromised a Stryker Corporation admin account and used Microsoft Intune to remotely wipe 200,000 devices</strong> across 79 countries. MFA was in place. It didn&#8217;t prevent the initial credential theft from being leveraged into catastrophic admin abuse. Once the attackers had a <em>single valid session</em> with administrative privileges, every device enrolled in the management platform became a target.</p><p><strong>MuddyWater rounds out the picture. Iran&#8217;s MOIS-affiliated group harvests credentials and then operates entirely within legitimate cloud services for command and control.</strong> They don&#8217;t need to bypass your MFA repeatedly because they&#8217;re working within trusted authentication contexts, using your own cloud infrastructure against you.</p><p>The pattern across all four groups is the same: MFA is a speed bump, not a wall.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!P4DE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!P4DE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!P4DE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:114766,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191885579?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!P4DE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!P4DE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ac008e-d42a-49cc-9f52-a0fe7770b8ff_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>How Does This Actually Work?</h1><p>The tool that makes this possible is called Evilginx. Originally built as a penetration testing tool, it&#8217;s an open-source reverse proxy framework that sits between a victim and a legitimate login page. The attacker sets up a server, registers a domain that looks similar to the real one, and configures Evilginx to proxy traffic to the actual Microsoft or Google login.</p><p>When you visit the phishing page, Evilginx forwards your request to the real login server. You see the real login page, rendered through the proxy. You enter your password. The real server sends back an MFA challenge. You approve it on your phone. The real server issues a session token. Evilginx captures that token before passing the authenticated page back to you.</p><p>You see a successful login. The attacker sees your session token.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-mO4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-mO4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 424w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 848w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 1272w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-mO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png" width="1008" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:595,&quot;width&quot;:1008,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:720462,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191885579?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fda2aef2a-3030-4edd-9a03-b2882159c9d0_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-mO4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 424w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 848w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 1272w, https://substackcdn.com/image/fetch/$s_!-mO4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa173e0a3-3d1c-4d52-b7ae-e0666f514886_1008x595.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>From there, the attacker loads your stolen token into their own browser. <strong>To Microsoft&#8217;s servers, the request looks identical to yours: same token, valid authentication, MFA already completed.</strong> The attacker can now read your email, access your files, and move laterally through your organization. Unless someone notices that your account is suddenly being accessed from two different countries at the same time, there&#8217;s no alert.</p><p>The commercial ecosystem around this technique has matured rapidly. Phishing-as-a-Service platforms like Tycoon 2FA, Sneaky2FA, and Flowerstorm sell ready-made kits that handle the entire reverse proxy setup. No technical expertise required. Push Security&#8217;s 2025 analysis found that MFA bypass is now standard fare in the criminal phishing marketplace, and that roughly one in three phishing attacks they detected were delivered outside of email entirely, through LinkedIn messages, Google search results, and other channels that email security tools never see.</p><p>Token theft accounted for 31% of Microsoft 365 breaches in 2025, making it the leading attack vector ahead of traditional credential compromise. Microsoft documented over 382,000 MFA fatigue attacks in a single year, with research showing that 1% of users blindly accept the first push notification they receive.</p><p>One percent sounds small until you calculate it across an organization with 10,000 employees.</p><h1>What Can You Do?</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1KPC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1KPC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 424w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 848w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 1272w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1KPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png" width="1022" height="690" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:690,&quot;width&quot;:1022,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:825640,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191885579?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29fe6f8a-1b6a-45ea-97aa-b00f20736f40_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1KPC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 424w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 848w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 1272w, https://substackcdn.com/image/fetch/$s_!1KPC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb2cf55-bd4f-422d-a9fe-462b4ac7d2ea_1022x690.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3><strong>For Everyone:</strong></h3><p><em><strong>Stop approving MFA prompts you didn&#8217;t initiate. This is the single most important takeaway from this entire article.</strong></em> If your phone buzzes with a login approval request and you aren&#8217;t actively logging into something, deny it. Every time. That unexpected prompt could be an attacker who already has your password, waiting for you to tap &#8220;Approve&#8221; so they can walk into your account.</p><p>Use a password manager. A good password manager auto-fills credentials only on the exact domain they were saved for. If you land on a phishing page at &#8220;micros0ft-login.com&#8221; instead of &#8220;microsoft.com,&#8221; your password manager will refuse to fill in your credentials. That moment of friction could save your organization.</p><h3><strong>For IT and Security Teams:</strong></h3><p><strong>Deploy phishing-resistant MFA</strong>. Hardware security keys (FIDO2/WebAuthn) and passkeys defeat reverse proxy attacks entirely because the authentication is cryptographically bound to the legitimate domain. The key literally cannot produce a valid response for a phishing site because the domain doesn&#8217;t match. Google deployed hardware security keys to all 85,000+ employees and reported zero successful phishing attacks afterward. Cloudflare survived a sophisticated phishing campaign that compromised other tech companies because their hardware keys refused to authenticate on the phishing domain, even after employees clicked the malicious links and entered their credentials.</p><p>Adoption of phishing-resistant authenticators grew 63% in 2024, according to Okta&#8217;s research. CISA calls FIDO2 and PKI-based authentication the gold standard. Multiple countries are now mandating the retirement of SMS-based authentication. The technology is mature and the deployment playbooks are proven.</p><p><strong>Block legacy authentication protocols. If IMAP, POP3, SMTP AUTH, and other legacy protocols are still enabled in your Microsoft 365 or Entra ID environment, you have a backdoor that bypasses MFA entirely.</strong> Create Conditional Access policies that block legacy authentication. Start in report-only mode to identify any legitimate usage, then enforce. This single change eliminates the attack vector that APT33 and dozens of other groups exploit through password spraying.</p><p><strong>Implement Conditional Access policies with teeth.</strong> Require compliant devices for access to sensitive resources. Restrict authentication to managed devices and known network locations for administrative accounts. Require step-up authentication for high-risk actions. These policies create layers of verification that survive a stolen session token.</p><p><strong>Monitor for token replay. When an attacker steals a session token, there&#8217;s a window where two different sessions using the same token are active from different IP addresses and user agents</strong>. Enable Continuous Access Evaluation in Entra ID, which can detect and revoke tokens when conditions change. Watch for impossible travel patterns. Alert on sessions where the user agent or IP address changes mid-session.</p><p><strong>Shorten token lifetimes for sensitive accounts.</strong> The shorter the session token validity, the smaller the window an attacker has to exploit a stolen token. This creates friction for legitimate users, so apply it selectively to high-privilege accounts where the security tradeoff is worth it.</p><h3><strong>For Security Leaders:</strong></h3><p>Audit your MFA deployment honestly. Check which accounts still use SMS-based MFA. Identify where legacy protocols remain enabled. Find the administrative accounts that have permanently assigned privileges rather than just-in-time access. The Stryker attack demonstrated what happens when a single admin account with broad permissions gets compromised. Least privilege and just-in-time access aren&#8217;t theoretical best practices. They&#8217;re the difference between a compromised account and a compromised enterprise.</p><h1>The Bottom Line</h1><p><strong>MFA still matters. Having MFA enabled is dramatically better than not having it. The vast majority of credential attacks still fail against accounts with any form of MFA enabled.</strong></p><p><strong>But &#8220;I have MFA&#8221; has become the new &#8220;I have antivirus.&#8221; It&#8217;s a starting point, not a finish line.</strong> The Iranian groups we profiled on our <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a> have built entire operational playbooks around the assumption that their targets use MFA. Their attacks are designed from the ground up to defeat it.</p><p>T<strong>he fix exists. Hardware security keys and passkeys are cryptographically immune to these attacks. Blocking legacy protocols closes the password-spraying backdoor. Conditional Access policies and token monitoring catch what gets through. None of this is exotic or experimental. It&#8217;s available today, from the vendors you already use.</strong></p><p>The question isn&#8217;t whether your MFA can be bypassed. It can. The question is whether you&#8217;ve deployed the controls that make bypass meaningless.</p><p><strong>Next time you get an unexpected MFA prompt on your phone, remember: that approval button might be the most dangerous click you make all year. Deny it. Call your IT team.</strong> </p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-approving-your-own-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-approving-your-own-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-approving-your-own-compromise?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><em>Research Sources: Intruvent CTI Cloud, Google Cloud/Mandiant APT42 Research, Check Point Research, Microsoft Threat Intelligence, Cisco Talos, Push Security 2025 Phishing Trends Report, Okta Secure Sign-in Trends Report 2025, Obsidian Security, CISA Phishing-Resistant MFA Guidance, Malwarebytes, Infoblox</em></p><p><em>For the complete Iranian threat actor profiles, detection queries, and hunting guides, visit the <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a>.</em></p><p><em>Last Updated: March 24, 2026</em></p><div><hr></div><p><em>Want sector specific threat intelligence for your organization?  Check out our BRACE CTI platform at <a href="https://intruvent.com/brace">https://intruvent.com/brace</a></em></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Social Media's Open Door — Part 4: The Highlight Reel]]></title><description><![CDATA[Instagram is the number one picture sharing and chat platform in the United States. Here's what you need to know to keep your account and your family safe while using the platform]]></description><link>https://edge.intruvent.com/p/prevent-this-social-medias-open-door-c75</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-social-medias-open-door-c75</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 17 Mar 2026 18:03:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Wwjf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>Welcome New Readers</h1><p><strong>Welcome to new readers!</strong> If this is your first time here, here&#8217;s how this works. P<strong>revent This publishes weekly and covers a specific type of cyber attack,</strong> breaks down how it works, and gives you practical steps to protect yourself. <strong>Every other week, we also publish Intruvent Edge, our cyber threat intelligence newsletter</strong> that takes a deep dive into a specific threat actor, complete with hunting logic and actionable intelligence.</p><h3>From the Intruvent Intel Desk</h3><p>Our latest analysis on Iranian cyber threats is live. If you missed it, check out our Iran Cyber Threat overview at <a href="https://intruvent.com/iran-cyber-threat/">our website.</a>  You can find the most recent Iran Conflict SITREP <a href="https://intruvent.com/wp-content/uploads/threat-intel/iran-conflict/Iran-Conflict-Situation-Report-v1.3.pdf">here.</a></p><p>A big thank you to Shane Shook, advisor to Intruvent and someone whose insight consistently makes our intelligence better. Shane recently shared research on Iranian threat activity that added depth to our own analysis, and we&#8217;ve incorporated his findings into our ongoing coverage.  Shane also recently published a piece at the National Security Institute regarding the new US Cyber Strategy which can be found <a href="https://thescif.org/nsi-experts-weigh-in-the-white-houses-2025-national-security-strategy-d55ce0e7d7c9">here</a>, and is well worth the read.</p><div><hr></div><p>Now, on to this week&#8217;s topic...</p><h1>What is Instagram?</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Wwjf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Wwjf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Wwjf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1511612,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191190793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Wwjf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Wwjf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb9e7be9-cef3-4f16-937d-1f13ad64cdc8_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Instagram is a photo and video sharing platform owned by Meta (formerly Facebook). <strong>With over 2 billion monthly active users, Instagram started as a simple photo filter app. It has evolved into a sprawling ecosystem of Stories, Reels, DMs, shopping, and live streaming.</strong> It is the second most popular social media app among U.S. teens behind YouTube, with 61% of 13 to 17 year olds using it regularly and 47% opening it daily.</p><p>If your teenager has a phone, there is a better than coin-flip chance they are on Instagram right now.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MMLo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MMLo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MMLo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg" width="1200" height="896" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:896,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:413871,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191190793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MMLo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 424w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 848w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!MMLo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fea96a331-5187-41f0-8b29-02fa100300d9_1200x896.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h1>What Happened?</h1><p><strong>In September 2024, Meta announced Instagram Teen Accounts with fanfare.</strong> Built-in protections. Private by default. Messaging restrictions. Content filters. Adam Mosseri, Instagram&#8217;s head, wrote that Teen Accounts were &#8220;designed to give parents peace of mind.&#8221;</p><p>Researchers tested that claim. The results were not encouraging.</p><p>A joint study by ParentsTogether Action, the HEAT Initiative, and Design It for Us found that nearly 60% of teens aged 13 to 15 still encountered unsafe content and unwanted messages on Instagram within a six-month window after Teen Accounts launched. Nearly 60% of kids who received unwanted messages said those messages came from users they believe to be adults. And roughly 40% of those unwanted messages were from people trying to start a sexual or romantic relationship with the teen.</p><p><strong>A separate independent review of Meta&#8217;s 47 stated safety features found that only eight worked as advertised. Nine others reduced harm but had limitations. Thirty features, 64% of the total, were either ineffective or no longer available.</strong> </p><p>It was a good start, but not a full solution&#8230;</p><p>Researchers found that adults could still message teenagers who did not follow them. Instagram&#8217;s algorithm continued recommending sexual content, violent content, and self-harm material to teen accounts despite filters that were supposed to block it. They also found evidence that children under 13 were actively using the platform and that the algorithm was incentivizing their engagement.</p><p>In October 2025, Meta introduced PG-13 content standards for teen users, promising to filter content the way movie ratings filter what kids see in theaters. Posts showing marijuana use, alcohol content, and extreme stunts would be hidden from most teen accounts. Parents could also opt into a stricter &#8220;Limited Content&#8221; mode.</p><p>The safety measures keep coming. The underlying problems keep staying.</p><div><hr></div><h1>Why Should You Care?</h1><p>Because Instagram is ground zero for teen sextortion in America, and the numbers are staggering.</p><p>A joint report from the National Center for Missing and Exploited Children (NCMEC) and Thorn (child safety advocacy experts) analyzed sextortion data from 2020 to 2023. Instagram was the most mentioned platform in financial sextortion reports. In cases where an offender threatened to distribute intimate imagery online, 81% of threats named Instagram as the distribution platform. When images were actually distributed, 60% of the time it happened on Instagram. And in 45% of reports that identified where offenders first made contact with victims, that first contact happened on Instagram.</p><p>The typical victim is not who most parents picture. Ninety percent of financial sextortion victims are boys between the ages of 14 and 17. They are catfished by someone posing as a peer, persuaded to share explicit images, and then blackmailed. The rise of financial sextortion has been linked to organized crime networks in Nigeria and Cote d&#8217;Ivoire, where the tactic is promoted as a way to get rich fast.</p><p>A February 2026 study published in the Journal of Adolescent Health surveyed 3,466 U.S. teens and found that nearly 1 in 3 had received a sext and almost 1 in 4 had sent one. Those numbers are up sharply from 2019. Among teens who sent a sext, nearly half reported their image was shared without their permission. And half of teens who sent a sext reported being targeted with sextortion afterward.</p><p>Teens who sexted someone outside of a current romantic relationship were 13 times more likely to have their images shared without consent and five times more likely to experience sextortion.</p><p>This is not hypothetical risk. This is happening to kids in your neighborhood, at your school, right now.</p><div><hr></div><h1>How Does This Work?</h1><p>Instagram&#8217;s risk profile for teens breaks down into four categories.</p><h3>The Algorithm Problem</h3><p><strong>Instagram&#8217;s recommendation engine is designed to maximize engagement. For teens, that means the algorithm learns what gets a reaction and serves more of it</strong>. Internal Meta research leaked in 2021 showed that Instagram&#8217;s own researchers knew the platform was contributing to body image issues and mental health harm, particularly for teenage girls. Despite years of promises, independent researchers continue to find that the algorithm recommends eating disorder content, self-harm material, and sexually suggestive posts to teen accounts. The algorithm does not care about your child&#8217;s wellbeing. It cares about keeping them scrolling.</p><h3>The &#8220;Private Account&#8221; Myth</h3><p>Many parents believe that setting their teen&#8217;s account to private solves the problem. It helps, but it does not solve it. A private account means new followers need approval. It does not prevent your teen from accepting a follow request from a stranger who looks like a peer. It does not prevent screenshots of their content by approved followers. It does not prevent their profile photo, bio, and username from being visible to everyone. And it does not prevent them from being found through friends&#8217; tagged photos, school hashtags, or location tags. A private account is a speed bump, not a wall.</p><h3>The Direct Message (DM) Pipeline</h3><p>Even with messaging restrictions, teens can still receive messages from anyone they follow or are connected to. Predators and sextortion operators know this. They create accounts that look like peers, engage with the same content, follow friends of the target, and eventually get followed back. Once that connection is made, the messaging restrictions disappear. The conversation often moves quickly to Snapchat or another platform where messages are harder to trace.</p><h3>The Finsta Problem</h3><p>Finstas, or &#8220;fake Instagrams,&#8221; are secondary accounts teens create specifically to post content they do not want parents or their wider social circle to see. These accounts typically have no parental supervision enabled, use a different email address, and exist entirely outside whatever safety guardrails parents have set up on the primary account. Meta&#8217;s own data suggests this is widespread, and Teen Account protections can be bypassed by anyone willing to create a new account with a false birthdate.</p><div><hr></div><h1>What Can You Do?</h1><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gIUK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gIUK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gIUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1103419,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/191190793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gIUK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!gIUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3c1cf55d-9518-4acc-b92d-73be84cbf30d_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Step 1: Set Up Parental Supervision Through Family Center</h3><p>Meta&#8217;s Family Center is the hub for parental oversight on Instagram. It is not perfect, but it is the foundation.</p><p>1. Open Instagram and tap your profile icon (bottom right)</p><p>2. Tap the menu (&#9776;) in the top right, then tap &#8220;Settings and privacy&#8221;</p><p>3. Scroll to &#8220;Supervision&#8221; under the &#8220;For families&#8221; section and tap &#8220;Family Center&#8221;</p><p>4. Follow the prompts to send a supervision invitation to your teen&#8217;s account</p><p>5. Your teen must accept the invitation from their device</p><p>Once connected, you can see who your teen follows and who follows them (but not their messages), set daily time limits from 15 minutes to 2 hours, schedule break times and sleep mode hours, and receive notifications if your teen reports content.</p><p>Important: teens under 16 need your permission to change default safety settings to be less strict. Teens 16 and 17 can change settings on their own. And your teen can remove supervision at any time. Have a conversation about why it stays on.</p><h3>Step 2: Verify Teen Account Settings</h3><p>If your teen is under 16, these should already be the defaults. Verify them anyway.</p><p><strong>Account Privacy:</strong> Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Account privacy &gt; Private Account should be ON.</p><p><strong>Messaging:</strong> Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Messages and story replies &gt; set to &#8220;Only people you follow.&#8221; This prevents strangers from sliding into DMs. Confirm this has not been changed.</p><p><strong>Sensitive Content Control:</strong> Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Content preferences &gt; Sensitive content &gt; Set to &#8220;Less.&#8221; This is the most restrictive option and limits what appears in Explore and Reels. For the updated PG-13 settings, parents can also enable &#8220;Limited Content&#8221; mode here for even stricter filtering.</p><p><strong>Comments:</strong> Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Comments &gt; Select &#8220;People you follow&#8221; to limit who can comment on posts.</p><p><strong>Tags and Mentions:</strong>  Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Tags and mentions &gt; Select &#8220;People you follow&#8221; or &#8220;No one.&#8221;</p><p><strong>Activity Status:</strong>   Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Activity status (under &#8220;How others can interact with you&#8221;) &gt; Toggle OFF. This prevents others from seeing when your teen was last active.</p><p><strong>Story Sharing:</strong>  Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Story &gt; Disable &#8220;Allow sharing to messages.&#8221; This prevents your teen&#8217;s Stories from being forwarded via DM.</p><h3>Step 3: Lock Down Location and Data Exposure</h3><p><strong>Remove location from posts.</strong> Before posting, tap the location field and remove it. This is a phone-level setting, not inside Instagram. </p><p>On iPhone: go to your phone&#8217;s Settings &gt; Privacy &amp; Security &gt; Location Services &gt; Instagram &gt; Set to &#8220;Never.&#8221; </p><p>On Android: phone Settings &gt; Location &gt; App permissions &gt; Instagram &gt; Deny or &#8220;Only while using the app.&#8221; GPS coordinates embedded in photos are metadata gold for anyone building a profile on your child.</p><p><strong>Disable contact syncing</strong>. Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Accounts Center &gt; Your information and permissions &gt; Upload contacts &gt; Instagram &gt; Toggle OFF. This prevents Instagram from mapping your teen&#8217;s entire contact list and suggesting connections to people they may know in real life but should not be connected to online.</p><p><strong>Review connected apps.</strong> Profile &gt; Menu (&#9776;) &gt; Settings and privacy &gt; Accounts Center &gt; Your information and permissions &gt; Apps and websites. Remove any third-party apps your teen has connected to Instagram. These often have broad permissions to access profile data, follower lists, and messages.</p><h3>Step 4: Have the Conversations That Matter</h3><p>Settings are guardrails. Conversations are the actual protection.</p><p><strong>About sextortion:</strong> &#8220;There are criminals who specifically target teenagers on Instagram. They pretend to be your age, build a friendship, and then pressure you into sharing photos. Then they threaten to send those photos to everyone you know unless you pay them. This happens to smart kids every single day. If it ever happens to you, come to me immediately. You will not be in trouble. The person doing it is the criminal.&#8221; Direct them to NCMEC&#8217;s CyberTipline at 1-800-843-5678 or report.cybertip.org.</p><p><strong>About the algorithm:</strong>  &#8220;Instagram is designed to show you more of whatever gets a reaction from you. If you pause on something that makes you feel bad about yourself, it will show you more of it. That is not a reflection of reality. It is a machine optimizing for your attention. If your feed starts making you feel worse instead of better, you can reset your recommendations in Settings and privacy &gt; Content preferences &gt; Reset suggested content.&#8221;</p><p><strong>About finstas:</strong>  &#8220;If you feel like you need a secret account to be yourself, let&#8217;s talk about why. I would rather know about it and help you navigate it than find out after something goes wrong.&#8221;</p><p><strong>About follower requests:</strong>  &#8220;If someone you have never met in real life sends you a follow request, do not accept it. If they have mutual friends, ask those friends if they actually know the person offline. Bots and fake accounts copy real people&#8217;s photos to look legitimate.&#8221;</p><h3>Step 5: Use Your Phone&#8217;s Built-In Tools</h3><p>Instagram&#8217;s controls have gaps. Supplement with operating system level tools.</p><p><strong>Apple Screen Time (iPhone):</strong>  Settings &gt; Screen Time &gt; App Limits. Set a daily limit for Instagram. Enable &#8220;Prevent Changes&#8221; under Content &amp; Privacy Restrictions so your teen cannot override it.</p><p><strong>Google Family Link (Android):</strong>  Set daily app limits, approve or block apps, and monitor usage. These controls operate at the system level, so they cannot be bypassed from within Instagram.</p><div><hr></div><h1>What&#8217;s Next on Their Phones: The Apps You Should Know About</h1><p>This is the final installment of Social Media&#8217;s Open Door. We have covered Snapchat, TikTok, Facebook, and now Instagram. But new platforms are showing up on your kids&#8217; phones all the time. Here are three to watch right now.</p><p><strong>Coverstar</strong> is marketed as the &#8220;safe TikTok alternative.&#8221; No DMs, moderated content, and community guidelines focused on positivity. It sounds great on paper. In practice, profiles are public by default, age verification is easy to bypass by simply deleting and recreating an account with a fake birthdate, the app serves inappropriate advertisements alongside kid content, and a virtual currency system called Starcoins lets followers send real-money gifts during livestreams. A former FBI agent has publicly flagged safety concerns. The user base is almost entirely tween girls dancing on camera for public audiences. The app markets itself with the tagline &#8220;Go viral, not toxic.&#8221; Parenting advocacy group Brave Parenting does not recommend it, noting that despite the safety branding, the platform still promotes comparison, competition, and objectification among children. If your child is using Coverstar, set their profile to private, talk about the difference between creativity and performing for strangers, and monitor for adults attempting to move conversations to other platforms through public comments.</p><p><strong>Lemon8</strong> is owned by ByteDance, the same Chinese company behind TikTok. Think Instagram meets Pinterest: lifestyle content, curated aesthetics, recipes, fashion, and beauty tips. It uses the same algorithmic approach as TikTok to surface content, and it carries the same data privacy concerns. When TikTok was briefly banned in January 2025, Lemon8 disappeared from app stores too because it falls under the same divest-or-ban legislation. ByteDance has been actively paying TikTok influencers to promote Lemon8 as a &#8220;backup app.&#8221; If you had concerns about TikTok&#8217;s data practices, those concerns apply here.</p><p>The common thread across every platform in this series is the same: default settings are not enough, privacy controls have gaps, and the most effective protection is a parent who understands how the app works and talks about it regularly.</p><div><hr></div><h1>The Bottom Line</h1><p>Instagram is the most popular image-sharing platform among American teenagers and the number one platform for sextortion. Meta continues to announce new safety features, and independent researchers continue to find that most of those features do not work as advertised. Teen Accounts are a step in the right direction, but they are not a solution.</p><p>Set up Family Center supervision. Verify every default setting yourself. Lock down location services and contact syncing. Have the hard conversations about sextortion, the algorithm, and secret accounts. Supplement with your phone&#8217;s built-in parental controls.</p><p>And remember the lesson from this entire series: every app on your kid&#8217;s phone is an unlocked door. Your job is to know which doors are open, teach your kids how to recognize who is standing on the other side, and make sure they know they can always come to you when something feels wrong.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-c75?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-c75?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-social-medias-open-door-c75?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>Your kid&#8217;s phone is a gateway to more than just their friends. It connects to your home network, your family&#8217;s location data, and in some cases, your workplace systems. The threat does not stop at their device. But neither does your ability to protect them.</p><div><hr></div><p><strong>Thanks for reading Intruvent Edge! This post is public so feel free to share it.</strong></p><p><strong>This is the final installment of the Prevent This: Social Media&#8217;s Open Door series. Catch up on the full series: Part 1 &#8212; Snapchat, Part 2 &#8212; TikTok, Part 3 &#8212; Facebook.</strong></p><div><hr></div><p><strong>Research Sources:</strong>  NCMEC/Thorn Financial Sextortion Report (2024), ParentsTogether Action/HEAT Initiative/Design It For Us Instagram Teen Accounts Study (2025), TIME Magazine Instagram Investigation (October 2025), Journal of Adolescent Health &#8212; Patchin &amp; Hinduja Sextortion Study (February 2026), Florida Atlantic University Sexting Research (2026), Pew Research Center Teens &amp; Social Media (December 2025), Meta Family Center Documentation, Instagram Teen Accounts Announcement (September 2024), ABC News PG-13 Content Standards Report (October 2025), ConnectSafely Parent&#8217;s Guide to Instagram (2025), Brave Parenting Coverstar Guide (2026), Bark Technologies App Reviews, Gabb Noplace Safety Review (2024)</p><p><strong>Last Updated:</strong> March 17, 2026</p>]]></content:encoded></item><item><title><![CDATA[They Used Your Own Tools Against You]]></title><description><![CDATA[An Iranian hacking group just wiped 200,000 devices at a $100 billion medical company. They didn&#8217;t use malware. They used Microsoft Intune.]]></description><link>https://edge.intruvent.com/p/they-used-your-own-tools-against</link><guid isPermaLink="false">https://edge.intruvent.com/p/they-used-your-own-tools-against</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 12 Mar 2026 18:55:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!41tF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!41tF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!41tF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 424w, https://substackcdn.com/image/fetch/$s_!41tF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 848w, https://substackcdn.com/image/fetch/$s_!41tF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 1272w, https://substackcdn.com/image/fetch/$s_!41tF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!41tF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png" width="1021" height="706" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:706,&quot;width&quot;:1021,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:906233,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190757900?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9a4c581-76a9-48d2-90e0-6e6cc50f10e3_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!41tF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 424w, https://substackcdn.com/image/fetch/$s_!41tF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 848w, https://substackcdn.com/image/fetch/$s_!41tF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 1272w, https://substackcdn.com/image/fetch/$s_!41tF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32307fc3-9c04-4022-be8b-7d9780fcbb46_1021x706.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>On Tuesday morning, employees at Stryker Corporation&#8217;s headquarters in Cork, Ireland walked into work and found every screen displaying the same image: a cartoon of a barefoot boy staring defiantly over his shoulder.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Their laptops wouldn&#8217;t boot. Their phones had been factory reset. Manufacturing systems across 79 countries: offline.</strong> The cartoon was the logo of Handala Hack Team. And the tool they used to pull it off? The same one Stryker&#8217;s own IT department uses every day to manage its devices.</p><p>Microsoft Intune.</p><p><strong>Handala didn&#8217;t deploy custom malware. They didn&#8217;t need a zero-day exploit. They compromised Stryker&#8217;s Intune administration and pushed legitimate remote wipe commands to every enrolled device</strong>: Windows, macOS, iOS, Android. Laptops, phones, tablets. 200,000 devices, according to Handala&#8217;s claim. Including employees&#8217; personal devices.</p><p>Stryker (NYSE: SYK), a $100 billion medtech company with 56,000 employees, told workers to immediately uninstall Intune, Company Portal, Teams, and VPN apps from their personal phones. Employees resorted to WhatsApp to communicate. SYK shares dropped roughly 4.5%. Ireland&#8217;s National Cyber Security Centre was notified.</p><p>This is the first confirmed large-scale weaponization of enterprise device management in a cyber attack. And it should concern anyone running Intune, Jamf, SCCM, Google Workspace MDM, or any other platform that has remote wipe authority over your fleet.  </p><p><strong>Want to make sure that your company isn&#8217;t the next target?  We built a complete intelligence package to help you respond to 4 of the top Iranian cyber threat groups. Situation reports, threat actor profiles, and hunting queries you can run today (click on the image below:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://intruvent.com/iran-cyber-threat/?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=handala-stryker" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6ccX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 424w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 848w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 1272w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6ccX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png" width="1208" height="597" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:597,&quot;width&quot;:1208,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:896435,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://intruvent.com/iran-cyber-threat/?utm_source=newsletter&amp;utm_medium=email&amp;utm_campaign=handala-stryker&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190757900?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F10953ff3-c6c4-47ec-90d5-46058e8e823e_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6ccX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 424w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 848w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 1272w, https://substackcdn.com/image/fetch/$s_!6ccX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdd509bf5-58d2-45fd-91b9-56be9cc8ded5_1208x597.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>(Alternative link: <a href="https://intruvent.com/iran-cyber-threat/"> https://intruvent.com/iran-cyber-threat/</a>)</p><div><hr></div><p>This Isn&#8217;t a Hacktivist Group.  This isn&#8217;t a ransomware operation.  <strong>This is a skilled, determined nation state actor.  One of many professional threat actor groups that work for the Iranian Government.</strong>  </p><p>Handala is the latest person for this skilled adversary, the name comes from Naji al-Ali&#8217;s famous 1969 political cartoon character, a ten-year-old refugee. </p><p><strong>Check Point Research connected Handala to Void Manticore in May 2024. Void Manticore, also tracked as Storm-0842 by Microsoft and BANISHED KITTEN by CrowdStrike, is a destructive operations unit inside Iran&#8217;s Ministry of Intelligence and Security (MOIS)</strong>. They operate under the Counter-Terrorism Division, led by Seyed Yahya Hosseini Panjaki, a sanctioned intelligence official who also goes by &#8220;Seyed Yahya Hamidi.&#8221;</p><p>Here&#8217;s how the MOIS model works. One unit, Scarred Manticore (Storm-0861), handles the espionage phase: breaking in, establishing persistent access, collecting intelligence. When Tehran decides it&#8217;s time to break things, that access gets handed off to Void Manticore for the destructive phase. Check Point calls it the &#8220;one-two punch&#8221; model. It was used in the 2022 Albania campaign. It&#8217;s been used repeatedly against Israel. The gap between initial intrusion and destruction can exceed twelve months.</p><p>Before Handala, this same unit operated as &#8220;HomeLand Justice&#8221; (Albania), &#8220;Karma&#8221;, and &#8220;DarkBit&#8221;. </p><h2>The Escalation Arc You Should Know</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3WF5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3WF5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 424w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 848w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 1272w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3WF5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png" width="1024" height="487" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:487,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:696148,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190757900?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F67265154-c63f-459f-a03d-e6df8523e8ef_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3WF5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 424w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 848w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 1272w, https://substackcdn.com/image/fetch/$s_!3WF5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dc83ea-c9b3-49c8-9d07-3f6259352ec9_1024x487.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Void Manticore&#8217;s capabilities have gotten steadily more dangerous since 2022. Here&#8217;s the trajectory:</p><p><strong>Albania, July 2022:</strong> CL Wiper and GoXML ransomware against government systems. Entry via a SharePoint vulnerability. CISA published a full advisory (AA22-264A) after the FBI confirmed Iranian state attribution.</p><p><strong>Israel, October 2023:</strong> BiBi-Linux &#8212; their first custom wiper targeting Israel, named to mock PM Netanyahu. Corrupts files with random data and slaps on a &#8220;.BiBi&#8221; extension. A Windows variant followed within weeks.</p><p><strong>Early 2024, Operation HamsaUpdate:</strong> Supply-chain-style delivery. Wipers disguised as security updates. Both Windows and Linux variants. Telegram bots for command and control.</p><p><strong>July 2024, The CrowdStrike Lure:</strong> When CrowdStrike&#8217;s Falcon agent caused a global outage, Handala exploited the chaos within hours. Phishing emails from a spoofed domain delivered a wiper through a sophisticated chain that included Bring Your Own Vulnerable Driver (BYOVD) for privilege escalation and a technique that copies a clean .text section over the hooked version to neutralize endpoint detection.</p><p><strong>Late 2024:</strong> Check Point observed Void Manticore pairing the commercial Rhadamanthys infostealer with custom wipers. Researchers described this as a shift from imitating cybercriminals to actively leveraging the cybercrime ecosystem.</p><p><strong>January 2025, School Sirens:</strong> Handala hijacked emergency PA systems in 20 Israeli kindergartens, broadcasting rocket sirens and audio on a Sunday morning. A mass SMS campaign followed.</p><p><strong>March 11, 2026, Stryker:</strong> MDM weaponization. No custom malware required.</p><p>Look at that arc. Web shells in 2022. Custom wipers in 2023. Supply-chain delivery in 2024. Psychological warfare in 2025. Legitimate enterprise tool weaponization in 2026. <strong>Each phase more operationally sophisticated than the last.</strong></p><h2>Why This Changes the Threat Model</h2><p><strong>The Stryker attack inverts a fundamental assumption in endpoint security: that your management tools are on your side.</strong></p><p><strong>Every organization running Intune has given it the ability to remotely wipe any enrolled device.</strong> That is one of the main functions of enterprise MDM. IT teams use it daily: offboarding employees, handling lost devices, enforcing compliance. The capability isn&#8217;t a vulnerability. It&#8217;s a feature.</p><p>But when an attacker gains Intune administrative access, every enrolled device becomes a target for destruction with a single API call. No malware to deploy. No EDR to evade. No YARA rules to match. The wipe command comes from a trusted source through a trusted channel, executed by a trusted agent already installed on every device.</p><p>The Microsoft Graph API exposes this programmatically. An attacker with a compromised admin token or service principal can script a POST request to <code>/deviceManagement/managedDevices/{id}/wipe</code> and hit every device in the tenant. The entire operation can be automated.</p><p>For the technically curious: passive analysis of public data on Stryker&#8217;s external footprint shows a cloud-first environment: Azure, M365, Entra ID. No internet-facing Pulse Secure, Fortinet, PAN-OS, or Citrix appliances visible in public scan data. <strong>That&#8217;s significant because Scarred Manticore&#8217;s standard playbook relies on exploiting perimeter VPN appliances. Those targets don&#8217;t appear to exist here.</strong></p><p><strong>The most probable initial access path? Cloud identity compromise: adversary-in-the-middle phishing to hijack Entra ID session tokens, credential stuffing, or OAuth consent phishing. All well-documented in the Iranian state playbook.</strong></p><p>[<strong>Editor&#8217;s note:</strong> we wrote about the &#8220;red hot&#8221; AiTM technique family on Tuesday&#8217;s edition of Prevent This.  If a small firm like Intruvent has multiple cases in our lab where AiTM was the vector, it shows that it is VERY wide spread]</p><p>One more data point. Stryker disclosed a data breach affecting the period May through June 2024. That timeline aligns uncomfortably well with Scarred Manticore&#8217;s documented persistence model: 12+ months of silent access before handoff to the destructive team. Whether that 2024 breach was the initial intrusion that enabled the March 2026 handoff remains unconfirmed. But that pattern fits, too.</p><h2>The Bigger Picture: Operation Epic Fury</h2><p>The Stryker attack didn&#8217;t happen in a vacuum.</p><p><strong>On February 28, the US and Israel launched Operation Epic Fury: a coordinated military campaign against Iranian military infrastructure.</strong> US Cyber Command degraded Iran&#8217;s internet connectivity to 1-4%. Supreme Leader Khamenei was killed in a targeted strike.</p><p><strong>Within hours, Iran activated the Electronic Operations Room on Telegram to coordinate retaliatory cyber operations</strong>. Palo Alto&#8217;s Unit 42 counted approximately 60 hacktivist groups mobilized under this umbrella, though CrowdStrike assessed that much of the activity was claim-driven rather than evidence-backed.</p><p>Handala&#8217;s claims were different. Handala backed them up with confirmed destruction.</p><p>Twelve days in, the military situation continues to escalate. CENTCOM reports 5,500+ targets struck. Iran&#8217;s True Promise IV missile campaign has reached 37 waves. Israeli forces have entered southern Lebanon. Oil prices spiked to $119/barrel before the IEA released 400 million barrels from strategic reserves. Iranian drones struck three AWS data centers in the UAE and Bahrain. The Strait of Hormuz remains effectively closed.</p><p>Mojtaba Khamenei, the killed Supreme Leader&#8217;s son, was named as Iran&#8217;s third Supreme Leader on March 8. The IRGC pledged full obedience. Iran&#8217;s Foreign Minister stated that Iran is not seeking a ceasefire.</p><p>In this environment, cyber operations aren&#8217;t a side note. They&#8217;re a primary instrument of Iranian asymmetric response.</p><p>We published a comprehensive situation report on the Iran conflict that covers all of this and more &#8212; including a full sector risk assessment and 19-action response framework. It&#8217;s available free and ungated on our new <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a>.</p><h2>What Should You Do Right Now</h2><p><strong>If you run Intune or any MDM platform:</strong></p><ol><li><p>Restrict remote wipe permissions to the absolute minimum number of accounts</p></li><li><p>Require approval workflows for bulk device actions</p></li><li><p>Enforce phishing-resistant MFA on all admin accounts&#8230; not SMS, not push notifications. FIDO2 or Windows Hello for Business</p></li><li><p>Implement Conditional Access policies requiring compliant, managed devices for admin portal access</p></li><li><p>Enable Privileged Identity Management (PIM) with time-limited activations</p></li><li><p>Segment MDM administrative access from general IT accounts</p></li><li><p>Review your BYOD enrollment: ensure personal devices use MAM-only (App Protection Policies) rather than full MDM, so a compromised admin can&#8217;t wipe employees&#8217; personal data</p></li></ol><p><strong>If you have exposure to the conflict (reports state that ALL US AND ISRAELI BUSINESSES are targets:</strong></p><ol><li><p>If you can, elevate SOC to 24/7 staffing</p></li><li><p>Alert/Activate incident response retainers.  At the very least, get your responders to a ready state.  Better yet, see if they can do a Compromise Assessment for you.</p></li><li><p>Review cloud infrastructure for single-region Middle East dependencies</p></li><li><p>Assess supply chain exposure to Strait of Hormuz disruption</p></li><li><p>Brief executive leadership on the sustained nature of the threat &#8212; a diplomatic resolution is assessed as very unlikely within 30 days</p></li></ol><p><strong>Deploy the hunting queries</strong> on our <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a>. We&#8217;ve published copy-paste-ready KQL and Sigma detection rules for Handala&#8217;s MDM weaponization, Lemon Sandstorm&#8217;s VPN exploitation, Agrius wiper families, and MuddyWater&#8217;s RMM tool abuse.</p><h2>What Else Is Moving</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OUBl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OUBl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OUBl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1144783,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190757900?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OUBl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!OUBl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18d58e86-3dab-4fbe-9ba1-b6430bf658f5_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Handala is the loudest actor in this conflict (to date), but not the only one. MuddyWater is deploying new Dindoor and FakeSet backdoors against US financial and aviation targets. Lemon Sandstorm has been pre-positioned inside Western critical national infrastructure for at least two years and may activate dormant access for disruptive ICS/SCADA operations. Agrius is assessed as likely to target energy and financial services within the next 30 days. CrowdStrike recently identified a new group, Hydro Kitten, targeting Western financial services.</p><p>We&#8217;ve published full threat actor profiles and hunting guides for each of these groups. All TLP:CLEAR. All free and ungated. Go get them:</p><p><strong><a href="https://intruvent.com/iran-cyber-threat/">intruvent.com/iran-cyber-threat</a></strong></p><h2>The Bottom Line</h2><p>Handala spent two years conducting psychological warfare and operating under multiple personas. The Stryker attack shows they&#8217;ve crossed a capability threshold.</p><p>MDM weaponization requires no custom malware, no zero-day exploits, and no advanced tradecraft. It requires administrative access to a platform that already has permission to wipe every device in your organization.</p><p>The countermeasures aren&#8217;t exotic. They&#8217;re the same controls security teams have been advocating for years: least privilege, phishing-resistant MFA, just-in-time access, conditional access policies, and monitoring for anomalous admin actions. The difference is that, as of March 11, 2026, those controls are no longer theoretical best practices. They&#8217;re the difference between operations continuing and 200,000 devices going dark.</p><p>If your Intune admin accounts are protected by SMS-based MFA and permanently assigned Global Administrator roles, you already know what needs to change.</p><p>Stay vigilant. Stay prepared. And stay tuned.</p><div><hr></div><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/they-used-your-own-tools-against?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/they-used-your-own-tools-against?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/they-used-your-own-tools-against?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p></p><div><hr></div><p></p><p><em>Research Sources: CISA Advisory AA22-264A, Check Point Research, Palo Alto Unit 42, Splunk, Trellix, Intezer, SecurityJoes, BlackBerry Research, Krebs on Security, Zetter Zero Day</em></p><p><em>For the complete IOC list, detection queries, and hunt procedures, visit the <a href="https://intruvent.com/iran-cyber-threat/">Iran Cyber Threat Intelligence Center</a>.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Prevent This: Social Media's Open Door, Part 3: The Everything App]]></title><description><![CDATA[Facebook was the original Social Media phenomenon. From Cambridge Analytica to AI Training Data: A Parent and Business Leader's Guide to Facebook's Security Risks and How to Lock It Down.]]></description><link>https://edge.intruvent.com/p/prevent-this-social-medias-open-door-afe</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-social-medias-open-door-afe</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 10 Mar 2026 17:12:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AUJM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>What is Facebook?</h1><p>Facebook is the world&#8217;s largest social media platform, owned by Meta Platforms, Inc. With over 3 billion monthly active users, it tries to be your number one social stop on the Internet.  It&#8217;s a marketplace, a news feed, a business directory, a messaging platform, a dating app, and increasingly, an AI training dataset, <strong>all rolled into one account tied to your real name, your real face, and likely your real phone number.</strong></p><p>Unlike Snapchat (built for teenagers) or TikTok (built for entertainment), Facebook was engineered from the start around <em>identity</em>. Your actual name. Your actual network. That design choice is both its power and its most significant security liability.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div><hr></div><h1>The Good</h1><p>Facebook has real value. For many families, it&#8217;s how grandparents stay connected with grandchildren. For small businesses, it&#8217;s often their primary online presence. For community organizations, nonprofits, and local news, it&#8217;s become the town square. Facebook Groups and Marketplace are genuinely useful tools, and Facebook&#8217;s infrastructure for staying in touch with people across time zones and generations is unmatched.</p><p>Meta has also invested heavily in security infrastructure over the years. It employs thousands of security engineers, runs a robust bug bounty program, and offers two-factor authentication, login alerts, and account recovery tools that are, when actually turned on, quite effective.</p><p>But the gap between what Facebook <em>can</em> do to protect you and what it <em>does</em> by default is wide. And the company&#8217;s history with your data deserves an honest look before we get to the settings.</p><div><hr></div><h1>The Track Record: A Pattern Worth Understanding</h1><p>Facebook has been fined, sued, and hauled before Congress more times than any other technology company in history.  Here are some notable instances:</p><p><strong>The Cambridge Analytica Scandal</strong> remains the most significant data privacy incident in social media history. In 2014, a psychology researcher named Aleksandr Kogan built a quiz app that collected data not only from the 270,000 people who took it, but through a loophole in Facebook&#8217;s API, from all of their friends as well. The result: personal data from approximately <strong>87 million Facebook users</strong> was harvested and handed to Cambridge Analytica, a political consulting firm, without those users ever knowing. The data was used to build psychological profiles for targeted political advertising.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AUJM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AUJM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AUJM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:413481,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190410237?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AUJM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AUJM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcd392aba-e835-4dc1-b344-90c989d6eb2b_1376x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Facebook knew about it in 2015 and asked Cambridge Analytica to delete the data. They didn&#8217;t. The public didn&#8217;t find out until 2018.</p><p><strong>The FTC fined Facebook $5 billion in 2019 to settle the investigation into the incident, according to</strong> <strong><a href="https://en.wikipedia.org/wiki/Facebook%E2%80%93Cambridge_Analytica_data_scandal">Wikipedia</a>.</strong>  As recently as November 2025, Facebook executives and a group of Meta shareholders agreed to a $190 million settlement in a lawsuit alleging that leadership prioritized executives over the company&#8217;s fiduciary responsibility to investors.   And in July 2025, an $8 billion class action lawsuit against Meta Founder Mark Zuckerberg and other Meta board members went to trial according to <a href="https://www.cbc.ca/news/world/meta-shareholders-lawsuit-begins-1.7586176">CBC News</a>.  The legal fallout from that single incident is still unfolding, a decade later.</p><p>The Cambridge Analytica scandal mattered because it exposed something most users didn&#8217;t understand: <strong>your Facebook data doesn&#8217;t stay between you and Facebook.</strong> Every app you&#8217;ve ever connected to your account, every quiz you&#8217;ve taken, every &#8220;Login with Facebook&#8221; button you&#8217;ve ever clicked, those are all doors. And Facebook&#8217;s history shows those doors haven&#8217;t always had locks.</p><p><strong>The 2021 Data Breach</strong> is less famous but directly relevant. Phone numbers, full names, birth dates, email addresses, and location data from <strong>533 million Facebook users</strong> were published in a hacker forum. If you had a Facebook account before 2019, your phone number was likely in that dataset. Attackers routinely reuse data from breaches like this for targeted phishing, profile-based extortion, credential stuffing, and SIM swap attacks that can escalate from social media into banking and email account takeovers (source: <a href="https://www.expressvpn.com/blog/facebook-data-breach/">ExpressVPN</a>).</p><p><strong>AI Training</strong> is the newest front. Facebook uses public data for AI training, which has raised privacy concerns (source: <a href="https://www.allthingssecured.com/tutorials/facebook-privacy-settings/">All Things Secured</a>).   In May 2025, Meta confirmed it was using public posts, photos, and comments from Facebook and Instagram to train its AI models, including content posted by users going back years. The opt-out exists,  but it&#8217;s buried and doesn&#8217;t apply to data already used.</p><div><hr></div><h1>Why Parents Should Care</h1><p>Facebook&#8217;s minimum age is 13, but a 2011 study found that 76% of parents reported their child joined Facebook younger than 13 according to <a href="https://en.wikipedia.org/wiki/Privacy_concerns_with_Facebook">Wikipedia</a>. The platform removes roughly 20,000 underage accounts per day, which tells you both that the problem is massive and that they are trying to handle enforcement of their rules.</p><p>For teenagers on the platform, the risks aren&#8217;t hypothetical. Predators use Facebook&#8217;s search features and public group memberships to identify and target minors. Scammers impersonate classmates or run fake marketplace listings targeting teens. And the &#8220;real name&#8221; requirement that makes Facebook feel safer than anonymous platforms actually makes it easier for bad actors to build convincing fake profiles that exploit your family&#8217;s trust network.</p><p>The <strong>account cloning attack</strong> is particularly relevant for parents: a criminal copies your profile photo and name, creates a new account, and then sends friend requests to everyone on your list, your kids included. Once connected, they have access to your network and a credible-looking identity to run scams from.</p><div><hr></div><h1>Why Business Leaders Should Care Specifically</h1><p>Facebook offers &#8220;Login with Facebook&#8221; as an authentication method for any business system or application.  This means that employees or customers can use their Facebook login credentials to authenticate to 3rd party applications.  But, the security of that system is now tied to the security of each employee&#8217;s personal Facebook account. Many organizations don&#8217;t realize they&#8217;ve accepted that risk.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fR2Z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fR2Z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fR2Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2590593,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190410237?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fR2Z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!fR2Z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f49433f-7380-49f0-bfde-44ae67c27b57_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Beyond that, business pages and Facebook Business Manager accounts are high-value targets. Hackers who gain access to your Business Manager can run paid ad campaigns on your credit card, impersonate your brand, access customer data in connected apps, and lock you out of your own page. These attacks are common, sophisticated, and often executed through phishing emails that look exactly like official Meta security alerts.</p><p>Employee social engineering is another vector. Attackers research leadership teams on Facebook to build convincing pretexts, the same technique that powers the vishing attacks covered in an earlier issue of this newsletter. A company org chart can be reconstructed from public Facebook profiles in under an hour.</p><div><hr></div><h1>How to Make Facebook (More) Secure</h1><p>Fair warning: Meta updates its interface frequently, and settings move. If you can&#8217;t find something exactly where described, use the search function within Settings to locate it.</p><p>Here&#8217;s a sharable cheat sheet, followed by the long form instructions:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TYmJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TYmJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 424w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 848w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 1272w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TYmJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png" width="918" height="1319" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1319,&quot;width&quot;:918,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2096732,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/190410237?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75b8424e-087d-4378-8f6b-967df45c935b_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TYmJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 424w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 848w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 1272w, https://substackcdn.com/image/fetch/$s_!TYmJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4a4a231a-f625-4e1b-9cf0-1c4b95260b17_918x1319.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>For Personal Accounts</h2><h3>Step 1: Lock Down Your Login</h3><p><strong>Enable Two-Factor Authentication (2FA).</strong> This is non-negotiable</p><ul><li><p>Go to <strong>Settings &amp; Privacy &gt; Settings &gt; Accounts Center &gt; Password and Security &gt; Two-Factor Authentication</strong></p></li><li><p>Choose an <strong>authenticator app</strong> (Google Authenticator, Authy, or similar) rather than SMS. SMS codes can be intercepted via SIM swap attacks</p></li></ul><p><strong>Turn on Login Alerts</strong></p><ul><li><p>In the same <strong>Password and Security</strong> section, enable <strong>Get alerts about unrecognized logins</strong></p></li><li><p>Set alerts to both email and in-app notifications</p></li></ul><p><strong>Review Active Sessions</strong></p><ul><li><p>Under <strong>Password and Security &gt; Where You&#8217;re Logged In</strong>, review every active session</p></li><li><p>Log out of anything you don&#8217;t recognize immediately</p></li></ul><div><hr></div><h3>Step 2: Audit Connected Apps &#8212; This Is the Cambridge Analytica Fix</h3><p>This is the single most overlooked security action on Facebook, and it&#8217;s where the Cambridge Analytica-style risk lives</p><ul><li><p>Go to <strong>Settings &gt; Your Activity &gt; Apps and Websites</strong></p></li><li><p>Review everything listed. Be ruthless. If you haven&#8217;t used an app in the past year, remove it</p></li><li><p>When you remove an app, also select the option to <strong>delete your activity</strong> on that app</p></li><li><p>Pay special attention to apps that have access to your friends list or your profile information</p></li></ul><p>Do this every six months. Apps change ownership, get acquired by data brokers, or simply go dark while retaining the data access they were granted years ago</p><div><hr></div><h3>Step 3: Tighten Your Privacy Settings</h3><ul><li><p><strong>Settings &gt; Privacy Checkup &gt; Who Can See What You Share</strong></p><ul><li><p><em>Who can see your future posts?</em> Set to <strong>Friends</strong> (not Public)</p></li><li><p><em>Limit the audience for past posts?</em> Run this once to retroactively restrict everything you&#8217;ve shared publicly</p></li><li><p><em>Who can see the people, Pages, and lists you follow?</em> Set to <strong>Only me</strong></p></li></ul></li><li><p><strong>Settings &gt; Privacy Checkup &gt; How People Find and Contact You</strong></p><ul><li><p><em>Who can send you friend requests?</em> Set to <strong>Friends of Friends</strong></p></li><li><p><em>Who can look you up using your email address?</em> Set to <strong>Only me</strong></p></li><li><p><em>Who can look you up using your phone number?</em> Set to <strong>Only me</strong></p></li><li><p><em>Do you want search engines outside of Facebook to link to your profile?</em> Set to <strong>No</strong></p></li></ul></li></ul><div><hr></div><h3>Step 4: Lock Down Your Profile Information</h3><ul><li><p>Go to your <strong>Profile &gt; About</strong> and review every field</p></li><li><p>Birthday: set to <strong>Only Me</strong> or remove the year entirely (birthdates are commonly used in identity theft)</p></li><li><p>Phone number: <strong>Only Me</strong>, or remove it from your profile entirely</p></li><li><p>Workplace and hometown: consider whether this information needs to be public</p></li><li><p>Check-ins and location: disable automatic location tagging on posts</p></li></ul><div><hr></div><h3><s>Step 5: Opt Out of AI Training</s></h3><ul><li><p>This option has (apparently) been removed in the latest versions of the Facebook Application.</p></li></ul><div><hr></div><div><hr></div><h2>For Parents of Teens (Under 18)</h2><p><strong>Use Supervision Tools.</strong></p><ul><li><p>Facebook has a <strong>Supervision</strong> feature for teens under 18, accessible through <strong>Settings &gt; Family Center</strong> on a parent account</p></li><li><p>This lets you see who your teen is connected with and receive activity updates</p></li><li><p>Similar to TikTok&#8217;s Family Pairing, set it up even if your teen pushes back</p></li></ul><p><strong>Review Their &#8220;About&#8221; Section Together.</strong></p><ul><li><p>Walk through every piece of information your teen has posted publicly</p></li><li><p>No phone numbers, no school name visible to non-friends, no location</p></li><li><p>The rule: if you wouldn&#8217;t put it on a flyer stapled to a telephone pole, it shouldn&#8217;t be public</p></li></ul><p><strong>Have the &#8220;Stranger&#8221; Conversation for Social Media.</strong></p><ul><li><p>The threat isn&#8217;t a stranger in a van. It&#8217;s a person who sent a friend request that looked like it came from someone they know.</p></li><li><p>Teach them: if someone they don&#8217;t recognize adds them, they don&#8217;t need to accept. Ever.</p></li><li><p>The platform makes it easy to accept because it <em>suggests</em> people. Suggestion is not endorsement.</p></li></ul><p><strong>Clone Attack Awareness.</strong></p><ul><li><p>Tell your teen: if they get a second friend request from someone already on their list, that&#8217;s a cloned account. Don&#8217;t accept it. Report it. Tell you.</p></li></ul><div><hr></div><h2>For Business Pages and Business Manager</h2><p><strong>Secure Your Business Manager Account First.</strong></p><ul><li><p>Go to <strong>business.facebook.com &gt; Business Settings &gt; Security Center</strong></p></li><li><p>Enable <strong>Two-Factor Authentication for Everyone</strong> to force all users on your Business Manager to use 2FA, not just admins</p></li><li><p>Review <strong>People</strong> and remove anyone who no longer works for your company. This is routinely neglected after employee departures.</p></li></ul><p><strong>Limit Ad Account Permissions.</strong></p><ul><li><p>Under <strong>Business Settings &gt; Ad Accounts</strong>, restrict who has financial control over adding payment methods or running campaigns</p></li><li><p>Set spending limits on all active ad accounts</p></li><li><p>Enable email alerts for all ad account activity</p></li></ul><p><strong>Set Up Brand Impersonation Monitoring.</strong></p><ul><li><p>Regularly search for your company name on Facebook to find pages impersonating your brand</p></li><li><p>Use <strong>Facebook&#8217;s Brand Rights Protection</strong> tools if you have a trademark</p></li><li><p>Report fake pages immediately. Cloned business pages are used to run scams targeting your customers.</p></li></ul><p><strong>Never Click Security Emails Without Verifying.</strong></p><ul><li><p>Phishing emails impersonating Meta Business security alerts are extremely common</p></li><li><p>Always go directly to <strong>business.facebook.com</strong> rather than clicking any email link claiming to be from Meta</p></li><li><p>Real Meta alerts will be waiting for you inside Business Manager when you log in directly</p></li></ul><div><hr></div><h1>The Bottom Line</h1><p><strong>Facebook is the most powerful identity platform on the internet. That power cuts both ways</strong>. It connects you to real people in your life, and it hands your real identity to anyone who gains access to your account, your connected apps, or your data.</p><p>The company&#8217;s track record is mixed when dealing with privacy vs monetization decisions. That&#8217;s not a reason to delete your account. I<strong>t&#8217;s a reason to stop treating Facebook like a trusted friend and start treating it like a business relationship, one where you&#8217;ve read the contract, audit the terms regularly, and don&#8217;t hand over more than you have to.</strong></p><p>The settings above take about 30 minutes to implement. They won&#8217;t make you invisible. But they&#8217;ll close the doors that Cambridge Analytica walked through, limit what third parties can see and harvest, and give you a fighting chance if someone tries to take over your account or clone your identity.</p><p><strong>If you use Facebook, you should implement these steps as soon as possible.</strong></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-afe?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-afe?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-social-medias-open-door-afe?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><em>Research Sources: Meta Privacy Policy and Terms of Service (2025), FTC v. Facebook enforcement records, Cambridge Analytica Congressional testimony and court records, ExpressVPN Facebook Data Breach Analysis, Keller &amp; Heckman Kids and Teens Privacy Report (January 2026), Internet 2.0, Meta Business Help Center, Thomas Law Offices Meta/Facebook Minor Safety Analysis, CBC News Cambridge Analytica lawsuit coverage (July 2025)</em></p><p><em>Last Updated: March 10, 2026</em></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Session Hijacking]]></title><description><![CDATA[Changing your password won't save you. Here's why attackers don't need it anymore.]]></description><link>https://edge.intruvent.com/p/prevent-this-session-hijacking</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-session-hijacking</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 03 Mar 2026 18:33:51 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jmt_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>A quick note:</strong> We're taking a one-week break from our "Social Media&#8217;s Open Door" series. Instagram and TikTok guides are live, and we'll pick back up with the rest soon. In the meantime, this attack is in our lab right now and it's too important to wait.</p><h2><strong>What Happened?</strong></h2><p>In January 2026, Microsoft flagged a multi-stage attack campaign hitting energy companies across multiple countries. The attackers weren&#8217;t stealing passwords. They were stealing something better.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The attack started with a SharePoint link. Looked normal. Came from a legitimate vendor email that had already been compromised. <strong>When employees clicked and logged in, attackers captured their session token in real time.</strong></p><p><strong>That token is basically a digital keycard. Once the attacker has it, they&#8217;re already inside. No password needed. MFA already bypassed.</strong></p><p><em>Within 14 minutes of capturing a token, attackers were creating inbox rules to hide their activity and sending 600+ phishing emails</em> from the compromised account. Internal contacts. External partners. Distribution lists. All from a trusted sender.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jmt_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jmt_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jmt_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:113307,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189726197?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jmt_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!jmt_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8abfb1a8-a980-4606-ac6e-75dafa096921_1024x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>By the time IT noticed, the attack had spread to multiple organizations.</p><p><strong>The technique is called Adversary-in-the-Middle (AiTM). And it&#8217;s everywhere right now.</strong>  We have multiple cases in the Intruvent Forensic Lab right now where this is the attack vector the bad guys used.</p><h2>Wait... Didn&#8217;t We Cover This Before?</h2><p>You might be thinking &#8220;this sounds like the Man-in-the-Middle attacks we covered last month.&#8221; You&#8217;re half right.</p><p>Traditional MitM attacks intercept data flowing between two parties. Someone tapping a phone line to eavesdrop, or stealing your password as it travels to the server. The defense was straightforward: encryption and multi-factor authentication. For a while, that worked.</p><p><strong>AiTM attacks evolved specifically to defeat MFA.</strong></p><p>Classic MitM attackers eavesdrop passively. <strong>AiTM attackers set up a fake login page that relays everything in real-time to the legitimate site, including your MFA code. They&#8217;re not just listening to the conversation. They&#8217;re participating in it</strong>, handing your credentials to Microsoft on your behalf and pocketing the session token that comes back.</p><p>Think of it via this analogy:  Classic MitM steals your key. AiTM waits for you to unlock the door, then clones the &#8220;already verified&#8221; badge before you step inside.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HuUb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HuUb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HuUb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:184210,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189726197?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HuUb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HuUb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F88183801-980e-4908-9a5c-760af8198a4f_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This is why phishing-resistant MFA matters. Hardware security keys and passkeys are bound to the legitimate site&#8217;s domain and can&#8217;t be relayed through a fake page. Wrong domain, no authentication.</p><div><hr></div><h2><strong>Why Should You Care?</strong></h2><p>You&#8217;ve probably heard that MFA stops 99% of attacks. That was true. Past tense.</p><p>AiTM attacks don&#8217;t try to guess your password or brute-force your MFA code. They sit between you and the login page, relaying everything in real time. You enter your password. They capture it. You enter your MFA code. They capture that too. You get logged in. So do they.</p><p>The session token you receive? They have a copy. And that token works from anywhere.</p><p>Password resets don&#8217;t help. The attacker already has a valid session. MFA resets don&#8217;t help either. The session is already authenticated.</p><p>This is why Microsoft explicitly warned that &#8220;password reset is not an effective solution&#8221; for these attacks. Organizations need to revoke active sessions and hunt for inbox rules the attacker created to stay hidden.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zQ1V!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zQ1V!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zQ1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:375025,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189726197?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zQ1V!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zQ1V!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb2a33fe-8e0c-4207-9e9f-97280fa14277_1376x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2><strong>How Does This Work?</strong></h2><p>Think of it like a relay race, except the baton is your login.</p><p>You click a link. It looks like your normal Microsoft login page. Same colors, same logo. But you&#8217;re actually on an attacker-controlled server that&#8217;s sitting in the middle.</p><p>When you type your password, the attacker&#8217;s server passes it to the real Microsoft. When Microsoft asks for your MFA code, the attacker relays that request to you. You enter the code. The attacker passes it along. Microsoft says &#8220;welcome&#8221; and issues a session token.</p><p><strong>That token goes to you. And to the attacker.</strong></p><p><strong>Now they&#8217;re logged in as you. No alerts. No warnings. Your session, their control.</strong></p><p>Once inside, attackers typically:</p><ul><li><p>Create inbox rules that auto-delete security alerts</p></li><li><p>Mark incoming emails as read so you don&#8217;t notice new messages</p></li><li><p>Send phishing emails to your contacts using your identity</p></li><li><p>Monitor for financial transactions to intercept</p></li><li><p>Delete evidence of their activity</p></li></ul><p>The whole process takes minutes. Recovery takes weeks.</p><div><hr></div><h2><strong>What Can You Do?</strong></h2><p><strong>For Organizations:</strong></p><p>Stop trusting passwords alone. Even with MFA. Implement phishing-resistant authentication like hardware security keys (FIDO2/WebAuthn). These can&#8217;t be relayed because they verify you&#8217;re on the legitimate site.</p><p><strong>Require dual approval for financial transactions.</strong> Wire transfer requests should always be verified through a separate channel. Not email. Not the same Teams chat. Pick up the phone and call a known number.</p><p>Monitor for suspicious inbox rules. Attackers create rules to hide their tracks. If you see rules auto-deleting emails with words like &#8220;security,&#8221; &#8220;alert,&#8221; &#8220;hack,&#8221; or &#8220;phish,&#8221; you have a problem.</p><p><strong>Use conditional access policies.</strong>  If your users shouldn&#8217;t be logging in from Nigeria, Eastern Europe or Asia, lock this places out.</p><p><strong>Disable legacy authentication protocols.  </strong>This one is huge.  The big AiTM attackers will use these protocols to rapidly conduct their attacks (see 14 minute window section above).  By blocking them it short circuits their attack capabilities.</p><p><strong>Set aggressive session timeouts.</strong> The longer a session stays active, the longer an attacker can use a stolen token. Microsoft&#8217;s default timeouts can stretch for days. That&#8217;s too long.</p><p>Hunt for impossible travel. If someone logs in from New York at 9am and Tokyo at 9:15am, that&#8217;s not jet lag. That&#8217;s a compromised session.</p><p><strong>For Everyone:</strong></p><p><strong>Check URLs before entering credentials.</strong> AiTM attacks rely on lookalike domains. &#8220;microsoft-login.com&#8221; is not &#8220;login.microsoft.com.&#8221;</p><p><strong>If a login page comes from an email link, stop. Go directly to the site by typing the address yourself.</strong> Bookmark your important logins.</p><p>Use hardware security keys if your employer offers them. They&#8217;re the only MFA method that can&#8217;t be phished in real time.</p><p><strong>Report suspicious emails even if you clicked.</strong> Speed matters. The faster security knows, the faster they can revoke sessions.</p><div><hr></div><h2><strong>The Bottom Line</strong></h2><p>MFA was supposed to be the lock that kept attackers out. AiTM attacks turned that lock into a revolving door.</p><p>Your password gets you in. So does the attacker. Your MFA code verifies you. And the attacker. The session token proves you&#8217;re legitimate. The attacker has one too.</p><p>Next time you click a login link from an email, pause. Is this the real site? Or are you about to hand someone your digital keycard?</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-session-hijacking?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-session-hijacking?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-session-hijacking?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><em>Research Sources: Intruvent BRACE reporting, Microsoft Security Blog (January 2026), FBI IC3 2024 Report, eSentire 2026 Threat Report, ReliaQuest BEC Detection Research, Palo Alto Networks</em></p><p><em>Last Updated: March 3, 2026</em></p>]]></content:encoded></item><item><title><![CDATA[Intruvent EDGE: Inside INC Ransomware's Ruthless Playbook]]></title><description><![CDATA[How a cybercriminal startup became one of healthcare's most persistent predators]]></description><link>https://edge.intruvent.com/p/intruvent-edge-inside-inc-ransomwares</link><guid isPermaLink="false">https://edge.intruvent.com/p/intruvent-edge-inside-inc-ransomwares</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 26 Feb 2026 17:51:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1ERw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In March 2024, Julie White, chief executive of NHS Dumfries and Galloway in Scotland, called it an &#8220;utterly abhorrent criminal act.&#8221;</p><p>She wasn&#8217;t being dramatic.</p><p>Cybercriminals had quietly copied 3 terabytes of patient data from her organization&#8217;s servers. <strong>Genetic reports. Letters between doctors. Psychological evaluations. Records affecting up to 150,000 people. And they were threatening to publish everything unless the NHS paid up.</strong></p><p><strong>The group called themselves INC Ransom. Within eight months, they would hit Alder Hey Children&#8217;s Hospital in Liverpool, one of Europe&#8217;s largest pediatric facilities.</strong> Same playbook. Same ruthlessness.  Sophisticated attacks by skilled attackers.</p><blockquote><p><strong>[Editor's Note]</strong> If you work in cybersecurity at a children's hospital, or know someone who does, please reach out (contact@intruvent.com). Intruvent provides free threat intelligence to children's hospitals worldwide. You all have a hard enough job already. Thank you for all that you do!</p></blockquote><p>Welcome to INC Ransomware, an operation that has positioned itself as one of the most prolific groups in the ransomware ecosystem.  Defenders and Threat Hunters, we have FREE Intel Guides available, please see the links below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1ERw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1ERw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 424w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 848w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 1272w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1ERw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png" width="1338" height="821" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a9197424-53d4-405e-8716-68400fc8933d_1338x821.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:821,&quot;width&quot;:1338,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:607476,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189265215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe315a4cb-a4b8-4fb6-b6f0-b225fa70ccc5_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1ERw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 424w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 848w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 1272w, https://substackcdn.com/image/fetch/$s_!1ERw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa9197424-53d4-405e-8716-68400fc8933d_1338x821.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p>&#128196; <strong><a href="https://intruvent.com/threat-intelligence/threat-actors/inc-ransomware/">Download the Threat Actor Profile &#8594;</a></strong></p><p>&#128269; <strong><a href="https://intruvent.com/threat-intelligence/threat-hunting-guides/inc-ransomware-hunting-guide/">Download the Threat Hunting Guide &#8594;</a></strong></p></blockquote><div><hr></div><h2>The Origin Story</h2><p>INC appeared in July 2023, seemingly from nowhere. Unlike most ransomware groups that splinter from existing operations, INC showed up as an original creation. Secureworks tracks them as GOLD IONIC. MITRE cataloged them as G1032. By September 2023, just two months in, they had posted 12 victims to their dark web leak site.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><p><strong>What set INC apart was their messaging. They framed intrusions as unauthorized security audits.</strong> &#8220;We&#8217;re making your environment more secure&#8221; was the implicit pitch. It&#8217;s manipulation dressed up as customer service.</p><p>The numbers tell the story: 162 victims in 2024. Over 300 in 2025. In July 2025, INC became the most deployed ransomware by victim count. They average 11 organizations per month.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EWUC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EWUC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 424w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 848w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 1272w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EWUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png" width="1536" height="827" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:827,&quot;width&quot;:1536,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:941137,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189265215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F35a15cd6-4cc7-42a2-82f1-8bd65002f36f_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EWUC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 424w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 848w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 1272w, https://substackcdn.com/image/fetch/$s_!EWUC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F315771bd-994c-48c7-8be1-bbc0f8c56e43_1536x827.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>How INC Gets In</h2><p>The trail often starts with internet-facing systems.</p><p>CVE-2023-3519 (Remote Code Execution) in Citrix NetScaler stands out as a consistent favorite. This vulnerability allows attackers to execute code without authentication. CISA issued an advisory in July 2023. INC was exploiting it almost immediately.</p><p>INC affiliates have also exploited Fortinet products, including FortiClient EMS (CVE-2023-48788) and FortiOS (FG-IR-24-535). In one documented case, attackers created new SSL VPN configurations on a compromised FortiGate to maintain persistent access.</p><p>But the scariest entry point might be the most mundane. Microsoft tracks an affiliate called Vanilla Tempest (formerly Vice Society) that adopted INC ransomware for healthcare targeting. <strong>Their approach? SEO poisoning. They manipulate search results so that when employees search for common business documents, they land on malicious sites</strong> that deploy Gootloader malware. <strong>No vulnerability required. Just someone searching for a contract template.</strong></p><p>Once inside, real people poke around the network. They run reconnaissance with netscan.exe and AdFind. They harvest credentials using tools like lsassy.py and Impacket&#8217;s secretsdump. In one case documented by HvS-Consulting, INC operators performed Kerberoasting and cracked the Domain Admin password within 48 hours of initial access.</p><div><hr></div><h2>Double Extortion</h2><p><strong>By the time encryption begins, attackers have typically spent days inside the network.</strong> They&#8217;ve exfiltrated terabytes using MEGASync, Rclone, or Restic. They&#8217;ve mapped backup systems.</p><p><strong>Then files get the &#8220;.INC&#8221; extension. Ransom notes appear everywhere.</strong> Sometimes the ransomware sends notes to network printers, ensuring everyone in the building knows what&#8217;s happening.</p><p>INC operates two leak sites: a private one for negotiations, and a public one for dumping data from organizations that refuse to pay. The demands are calibrated. <strong>Attackers review financial records and cyber insurance policies to set their price.  You pay one sum to unlock your files, you pay another sum to ensure they don&#8217;t leak your files.</strong></p><p>Some attacks skip encryption entirely. ReliaQuest documented cases where INC affiliates exfiltrated data but never deployed the encryptor. Pure extortion, no encryption required.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wp2H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wp2H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 424w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 848w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 1272w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wp2H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png" width="1444" height="715" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:715,&quot;width&quot;:1444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:536056,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189265215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afa59f1-3aba-4993-9b8b-6f8b8def2a78_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wp2H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 424w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 848w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 1272w, https://substackcdn.com/image/fetch/$s_!wp2H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0fc7c0ae-6466-43a4-a978-a2f0dbfb2c33_1444x715.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>Healthcare in the Crosshairs</h2><p><strong>Healthcare accounted for 29% of INC&#8217;s attacks in early 2025.</strong> Sophos identified INC as one of the three most prominent ransomware groups targeting healthcare organizations last year.</p><p>Beyond the NHS attacks, the victim list reads like a healthcare industry directory. Compass Health Network, a mental health provider, lost 500,000 sensitive records including therapy notes and psychiatric diagnoses. OnePoint Patient Care, a hospice pharmacy provider, had a breach affecting 1.74 million individuals.</p><p>The UK&#8217;s NHS has a policy of not paying ransoms. INC knows this. They keep targeting British healthcare anyway.</p><p>The implication: <strong>INC isn&#8217;t targeting healthcare solely because these organizations might pay. Medical records have long shelf lives on criminal marketplaces. They enable identity theft and fraud for years after the initial breach.</strong></p><div><hr></div><h2>The Code That Wouldn&#8217;t Die</h2><p>In March 2024, someone using the handle &#8220;salfetka&#8221; appeared on Russian-language forums selling INC&#8217;s complete source code for $300,000, limited to three buyers.</p><p><strong>By July 2024, a new operation called Lynx emerged. Binary analysis showed 48% overall code similarity with INC. The Linux variants showed 91% overlap.</strong></p><p>But here&#8217;s the twist: INC didn&#8217;t go away. Both operations continue claiming victims in parallel. Some incident responders have seen Lynx ransomware deployed in attacks later claimed on INC&#8217;s leak site. For defenders, detection rules for one catch both.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!it35!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!it35!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 424w, https://substackcdn.com/image/fetch/$s_!it35!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 848w, https://substackcdn.com/image/fetch/$s_!it35!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 1272w, https://substackcdn.com/image/fetch/$s_!it35!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!it35!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png" width="1279" height="753" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36c53424-4217-4319-926b-6da4dd578b06_1279x753.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:753,&quot;width&quot;:1279,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:828459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/189265215?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d3e91ed-2531-4cea-b9d0-04edc8bdd326_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!it35!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 424w, https://substackcdn.com/image/fetch/$s_!it35!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 848w, https://substackcdn.com/image/fetch/$s_!it35!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 1272w, https://substackcdn.com/image/fetch/$s_!it35!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36c53424-4217-4319-926b-6da4dd578b06_1279x753.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And then came the opsec failure. In January 2026, security researchers discovered that INC operators had reused Restic backup infrastructure across multiple intrusions without properly securing it. The mistake allowed data recovery for 12 US organizations.</p><p>Even cybercriminals make configuration errors.</p><div><hr></div><h2>Beyond Healthcare</h2><p>While healthcare dominates the victim list, INC&#8217;s appetite extends further.</p><p>Stark Aerospace, a US missile systems and aerial weapons manufacturer, had 4TB of data claimed stolen. The attackers allegedly accessed source code, design plans, employee passports, and UAV firmware.</p><p>OnSolve, the company behind the CodeRED emergency alert system used by municipalities nationwide, was hit in November 2025. The attackers demanded $950,000 and exfiltrated customer data including plaintext passwords. The breach forced decommissioning of legacy infrastructure that affected emergency communication capabilities across the country.</p><p>Critical infrastructure. Defense contractors. Emergency services. INC doesn&#8217;t have any off-limit sectors.</p><div><hr></div><h2>Detection Quick Reference</h2><p>See our full guides for more info, but here is a cheat sheet for you on quick detection items.</p><p><em>Pre-encryption warning signs:</em></p><ul><li><p>AnyDesk, ScreenConnect, or TightVNC on servers where they don&#8217;t belong</p></li><li><p>netscan.exe or AdFind.exe execution</p></li><li><p>MEGASync, Rclone, or Restic on non-backup systems</p></li><li><p>Shadow copy deletion commands</p></li></ul><p><em>Ransomware execution indicators:</em></p><ul><li><p>Files with <code>.INC</code> extension</p></li><li><p><code>INC-README.TXT</code> or <code>INC-README.HTML</code> in directories</p></li><li><p><code>INC_Update</code> scheduled task</p></li></ul><p><em>Patch priority:</em></p><ul><li><p>Citrix NetScaler: CVE-2023-3519, CVE-2023-4966</p></li><li><p>Fortinet: CVE-2023-48788, FG-IR-24-535</p></li></ul><p>Full guides are available for FREE on the Intruvent site:</p><blockquote><p>&#128196; <strong><a href="https://intruvent.com/threat-intelligence/threat-actors/inc-ransomware/">Download the Threat Actor Profile &#8594;</a></strong></p><p>&#128269; <strong><a href="https://intruvent.com/threat-intelligence/threat-hunting-guides/inc-ransomware-hunting-guide/">Download the Threat Hunting Guide &#8594;</a></strong></p></blockquote><div><hr></div><div><hr></div><h2>What This Means For You</h2><p>INC represents exactly the threat mid-market enterprises and healthcare organizations need to plan for: sophisticated enough to bypass basic defenses, patient enough to conduct proper reconnaissance, ruthless enough to publish your data regardless of harm.</p><p><strong>[IMPORTANT] Patch perimeter devices.</strong> Citrix NetScaler, FortiClient EMS, and FortiOS have all featured in INC intrusions. Verify your patch status today.</p><p><strong>Monitor living-off-the-land techniques.</strong> INC operators use PsExec, WMI, and legitimate remote tools. Behavioral detection catches what signatures miss.</p><p><strong>Watch for unauthorized RMM tools.</strong> AnyDesk, ScreenConnect, and TightVNC on servers where they don&#8217;t belong is a red flag.</p><p><strong>Assume breach in your backup strategy.</strong> INC operators study networks before encryption. Air-gapped or immutable backups provide the recovery option they work hardest to eliminate.</p><div><hr></div><h2>The Uncomfortable Truth</h2><p>INC has operated continuously for over two and a half years. They sold their source code and kept going. They spawned Lynx, adding hundreds more victims. They made an opsec mistake that cost them leverage over a dozen organizations, and they&#8217;re still running.</p><p>The 150,000 people in Scotland whose medical records ended up on the dark web didn&#8217;t choose to become part of this story. Neither did the patients at Alder Hey or the communities relying on CodeRED for emergency alerts.</p><p>Understanding how groups like INC operate won&#8217;t prevent every attack. But it helps organizations focus limited security resources where they matter most.</p><p>That&#8217;s the work. One intrusion at a time.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-inside-inc-ransomwares?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/intruvent-edge-inside-inc-ransomwares?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/intruvent-edge-inside-inc-ransomwares?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><em>Thanks for reading Intruvent Edge!</em></p><div><hr></div><p><strong>Research Sources:</strong> Secureworks CTU, Palo Alto Unit 42, Trend Micro, MOXFIVE, Microsoft Threat Intelligence, Check Point Research, Sophos X-Ops, HvS-Consulting, ReliaQuest, Huntress, CISA</p><p><em>Last Updated: February 2026</em></p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Social Media's Open Door - TikTok]]></title><description><![CDATA[From Federal Bans to Faceprint Collection: A Parent's Guide to TikTok's Security Risks and How to Secure It.]]></description><link>https://edge.intruvent.com/p/prevent-this-social-medias-open-door-d7e</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-social-medias-open-door-d7e</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 24 Feb 2026 17:49:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EQl3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!EQl3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!EQl3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!EQl3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2616418,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188972760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!EQl3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!EQl3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71ba45e2-0f28-447d-8094-552ba06e8df0_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What is TikTok?</h1><p>TikTok is a short-form video platform owned by ByteDance, a Chinese technology company. With over 170 million users in the United States alone, it&#8217;s become the digital hangout spot for an entire generation. Users create and share videos ranging from 15 seconds to 10 minutes, covering everything from dance challenges to educational content.</p><p>But beneath the entertaining surface lies a complex web of security concerns that have caught the attention of lawmakers, security researchers, and intelligence agencies worldwide.  But like any technology, there are pros and cons to using it.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h1>The Good</h1><p>Like any application, there are both positive and negative uses for TikTok, and pros and cons to using it.  My outspoken colleague Gregg Yurchak uses TikTok as well as YouTube Shorts to reach his audience of almost 700 people for his <a href="https://www.google.com/url?sa=t&amp;source=web&amp;rct=j&amp;opi=89978449&amp;url=https://www.youtube.com/hashtag/cybersecsec">&#8220;Cybersecurity in 60 seconds&#8221; channel</a> (@cybersecsec).  Folks like Gregg use TikTok as a means to reach an audience that may not be accessible on another platform.</p><p>Also, recent legislation and Executive Orders forced ByteDance to sell the majority of TikTok in the US.  This sale and the laws surrounding it may mean that TikTok is more secure than it has been in the past.  Lets dive in.</p><div><hr></div><h1>The Growing Concerns</h1><p>TikTok&#8217;s security issues are documented by security researchers, investigated by government agencies, and rooted in the legal framework under which ByteDance operates. A<a href="https://internet2-0.com/tiktok/"> 2022 analysis by Internet 2.0</a>, an Australian cybersecurity firm, found <strong>TikTok&#8217;s data collection exceeded typical social media platforms, harvesting device identifiers, location data, and biometric data </strong><em><strong>including faceprints and voiceprints</strong></em>. <a href="https://www.buzzfeednews.com/article/emilybakerwhite/tiktok-tapes-us-user-data-china-bytedance-access">BuzzFeed News reported</a> that ByteDance employees in China accessed U.S. user data despite TikTok&#8217;s assurances otherwise, while security researchers discovered TikTok was <a href="https://latesthackingnews.com/2020/06/30/53-different-apps-including-tiktok-spy-on-iphone-ipad-clipboard-data/">accessing clipboard data </a>that could expose passwords and credit card numbers. China&#8217;s National Intelligence Law requires all Chinese companies to &#8220;support, assist, and cooperate with state intelligence work.&#8221;  This is a legal mandate that concerns U.S. lawmakers.</p><p>The biometric data collection is particularly alarming. In June 2021, immediately after paying <a href="https://www.nbcchicago.com/news/local/judge-approves-92-million-tiktok-settlement-with-illinois-claimants-receiving-biggest-share/2921881/">$92 million to settle an Illinois lawsuit</a> for collecting biometric data without consent, TikTok quietly updated its U.S. Privacy Policy to explicitly permit collecting &#8220;faceprints and voiceprints.&#8221; The catch: TikTok only seeks permission &#8220;where required by law.&#8221; Only five states have biometric privacy laws, meaning in 45 states, TikTok can collect this data without asking. As Carnegie Mellon privacy expert Alessandro Acquisti <a href="https://time.com/6071773/tiktok-faceprints-voiceprints-privacy/">told TIME Magazine,</a> <strong>biometric data represents permanent identifiers; unlike passwords, you can&#8217;t change your faceprint if it&#8217;s compromised.</strong> The potential uses range &#8220;from benign, such as secure access to the app, to chilling, such as mass re-identification and surveillance.&#8221;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tMed!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tMed!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tMed!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tMed!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tMed!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tMed!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:373768,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188972760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tMed!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tMed!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tMed!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tMed!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0aa422d-1952-44e9-b5b3-386557796c58_1408x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>Legal Action</h1><p>Because of concerns like those outlined above, the US Government decided to step in and help work out a solution.  What followed was years of legal battles, failed negotiations, and regulatory uncertainty spanning two administrations. </p><p><strong>Congress finally took decisive action in April 2024, passing the Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA)</strong>, which gave ByteDance nine months to sell or face a nationwide ban. After the Supreme Court unanimously upheld the law in January 2025 and the app briefly went dark for U.S. users, President Trump (now in his second term) stepped in with multiple deadline extensions while brokering a deal. <strong>The resolution came in January 2026 when TikTok's U.S. operations were transferred to a new joint venture controlled by American investors including Oracle, Silver Lake, and Abu Dhabi's MGX, with ByteDance reduced to a minority stake below the 20% threshold required by law.</strong> </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a4bW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a4bW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 424w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 848w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a4bW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png" width="1022" height="1204" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1204,&quot;width&quot;:1022,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1881127,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188972760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb5dab84-1be3-4dac-acf2-78bd59250b32_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a4bW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 424w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 848w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 1272w, https://substackcdn.com/image/fetch/$s_!a4bW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb4124926-b8aa-40ea-8924-d7da91617d11_1022x1204.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>What the TikTok Deal Actually Means</h1><p>So what actually changed? <strong>As of January 2026, American users' data now lives on Oracle's servers here in the U.S., not overseas.</strong> The algorithm, that secret sauce that decides which videos you see, is being retrained using only American user data, and <strong>Oracle is responsible for making sure TikTok follows all the national security rules.</strong> Content moderation (deciding what stays up and what gets taken down) is now handled by people in the U.S., and a new board with mostly American members is calling the shots. </p><p><strong>But here's the catch: ByteDance didn't fully walk away. They still run the advertising, e-commerce, and marketing side of things for American users, which means your TikTok experience probably feels exactly the same as before.</strong> The algorithm retraining is also still a work in progress. It's not like someone flipped a switch and everything became "American" overnight.</p><h1>How to Make TikTok (More) Secure</h1><p>If your teenager uses TikTok, the settings you configure today can make the difference between a relatively safe experience and one that exposes them to strangers, predators, and data harvesting on a massive scale. The good news is that TikTok has built in some solid parental controls. The bad news is that most parents have no idea they exist. </p><p>The platform now defaults accounts for users under 18 to private, and users under 16 have direct messaging disabled entirely. But defaults only go so far. The following steps will help you lock down your teen's account, limit data collection, and set up Family Pairing so you can monitor their activity from your own device. Fair warning: TikTok updates its interface frequently, so if you cannot find an exact setting, use the search bar within Settings and privacy to locate it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XAFJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XAFJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XAFJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png" width="1080" height="1350" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1350,&quot;width&quot;:1080,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1362799,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188972760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XAFJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 424w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 848w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 1272w, https://substackcdn.com/image/fetch/$s_!XAFJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a73f043-f96c-439e-8c66-c29390318b33_1080x1350.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>The Bottom Line</h1><p>TikTok&#8217;s security concerns aren&#8217;t theoretical. They&#8217;re documented by security researchers, investigated by government agencies, and serious enough that federal law required divestment. The January 2026 sale creates a complex ownership structure that complies with the law, and <em>should</em> make the application more secure.</p><p>If TikTok remains part of your family&#8217;s digital life, treat it like any other calculated risk. Implement every security control available, have ongoing conversations about digital safety, and stay informed as the legal, technical, and geopolitical landscape continues to evolve.</p><p>The best defense against any platform&#8217;s security risks is an informed user who understands both the capabilities of the technology and the motivations of those who control it.</p><p>Join me for our next Intruvent Edge Newsletter on Thursday where we dive into the disappearance and possible re-emergence of a Threat Actor Group.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-d7e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door-d7e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-social-medias-open-door-d7e?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><strong>Disclaimer:</strong>  TikTok is a registered trademark of ByteDance Ltd. This article is published for educational and informational purposes as part of cybersecurity awareness. All cited claims are attributed to their original sources. The views expressed are those of the author based on publicly available information and do not constitute legal advice.</p><div><hr></div><h4>Research Sources:</h4><p>Internet 2.0 cybersecurity analysis (September 2022)</p><p>BuzzFeed News investigative reporting (June 2022)</p><p>National Intelligence Law of the People&#8217;s Republic of China (2017)</p><p>Microsoft Security Response Center advisories</p><p>Congressional legislation (H.R. 7521, H.R. 2617, Public Law 118-50)</p><p>Department of Defense memoranda</p><p>Executive Orders 13942 (2020) and enforcement pause orders (2025)</p><p>TikTok official privacy policy and settings documentation</p><p>Axios, CNN Business, NPR, CNBC reporting on TikTok sale (December 2025-January 2026)</p><p>Congressional statements from Rep. Moolenaar and Sen. Markey (December 2025-January 2026)</p><p>Last Updated:February 24 2026</p>]]></content:encoded></item><item><title><![CDATA[Prevent This: Social Media's Open Door. Part 1: The Ghost in Your Kid's Phone]]></title><description><![CDATA[Your kid's favorite "disappearing" photo app has 130 million teen users, a documented predator problem, and parental controls you've probably never heard of. Here's how to set it up more securely.]]></description><link>https://edge.intruvent.com/p/prevent-this-social-medias-open-door</link><guid isPermaLink="false">https://edge.intruvent.com/p/prevent-this-social-medias-open-door</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Tue, 17 Feb 2026 18:00:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GA0D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>About this Series</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GA0D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GA0D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GA0D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2452639,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188279882?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GA0D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!GA0D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fce9e5dfa-fded-4010-8063-c30925a94018_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Your kid's phone is a gateway to more than just their friends. It connects to your home network, your family's location data, and in some cases, your workplace systems. When a predator targets your teenager on Snapchat or a scammer tricks them into clicking a malicious link on Instagram, the threat doesn't stop at their device. It can pivot to your home security cameras, your work laptop on the same Wi-Fi, or your personal or financial information.</p><p><strong>This &#8220;Social Media&#8221; series breaks down the most popular social platforms your kids are using, the specific risks each one presents, and the settings you need to lock down to protect them from both predators and cyber threat actors.  </strong>This week we&#8217;ll start with Snapchat.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>What Happened?</h2><p><strong>If you&#8217;re not on Snapchat yourself, here&#8217;s the short version: it&#8217;s a messaging app built around photos and short videos that disappear after viewing.</strong> It also offers Stories (24-hour visible content), augmented reality filters, real-time location sharing, and an AI chatbot. It launched in 2011, it&#8217;s owned by Snap Inc., and its official minimum age is 13.</p><p><strong>Kids love it because it feels more private and lower-pressure than Instagram or TikTok.</strong> No public follower count, no permanent feed to curate, and disappearing messages make everything feel casual and off-the-record. For teenagers, it&#8217;s replaced texting as the place they make plans, joke around, and stay connected. According to Pew Research Center, roughly 130 million teens use it daily worldwide.</p><p>In January 2026, Snapchat settled a lawsuit with New Mexico accusing the platform of fueling addiction and mental health harm among minors, TechCrunch reported. Two days later, the company rolled out new parental controls. The timing wasn&#8217;t subtle.</p><p>The lawsuit was just the latest. In 2024, the New Mexico Department of Justice sent undercover agents posing as teenagers onto Snapchat. According to the state&#8217;s complaint, within minutes of creating a fake account for a 14-year-old, agents were flooded with predatory messages, including usernames that explicitly referenced child abuse. Internal Snap documents cited in the lawsuit revealed the company was receiving roughly 10,000 sextortion reports per month. Employees had been raising alarms for years, according to NPR&#8217;s reporting on the case.</p><p>Florida, Utah, Kansas, and other states have filed their own lawsuits. Over 600 cases naming Snap Inc. have been filed since 2022, according to court records. The consistent allegation across these suits: disappearing messages, minimal age verification, and algorithmic friend suggestions create an environment where predators thrive.</p><p>Despite this, Snapchat remains one of the most popular apps among American teenagers, according to Pew Research Center surveys. For many kids, leaving the platform means leaving their entire social circle.</p><div><hr></div><h2>Why Should You Care?</h2><p>You probably can&#8217;t keep your teenager off Snapchat entirely, and <strong>a growing body of research suggests that banning social media outright tends to backfire.</strong> Studies published in <em>Nature</em> and <em>JAMA Network Open</em> point to a consistent finding: digital literacy and supervised engagement outperform prohibition. <strong>Bans push kids to unmonitored spaces, erode trust, and skip the part where teenagers learn to navigate digital life responsibly.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tk-8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tk-8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tk-8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:412908,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188279882?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tk-8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tk-8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa40ae5c7-15a0-4d5b-bb75-324fba98b47d_1408x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That said, &#8220;supervised&#8221; is doing a lot of heavy lifting in that sentence. Snapchat has specific, well-documented risks that parents need to understand.</p><p><strong>Sextortion is surging.</strong> Nearly one in four Gen Z teens and young adults surveyed across six countries reported being victims of sextortion. Among minors who shared intimate images, 76% said they were lied to by the abuser, and 66% lost control of the material. The National Center for Missing and Exploited Children (NCMEC) is one of the premiere agencies in the US dedicated to helping protect children from predators.  NCMEC received over 456,000 reports of online enticement in 2024. The FBI, DHS, and multiple state attorneys general have all flagged apps like Snapchat as a primary vector for this type of crime.</p><p><strong>&#8220;Disappearing&#8221; messages create a false sense of safety.</strong> Teens think Snaps vanish, so there&#8217;s no risk. But screenshots happen. Screen recordings happen. Predators know this illusion makes kids more likely to share content they&#8217;d never put in a regular text.</p><p><strong>Snap Map broadcasts your kid&#8217;s location.</strong> It can pinpoint a user down to a specific building. <em>If your teen&#8217;s settings aren&#8217;t locked down, anyone on their friends list (including strangers accepted through Quick Add) can see exactly where they are.</em></p><p><strong>Quick Add connects strangers to kids.</strong> This feature suggests new friends based on mutual connections and phone contacts. Safety researchers have identified it as one of the main ways adult predators access minors on the platform.</p><div><hr></div><h2>How Does This Work?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pR4Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pR4Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pR4Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg" width="1024" height="1067" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1067,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:143123,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188279882?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pR4Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 424w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 848w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!pR4Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d26f5a4-003d-4f69-8ba1-21630a2d3e08_1024x1067.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A quick guide to the features that matter most:</p><p><strong>Snaps</strong> are photos or videos sent to friends. They disappear after viewing, usually within seconds. Recipients can replay once or screenshot (the sender gets notified of a screenshot, but that doesn&#8217;t prevent the capture).</p><p><strong>Stories</strong> are Snap collections visible to friends (or the public, depending on settings) for 24 hours.</p><p><strong>Spotlight</strong> is Snapchat&#8217;s short-form video feed, similar to TikTok. An algorithm recommends content based on engagement. This is where teens encounter content from strangers.</p><p><strong>Snap Map</strong> shows friends&#8217; real-time locations whenever they open the app, unless Ghost Mode is enabled.</p><p><strong>Quick Add</strong> suggests new connections based on mutual friends, contacts, and communities. Safety advocates have pushed Snap to disable this for minors.</p><p><strong>My AI</strong> is a built-in chatbot. Parents can disable it through Family Center.</p><p><strong>Streaks</strong> track consecutive days two users have exchanged Snaps. Sounds harmless, but they create compulsive patterns. Teens describe feeling obligated to send content daily just to keep the counter alive, often without thinking about what they&#8217;re sending.</p><div><hr></div><h2>What Can You Do?</h2><h3>Set Up Family Center</h3><p>Both you and your teen need Snapchat accounts, and your teen must accept your invitation to connect.</p><p><strong>Family Center lets you:</strong></p><ul><li><p>See your teen&#8217;s full friends list and new friends from the past 7 days</p></li><li><p>See who they&#8217;ve chatted with (usernames only, not message content)</p></li><li><p>See how they might know new friends (mutual connections, shared contacts)</p></li><li><p>View daily screen time broken down by feature</p></li><li><p>Restrict sensitive content on Spotlight and Stories</p></li><li><p>Disable the My AI chatbot</p></li><li><p>Request your teen&#8217;s location and share yours</p></li><li><p>Report accounts to Snapchat&#8217;s Trust and Safety team</p></li></ul><p><strong>Family Center does NOT let you:</strong></p><ul><li><p>Read messages or view Snaps</p></li><li><p>Set screen time limits or lock the app</p></li><li><p>Prevent your teen from removing your access (Snapchat won&#8217;t notify you if they do)</p></li></ul><p><strong>Setup:</strong> Open Snapchat &gt; Profile icon &gt; Settings (gear) &gt; Family Center &gt; &#8220;Get Started.&#8221; Your teen accepts from their end.</p><h3>Lock Down These Settings</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mpUl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mpUl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 424w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 848w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 1272w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mpUl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png" width="1350" height="1688" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1688,&quot;width&quot;:1350,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1604950,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/188279882?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mpUl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 424w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 848w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 1272w, https://substackcdn.com/image/fetch/$s_!mpUl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F646d9a22-e99b-4d35-8403-39dfd9ebd67c_1350x1688.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Walk through your teen&#8217;s phone together and adjust these:</p><p><strong>***1. Ghost Mode: ON.</strong> The most important setting. Snap Map &gt; gear icon &gt; Ghost Mode &gt; &#8220;Until turned off.&#8221; Hides your teen&#8217;s real-time location from everyone.</p><p><strong>***2. Contacts: Friends Only.</strong> Should be the default for teen accounts, but verify. Settings &gt; Privacy Controls &gt; Contact Me &gt; &#8220;Friends and Contacts.&#8221;</p><p><strong>3. Quick Add: OFF.</strong> Settings &gt; Privacy Controls &gt; See Me in Quick Add &gt; toggle off. Stops Snapchat from suggesting your teen&#8217;s profile to strangers.</p><p><strong>4. Story Privacy: Friends Only.</strong> Settings &gt; Privacy Controls &gt; View My Story &gt; &#8220;My Friends&#8221; or &#8220;Custom.&#8221;</p><p><strong>5. My AI: OFF.</strong> Disable through Family Center if you have concerns about unsupervised chatbot conversations.</p><p><strong>6. Content Restrictions: ON.</strong> Through Family Center, restrict sensitive content on Spotlight and Stories.</p><h3>Supplement with Phone-Level Controls</h3><p>Snapchat doesn&#8217;t offer screen time management, so use your phone&#8217;s tools:</p><p><strong>Apple Screen Time</strong> (iPhone) lets you set daily app limits, enforce downtime, and restrict downloads. <strong>Google Family Link</strong> (Android) offers similar controls. These operate at the system level and can&#8217;t be bypassed from within Snapchat.</p><h3>Have the Conversation</h3><p><strong>On disappearing messages: &#8220;Nothing online truly disappears. Screenshots and screen recordings can capture anything. Before you share something, ask yourself if you&#8217;d be okay with it showing up on a billboard.&#8221;</strong></p><p><strong>On strangers:</strong> <strong>&#8220;If someone you don&#8217;t know in real life adds you, don&#8217;t accept.</strong> If someone starts asking personal questions or pressuring you for photos, tell me immediately.&#8221;</p><p><strong>On sextortion:</strong> &#8220;Criminals trick teenagers into sharing images and then blackmail them. It happens to smart kids every day. If it ever happens to you or a friend, come to me. You won&#8217;t be in trouble. The person doing it is the criminal.&#8221; Direct them to NCMEC&#8217;s CyberTipline (1-800-843-5678) or report.cybertip.org.</p><p><strong>On streaks:</strong> &#8220;The app is designed to make you feel like you have to be on it constantly. That&#8217;s product design, not friendship. It&#8217;s okay to put it down.&#8221;</p><p><strong>On Snap Map:</strong> &#8220;Would you walk around holding a sign with your exact address? Ghost Mode stays on.&#8221;</p><div><hr></div><h2>The Bottom Line</h2><p>Social Media apps serve a purpose: They are the new norm for teen communications.  Snapchat isn&#8217;t going away. Chance are that your teen&#8217;s friends are on it.  And the research shows that education and supervised engagement protect kids better than blanket bans. </p><p>But Snapchat&#8217;s default settings are more permissive than most parents realize, and the platform&#8217;s parental tools still have real gaps. Set up Family Center. Enable Ghost Mode. Kill Quick Add. Then have the conversation. The 15 minutes it takes to walk through these settings together could save your family from a crisis.</p><div><hr></div><p><em>Thanks for reading Intruvent Edge! This post is public so feel free to share it.</em></p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/p/prevent-this-social-medias-open-door?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://edge.intruvent.com/p/prevent-this-social-medias-open-door?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div><hr></div><p><strong>Research Sources:</strong> Snap Inc. Newsroom &amp; Family Center Documentation, Snapchat Support (help.snapchat.com), New Mexico DOJ v. Snap Inc. (2024), NPR (Dara Kerr, 2024), TechCrunch (January 2026), Snap Inc./Western Sydney University Sextortion Research (2025), NCMEC CyberTipline Reports (2024), Thorn Sextortion Study (2025), DHS Know2Protect Campaign (2025), After Babel Platform Analysis (2025), Malwarebytes Online Safety Research (2025), Pew Research Center (2025), Nature (2025), JAMA Network Open (2024)</p><p><strong>Last Updated:</strong> February 17, 2026</p>]]></content:encoded></item><item><title><![CDATA[INTRUVENT EDGE: January 2026 Threat Trends]]></title><description><![CDATA[The Monthly Intelligence Digest for Security Leaders]]></description><link>https://edge.intruvent.com/p/intruvent-edge-january-2026-threat</link><guid isPermaLink="false">https://edge.intruvent.com/p/intruvent-edge-january-2026-threat</guid><dc:creator><![CDATA[Sig Murphy]]></dc:creator><pubDate>Thu, 12 Feb 2026 17:29:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6h58!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Theme of the Month: The Perimeter Has Dissolved</h2><p>Cross-sector analysis for our January BRACE reports was telling.   January&#8217;s threat landscape delivered a verdict: the traditional security perimeter is gone. Attackers are targeting things outside the traditional parameter: operating iyour cloud APIs, your SaaS integrations,  your OT networks. Often without ever touching your endpoints. You&#8217;ll need to move fast to regain the advantage.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Numbers That Matter</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6h58!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6h58!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6h58!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6h58!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6h58!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6h58!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:134080,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/187750432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6h58!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6h58!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6h58!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6h58!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e27a26f-9a28-42f1-b965-f7aef407c3ad_1024x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Active Threat Groups: 70</strong> (up 12% month-over-month, highest count since tracking began)</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Cross-Sector Actors: 17</strong> (Qilin leading, cartel coordination accelerating)</p><p><strong>Critical CVEs: 85 tracked</strong> (58 rated CRITICAL or HIGH, exploitation pace exceeds patching)</p><p><strong>Emerging Signals: 107 indicators</strong> (AI-enabled attacks surging across sectors)</p><div><hr></div><h2>1. Codefinger: Ransomware Without the Malware</h2><p><strong>The first ransomware that doesn&#8217;t need your network. </strong></p><p>In January, Halcyon&#8217;s researchers disclosed &#8220;Codefinger,&#8221; a ransomware operation weaponizing AWS S3&#8217;s Server-Side Encryption with Customer-Provided Keys (SSE-C) to lock organizations out of their own cloud storage. No malware. No lateral movement. No endpoint compromise. Just API calls.</p><p><strong>How it works:</strong></p><p>Attackers obtain leaked AWS credentials from GitHub commits, phishing, or infostealer logs. They enumerate S3 buckets and identify valuable data. Using the S3 API, they re-encrypt objects with attacker-controlled SSE-C keys. Original data becomes mathematically unrecoverable without the key.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!3icc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!3icc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3icc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3icc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3icc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!3icc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:106800,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/187750432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!3icc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!3icc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!3icc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!3icc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4934acf6-fbab-4ffa-9256-77a55650d43e_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Why your current defenses won&#8217;t help:</strong> EDR doesn&#8217;t see it because there&#8217;s no malware. Network monitoring misses it because the traffic is legitimate API calls to AWS. Backup systems can&#8217;t help if backups are stored in the same S3 buckets. The attack happens entirely within AWS&#8217;s legitimate service layer. CloudTrail logs show the activity, but only if you&#8217;re watching.</p><p><strong>Defensive priority:</strong> Audit IAM permissions for <code>s3:PutObject</code> with SSE-C capabilities. Enable S3 Object Lock for critical data. Deploy CloudTrail alerting for unusual SSE-C operations. Segregate backup storage with separate credentials.</p><p><em>Source: Halcyon Research, January 2026</em></p><div><hr></div><h2>2. Eight Minutes: When Attackers Move Faster Than Your SOC</h2><p><strong>From phishing email to full AWS environment compromise in under 10 minutes.</strong></p><p>A January incident reconstructed by cloud security researchers at Wiz revealed a new operational tempo: threat actors using AI-assisted tooling achieved complete cloud environment takeover in just 8 minutes.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-S7T!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-S7T!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-S7T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg" width="1376" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1376,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:221663,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/187750432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-S7T!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 424w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 848w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!-S7T!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6807517e-913f-40fc-9a1e-f958993b529c_1376x768.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>The attack chain:</strong></p><p><strong>0:00</strong>: Spear-phishing email with malicious OAuth consent link</p><p><strong>0:45</strong>: Victim grants OAuth app access to M365 mailbox</p><p><strong>2:30</strong>: Automated credential harvesting from mailbox attachments</p><p><strong>4:00</strong>: AWS console login using harvested service account credentials</p><p><strong>5:30</strong>: Lambda functions enumerated, secrets extracted</p><p><strong>8:00</strong>: New IAM admin user created, persistence established</p><p>Traditional incident response assumes hours or days. Eight minutes doesn&#8217;t give SOC teams time to triage an alert, let alone contain a breach.</p><p><strong>The takeaway:</strong> Speed is the new competitive advantage for attackers. Detection must be automated, and response playbooks need to trigger without human approval for high-confidence signals.</p><p><em>Source: Wiz Cloud Threat Intelligence, January 2026</em></p><div><hr></div><h2>3. Bybit&#8217;s $1.5 Billion Lesson: Lazarus Never Sleeps</h2><p><strong>The largest single crypto theft in history. Here&#8217;s how they did it.</strong></p><p>North Korea&#8217;s Lazarus Group executed a $1.5 billion heist against cryptocurrency exchange Bybit in January, eclipsing the $620M Ronin Bridge attack as the largest crypto theft ever recorded.</p><p><strong>Technical execution:</strong></p><p>Social engineering campaign targeting exchange developers. Supply chain compromise of a trading interface component. Hot wallet credentials exfiltrated via memory scraping. Funds dispersed across 50+ wallets within 90 minutes.</p><p><strong>The strategic angle:</strong> At $1.5B, this single operation likely funds a significant portion of North Korea&#8217;s weapons programs for 2026. Lazarus isn&#8217;t criminal in the traditional sense. It&#8217;s a revenue-generating arm of a sanctions-evading government. The financial services sector remains the highest-value target for state-sponsored actors with economic motivations.</p><p><strong>For financial institutions:</strong> Third-party code review isn&#8217;t optional. Hot wallet architecture must assume compromise. Behavioral analytics on transaction patterns are essential.</p><p><em>Source: Chainalysis, FBI IC3 Advisory, January 2026</em></p><div><hr></div><h2>4. Sandworm Returns: DynoWiper and Poland&#8217;s Grid</h2><p><strong>Russia&#8217;s elite cyber unit tests new destructive capabilities in NATO territory.</strong></p><p>January saw Sandworm (GRU Unit 74455) deploy &#8220;DynoWiper,&#8221; a new destructive malware variant, against Polish energy infrastructure. The attack was contained before causing outages, but the technical sophistication marks an evolution from their 2015-2016 Ukraine grid attacks.</p><p><strong>Key findings:</strong></p><p>DynoWiper specifically targets Schneider Electric SCADA systems. Uses legitimate OT protocols (Modbus, IEC 61850) to blend with normal traffic. Includes anti-forensics modules that corrupt PLC firmware after wiping. Pre-positioned for months before activation.</p><p><strong>The timing isn&#8217;t coincidental.</strong> Poland&#8217;s critical role in NATO logistics and Ukraine support makes it a high-priority target. This operation signals preparation for potential escalation.</p><p>This marks the first known Sandworm attack targeting a NATO member&#8217;s critical infrastructure. That detail matters.</p><p><strong>OT/ICS operators:</strong> Baseline legitimate OT traffic patterns now. Detection rules for anomalous Modbus commands should be deployed across all energy sector SCADA environments.</p><p><em>Source: Dragos Threat Intelligence, CERT Polska, January 2026</em></p><div><hr></div><h2>5. When Hacktivists Cause Physical Impact</h2><p><strong>CISA Alert AA25-343A: The line between digital and physical has dissolved.</strong></p><p>In January, CISA issued a rare alert documenting pro-Russia hacktivist groups achieving physical impact on US critical infrastructure. Water treatment facilities experienced pump failures. Manufacturing PLCs entered unsafe states.</p><p><strong>What changed:</strong></p><p>Hacktivist groups are now sharing ICS exploitation guides on Telegram. Operational technology defaults (default passwords, exposed HMIs) create attack surface. Groups previously limited to DDoS and defacement have upskilled to OT compromise.</p><p>The attacks weren&#8217;t sophisticated. They didn&#8217;t need to be. Internet-exposed HMIs with default credentials were the only requirement.</p><p>Critical infrastructure operators have known about these exposures for years. Regulators have issued guidance. Hacktivists have now become the enforcement mechanism.</p><p><strong>Action required:</strong> Internet-exposed ICS asset discovery should be a weekly automated scan. Default credential campaigns need executive sponsorship and deadlines.</p><p><em>Source: CISA Advisory AA25-343A, January 2026</em></p><div><hr></div><h2>6. OAuth: The Supply Chain You Forgot to Secure</h2><p><strong>Two SaaS supply chain compromises expose the trust problem in enterprise OAuth.</strong></p><p>January saw back-to-back OAuth-based supply chain attacks targeting enterprise SaaS platforms:</p><p><strong>Salesloft-Drift Compromise:</strong> Attacker compromised Drift&#8217;s OAuth integration with Salesloft. All customers with the integration active had mailbox access exposed. Estimated 4,200 organizations affected.</p><p><strong>Gainsight Customer Data Exfiltration:</strong> OAuth token theft from Gainsight&#8217;s customer success platform. Product usage data for 800+ enterprise customers exfiltrated. Competitive intelligence implications significant.</p><p><strong>The pattern:</strong> OAuth tokens are persistent, broadly scoped, and rarely audited. Once compromised, they provide silent access until explicitly revoked.</p><p><strong>OAuth security priorities:</strong></p><p>Inventory all OAuth grants across your SaaS portfolio. Implement just-in-time access for sensitive integrations. Monitor for OAuth grants from unusual locations or devices. Establish a periodic OAuth grant review process.</p><p><em>Source: Obsidian Security, January 2026</em></p><div><hr></div><h2>Quick Hit: Scattered Spider Joins DragonForce</h2><p><strong>The social engineering experts have a new home.</strong></p><p>Following the disruption of their infrastructure in late 2025, Scattered Spider operators have affiliated with the DragonForce ransomware cartel. This partnership combines Scattered Spider&#8217;s elite social engineering capabilities with DragonForce&#8217;s infrastructure and ransom negotiation experience.</p><p>Expect SIM swapping and help desk social engineering attacks to increase through Q1 2026, now backed by more robust ransomware deployment.</p><p><em>Source: Mandiant M-Trends, January 2026</em></p><div><hr></div><h2>Trend Watch: Encryption Is Optional</h2><p><strong>Quadruple extortion becomes the new baseline.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HjmE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HjmE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HjmE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:261489,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/187750432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HjmE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HjmE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6f62bf3d-5ab9-46ba-8c7d-0c48add95128_1024x1024.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>January data confirms a shift in ransomware economics: encryption is increasingly optional. The modern extortion playbook:</p><p><strong>Data theft</strong>: Exfiltrate before announcing presence</p><p><strong>Encryption</strong>: Sometimes deployed, sometimes skipped</p><p><strong>Public shaming</strong>: Victim names posted to leak sites</p><p><strong>Third-party notification</strong>: Customers, regulators, and partners contacted directly</p><p>Groups like BianLian have abandoned encryption entirely. Why invest in complex crypto when data theft alone generates payments?</p><p><strong>Defensive implication:</strong> Data Loss Prevention (DLP) and exfiltration detection are now as critical as backup integrity.</p><div><hr></div><h2>January 2026 By The Numbers</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0CuU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0CuU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0CuU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg" width="928" height="1152" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1152,&quot;width&quot;:928,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:254823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://edge.intruvent.com/i/187750432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0CuU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 424w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 848w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!0CuU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F14cb5c4f-5693-4413-9f2f-14ca6e3bef16_928x1152.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Qilin</strong> led all actors, active in 17 of 18 sectors analyzed</p><p><strong>T1078 (Valid Accounts)</strong> was the #1 technique, used by 65 actors across all sectors</p><p><strong>Russia</strong> accounted for 61% of attributed actor activity</p><p><strong>AI-enabled attacks</strong> flagged as emerging signal in 17 sectors</p><p><strong>Custom Sector - Amazon AWS Cloud Technologies</strong> sector had highest severity concentration (6 CRITICAL)</p><div><hr></div><h2>Defensive Playbook: February Priorities</h2><p>Given the wide spread of attack vectors this month, here are some defensive measures that you can take to protect your organization over the next 90+ days.</p><p><em>NOTE: Every environment is different, and Intruvent has not examined <strong>your</strong> environment.  These are general recommendations that you should undertake only after evaluating their usefulness and efficacy for your specific circumstances.</em></p><h3>Immediate (This Week)</h3><p>Audit S3 bucket SSE-C permissions and access patterns</p><p>Review OAuth grants for all SaaS integrations</p><p>Scan for internet-exposed ICS/OT assets</p><h3>Short-Term (30 Days)</h3><p>Deploy CloudTrail alerting for unusual S3 encryption operations</p><p>Implement automated response for OAuth-based compromise indicators</p><p>Baseline OT network traffic for anomaly detection</p><h3>Strategic (90 Days)</h3><p>Evaluate data exfiltration detection capabilities vs. encryption-focused controls</p><p>Develop 8-minute response playbook for cloud credential compromise</p><p>Third-party OAuth integration security review program</p><div><hr></div><h2>Sources</h2><ol><li><p>Intruvent BRACE Sector Reports - Cross-Sector Threat Intelligence, January 2026</p></li><li><p>Halcyon Research - Codefinger SSE-C Analysis, January 2026</p></li><li><p>Wiz Cloud Threat Intelligence - AI-Accelerated Breach Study, January 2026</p></li><li><p>Chainalysis - Bybit Incident Analysis, January 2026</p></li><li><p>FBI IC3 - North Korea Cryptocurrency Advisory, January 2026</p></li><li><p>Dragos Threat Intelligence - DynoWiper Technical Report, January 2026</p></li><li><p>CERT Polska - Energy Sector Incident Report, January 2026</p></li><li><p>CISA - Advisory AA25-343A, January 2026</p></li><li><p>Obsidian Security - OAuth Supply Chain Report, January 2026</p></li><li><p>Mandiant M-Trends - RaaS Evolution Update, January 2026</p></li></ol><div><hr></div><p><em>INTRUVENT EDGE is published monthly. For the complete cross-sector technical analysis, see the January 2026 Cross-Sector Trends Report.</em></p><p><em>Questions? Feedback? Reply to this email or reach out at contact@intruvent.com</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://edge.intruvent.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Intruvent Edge! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>