lunarcyber.com Mass Credential Exposures Across Major Corporations
Article Content
- •Over 747,485 credential exposure events identified across ten organizations.
- •Apple and OpenAI had significant discrepancies between employee and client credential exposures.
- •Infostealer malware was present in all analyzed organizations, highlighting ongoing risks.
Lunar Cyber reported 747,485 credential exposure events linked to ten large organizations, primarily in technology, finance, and retail. The analysis revealed that infostealer malware and breach databases were responsible for these exposures, with Apple showing over 46 million total events, but only 209,767 tied to employee accounts. OpenAI had 11.1 million total events, with just 531 linked to its domain. Employee-domain exposures were significant for companies like Owens Corning and Eversource, where over 93% and 53% of events were tied to their own domains, respectively. The report highlighted the importance of distinguishing between employee and client exposures, as the latter can still pose risks but differ in impact. Infostealer malware was identified across all organizations, with common families including LummaC2 and RedLine. The findings emphasize the ongoing risk of credential exposure even without a public breach.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Acreed and Amphenol in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…