Related Threat Clusters
-
New Cyber Extortion Groups Target Critical Infrastructure with Phishing Tactics
Two threat groups, Cordial Spider and Snarky Spider, affiliated with The Com, are targeting U.S. organizations across various critical infrastructure sectors for rapid data theft and extortion. Their operations,…
5 articles · Updated May 1, 2026 -
Icarus Group Exploits Klue OAuth Breach to Steal Salesforce Data
In June 2026, a significant security incident involving Klue, a market intelligence platform, allowed the Icarus threat actor group to exfiltrate Salesforce CRM data from multiple organizations, including Huntress. The…
80 articles · Updated June 18, 2026 -
DOUBLECUP Service Delivers Malware via Cached PNG Images
The DOUBLECUP loader-as-a-service, identified by SOCRadar, employs ClickFix attacks to conceal malware within PNG images cached by browsers. This service, operational since June 2026, targets Windows and macOS systems,…
4 articles · Updated August 4, 2026 -
Gainsight Apps Breach Exposes Data of Over 200 Salesforce Customers
A significant supply chain attack has compromised Salesforce-stored data from more than 200 companies through applications published by Gainsight. Salesforce confirmed unauthorized access to customer data and is…
30 articles · Updated November 23, 2025 -
ShinyHunters Target SSO Accounts in Voice Phishing Attacks
The ShinyHunters extortion gang has claimed responsibility for a series of voice phishing attacks targeting single sign-on (SSO) accounts at major platforms including Okta, Microsoft, and Google. In these attacks,…
191 articles · Updated January 25, 2026 -
ShinyHunters Claims Gainsight Breach via Salesloft Drift Access
ShinyHunters has taken responsibility for a breach of Gainsight, impacting hundreds of Salesforce customers. The group stated they accessed Gainsight through vulnerabilities exploited during the Salesloft Drift hack…
2 articles · Updated November 22, 2025 -
Data Breach Affects Over 200 Companies via Gainsight Integration with Salesforce
Hackers compromised Salesforce-stored data from more than 200 companies through a supply chain attack involving Gainsight applications. Google confirmed the breach, stating that unauthorized access to customer data was…
44 articles · Updated November 27, 2025 -
Phishing Campaign Targets HubSpot Users
An active phishing campaign has been detected targeting HubSpot customers. The Evalian SOC reported that users are being targeted through deceptive emails designed to steal sensitive information.
4 articles · Updated December 19, 2025 -
ShinyHunters Targets Canva and 99 Other Organizations in Credential Theft Campaign
ShinyHunters has launched a credential stealing campaign targeting around 100 organizations using Okta's single sign-on (SSO) service. The operation has been confirmed by both researchers and the criminal group, with…
2 articles · Updated January 26, 2026 -
ShinyHunters Phishing Campaign Targets Over 100 Organizations
A phishing campaign attributed to ShinyHunters has targeted over 100 organizations, utilizing vishing and advanced phishing kits to bypass multi-factor authentication on platforms like Okta and other SSO services. The…
2 articles · Updated January 28, 2026
Recent Intelligence Reports
- New DOUBLECUP ClickFix service hides malware in browser cache images — Bleepingcomputer · August 3, 2026
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — Bleepingcomputer · June 18, 2026
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — Bleepingcomputer · June 18, 2026
- Attackers Deploy AiTM Phishing Pages to Access SharePoint, HubSpot, and Google Workspace — Cybersecuritynews · May 2, 2026
- ShinyHunters swipes right on 10M records in alleged dating app data grab — Theregister · January 29, 2026
- ShinyHunters swipes right on 10M records in alleged dating app data grab — Theregister · January 29, 2026
- Over 100 Organizations Targeted in ShinyHunters Phishing Campaign — Feeds.Feedburner · January 27, 2026
- Canva among ~100 targets of ShinyHunters Okta identity-theft campaign — Theregister · January 26, 2026