Cybersecurity News

Filters
Tag
Reset

Filtered by tag: identity theft × Clear

Cybercriminals Are Selling Corporate Executives’ Social Security Numbers for Just 25 Cents

Matched: health

Rapid7 has tracked 476 compromised SSN records tied to 395 corporate executives on dark web marketplaces since early 2026, with records selling for as little as 25 cents. C-suite executives account for 44.6% of affected profiles. Three platforms — Xilo, Bankomat, and PeopleFinder — represent 81.5% of leaks, sourcing data from large breaches, infostealers, and phishing. Unlike passwords or cards, SSNs cannot be changed, making them permanently exploitable for fraud and impersonation schemes.

Private equity giant Apollo confirms data breach saw personal info stolen

Apollo Global Management confirmed a cyberattack between July 6–10, 2026, in which a threat actor used social engineering to access its cloud environment. Stolen data included names, dates of birth, contact information, addresses, and Social Security numbers. Financial data was not compromised. Apollo notified authorities, engaged forensic experts, and is offering affected individuals two years of free identity protection. No group has claimed responsibility and the data has not appeared on the dark web.

This new malware can use Google passkeys even after a victim resets their password

Researchers have discovered a malware toolkit called Atlantis AIO that can bypass multi-factor authentication and maintain access to Gmail, Microsoft, Apple, and LinkedIn accounts even after victims reset their passwords. The malware exploits session cookies and OAuth tokens, meaning credential changes don't revoke access. It automates credential-stuffing attacks across over 140 platforms.