Tag

#credential stuffing

9 stories taggedcredential stuffing.

A smartphone screen showing compromised account login alerts and unauthorized phone plan changes, Canadian mobile carrier customer service portal open in backgr
Breaches

Telus Customers Hit by Account Breach Spanning More Than a Year

Canada's second-largest phone company says criminals used stolen login details to break into customer accounts, access personal data, and in some cases quietly change people's phone plans.

3 min read
An office worker at a desk during a phone call, a fake login page displayed on their monitor screen, with a hand reaching toward the keyboard about to enter cre
Threat Intelligence

The Fake IT Call and the Click That Opens the Door

Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

4 min read
A security operations center where analysts are tracking millions of spoofed login attempts on large dashboard displays, threat intelligence feeds scrolling acr
Identity & Access

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences

Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

5 min read
Illustration: a generic fast-food mobile ordering app open on a smartphone resting on a wooden table
Breaches

Chick-fil-A customer accounts hit in June credential-stuffing wave

The chicken chain says attackers used passwords stolen elsewhere to break into Chick-fil-A One accounts over three days in June 2026.

3 min read
Illustration: a laboratory glass vial containing a coiled DNA double helix model
Breaches

23andMe to pay $18 million after 43 states found 'flimsy' security let hackers steal 6.9 million profiles

A coalition of state attorneys general says the DNA testing firm lacked basic protections like multifactor authentication before the 2023 breach that exposed genetic data on nearly seven million customers.

4 min read
Illustration: a modern smartphone on a dark desk, screen showing a generic fingerprint unlock prompt glowing softly
Identity & Access

Passkeys Are Winning the Login Fight. Attackers Are Moving to the Verification Step.

Credential stuffing is fading as passkeys go mainstream. The next account takeover battle is happening at password resets, help desks, and identity checks.

4 min read
Illustration: a glowing laptop keyboard in a dark room, with faint green and amber light reflecting off the keys
Identity & Access

Third DraftKings Credential-Stuffing Conspirator Sentenced to 18 Months

Nathan Austad gets a year and a half in federal prison, plus $1.8 million in forfeiture and restitution, closing out the last of the DraftKings account-takeover prosecutions.

2 min read
Illustration: a rack-mounted enterprise firewall appliance glowing with dim amber status LEDs in a darkened server room
Threat Intelligence

FortiBleed: Russian-Speaking Broker Tied to 430K FortiGate Credential Harvest

Researchers attribute the long-running operation to a financially motivated IAB, with credential lists feeding brute-force runs against exposed FortiGate appliances since February.

3 min read
Illustration: a double helix DNA strand rendered in cool blue light inside a cracked glass display case, dark background
Policy & Regulation

California Sues 23andMe's Bankruptcy Successor Over 2023 Data Breach

AG Rob Bonta is going after Chrome Holding Co., the shell 23andMe rebranded into after its bankruptcy, arguing the company failed to adequately protect the genetic and personal data of millions of users.

2 min read
© 2026 Threat Vectr