RSS Amplifier

Pithy Security | InfoSec Made Simple · Aug 22, 2025

How A Phone Call Hacked Google, Adidas & 1.1 Million Records. 📞💥🔓

0
Sign in to vote or save

MrComputerScience · Pithy Security | InfoSec Made Simple

Three major cybersecurity stories dominated headlines this week, each exposing a different vulnerability in our digital lives.

A simple phone call impacted 91 major companies, including Google and Adidas. Germany moved to ban the tools that protect your privacy, and a college kid built a $700,000 digital weapon.

Here's what happened and why it matters to you.

A brazen social engineering campaign has compromised dozens of organizations worldwide, including HR giant Workday, insurance titan Allianz Life, and luxury brands such as Dior and Chanel. The hackers' method is alarmingly simple. They call employees pretending to be IT or HR staff, then trick them into handing over account credentials for their cloud-based CRM systems. The damage is staggering, with Allianz Life alone losing data on 1.1 million customers.

Key Insights:

The attackers then slip malicious apps into compromised accounts to quietly drain cloud systems. Big names like Google, Adidas, Cisco, and Qantas fell for the same fundamental trick. The social engineers didn't even need to use sophisticated malware or zero-day exploits. Instead, they deploy old-fashioned deception that exploits the employee's willingness to help. Several tech researchers have attributed the attacks to a collaboration between the cybercrime groups Scattered Spider and ShinyHunters, which have used their combined expertise to execute this widespread campaign.

Why This Matters For You:

The message is clear. Your organization's most significant vulnerability isn't its firewall. Instead, it's the friendly person who answers the phone. As this wave of attacks continues targeting multiple industries, companies are scrambling to train employees that sometimes the most dangerous cybersecurity threat comes from a (seemingly) chummy voice on the other end of the line.

Read More on Bleeping Computer.

A 22-year-old from Eugene, Oregon, has been arrested for operating one of the world's most prolific cyberattack services. Ethan Foltz allegedly operated "Rapper Bot," a DDoS-for-hire platform that launched 370,000 attacks against 18,000 victims across more than 80 countries. His service allowed anyone to crash websites and networks for as little as $20, with no technical skills required.

Key Insights:

The FBI says Rapper Bot generated over $700,000 in revenue since 2021 by democratizing digital destruction. Victims included X (Twitter), schools, hospitals, government agencies, and small businesses that were unable to defend against the floods of malicious traffic. One attack could knock a company offline for hours or days, resulting in thousands of dollars in lost revenue and productivity.

Why This Matters For You:

The arrest of Ethan Foltz is a victory. But it's wise to understand how Rapper Bot grew into a digital weapon of this scale. It launched on a foundation of insecure, networked devices. This malware specifically targeted outdated home routers and smart cameras with default or weak passwords. So, while law enforcement hunts for the next digital mercenary, the power to disrupt their operations lies with you. Secure your home network! Update your devices, change their default passwords, and consider whether each device needs to be on your network in the first place.

Read More on The Register.

Germany's Federal Supreme Court has revived a long-running legal battle, partially overturning a prior ruling and reigniting the possibility of a nationwide ban on ad blockers. The case centers on whether ad blockers violate copyright by altering website code when they block ads. Publisher Axel Springer is fighting Adblock Plus maker Eyeo, claiming that blocking ads is essentially digital piracy.

Key Insights:

This case spans beyond annoying pop-ups. Ad blockers serve as frontline defenses against tracking scripts and malicious advertisements. If Germany bans these tools, it could become the first democratic country to do so, a precedent that could ripple across Europe and the world. The ruling would strip away a critical security layer that millions rely on to protect their data and avoid malware-infected ads.

Why This Matters For You:

Mozilla warns this decision could spread beyond Germany's borders, threatening user privacy and security everywhere. The precedent would give publishers powerful legal ammunition to force users into accepting invasive tracking and potentially dangerous ads. Your right to control what loads on your screen might soon depend on what lawyers decide in a Hamburg courtroom.

Read More on Mozilla.

In 1989, 20,000 floppy disks were mailed to AIDS researchers across 90 countries. The label said it was medical software. What it did was encrypt your computer and display a ransom note, instructing you to send $189 to a P.O. box in Panama. It was the first documented ransomware attack, and it came through the postal service.

The culprit? A Harvard-trained biologist named Dr. Joseph Popp. No hoodie. No basement. Just a warped belief that he was raising money for AIDS awareness. He hid the malware in the disk's code, timed it to activate after 90 boots, and demanded payment, making history before the word "ransomware" even existed.

Today's ransomware gangs use Tor, crypto, and triple extortion. But the core idea? Same as 1989. Trick the user. Encrypt the system. Demand the money. The technology evolves, but the human blind spots remain unchanged.

These are my go-to privacy + security tools. Some links are affiliate links. (They support this newsletter at no extra cost to you!)

  • Proton Mail - One of the more private and secure email services. Basic accounts are free.

  • Proton VPN – Keep your internet, browsing history, and connection secure with servers in over 120 countries.

  • Proton Pass - Protect passwords with an elite encrypted password manager. Supports 2FA codes, device sync, multiple vaults, notes, and more.

  • Proton Drive - Store your data safely. Get 5GB for free and enjoy peace of mind, knowing your files are safe.

Please read my two newsletters:

# 1 - Pithy Cyborg - AI news in a no-fluff format. Timely insights into how AI is changing the world around us. Plus, a fun and battle-tested AI prompt in each issue.

# 2 - Pithy Security - Useful cybersecurity news without fear-mongering. Simple security so you can spot scams and stay safe without needing to become an expert.

Follow for extra insights:

Bluesky | X (Twitter) | LinkedIn | YouTube

PS: Do you have questions? Reply to this email!

Thanks for reading. More cutting-edge cybersecurity insights coming soon.

You're receiving this because you subscribed at PithySecurity.Substack.com. You can unsubscribe at any time using the link below. This newsletter reflects my personal opinions, not professional or legal advice. I may earn commissions from recommended tools. Thanks for your support!

Read the original on pithysecurity.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.