Skip to player
Skip to main content
Search
Connect
Watch fullscreen
Like
Bookmark
Share
More
Add to Playlist
Report
Payroll pirates are hijacking ads to steal your logins and paychecks
Rizzle
Follow
7 hours ago
Category
🤖
Tech
Transcript
Display full video transcript
00:00
Payroll pirates are hijacking ads to steal your logins and paychecks.
00:05
Cyber crooks dubbed the payroll pirates are ramping up their game,
00:09
hijacking search ads to pilfer your work logins and security codes,
00:13
as reported by 9to5mac.
00:17
These digital buccaneers are spoofing over 200 legit HR, payroll, credit union, and trading sites,
00:24
potentially harming half a million users worldwide.
00:28
Troy Hunt, a Microsoft regional director, who also runs the site Have I Been Pawned,
00:34
claims this to be the biggest breach in existence.
00:37
I hate hyperbolic news headlines about data breaches,
00:40
but for the 2 billion email addresses headlined to be hyperbolic,
00:46
it'd need to be exaggerated or overstated, and it isn't.
00:49
It's rounded up from the more precise number of 1,957,476,021 unique email addresses.
01:01
But other than that, it's exactly what it sounds like.
01:05
Search for your payroll portal on Google or Bing,
01:08
and a slick ad lures you to a phony login page.
01:10
Attackers capture your username, password, and multi-factor authentication codes,
01:17
nullifying the extra security.
01:19
After going quiet late last year,
01:21
the crew resurfaced mid-2024 with souped-up phishing kits.
01:26
Microsoft's security team tracks them as Storm2-657,
01:31
targeting universities and other organizations.
01:33
Checkpoint found the campaign now uses Telegram bots to steal one-time codes in real-time,
01:41
backed by a revamped system that hides data theft.
01:44
Activity appears in Kazakhstan and Vietnam using cloaked, age domains.
01:49
Logs show at least four admins, including one who boasted in a video from Odessa.
01:55
Pirates are adapting fast.
01:57
Pro tip, double-check URLs, avoid ad-driven links for logins,
02:02
and report suspicious sites.
02:05
Use Have I Been Pawned to check your email,
02:08
change your passwords, enable two-factor authentication,
02:11
review your Gmail security activity,
02:14
and update any reused passwords.
Be the first to comment
Add your comment
Recommended
12:12
|
Up next
Following Your Stolen Data Through The Dark Web
WIRED
6 weeks ago
2:19
Researchers say AI browsers are a cybersecurity mess.
Rizzle
3 weeks ago
2:02
The Psychology Behind Phishing Attacks and How to Outsmart Them
Rizzle
4 weeks ago
1:07
Protecting Yourself From Cybersecurity Attacks
Stringr
5 years ago
7:30
Busting Cybersecurity Myths | Delhi Police Cybersecurity Awareness Month | OneIndia News
Oneindia
2 years ago
2:34
Companies to report ransomware attacks under new proposal
ABC NEWS (Australia)
1 year ago
1:36
Cybersecurity: Hackers threaten critical infrastructure
DW (English)
3 years ago
2:17
Websites being used to test stolen credit card numbers
ABC NEWS (Australia)
2 years ago
1:54
Hackers Take Over PA Systems At Several Airports
Rizzle
4 weeks ago
0:42
Cybercriminals Infiltrate Trucking Systems To Steal High-Value Cargo
Benzinga
11 hours ago
2:35
Max B – “No More Tricks”
Rizzle
7 hours ago
2:29
YFN Lucci – “Already Legend” [“Thank You” Deluxe Edition]
Rizzle
7 hours ago
2:27
Summer Walker earns her third straight top 2 album with “Finally Over It”
Rizzle
7 hours ago
1:58
Ja Rule explains backstage scuffle at Brandy and Monica’s Barclays concert after three men sucker-punched him before his set; Denies Max B's involvement
Rizzle
7 hours ago
2:33
Who’s next in Apple’s CEO hot seat after Tim Cook?
Rizzle
7 hours ago
2:20
TikTok gives you the power to turn down the AI
Rizzle
7 hours ago
2:15
WhatsApp finally tests multi-account support on iPhone
Rizzle
7 hours ago
2:16
YouTube is testing in-app DMs
Rizzle
7 hours ago
1:30
Apple Vision Pro now supports PSVR2 controllers
Rizzle
7 hours ago
2:21
OpenAI reportedly shares 20% of its revenue with Microsoft
Rizzle
7 hours ago
1:53
Roomba is dying and your dusty old broom might be making a comeback
Rizzle
7 hours ago
2:21
OpenAI gives teachers their own ChatGPT
Rizzle
7 hours ago
1:51
Google’s Private AI Compute brings cloud power without the creepy snooping
Rizzle
7 hours ago
1:59
Amazon’s satellite project gets a makeover
Rizzle
7 hours ago
2:33
Apple owes $634 million to Masimo for blood-oxygen tech
Rizzle
7 hours ago
Be the first to comment