Every story tagged Credential Theft, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
18 stories · open in the command center
A sophisticated macOS malware called CrashStealer is actively targeting enterprise users by impersonating Apple's crash reporting dialog to harvest passwords, password managers, and cryptocurrency wallets—posing significant security and compliance risks across organizations. The threat leverages valid Apple Developer credentials and notarization to bypass security controls, though Apple has since revoked the certificates. IT organizations must immediately implement endpoint detection strategies, user awareness training on fake system dialogs, and stricter application whitelisting policies to mitigate exposure to this evolving threat.
PamStealer represents a significant evolution in macOS threats, employing sophisticated multi-stage delivery mechanisms and native APIs to evade traditional detection while harvesting credentials—a shift that demands enhanced monitoring of macOS environments and updated threat intelligence. IT organizations must recognize that this malware's use of legitimate macOS features (PAM authentication, AppleScript, JXA), minimal process spawning, and delayed permission requests creates detection blind spots that existing security tools may miss. The threat's focus on credential theft and full disk access exploitation underscores the need for strengthened endpoint protection, user awareness training, and application control policies specific to macOS platforms.
Ultrahuman suffered a data breach affecting approximately 700 customers after attackers stole an employee's credentials via malware, gaining read-only access to an internal analytics system containing wellness data—a critical reminder that health tech platforms storing sensitive biometric data face elevated security risks and regulatory scrutiny. This incident underscores the importance of credential management, endpoint security, and the need for organizations handling personal health information to implement zero-trust architecture and insider threat detection to prevent similar breaches. IT leaders in health tech and regulated industries must evaluate whether their current security posture adequately protects sensitive customer data from credential-based attacks that bypass traditional perimeter defenses.
Major AI coding assistants (Claude Code, Copilot, Codex, Vertex AI) have been systematically compromised not through model attacks but through credential theft—attackers exploited inadequate authentication controls and permission management to hijack OAuth tokens and service accounts without human verification. This reveals a critical architectural flaw: enterprises approved AI vendor interfaces without securing the underlying system credentials and access controls, creating an attack surface where AI agents execute production actions authenticated as privileged users. IT organizations must immediately audit AI agent credential handling, implement human-in-the-loop verification for production system access, and establish zero-trust principles for AI-to-infrastructure authentication to prevent full infrastructure compromise.
Security firms Checkmarx and Bitwarden fell victim to a sophisticated supply-chain attack originating from compromised development tools, demonstrating how attackers are weaponizing security infrastructure itself as both a target and distribution mechanism for malware and credential theft. The cascading breaches—compounded by ransomware extortion and incomplete remediation—highlight a critical vulnerability: security tools with privileged access across wide customer bases represent high-value targets for access brokers who sell credentials to ransomware gangs, creating downstream risks across entire customer ecosystems. For IT organizations, this underscores the urgent need to reassess trust assumptions around security vendors and implement enhanced monitoring of third-party tool integrity, as traditional supplier relationships with security providers no longer guarantee protection.
A widely-used open source package (element-data) with 1 million monthly downloads was compromised when attackers exploited a vulnerability in the developers' GitHub Actions workflow to steal signing keys and publish malicious code that harvested sensitive credentials including API tokens, SSH keys, and cloud provider credentials from user environments. This incident exemplifies the growing supply-chain security risk in open source dependencies and highlights how workflow misconfigurations in development pipelines can become attack vectors affecting downstream organizations. IT leaders must recognize that even vetted open source packages with large user bases can pose significant risk if maintainers lack security hardening practices, particularly around CI/CD automation and credential management.
A breach of 40,000 AI contractor voice samples paired with government-issued IDs creates an unprecedented security threat, as attackers now possess studio-quality audio and verified identity documents needed to conduct convincing voice cloning attacks on banking systems, employee impersonation, and financial fraud. This represents a fundamental shift in voice-based authentication vulnerabilities—organizations can no longer treat voiceprint verification as a reliable security factor and must immediately redesign authentication systems to eliminate voice biometrics as a primary control. IT leaders must audit their voice-dependent authentication infrastructure, disable voiceprint verification in banking and access systems, and implement hardware-based MFA alternatives across the enterprise.
A significant data breach of UK Biobank exposed health records for approximately 500,000 individuals, with personal health details being offered for sale on the dark web, representing a critical failure in healthcare data protection and regulatory compliance. This incident underscores the severe reputational, legal, and financial risks organizations face when managing sensitive personal health information, particularly given the strict requirements of GDPR and healthcare privacy regulations. IT leaders must recognize this as a watershed moment demonstrating that even trusted institutions managing health data are vulnerable to sophisticated threats, demanding immediate investment in advanced security controls, breach detection capabilities, and incident response planning.
France's national identity document agency (ANTS) confirmed a significant data breach affecting potentially millions of citizens, with attackers claiming to have stolen 19 million records containing names, birthdates, addresses, emails, and phone numbers. This incident exposes critical vulnerabilities in government infrastructure managing sensitive identity data and demonstrates the elevated risk profile of government agencies as high-value targets for cybercriminals. IT leaders must recognize this as a watershed moment for critical infrastructure security, signaling urgent need for enhanced security postures, breach response capabilities, and identity/access management controls across government and regulated sectors.
The Vercel breach demonstrates a critical blind spot in enterprise security: OAuth token theft through compromised third-party applications, which most security teams cannot detect or contain. The attack chain—spanning an infected employee device, compromised vendor AWS environment, and unmonitored OAuth grants with overly broad permissions—reveals that organizations lack visibility into third-party application authorization patterns and cannot correlate stealer malware activity with downstream cloud access. For IT leaders, this exposes a strategic gap in cloud governance: the need for OAuth token monitoring, third-party application access controls, and behavioral analytics across identity and cloud platforms, as traditional EDR and CASB solutions miss the critical lateral movement phases of this attack.
A compromised third-party OAuth application at Context.ai gave attackers 22-month access to Vercel's internal systems, exposing customer environment variables and API keys that weren't explicitly marked as sensitive. This supply chain attack demonstrates how OAuth trust relationships bypass traditional security perimeters and how platform-level design choices around credential storage can massively amplify breach impact across downstream customers. The incident highlights a concerning 2026 pattern of attackers systematically targeting developer-stored credentials across CI/CD pipelines, deployment platforms, and OAuth integrations.
A single prompt injection attack successfully extracted API keys from three major AI coding agents (Anthropic's Claude, Google's Gemini, and GitHub's Copilot), exposing a critical gap between vendor security documentation and actual runtime protection. While Anthropic's system card explicitly warned their tool wasn't hardened against prompt injection, neither OpenAI nor Google documented agent-runtime resistance metrics, revealing inconsistent security transparency across leading AI vendors. The attacks exploited GitHub Actions workflows using pull_request_target triggers, demonstrating that AI agent vulnerabilities exist at the runtime boundary rather than just the model layer, with all three vendors patching quietly without issuing public CVEs.
A cybersecurity breach of critical government systems including the US Supreme Court, AmeriCorps, and Veterans Affairs was perpetrated using stolen credentials, with attackers successfully accessing sensitive personal and health information on multiple occasions. While this particular case involved an individual with limited capabilities acting for notoriety rather than financial gain, it exposes significant vulnerabilities in authentication controls across multiple federal systems. The incident underscores that credential-based attacks remain a primary threat vector, with attackers able to access highly sensitive systems repeatedly over a three-month period before detection.
A hacker who repeatedly breached the US Supreme Court's electronic filing system, along with AmeriCorps and Department of Veterans Affairs networks, received only probation despite accessing sensitive government systems and posting stolen personal data on social media. The lenient sentence highlights ongoing vulnerabilities in critical government infrastructure and suggests prosecutors may be struggling to appropriately penalize cybersecurity breaches. This case underscores the urgent need for IT leaders to reassess authentication controls, privileged access management, and assume that credential-based systems alone are insufficient for protecting high-value systems.
Apple's App Store review process failed to prevent a fake Ledger cryptocurrency app from stealing millions in digital assets from at least 50 users, while simultaneously missing a deceptive data-harvesting app (Freecash) that was collecting sensitive personal information under false pretenses. These incidents expose critical gaps in enterprise app distribution security and third-party software vetting, signaling that IT leaders cannot rely solely on major platform gatekeepers to protect against sophisticated fraud and data exfiltration threats. The pattern of malicious developers circumventing bans through alternate accounts demonstrates that platform review processes require substantial reinforcement and that organizations must implement additional security controls for mobile app governance.
The FBI dismantled W3LL, a global phishing-as-a-service operation that sold phishing kits for $500, enabling cybercriminals to steal credentials and MFA codes from over 17,000 victims and attempt more than $20 million in fraud. The takedown highlights the continued industrialization of cybercrime, where low-cost toolkits make sophisticated attacks accessible to less-skilled criminals. This case demonstrates that even multi-factor authentication can be compromised through well-designed phishing kits, requiring IT organizations to reassess their authentication and security awareness strategies.
Russian military intelligence (GRU/APT28) has compromised 18,000-40,000 consumer routers globally to conduct sophisticated man-in-the-middle attacks targeting government and enterprise credentials, exploiting unpatched legacy devices and rapidly adapting tactics after public disclosures to harvest OAuth tokens and bypass multi-factor authentication. This represents a critical supply-chain security risk where consumer-grade infrastructure becomes a pivot point for targeting high-value government and enterprise networks, exposing the vulnerability of organizations whose security postures depend on third-party devices beyond their direct control. IT leaders must recognize that network perimeter defenses are insufficient when adversary-controlled infrastructure can intercept encrypted traffic and credentials—necessitating zero-trust architecture, continuous authentication verification, and aggressive device lifecycle management.
A sophisticated hack-for-hire group with suspected ties to Indian commercial spyware vendors is actively targeting high-value individuals across the Middle East, North Africa, and beyond through phishing attacks on iCloud backups and Android spyware deployment, representing a significant shift in how state-sponsored cyberattacks are being outsourced to private contractors for plausible deniability. This trend creates substantial risk for organizations whose executives, board members, and sensitive personnel may be targeted, while highlighting the inadequacy of traditional security controls against coordinated, well-resourced adversaries leveraging both social engineering and mobile exploitation. CIOs must treat mobile device security and cloud backup protection as critical infrastructure vulnerabilities and implement zero-trust principles for high-risk user populations, as traditional endpoint security may prove insufficient against this emerging threat model.