When did you last hand your driver's license to a rental-car counter, a retail checkout, or a venue door? The scan doesn't disappear after that transaction. It may still exist, and as of last week it may have been for sale.
A criminal is currently selling a phishing kit for $10,000 that claims it can register its own passkey on a victim's account during login, one that survives a password reset. Nobody has tested whether the kit actually works. But a separate research team already proved a real Google account can be tricked into accepting exactly that kind of rogue passkey, using a completely different method.
Water pressure dropped and some plants flooded in Minnesota last week, when a coordinated attack cut operators off from the equipment that runs their own treatment systems. US investigators think Iran is probably behind it.
On May 26, the FBI issued a flash alert warning that the Silent Ransom Group, an extortion operation also tracked as Luna Moth, has begun sending operatives into US law firm offices posing as IT support technicians. They walk past reception, plug USB drives into workstations, and copy files. No malware. No ransomware encryption. No locked screens. The systems keep running while the data walks out the door. According to BleepingComputer, 38 firms have already had client data leaked, with demands ranging from $1 million to $8 million.
On April 1, the ShinyHunters extortion group social-engineered a Charter Communications employee into handing over their Microsoft Entra (formerly Azure Active Directory) credentials through a voice phishing call. From that single set of credentials, the attacker pivoted into Charter's Salesforce CRM (customer relationship management system) and extracted customer and employee records before Charter detected the intrusion.
On May 4, someone stole $150,000 from an AI-powered crypto wallet using Morse code. The attacker posted a reply on X asking Grok to translate a Morse code message. The decoded text contained hidden instructions to transfer funds. Grok translated it faithfully. Bankrbot, an AI agent connected to the wallet, treated the translation as a legitimate command and wired the money. No password was stolen. No system was hacked. The attacker just talked to the AI in a language it understood and the safety filters didn't.
State of the Threat readers have followed this story all year. February 21: we covered the shift from fake LinkedIn profiles to stolen real identities. March 8: nearly every Fortune 500 CISO admitting they had unknowingly hired at least one DPRK IT worker. March 22: Treasury sanctions on the facilitators. This week, the prosecutions arrive.
On March 19, Bloomberg reported that North Korea's foreign exchange earnings have reached their highest level since before the 2018 round of United Nations sanctions that were supposed to choke off the regime's revenue. The sanctions are still in place. Not working, but in place.
A Greek court just proved what the industry has known for years. Governments are buying commercial spyware and pointing it at the people making decisions they want to influence.