Skip to content

What is OSINT? A complete guide to open-source intelligence

What is OSINT

Summary: OSINT uses public data to detect threats, spot breaches, and protect identities. It scans the web for risks. Learn how to prevent them.

Open-source intelligence (OSINT) uses publicly available data to detect data breaches, identify adversaries, and strengthen cybersecurity.

Cybercriminals sell data and plan attacks on the dark web, while phishers become more sophisticated. OSINT counters these trends by collecting publicly available information to identify threat actors.

Open source intel is a valuable tool for journalists, law enforcement, security researchers, and conventional businesses. OSINT can help avoid leaving data breadcrumbs on lesser-known forums, repositories, or outdated web pages. Let’s find out how.

What is OSINT

Open Source Intelligence (OSINT) collects and uses publicly available data to answer specific security questions. Cybersecurity analysts use OSINT tools to convert masses of information into usable intelligence. This intelligence helps them understand security risks, detect data leaks, and mitigate critical vulnerabilities.

However, open-source intelligence is not just a defensive asset. Cybercriminals use OSINT techniques to research targets and design phishing attacks.

What qualifies as an “open source” for OSINT purposes?

OSINT uses publicly available information. It does not cover private threat databases or encrypted forums. Instead, OSINT resources include:

  • Public records. These include DNS records that help diagnose malicious websites, TLS certificate logs, and historical DNS records where available. OSINT analysts may also consult SEC filings or other business records to assess whether companies are legitimate.
  • Media sources. Publicly sold newspapers, magazines, or news websites qualify as open-source intelligence.
  • Social media platforms. Includes Twitter profiles and followers, along with professional LinkedIn pages. GitHub can also be useful when verifying developers. Analysts may also have access to public Telegram or Discord servers used by threat actors.
  • Vulnerability databases. These databases keep track of current and emerging threats. For example, CVE registers like Exploit-db document known exploits.
  • Libraries. Public code libraries help analysts trawl digital records to detect malicious activity. For example, InstaLoader scrapes Instagram profiles for relevant information.
  • Image repositories. OSINT sources are not all textual. Analysts may consult image libraries to match the identities of individuals.

Many OSINT definitions also include the Dark Web. The Dark Web is inaccessible to ordinary web users without specialist Tor browsers. However, access is free, and there is no single owner, so the Dark Web qualifies as an OSINT source.

It also hosts marketplaces for stolen credentials and discussion forums to plan attacks, making it one of the most important OSINT tools.

Given the list above, you might wonder what does not qualify as OSINT data. OSINT data must originally be publicly available. This excludes a few classes of data.

For example, leaked or stolen data, proprietary databases like LexisNexis, law enforcement documents, and private messages on social media platforms do not count. Content behind paywalls is generally not deemed open source, nor are internal business records.

How does OSINT work?

OSINT works in several stages. We call these stages the intelligence cycle because the final stage feeds back to the start, creating a positive feedback loop.

How OSINT works

Stage 1: Preparation

OSINT starts with an objective. Researchers must define the question they seek to answer. They must then decide how to answer their question accurately. Before venturing into open-source databases, researchers need a road map to an actionable answer, including relevant sources and data points.

Stage 2: Data collection

Next, researchers gather data from reliable public intel sources. Intelligence teams gather as much information as possible, as it helps them answer the overall question. It’s important to strike a balance. Excessive data collection swamps analysts, but gathering insufficient data results in low-quality outputs.

OSINT specialists target their searches with scraping tools and code libraries. These tools trawl platforms, websites, and databases, returning answers based on predefined parameters. Analysts can automate most searches, saving time and delivering consistent results.

Note: Analysts generally do not use deception to obtain actionable intelligence (for instance, by creating fake profiles to deceive threat actors).

This method is known as passive intelligence gathering. It contrasts with active techniques that engage directly with suspected threat actors via social networking sites, spoofed emails, or other forms of deception.

Stage 3: Data processing

The next stage turns raw data into usable intelligence. Researchers trim data sets, removing irrelevant information and making data easier to read and interpret.

Meanwhile, data normalization converts many data types into a single format. This makes it possible to search across multiple data sets, making collected data far more powerful.

Stage 4: Analysis and interpretation

Analysts mine intelligence feeds for connections and anomalies. For example, they may detect a pattern of suspicious DNS changes relating to a regular vendor. This could indicate a website hijack or spoofing attack is in progress.

Analysts foreground the original question when writing a report for wider assessment. This report provides a provisional answer for security team leaders to approve or challenge.

Stage 5: Putting threat intelligence to work

After approving the report, security teams disseminate the information to relevant stakeholders. This information helps departments and partners proactively mitigate security risks. For example, analysts may provide a blocklist of unsafe IP addresses or recommend exploit patches.

Dissemination also links back to preparation. OSINT assessments identify critical security vulnerabilities, prompting fresh questions and restarting the intelligence cycle.

 

Why should businesses use OSINT in their security strategy?

If you have never used open-source intelligence techniques, the OSINT cycle may not seem essential. However, there are several compelling reasons to combine existing network security systems with OSINT tools.

1. OSINT covers every angle

Today’s advanced threat intelligence tools search multiple data sources to create in-depth security reports.

Security teams can search website DNS information to find fake websites, alongside social media accounts to find fraudulent contacts. They might also scrape databases of stolen credentials to discover whether individuals are using compromised passwords.

Fighting insurance fraud provides a great example. Fraud investigators now routinely derive OSINT from Facebook profiles and marketplace data. The two services should be distinct, but investigators can use digital evidence to connect sellers and personal profiles.

In this way, insurers can connect reports of stolen goods to marketplace sales of the same items, often solid evidence of fraud.

2. OSINT delivers value for money

Despite using advanced techniques, open-source intelligence can cut cybersecurity costs. OSINT draws insights from publicly available data that can be accessed free of charge. Proactively identifying threat actors also prevents attacks early on, cutting the risk (and cost) of data breaches.

For instance, a small app vendor wants to minimize its exposure to credential theft and supply chain attacks. It uses OSINT to track leaked credentials and detect whether the criminals are discussing the company online.

3. OSINT protects a critical vulnerability: user identities

According to Statista, in 2024, criminals stole over 1.35 billion user credentials in the United States. This includes employee and vendor credentials that threat actors use to breach networks and extract sensitive data.

Unfortunately, victims don’t know their credentials are compromised until attacks occur. That’s why user identities are currently a critical security concern.

OSINT tools solve this problem. Security teams can monitor dark web marketplaces for employee credentials or mentions of their company. This intelligence allows security teams to alert affected users and force password changes.

4. Companies can adopt a strategic approach to outpace emerging threats

Cybersecurity threats never sleep. In 2024, security experts registered over 6 billion malware attacks worldwide, while over 450,000 new malware agents or unwanted programs appear daily. OSINT provides a way to stay ahead of this surge and meet threats head-on.

For example, a financial institution worries about exploits targeting its client database. Security professionals use OSINT tools to scrape dark web forums, looking for mentions of software the company uses.

Simultaneously, OSINT experts look for mentions of the financial brand to detect suspicious discussions and assess attacks against similar companies to discover current threat vectors.

OSINT: Critical challenges for security teams

OSINT is powerful, but it is not a magic bullet. Companies regularly encounter problems when exploiting public records and other intelligence sources. Common bottlenecks include:

Being overwhelmed by too much data

How much data is enough to answer your critical cybersecurity question? OSINT teams can easily become overloaded with data, generating noise and making it harder to discern actionable intelligence.

Teams with too much data to handle become bogged down. Analysts take longer to parse data and identify threats, while costs rise accordingly.

Poorly designed metrics generate false positives. Data feeds may flag benign activity as a potential threat or – even worse – overlook genuine threats. Meanwhile, security teams struggling with false positives are prone to fatigue and poor performance.

Choosing reliable information sources

Not all OSINT sources are equal. A single inaccurate source can amplify false positives and contaminate security reports. Threat actors can mislead investigators with inaccurate information, while sources become outdated, making their information far less useful.

Security teams need processes to verify information and sources. Regularly assess the sources you use and jettison databases or methods that underperform.

Updating techniques to reflect current threats

In a world of ever-changing threats, keeping your OSINT framework current is critical. Without updated intelligence, companies may search for yesterday’s threat actors and allow active collectives to launch attacks.

Regulations evolve, potentially making OSINT techniques illegal (or enabling previously inaccessible methods). Tools evolve, making it vital to assess vendor performance and choose the best providers.

Updating skills is just as essential. Teams need regular training to use cutting-edge OSINT techniques effectively. For example, artificial intelligence and machine learning empower OSINT teams, potentially accelerating the intelligence cycle. However, only companies with the right skill set will realize the benefits.

Setting ethical boundaries

OSINT techniques often collide with privacy and data protection concerns. Security teams must identify threat actors without compromising user privacy. Codes of conduct are vital to prevent threat identification without robust evidence.

Similarly, teams need clear boundaries about acceptable and unacceptable information sources. Scraping semi-private databases may breach local data protection laws (especially in the European Union, where GDPR applies).

Reckless use of OSINT data collection can damage corporate reputations. So use data analysis tools wisely, and stay focused on specific security vulnerabilities.

Types of open-source intelligence tools

Open-source intelligence strategies rely on specialist tools to extract, organize, and analyze data. With that in mind, the following tools could be wise additions to your OSINT framework.

Tools to analyze social media platforms

Social media analytics tools scrape social media platforms for open-source intelligence. Companies can search LinkedIn, Twitter, Facebook, Instagram, and specialist forums to detect mentions of their brand. Analytics tools can monitor engagement spikes (such as unusual hashtags) that could indicate an incoming attack.

Artificial intelligence supplements basic social media analysis. AI enables sentiment analysis to separate normal discussions from malicious content or brand impersonation.

Web data analysis tools

These tools analyze domain registrations, DNS information, and IP addresses. By comparing website data with the signatures of legitimate sites, OSINT technicians can identify malicious websites and block phishing attacks via web filtering blocklists.

Deep and dark web monitoring

The dark web is a playground for threat actors, offering a place to source login details, forge connections, and launch attacks. OSINT tools monitor the dark web for mentions of a company, critical vendors, or leaked credentials.

Advanced dark web monitoring tools like NordStellar allow security teams to alert users when data leaks compromise their credentials. Dark web intelligence may uncover illicit data sales by insiders or provide pointers about upcoming attacks.

File metadata analysis

Security teams use OSINT to assess incoming documents or file downloads and determine whether they are safe. Investigators use file headers and logs to identify the file’s creator and look for embedded code or malicious macros.

OSINT techniques

So far, we’ve discussed tools and benefits for open source intelligence. However, it’s important to dig deeper and examine some core OSINT techniques. OSINT is surprisingly powerful and granular, and it goes far beyond basic keyword searches.

Common features of OSINT tools include:

EXIF extraction and file metadata

Exchangeable Image File Format (EXIF) extraction examines suspicious files. Analysts examine timestamps and geolocation data to identify when and where files were edited. Tools identify the software used to make edits and even device information.

Data cross-referencing

Cross-referencing turbo-charges OSINT by leveraging multiple data sets. Investigators can verify data by comparing different sources. Using many data points (including IP addresses, DNS, or forum posts) adds depth to threat analysis and attribution. Security teams get a full picture of attack patterns and likely techniques.

IP address and domain analysis

OSINT teams analyze IP addresses and website domain names to verify the legitimacy of sites and individuals. They may look at historical DNS changes to detect impersonation, or consult global databases of IP addresses connected to previous attacks.

Threat monitoring

Security teams actively monitor discussions on Dark Web forums, mainstream social media sites, and communication platforms like Discord and Telegram. Sometimes, this may require active reconnaissance (for example, by scanning server ports or assuming fake identities to access restricted sites).

Advanced searches allow OSINT specialists to home in on relevant discussions to detect mentions of future attacks or leaked hashes and credentials.

What are the main use cases of OSINT?

Cybersecurity technologies are only effective when used properly. Open-source intelligence is no exception. Fortunately, OSINT tools have many use cases for small, medium, and large enterprises. We’ve chosen a few use cases from many, and one will most likely apply to your operations.

Protecting your brand reputation online

Cybercriminals can spoof brands to sell counterfeit products, write phishing emails, or divert customers to malicious websites. Companies must know when spoofing occurs and act quickly to dismantle criminal activity.

OSINT helps track dark web forums and social media accounts for brand mentions. Scanning tools detect fake websites linked to a company’s brand and help identify the culprits.

OSINT tools also help detect exposed credentials and potential data leaks. This intelligence helps companies maintain customer trust by minimizing data theft and alerting customers when incidents occur.

Maintaining robust cybersecurity

In today’s digital economy, effective cybersecurity is proactive and based on threat intelligence. Using open-source intelligence allows companies to monitor current threats, detect attacks early on, and stay ahead of their adversaries.

Security teams can use OSINT data collection to learn about threat vectors. That way, companies can improve their security posture before attacks occur. Naturally, network security tools are critically important. OSINT supplements them, enabling targeted security measures.

Preventing corporate espionage and insider threats

Companies face an ever-present threat of intellectual property theft or corporate sabotage. OSINT techniques detect the warning signs of corporate espionage.

Social media searches detect posts from alienated employees (or worse, posts on the dark web). Web, image, and social media searches help companies screen employees and filter security risks. OSINT searches detect leaked credentials or confidential documents before adversaries can monetize them.

Journalism and fact-checking

The media industry uses OSINT to verify sources and investigate stories. For instance, news organizations must constantly check the accuracy of photographs and videos, which is becoming increasingly challenging as AI develops. Often, OSINT is the only solution, allowing companies to check the identity of sources, the location of images, and the metadata underlying them.

Strengthening compliance strategies

OSINT also helps companies meet their data security and privacy compliance goals. Scanning tools allow compliance teams to identify leaked data and take appropriate action. OSINT helps companies assess vendors and cut supply chain risks. Intelligence also makes it easier to investigate insider threats and protect internal systems.

How is OSINT used in cybersecurity?

OSINT has many use cases, but strengthening cybersecurity is the most important. Cybersecurity experts use OSINT to:

  • Detect ongoing and past data breaches
  • Diagnose the causes of data breaches and implement security controls
  • Analyze threat actors and counter relevant attack methods
  • Identify phishing attacks and inform stakeholders
  • Analyze downloads and documents to identify threats
  • Discover malicious websites and who is behind them

Put OSINT to work: strengthen your security with NordStellar

Proactive security strategies detect and mitigate threats before they reach the public eye. NordStellar equips your team with deep visibility into external threats, exploring parts of the internet where conventional security tools won’t go.

NordStellar uses OSINT to deliver comprehensive cyber threat visibility. Users can easily scan dark web sources for company mentions and leaked emails or credentials. Anti-cybersquatting tools help defeat spoofers. Attack Surface Management (ASM) also scans your network edge, detecting security vulnerabilities.

With NordStellar, you can act on real-time intelligence, protect sensitive data, and reduce your risk, without adding complexity to your stack.

To find out more, contact our team today to learn how NordStellar fits into your security strategy.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is the cyber kill chain? Framework, limitations, and alternative models

What is the cyber kill chain? Definition, framework, and limits
In a world full of cyber threats, it’s not really a question of if a cyberattack will happen but when. That’s why it’s so important to understand how attackers think and move. One of the most commonly used ways to break down and anticipate these attacks is the cyber kill chain — a step-by-step method that shows how hackers get in, take control, and try to reach their goals.

The cyber kill chain model helps security teams spot and stop threats early by mapping out the attacker’s journey. But like any method, it’s not perfect. In this article, we’ll walk through how the kill chain works, where it falls short, and how other alternatives — like the unified kill chain, MITRE ATT&CK, and cloud-based models — can fill the gaps.

What is the cyber kill chain?

The cyber kill chain is a cybersecurity kill chain model that outlines the stages of a cyberattack — from initial planning to the attacker achieving their final goal. It helps security teams understand how intrusions unfold and where they can step in to stop them. Originally developed by Lockheed Martin in 2011, the cyber kill chain definition adapts military concepts to digital threats, turning the chaos of a cyberattack into a clear sequence of steps.

The purpose of the model is simple — break the chain, stop the attack. By dissecting each of the cyber kill chain phases, organizations can identify weaknesses in their defenses, improve threat detection, and respond more effectively to incidents.

Such cyber kill chain methodology encourages defenders to think like attackers. It’s not just about patching vulnerabilities — it’s about anticipating moves, analyzing behavior patterns, and building a proactive defense. Whether it’s preventing malware delivery, detecting suspicious command-and-control activity, or containing lateral movement, the kill chain offers a structured way to reduce cyber exposure.

While the kill chain was groundbreaking at the time of its release, today, threats are more complex and dynamic. Attackers no longer follow a single path, and defenders need more flexible strategies. Still, the cyber kill chain remains a foundational tool in enterprise cybersecurity, especially when paired with modern models like MITRE ATT&CK and threat intelligence platforms like NordStellar. For teams looking for clear cyber kill chain examples or a breakdown of its seven steps, it’s still one of the best ways to understand and counter the modern cyberattack kill chain.

The 7-step cyber kill chain framework

At the heart of the cyber kill chain is a seven-step process that mirrors the typical lifecycle of a cyberattack. Each phase represents a specific tactic used by threat actors, and each offers a potential point of detection or disruption for defenders.

Understanding these steps not only helps in identifying and mitigating threats but also informs smarter investment in tools like vulnerability scanning, threat detection, and threat exposure management platforms.

Cyber kill chain

1. Reconnaissance

Every attack starts with cyber kill chain reconnaissance. In this phase, the attacker gathers information about their target — systems, software, employees, email addresses, exposed credentials, and network configurations. The goal is to find exploitable weaknesses with minimal exposure. The process may involve scouring dark web forums for leaked sensitive data, identifying a company’s attack surface and perimeter security gaps, or scanning public IPs for unpatched services.

2. Weaponization

Once a vulnerability is identified, the attacker creates their weapon. This weapon could be a phishing email with a malicious link, a rigged PDF, or a file embedded with infostealer malware. The payload is often customized based on the information gathered in the first phase. Weaponization marks the point where a harmless-looking delivery vehicle is fused with exploit code, ready to be deployed.

3. Delivery

Now, it’s about getting the weapon to the target. Email is the most common delivery method — especially in phishing attacks — but attackers also use infected websites, USB drives, compromised third-party software, or direct exploitation of open services. Because this step happens outside the victim’s systems, it’s one of the hardest to catch unless robust filtering and sandboxing tools are in place.

4. Exploitation

This is the stage where the attacker takes advantage of a vulnerability to execute malicious code on the target system. It could be a user unknowingly opening a malicious attachment, a browser plugin with a known flaw, or an unpatched service being remotely accessed. Once exploited, the attacker can begin interacting with the system, typically with the goal of escalating privileges or disabling security features to prepare for further steps.

5. Installation

Next, the attacker installs persistent malware or backdoors to ensure continued access. This process could involve the use of rootkits, trojans, or hidden payloads that blend into regular system activity. Without continuous threat detection, this step can go unnoticed for weeks or months, giving attackers the time to explore, extract, and exploit further.

6. Command and control (C2)

Now embedded in the system, the malware connects to a remote command server to receive instructions. This step is known as the command and control phase (C2). Through this channel, attackers can remotely move through systems, execute commands, extract data, or deploy additional tools. Many modern C2 frameworks are designed to blend into regular network traffic, making them harder to spot without behavioral analytics.

7. Actions on objectives

This final step is where the attacker fulfills their mission. It could be data breach and exfiltration, encryption for ransom, destruction of systems, or even long-term espionage. By this point, the attacker has successfully bypassed multiple layers of security and is operating inside the target network. Containing insider threats here is urgent and expensive.

8. Monetization

While not part of the original Lockheed Martin kill chain, many security teams add an eighth phase — monetization. This additional stage reflects the reality that most internal or external attacks today are financially motivated — whether it’s ransomware payouts, stolen data sales, or extortion schemes. Tracking how attackers attempt to convert stolen assets into revenue is important to modern cybersecurity kill chain thinking.

Cyber kill chain example

To see how the cyber kill chain model works in practice, let’s look at a well-documented example — the 2020 SolarWinds supply chain attack.

In this breach, attackers compromised the software supply chain of SolarWinds, a popular IT management platform, and inserted malicious code into a routine software update, ultimately impacting thousands of organizations, including U.S. government agencies.

Here’s how this attack maps to the cyber kill chain steps:

  1. Reconnaissance. The attackers spent months studying SolarWinds’ build process and identifying ways to insert malware without being detected. This phase likely included research on the company’s infrastructure, code repositories, and internal teams.
  2. Weaponization. The attackers created a backdoor called “SUNBURST,” which was designed to blend in with legitimate SolarWinds software code and avoid detection. It was digitally signed and prepared for distribution.
  3. Delivery. The trojanized software was delivered through a legitimate SolarWinds Orion platform update and pushed out to around 18,000 customers.
  4. Exploitation. Once the malicious update was installed, the SUNBURST malware began executing, allowing attackers to silently communicate with compromised systems.
  5. Installation. The malware established persistent access and began downloading further payloads to deepen the compromise.
  6. Command and control (C2). The attackers maintained communication with infected systems through a stealthy command-and-control infrastructure, avoiding known malicious IPs and using obfuscated traffic.
  7. Actions on objectives. In targeted environments (such as U.S. federal agencies), the attackers escalated privileges, moved laterally, and accessed sensitive data and emails.
  8. Monetization/impact. While the attackers’ motives were largely espionage-related rather than financial, the impact of the breach was severe, including reputational damage, regulatory scrutiny, and long-term trust issues.

Evolution of the cyber kill chain

Since its introduction by Lockheed Martin in 2011, the cyber kill chain has been a foundational model in cybersecurity. Originally built to stop cyberattacks, the cyberattack kill chain described a linear, seven-step process that attackers follow, from reconnaissance to actions on objectives.

But cyber threats have changed. Modern attacks are faster, more automated, and often nonlinear. Attackers may skip various stages, double back, or hit from multiple angles at once.

To keep up, cybersecurity professionals have reimagined the intrusion kill chain in several key ways:

  • Broader coverage. New frameworks include extra stages like monetization to reflect modern motives.
  • More flexibility. Real-world security breaches don’t follow a script, so the model has become less rigid.
  • Integrated response. The cyber kill chain in breach responses connects detection to remediation more directly.
  • Technology-driven. AI, machine learning, and automation are now part of the defense strategy.

These updates have shaped what’s now known as the unified cyber kill chain — a more complete approach to understanding the cyberattack lifecycle.

Applying the cyber kill chain in modern cybersecurity

The cyber kill chain framework offers a structured way to detect, prevent, and respond to attacks by breaking down the cyberattack lifecycle into distinct phases. Understanding each stage — from reconnaissance to actions on objectives — helps security teams disrupt cyberattacks before they escalate.

Early in the cyber kill chain process, during reconnaissance, defenders can use threat intelligence and attack surface monitoring to detect suspicious scanning or data harvesting. This approach gives teams time to harden exposed systems and reduce vulnerabilities.

In the cyber kill chain weaponization and delivery phases, tools like email filtering, sandboxing, and user training help block phishing attempts and malicious payloads. Once an attacker tries to exploit a weakness, patch management and behavioral analytics play a key role in identifying and stopping unusual activity.

As attackers attempt installation or establish command and control, endpoint detection, response tools, and traffic monitoring can shut down unauthorized access. Platforms like NordStellar enhance visibility here, helping teams act quickly and contain threats.

Finally, in the actions on objectives stage — when attackers try to move laterally, steal data, or deploy ransomware — segmentation, access controls, and real-time detection tools are critical. Strong incident response plans and backups further limit the impact if an attacker gets that far.

Applying defenses at each cyber kill chain phase builds a layered, proactive approach. Early perimeter security measures, like firewalls and intrusion prevention systems, help stop attacks during reconnaissance and delivery stages before attackers gain access.

Traditional cyber kill chain model limitations

The traditional cyber kill chain model faces criticism primarily for its linear, step-by-step approach. Real-world cyberattacks often don’t follow a neat sequence — attackers may skip various stages, repeat steps, or operate on multiple fronts simultaneously. Doing so makes the model less effective in capturing complex and adaptive threats.

Additionally, the cyber kill chain was created to address outside attacks on target network limits. But now, with cloud systems, insider threats, and supply chain risks, attacks happen in more places, which is why this framework fails to cover all types of threats.

The cyber kill chain also tends to emphasize early detection and prevention but pays less attention to post-compromise activities like lateral movement and data exfiltration, leaving gaps in breach response. Lastly, its rigid structure can promote a reactive security mindset rather than encouraging continuous monitoring and proactive defense needed against sophisticated attacks.

Cyber kill chain alternatives

As cyber threats have grown more complex, new frameworks have emerged to complement or improve upon the traditional cyber kill chain. These alternative models offer more flexibility, deeper insights, or better alignment with modern environments like cloud computing. Here are some of the key alternatives:

Unified kill chain

The unified kill chain expands on the original by integrating multiple attacker methodologies into a single framework. It addresses the limitations of the linear kill chain by including broader attack tactics and focusing on continuous attacker behavior across multiple stages. This model is more adaptable to complex, multi-vector attacks.

MITRE ATT&CK framework

MITRE ATT&CK is a comprehensive knowledge base of adversary tactics and techniques based on real-world observations. Unlike the kill chain’s sequential stages, ATT&CK maps attacker behaviors across different phases and provides detailed guidance for detection and mitigation. It’s widely used for threat hunting and developing proactive defenses.

Kill chain in cloud-native contexts

With the rise of cloud computing, traditional models struggle to account for the distributed nature of cloud environments. Cloud-native kill chain models adjust the framework to focus on specific cloud vulnerabilities, container exploitation, and API attacks, offering tailored guidance for protecting modern infrastructures.

OODA loop

Originally a military decision-making process, the OODA loop (observe, orient, decide, act) emphasizes speed and adaptability. In cybersecurity, it encourages rapid detection and response cycles to outpace attackers, promoting a mindset of continuous observation and quick reaction rather than fixed stages.

To give you a clear overview, the table below summarizes the key cyber kill chain alternatives discussed above, highlighting their approaches, strengths, and limitations:

Model

Approach

Strengths

Limitations

Traditional cyber kill chain

Linear, 7-step sequence

Simple, easy to understand

Too rigid, doesn’t capture modern attacks well

Unified kill chain

Integrated attacker tactics

More adaptable, covers complex multi-vector attacks

Still evolving, less widely adopted

MITRE ATT&CK framework

Detailed tactics and techniques

Comprehensive, practical for threat hunting

Complex, requires expertise

Cloud-native kill chain

Cloud-focused stages

Tailored to cloud infrastructure

Narrow scope outside the cloud

OODA loop

Rapid decision cycle

Promotes agility and fast response

Less structured, may lack detailed attack mapping

Summary

From its origins as a way to break down cyberattacks into manageable steps, the cyber kill chain remains an important framework in cybersecurity. It helps security teams understand attacker behavior and identify key moments to intervene and stop security breaches. By clearly mapping the external attack stages, it supports more effective detection, prevention, and response.

That said, the cyber kill chain has limitations, especially in handling multi-layered threats. Combining it with alternative models like MITRE ATT&CK or the unified kill chain — and applying flexible, adaptive defense strategies — is key to a stronger security posture.

For organizations looking to enhance their threat detection and response capabilities, using advanced solutions such as NordStellar’s threat exposure management platform can make a significant difference. NordStellar helps unify visibility across attack surfaces and provides actionable threat intelligence to stay ahead of attackers.

Cyberattacks follow a pattern. NordStellar helps you stop them at every step. Talk to our team today.

 

 

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Telegram scams: How can you secure your business?

How to stay safe from Telegram scams and protect your business

Known for its encrypted messaging, file sharing, and private channels, Telegram has become a go-to app for both personal and business communication. However, as the platform’s popularity increases, so do the online threats associated with it. From phishing schemes to malware as a service, cybercriminals take advantage of Telegram’s anonymity and huge user base.

Understanding how these Telegram app scams work becomes inevitable for protecting sensitive data — whether personal or business.

In this article, we’ll look into what scams on Telegram are, how cybercriminals use the platform in their attack strategies, and how to spot and prevent the most common types of scams.

What is a Telegram scam?

Telegram scam is a type of fraud that can occur on the Telegram platform. Scammers exploit the platform’s most popular features (think of encrypted messaging, private channels, and anonymous user profiles) to deceive individuals and businesses.

While Telegram’s focus on privacy and security is appealing to legitimate users, it unfortunately creates endless opportunities for Telegram fraudsters looking to exploit its users.

In fact, the platform’s anonymity is one of the key reasons the number of scams using Telegram is growing. These days, Telegram scammers can create fake Telegram accounts, impersonate businesses, or operate within private groups to avoid detection. They can then distribute malicious files or phishing links, adding yet another layer of risk.

Businesses are especially vulnerable as cybercriminals increasingly leverage Telegram for cyberattacks. From impersonating C-level executives to delivering malware disguised as legitimate business files, Telegram scams can lead to severe consequences, ranging from data breaches and financial losses to hard-to-recover reputational damage.

How do Telegram scams work?

Telegram scams usually begin with cybercriminals abusing the platform’s unique features to commit fraud and trick users. Scammers often employ social engineering tactics, such as impersonation scams, to trick victims into sharing personal information or clicking on malicious links.

For example, scammers may impersonate top-level executives, act as customer support and perform tech support scams, or promote fake investment opportunities. In some cases, they distribute malware via Telegram bots or channels, infecting devices and stealing both personal and corporate data.

By taking advantage of Telegram’s anonymity and wide-reaching capabilities, scammers can execute the full chain of attack to infect devices and steal data without being noticed.

How do cybercriminals use Telegram in the attack chain?

Cybercriminals use Telegram at various stages of the attack chain to maximize their reach and avoid detection. The main stages include:

Reconnaissance

The attack chain often begins with cybercriminals gathering information on their targets. They may join public groups, analyze conversations, or research publicly available data about individuals or businesses.

Attackers often look for clues that reveal organizational structures, employee roles, or ongoing projects. They may also monitor discussions related to specific industries to identify potential targets. By lurking in relevant Telegram channels or forums, scammers can quietly collect valuable insights without drawing attention.

Doing so helps them identify potential victims and gather insights, such as the names of key employees or business details, to make their attacks more convincing.

Social engineering

Once attackers have gathered sufficient information, they may engage in social engineering tactics. Impersonating trusted figures, like executives or IT support, cybercriminals use Telegram to deceive victims into sharing personal information or financial details.

To make their approach more convincing, attackers may create fake group chats that appear to involve multiple colleagues, increasing the sense of legitimacy. They may also send unsolicited direct messages marked as urgent or confidential, pressuring the victim to act quickly without verifying the request.

In some cases, cybercriminals use voice messages or video calls to further establish trust, making it even harder for victims to detect the scam and making it easier for fraudsters to steal personal data.

Malware distribution

At this stage, cybercriminals use Telegram bots or fake channels to distribute malicious files or phishing links. These links can lead to the installation of malware on the victim’s device, allowing scammers to steal data or gain unauthorized access to systems.

Attackers often disguise these malicious files as legitimate documents, software updates, or even fake job listings to increase the chances of victims downloading them.

Some bots are programmed to automatically send harmful attachments or links when triggered by specific keywords in chat groups. Once installed, the malware can harvest credentials, track user activity, or even grant remote control to the attacker, putting personal or business data at risk.

Exploitation and sale of stolen data

After compromising the victim, cybercriminals can use Telegram to sell stolen data, such as corporate credentials or sensitive files. The anonymity provided by Telegram allows criminals to carry out these transactions without fear of being easily traced.

Coordination and collaboration among Telegram scammers

Scammers on Telegram can also use the platform to coordinate and collaborate with other cybercriminals. Telegram groups and channels can be used to provide a semi-private space for sharing attack strategies, discussing vulnerabilities, or even offering cybercrime as a service.

Within these groups, criminals may exchange tips on social engineering techniques, share phishing kits, or pool resources to target larger organizations. This collective knowledge and resource-sharing make cyberattacks more sophisticated and harder to detect.

In some cases, attackers even auction off stolen credentials or offer hacking services, increasing the potential for account takeover and data breaches.

Why is Telegram a growing threat vector for businesses?

Telegram is becoming a preferred tool for cybercriminals targeting businesses, and several factors contribute to its rise as a threat vector:

  • Anonymity and encryption. Two of the platform’s key features (strong end-to-end encryption and anonymous Telegram accounts) make it difficult for authorities to spot malicious activities. Cybercriminals can create scam accounts, impersonate employees or executives, and operate in private channels or groups, making their actions harder to monitor and shut down.
  • Large user base. The platform’s popularity with individuals and businesses alike provides attackers with a wide pool of potential targets, ranging from unsuspecting employees to legitimate companies with valuable data.
  • Malware delivery and phishing. Telegram’s ability to host channels and bots makes it a convenient platform for distributing malicious links, phishing schemes, and malware. Telegram scammers can send targeted messages with harmful attachments or direct users to fake login pages, stealing login credentials or installing malware.
  • Ease of scalability. Telegram’s group chat and channel features allow attackers to scale their operations quickly. They can carry out large-scale phishing campaigns or distribute stolen data to numerous buyers in one go. All of this makes it a high-risk platform for businesses, as cybercriminals can launch coordinated attacks targeting many users at once.
  • Integration with other attacks. Telegram is often used as a part of a broader attack strategy. Whether it’s to distribute infostealer malware, track data breaches, or coordinate with other actors on dark web markets and forums, Telegram provides a flexible environment for cybercriminals to enhance the effectiveness and reach of their operations.

Due to these features, businesses need to be more vigilant in recognizing potential risks associated with Telegram and implement proactive measures to safeguard sensitive data from being compromised.

Common Telegram app scams

Telegram has become a prominent platform for various types of fraud, with scammers continuously finding new ways to exploit its features. From impersonation schemes to malware distribution, Telegram scams target businesses in multiple ways.

Executive impersonation and social engineering

One of the most common scams involves cybercriminals impersonating top-level executives like CEOs or CFOs. These scams often use social engineering techniques to deceive employees into acting quickly — whether it’s transferring money or providing sensitive information (bank details, payment details, personal or financial information, etc.).

Scammers create fake accounts, pose as trusted individuals, and send urgent messages that prompt victims to act without verifying the source, leading to potential financial or data loss.

Fake support channels and brand impersonation

In this type of scam, cybercriminals tend to mimic your company’s name, logo, other branding details, or official messaging style to create fake support channels and commit tech support scams.

Naturally, these scam accounts are used to deceive customers or business partners into providing personal information, making payments, pressing fake links, or downloading malicious files.

Since these fake Telegram channels may look legitimate at first glance, victims are often tricked into interacting with the attackers, unaware they’re being targeted.

Malware delivery via Telegram bots or messages

Telegram bots and direct messages are commonly used to deliver malware disguised as fake job listings, business files, or legitimate links. These links or attachments often appear to come from trustworthy sources but lead to malicious sites or harmful files.

Once clicked, these suspicious links can install malware on the victim’s device, steal sensitive information, or give attackers remote access to business networks.

Sale of stealer logs and internal credentials

Cybercriminals can also use Telegram as a marketplace to sell stolen corporate credentials. After malware is deployed to harvest internal credentials from infected devices, the attackers may sell these stealer logs in Telegram groups.

All this allows them to monetize stolen data, which can lead to further attacks or even data breaches. Businesses may find themselves at risk of severe financial loss if these credentials are misused.

Phishing campaigns using cloned business pages

Phishing campaigns through Telegram often involve creating cloned business pages that mimic legitimate brands or login portals. These fake pages are designed to deceive Telegram users into entering their login credentials, which are then harvested by cybercriminals.

The cloned pages may appear nearly identical to the real sites, making it difficult for victims to distinguish them from the official ones. These phishing domains pose a significant threat to personal information because unsuspecting users may share their credentials, putting both personal and business data at risk.

How do you detect scams on Telegram?

Detecting scams on Telegram can be quite challenging, but there are key red flags to look out for:

  1. Suspicious usernames or profiles. Don’t trust Telegram accounts that have suspicious usernames, seem unusual or incomplete, or look similar to well-known brands or individuals yet somehow feel off.
  2. Unsolicited messages or offers. If you receive unexpected messages or offers that sound too good to be true (think investment opportunities or outrageous job offers), be cautious.
  3. Links to unknown websites. Scammers often send links to phishing domains or suspicious fake websites. Always verify the URL before clicking on any link.
  4. Requests for personal information or credentials. Legitimate businesses will never ask for sensitive personal information via Telegram. Be suspicious of any request for credentials or financial details.
  5. Unusual activity in channels or groups. If you’re part of a Telegram group and notice strange behavior, such as unrequested promotional messages or suspicious file sharing, it could be a sign of a scam.

By staying alert and educating your team about these warning signs, you can reduce the risk of falling victim to Telegram bot scams.

What do you do if you get scammed on Telegram?

If you got scammed on Telegram, taking quick action is important to minimize the damage. Here are the steps you should follow:

  1. Disconnect from the scammer. Immediately block and report the suspicious account to Telegram. Doing so will help prevent further interaction.
  2. Change your passwords. If you have shared login credentials or financial information, change your passwords right away. Consider using a password manager to create strong, unique passwords for each account.
  3. Alert your team or organization. If the scam targets your business, inform your colleagues or employees about the breach. Taking this step will help prevent further incidents and ensure everyone is aware of the risk.
  4. Monitor your accounts and financial transactions. Regularly check your accounts for any unusual activity or unauthorized transactions to prevent scammers from taking advantage of your bank account logins and other data. If needed, contact your bank or financial institution to flag any suspicious behavior.
  5. Report the scam. Reporting the incident to Telegram can help prevent future scams and protect other users. Additionally, you may want to file a report with local authorities or cybersecurity organizations if sensitive data is compromised.

Taking these steps quickly can help you regain control and minimize the long-term impact of a Telegram app scam.

How to prevent common Telegram scams?

Preventing scammers on Telegram from taking advantage of your most sensitive information requires a proactive approach combining a set of tactics — from employee awareness and technical safeguards to ongoing monitoring. By implementing these strategies, you can reduce the likelihood of falling victim to scams.

Train employees

Educating your team is one of the most effective ways to prevent Telegram scams. Train employees to recognize suspicious Telegram profiles, messages, and scam links. Encourage them to verify the authenticity of any unexpected requests, especially if they involve sensitive information, financial transactions, or clicking on links.

Regular phishing awareness training can help teams stay alert to increasingly smarter scam tactics and avoid falling for common social engineering attacks. This type of training also mitigates the risk of account takeover, which can later result in identity theft.

Monitor Telegram for brand and credential abuse

Use threat exposure management solutions to regularly scan Telegram for any misuse of your company’s name or employee credentials. Scammers often impersonate businesses or use stolen data to trick victims. By monitoring for brand abuse or suspicious activity on fake Telegram channels, you can identify threats before they escalate.
Solutions like data breach monitoring can help catch these issues early and protect your reputation. Don’t forget to monitor the Telegram dark web for any leaked data that may be sold to malicious actors, exposing your organization to even greater risk.

Secure accounts with MFA and password managers

Implement two-factor authentication or multi-factor authentication (MFA) for all accounts, especially those tied to sensitive business data. Ensuring this step adds an extra layer of security if credentials are stolen or leaked via Telegram channels.

Additionally, encourage employees to use password managers to generate strong, unique passwords for each account. Doing so helps limit the potential damage if an account is compromised, particularly when dealing with threat exposure, account takeover, or even identity theft incidents.

Regularly monitor the dark web and stealer logs

Monitor the dark web and stealer log databases for any signs of compromised credentials. Telegram scammers often sell stolen credentials in Telegram groups, which could be used to launch attacks against your organization.

By staying ahead of these threats, you can take action before exposed data is used in phishing campaigns or other malicious activities. Keeping an eye on threat exposure ensures you stay one step ahead in protecting your personal information.

Use NordStellar to monitor Telegram-based threats

NordStellar is an excellent platform for monitoring Telegram-based threats. It detects various domain manipulations and provides real-time dark web and data breach monitoring. With NordStellar, you can monitor potential threats, including credential abuse, before they cause significant damage to your business. The platform provides actionable alerts and detailed reports to help security teams respond quickly and reduce potential damage from Telegram scams.

Detect Telegram-based threats before they compromise your business and your personal information. Contact NordStellar to learn how our solutions can help your organization stay ahead of Telegram scams and cyberattacks.

 

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is an OTP bot? How it works, risks, and prevention

What is an OTP bot

Summary: Learn how OTP bots steal one-time passwords, the growing risks for businesses, and practical steps to block attacks before they compromise your network.

One-Time Password (OTP) bots are automated scripts that trick users into delivering authentication codes to criminal actors.

The advent of inexpensive and readily available OTP bots has lowered the barrier for attackers to breach user accounts and access sensitive data. Unfortunately, many organizations still rely on SMS-based OTPs, which are vulnerable to social engineering and phishing attacks. Ironically, authentication tools designed to protect data may actually put it at risk.

This article will introduce the concepts behind OTP bots. We will explore types of bots and attack methods, discuss how OTP bots raise security risks, and suggest the next steps to secure your authentication portals.

What is an OTP bot?

A one-time password (OTP) is a single-use code commonly used in 2FA/MFA tools to enable user access. One-time passwords are unique and time-limited. This protects against credential theft attacks by requiring more than simple user name and password combinations.

An OTP bot is an automated script used by malicious actors to steal one-time passwords and compromise two-factor authentication (2FA) or multi-factor authentication (MFA) security. These bots use phishing techniques to deceive users into providing one-time passwords and enabling network access.

Attackers use several techniques to launch OTP bot attacks, including emails, voice phishing (vishing), and social engineering tactics. Attackers often use Telegram to share, sell, and coordinate the use of off-the-shelf OTP bot scripts.

How do OTP bots work?

OTP bot attacks blend automated bots and social engineering – an approach that is hard to detect. A typical OTP bot life cycle plays out something like this.

1. Preparation

The first step in an OTP bot attack establishes a connection between attackers and victims. Attackers seek to gain trust before convincing targets to provide their one-time passwords. In this phase of the attack, targets could encounter a few types of OTP bots.

  • Voice bots. OTP bots commonly use vishing techniques to simulate voice calls. In vishing attacks, criminals program bots with the phone numbers of targets. Bots call the victim’s phone number posing as a legitimate bank, a trusted vendor, or even a LinkedIn contact. As artificial intelligence and voice synthesis evolve, voice-based OTP bot attacks are becoming more effective and harder to track. With sufficient data, criminals can synthesize voices that closely resemble real-world contacts.
  • Phishing emails. Alternatively, attackers may send phishing emails to their victims. Bots use urgent language to convince the victim to provide their one-time credentials. Attackers use social engineering to research their targets’ professional duties and contacts. Bots leverage this research to write more persuasive messages. They also employ spoofing techniques to make the form of emails more convincing.
  • SMS OTP bots. Some attacks use fake SMS messages to convince their victims. These OTP bots send messages that mimic official alerts from legitimate companies. For instance, attackers might copy a text message from a security partner, requesting credentials for routine maintenance. Or they might pose as lenders seeking access to corporate bank accounts.
  • App-based OTP bots. Some OTP bots rely on fake authentication apps or web portals that closely imitate real ones. These aren’t real apps hacked by bots, but they’re convincing fakes built to steal one-time passwords.

2. Deception

The next stage in an OTP attack launches the password request process. The OTP bot triggers a password request on the service that criminals want to access. They generally use stolen credentials to ensure the target receives a one-time password request.

The authentication portal sends a one-time password to the victim’s account. At this point, attackers must act quickly. The OTP bot contacts the target and requests that they share the OTP. This could happen via phone calls, emails, or SMS messaging apps.

3. Infiltration

If the bot has developed sufficient trust and acted quickly enough, victims will share the one-time passcode, often without thinking of the consequences. Following OTP delivery, attackers gain unauthorized access and compromise the wider network. From there, it’s a short step to account takeovers and data breaches.

Remember: OTP bots are automated programs designed to act with minimal human input. Criminal collectives may use groups of bots to target an entire workforce. Advanced OTP bots can handle many stages of the attack automatically, significantly reducing the need for human intervention.

Common platforms and tools used in OTP bot attacks

While built as a legitimate messaging app, Telegram is frequently abused by attackers to host OTP bots, coordinate phishing campaigns, and share malware kits.

Telegram has been a popular base for attackers since at least 2021, when security experts uncovered the SMSRanger kit. This bot script impersonates PayPal and other payment apps. Entering a few scripting commands on Telegram allows criminals to direct bots to their targets. With scripts selling for under $50, OTP attacks are extremely cost-effective.

Other popular Telegram bots include SMS Buster, OTP Bot, Brainshot, and Apollo. These tools scan for SMS-based OTPs. Some of these tools are also integrated with CAPTCHA-solving filters or rely on social engineering to bypass CAPTCHA challenges.

 

Why OTP bots are a serious threat to businesses

OTP bots pose a threat to businesses because they target critical security infrastructure. Companies rely on 2FA/MFA to authenticate users before granting access. OTP bots bypass this measure, allowing threat actors to infiltrate network resources.

Another problem is that automated scripts drive down the cost of OTP attacks. Criminals can buy OTP bots and use Telegram’s API to manage attacks. Operating bots requires relatively little expertise and they can target many network users at the same time.

Bots also exploit human weaknesses. Skillful phishers create scripts that prompt targets to behave in ways they would not normally do. Manipulating human behavior allows criminals to bypass technical security measures.

Successful OTP bot attacks often have serious consequences, including account takeovers, enabling exfiltration of sensitive data, or secondary ransomware attacks. A single employee’s mistake can lead to crippling financial losses due to ransom payments, customer compensation, lost business, and regulatory fines.

Red flags and indicators of an OTP bot attack

Given the consequences listed above, companies need ways to detect criminal activity and cut OTP bot risks. Common red flags that signify OTP bot attacks include:

  • Surges in OTP request numbers. Spikes in password requests may indicate criminal activity as bots target multiple accounts. Bot activity is more likely if requests come from similar device profiles or IP addresses.
  • Rapid OTP requests. Users may also make repeated password requests in shorter timeframes than normal.
  • Repeated login failures strongly indicate the use of these techniques. OTP bots may use credential stuffing to start attacks and find legitimate login credentials.
  • Geolocation anomalies. Contacts may make calls, send SMS messages, or emails from unusual locations. Mis-matches between standard locations and sender locations should raise concerns.
  • Disposable phone or VoIP numbers. Vishers use temporary numbers to conceal their identities and work around verification processes.
  • Unusual changes in carrier networks. Employees may detect rapid changes in their mobile device carrier. This could indicate a SIM-swapping attack to enable OTP interception.
  • Abnormal timing. Sometimes, OTP bots operate more quickly (or slowly) than a legitimate site. Changes in the rhythm of interactions with authentication systems could indicate bot activity.

How to prevent OTP bot attacks and protect your business

One-time passwords require rock-solid protection against malicious actors. Many businesses assume their OTPs are secure and focus their energy on other security measures. However, complacency is not an option.

Companies need strategies to detect and neutralize automated OTP bots. Let’s discuss a few best practices to achieve these aims.

Don’t rely on SMS messages for multi-factor authentication

MFA is essential when strengthening account security. However, SMS-only MFA is becoming less secure. Criminals can easily intercept SMS-based OTPs. Parsing text messages for evidence of phishing is also more difficult than checking email headers or sender addresses.

Token-based authentication is a more reliable method. Even better, you can combine OTPs with biometric verification factors. Criminals struggle to copy biometrics (provided you store factors securely).

Implement account protection measures

Put in place security measures to block suspicious requests. For example, captcha filters block many OTP bots by requiring more than an OTP alone. Rate limiting blocks access after a certain number of requests, while short expiry times help cut the risk of OTP theft.

Security teams can also monitor access requests in detail to verify user identities. Device posture security measures check that a user’s device is legitimate. Monitoring tools can also track user behavior and detect unusual patterns that indicate ongoing attacks.

Implement robust password security policies

Security policies should require long, complex passwords and make secure password management tools mandatory. Users should also verify requests to share OTPs with external identities. Apply the principle of least privilege. All OTP requests are suspicious until proven otherwise.

Integrate OTP security into anti-phishing training

You probably already educate employees about phishing risks. Understanding temp OTP bot activity should be part of training exercises. Ensure staff understand how criminals use language to prompt unsafe behavior. Reinforce the need for verification and vigilance.

Tools that help defend against OTP bots

Today’s attackers use machine learning and automation to enhance OTP bots, making them harder to detect and more effective. Businesses should respond by updating their technical toolkit. The tools below enhance digital security and help block automated bots:

  • Behavioral analytics. These tools analyze user behavior to generate baseline data. They compare user signatures with real-time behavior patterns, helping detect anomalies and potentially prevent unauthorized account access.
  • Authentication apps. Apps like Google Authenticator and Authy store user account data and deliver secure OTPs for each login request. They do not rely on SMS messages, eliminating a critical vector for bot attacks.
  • IP allowlisting. Allowlisting tools keep registers of authorized IP addresses. This blocks access for attackers without the right digital address.
  • Device Posture Security (DPS). DPS tools go further than IP addresses, assessing the signatures of devices accessing the network. They keep logs of approved user devices and block access if device profiles don’t match.
  • Anti-fraud tools. These tools track network activity to detect evidence of fraud before a suspicious transaction occurs.
  • Adaptive authentication. Flexible tools apply step-up authentication in unsafe contexts. For example, employees may access central networks from public Wi-Fi services. Or they could request access to extremely sensitive information. In those circumstances, adaptive tools request additional login credentials like biometric factors or hardware tokens.
  • Dark Web monitoring. NordStellar’s platform monitors Dark Web forums, seeking mentions of companies. Meanwhile, data breach monitoring checks various types of exposed data, such as login credentials, email addresses, and personally identifiable information (PII). This way, security teams gain early insights into emerging OTP threats.

Should businesses still use OTP for authentication?

OTPs are not going away and companies need authentication systems to safeguard sensitive information. However, the spread of OTP bots is challenging the use of OTPs, especially those delivered via SMS.

One thing is certain: Companies using SMS-based authentication should consider alternatives. Criminals are highly skilled at using text messages to trick users and steal OTPs, making SMS passwords extremely vulnerable.

Other forms of authentication (tokens, authentication apps, and biometrics) are safe, provided companies use secure OTP delivery systems.

To strengthen your defense against OTP bot attacks:

  • Monitor access requests for unusual or high-risk activity.
  • Train employees to recognize social engineering and OTP phishing.
  • Use encryption to protect OTPs at rest and in transit.
  • Apply threat intelligence to detect OTP bot patterns early.

The key takeaway is that authentication remains essential for network security. However, if you let your guard down, OTP bots will bypass weak authentication processes.

Protect your business before OTP threats strike—connect with the NordStellar team today.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

The top 15 most infamous ransomware groups (2025 update)

The top 15 most infamous ransomware groups (2025)

Summary: Discover the most notorious ransomware groups. Learn about their operations and tactics, top targets, and proven defenses against ransomware threats.

Ransomware groups are responsible for some of the biggest cyber incidents in recent history. These cybercriminal groups target organizations of all sizes, from small companies to global corporations, to extort large amounts of money. This article explores the rise of ransomware organizations and their methods, provides a list of ransomware groups that are relevant today, and gives advice on how to protect your organization from falling victim to cyber extortion.

The rise of ransomware groups in recent years

Ransomware attacks are evolving at an alarming pace. What used to be isolated, small-scale incidents have now grown into highly organized, professional operations.

One major factor driving this surge is the way ransomware groups operate. Many active groups operate like businesses by offering ransomware-as-a-service (RaaS) to other criminal organizations.

These cybercriminals, who operate as ransomware-as-a-service groups, “rent” ransomware tools to other threat actors. Easy access to ransomware tools allows anyone, even individuals or groups with limited technical skills, to launch sophisticated attacks without needing to create malware themselves.

The numbers paint a clear picture. The Q1 2025 Global Cyber Attack Report by Check Point Software revealed that ransomware attacks jumped 126% compared to the same period in 2024, with 2,289 incidents reported worldwide. North America bore the brunt of these attacks, accounting for 62%, while Europe came in next at 21%.

Ransomware groups target industries that they know are most vulnerable. The report revealed that the consumer goods and services sector took the hardest hit, making up 13.2% of attacks globally, followed by business services (9.8%) and industrial manufacturing (9.1%).

There is a promising trend, though. Fewer victims are agreeing to pay the ransom. According to ransomware remediation firm Coveware, only 29% of victims paid the ransom in Q4 2023, compared to 46% in 2021 and 85% in 2019. This data shows that organizations are beginning to resist cyber extortion.

Still, refusing to pay doesn’t mean the problem goes away. Ransomware groups are launching more attacks than ever, and the financial damage keeps growing. Cybersecurity Ventures predicts that ransomware will cost victims around $275 billion annually by 2031.

So, while fewer victims are paying ransoms, ransomware attacks are growing more frequent and more sophisticated. This threat is not going away, and businesses of all sizes remain a target. To stay safe, organizations need to take action now.

Tactics and techniques used by top ransomware groups

The biggest ransomware groups are highly organized and use advanced tactics to breach networks, encrypt critical files, and extort money from businesses. Understanding how these threat actors operate is one of the most effective ways to defend against them.
By recognizing their methods, organizations can strengthen defenses, address vulnerabilities, and respond more effectively to potential threats. Below are some of the key tactics and techniques these ransomware groups use to maximize their impact and profits:

  • Phishing emails. Phishing remains one of the most common ransomware attack vectors. Ransomware groups often send fake emails designed to trick employees into opening malicious attachments or clicking on harmful links.
  • Exploitation of unpatched systems. Ransomware groups regularly target vulnerabilities in outdated security software or unpatched operating systems. This method allows attackers to gain initial access to networks and deploy ransomware with minimal effort.
  • Data exfiltration. Ransomware attacks now go beyond simple file encryption. Threat actors steal sensitive data from ransomware victims and threaten to publicly release it unless their demands are met. This tactic amplifies the pressure on organizations because data breaches often lead to legal consequences, as well as financial and reputational damage.
  • Double and triple extortion. Some of the most aggressive and prolific ransomware groups, such as LockBit and Cl0p, use double or triple extortion techniques. Multi-extortion tactics involve encrypting files, stealing sensitive victim data, and threatening financial penalties or public exposure.

Top 15 ransomware groups to know about in 2025

The following list highlights some of the most notorious ransomware groups you might hear or read about in 2025 and the upcoming years. While not all of them are still active, their operations and tactics continue to shape the ransomware threat landscape and how new ransomware groups operate.

1. LockBit

LockBit is one of the most aggressive ransomware groups in the world. This organization is responsible for more attacks than any other ransomware group, with over 1,700 attacks in the US since 2020, and has collected an estimated $91 million in ransom payments.

In 2023, it crippled Royal Mail, demanding a $80 million ransom. Later that year, it hit Taiwan Semiconductor Manufacturing Company (TSMC) with a $70 million ransom demand.

Although LockBit’s website was taken over by law enforcement authorities in early 2024, the group managed to rebuild and resume operations after the takedown. LockBit remains a serious global threat in 2025.

2. BlackCat/ALPHV

BlackCat, also known as ALPHV, is one of the most advanced and dangerous ransomware groups operating today. It doesn’t just encrypt data — it steals it first, which puts extra pressure on victims to meet the group’s demands.

The group’s latest ransomware strain, “Sphynx,” includes advanced features designed to evade detection and bypass security measures. BlackCat constantly evolves and targets high-value sectors, which makes it a serious and ongoing global threat that organizations cannot afford to ignore.

3. Cl0p

Cl0p, also written as Clop, is a highly sophisticated ransomware group that has been active since 2019. It primarily targets large organizations with revenues exceeding $5 million, including critical industries like healthcare and public health. Known for its double extortion tactics, Cl0p encrypts data and exfiltrates sensitive files, then threatens to release them on its dark web leak site if victims refuse to pay.

Although Ukrainian authorities arrested six suspected members of the Cl0p ransomware gang in 2021, as one of the most active ransomware groups, it still remains dangerous. The group relentlessly steals data and uses advanced tactics, which makes it a constant danger to organizations worldwide.

4. Conti

Conti is one of the most notorious ransomware gangs that operated between 2020 and 2022. Known for its aggressive double extortion tactics, the group reportedly extorted $180 million at its peak in 2021, making it one of the most profitable ransomware operations in history.

In 2022, Conti faced global backlash after publicly supporting Russia’s invasion of Ukraine. This controversial stance led many victims to refuse ransom payments. Shortly after, an insider leaked tens of thousands of internal chats and source code, exposing the group’s internal operations.

While Conti officially shut down in 2022, cybersecurity experts believe its members are still active and operate under different aliases.

5. Royal/BlackSuit

Royal ransomware is a highly dangerous threat that has targeted healthcare organizations, private companies, and local governments since it emerged in 2022. Initially operating under the name Zeon, Royal ransomware group is known for its personalized ransom demands, which range from $250,000 to over $2 million.

Security experts believe Royal is run by experienced hackers who split from other major ransomware gangs like Conti. The group employs advanced techniques to infiltrate networks and strongly focuses on double extortion tactics.

One of its most high-profile attacks occurred in May 2023, when it crippled the city of Dallas, Texas. This attack resulted in $8.5 million in mitigation costs and required thousands of hours of data recovery work. After June 2023, Royal ransomware evolved into what is now known as BlackSuit ransomware.

By late 2023, the group operating under its new name had extorted over $275 million from more than 350 victims worldwide. As of 2025, the BlackSuit variant continues the legacy of its predecessor.

6. REvil/Sodinokibi

REvil, also known as Sodinokibi, is one of the most infamous ransomware gangs in history. This Russian-linked group quickly gained notoriety for high-profile attacks on critical infrastructure and global corporations.

One of REvil’s most notable attacks targeted an Apple supplier. The hackers stole proprietary blueprints for new Apple devices and threatened to release them unless the supplier paid the ransom.

Although Russian authorities claimed to have dismantled the group in early 2022 and arrested several members, many experts believe remnants of REvil continue to operate under different aliases or contribute to other ransomware groups.

7. Hive

Hive ransomware, first found in June 2021, attacked industries like healthcare, finance, telecommunications, and governments. Major victims included CNA Insurance, Memorial Health System, the Bank of Zambia, and Costa Rica’s government.

In January 2023, the US Department of Justice, with help from Germany, the Netherlands, and Europol, shut down Hive’s operations. Investigators secretly infiltrated the group for months and blocked $130 million in ransom payments. Authorities seized Hive’s servers in California and Europe.

Despite this takedown, experts believe Hive’s hackers may have joined other ransomware groups or started working on a new ransomware strain. Unfortunately, law enforcement takedowns rarely put an end to these groups, just pause their operations.

8. Ragnar Locker

Ragnar Locker, one of the most active ransomware groups since 2019, was notorious for targeting critical infrastructure, including energy providers, governments, airlines, and hospitals. The group employed double extortion, demanding massive ransom payments for both decryption tools and the non-release of stolen data.

Ragnar Locker used the “Wall of Shame” leak site on the dark web to pressure victims, explicitly threatening to publish stolen data if they contacted police. In 2023, a global law enforcement operation dismantled Ragnar Locker’s infrastructure, and the group stopped operating under that name.

9. DarkSide/BlackMatter

DarkSide, first discovered in August 2020, gained global attention in May 2021 when it launched the Colonial Pipeline attack. This attack forced the shutdown of a 5,500-mile fuel pipeline that supplies 45% of the East Coast’s fuel, causing widespread fuel shortages, a state of emergency, and a ransom payment of over $4 million.

DarkSide used double extortion tactics, encrypting data while also stealing sensitive information to pressure victims. Following increased law enforcement pressure after the Colonial Pipeline attack, DarkSide briefly disappeared, and its members later resurfaced under the name BlackMatter.

Even though DarkSide/BlackMatter itself may no longer operate, its methods, tools, and tactics, such as double extortion, inspired other ransomware groups. It remains a key case study in the fight against ransomware.
10. Vice Society
Vice Society is a ransomware group that emerged in 2021. It quickly gained infamy for targeting schools, hospitals, and other vulnerable sectors. The group, believed to be Russian-speaking, targets underfunded organizations that often lack strong cybersecurity defenses.

Vice Society uses double extortion, encrypting data and threatening to leak sensitive files unless victims pay up. Unlike many ransomware gangs, it doesn’t run a RaaS model. Instead, it builds its own custom ransomware and uses powerful hacking tools like Cobalt Strike, Zeppelin, and Hello Kitty/FiveHands to carry out its attacks.

11. Medusa

Medusa is a highly active and dangerous ransomware-as-a-service (RaaS) group that has been operating since late 2021. Known for targeting industries like education, healthcare, legal services, insurance, and manufacturing, Medusa has impacted over 430 victims worldwide as of May 2025.

One of the most active ransomware groups uses aggressive tactics, including large-scale file encryption, data theft, and double extortion. The group encrypts data and threatens to publicly release stolen information if victims refuse to pay the ransom.

Medusa’s attacks have mostly affected organizations in the United States, the United Kingdom, and Canada. This ransomware group remains a significant global threat in 2025.

12. BianLian

BianLian is a rapidly evolving ransomware group that has been active since late 2021. It targets critical industries such as healthcare, manufacturing, and professional services across the United States and Europe.

The group initially used a double-extortion model, encrypting and stealing data. However, in 2023, it shifted tactics and abandoned encryption in favor of data theft and extortion.

BianLian has quickly become one of the top three most active ransomware groups, ranking alongside LockBit and BlackCat/ALPHV. Its leak site displays a growing list of victims, with the healthcare and manufacturing sectors being hit the hardest.

As of 2025, the group continues to expand operations by actively recruiting developers and affiliates to refine its methods, making it an ongoing threat to global cybersecurity.

13. 8Base

8Base is a ransomware group that first appeared in 2022 and significantly increased its activity in 2023. Known for targeting small to medium-sized businesses (SMBs) across industries like finance, manufacturing, IT, and healthcare, the group primarily operates in the United States, Brazil, and the United Kingdom.

8Base uses a combination of data encryption and “name-and-shame” tactics to pressure victims into paying ransoms. Despite its rapid rise in activity and a growing list of victims, 8Base remains relatively mysterious. Cybersecurity researchers have very limited information about this group’s identities or motivations.

14. RansomHouse

RansomHouse is a unique ransomware group that emerged in 2022. It focuses solely on data theft and extortion without encrypting files. Its “extortion-only” approach allows it to steal sensitive data and demand ransom payments in Bitcoin, all while claiming to act as a “force for good” by exposing weak security practices.

This strategy makes this group’s attacks harder to detect because skipping encryption triggers fewer alarms and can lead to longer dwell times inside victim networks.

RansomHouse primarily targets companies with poor security measures and markets itself as a mix of bug bounty hunters and penetration testers. After stealing data, it offers to provide a full report on exploited vulnerabilities and promises to delete the stolen information — if the ransom is paid, of course.

15. NoEscape

NoEscape, a ransomware group that emerged in May 2023, has quickly built a reputation for its aggressive multi-extortion tactics. It primarily targets industries like healthcare, manufacturing, and education, focusing on small and mid-sized businesses in North America and Europe, which often lack the resources to defend against attacks.

The group uses multi-layered extortion. It encrypts data, steals it, and threatens to leak it to maximize pressure on victims. NoEscape operates a TOR-based leak site to display stolen data and victim lists, solidifying its reputation as a fast-moving and ruthless threat.

While it avoids attacking entities in the Commonwealth of Independent States (CIS), its focus on critical industries makes it a significant danger to businesses worldwide.

 

How to protect your organization from ransomware groups

Ransomware groups target businesses of all sizes — no organization is safe. To defend against these malicious actors, organizations need to act now by employing strategic, proactive cybersecurity measures. Below are key steps your organization can take to reduce the risk of becoming a ransomware victim.

Train employees

Your employees are your first line of defense against ransomware. Threat actors rely on mistakes, using phishing emails and fake links to breach your critical systems.

Teach your team to recognize suspicious emails, unexpected attachments, and untrusted links. Regular training and phishing tests will help them stay alert and protect your organization from known or emerging ransomware groups.

Protect your data with backups and segmentation

Regularly back up critical data and store those backups securely offline, away from your main network. This approach ensures your data stays safe even if an attack happens. Failing to follow this step has left many organizations unable to recover from ransomware attacks and has amplified the impact of some of the biggest data breaches in recent years.

Network segmentation adds another layer of protection by separating sensitive data and systems from the rest of your network. Segmenting your network limits the ransomware’s reach and gives you more time to respond during an attack.

Strengthen endpoint security

Ransomware attacks often start on endpoints like laptops, desktops, or servers. To block these attacks early, use advanced endpoint protection tools that detect and stop ransomware as soon as an employee downloads a malicious file or clicks on a phishing link.

Stay ahead with threat intelligence feeds

Keep ransomware actors at bay by tracking real-time threat intelligence feeds. These tools alert you to new ransomware variants, active attacks, and exploitable vulnerabilities. Services like NordStellar deliver timely updates, which can help you spot risks early and strengthen your defenses.

Prepare with an incident response plan

Develop a clear, step-by-step strategy that outlines how to detect, contain, and respond to an attack. Test the plan regularly through simulated scenarios so employees and IT staff understand their roles and can act quickly in an emergency.

A well-prepared plan minimizes chaos, accelerates recovery, and provides a structured approach to handling ransomware. The faster your response, the less impact the attack will have on your organization.

Use advanced cybersecurity solutions

Invest in advanced cybersecurity tools that provide multi-layered protection. NordStellar threat exposure management platform provides solutions that allow companies to detect and respond to cyber threats early, breaking the cyber kill chain before an attack escalates.

NordStellar includes solutions like vulnerability management and dark web monitoring, which can give you insight into emerging ransomware tactics and help you identify if your data has been exposed. By partnering with NordStellar, your business is equipped with the latest technology to face evolving threats and stay one step ahead of cybercriminals.

Your data deserves the highest level of security. Contact the NordStellar team today to protect your organization against ransomware attacks.

FAQ

What is ransomware-as-a-service?

Ransomware-as-a-service (RaaS) is a business model where ransomware creators rent out their malware to other criminals for profit. RaaS is part of a larger trend called malware-as-a-service (MaaS), where hackers sell or rent malicious tools on the dark web. Unlike general malware, RaaS focuses solely on ransomware, which makes it simple for criminals to encrypt files and demand payment.

How does ransomware spread?

Ransomware spreads through phishing emails, infected software downloads, unpatched vulnerabilities, and malicious websites.

How do ransomware groups choose their targets?

Ransomware groups typically target organizations with valuable data and weak cybersecurity defenses. Ransomware groups are highly likely to target businesses that have paid ransoms in the past because they may assume these organizations are more likely to pay again.

Can ransomware come back after removal?

Yes, ransomware can return after removal if the underlying cause of the malware infection isn’t resolved.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is a DDoS attack? Types and mitigation strategies

What is a DDoS attack: Types, examples, mitigation

Not every online outage is an accident. Some are carefully orchestrated, meant to disrupt, damage, and draw attention. A DDoS attack is one of the most common methods used for this purpose, and it has become a serious threat to any business with a digital presence.

DDoS attacks are cheap to launch, hard to trace, and increasingly used to target the most sensitive institutions, such as banks, retailers, media outlets, and even hospitals. In a world that runs on constant connectivity, the effects are immediate — websites go down, users get locked out, and trust takes a hit.

In this article, we’ll explore what DDoS attacks are, how they work, and why they’re so effective. You’ll see real-world examples, learn to spot the warning signs, and discover the latest strategies to protect your systems from getting overwhelmed.

What is a DDoS attack?

A distributed denial-of-service (DDoS) attack is a cyberattack that disrupts the normal operation of a target server, service, or network connection. Unlike a traditional DoS attack, a DDoS attack uses multiple compromised devices, making it much harder to defend against.

Dangers caused by DDoS attacks

DDoS causes immediate and sometimes hard-to-recover damage, including:

  • Service disruption. The primary goal is to overwhelm a target server or network, rendering it slow, unresponsive, or completely unavailable to legitimate users.
  • Bandwidth exhaustion. Many DDoS attacks flood the target with more traffic than it can handle, blocking legitimate requests and consuming all available bandwidth.
  • System crashes. The flood of data can cause servers to crash or freeze, leading to significant downtime for businesses relying on those services.

Motivations behind DDoS attacks

The reasons behind DDoS attacks can vary, and attackers often have specific motives for launching them. Whether for political, financial, or competitive reasons, DDoS attacks can have far-reaching consequences.

Most common motivations include the following:

  • Hacktivism. Attacks are launched for political or social causes to disrupt organizations seen as unethical or oppressive.
  • Extortion. Cybercriminals demand a ransom to stop the attack. Failure to comply results in continued disruption.
  • Sabotage. Competitors or adversaries use DDoS attacks to damage an organization’s reputation, operations, or customer trust.
  • Distraction. A DDoS attack can serve as a smokescreen, distracting from more sophisticated attacks like data breaches or network infiltrations.

How does a DDoS attack work?

A successful DDoS attack works as a well-coordinated and systematic effort to overwhelm a target by sending an enormous amount of traffic to its systems. To understand how these attacks unfold, let’s break them down step by step.

DDoS attack

1. Preparation and planning

To launch DDoS attacks, attackers often research the target’s infrastructure to identify vulnerabilities and weak points. Attackers may also recruit a network of compromised devices (bots) to carry out the attack, which makes it harder to trace the origin of the traffic. Understanding what DDoS does in this phase is key — it identifies weak points and sets the stage for maximum disruption.

2. Building a botnet

The core of many DDoS attacks is the botnet — a network of infected devices, also known as bots. Attackers usually take control of thousands or even millions of devices by exploiting vulnerabilities in internet of things (IoT) devices, computers, and servers. These infected devices are referred to as zombies, and they’re often spread across the world, giving the attack a global scale. The devices could be anything from smart home appliances to personal computers.

How does infection happen? The botnet creator often infects devices by spreading malware through phishing emails, malicious websites, or other cyberattack methods. Once infected, these devices become part of the botnet and await instructions.

3. Command and control servers (C&C)

Once the botnet is built, the command and control servers (C&C) take over. These servers are controlled by the attacker and issue the attack commands to the botnet. Essentially, the C&C servers tell the infected devices when and how to attack the target.

The C&C servers often use encrypted channels to communicate with the bots, making the attack more difficult to detect or stop.

4. Initiation of the attack

When everything is set up, the botnet is triggered to flood the target with a large volume of traffic. The traffic could come in various forms — volumetric attacks, protocol attacks, and application layer attacks. This phase highlights the full scope of a DDoS attack in cybersecurity, where multiple vectors are used to degrade or take down a target’s operations.

5. Overloading the target

As the traffic increases, the targeted server or network begins to slow down due to resource exhaustion. Legitimate users experience delays, and eventually, the system becomes unresponsive. The attack continues, often forcing the targeted service to go offline.

The most common DDoS tactics include:

  • DNS amplification. A common tactic in DDoS attacks, where attackers exploit vulnerabilities in DNS servers to amplify the size of the service attack.
  • SYN flood. A type of protocol attack that targets the server’s TCP connection handling by sending incomplete connection requests.

6. Execution and impact

At this point, the target is under siege. The attacker’s goal is either to disrupt services (causing downtime and service unavailability) or to distract from other malicious activities. Some attackers might demand ransom in exchange for stopping the attack, while others are just trying to make a statement, disrupt operations, or cause financial damage.

The server struggles to handle the constant flow of requests, and downtime ensues, leading to service disruption, potential financial loss, and damage to the company’s reputation.

One common question businesses ask is how long does DDoS last, and the answer varies. Some attacks only last a few minutes, while others persist for hours or even days, depending on the resources and determination of the attacker.

Categories of DDoS attacks

DDoS attacks don’t all look the same. Some flood the network with meaningless traffic, while others quietly exhaust server resources with seemingly normal requests. To make sense of the chaos, these attacks are generally classified based on which layer of the OSI (Open Systems Interconnection) model they target — from the application itself all the way down to the physical infrastructure.

Here’s an overview of the main DDoS attack categories:

Application layer attacks

These attacks focus on Layer 7 — the application layer — where web pages are loaded and API requests are processed. They mimic real user behavior to overwhelm applications while remaining hard to filter out.

  • Typical attacks: HTTP floods, Slowloris, DNS query floods.
  • Goal: To crash websites or services by exhausting server-side resources.
  • Targets: Public-facing apps like shopping carts, login pages, or search functions.

Protocol (infrastructure layer) attacks

Targeting Layers 3 and 4, these attacks exploit the underlying transport and network protocols like TCP, UDP, or ICMP. They aim to exhaust the processing capacity of routers, firewalls, or load balancers.

  • Typical attacks: SYN floods, UDP floods, fragmented packet attacks.
  • Goal: To disrupt service by breaking the rules of how devices talk to each other.
  • Targets: Network infrastructure, gateways, or edge devices.

Volumetric attacks

These are the “blunt force” attacks of the DDoS world — they flood the network with sheer volume, consuming all available bandwidth.

  • Typical attacks: DNS amplification, NTP floods, UDP floods.
  • Goal: To saturate the internet connection and take the entire service offline.
  • Targets: Entire network segments, ISPs, or cloud platforms.

To put it in context, here’s how these attacks line up with the OSI model:

OSI layer

Type of attack

Examples

Impact

Layer 7: Application

Application layer attacks

HTTP floods, Slowloris, DNS query floods

Web server overload, app downtime

Layer 4: Transport

Protocol attacks (infrastructure)

SYN flood, UDP flood, TCP connection flood

Resource exhaustion of firewalls/load balancers

Layer 3: Network

Protocol and volumetric attacks

ICMP flood, IP fragmentation

Network equipment congestion

Layer 2: Data link

Rare/targeted disruption

MAC flooding, ARP spoofing

MAC flooding, ARP spoofing
Switch/router table overflows, link disruption

Layer 1: Physical

Hardware-level disruption

Cable cuts, signal interference

Complete physical disconnection

DDoS attack examples and real-world cases

Distributed denial-of-service (DDoS) attacks have made headlines over the years for taking down some of the internet’s most widely used services.

One of the most well-known examples occurred in 2018, when GitHub was targeted with a record-breaking attack that peaked at 1.35 Tbps. The attackers used a technique called memcached amplification, overwhelming the platform with traffic. Although GitHub responded quickly by rerouting the traffic through a mitigation service, the attack demonstrated just how fast and massive these attacks can become.

In 2016, DNS provider Dyn suffered a major DDoS attack that temporarily knocked major websites offline, including Twitter, Reddit, and Netflix. The attack was powered by the Mirai botnet, a DDoS network of compromised IoT devices like security cameras and routers. This event drew global attention to the vulnerabilities in consumer-grade connected devices.

Amazon Web Services (AWS) reported mitigating a DDoS attack in 2020 that reached 2.3 Tbps, making it the largest on record at the time. While the disruption was contained, the scale of the attack marked a shift toward more powerful and complex threats targeting cloud infrastructure.

These attacks are highly dangerous as they often result in lost revenue, customer trust issues, and high response costs.

How to detect a DDoS attack

Detecting a DDoS attack early is important to minimize its impact. While some disruptions are immediately obvious — like your website going down — others are more subtle and can look like ordinary performance issues, which include:

  • Unusually slow network performance. Pages take longer to load or time out entirely, even though user activity or backend operations haven’t changed.
    _ Unexplained spikes in traffic. A sudden surge in incoming requests, especially from unfamiliar IP addresses, locations, or devices, can signal hostile traffic. These spikes can vary based on the DDoS attack types, such as volumetric, protocol, or application-layer attacks.
  • Website or service outages. If your site becomes inaccessible or returns error codes (like 503 Service Unavailable), it might be overwhelmed by fake traffic — a common indicator of a DDoS attack in cloud computing environments where elastic resources are still not infinite.
  • Abnormal traffic patterns. For example, a flood of requests hitting a single API endpoint, login page, or checkout flow, often used as a tactic in application-layer attacks.
  • System resource exhaustion. Servers run out of CPU, memory, or bandwidth as they try to handle the flood of requests, impacting legitimate users.

To confirm whether you’re under attack, review logs and analytics. Also, consult your hosting or content delivery network (CDN) provider.

How to mitigate DDoS attacks

Mitigating a DDoS attack requires a combination of proactive planning, real-time monitoring, and the right defensive tools. Since no two attacks are identical, having a multi-layered enterprise security strategy ensures that you can employ a DDoS protection plan under a wide range of attack types while reducing your threat exposure.

Risk assessment

Consider integrating vulnerability scanning into your routine assessments. Regularly assessing your system’s vulnerabilities is crucial to understanding potential weak spots. External vulnerability scanning, in particular, helps identify issues from an outsider’s perspective — just like a hacker would.

Traffic differentiation

Distinguishing between legitimate and compromised traffic is the first line of defense. You can use firewalls and intrusion detection systems (IDS) to analyze incoming traffic patterns and drop suspicious requests early.

Continuous monitoring of network traffic

Setting up real-time monitoring of your network helps identify anomalies and attack patterns. Many DDoS mitigation services offer automated alerts to notify your team about traffic spikes and unusual patterns.

Black hole routing

When under attack, redirecting malicious traffic to a null route — a “black hole” — ensures it doesn’t affect your servers. While this doesn’t prevent the attack, it can isolate it from impacting your website or services.

Rate limiting

Rate limiting restricts the number of requests that can be made from a single IP in a specific timeframe. This measure prevents bots from flooding your system with requests and gives legitimate users a better chance to access your services.

Firewalls and anti-DDoS services

Advanced firewalls can block incoming attack traffic based on signature patterns. Additionally, subscribing to anti-DDoS services helps mitigate large-scale attacks by filtering the attack traffic.

Anycast network diffusion

Anycast routing allows legitimate traffic to be distributed across multiple data centers globally, making it harder for attackers to overwhelm a single point of failure. By spreading traffic out, the attack becomes less concentrated.

Incident response plan

An effective incident response plan ensures your team knows exactly what to do when an attack is detected. The plan should outline procedures for notifying key stakeholders, immediate actions to take, coordination with your hosting or CDN provider for faster response, and communication strategies for informing customers or users about the disruption.

Having a clear plan in place will reduce downtime, minimize confusion, and speed up recovery time.

 

Increasing DDoS attack threats

The nature of DDoS attacks is changing. While traditional attacks are still a concern, new techniques are appearing that complicate defense efforts and expand the attack surface — the total number of entry points that could be exploited.

The following are some of the emerging trends and the increasing threats in the world of DDoS attacks.

Multi-vector attacks

Attackers are no longer limited to a single type of DDoS attack. Multi-vector attacks combine multiple techniques — such as volumetric, protocol, and application layer attacks — into one devastating strike. These DDoS attacks are harder to block because they target different layers of a system simultaneously, often overwhelming defenses at multiple points in the cyber kill chain.

IoT botnets and Mirai variants

The proliferation of connected devices has led to a rise in IoT botnets — networks of compromised internet of things devices (like cameras, routers, and thermostats). The Mirai botnet, which was responsible for the 2016 Dyn DNS attack, is a prime example. With millions of IoT devices susceptible to compromise, attackers now have an enormous pool of devices to leverage for DDoS attacks.

AI-enhanced automations

Artificial intelligence (AI) is being used to enhance the effectiveness of DDoS attacks. With AI, attackers can automate and fine-tune service attacks in real time, making these attacks harder to detect and mitigate. AI can also be used to adjust the attack’s scale and timing based on the system’s defenses.

“Carpet-bombing” attacks

In a carpet-bombing attack, the attacker floods a network with traffic across a wide range of IP addresses. This tactic makes it difficult to filter out malicious traffic because it doesn’t come from a single source but from many, often making it harder for defenses to identify the attack as malicious.

DDoS as a service

As DDoS attacks become easier to execute, a new DDoS-as-a-service business model has emerged. This model allows attackers to rent botnets or perform service attacks to target their victims. The availability of DDoS tools for hire has lowered the barrier to entry, meaning that even less technical attackers can launch significant disruptions.

With the growing complexity of DDoS strategies, attack surface management has become essential. By continuously identifying, monitoring, and reducing exposed assets and entry points, organizations can make it harder for attackers to find weaknesses, especially in distributed and cloud-native environments.

How organizations can defend against DDoS threats

As DDoS attacks grow more sophisticated, organizations must adopt advanced and proactive strategies to protect their networks and services.

The following are the most common tactics for DDoS protection:

  • AI-based detection and mitigation. AI systems can analyze network traffic patterns, learning to identify anomalies or malicious behavior in real time. Such tools allow for quicker responses, reducing the time it takes to detect and neutralize an attack. AI can also be used to automate mitigation, adjusting defenses without human intervention.
  • Threat intelligence platforms. By analyzing real-time data from global threat feeds and monitoring sources, organizations can gain insights into ongoing service attack trends and proactively adjust defenses. Threat intelligence helps predict attack patterns, allowing for more targeted defenses.
  • Edge computing for enhanced defense. Edge computing allows data processing to occur closer to the source of the traffic, reducing the amount of data that needs to be processed centrally. By distributing traffic load and using edge locations, organizations can divert or mitigate DDoS attacks before they hit the core network.
  • Cloud-based DDoS protection services. Cloud providers offer specialized DDoS protection services. These platforms use advanced mitigation techniques, including massive traffic scrubbing capabilities, to filter out malicious traffic at the network edge before it reaches your servers.
  • Hybrid defense strategies. Many organizations are adopting hybrid defense models, combining on-premises security systems with cloud-based DDoS protection. Such a multi-layered approach ensures that defenses are robust across all points in the network.
  • Real-time monitoring and incident response. By implementing a real-time monitoring solution, organizations can quickly detect traffic anomalies, analyze the scope of the attack, and deploy mitigation tactics. Having a dedicated incident response team ready to handle a DDoS attack helps reduce downtime and ensures that businesses can return to normal operations swiftly.

For organizations looking to strengthen their defenses against DDoS attacks, NordStellar provides an attack surface management service that helps you better understand your company’s attack surface, find and fix vulnerabilities in your external digital assets, and meet the necessary compliance requirements.

Discover threats before they impact your business. Contact NordStellar to learn how our solutions can help your organization stay one step ahead of cybersecurity threats.

 

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Malware as a service (MaaS): Definition, rising threat, and protection strategies

Malware-as-a-service (MaaS): A growing cybersecurity threat

Malware as a service (MaaS) is becoming a go-to solution for cybercriminals, resulting in the growing popularity of such products. In the second half of 2024, MaaS attacks were responsible for as much as 57% of cyber threats to organizations, with most attackers relying on malware they didn’t create and don’t own but rather bought from more experienced parties.[1] The dark market for malware sold for a subscription fee is thriving, so it’s important to understand how to protect your company. Discover more about MaaS in cybersecurity and learn effective strategies to keep your organization safe.

What is malware as a service?

Malware as a service (MaaS) is a cybercrime business model that offers malware and related services for purchase or subscription. MaaS providers often sell bundles with user-friendly dashboards, customer support, and automation tools, making it easier for inexperienced criminals to carry out cyberattacks.

MaaS falls under the broader umbrella of cybercrime-as-a-service (CaaS), which includes a wide range of illicit offerings such as phishing kits, hacking tools, and stolen credentials. In the case of MaaS, cybercriminals can rent or purchase the infrastructure and malware they need to execute attacks without developing the malware themselves or owning any sophisticated resources.

In the past, most hackers used to create and own their own malware. To this day, the most famous viruses and malicious applications are linked to their creators, who were not only developers but also distributors and profiteers.

However, the market has evolved, and not all cybercriminals are experienced hackers. Some simply rely on off-the-shelf malware services, often found on underground forums or encrypted messaging platforms, where various malicious agents gather and connect. This shift makes MaaS a relatively young “business” model in terms of cybersecurity history.

How do MaaS platforms work?

Malware-as-a-service platforms operate as cybercrime marketplaces where malicious software is sold. These platforms are highly organized, with developers creating the software, administrators managing transactions, and agents providing support. Cybercriminals have plenty of options available — they can purchase software (one-time payment), enable a monthly subscription (and all the perks that come with it), or pay a percentage of what they make from the attacks (share profit).

In the cybersecurity world, MaaS product buyers are referred to as affiliates. This term originates from affiliate programs and is used by MaaS operators to describe their services. Affiliates and operators usually use encrypted messaging apps to connect and finalize transactions, ensuring they’re both as anonymous as possible.

MaaS platforms are often similar to legitimate software-as-a-service (SaaS) platforms — hence the resemblance in its name. The difference is that SaaS providers offer legitimate software with no ill intent, while MaaS providers and buyers intend to use the products against their victims.

Who uses MaaS and why?

Malware as a service is used by a wide range of cybercriminals, from amateurs to organized crime groups. The main users include:

  • Amateur hackers. Inexperienced hackers are often drawn to MaaS because they lack coding skills or programming knowledge but still want to profit from malicious attacks. This option presents a low risk, making it a quick way for amateurs to make money. Typically, their most common targets are small businesses and individuals with poor security habits.
  • Organized crime groups. Organized crime groups operate more like businesses than individuals. By using MaaS, they can delegate many of their operations and focus on more profitable areas, such as launching ransomware attacks on government institutions, extracting sensitive data to sell on the dark web, or laundering money.
  • Nation-state actors. Although these operations are often publicly condemned, many governments hire hackers for espionage and intelligence gathering. MaaS allows them to gain a political advantage over other countries without leaving a trace — since the malware is purchased rather than developed in-house — and it provides them with a way to conduct cyber operations without the need for extensive resources or development.

MaaS offers attackers a unique opportunity — it allows them to use off-the-shelf software for a subscription fee or a percentage of the profits gained from an attack, usually paid in cryptocurrencies to increase anonymity.

Developing any kind of functional software, including malware, is complicated and requires skill and knowledge. Modern cybercriminals don’t have to do that anymore, reducing both effort and exposure.

There are, however, a few risks associated with using MaaS. The dark web is full of cybercriminals, scammers, and people with no good intentions. Inexperienced attackers can fall victim to fraud and lose money.

Types of malware sold via MaaS

Malware as a service can take many forms, as the term “malware” is quite broad and refers to several types of malicious software. Some of the most commonly distributed MaaS products are:

  • Ransomware. Ransomware is a type of malware that encrypts data and prevents the victim from accessing it. Hackers use it to demand ransoms because many users would rather pay for decryption than lose sensitive information or have it released to the public. Ransomware distributed as MaaS is often referred to as ransomware as a service (RaaS).
  • Infostealers. These applications are created to steal private information, such as login credentials and credit card numbers. Advanced variants like Lumma Stealer or RedLine Stealer are particularly dangerous, capable of extracting passwords, cookies, and even cryptocurrency wallets. Infostealers send the stolen information to attackers, who can later sell or trade it on underground forums and marketplaces or use it for identity theft.
  • Spyware. Spyware monitors user activity, capturing data such as keystrokes, screenshots, and even images or video from the camera. The information obtained by spyware helps hackers gain information about their victims and use it to launch other cyberattacks.
  • Backdoors and botnets. Backdoors are covert mechanisms that allow unauthorized remote access to a system. They can take the form of a hidden part of a program, a standalone software, or a code at the hardware or firmware level. Attackers often use backdoors to compromise devices and incorporate them into large networks of infected devices known as botnets. This tactic allows attackers to launch simultaneous attacks from multiple devices, making it more challenging to detect the threat source.

How to protect your business against MaaS attacks

Protecting your business against MaaS attacks requires a well-defined strategy. Companies must ensure that not only the technical part of the problem is taken care of but also the human factor, which, more often than not, causes security leaks and makes attacks simpler.

Some of the best practices for vulnerability management include:

  • Investing in threat intelligence. Threat intelligence refers to the collection, analysis, and use of information about cybercrimes and hackers. Think of a spy working for a government agency, informing it in advance of potential threats, but in the cybersecurity world. Organizations can use specialized threat intelligence tools that automate the gathering and analysis of security data from multiple sources. There are several threat intelligence types, each of which is helpful in quickly detecting and mitigating vulnerabilities.
  • Relying on threat detection tools. Threat detection tools are designed to help spot any potentially malicious anomalies as quickly as possible. Manually monitoring massive amounts of traffic is humanly impossible, especially in a large company, so the best solution is to use automated software.
  • Monitoring the dark web. Dark web monitoring services scan the dark web in real time, searching for any company-related keywords and information that may have leaked after an attack you didn’t even know about.
  • Focusing on staff training. Employees can become a company’s weakest security link. A lack of cybersecurity awareness can make them vulnerable to phishing attacks and other cyber threats. Training and regular practice drills can improve a company’s cybersecurity, as no software can protect employees from themselves.

As with any malware and cyber threats, the best defense against MaaS is prevention. Losing data to hackers always means huge reputational and financial damage, some from business interruption and some from damage control and legal fees. Managing your threat exposure is critical to minimize the time it takes to detect and mitigate MaaS-related threats.

NordStellar provides a range of features designed to help identify, monitor, and prevent potentially malicious events so your clients and partners can trust you to keep their data safe.

 

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

A closer look at the biggest data breaches from 2020 to 2024

22 biggest data breaches from 2020 to 2024

The biggest data breaches in history have set new records. According to the Identity Theft Resource Center data, in the first half of 2024, over 1 billion US consumers had their personal information exposed — a 490% increase from 2023[1]. The consequences are severe — businesses are losing millions in lawsuits and facing reputational damage, individuals are dealing with identity theft and fraud, and governments are enforcing stricter regulations and demanding stronger data security measures.

While the risks posed by data breaches continue to grow, companies can take action and protect themselves. In this article, we examine the biggest data breach examples from 2020 to 2024, key trends shaping cybersecurity, and steps companies can take to protect their data.

1. National Public Data (NPD) breach

  • Date the data breach occurred: April 2024
  • Cause: Hacking
  • Countries affected: The United States, Canada, and the United Kingdom
  • Number of records exposed: 2.9 billion
  • People affected: Up to 170 million
  • Types of data compromised: Social Security numbers (SSNs), names, dates of birth (DOBs), email addresses, phone numbers, and mailing addresses

Discovery and announcement

In August 2024, security researchers found around 2.9 billion stolen National Public Data records for sale on dark web forums. The discovery raised alarms and led to an internal investigation. Shortly after, the company confirmed the breach.

Response

In response to the huge data breach, National Public Data collaborated with law enforcement and conducted a thorough review of affected records to assess the impact. The company strengthened its data security measures to prevent future incidents.

National Public Data also provided instructions on obtaining free credit reports from Equifax, Experian, and TransUnion. Additionally, it recommended users place fraud alerts or consider a credit freeze to mitigate the risks of identity theft.

Impact

The NPD data breach not only exposed billions of records but also led to the collapse of the company. After intense scrutiny, regulatory investigations, and mounting legal challenges, NPD declared bankruptcy in October 2024 and ceased operations[2], [3].

2. Mother of all breaches (MOAB)

  • Date the breach was discovered: January 2024
  • Cause: Compilation of multiple data breaches
  • Countries affected: Multiple
  • Number of records exposed: 26 billion
  • People affected: Hundreds of millions
  • Types of data compromised: Usernames, passwords, email addresses, and other sensitive information​

Discovery and announcement

In January 2024, security researcher Bob Diachenko and Cybernews investigators uncovered a huge data breach known as the “Mother of all breaches” (MOAB). The dataset contained approximately 26 billion records compiled from 3,876 websites, combining data from numerous past cybersecurity breaches.

Major platforms like LinkedIn, Twitter, Adobe, and Dropbox were among the affected sources. The breach also included records from government organizations in the US, Brazil, Germany, the Philippines, Turkey, and several other countries. Leak-Lookup, a data breach search engine, admitted it was the holder of the leaked dataset.

Response

Leak-Lookup attributed the breach to a “firewall misconfiguration” that has since been fixed. In response, Cybernews updated its data leak checker to include MOAB-related information, which would allow users to check if their data was exposed in one of the biggest data breaches to date.

Impact

The MOAB breach exposed the dangers of large-scale data collection and the lasting damage caused by repeated data security failures. By combining stolen records from thousands of past incidents, this breach significantly increased the risk of identity theft, fraud, and cyberattacks. With so much sensitive personal data in one place, hackers can easily locate and exploit exposed credentials, launch targeted phishing scams, and take over accounts.

The breach also raised concerns about how long companies store sensitive user data. It underscored the need for stricter policies to limit data retention and improve security. Even old breaches, once considered isolated incidents, can resurface in massive leaks like this, putting millions at risk. As of January 2024, MOAB is almost certainly the largest data breach ever discovered[4].

3. Financial Business and Consumer Solutions (FBCS) data breach

  • Date discovered: February 26, 2024
  • Cause: Unauthorized access to FBCS’s internal network
  • Countries affected: Primarily the United States
  • Number of records exposed: Undisclosed
  • Number of people affected: Undisclosed
  • Types of data compromised: Names, addresses, DOBs, SSNs, driver’s license and state identification numbers, medical claims, provider and clinical information, and health insurance details

Discovery and announcement

On February 26, 2024, FBCS detected unauthorized access to certain systems within its network. Investigators found that hackers had access to FBCS systems from February 14 to February 26, 2024.

During this time, they could view or acquire sensitive information stored on the network. To assess the impact, FBCS conducted a full review to determine what data was at risk and who was affected.

Response

After discovering the breach, FBCS took immediate action to investigate and contain the incident. The company reported the matter to federal law enforcement and worked with forensic specialists to understand how the breach occurred and prevent future attacks.

To strengthen security, FBCS built a new, more secure environment with additional safeguards to protect sensitive data. The company also urged affected individuals to remain vigilant against potential identity theft and fraud.

Impact

One of the biggest data breaches in 2024 exposed highly sensitive personal and healthcare information, which put individuals at risk of identity theft and medical fraud. Stolen SSNs and medical records could be misused for fraudulent insurance claims, unauthorized medical treatments, or financial scams[5].

4. Ticketmaster data breach

  • Date discovered: May 2024
  • Cause: Unauthorized access to a cloud database hosted by a third-party data services provider
  • Countries affected: The United States, Canada, and Mexico
  • Number of records exposed: Undisclosed
  • People affected: Customers who purchased tickets to events in North America
  • Types of data compromised: Email addresses, phone numbers, encrypted credit card information, and other personal details provided during ticket purchases

Discovery and announcement

In May 2024, Ticketmaster detected unauthorized activity in an isolated cloud database managed by a third-party provider. The company launched a full investigation with cybersecurity experts and notified the relevant authorities. The investigation confirmed that no further unauthorized access occurred beyond the initial incident.

Response

Ticketmaster worked with law enforcement, banks, and credit card companies to investigate the breach and mitigate its impact. Affected customers were offered a free 12-month identity monitoring service from a leading provider. Customers were also advised to monitor their bank and credit card statements for suspicious transactions and report any unauthorized activity immediately.

Impact

The Ticketmaster breach raised concerns about the security of third-party data storage and the risks customers face when trusting companies with personal and payment information. Although the company encrypted payment card data, hackers could still use exposed contact details for phishing scams, fraud attempts, and identity theft[6].

5. Change Healthcare data breach

  • Date discovered: February 21, 2024
  • Cause: A cybercriminal gained unauthorized access to Change Healthcare’s computer system and deployed ransomware
  • Countries affected: Primarily the United States
  • Number of records exposed: Undisclosed
  • People affected: Patients, healthcare providers, and insurers relying on Change Healthcare’s services
  • Types of data compromised: Names, contact details, DOBs, health insurance information, SSNs, government-issued IDs, medical records, diagnoses, medications, test results, financial data, and payment details

Discovery and announcement

On February 21, 2024, Change Healthcare detected ransomware activity in its systems. The company immediately shut down affected systems, disconnected its network to contain the attack, and launched an investigation with law enforcement and leading cybersecurity experts.

Response

On July 29, 2024, Change Healthcare began notifying affected individuals by mail. To contain the breach, the company shut down systems and severed network connections to stop further access. It also strengthened security policies and implemented additional safeguards to prevent future incidents.

Change Healthcare worked with cybersecurity experts to monitor both the clear and dark web for any misuse of stolen data. The company offered affected individuals free credit monitoring and identity protection services through IDX for two years, covering all costs.

Impact

One of the biggest data breaches in the healthcare industry had serious consequences for patients, healthcare providers, and insurers. Stolen medical records and insurance details could be used for identity theft, fraudulent claims, or financial fraud[7], [8].

6. AT&T data breach

  • Date discovered: April 19, 2024
  • Cause: Unauthorized access to AT&T’s workspace on a third-party cloud platform
  • Countries affected: Primarily the United States
  • Number of records exposed: Undisclosed
  • People affected: Both current and former AT&T customers, as well as customers of mobile virtual network operators (MVNOs) using AT&T’s wireless network
  • Types of data compromised: Records of customer call and text interactions, including telephone numbers and, for some records, associated cell site identification numbers

Discovery and announcement

On April 19, 2024, AT&T learned that a threat actor had unlawfully accessed and copied its call logs. The company immediately launched its incident response plan and brought in external cybersecurity experts to investigate.

The breach took place between April 14 and April 25, 2024. During this period, hackers stole files containing customer call and text records from May 1 to October 31, 2022, and January 2, 2023.

Response

AT&T quickly closed the unauthorized access point and worked with law enforcement to arrest those involved in the incident. The company notified both current and former customers whose information was compromised and provided resources to help protect their data.

Impact

The breach exposed call and text records from nearly all of AT&T’s wireless customers, including those using AT&T’s network through MVNOs and landline customers who interacted with these numbers during the specified periods.

Although the compromised data didn’t include content from communications or other sensitive personal information, the exposure of phone numbers and associated cell site identification numbers raised significant privacy concerns[9], [10].

7. Dell customer information data breach

  • Date the breached data was posted on the dark web: April 28, 2024
  • Cause: Unauthorized access to a Dell portal
  • Countries affected: The United States, China, India, Australia, and Canada​
  • Number of records exposed: 49 million customer records
  • People affected: Dell customers who made purchases between 2017 and 2024
  • Types of data compromised: Customer names, physical addresses, Dell hardware details, order and warranty information

Discovery and announcement

On May 9, 2024, Dell confirmed unauthorized access to a database containing customer information related to sales. Dell clarified that no financial or other personal data, such as email addresses, phone numbers, or passwords, were exposed.

Response

Dell took immediate action to contain the breach, activated its incident response procedures, and involved external cybersecurity experts to investigate the scope of the attack. The company notified law enforcement and worked to secure its systems further. It also informed the customers of the breach and gave advice on how to safeguard their information.

Impact

The breach exposed the personal information of approximately 49 million customers, particularly affecting those who made purchases from Dell between 2017 and 2024[11], [12].

8. Synnovis data breach

  • Date of attack: June 3, 2024
  • Cause: Ransomware cyberattack
  • Country affected: The United Kingdom
  • Data exposed: Approximately 400 GB of data
  • People affected: Patients and healthcare providers in South East London
  • Types of data compromised: Names, NHS numbers, and test codes

Discovery and announcement

On June 3, 2024, Synnovis, a partnership providing pathology services to several NHS organizations in South East London, experienced a ransomware attack that disrupted all IT systems and affected sample processing and result transmission.

On June 20, a cybercriminal group claiming responsibility for the attack published data online and claimed it was stolen from Synnovis. Synnovis confirmed that the data was from its administrative systems.

Response

In response to the breach, Synnovis worked closely with law enforcement, the Information Commissioner, the National Cyber Security Centre, and NHS England. It began a comprehensive investigation and took immediate steps to contain the breach and restore operations.

Synnovis publicly apologized for the disruptions caused to patients and healthcare services and reaffirmed its commitment to preventing future incidents. The company urged affected patients to attend scheduled appointments unless instructed otherwise and continued to provide updates to the public regarding the impact on services.

Impact

The ransomware attack caused major disruptions, including delays in test result processing and appointment cancellations. While emergency care remained operational, the breach affected many non-urgent services in South East London. It took the company until late autumn to restore access to all services that were available before the cyber attack.
Although the breach didn’t expose any sensitive clinical data, it severely impacted essential healthcare services, resulting in significant financial losses. According to company accounts, the estimated cost of the breach was £32.7 million — well above Synnovis’ 2023 profits of £4.3 million[13], [14], [15], [16], [17].

9. The 2023 Twitter (now X) data breach

  • Date discovered: January 4, 2023
  • Cause: A vulnerability in Twitter’s application programming interface (API) that allowed unauthorized access to user data
  • Countries affected: Multiple
  • People affected: Over 200 million Twitter users
  • Types of data compromised: Email addresses and phone numbers

Discovery and announcement

In January 2023, a hacker forum published a database containing the email addresses and usernames of over 200 million Twitter (now X) users. The data was sold for eight credits of the forum’s currency, worth approximately $2.

It was released as a RAR archive, which consisted of six text files totaling 59 GB of data. It was reportedly collected by exploiting a vulnerability in Twitter’s API between June 2021 and January 2022. BleepingComputer confirmed the validity of many of the email addresses listed in the leak.

Response

Twitter stated that it found no evidence the data was obtained through a vulnerability in its systems. The company suggested that the data might have been collected from publicly available sources.

Impact

The breach made it easier to link Twitter handles to real identities, potentially exposing these individuals to harm, retaliation, or surveillance. Verified users, including celebrities and politicians, were particularly vulnerable to extortion or manipulation because hackers could potentially exploit their data for malicious purposes[18], [19].

10. Progress Software data breach (MOVEit vulnerability)

  • Date discovered: May 2023
  • Cause: Zero-day vulnerability in Progress Software’s MOVEit Transfer application
  • Countries affected: Primarily the United States
  • People affected: Over 94 million users
  • Types of data compromised: Names, SSNs, banking details, and other confidential records

Discovery and announcement

On May 31, 2023, Progress Software identified a critical zero-day vulnerability (CVE-2023-34362) in its MOVEit Transfer application, a managed file transfer solution widely used across various sectors. This vulnerability, which stemmed from an SQL injection flaw, allowed unauthorized access to sensitive data within MOVEit Transfer’s databases.

Response

​Progress Software acted swiftly upon discovering the vulnerability. Within 48 hours, the company initiated an investigation, alerted MOVEit customers, and provided immediate mitigation steps.

On June 15, 2023, Progress released a security patch to address the flaw. The company temporarily took MOVEit Cloud offline to prevent further exploitation while applying patches.

Impact

The MOVEit breach significantly affected thousands of organizations globally. Progress Software reported $951,000 in cyber incident and vulnerability response expenses during its fiscal third quarter, which ended August 31, 2023.

Additionally, Progress Software faced 58 class-action lawsuits and received a subpoena from the US Securities and Exchange Commission (SEC). However, in August 2024, the SEC concluded its investigation and decided not to recommend any enforcement action against the company.

Despite this, as of this article’s publication, Progress Software continues to face hundreds of class-action lawsuits centralized in Massachusetts federal courts[20], [21], [22], [23], [24].

11. T-Mobile data breach

  • Date discovered: January 5, 2023
  • Cause: Unauthorized access via an exposed application programming interface (API)
  • Country affected: The United States
  • Number of records exposed: 37 million customer accounts
  • People affected: Current postpaid and prepaid customers of T-Mobile in the US
  • Types of data compromised: Customer names, billing addresses, email addresses, phone numbers, DOBs, T-Mobile account numbers, number of lines on the account, and service plan features

Discovery and announcement

On January 5, 2023, T-Mobile confirmed a data breach after a thorough investigation. The investigation found that a bad actor exploited an exposed application programming interface (API) to access limited customer information.

Response

Within 24 hours of detection, T-Mobile shut down the compromised API to prevent further access. The company immediately implemented its incident response protocols, notified affected customers, and reassured them that their financial data remained secure. It emphasized that no customer accounts were at direct risk.

Impact

While T-Mobile didn’t expect a significant impact on its business operations, it acknowledged the potential effect on customer trust. To address this, the company pledged to invest in cybersecurity improvements to better protect its customers and prevent future breaches.

In addition, on September 30, 2023, T-Mobile reached a $31.5 million settlement to resolve a probe by the Federal Communications Commission (FCC) into major data breaches that occurred over a three-year period. As part of the settlement, T-Mobile was required to pay a $15.75 million civil penalty and spend another $15.75 million over the next two years to strengthen its cybersecurity program[25], [26].

 

12. HCA Healthcare data breach

  • Date discovered: July 5, 2023
  • Cause: Theft from an external storage location
  • Country affected: The United States
  • Number of records exposed: 27 million rows of data
  • People affected: 11 million HCA Healthcare patients
  • Types of data compromised: Patient names, cities, states, ZIP codes, email addresses, phone numbers, DOBs, genders, service dates, facility locations, and upcoming appointment details

Discovery and announcement

On July 5, 2023, HCA Healthcare discovered that an unauthorized party had posted a list containing patient information on an online forum. The stolen data came from an external storage location used for formatting email communications, like appointment reminders and healthcare education messages.

On July 10, 2023, the company announced the breach in a press release, outlined its response plan, and began assessing the full impact.

Response

Upon discovering the breach, HCA Healthcare promptly disabled access to the compromised storage location and enrolled third-party experts for a comprehensive investigation. The company also reported the incident to law enforcement.

On July 14, 2023, HCA Healthcare began notifying impacted patients via email and mailed official notification letters. Shortly after, the company launched a dedicated webpage for real-time updates. To support affected individuals, it offered credit monitoring and identity protection services.

Impact

The breach didn’t disrupt patient care or operations but raised concerns about potential phishing attacks that may target affected individuals. HCA Healthcare advised patients to remain cautious of unsolicited communications asking for sensitive personal information. The company reported no financial costs[27], [28].

13. Cash App data breach

  • Date discovered: April 2022
  • Cause: Unauthorized access by a former employee
  • Country affected: The United States
  • People affected: 8.2 million users
  • Types of data compromised: Names, brokerage account numbers, portfolio values, holdings, and stock trading activity for one day

Discovery and announcement

In December 2021, a former employee of Block, Inc., the parent company of Cash App, accessed and downloaded sensitive customer data without authorization. Four months later, the company discovered the breach.

The discovery prompted Block to file a report with the US Securities and Exchange Commission (SEC). The compromised data was related to users of Cash App Investing, which is separate from Cash App’s primary peer-to-peer payment service.

Response

Once the breach was identified, Block acted quickly to launch an internal investigation and notify law enforcement. The company also brought in a leading forensics firm to help assess the scope of the breach.

Block notified approximately 8.2 million affected current and former customers. The company also provided them with clear information about the breach and offered guidance on how to protect their accounts.

Impact

Although hackers did not access critical personal details, the breach raised concerns about internal security practices and data protection measures. In response, Block agreed to a $15 million settlement to address allegations of negligence and compensate affected customers[29], [30].

14. The 2022 Twitter (now X) data breach

  • Date discovered: July 21, 2022
  • Cause: API vulnerability
  • Countries affected: Multiple
  • Number of records exposed: Details of 5.4 million Twitter accounts
  • People affected: 5.4M users
  • Types of data compromised: Usernames, phone numbers, and email addresses
    Discovery and announcement

In January 2022, Twitter (now known as X) was alerted to a vulnerability through its bug bounty program. This flaw allowed anyone to submit an email address or phone number to Twitter’s systems and identify the associated account.

The issue stemmed from a code update in June 2021. Twitter immediately fixed the flaw, and no exploitation was detected at that time. However, in July 2022, a report revealed that someone had exploited the vulnerability and was selling the collected data. Twitter confirmed the breach after reviewing the available data.

Response

Twitter acted quickly by notifying affected account owners. To protect users operating pseudonymous accounts, the company advised all users not to link publicly known phone numbers or email addresses to their accounts. Twitter also recommended enabling two-factor authentication for added security.

Impact

The breach exposed contact details — phone numbers and email addresses — for 5.4 million Twitter accounts. While much of the data was publicly available, hackers could still potentially use it in targeted phishing attacks and compromise users who wanted to remain anonymous[31], [32].

15. Syniverse data breach

  • Date discovered: May 2021
  • Cause: Unauthorized access to Syniverse’s electronic data transfer (EDT) environment
  • Countries affected: Multiple
  • Number of records exposed: Unknown
  • People affected: Customers of 235 telecom carriers, potentially billions of individuals whose messages and call records were processed by Syniverse
  • Types of data compromised: Login credentials for carrier customers, call records, data usage details, and text message routing information

Discovery and announcement

In May 2021, Syniverse discovered that an unknown individual or group had gained unauthorized access to its electronic data transfer (EDT) environment. The breach had been ongoing since May 2016, which means that attackers had access to sensitive information for nearly five years before the company discovered the breach.

On September 27, 2021, Syniverse disclosed the breach in a filing with the US Securities and Exchange Commission (SEC). The company confirmed that the breach impacted 235 telecom customers, but the potential number of affected individuals could be in the millions or even billions.

Response

Upon discovery, Syniverse activated security protocols and hired a top-tier forensics firm to investigate. The company reset or deactivated all affected customer credentials to prevent further access.

Syniverse notified law enforcement agencies, cooperated with investigators, and implemented stronger security measures to prevent future breaches. However, the company didn’t notify individual users directly. Instead, it relied on telecom customers to inform impacted subscribers.

Impact

The breach raised concerns because Syniverse handles inter-carrier messaging and data routing for major telecom operators. While the full extent is still unclear, cybersecurity experts speculated that the breach could have been a state-sponsored attack because no ransom demands or attempts to sell the data were observed[33], [34].

16. Facebook (Meta) data breach

  • Date discovered: April 2021
  • Cause: Scraping due to a vulnerability in Facebook’s feature
  • Number of countries affected: 106 countries
  • Number of records exposed: Unknown
  • People affected: 533 million Facebook users
  • Types of data compromised: Phone numbers, Facebook IDs, names, locations, DOBs, bios, and email addresses

Discovery and announcement

In April 2021, personal data from over 533 million Facebook users across 106 countries was leaked online. Hackers obtained the data through a vulnerability in Facebook’s “Contact importer” feature, which Facebook claimed to have patched in 2019.

Response

A Facebook spokesperson stated that the data was scraped due to the vulnerability in the “Contact importer” feature. However, Facebook didn’t notify affected users and argued that the data was publicly available.

Further investigation showed that Facebook planned to downplay the leak as an industry-wide issue rather than an isolated security failure. An internal email from April 2021 revealed the company’s strategy to minimize press coverage of the breach.

Impact

The exposed data posed risks, including potential impersonation, scams, and social engineering attacks. In November 2022, the Irish Data Protection Commission fined Meta Platforms, Facebook’s parent company, $276 million for violating GDPR regulations. This fine contributed to Meta’s reputation for receiving some of the largest data breach fines under GDPR[35], [36], [37], [38].

17. Microsoft data breach

  • Date discovered: January 2021
  • Cause: Exploitation of four zero-day vulnerabilities
  • Countries affected: Primarily the United States and several countries in Europe
  • Number of records exposed: Not explicitly quantified
  • Servers affected: Approximately 250,000 servers worldwide
  • People affected: Undisclosed
  • Types of data compromised: Emails, email attachments, user credentials, and administrative privileges on affected servers

Discovery and announcement

In early January 2021, cybersecurity firm Volexity discovered unusual activity on Microsoft Exchange Servers, which led to the identification of a major breach. Attackers exploited four zero-day vulnerabilities in the Exchange Server, collectively known as “ProxyLogon,” which allowed them to access email accounts, passwords, and administrative privileges.

The attackers used this access to move laterally within networks and installed web shells — malicious scripts that provided ongoing access, even after the vulnerabilities were patched. On March 2, 2021, Microsoft publicly disclosed the vulnerabilities.

Response

Upon discovering the breach, Microsoft acted swiftly and released security patches for Exchange Server versions 2010, 2013, 2016, and 2019. The company urged organizations to implement these patches immediately to close the vulnerabilities.

However, simply applying the patches didn’t remove the web shells already installed by the attackers. Organizations were advised to conduct thorough investigations to identify and remove any remaining threats and ensure their systems were secure.

Impact

The breach affected about 250,000 servers worldwide. In the United States alone, it compromised approximately 30,000 organizations. The breach impacted various sectors, including healthcare, legal, higher education, defense, policy think tanks, and small businesses.

The exposed stolen data could potentially lead to intellectual property theft, espionage, and further malicious activities, such as ransomware deployment on some compromised servers. The scale and severity of the attack make it one of the largest and most damaging cyber incidents in recent US history[50], [51], [52].

18. SolarWinds data breach

  • Date discovered: December 2020
  • Cause: Supply chain attack
  • Countries affected: Primarily the United States, but also the United Kingdom, Canada, Mexico, Spain, Israel, the United Arab Emirates, and other countries
  • Number of records exposed: Undisclosed, but numerous US federal agencies and private sector companies were affected
  • People affected: More than 18,000 SolarWinds customers
  • Types of data compromised: Emails, confidential documents, internal communications, and potentially sensitive government and corporate data

Discovery and announcement

In December 2020, cybersecurity firm FireEye discovered a cyberattack targeting SolarWinds’ Orion software, a widely used IT management platform. Investigations revealed that the attackers had infiltrated SolarWinds as early as September 2019 and were testing their ability to inject malicious code.

By February 2020, they successfully inserted trojanized code into Orion’s software updates, which SolarWinds unknowingly distributed. This backdoor, named SUNBURST, granted remote access to infected systems.

Response

On December 13, 2020, the Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive for federal agencies to disconnect SolarWinds Orion products. The White House’s National Security Council formed a Cyber Unified Coordination Group to lead the response.

SolarWinds worked with law enforcement and cybersecurity experts to investigate the breach and released patches to fix the vulnerability. Microsoft and other security firms helped reroute malicious traffic to limit further exploitation. Congress held hearings to assess the risks to the IT supply chain and urged stricter regulations for government contractors handling extremely sensitive data.

Impact

The SolarWinds breach is one of the most significant cybersecurity incidents in history, which affected multiple US federal agencies, including the Departments of Treasury, Commerce, State, Homeland Security, and the National Nuclear Security Administration.

The breach exposed vulnerabilities in supply chain security and raised concerns about espionage and cyber warfare. While not all 18,000 customers were exploited, high-value targets, such as US government agencies and Fortune 500 companies, were specifically targeted.

In response to the breach, the US government formally blamed Russia’s Foreign Intelligence Service (SVR) for orchestrating the attack. The US administration identified the breach as part of a broader campaign of cyber espionage linked to the Russian government.

In April 2021, the Biden administration imposed sanctions on Russia. Additionally, the US Securities and Exchange Commission (SEC) fined several tech firms for failing to disclose cybersecurity risks related to the breach[39], [40], [41], [42].

19. MGM Hotels data breach

  • Date discovered: July 2019
  • Cause: Unauthorized access to an exposed cloud database
  • Countries affected: Primarily the United States
  • Number of records exposed: Tens of millions of private customer data records
  • People affected: More than 10.6 million hotel guests
  • Types of data compromised: Names, home addresses, phone numbers, emails, DOBs

Discovery and announcement

In July 2019, MGM Resorts suffered a large data breach when an unauthorized party accessed a cloud database containing information of millions of guests, including regular travelers, celebrities, tech executives, journalists, and government officials. Although MGM stated that the compromised data was “old,” many contact details were still valid.

Response

After discovering the breach, MGM hired two cybersecurity firms to investigate. While the company notified affected customers of the breach, it didn’t make a public disclosure until cybercriminals exposed the breached data in 2020. Experts criticized the delayed public disclosure and MGM’s lack of transparency.

Impact

The exposed data presented significant security risks, especially for high-profile guests. While MGM stated the breach didn’t affect operations, the leak damaged the company’s reputation and highlighted vulnerabilities in its data protection practices. The breach led to class-action lawsuits and a $45 million settlement, which also covered damages from later cybersecurity incidents.

In September 2023, MGM experienced another major data breach, which further heightened concerns about its data security practices[43], [44].

20. Marriott International data breach

  • Date discovered: End of February 2020
  • Cause: Unauthorized access using compromised employee login credentials
  • Countries affected: Multiple
  • People affected: 5.2 million guests
  • Types of data compromised: Contact details (name, address, email, phone), loyalty account info (account number, points balance), personal details (company, gender, birthday), preferences (room type, language), linked partnerships (airline loyalty programs)

Discovery and announcement

In late February 2020, Marriott discovered that an unexpected amount of guest information had been accessed using the login credentials of two employees at a franchise property. The unauthorized activity likely began in mid-January 2020.

Response

Upon discovery, Marriott disabled the compromised credentials and initiated an investigation. The company increased monitoring and provided resources to inform and assist guests. It also notified relevant authorities and cooperated with their investigations.

On March 31, 2020, Marriott emailed affected guests, set up a dedicated website, and provided call center resources. Marriott also offered free enrollment in the IdentityWorks personal information monitoring service for one year, provided by Experian.

Impact

The breach exposed the sensitive information of 5.2 million guests. While the breach didn’t compromise financial data or encrypted passwords, it raised concerns about Marriott’s data security practices, especially in light of the 2018 breach that affected 500 million guests.

In October 2024, Marriott agreed to pay a $52 million settlement to 49 states and the District of Columbia over multiple data security failures from 2014 to 2020 that affected over 334 million customers.

As part of the settlement, Marriott and Starwood committed to improving data security. They also allowed US customers to request the deletion of their personal information and reviewed loyalty accounts for potentially stolen points[45], [46], [47].

21. CAM4 data breach

  • Date discovered: March 2020
  • Cause: A firewall failure
  • Countries and people affected: Primarily users from the US, Brazil, and Italy
  • Number of records exposed: 10 billion records
  • Types of data compromised: Names, email addresses, hashed passwords, country of origin, device information, gender preference, sexual orientation, payment logs (credit card type, amount paid), chat transcripts, fraud detection logs, and IP addresses

Discovery and announcement

In March 2020, cybersecurity researchers from Safety Detectives discovered that CAM4, an adult live-streaming platform, had left its Elasticsearch production database exposed online without a password. This misconfiguration allowed anyone with the correct IP address to access sensitive user information.

Response

Granity Entertainment, CAM4’s parent company, quickly secured the exposed database by removing it from public access and moving it to a secure internal network. It also deleted any personally identifiable information from the database. However, because the logs dated back to March 16, 2020, it’s possible that cybercriminals had accessed the data before the company secured it.

On May 4, 2020, Granity publicly stated that researchers and internal security teams had accessed only 93 individuals’ data. It denied that external hackers had exploited the database. Still, experts criticized CAM4 for not having sufficient security measures in place.

Impact

Although investigators found no confirmed evidence of widespread data misuse, the breach exposed users to potential blackmail, phishing, and identity theft. Users who did not use anonymous credentials risked having their real identities linked to their online activity.

While the breach didn’t receive widespread media attention, privacy experts warned that if cybercriminals had exploited the data, Granity Entertainment could have faced significant lawsuits and regulatory penalties, especially under Europe’s GDPR and other global data protection laws[48], [49].

22. Sina Weibo data breach

  • Date discovered: March 2020
  • Cause: Exploitation of a feature allowing users to find friends by uploading their phone contacts
  • Countries affected: Primarily China
  • Number of people affected: 538 million users
  • Types of data compromised: Names, usernames, gender, location, and phone numbers

Discovery and announcement

In March 2020, Sina Weibo, China’s leading microblogging platform, confirmed a massive data breach that affected approximately 538 million users. The breach was revealed when a hacker offered the stolen user data for sale on the dark web for $250. Weibo clarified that passwords were not exposed in the breach.

Response

After the breach, China’s Ministry of Industry and Information Technology (MIIT) summoned Weibo representatives to address the incident. The MIIT instructed Weibo to improve data security and internal management and notify users and authorities of future incidents.

Although the data breach didn’t expose any passwords, Weibo advised users who reused passwords across different platforms to take extra precautions. The company committed to strengthening its security measures and reported the breach to law enforcement.

Impact

The breach compromised the personal information of 538 million users, making it one of the world’s biggest data breaches. The stolen data increased the risk of phishing attacks, identity theft, and other malicious activities[53].

Recent major data breaches reveal several key trends and patterns:

  1. Attackers continue to rely on common but highly effective methods, including phishing, ransomware, and supply chain attacks. Top ransomware groups use these tactics to target organizations and maximize their impact.
  2. Corporate data breaches expose large volumes of sensitive customer information, while government hacks raise serious national security concerns.
  3. Industries dealing with valuable personal or financial data, including healthcare, finance, and technology, remain prime targets.
  4. The full scale of data breaches often takes months or years to emerge.
    What’s more, stolen data frequently appears on the dark web long after the initial attack, making it challenging for authorities to trace the source or hold attackers accountable. This delay puts organizations and individuals at risk without their knowledge, giving cybercriminals a significant advantage.

In response, regulatory bodies are tightening compliance requirements. Laws like GDPR and CCPA are driving companies to improve security and breach disclosure practices. However, as cybercrimes continue to evolve, businesses must go beyond just compliance and implement proactive cybersecurity strategies to stay ahead of emerging threats.

How companies can protect against data breaches

Cyberattacks are becoming more sophisticated, but businesses can take strategic steps to reduce the risk and minimize damage. Below are four essential measures every company should implement to strengthen cybersecurity and respond effectively to various data breach types.

  • Enforce strong access controls. Limiting access to sensitive data and systems with multi-factor authentication (MFA) and role-based permissions reduces the risk of insider threats and unauthorized intrusions. Regular vulnerability management can help identify and address any weaknesses in these systems.
  • Keep systems updated and patched. Cybercriminals often exploit outdated software with known vulnerabilities. Regularly updating and patching applications, operating systems, and security tools can close these gaps and prevent attackers from using them as entry points.
  • Train employees to recognize cyber threats. Recent findings show that human error is the leading cause of data breaches[54]. Educating employees on phishing, social engineering, and secure data handling can reduce the likelihood of accidental leaks and security lapses. A well-trained staff acts as the first line of defense against cyber threats.
  • Monitor and contain breaches with threat detection tools. No system is completely immune to cyberattacks, which is why early detection is critical. Data breach monitoring and threat detection and response solutions, like those provided by NordStellar, can help businesses identify breaches in real time, contain the damage, and prevent attackers from spreading further within the network.
    Additionally, the rise of malware-as-a-service (MaaS) means companies must be prepared for increasingly accessible and powerful malware tools that may bypass traditional security measures. Rapid response and continuous monitoring can significantly reduce an incident’s impact.

Cyberattacks aren’t going anywhere. Contact the NordStellar team to get complete visibility over your cyber threats.

References

[1] “ITRC sees third-most data breach victims in a quarter in Q2 2024,” Identity Theft Resource Center, Jul. 17, 2024. [Online]. Available: https://www.idtheftcenter.org/post/itrc-sees-third-most-data-breach-victims-in-quarter/

[2] “Breach information,” National Public Data, 2024. [Online]. Available: https://web.archive.org/web/20240813211719/https://nationalpublicdata.com/Breach.html

[3] Hofmann v. Jerico Pictures Inc., No. 024-CV-61383-SD (Fla. Aug. 1, 2024). Bloomberg Law. [Online]. Available: https://www.bloomberglaw.com/public/desktop/document/HofmannvJericoPicturesIncDocketNo024cv61383SDFlaAug012024CourtDoc?doc_id=X6S27DVM6H69DSQO6MTRAQRIVBS

[4] V. Petkauskas, “Billions of passwords and credentials leaked in the ‘Mother of All Breaches,'” Cybernews, Mar. 13, 2024. [Online]. Available: https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/

[5] “Cyber incident,” FBCS, Inc., n.d. [Online]. Available: https://www.fbcs-inc.com/cyber-incident/

[6] “Ticketmaster data security incident,” Ticketmaster, n.d. [Online]. Available: https://help.ticketmaster.com/hc/en-us/articles/26110487861137-Ticketmaster-Data-Security-Incident

[7] “Health data breach,” UnitedHealth Group. [Online]. Available: https://www.unitedhealthgroup.com/ns/health-data-breach.html

[8] “HIPAA substitute notice,” Change Healthcare. [Online]. Available: https://www.changehealthcare.com/hipaa-substitute-notice.html

[9] “Form 10-Q: Quarterly report,” US Securities and Exchange Commission. [Online]. Available: https://www.sec.gov/ix?doc=/Archives/edgar/data/0000732717/000073271724000046/t-20240506.htm

[10] “Addressing illegal download activity,” AT&T. [Online]. Available: https://about.att.com/story/2024/addressing-illegal-download.html

[11] D. Winder, “Dell confirms database hacked, hacker says 49 million customers hit,” Forbes, May 10, 2024. [Online]. Available: https://www.forbes.com/sites/daveywinder/2024/05/10/dell-confirms-database-hacked-hacker-says-49-million-customers-hit/

[12] “Threat actor claims sale of Dell database containing 49 million customer records,” Daily Dark Web, [Online]. Available: https://dailydarkweb.net/threat-actor-claims-sale-of-dell-database-containing-49-million-customer-records/

[13] “Update on cyber incident, 25 July 2024,” Synnovis. [Online]. Available: https://www.synnovis.co.uk/news-and-press/update-on-cyber-incident-25-july-2024

[14] “Cyberattack update, 01 July 2024,” Synnovis. [Online]. Available: https://www.synnovis.co.uk/news-and-press/cyberattack-update-01-july-2024

[15] “NHS London statement on Synnovis ransomware cyber attack,” NHS England, Jun. 4, 2024. [Online]. Available: https://www.england.nhs.uk/london/2024/06/04/nhs-london-statement-on-synnovis-ransomware-cyber-attack/

[16] “Synnovis ransomware cyber attack,” NHS England. [Online]. Available: https://www.england.nhs.uk/london/synnovis-ransomware-cyber-attack/

[17] “Cyber attack cost Synnovis an estimated £32.7m in 2024,” Digital Health, Jan. 2025. [Online]. Available: https://www.digitalhealth.net/2025/01/cyber-attack-cost-synnovis-estimated-32-7m-in-2024/

[18] “Update about an alleged incident regarding Twitter user data being sold online,” Twitter (X), 2023. [Online]. Available: https://privacy.x.com/en/blog/2023/update-about-an-alleged-incident-regarding-twitter-user-data-being-sold-online

[19] L. Abrams, “200 million Twitter users’ email addresses allegedly leaked online,” BleepingComputer, [Online]. Available: https://www.bleepingcomputer.com/news/security/200-million-twitter-users-email-addresses-allegedly-leaked-online/

[20] “MOVEit Transfer critical vulnerability,” Progress, May 31, 2023. [Online]. Available: https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023

[21] “MOVEit Transfer and MOVEit Cloud vulnerability,” Progress, [Online]. Available: https://www.progress.com/trust-center/moveit-transfer-and-moveit-cloud-vulnerability

[22] “MOVEit vulnerability,” National Cyber Security Centre, [Online]. Available: https://www.ncsc.gov.uk/information/moveit-vulnerability

[23] “Form 8-K: Current report,” US Securities and Exchange Commission, Aug. 6, 2024. [Online]. Available: [https://www.sec.gov/Archives/edgar/data/876167/000087616724000138/prgs-20240806.htm (https://www.sec.gov/Archives/edgar/data/876167/000087616724000138/prgs-20240806.htm)

[24] “MDL 3083: In Re: MOVEit Customer Data Security Breach Litigation,” US District Court for the District of Massachusetts, [Online]. Available: https://www.mad.uscourts.gov/caseinfo/multi-district-litigation.htm#:~:text=MDL%203083%3A%20In%20Re%3A%20MOVEit%20Customer%20Data%20Security%20Breach%20Litigation

[25] “Customer information,” T-Mobile, [Online]. Available: https://www.t-mobile.com/news/business/customer-information

[26] “Form 8-K: Current report,” US Securities and Exchange Commission, Jan. 9, 2023. [Online]. Available: https://www.sec.gov/ix?doc=/Archives/edgar/data/0001283699/000119312523010949/d641142d8k.htm

[27] “HCA Healthcare reports data security incident,” HCA Healthcare, [Online]. Available: https://investor.hcahealthcare.com/news/news-details/2023/HCA-Healthcare-Reports-Data-Security-Incident/default.aspx

[28] “Privacy update,” HCA Healthcare, [Online]. Available: https://hcahealthcare.com/about/privacy-update.dot

[29] “Form 8-K: Current report,” US Securities and Exchange Commission, Aug. 9, 2022. [Online]. Available: https://www.sec.gov/ix?doc=/Archives/edgar/data/0001512673/000119312522095215/d343042d8k.htm

[30] “Salinas, et al. v. Block, Inc. and Cash App Investing, LLC,” Cash App Security Settlement, [Online]. Available: https://cashappsecuritysettlement.com/home

[31] “An issue affecting some anonymous accounts,” X (Twitter), 2022. [Online]. Available: https://privacy.x.com/en/blog/2022/an-issue-affecting-some-anonymous-accounts

[32] L. Abrams, “Hacker selling Twitter account data of 54 million users for $30K,” BleepingComputer, [Online]. Available: https://www.bleepingcomputer.com/news/security/hacker-selling-twitter-account-data-of-54-million-users-for-30k/

[33] “Preliminary proxy statement,” US Securities and Exchange Commission, [Online]. Available: https://www.sec.gov/Archives/edgar/data/1839175/000119312521284329/d234831dprem14a.htm

[34] “Telecoms giant Syniverse discloses years-long data breach,” SecurityWeek, [Online]. Available: https://www.securityweek.com/telecoms-giant-syniverse-discloses-years-long-data-breach/

[35] A. Holmes, “Stolen data of 533 million Facebook users leaked online,” Business Insider, Apr. 3, 2021. [Online]. Available: https://www.businessinsider.com/stolen-data-of-533-million-facebook-users-leaked-online-2021-4?r=US&IR=T

[36] “Data Protection Commission announces decision in Facebook data scraping inquiry,” Data Protection Commission, [Online]. Available: https://www.dataprotection.ie/en/news-media/press-releases/data-protection-commission-announces-decision-in-facebook-data-scraping-inquiry

[37] Reuters, “Facebook users affected by data breach eligible for compensation, German court says,” Reuters, Nov. 18, 2024. [Online]. Available: https://www.reuters.com/technology/facebook-users-affected-by-data-breach-eligible-compensation-german-court-says-2024-11-18/

[38] P. Van Leemputten “Interne mail toont hoe Facebook veiligheidsproblemen wil ‘normaliseren,’” Data News, [Online]. Available: https://datanews.knack.be/nieuws/interne-mail-toont-hoe-facebook-veiligheidsproblemen-wil-normaliseren/

[39] D. Temple-Raston, “A worst nightmare cyberattack: The untold story of the SolarWinds hack,” NPR, Apr. 16, 2021. [Online]. Available: https://www.npr.org/2021/04/16/985439655/a-worst-nightmare-cyberattack-the-untold-story-of-the-solarwinds-hack

[40] “SolarWinds cyberattack demands significant federal and private sector response [infographic],” US Government Accountability Office, [Online]. Available: https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic

[41] “Fact sheet: Imposing costs for harmful foreign activities by the Russian government,” The White House, Apr. 15, 2021. [Online]. Available: https://web.archive.org/web/20210422234636/https://www.whitehouse.gov/briefing-room/statements-releases/2021/04/15/fact-sheet-imposing-costs-for-harmful-foreign-activities-by-the-russian-government/

[42] “Press release 2024-174,” US Securities and Exchange Commission, [Online]. Available: https://www.sec.gov/newsroom/press-releases/2024-174

[43] C. Cimpanu, “Exclusive: Details of 10.6 million MGM hotel guests posted on a hacking forum,” ZDNet, [Online]. Available: https://www.zdnet.com/article/exclusive-details-of-10-6-million-of-mgm-hotel-guests-posted-on-a-hacking-forum/

[44] “Tonya Owens, et al. v. MGM Resorts International et al.,” US District Court for the District of Nevada, [Online]. Available: https://storage.courtlistener.com/recap/gov.uscourts.nvd.164564/gov.uscourts.nvd.164564.63.0.pdf

[45] “Marriott International notifies guests of property system incident,” Marriott International, Mar. 31, 2020. [Online]. Available: https://news.marriott.com/news/2020/03/31/marriott-international-notifies-guests-of-property-system-incident

[46] “Marriott International: Incident Notification,” Marriott International, [Online]. Available: https://web.archive.org/web/20200401163431/https://mysupport.marriott.com/

[47] “FTC takes action against Marriott, Starwood over multiple data breaches,” Federal Trade Commission, Oct. 2024. [Online]. Available: https://www.ftc.gov/news-events/news/press-releases/2024/10/ftc-takes-action-against-marriott-starwood-over-multiple-data-breaches

[48] “CAM4 responds to allegations of security breach,” CAM4, [Online]. Available: https://www.cam4.com/blog-uk/cam4-responds-to-allegations-of-security-breach/

[49] A. Bizga, “CAM4 data leak exposes personal data of millions of users,” Security Boulevard, May 2020. [Online]. Available: https://securityboulevard.com/2020/05/cam4-data-leak-exposes-personal-data-of-millions-of-users/

[50] A. M. Pitney, S. Penrod, M. Foraker, and S. Bhunia, “A systematic review of 2021 Microsoft Exchange data breach exploiting multiple vulnerabilities,” 2022 7th International Conference on Smart and Sustainable Technologies (SpliTech), Split / Bol, Croatia, 2022, pp. 1-6, https://doi.org/10.23919/SpliTech55088.2022.9854268

[51] “Active exploitation of Microsoft Exchange zero-day vulnerabilities,” Volexity, Mar. 2, 2021. [Online]. Available: https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/

[52] MSRC Team, “Multiple security updates released for Exchange Server,” Microsoft Security Response Center, Mar. 2021. [Online]. Available: https://msrc.microsoft.com/blog/2021/03/multiple-security-updates-released-for-exchange-server/

[53] 微博安全中心 (Weibo Security Center), “有关“微博用户信息被出售事件”的说明,” Weibo, [Online]. Available: https://weibo.com/2735327001/IzCMJioqC?from=page_1006062735327001_profile&wvr=6&mod=weibotime&type=comment

[54] “2024 Data Breach Investigations Report,” Verizon, 2024. [Online]. Available: https://www.verizon.com/business/resources/reports/dbir/?CMP=OOH_SMB_OTH_22222_MC_20200501_NA_NM20200079_00001

 

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

What is a phishing domain? Risks, signs, and how to protect against it

Phishing domain: Risks, signs, and protection

Cybercriminals are getting smarter, and so are their traps. One of the most deceptive tactics on the rise is phishing domains. While built to look legitimate, their core goals are to hijack sensitive data, deliver malware, or impersonate trusted brands.

Now that phishing attacks have become more sophisticated, it’s harder (while being even more important) to learn how to identify phishing domains and prevent these attacks at both individual and business levels.

In this article, we’ll break down how phishing domains work, what risks they pose, and what you can do to protect yourself against them.

What is a phishing domain?

A phishing domain is a fraudulent web address designed to look like a legitimate website. Its main goal is to trick online users into revealing sensitive information. Think of passwords, credit card numbers, address details, or login credentials. Such domains often impersonate well-known brands or trusted services and are key to many cyberattacks. In fact, some phishing domains look incredibly realistic, making them difficult to recognize even for experienced users.

A phishing attack often starts with a simple link, delivered via email, text message, or online ad. The user clicks, landing on a site that looks perfectly legitimate. But behind the familiar branding and layout, a phishing domain is at work — using social engineering tricks to convince users to enter sensitive information like login credentials to bank accounts, credit card numbers, or personal details.

By the time the deception is noticed, the data is usually in the wrong hands.

How does a phishing domain work?

Phishing domains are carefully crafted to look like legitimate websites — from the URL to the layout, branding, and even small details like SSL certificates. These fraudulent domains often use the “HTTPS” prefix to appear secure, even though they may lack true security. The goal is to trick users into believing they’ve landed on a trusted page, prompting them to take actions that compromise their security.

Cybercriminals typically distribute these fake domains through phishing emails, malicious ads, and scams on Telegram or other social media platforms. Once a user clicks on the link, they’re directed to the malicious site.

Once on the site, users are often presented with a legitimate-looking login page or form. They may be asked to enter sensitive information such as email credentials, credit card details, Social Security numbers, or company logins. These pages use psychological tactics like urgency, fear, and pressure to convince users to act quickly without thinking. For example, a message may warn that an account is about to be locked, urging the user to provide sensitive data immediately. In some cases, simply interacting with the site may trigger malware downloads or spyware installations.

Phishing domains vs. spoofed domains

A phishing domain is a real domain name registered by attackers to closely imitate a legitimate one, for example, secure-login.yourbank-update.com instead of yourbank.com. These domains are often realistic enough to bypass casual inspection or even basic phishing domain checks, making them especially dangerous. Many phishing domains also use “HTTPS” to seem secure, exploiting users’ trust in the padlock symbol and the SSL certificate.

A spoofed domain, in contrast, is commonly used in email address spoofing attacks. The attacker doesn’t register a fake domain but instead forges the sender’s address in the email header, making it appear as if the message is from a trusted source (such as support@yourbank.com). The email itself might still link to a phishing domain, but the spoofed address adds an extra layer of deception, increasing the chances of the user clicking the link.

While both phishing and spoofed domains aim to deceive users and harvest data, phishing domains are generally more dangerous in the long term. Unlike spoofed domains, phishing domains are harder to detect with basic tools and can slip past standard filters, especially if they use HTTPS, display realistic branding, or mimic common URL structures. However, modern email security tools, such as DMARC, SPF, and DKIM for spoofing, along with domain reputation services for phishing, are improving and can help mitigate the risks, though not perfectly.

Recognizing these distinctions — and understanding the psychological tactics and the steps users take after a click — is key to building better phishing awareness and stronger domain security strategies.

Who is mostly targeted by phishing domains?

Phishing domains are used within phishing campaigns to target users, such as employees and customers, in industries that handle sensitive data. According to Statista, in Q3 of 2024, 30.5% of global phishing attacks targeted social media platforms. Web-based software services and webmail followed, accounting for 21.2% of phishing incidents. Additionally, companies in the finance sector reportedly experienced around 13% of phishing attempts.

Other significantly impacted industries include e-commerce, retail, and telecommunications, again proving how important real-time protection against phishing is. Sensitive data, such as financial information and personal documents, is at high risk, making timely action essential for safeguarding against these attacks.

Risks associated with phishing domains

Phishing domains cause serious risks to online security, including various types of data breaches, financial losses, identity theft, and disruptions in operations. Such malicious domains often fool even the most cautious and vigilant users and sneak past basic security controls.

The following are the most common risks associated with phishing domains:

  • Data breaches. Fake domains trick users into entering sensitive personal information — customer records, login credentials, address details, and different internal files — all of which can later be used to carry out a large-scale data breach.
  • Financial losses. Attackers impersonating trusted partners or vendors can trick businesses into making fraudulent payments, approving fake invoices, or sharing credit card details.
  • Reputational damage. When phishing domains closely resemble reputable organizations and target their customers or partners, the damage to trust and credibility can be nearly impossible to undo, especially if news spreads publicly.
  • Credential theft. Phishing websites often mirror login portals to collect usernames, passwords, and even two-factor authentication codes, giving attackers access to company systems. This theft can lead to account takeovers and even identity theft, making it essential to implement account takeover prevention strategies to protect business accounts and sensitive data.
  • Malware infections. Some phishing domains are weaponized with malware — ransomware, spyware, keyloggers — that gets installed on a user’s device once they interact with the site.
  • Operational disruption. A successful phishing attack can shut down systems, interrupt workflows, and force emergency responses from IT and security teams, leading to costly delays and significant losses in both time and productivity.
  • Legal consequences. Businesses targeted or compromised by phishing domains may face fines, lawsuits, or regulatory penalties due to violations of data protection laws and compliance requirements.

Each of these risks underscores why phishing domain detection, domain monitoring, and employee training should be non-negotiable elements of a strong security strategy. Learning how to recognize potential phishing threats is the next natural step.

 

How do you identify phishing domains?

You can recognize phishing domains by subtle signs in the URL, site design, or behavior. The key is to know what to look for.

Known phishing domains often have the following attributes.

  • Suspicious URLs. The domain name may look odd or overly complex.

Example: secure-login.yourbank-update.com instead of yourbank.com.

  • No HTTPS encryption. A secure site should use HTTPS and display a valid certificate. If your browser warns that the connection isn’t private or secure, it may indicate a malicious or spoofed site — though note that even phishing sites can have HTTPS.

Example: “Your connection is not private” warning in Chrome when visiting a suspicious site.

  • A legitimate site should always use HTTPS. Insecure HTTP protocols and a lack of encryption are major red flags.

Example: http://yourbank-login.com (missing the secure “https://”).

  • Poor grammar and misspellings. Content featuring mistakes or unusual phrasing often signals a suspicious site.

Example: “Your acccount has been locked. Please update imediately.”

  • Inconsistent branding or design. Look for pixelated logos, inconsistent fonts, and designs that simply don’t feel right.

Example: A fake PayPal site with a weird logo or a different font.

  • Requests to enter sensitive information. Legitimate sites rarely ask for unsolicited requests such as login details, personal data, address details, or card numbers via email or pop-ups.

Example: “Enter your Social Security Number to confirm your identity.”

  • Suspicious links or attachments. Unexpected attachments or links redirecting to external domains are red flags, signaling malicious websites.

Example: A link disguised as company.com actually points to company-security-alert.net.

  • Urgent or threatening language. Cyberattackers often use scare tactics to pressure users into taking action.

Example: “Your account will be suspended in 24 hours — log in now!”

  • Hovering over links before clicking. Simply dragging your mouse over a link (without clicking) lets you preview the full URL, usually shown in your browser’s status bar. If the address looks suspicious or doesn’t match the official domain, it’s a red flag.

Example: A link labeled “yourbank.com” actually shows “login-secure-yourbank.com” in the status bar.

  • Manually verifying the website. Instead of clicking on links from suspicious emails or SMS, open a new browser window and manually type the official domain directly to ensure you’re visiting the legitimate site.

Example: Type “paypal.com” yourself instead of clicking a link that claims to go there.

Tactics used in phishing domains

Over the years, phishing attackers have developed increasingly sophisticated tactics to exploit domain names and steal sensitive data. Among many different ones, these are the most common deceptive techniques to create lookalike or misleading domains:

Domain or session hijacking

Domain hijacking involves taking control of a legitimate domain by exploiting expired registrations or insecure DNS settings. Another phishing tactic is session hijacking, where attackers gain control of an active user session to extract sensitive data.

Typosquatting

Cybercriminals register misspelled or similar domain name versions of popular domains to catch users who make typing errors. These domain names closely replicate legitimate ones, sometimes with only a single character difference.

Example: gooogle.com or netfl1x.com — these are classic similar domain name phishing attempts.

IDN spoofing (Homograph attacks)

Attackers use characters from other languages that resemble Latin letters to trick users into visiting fraudulent sites.

Example: аррӏе.com (Cyrillic characters) vs. apple.com

Subdomain takeover

Phishers can exploit unused or unmonitored subdomains of trusted domains to host malicious content. This vulnerability occurs when an organization owns a subdomain but neglects to properly configure or decommission it.

Example: support.oldportal.company.com used by attackers if the subdomain is improperly configured.

Staying alert to these tactics and conducting regular phishing domain checks can drastically reduce the risk of falling victim. For businesses, integrating domain monitoring tools can help flag suspicious activity before it escalates.

What do you do if you detect phishing attempts?

If you detect a phishing domain, acting quickly is crucial to prevent potential damage from escalating. The quicker you react, the more control you’ll keep and the more resources you’ll save.

Whether you’re an individual or part of a larger organization, quick and informed action can reduce the damage phishing domains cause. Here are the key steps to take:

  • Avoid interacting with suspicious domains. If you come across a site that looks suspicious — especially if it involves unsolicited requests, strange verification methods, or urgent requirements — don’t click any links, enter login credentials, or download attachments. Close the site immediately.
  • Report the phishing domain. Alert the legitimate organization being impersonated. Most brands offer a way to report phishing on their websites or through dedicated email addresses. Early reporting helps limit the spread and alert others.
  • Notify your IT and security teams. If you’re part of a company, inform internal IT or security departments right away. They can block access to the domain across all systems and protect others from interacting with it.
  • Block the domain across your network. Use domain security tools, DNS filters, or firewalls to prevent employees or users from accessing the phishing site on any connected devices.
  • Change affected credentials. If any login details were entered on a phishing domain, change those passwords immediately using a trusted password manager. Avoid reusing the same passwords across accounts.
  • Monitor for unusual activity. Keep a close eye on email, financial, and internal business systems for any signs of unauthorized access or suspicious behavior. Encourage employees to report anything unusual.
  • Inform affected stakeholders. If customers, partners, or employees may have interacted with the phishing domain, notify them promptly and offer clear guidance on the next steps to secure their data and accounts.
  • Audit your systems. Conduct an internal review to understand how the phishing domain was detected, whether any systems were compromised, and what changes are needed in your security protocols to prevent future phishing threats.
  • Report major incidents. If sensitive data was exposed or financial loss occurred, report the attack to law enforcement or your national cybersecurity agency. Formal reporting can support broader protection efforts and legal recourse.

Best practices to prevent and protect against phishing attacks

Preventing and protecting against phishing domains requires a multi-layered approach. By following a few best practices, businesses can significantly reduce their risk of falling victim to these attacks.

Strengthen employee awareness

One of the most effective ways to prevent phishing attacks is by educating your employees. A well-informed workforce is your first line of defense against phishing domains.

  • Teach employees about phishing risks. Hold regular training sessions to help them stay informed and identify phishing emails and fake domains.
  • Encourage cautious behavior. Advise employees to verify website URLs, check for HTTPS encryption, and avoid clicking suspicious links.
  • Run simulated phishing exercises. Conduct internal phishing simulations to help employees practice spotting fake domains and emails in a controlled environment.

Improve security defenses

Investing in strong security measures can prevent phishing domains from affecting your business in the first place.

To provide real-time protection and safeguard your most sensitive data against malicious activities, make sure you:

  • Enable multi-factor authentication (MFA). MFA adds an extra layer of protection by requiring users to provide two or more forms of verification before accessing sensitive accounts.
  • Use strong email filtering. Implement advanced email filters that block phishing emails and malicious links before they reach employees’ inboxes.
  • Employ firewalls and antivirus software. Keep these systems updated to protect your network from malware or unauthorized access via phishing domains.
  • Monitor your domain for impersonations. Regularly monitor for domains attempting to imitate your brand with a threat exposure management platform that detects various forms of cybersquatting.

With these basic measures in place, you can take more control of your security online, even when faced with the latest threats.

Maintain system resilience

Ensuring your systems are resilient against phishing attempts can help your business recover quickly if a phishing attack succeeds.

To do that, ensure you complete a set of essential tips.

  • Update your software regularly. Apply security patches and updates to operating systems and applications to patch vulnerabilities.
  • Ensure regular backups. Back up important data and systems regularly to restore operations quickly if they’re compromised.
  • Use security monitoring tools. Monitor your network and website for abnormal activity, especially from suspicious domains.

Utilize proactive cybersecurity solutions

Proactive solutions can detect and block phishing domains before they can cause damage.

  • Leverage anti-phishing solutions. Use specialized tools that identify phishing domains and automatically block them across your network.
  • Use domain monitoring services. Solutions like NordStellar’s domain monitoring can help detect lookalike domains and prevent phishing attacks before they escalate.
  • Invest in cybersquatting detection. Protect your brand with NordStellar’s cybersquatting detection solution, which flags domains attempting to impersonate your organization. Doing so can help you catch and respond to threats like typosquatting or domain hijacking early.

By implementing these best practices, businesses can significantly enhance their defenses against phishing domains, ensuring both proactive detection and rapid response in the event of an attack.

Discover threats before they impact your business. Contact NordStellar to learn how our solutions can help your organization stay one step ahead of cybersecurity threats.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

Data leak prevention vs. data loss prevention: differences and importance

Data leak prevention vs. data loss prevention: Key differences

“Data leak” and “data loss” may sound like synonyms, but their nature is different. While one typically occurs due to human error, the other may come as a result of a hardware failure or a cyberattack. Consequently, data leaks and data loss have different prevention measures that may prove crucial for many enterprises. In this article, learn the differences between data leak and data loss prevention along with the importance of safeguarding companies against cyber threats.

What is data loss prevention?

Data loss prevention is a term that describes cybersecurity measures used for mitigating risks such as system failure, accidental data deletion, hardware damage, or cyberattacks. These incidents typically cause complete information inaccessibility and permanent data loss along with substantial reputational, financial, and legal consequences.

Data loss scheme

While data loss can be accidental, more often it’s a result of a cyberattack. Malicious actors may use various data breach types (such as malware, social engineering, and other attack vectors) to steal or deny access to sensitive information. Due to such a wide scope of exposure, data loss prevention typically includes tools and procedures designed to limit the company’s cyberattack surface.

Proper data loss prevention requires measures such as thorough data recovery and incident response plans, regular backups, and data encryption. Additional security options such as employee cybersecurity training and blocking of unauthorized devices from accessing the corporate network can also contribute to limiting the risk of data loss.

What is data leak prevention?

Data leak prevention is a cybersecurity term that describes the measures used for safeguarding against risks such as unauthorized data access, internal and external exposure, or transmission of sensitive information (for example, intellectual property or confidential business records). Unlike data loss, data leaks are more likely to be the cause of a human error. However, they can sometimes occur as a result of insider threats or external cyberattacks.

Data leak scheme

Data leak prevention methods usually revolve around compartmentalizing sensitive company data. It can include restricting employee access to certain databases, preventing the use of personal email accounts in the company’s workspace, or blocking unapproved file-sharing services. Data leak prevention methods can also involve constant monitoring of network activities to detect and respond to any unauthorized information transfer attempts.

Key differences between data leak prevention and data loss prevention

The key differences between data leak and data loss prevention lie in the nature of the cyber risks themselves. Since data leaks and data loss differ in their scope, methods, and use cases, the prevention against these threats follows the same criteria. Here are the key differences between data leak prevention and data loss prevention.

Scope and focus

The scope and focus of data leak prevention and data loss prevention differ in significant ways. While both aim to safeguard sensitive information, data loss prevention focuses broadly on external threats by protecting data from being lost, stolen, or misused, whether through accidental or malicious actions. That means preventing unauthorized access, monitoring data flows, and securing data at rest, in motion, and in use. By contrast, data leak prevention narrows its focus to internal systems by identifying and preventing the unintentional or intentional exposure of sensitive data to external entities, such as through unauthorized file sharing, email transmissions, or cloud misuse.

Methods of protection

The methods used in data loss prevention and data leak prevention overlap in some areas but differ in their primary approach. Data loss prevention solutions emphasize comprehensive protection through techniques such as encryption, access controls, and backup strategies. These measures allow system owners to secure sensitive data, limit who can view or edit information, and ensure data can be restored if lost or compromised. Data leak prevention tools, on the other hand, focus more on monitoring and preventing unauthorized data sharing, such as blocking unapproved file transfers, restricting the use of external devices (such as USB drives), and controlling access to cloud applications.

Use cases and implementation

Businesses implement data leak and data loss prevention based on their corporate needs. For example, companies may apply data loss prevention to comply with laws such as HIPPA or the GDPR, secure intellectual property, monitor data at rest, in transit, or in use, and meet audit or reporting requirements. Meanwhile, data leak prevention has a specific focus on insider threat management, addressing risks like employees accidentally or intentionally sharing confidential information via email, cloud services, or file-sharing applications. This can be critical for industries like finance, healthcare, or government, where small leaks can lead to significant reputational damage or data breaches.

Here’s a simplified comparison between the use cases of data leak and data loss prevention:

Aspect

Data loss prevention

Data leak prevention

Primary use case

Regulatory compliance (for example, GDPR, HIPAA).

Insider threat management and external data exposure.

Focus of implementation

Preventing loss of data at rest, in transit, or in use.

Stop unauthorized sharing of data outside the organization.

Example

Using encryption to secure sensitive customer records in databases.

Blocking an employee from emailing trade secrets to a personal account.

Industry applications

Primarily finance, healthcare, legal, and retail.

Primarily technology, government, and law enforcement.

Why are both data loss prevention and data leak prevention important for businesses?

Data loss and data leaks pose significant risks to businesses that can range from financial loss to irreparable reputational damage. Losing critical data — whether through accidental deletion, cyberattacks, or hardware failure — can disrupt operations or expose the company to financial and legal consequences. Meanwhile data leaks can lead to exposure of confidential information, giving competitors a clear advantage. Together, these risks highlight the growing need for businesses to safeguard their sensitive information in every step.

An effective enterprise cybersecurity strategy integrates both data loss and data leak prevention. Implementing data security measures (such as two-factor authentication or role-based access control) while monitoring and blocking unauthorized sharing of information is one of the examples of how businesses can combine data loss and data leak prevention. That way, organizations can protect against malicious attacks and insider threats at the same time also ensuring compliance with regulatory requirements such as the GDPR, HIPAA, and CCPA.

 

How to implement both data loss prevention and data leak prevention

Data loss and data leak prevention requires thorough analysis of data risks and a commitment to invest additional resources into system security. Here’s how to implement the basics of data loss and data leak prevention.

Conduct a data risk assessment

The first step in mitigating any cybersecurity risk is recognizing there is one. That’s why it’s crucial to conduct a proper risk assessment when considering data loss and data leak prevention measures. A thorough vulnerability assessment allows organizations to prioritize security options, prevent data breaches, and avoid financial and reputational damage.

Regular data audits help maintain visibility of sensitive information and address vulnerabilities in storage, access, or usage. In addition, implementing a clear backup and recovery plan can ensure a rapid restoration of critical data in case of loss or cyberattacks, minimizing downtime and operational disruptions.

Implement a layered security approach

A layered security approach strengthens data protection by combining multiple defenses to address different types of threats. The optimal way to apply this approach is by using encryption to secure sensitive data during storage and transmission. Additional security layers should include firewalls (to monitor and control network traffic) and endpoint security tools for threat detection and mitigation of malware, unauthorized activity, or potential data breaches. This multi-layered strategy can reduce vulnerabilities, limit cyber exposure, and ensure a stronger overall security posture for the business.

Monitor and educate employees

Employee cybersecurity training is essential for implementing effective data leak and data loss prevention strategies. Human error is often the weakest link in cybersecurity, making it crucial to train employees to recognize common threats such as phishing attempts and Telegram scams. Additionally, employees should be educated on secure data handling practices and the consequences of failing to comply with data protection policies. By providing clear guidelines and recurring training, staff can be transformed from a potential liability into a vital first line of defense against cyber threats.

How NordStellar’s data breach monitoring strengthens data loss and data leak prevention

NordStellar’s data breach monitoring solution gives companies an upper hand in data loss and data leak prevention. With solutions such as dark web monitoring and account takeover prevention, the platform can help businesses save precious time and act quickly in cases of data and credential leaks. And that’s not all — NordStellar’s external vulnerability scanning helps detect flaws in the internet-facing parts of the network and uncover missing security patches and out-of-date software across all outer-facing assets. It’s an invaluable platform for businesses looking to improve their attack surface management and safeguard against data loss and data leaks.

Mitigate the risks of data loss and data leaks with NordStellar — a next-gen threat exposure management platform. Contact the NordStellar team today to learn more.

About NordStellar
NordStellar is a threat exposure management platform that enables enterprises to detect and respond to network threats before they escalate. As a platform and API provider, NordStellar can provide insight into threat actors’ activities and their handling of compromised data. Designed by Nord Security, the company renowned for its globally acclaimed digital privacy tool NordVPN.

About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.