惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
Jina AI
Jina AI
量子位
博客园 - 叶小钗
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园 - 聂微东
美团技术团队
Last Week in AI
Last Week in AI
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园_首页
V
Visual Studio Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog

Troy Hunt's Blog

Weekly Update 521: Breach Perception v. Reality Weekly Update 520: The Unscripted Edition Weekly Update 519: Breaches & Data Integrity A Cautionary Tale About Data Breach Claims, Verification and Carhartt Weekly Update 518: IoT Doorlock Nirvana with UniFi Welcoming the Sri Lankan Government to Have I Been Pwned Weekly Update 517: Cyber Ransoms Weekly Update 516: Live From Vietnam Welcoming the Nepalese Government to Have I Been Pwned Weekly Update 515 Weekly Update 514: This Week in Data Breaches Weekly Update 513: Clauding The Home Network Weekly Update 512: IoT Lockout Fail Weekly Update 511: Live from my Riad in Marrakech Swimming Pools, Pee, and Trying to Delete Your Data From the Internet Weekly Update 510: Live From Mallorca with Scott Helme Weekly Update 509 Weekly Update 508 Weekly Update 507 Welcoming the Philippine Government to Have I Been Pwned 1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever Weekly Update 506 Welcoming the Bhutanese Government to Have I Been Pwned Weekly Update 505 Weekly Update 504 Welcoming the Bahamian Government to Have I Been Pwned Welcoming the Bangladesh Government to Have I Been Pwned Welcoming the Costa Rican Government to Have I Been Pwned Weekly Update 503 Weekly Update 501
Weekly Update 502
Troy Hunt · 2026-05-06 · via Troy Hunt's Blog

It's a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will be teenagers to their early 20s), consistently gaining access to the data of massive brands. Not through technical ingenuity alone (although I'm sure there's a portion of that), but primarily through good ol' social engineering. That's coming through in the disclosure notices from the impacted companies, and Mandiant has a good write-up of it too:

These operations primarily leverage sophisticated voice phishing (vishing) and victim-branded credential harvesting sites to gain initial access to corporate environments by obtaining single sign-on (SSO) credentials and multi-factor authentication (MFA) codes

Question now is how long their run will go for. There's a very predictable ending if things keep going in this direction but right now, they show little sign of abating.

Listen on Apple Podcasts

Watch and Listen on YouTube

Download via RSS

Weekly update