惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
IT之家
IT之家
博客园_首页
博客园 - 【当耐特】
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
G
Google Developers Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
GbyAI
GbyAI
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Help Net Security
T
Tailwind CSS Blog
B
Blog RSS Feed
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
博客园 - 叶小钗
雷峰网
雷峰网
量子位

The Register - Security

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw
Adaptavist Group breach spawns imposter emails as ransomw...
Carly Page · 2026-04-21 · via The Register - Security

UK enterprise software consultancy The Adaptavist Group is investigating a security breach after an intruder logged in with stolen credentials, while a ransomware crew claims it grabbed far more than the company is currently admitting.

In a letter to customers, Adaptavist's CEO Simon Haighton-Williams said the biz detected an "IT security incident" in late March after an attacker used compromised login details to gain unauthorized access to some of its systems. The company, which builds and sells tools and services around platforms like Atlassian's Jira and Confluence, has brought in external security specialists and says a forensic investigation is underway to work out what, if anything, was accessed or taken.

The official line, for now at least, is that the systems accessed contained "typical business data," such as contact information, contracts, and NDAs related to client work. 

"Please be assured that the data we hold relating to individual customer contacts is that which you would expect to find on a business card: name, business email address, job role, contact number, organization, etc," the post stresses.

Meanwhile, a ransomware group calling itself "The Gentlemen" has claimed responsibility in a post on its dark web leak site, boasting of a "complete infrastructure compromise" and a sprawling cache of stolen data. According to Trend Micro, the group is a relative newcomer to the ransomware game with a fairly standard routine: get in using valid access, move quietly, lift data, and then use that data as leverage.

The dark web post, seen by The Register, claims a haul that includes hundreds of thousands of alleged customer records, source code for products like ScriptRunner, internal documents, credentials, and production systems – along with some eyebrow-raising references to external customer environments.

As ever, those claims come with a health warning. Ransomware crews have a habit of overstating their access to increase pressure on their victims, and Adaptavist Group is keen to stress that there is "no evidence" that data relating to customers was accessed.

"Despite claims to the contrary which have been made by an unknown third-party, there is no evidence at this time that any other personal data relating to customers or partners was accessed, exfiltrated or otherwise compromised in this incident which may cause any risk to the individuals involved," Williams wrote. 

"Whilst I realize that incidents are never welcome and it's never pleasant to receive news of them, I would like to reassure you that there is no sign of, nor reason to believe that there was any access to client systems, data that we process on behalf of clients, or our production systems."

Adaptive Group has warned, however, that an unknown third party has been sending "misleading correspondence" to customers and partners while impersonating the company in relation to the incident, suggesting someone is already trying to turn the situation into a phishing opportunity. ®