Threat Intelligence Brief
Curated summary with source attribution
Source: hookphish.com
Threat Risk: Medium
Victim: SplitVPN users
Incident: Unauthorized access and exfiltration of a customer database.
Impact: Exposure of 865k emails, IP addresses, and partial payment data.
Attacker: Unidentified threat actors
Analysis: The breach of SplitVPN leaked approximately 865,000 email addresses along with IP addresses and partial credit card information. This combination of data allows attackers to craft highly convincing phishing lures and potentially conduct identity theft. The absence of a detailed remediation report from the provider increases the long-term risk for affected users.
Recommendations: Change passwords for all accounts that shared credentials with SplitVPN; Enable multi-factor authentication (MFA) across all sensitive platforms; Remain vigilant against targeted phishing emails leveraging leaked personal details
Source: HookPhish
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source