data theft3 articles
Nearly 2,000 Hacked WordPress Sites Are Powering a Surprisingly Sophisticated Criminal Operation
A large-scale cybercrime operation called **StopAndProtect** has compromised nearly 2,000 outdated WordPress websites, using them as infrastructure to distribute malware, issue attacker commands, and store stolen data from victims. The campaign begins with fake ClickFix CAPTCHA prompts that trick users into running malicious PowerShell commands, deploying a toolkit that includes ransomware, a credential stealer, a screen locker, a worm, and a chat utility for communicating with victims. As of late July 2026, over 6,000 unique IP addresses have been compromised, with researchers urging users to be wary of unexpected CAPTCHA prompts that instruct them to run commands outside the browser.
Netflix Lost a $45M Nicolas Cage Film Off Someone's Desk. Now It's Being Sued.
Netflix is being sued after an unencrypted drive containing the unreleased Nicolas Cage film *Fortitude* — which cost $45 million to produce — was stolen from its offices, with the production company alleging Netflix waited up to a week to report the theft and failed to take basic security precautions. The plaintiffs, producer Simon Afram and Op-Fortitude, are seeking at least $112.5 million in damages, claiming Netflix left the unencrypted drive — which Netflix itself allegedly requested be delivered unlocked — unsecured on an office desk. Netflix denies liability, arguing the production company bears responsibility for not encrypting the drive, and accuses the plaintiffs of using the lawsuit to extort money.
A U.S. County Paid $1 Million to a Group That Never Even Locked a Single File
A U.S. government entity, likely Union County, Ohio, paid approximately $1 million in bitcoin to a group called Kairos after hackers stole over 1.6 million files and threatened to publish sensitive records, including data from the prosecutors' office. Unlike typical ransomware attacks, Kairos never encrypted any systems — it relied solely on the threat of leaking stolen data as leverage, reflecting a growing trend where extortion groups skip encryption entirely. After a month-long negotiation, the county paid ten times its opening offer, receiving only an unverifiable "proof of deletion" in return, with blockchain tracing linking the funds to exchanges including Bybit, OKX, and a Russian service.