social engineering11 articles
ClickFix Is Everywhere Now, and It's Not Going Away
ClickFix attacks, which trick users into copying and pasting malicious terminal commands by disguising them within fake CAPTCHA prompts on compromised websites, have rapidly spread from a niche technique to a widespread threat targeting both Windows and Mac users. The method has proven highly effective because it exploits user fatigue with complex online interactions, bypasses traditional security requirements like code-signing certificates, and has been adopted by everyone from opportunistic hackers to state-sponsored groups like Russia's Sandworm. While some defensive tools and user awareness can help mitigate the risk, the technique's simplicity and effectiveness mean it is unlikely to disappear anytime soon.
4.1 Million Patients Hit as AdaptHealth Suffers Cloud Breach
A data breach at US healthcare company AdaptHealth compromised the personal, health, and insurance information of over 4.1 million individuals after a threat actor used social engineering to access cloud-based systems in early June. The attacker exfiltrated names, contact details, and health and insurance information, though Social Security numbers and financial data were reportedly unaffected. A separate breach at clinical genomics company Baylor Genetics, also occurring in June, impacted nearly 2.8 million individuals, with hackers stealing a broader range of data including Social Security numbers and employee financial information.
TerminalFix: The ClickFix Variant That Hands Attackers Your Entire Network
is a new variant of ClickFix malware that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages on compromised websites. The attack uses a multi-stage process involving DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance, ultimately deploying a Python-based reverse-tunnel backdoor that grants attackers persistent access to the victim's internal network. Microsoft warns the technique is particularly dangerous as it can be exploited to escalate privileges, steal data, and deploy ransomware, and recommends restricting PowerShell execution, monitoring for DLL sideloading, and training employees to recognise ClickFix-style attacks.
Apollo Global Hit by Social Engineering Attack Exposing Names, Contacts and SSNs
Apollo Global Management suffered a data breach after a social engineering (vishing) attack allowed threat actors to access its cloud platforms between July 6–10, potentially exposing personal information including names, contact details, and Social Security numbers. The attack is linked to a cybercrime group known as BlackFile (UNC6671), which has been targeting major financial and private equity firms across North America, Australia, and the UK using IT helpdesk-themed phone phishing tactics. While Apollo is the only confirmed victim of a successful data compromise so far, Apollo states there is no evidence the stolen data has been made public or used for fraud, and affected individuals are being offered identity protection services.
Apollo Global Got Social Engineered. SSNs Walked Out the Door.
Apollo Global Management suffered a data breach between July 6–10 after attackers used social engineering tactics to gain unauthorized access to its cloud systems, stealing sensitive personal information including names, Social Security numbers, dates of birth, and home addresses. The breach is consistent with a broader campaign targeting private equity and financial firms, with Google previously warning that an extortion-focused group called UNC6671 was posing as IT staff to harvest employee credentials. Apollo has notified law enforcement, engaged cybersecurity experts, and is offering affected individuals 24 months of credit monitoring, though key details — such as the number of people affected and which cloud platforms were compromised — remain undisclosed.
Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the Door
Levi Strauss & Co disclosed a cyberattack in an SEC filing, revealing that social engineering was used to compromise three employees' company-issued computers, resulting in corporate data being accessed and exfiltrated. The company says it has contained the incident and evicted the attackers, with no customer data or business operations appearing to have been affected. The investigation is ongoing, and unconfirmed reports suggest the hacking group UNC6671, known for voice phishing campaigns, may have been responsible.
Ransomware Crews Have Done Their Homework: It's the IT Manager They Want
Ransomware attackers are increasingly targeting mid-level managers — particularly those in their mid-40s working in finance, HR, sales, or operations — rather than executives, because these employees hold "business privilege" that gives them influence over payment decisions and access to sensitive data. Research by Zscaler tracking 351 victims found that attackers conduct detailed reconnaissance to map organisational structures and identify the people most likely to accelerate a ransom payment. More broadly, the ransomware landscape is intensifying, with blocked attempts up 146%, public extortion cases up 70%, and stolen data volumes up 92% over the past year.
How Complaining About a Doctor Got a Red Teamer Into a Restricted Hospital Records Room
A red teamer named Dahvid Schloss successfully infiltrated a hospital's secure records room using social engineering — by wearing scrubs, carrying a fake badge, and bonding with a nurse over complaints about a real, notoriously difficult doctor. He also discovered serious network security flaws at other hospitals, where medical devices transmitted sensitive patient data, including Social Security numbers, unencrypted over the same Wi-Fi network as guests. The incidents highlight how human trust and poor network segmentation can be just as dangerous as technical vulnerabilities in healthcare settings.
Clover Health Investments Hit by Social Engineering Attack, Patient Data Exposed
Clover Health Investments disclosed a data breach discovered on July 4, resulting from a social engineering attack that compromised three non-managerial employee accounts with access to personal and protected health information. The company activated its response plan, engaged third-party cybersecurity experts, and believes the attackers have been evicted, though the full scope of the breach remains undetermined. No threat actor or ransomware group has claimed responsibility for the incident.
AdaptHealth Blames Social Engineering After Patient Data Walks Out the Door
Medical equipment provider AdaptHealth suffered a cyberattack in which criminals used social engineering to compromise a third-party contractor and gain access to the company's cloud systems. Attackers stole sensitive patient data, including personally identifiable information, protected health information, and a password file linked to insurance billing, though Social Security numbers and payment details are believed to be unaffected. AdaptHealth disclosed the breach to the SEC on June 27, deeming it material due to the potential volume of data at risk, while investigations into the full scope of the incident are ongoing.
Fake IT Support Calls Are How This Gang Walks Into Law Firms and Walks Out With Everything
The Silent Ransom Group (also tracked as UNC3753/Luna Moth) is actively targeting U.S. law firms and professional services organisations using social engineering tactics, including fake IT support phone calls that trick employees into installing remote access tools, enabling data theft within hours. Once inside a network, attackers steal sensitive legal and financial documents before sending highly aggressive ransom demands — sometimes within 30 minutes of exiting the victim's environment — threatening to notify clients and regulators if payment is not made. Cybersecurity firm Mandiant and the FBI recommend organisations counter these attacks by enforcing strict IT verification procedures, limiting remote access tools, implementing multi-factor authentication, and training staff to recognise voice phishing attempts.