home.social

#unc6040 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #unc6040, aggregated by home.social.

  1. #Salesforce says it won’t pay #extortion demand in 1 billion records #breach

    The threat group behind the campaign is calling itself #ScatteredLAPSUS$ Hunters, a mashup of three prolific data-extortion actors: #ScatteredSpider , #LAPSuS$ , and #ShinyHunters. #Mandiant, meanwhile, tracks the group as #UNC6040, because the researchers so far have been unable to positively identify the connections.
    #privacy #security

    arstechnica.com/security/2025/

  2. So many news reports have repeated the BBC's mistaken estimate about the number of customers affected by the Kering data breaches. So...

    No, folks, it's not 7.4 million affected or fewer. It's a lot more because the BBC's estimate was based on just the second and smaller breach (Balenciaga, Brioni, and Alexander McQueen), and not the Gucci data which allegedly has more than 43 million records. Even assuming repeat customers are in there, there are likely a lot of unique customers in the Gucci data.

    If we use the same percent based on 7.4 million out of almost 13 million recordsin the second data set, then that would yield 24-25 million unique email addresses for the Gucci data set, for an estimated total of more than 31 million customers all told.

    I didn't estimate the number of unique customers in my reporting because it's too sloppy. But it's highly unlikely to be 7.4 million or fewer as BBC reported.

    #Kering #Gucci #Balenciaga #Brioni #AlexanderMcQueen #databreach #Salesforce #ShinyHunters #UNC6040 #incidentresponse #transparency

    My reports:
    databreaches.net/2025/09/11/ex

    databreaches.net/2025/09/15/up

    @euroinfosec @zackwhittaker

  3. Last week, I broke the story about Gucci and other Kering brands being hacked by ShinyHunters as part of the Salesforce campaign. In my reporting, I included chat logs and other exclusive details. You can read my original reporting here: databreaches.net/2025/09/11/ex

    There is now an update that refutes Kering's reported claim today that they didn't have any conversations with the hackers. I also highlight their failures to be more transparent about the incidents:
    databreaches.net/2025/09/15/up

    #databreach #Salesforce #ShinyHunters #Gucci #Brioni #Balenciaga #KERING #AlexanderMcQueen #UNC6040