Jingle Thief: Inside a Cloud-Based Gift Card Fraud Campaign
We investigated a campaign waged by financially motivated threat actors operating out of Morocco. We refer to this campaign as Jingle Thief, due to the attackers’ modus operandi of conducting gift card fraud during festive seasons. Jingle Thief attackers use phishing and smishing to steal credentials, to compromise organizations that issue gift cards. Their operations primarily target global enterprises in the retail and consumer services sectors. Once they gain access to an organization, they pursue the type and level of access needed to issue unauthorized gift cards. The activity related to this campaign is tracked by Unit 42 as cluster CL‑CRI‑1032. The threat actors behind the activity target organizations that primarily rely on cloud-based services and infrastructure. They then exploit Microsoft 365 capabilities to conduct reconnaissance, maintain long-term persistence and execute large-scale gift card fraud. We assess with moderate confidence that the activity cluster we track as CL-CRI-1032 overlaps with the activity of threat actors publicly tracked as Atlas Lion and STORM-0539 [PDF].
CISA’s international, industry and academic partnerships slashed
The Trump administration has effectively closed the division of the Cybersecurity and Infrastructure Security Agency that coordinates critical infrastructure cybersecurity improvements with states and local governments, private businesses and foreign countries. Sweeping layoffs in mid-October eliminated almost all 95 employees in CISA’s Stakeholder Engagement Division (SED), four people familiar with the matter told Cybersecurity Dive. After the cuts take effect in early December, they will leave three of the division’s four units without any staff: Council Management, which convenes meetings between government agencies and the operators of U.S. critical infrastructure; Strategic Relations, which partners with and supports small businesses, academic institutions, nonprofit groups and state and local governments; and International Affairs, which coordinates meetings and information sharing with other countries and helps train their cyber experts.
US accuses former L3Harris cyber boss of stealing and selling secrets to Russian buyer
The U.S. government has accused a former executive at defense contractor L3Harris of stealing trade secrets and selling them to a buyer in Russia, according to court documents seen by TechCrunch. On October 14, the Department of Justice accused Peter Williams of stealing eight trade secrets from two unnamed companies. The DOJ made the allegation in a “criminal information” document, which, like an indictment, represents a formal accusation of alleged crimes. The document does not specify Williams’ relationship with the two companies or the types of trade secrets, nor does it name the alleged Russian buyer.
Medusa Ransomware Leaks 834 GB of Comcast Data After $1.2M Demand
The Medusa ransomware group has leaked 186.36 GB of compressed data it claimed to have stolen from Comcast Corporation, a global media and technology company. According to Hackread.com’s earlier report, the group stated that it breached Comcast in late September 2025 and obtained a total of 834 GB of data. The leaked 186 GB archive, once decompressed, should amount to around 834 GB of data, based on the group’s claims. The data trove was released on Sunday, October 19. The ransomware group had initially asked for $1.2 million from potential buyers to download it, the same amount it asked Comcast to pay for the data to be deleted instead of leaked or sold.
Fake LastPass death claims used to breach password vaults
LastPass is warning customers of a phishing campaign sending emails with an access request to the password vault as part of a legacy inheritance process. The activity started in mid-October, and the domains and infrastructure used point to a financially motivated threat group called CryptoChameleon (UNC5356). CryptoChamemelon employs a phishing kit specializing in cryptocurrency theft, targeting multiple wallets including Binance, Coinbase, Kraken, and Gemini, using fake Okta, Gmail, iCloud, and Outlook sign-in pages.