{"id":5809,"date":"2025-12-30T01:13:52","date_gmt":"2025-12-29T20:13:52","guid":{"rendered":"https:\/\/paknews.centers.pk\/the-worst-hacks-of-2025\/"},"modified":"2025-12-30T01:13:52","modified_gmt":"2025-12-29T20:13:52","slug":"the-worst-hacks-of-2025","status":"publish","type":"post","link":"https:\/\/paknews.centers.pk\/ur\/the-worst-hacks-of-2025\/","title":{"rendered":"The Worst Hacks of 2025"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p><span class=\"lead-in-text-callout\">It was a<\/span> strange year in cyberspace, as US president Donald Trump and his administration launched foreign policy initiatives and massive changes to the federal government that have had significant geopolitical ramifications. Through it all, the steady drumbeat kept pounding of data breaches, leaks, ransomware attacks, digital extortion cases, and state-sponsored attacks that have unfortunately become a backdrop of daily life.<\/p>\n<p class=\"paywall\">Here&#8217;s WIRED&#8217;s look back on this year&#8217;s most significant breaches, hacking sprees, and digital attacks. Stay alert, and stay safe out there.<\/p>\n<h2 class=\"paywall\">Salesforce Integrations<\/h2>\n<p class=\"paywall\">Attackers grabbed data from the sales management giant Salesforce in at least two breaches this year\u2014but they didn&#8217;t compromise Salesforce directly. Instead, the group breached third-party Salesforce contractor integrations, including those of <a data-offer-url=\"https:\/\/www.gainsight.com\/blog\/supporting-our-customers-and-community-an-update-on-the-recent-security-advisory-related-to-gainsight\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.gainsight.com\/blog\/supporting-our-customers-and-community-an-update-on-the-recent-security-advisory-related-to-gainsight\/&quot;}\" href=\"https:\/\/www.gainsight.com\/blog\/supporting-our-customers-and-community-an-update-on-the-recent-security-advisory-related-to-gainsight\/\" rel=\"nofollow noopener\" target=\"_blank\">Gainsight<\/a> and <a data-offer-url=\"https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification&quot;}\" href=\"https:\/\/trust.salesloft.com\/?uid=Drift%2FSalesforce+Security+Notification\" rel=\"nofollow noopener\" target=\"_blank\">Salesloft<\/a>.<\/p>\n<p class=\"paywall\">Google&#8217;s Threat Intelligence Group <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/data-theft-salesforce-instances-via-salesloft-drift\" target=\"_blank\" rel=\"noopener\">published<\/a> about the spree in August, saying that some Google Workspace data had been compromised as part of the breach of the sales and marketing platform Salesloft Drift. Though the incident was not a direct hack of Google Workspace, it represented a rare instance in recent years of Alphabet customer data being exposed.<\/p>\n<p class=\"paywall\">Other impacted companies include Cloudflare, Docusign, Verizon, Workday, Cisco, LinkedIn, Bugcrowd, Proofpoint, GitLab, SonicWall, Adidas, Louis Vuitton, and Chanel. The credit bureau <a data-offer-url=\"https:\/\/www.cnet.com\/tech\/services-and-software\/more-than-4-4-million-exposed-in-credit-bureau-transunion-breach\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.cnet.com\/tech\/services-and-software\/more-than-4-4-million-exposed-in-credit-bureau-transunion-breach\/&quot;}\" href=\"https:\/\/www.cnet.com\/tech\/services-and-software\/more-than-4-4-million-exposed-in-credit-bureau-transunion-breach\/\" rel=\"nofollow noopener\" target=\"_blank\">TransUnion also had a breach<\/a> apparently tied to the situation that exposed the information of 4.4 million people, including names and Social Security numbers.<\/p>\n<p class=\"paywall\">The spree was perpetrated by a group known as Scattered Lapsus$ Hunters\u2014a potential amalgam of actors and tooling from the hacking and data theft groups Scattered Spider, Lapsus$, and ShinyHunters. Researchers <a data-offer-url=\"https:\/\/levelblue.com\/blogs\/spiderlabs-blog\/scattered-lapsuss-hunters-anatomy-of-a-federated-cybercriminal-brand\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/levelblue.com\/blogs\/spiderlabs-blog\/scattered-lapsuss-hunters-anatomy-of-a-federated-cybercriminal-brand&quot;}\" href=\"https:\/\/levelblue.com\/blogs\/spiderlabs-blog\/scattered-lapsuss-hunters-anatomy-of-a-federated-cybercriminal-brand\" rel=\"nofollow noopener\" target=\"_blank\">note<\/a>, though, that the group isn&#8217;t actually a one-to-one evolution of the three namesakes. Regardless, Scattered Lapsus$ Hunters have a <a data-offer-url=\"https:\/\/techcrunch.com\/2025\/10\/03\/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/techcrunch.com\/2025\/10\/03\/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases\/&quot;}\" href=\"https:\/\/techcrunch.com\/2025\/10\/03\/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases\/\" rel=\"nofollow noopener\" target=\"_blank\">data leak site<\/a> where they&#8217;ve been previewing troves of stolen data from the campaign and conducting digital extortion attacks on victims.<\/p>\n<h2 class=\"paywall\">Clop\u2019s Oracle E-Business Hacking Spree<\/h2>\n<p class=\"paywall\">The ransomware group Clop is known for carrying out mass exploitation of vulnerabilities for data breaches and extortion attacks. <a href=\"https:\/\/www.wired.com\/story\/clop-moveit-hack-us-agencies-data-theft\/\" target=\"_blank\" rel=\"noopener\">Past rampages<\/a> in recent years had <a href=\"https:\/\/www.wired.com\/story\/moveit-breach-victims\/\" target=\"_blank\" rel=\"noopener\">huge numbers of victims<\/a> at both private companies and government agencies. This year, the group did it again, exploiting a vulnerability in Oracle\u2019s E-Business internal management platform to steal data from <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/oracle-ebusiness-suite-zero-day-exploitation\" target=\"_blank\" rel=\"noopener\">numerous companies and organizations<\/a>.<\/p>\n<p class=\"paywall\">As part of the spree, Clop was able to steal employee data from multiple companies, including the personal information of executives, and used it to send emails and other threatening communications to senior employees as part of demands for millions of dollars in ransom to delete the data instead of publishing it.<\/p>\n<p class=\"paywall\">Oracle scrambled to <a data-offer-url=\"https:\/\/blogs.oracle.com\/security\/apply-july-2025-cpu\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blogs.oracle.com\/security\/apply-july-2025-cpu&quot;}\" href=\"https:\/\/blogs.oracle.com\/security\/apply-july-2025-cpu\" rel=\"nofollow noopener\" target=\"_blank\">patch<\/a> the vulnerability at the beginning of October, but Clop had already been exploiting it to steal data from hospitals and health care groups, media companies like <a data-offer-url=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/12a31419-4ed0-41ba-a045-2593908ba368.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/12a31419-4ed0-41ba-a045-2593908ba368.html&quot;}\" href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/12a31419-4ed0-41ba-a045-2593908ba368.html\" rel=\"nofollow noopener\" target=\"_blank\">The Washington Post<\/a>, and universities like the University of Pennsylvania (see below).<\/p>\n<h2 class=\"paywall\">University Breaches<\/h2>\n<p class=\"paywall\">The University of Pennsylvania <a href=\"https:\/\/university-communications.upenn.edu\/data-incident\" target=\"_blank\" rel=\"noopener\">publicly disclosed<\/a> a data breach at the beginning of November that <a data-offer-url=\"https:\/\/www.thedp.com\/article\/2025\/10\/penn-gse-emails-we-got-hacked-subject-security-breach\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.thedp.com\/article\/2025\/10\/penn-gse-emails-we-got-hacked-subject-security-breach&quot;}\" href=\"https:\/\/www.thedp.com\/article\/2025\/10\/penn-gse-emails-we-got-hacked-subject-security-breach\" rel=\"nofollow noopener\" target=\"_blank\">took place<\/a> at the end of October, impacting personal data\u2014some of it years or decades old\u2014of students, alumni, and donors. The data also included internal university documents and some financial information. The incident was the result of a phishing attack; the hacker sent email blasts to students and alumni describing Penn as \u201cwoke\u201d and saying that the school prioritizes \u201clegacies, donors and unqualified affirmative action admits.\u201d The Verge <a data-offer-url=\"https:\/\/www.theverge.com\/policy\/812700\/university-pennsylvania-hack-data-sale-dei\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.theverge.com\/policy\/812700\/university-pennsylvania-hack-data-sale-dei&quot;}\" href=\"https:\/\/www.theverge.com\/policy\/812700\/university-pennsylvania-hack-data-sale-dei\" rel=\"nofollow noopener\" target=\"_blank\">reported<\/a>, though, that ultimately the hacker may have been financially motivated.<\/p>\n<p class=\"paywall\">Harvard <a href=\"https:\/\/www.huit.harvard.edu\/cyberincident\" target=\"_blank\" rel=\"noopener\">said<\/a> in a November statement that the systems of its Alumni Affairs and Development office had been breached via a \u201cphone-based phishing attack.\u201d The incident involved personal information of alumni, their partners, Harvard donors, parents of current and former students, some current students, and some faculty and staff. The data included email addresses, phone numbers, physical addresses, event attendance records, information about donations to the university and other fundraising details. <a href=\"https:\/\/paw.princeton.edu\/article\/princeton-database-breached-targeted-phishing-incident\" target=\"_blank\" rel=\"noopener\">Princeton University<\/a> was hit with a similar attack that same month, although the scope of affected data seems more limited.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.wired.com\/story\/worst-hacks-of-2025\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>It was a strange year in cyberspace, as US president Donald Trump and his administration launched foreign policy initiatives and massive changes to the federal government that have had significant geopolitical ramifications. Through it all, the steady drumbeat kept pounding of data breaches, leaks, ransomware attacks, digital extortion cases, and state-sponsored attacks that have unfortunately [&hellip;]<\/p>","protected":false},"author":1,"featured_media":5810,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36],"tags":[],"class_list":["post-5809","post","type-post","status-publish","format-standard","has-post-thumbnail","category-tech"],"_links":{"self":[{"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/posts\/5809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/comments?post=5809"}],"version-history":[{"count":0,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/posts\/5809\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/media\/5810"}],"wp:attachment":[{"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/media?parent=5809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/categories?post=5809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/paknews.centers.pk\/ur\/wp-json\/wp\/v2\/tags?post=5809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}