Visualização normal
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 1, September 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026 ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 4, August 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026 Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
Ransom & Dark Web Issues Week 4, August 2026
-
ASEC BLOG
-
Security Issues in the Korean & Global Financial Sector in July 2026
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
Security Issues in the Korean & Global Financial Sector in July 2026
-
Malwarebytes
-
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.
Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.
Meta said it disagreed with the ruling and planned to appeal.
“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”
But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:
- Develop an under-13 prediction model within two years.
- Seek proof of age from users it estimates are under 13.
- Treat uncertain accounts as belonging to minors until their age is verified.
- Delete personal data collected from under-13 users.
The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.
This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.
From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts.
How to keep your children safe
In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).
Some tips for parents:
- Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
- Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
- Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
- Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
- Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
- Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.
The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
-
Malwarebytes
-
Sexual predators targeting online accounts for intimate images, FBI warns
The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII). The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.
Sexual predators targeting online accounts for intimate images, FBI warns
The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII).
The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.
According to the FBI, criminals use a mix of account takeover and social engineering tactics:
- Password and PIN guessing: Criminals make high-volume login attempts using data from breaches, public social media profiles, leak sites, and other publicly available sources. Known victims may be targeted using name variations, birth dates, and other predictable personal details.
- Fake customer service texts: Victims receive a message claiming their social media account will be locked or disabled. The criminal triggers a legitimate password reset request, then persuades the victim to hand over the resulting verification code.
- Phishing emails: Lookalike support domains and email addresses warn of a “new login” and direct victims to a fake password change page designed to steal credentials.
This is different from the familiar “I recorded you” sextortion email, which typically relies on intimidation rather than a real account compromise. Still, if such an email includes a password you still use, change it immediately wherever it remains in use.
How to stay safe
There are several ways to reduce the risk of becoming a victim:
- Avoid storing sensitive images on social media platforms or other internet-connected services when possible. Breaches and leaks happen, and those images can end up in the wrong hands.
- Use a password manager to create a unique, long password for every account. Don’t base passwords or PINs on names, birthdays, or other public information.
- Turn on multi-factor authentication (MFA), preferably with passkeys or hardware security keys where available. MFA is valuable, but criminals can still phish one-time codes and session cookies, so never approve an unexpected prompt or share a verification code.
- Treat unexpected “account warning” links in texts and emails as suspicious. Open the service’s official app or type the known web address yourself instead. Don’t trust sponsored search results to take you to the correct website.
If you discover that intimate content has been stolen or shared, preserve any relevant links and evidence, secure the affected accounts, and report it through the FBI’s NCII reporting portal at ncii.ic3.gov.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
-
ASEC BLOG
-
July 2026 Dark Web Breach Incident Trend Report
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
July 2026 Dark Web Breach Incident Trend Report
-
ASEC BLOG
-
July 2026 Dark Web Threat Actor Trend Report
Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]
July 2026 Dark Web Threat Actor Trend Report
-
Malwarebytes
-
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual
Meta ordered to pay $942 million over harm to children
A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.
Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.
Meta said it disagreed with the ruling and planned to appeal.
“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”
But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:
- Develop an under-13 prediction model within two years.
- Seek proof of age from users it estimates are under 13.
- Treat uncertain accounts as belonging to minors until their age is verified.
- Delete personal data collected from under-13 users.
The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.
This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.
From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts.
How to keep your children safe
In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).
Some tips for parents:
- Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
- Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
- Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
- Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
- Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
- Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.
The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
-
Malwarebytes
-
Californians can tell data brokers to DROP their information
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place. DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry. Data brokers collect and sell extensive personal information, including financial details, onlin
Californians can tell data brokers to DROP their information
California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.
DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.
Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.
DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.
How to use DROP
You’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.
- Go to the DROP portal.
- Use the “Get Started” button on the homepage.
- Accept the terms and conditions presented by the platform by using the “I accept” button.
- You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
- After residency verification, create a deletion request:
- Provide your email address and/or phone number to verify contact details.
- Fill in basic information (name, address, etc.) so brokers can locate your records.
- Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.
Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.
For non-Californians
Some other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.
Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.
For each broker you’ll have to submit individual requests:
- Use their web forms, email addresses, or postal addresses to request:
- Deletion of your data, and
- Opt‑out from sale or sharing of your data.
You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.
It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.
Sounds like a lot of work? Malwarebytes Personal Data Remover can help.
How to reduce future data broker collection
This is probably the only field where “security by obscurity” works.
Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.
A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.
For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.
Your name, address, and phone number may already be for sale.
Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way.
-
ASEC BLOG
-
June 2026 Security Issues in Korean & Global Financial Sector
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
June 2026 Security Issues in Korean & Global Financial Sector
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 3, July 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2026 DragonForce Ransomware Attack on a Saudi Arabian Chemical Manufacturer AiLock Ransomware Attack on Japan’s Largest Taxi and Limousine Operator Cyberattack on Japan’s Largest Frozen Food Company Disrupts the Wider Food Supply Chain
Ransom & Dark Web Issues Week 3, July 2026
-
ASEC BLOG
-
June 2026 Dark Web Breach Incident Trend Report
Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]
June 2026 Dark Web Breach Incident Trend Report
-
ASEC BLOG
-
June 2026 Dark Web Threat Actor Trend Report
Note The June 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—operating on the deep web and dark web. It is noted that the accuracy of some information could not be verified. Major Issues In Malaysia, a series of website defacement and compromise incidents targeting local development agencies and public […]
June 2026 Dark Web Threat Actor Trend Report
-
ASEC BLOG
-
Ransom & Dark Web Issues Week 2, July 2026
ASEC Blog publishes Ransom & Dark Web Issues Week 2, July 2026 Saudi Arabian Medical Records Breach, For Sale on Cybercrime Forum Irish ICT Company Data Leaked, For Sale on Cybercrime Forum LeakNet Breach Targets US Healthcare Insurer, Shared on Cybercrime Forums
Ransom & Dark Web Issues Week 2, July 2026
-
SentinelLabs

-
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in. At Balochistan Police, the compromised assets included servers hosting web a
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
Executive Summary
- SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026.
- All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in.
- At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records.
- A suspected China-nexus actor planted implants in one of the web applications, which serves both police staff and citizens, weaponizing a tool of Pakistan’s police digitalization against its users.
- Pakistani law enforcement organizations attract cyber collection because they hold information on Pakistan’s internal security that regional powers have an incentive to pursue.
- For China, the likely primary concern is the safety of its nationals, the target of repeated deadly attacks Pakistan has failed to prevent, leading Beijing to assess that threat for itself rather than rely on its partner alone.
- For India, the strongest motive is probably its rivalry with Pakistan, with Balochistan Police offering insight into the security posture of a Pakistani province prominent in wider mutual accusations over cross-border support for militancy.
Overview
Suspected China- and India-nexus threat actors carried out intrusions into several Pakistani law enforcement organizations between 2024 and 2026. Our analysis of C2 netflow data revealed that suspected China- and India-nexus threat actors operating PlugX, ShadowPad, Cobalt Strike, and Remcos infrastructure have converged on this victim class.
All of these threat actors were active against Balochistan Police, the principal police force serving the Pakistani province of the same name, at various points between 2024 and 2026. The affected assets spanned network appliances and servers hosting web applications that manage biometric records, hotel and tenant registrations linked to national identity records, criminal case files, and personnel records. A suspected China-nexus threat actor also compromised one of these web applications, deploying custom implants masquerading as a portal update. The application is used by police staff and by citizens interacting with law enforcement through it, and the compromise put both user groups within the threat actor’s reach.
When multiple cyberespionage actors operate against law enforcement institutions of a single state, the convergence itself is a signal of target value. What draws them is a particular kind of institution: one that holds the government’s internal security picture, what it knows about the threats inside its borders, and how it acts against them. Each of the states suspected to be behind the activities covered in this post has its own stake in the threats monitored by Pakistani law enforcement.
Strategic Motives | Distrust and Accusations
The China-nexus activity is most likely motivated primarily by concern for the safety of Chinese nationals. Their presence across Pakistan is substantial, tied in large part to the China-Pakistan Economic Corridor (CPEC), Beijing’s flagship Belt and Road infrastructure program in the country. Chinese nationals have been the target of repeated deadly attacks, some of which were claimed by the Balochistan Liberation Army (BLA), a Baloch separatist group opposed to China’s presence in the Pakistani resource-rich southwest. Notable attacks include the October 2024 Karachi airport attack and the March 2024 suicide bombing in northwestern Pakistan.
The attacks have fueled explicit Chinese dissatisfaction with Pakistani counter-militancy performance. In October 2024, China’s Ambassador to Pakistan publicly called them “unacceptable”, warning that the security situation was the main obstacle to CPEC. The threat to Chinese nationals remains unresolved. As recently as January 2026, China’s Minister of Public Security and Pakistan’s Interior Minister agreed to expand counterterrorism coordination, deepen police training exchanges, and establish a special unit in Islamabad to protect Chinese nationals.
Pakistani law enforcement is a natural collection target for China. The data it holds would let China assess the security environment its nationals face independently, rather than relying on a partner whose protection has repeatedly fallen short.
For the India-nexus activity, which was focused on Balochistan, the strongest motive is probably the adversarial security relationship between India and Pakistan, in which the province is a recurring flashpoint. Pakistan has long accused India of backing the Baloch insurgency, describing the BLA as an “Indian proxy“, a charge it has not publicly substantiated and that India denies. India, in turn, accuses Pakistan of backing the militant groups behind attacks in Indian-administered Kashmir, which Pakistan denies.
The Baloch insurgency is a front in the antagonism between the two states, and Balochistan Police would hold the operational record of how Pakistan manages the province’s security. For India, that material could offer visibility into a conflict at the center of the accusations and counter-accusations between them.
Balochistan Police is the same law enforcement institution the China-nexus actors were active against, approached from the opposite direction. To China, it is the police force of a partner that cannot be trusted to protect Chinese nationals in Balochistan. To India, it is the police force of a rival, with deep insight into the security of a province central to the friction between the two states.
Intrusions Into Pakistani Law Enforcement Organizations
We observed the highest concentration of intrusions at Balochistan Police. They affected network appliances and web servers hosting several of its web applications, one of which, the Complaint Management System (CMS), drew particular attention. The next two sections discuss the impacted assets in greater detail.
We also identified compromised infrastructure associated with several other Pakistani law enforcement organizations:
- the Khyber Pakhtunkhwa Police, the police force of Khyber Pakhtunkhwa province;
- the Islamabad Police, which serves the Islamabad Capital Territory;
- the Punjab Safe Cities Authority (PSCA), an autonomous government body that operates the integrated command, control and communication system for the police in the major cities of Punjab province.

We group the C2 activity we observed against all these targets into four clusters, each associated with a single malware family or tool: PlugX, ShadowPad, Cobalt Strike, and Remcos.
Because we cluster based on tooling, not on actor attribution, the number of threat actors behind each C2 activity cluster differs. We associate the Remcos cluster with a single actor, while the PlugX, ShadowPad, and Cobalt Strike clusters are built on shared or commodity tooling and may each involve more than one operator.
The table below presents the constituent servers of each C2 activity cluster, along with the first and last dates on which any of its servers communicated with Pakistani law enforcement infrastructure. The figure that follows shows how each cluster’s activity was distributed across the targeted organizations over time.
| C2 activity cluster | C2 servers | First seen | Last seen |
| PlugX | 172.111.233[.]36, 172.111.233[.]96, 172.111.233[.]12, 172.111.233[.]105, 172.111.233[.]26, 172.94.9[.]49, 172.94.9[.]43, 172.94.9[.]19, 45.74.6[.]17 | 27 February 2024 | 28 September 2024 |
| ShadowPad | 45.125.32[.]218 | 5 November 2024 | 29 November 2024 |
| Cobalt Strike | 142.171.183[.]8, 193.42.25[.]65 | 12 October 2024 | 5 December 2025 |
| Remcos | 89.31.121[.]220 | 13 January 2026 | 9 April 2026 |

The sections below cover the basis for each cluster’s attribution and its broader victimology. The observation windows we present there are generally wider, spanning all per-cluster victims.
C2 Activity Cluster | PlugX and ShadowPad
PlugX and ShadowPad point to China-nexus cyberespionage groups on the basis of the tooling itself, since both are backdoors shared among multiple such groups. The victimology we observed for PlugX (between 27 February and 28 September 2024) and ShadowPad (between 3 August and 1 December 2024) reinforces this assessment.
Beyond Pakistani law enforcement, victimology for PlugX and ShadowPad includes government, foreign affairs, defense, nongovernmental, and research entities across South, Southeast, Central, and East Asia, the Arabian Peninsula, and Southeast Europe, consistent with China-aligned collection.
C2 Activity Cluster | Remcos
We attribute the Remcos C2 server 89.31.121[.]220 to a suspected India-nexus threat actor, which Recorded Future tracks as TAG-179. Its infrastructure, tooling, and TTPs overlap to varying degrees with those of the threat actors tracked by Kaspersky as Mysterious Elephant and by Qihoo 360 as APT-C-08 (a.k.a. Bitter).
Our data shows that TAG-179 has been intensifying its activities and diversifying its TTPs since early 2025. This trend aligns with the prior research from Kaspersky and Qihoo 360, which documents in detail the tooling and infection chains used across 2025 and 2026.
Notably, Qihoo 360 describes a chain that delivers a Remcos backdoor configured with the same server that constitutes our Remcos C2 activity cluster (89.31.121[.]220). The IOC table of this report lists several lure files and backdoor components that we associate with TAG-179.
Among the lures is one with direct relevance to Pakistani law enforcement: it displays a decoy document posing as an operational plan for the repatriation of illegal foreigners, including Afghan Citizen Card (ACC) holders. These are Afghan nationals who have been granted temporary registration in Pakistan and are targeted for deportation under Pakistan’s Illegal Foreigners’ Repatriation Plan.
The decoy document outlines coordination among district-level police forces, the National Database and Registration Authority (NADRA, an agency of the Pakistani Ministry of Interior), and Pakistani intelligence organizations. Its subject matter is consistent with the Pakistani law enforcement victimology of TAG-179, making it an example of a plausible lure against this target class.

Within our observation window for the Remcos C2 activity (from 20 November 2025 to 21 April 2026), the victimology outside Pakistani law enforcement includes government, defense, foreign affairs, intelligence, research, and manufacturing entities across South and Southeast Asia, and the Middle East.
C2 Activity Cluster | Cobalt Strike
Although Cobalt Strike is a commodity tool that carries no inherent attribution, we attribute with medium confidence both servers in this C2 activity cluster to China-nexus threat actors.
The C2 traffic to 142.171.183[.]8, spanning 13 September 2024 to 5 December 2025, reveals victimology extending beyond Pakistani law enforcement to government, academic, telecommunications, and non-governmental entities across South, East, and Southeast Asia, the Middle East, and South America, in line with a China-aligned targeting profile. Among these entities are Tibetan Buddhist organizations in Taiwan, a long-standing Chinese cyberespionage interest.
For 193.42.25[.]65, we observed C2 communications only with Balochistan Police infrastructure, taking place between 7 November and 5 December 2024. 193.42.25[.]65 also served as next-stage infrastructure for one of two implants deployed on the Balochistan Police CMS web application. We trace these implants to a Chinese-speaking developer through related samples sharing the same development environment, a topic we discuss in greater detail in a later section.
Balochistan Police | Compromised Assets
Across the four C2 activity clusters, C2 communications involving the following Balochistan Police assets took place between 2 June 2024 and 9 April 2026:
- two network appliances;
- web servers hosting several Balochistan Police web applications;
- a Fortinet FortiMail appliance that had served as Balochistan Police’s primary inbound email gateway.
At the time of this activity, the FortiMail appliance was no longer the designated inbound email gateway, but it remained operational on the network and may have continued to process outbound or internal mail relay traffic. Its compromise may therefore have additionally exposed email traffic it processed.
Many of the web applications hosted on the affected servers are part of the Smart Police Station initiative, an EU-supported effort to modernize Balochistan policing and improve how it serves the public through digitalization. Throughout the threat actor activities, the web servers hosted a mix of public-facing applications through which citizens and businesses access policing services, alongside restricted police applications protected by firewalls against unauthorized external access.
The table below summarizes the application functions as described in publicly available documentation.
| Application | Function |
| First Information Report (FIR) | Application for FIR registration and management. FIRs are documents prepared by police upon receiving information about the commission of a cognisable offence. |
| Human Resource Management Information System (HRMIS) | Personnel database managing officer service records, transfers, postings, payroll, and performance evaluations. |
| Anti-Vehicle Lifting System (AVLS) | Database for tracking stolen vehicles, their recovery, and investigation. |
| HotelEye | System for hotel guest check-in logging, integrated with NADRA identity records to notify police when individuals with criminal records check in. |
| Criminal Record Management System (CRMS) | Criminal records database with fingerprint-based biometric matching. |
| Tenant Registration System (TRS) | Landlord-tenant registration platform integrated with criminal records. |
| Complaint Management System (CMS) | Platform for registering, tracking, and resolving citizen complaints, from reports of crime and loss of documents to complaints about police misconduct. |
If the threat actors could reach the data stores backing these applications from the compromised servers, the data they could obtain would span police personnel records, criminal case files, biometric records, stolen vehicle records, hotel guest check-in records, tenant registration records, and citizen complaints. Together, it would provide broad visibility into Balochistan Police’s operational posture, capabilities, and intelligence activities.
Balochistan Police | CMS Compromise
The CMS web application, accessible at cms.balochistanpolice[.]gov[.]pk and hosted on one of the affected Balochistan Police web servers, was also compromised. Based on shared infrastructure and a common focus on Balochistan Police, we associate this intrusion with the threat actor operating 193.42.25[.]65, a constituent of the Cobalt Strike C2 activity cluster.
The landing page at cms.balochistanpolice[.]gov[.]pk features a login interface and a separate search form.

Access behind the login interface is highly likely restricted to law enforcement personnel. Stolen login credentials for the portal, which we retrieved from information stealer logs published on the dark web, reveal a consistent naming convention across the recovered usernames: a ps- prefix (most probably denoting “police station”) followed by a district or city within Balochistan, such as ps-barkhan.
In contrast, the search form, which posts to /Complaint/PublicSearch and accepts a complaint reference number and mobile number, is evidently intended to allow citizens to check the status of a filed complaint.
We therefore assess with high confidence that the CMS application serves two distinct user groups: law enforcement personnel and citizens.
Based on VirusTotal data, two variants of an implant named cms_plugin.exe were uploaded to cms.balochistanpolice[.]gov[.]pk/client%20scripts/ in late 2024, one written in the Rust programming language, the other compiled as a .NET executable. The Rust executable is a malware stager that downloads a payload from 193.42.25[.]65 and executes it. We could not retrieve the next stage at the time of analysis.
The .NET executable masquerades as 360Safe.exe, a component of the endpoint security software 360 Safe Guard from the Chinese vendor Qihoo 360. It reflectively loads an assembly implementing an AsyncRAT client, which is configured to use 41.216.188[.]140 as its C2 server. The assembly has a PDB path of D:\codedome\case\six\Client\Client2\obj\Debug\Client2.pdb.
Pivoting on the D:\codedome prefix, we identified multiple additional samples highly likely built in the same development environment. Several are AsyncRAT clients that share implementation patterns with the one embedded in cms_plugin.exe, such as variable naming and string obfuscation, reinforcing a common origin beyond the shared PDB prefix. Some contain Chinese-language terms in pinyin in their PDB paths, such as xinshi (likely 新式, “new type” or “new variant”), and one includes log messages in simplified Chinese. These indicators point to a Chinese-speaking developer behind the samples linked by the D:\codedome prefix, including the one deployed on the Balochistan Police CMS application.

Pivoting on the cms_plugin.exe filename, we identified a third malware stager functionally similar to the Rust variant, also downloading the next stage from 193.42.25[.]65.
Both cms_plugin.exe samples downloading from 193.42.25[.]65 display the message Update Complete! Please refresh the page upon execution, mimicking an update for the CMS portal.
The fake update prompt, combined with the cms_plugin.exe filename and the hosting location in the portal’s /client scripts/ directory, indicates that the implants were targeted at users of the CMS platform: police staff, citizens checking complaint status, or both. Successful infection would grant the threat actor access to the victim’s device. In the case of police personnel, this could provide a foothold into internal police networks and access to operational data beyond the CMS platform. In the case of citizens, it would enable surveillance of those who have filed complaints through the platform.
Conclusion
The intrusions we cover in this post show how domestic security institutions can become high-value intelligence targets when the threats they monitor overlap with foreign intelligence requirements. Balochistan Police sits at such an intersection, attracting cyberespionage activity from both a partner and an adversary of Pakistan. For China-nexus actors, access to its systems could support independent assessment of threats to Chinese nationals and interests in the country. For India-nexus actors, such access provides visibility into how Pakistan manages security in a province central to its adversarial relationship with India.
The compromise of the Complaint Management System web application adds a second dimension to the activity against Balochistan Police, extending the threat actor’s reach beyond the initially compromised environment. By hosting implants in a portal used by both citizens and law enforcement personnel, the threat actor turned a tool built to make policing in Pakistan more accessible and accountable to the public into a malware delivery mechanism. This weaponization widened the collection surface from the application and its data to the users interacting with it.
The multi-actor convergence on Balochistan Police points to a structural consequence of digital policing. Systems built to centralize records, workflows, and public interaction can also centralize intelligence value by bringing together operational, institutional, and civilian data across connected environments. Law enforcement infrastructure in that setting is no longer just the digital backbone of policing but intelligence terrain, and it will be treated as such by any adversary who can reach it.
Indicators of Compromise
SHA-1 Hashes
| Value | Note |
| 000fad96a85dd6933c22d3dbec9aed47b7f1f066 | Backdoor launcher (TAG-179) |
| 08570471f39bb6725f07b8cddbea99ed48c22686 | Backdoor launcher (TAG-179) |
| 23f4766c011d193f076dfc735dc460e2a41ead79 | Backdoor launcher (TAG-179) |
| 23f6781919a50b118d8d4e6a7e9ae63b71ecc885 | cms_plugin.exe |
| 2bab40c55637398f0497cff9c8cbea564d595c7f | Lure file (TAG-179) |
| 4039454c9189e64285e93fc075a30b93f814b5b5 | cms_plugin.exe |
| 47f8cb0c2dcf62702f58cfc1603d6325755f6820 | Backdoor launcher (TAG-179) |
| 539bd79fbb684edea94eb37518134b97e94b9dd8 | Lure file (TAG-179) |
| 58cb2d95063b9df807b7aa8dc106b74ce988a491 | cms_plugin.exe |
| 5d60ff36ff519c2e13e7f66cfa0bb46be79592a7 | Backdoor (TAG-179) |
| 63b88d00331de88af696dfb7a896935d830e485f | Backdoor (TAG-179) |
| 6fe2e74d009abbd56de01fd7404a1245e9b47c79 | Lure file (TAG-179) |
| 71757adba833b46f961e840d0f055bcce0b529c4 | Lure file (TAG-179) |
| 8c329db96e093fa25268e078405a33c518dbb5c9 | Backdoor (TAG-179) |
| c6c197e61079a0a33108c2c87b5e3c7056a138ec | Lure file (TAG-179) |
| d66ab0cd2e44dc8389c111b7ed34c7bcb0b35311 | Backdoor (TAG-179) |
IP Addresses
| Value | Note |
| 142.171.183[.]8 | Cobalt Strike C2 server |
| 172.111.233[.]105 | PlugX C2 server |
| 172.111.233[.]12 | PlugX C2 server |
| 172.111.233[.]26 | PlugX C2 server |
| 172.111.233[.]36 | PlugX C2 server |
| 172.111.233[.]96 | PlugX C2 server |
| 172.94.9[.]19 | PlugX C2 server |
| 172.94.9[.]43 | PlugX C2 server |
| 172.94.9[.]49 | PlugX C2 server |
| 193.42.25[.]65 | Cobalt Strike C2 server |
| 41.216.188[.]140 | AsyncRAT C2 server |
| 45.125.32[.]218 | ShadowPad C2 server |
| 45.74.6[.]17 | PlugX C2 server |
| 89.31.121[.]220 | Remcos C2 server |
URLs
| Value | Note |
| https[://]cms.balochistanpolice[.]gov[.]pk/client%20scripts/cms_plugin.exe | Implant-hosting URL on the Balochistan Police CMS portal |

-
Unit 42

-
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.
CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure
Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor.
The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

-
ASEC BLOG
-
May 2026 Dark Web Breach Incident Trend Report
Notes the May 2026 Dark Web Breach Incident Trend Report is organized around the major cases of Data Breaches posted on the deep web and dark web forums. due to the nature of the source, some of the information may not be fully verifiable as to whether it is true or not, and is therefore […]
May 2026 Dark Web Breach Incident Trend Report
-
ASEC BLOG
-
May 2026 Dark Web Threat Actor Trend Report
Notes the May 2026 Dark Web Threat Actor Trend Report summarizes the trends of threat actors and hacktivists operating on the deep web and dark web. some statements are not factually verifiable. Major Issues hacktivist activity targeting the South Korean Region was concentrated. some hacktivist groups claimed DDoS attacks against the website of the South […]
May 2026 Dark Web Threat Actor Trend Report
-
Malwarebytes
-
Company bragged phone mics could listen to conversations. They couldn’t.
A media company and two of its marketing partners have been fined for selling a service which, they said, listened in to people’s conversations through their phones. Actually they did nothing of the sort. Most people have worried at some point that their phone has been listening to them through the microphone. You know how it goes: One minute you’re speaking to your friend about how you’ve always wanted to go to Fiji, the next minute you’re seeing social media ads for vacations there. However
Company bragged phone mics could listen to conversations. They couldn’t.
A media company and two of its marketing partners have been fined for selling a service which, they said, listened in to people’s conversations through their phones. Actually they did nothing of the sort.
Most people have worried at some point that their phone has been listening to them through the microphone. You know how it goes: One minute you’re speaking to your friend about how you’ve always wanted to go to Fiji, the next minute you’re seeing social media ads for vacations there. However, as yet there hasn’t been much real proof that this is actually happening.
But that didn’t stop Cox Media Group from claiming it could listen in. Between 2023 and 2024, the company publicly promoted a service called “Active Listening” or “Voice Data,” claiming it used AI-powered voice-processing technology to capture conversations from smartphones, along with smart TVs and other devices with embedded microphones.
The company told potential advertising clients that the system provided a tool to target, retarget, and retain customers.
The scandal came to light when 404 Media published internal pitch decks from Cox that detailed the supposed “Active Listening” capabilities. After the revelations, Cox initially backpedaled and denied listening to conversations, but the marketing materials contradicted these denials.
The FTC found that the “Active Listening” service was completely fabricated. The service did not listen to consumers’ conversations or use voice data at all, nor did it accurately place ads in customers’ desired geographic locations. Instead, Cox and its partners simply resold email lists obtained from other data brokers at a significant markup.
Worst of all, the companies also falsely claimed that consumers had opted into voice data collection when they had not.
The Federal Trade Commission (FTC) fined the companies a total of $930,000 for falsely claiming they could spy on consumers. Cox Media Group must pay $880,000, while MindSift and 1010 Digital Works will each pay $25,000. The settlement funds will be used to provide refunds to Cox Media Group customers who were deceived by these false claims.
How to safekeep your personal data
In this case, the data that was being sold came from data brokers. Keeping your personal data away from them requires a combination of preventive measures and active removal efforts.
- Minimize what you share on social media and elsewhere online. Data brokers use scraping tools to gather information from forum posts and public profiles so avoid sharing sensitive details like your birth date, home address, phone number, and financial information.
- Before signing up for online services, loyalty programs, or apps, carefully read privacy policies to understand how companies will collect, use, and share your data.
- For active data removal, your options depend largely on where you live. It’s often best to leave that work to a specialized service you can trust.
- Disable advertising IDs on your smartphones, tablets, and computers through your device settings where possible.
- Use a VPN to hide your IP address and encrypt your browsing traffic, install ad and tracking blockers, and consider using more privacy-focused browsers.
Still wondering if your phone is listening to you?
We looked into this very topic on our Lock and Code podcast. Listen to it below, or search for it on your favorite podcast player.
Scammers don’t need to hack you. They just need you to click once.
Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.
-
Blog – Cyble

-
Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026
In 2026, opportunistic assaults and isolated breaches will no longer characterize Australia's cyber risk environment. Industrialized data theft, in which stolen data is packaged, repackaged, and marketed on underground marketplaces, is influencing it. Threat actors are already combining Australian data into composite "breach packages," increasing both its commercial worth and its downstream danger, as opposed to single-company breaches occurring in isolation. This trend is also intensifying
Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026
![]()
In 2026, opportunistic assaults and isolated breaches will no longer characterize Australia's cyber risk environment. Industrialized data theft, in which stolen data is packaged, repackaged, and marketed on underground marketplaces, is influencing it.
Threat actors are already combining Australian data into composite "breach packages," increasing both its commercial worth and its downstream danger, as opposed to single-company breaches occurring in isolation. This trend is also intensifying concerns around Australian dark web data, where aggregated breach packages are increasingly traded and monetized.
This move has a direct impact on how exposed enterprises will be in 2026 and is not merely cosmetic; rather, it represents a structural shift in how cybercriminal ecosystems monetize stolen information.
Why are Australian dark web data breaches increasing?
Australian cyber events have sharply increased, according to Cyble cyber threat intelligence monitoring. 71 publicly reported data breaches involving Australian companies were found between January and early October 2025. Compared to the 48 breaches that were reported at the same time in 2024, that is a 48% increase.
The overall trend is even more telling: 71 breaches in 2025 have already surpassed the 66 Australian breaches that were reported in 2024. This suggests that the year is structurally exceeding previous standards rather than just drifting upward. The rapid escalation in both the number and severity of every major data breach Australia has experienced indicates a maturing underground economy centered on stolen information.
Cyble reported 1,684 occurrences of reported data breaches worldwide in 2025, an 18% increase. In light of this, Australia's more rapid growth stands out as being disproportionately severe rather than a component of a global increase.
It is crucial to remember that these numbers only include occurrences that have been reported to the public. Since many breaches never appear on forums or leak sites, the actual exposure baseline is probably much greater. This means the scale of the current Australian data breach landscape may still be underestimated.
Why “Bundled Data” Has Become the New Trade Standard
The packaging of stolen Australian data into bundled datasets is one of the most significant developments in underground markets. Threat actors are progressively combining several datasets into composite offerings rather than selling a single breach per victim organization.
Bundled data is easier to monetize, which provides a straightforward economic explanation for this practice. It enables cybercriminals to:
- Combine data from several organizations to increase resale value
- Attract a larger range of purchasers (ransomware affiliates, fraud groups, and access brokers)
- Cut down on the time spent promoting specific violations
Bundling also indicates maturity in the supply chain for cybercrime from an operational perspective. Data is now curated rather than just stolen.
This implies that an organization's security posture is no longer the only factor influencing exposure. One vendor or partner's data may unintentionally be included in a larger selling bundle with unrelated victims due to a breach. This is one reason why modern dark web data breach operations are becoming more difficult to contain once information is leaked.
Ransomware Groups Are Driving the Acceleration
The prevalence of ransomware-related entities is a significant contributing element to Australia's breach rise.
Ransomware groups were responsible for around half of the 71 breaches that were discovered in 2025. This indicates a change in attribution from around 42% of Australian violations in 2024 to approximately 71% in 2025.
This modification shows how ransomware tactics have evolved. Data theft is becoming more important to groups than encryption. Even if encryption is never used, attackers exfiltrate sensitive data before using it for extortion or resale, rather than depending only on locking measures.
This dual-use approach feeds directly into the bundling ecosystem. Stolen datasets become modular assets that can be repackaged across multiple campaigns, contributing to the growing volume of dark web data breaches impacting Australian organizations.
Supply Chain Attacks Expand the Blast Radius
The increase in supply chain compromise is another significant factor. Attackers are taking advantage of third-party providers' laxer security measures rather than going after companies directly.
This has a domino effect:
- Numerous downstream companies may be exposed by a single hacked vendor
- Unintentionally, data from unrelated victims is combined
- Attack surfaces extend beyond the impacted enterprise's direct control
This is one of the main ways that bundled data sales are made possible. Multi-organization datasets are inevitably created by supply chain breaches, consolidated, and resold.
Sector Exposure: No Industry Left Untouched
Australian breaches in 2025 have impacted a wide range of industries, including:
- Professional services
- Information technology
- Healthcare
- Energy and utilities
- Banking and financial services
- Education
- Construction and real estate
- Telecommunications
- Transportation and hospitality
- Manufacturing
The breadth of targeting highlights a key reality: attackers are no longer selecting industries solely based on prestige or financial value. Instead, any organization with usable data, operational leverage, or weak third-party dependencies becomes a viable target.
Notable Incidents Highlight the Scale of Exposure
Several incidents in 2025 illustrate the depth and variety of compromised data:
- A threat actor operating via a private Telegram channel claimed access to approximately 2TB of sensitive documents allegedly belonging to a major Australian airline
- A telecommunications-related database containing around 236,000 records reportedly included names, emails, passwords, phone numbers, billing details, and payment data
- A SaaS provider offering loan management and digital signing tools reportedly had its source code exposed, including authentication systems, APIs, and administrative modules
- An ICT and telecommunications provider breach allegedly exposed financial records and internal databases, claimed by an extortion group
- In construction, 71GB of engineering and infrastructure files were advertised, including geotechnical reports and safety documentation
- A trading platform breach reportedly exposed 27,000 records containing KYC data, user identities, and transaction histories
- Pension funds were impacted through credential reuse attacks that enabled unauthorized account access and financial losses
- Energy and logistics systems were affected by leaks involving millions of operational files from petroleum distribution and internal logistics networks
Across these incidents, one pattern stands out: attackers are extracting structured, high-value data sets that can be reused, recombined, and resold.
Why Australia Is in the Crosshairs
The increase in targeting can be explained by several structural factors:
First, ransomware and data extortion groups find Australian companies appealing because they are very data-driven and technologically advanced.
Second, systemic exposure is increased by reliance on outside service providers. One provider's security flaws can spread throughout large ecosystems.
Third, the cost of starting large-scale campaigns is being reduced by attackers using sophisticated tools, such as automation and AI-assisted phishing.
Lastly, Australia's widespread use of digital technology raises the attack surface and data accessibility.
Defensive Shifts Required for 2026
Organizations are being forced to adopt intelligence-driven security solutions due to the shifting threat landscape.
Risk-based vulnerability management, which concentrates remedial efforts on actively exploited vulnerabilities rather than theoretical problems, is becoming important.
To protect against credential-based assaults, which are commonly employed in supply chain and ransomware incursions, multi-factor authentication is becoming a standard requirement.
To identify vulnerability outside of their immediate surroundings, organizations are also improving their supply chain risk assessments.
To combat contemporary threats like AI-generated phishing, deepfake impersonation, and automated social engineering efforts, security awareness programs are changing.
Behavioral analytics and AI-driven detection systems are becoming more and more important at the infrastructure level to find anomalies that conventional monitoring tools overlook.
Lastly, as businesses shift from implicit trust to continuous verification models, Zero Trust architectures are becoming more popular.
The Role of Intelligence-Led Defense Platforms
Platforms such as those developed by Cyble reflect a broader shift toward real-time, intelligence-led security operations. Their approach combines dark web monitoring, external attack surface visibility, vulnerability intelligence, and endpoint compromise detection.
While such systems vary in implementation, the broader trend is clear: security teams are moving away from static defense models toward continuous monitoring of external threat ecosystems.
This shift is especially relevant in environments where stolen data is rapidly aggregated and resold, making early detection of exposure more valuable than post-incident response.
Bundling Is the New Exposure Multiplier
The 48% increase in Australian data breaches highlights a major shift in cybercrime operations. Stolen data is no longer traded in isolation — cybercriminals are bundling, repackaging, and reselling Australian dark web data across larger underground ecosystems, increasing exposure for multiple organizations at once.
For the upcoming years, organizations must focus not only on preventing breaches but also on understanding how stolen data is reused and monetized after exfiltration. With AI-native threat intelligence, dark web monitoring, and attack surface management, Cyble helps organizations identify exposed data, detect emerging threats, and strengthen cyber resilience.
Want to see the intelligence behind the data in this report or learn how Cyble can help protect your organization?
Schedule a personalized demo with Cyble today.
The post Why Australian Dark Web Data Is Now Being Sold in Bundles — and What It Means for Organizational Exposure in 2026 appeared first on Cyble.