Topic
Breaches & Data Leaks
Real-world intrusions and data leaks — how they started and the lessons for security teams.
66 articles in this topic
REF6598 & PHANTOMPULSE: How Hackers Are Weaponizing Obsidian's Plugin Ecosystem to Breach Financial Sector Employees
A sophisticated threat actor is abusing the Obsidian note-taking app's community plugin ecosystem to silently install a new RAT on financial employees' machines — no CVE, no exploit, just trusted software turned weapon.
Cloud & IdentityMcGraw-Hill's 13.5M-Record Salesforce Breach: Why Cloud Misconfiguration Is the Silent SAMA CSCC Compliance Failure
A Salesforce misconfiguration exposed 13.5 million records at McGraw-Hill. With 31% of cloud breaches sharing this same root cause, Saudi financial institutions must audit their SaaS posture before their next SAMA review.
Breaches & Data LeaksShinyHunters Breach Anodot to Compromise Dozens of Snowflake Accounts: A Supply Chain Wake-Up Call for Saudi Financial Institutions
On April 7, 2026, the ShinyHunters gang breached AI analytics firm Anodot and weaponized stolen Snowflake authentication tokens against dozens of companies. Saudi financial institutions using cloud data platforms face direct SAMA CSCC third-party risk exposure — here's what you must do now.
Supply Chain & Third PartyBooking.com's ClickFix Supply Chain Breach: The Third-Party Vendor Risk Every Saudi Financial CISO Must Address Now
Booking.com confirmed a breach exposing millions of customers' reservation data — attackers never touched Booking.com directly. They compromised hotel partners using ClickFix malware. Saudi financial institutions face identical third-party exposure under SAMA CSCC.
Breaches & Data LeaksShinyHunters Hits McGraw-Hill via Salesforce Misconfiguration: 13.5M Records and a Warning Saudi Financial CISOs Must Heed
No malware, no CVE, no phishing — just a Salesforce misconfiguration. ShinyHunters walked out with 13.5 million McGraw-Hill records. Saudi banks running Salesforce or Dynamics 365 hold far more sensitive data and face identical exposure under PDPL and SAMA CSCC.
Compliance & RegulationBooking.com Breach Forces Global PIN Resets — Third-Party Platform Risk Is Now a SAMA Compliance Issue for Saudi Financial Institutions
Booking.com confirmed hackers accessed customer reservation data on April 13, 2026. Saudi financial CISOs must review third-party risk registers, PDPL obligations, and phishing defences immediately.
VulnerabilitiesEngageLab SDK Intent Redirection Flaw Exposed 50 Million Android Users — A Third-Party SDK Risk Alarm for Saudi Financial Mobile Apps
Microsoft uncovered an intent redirection vulnerability in EngageLab SDK that silently put 50 million Android users — including 30 million cryptocurrency wallet installs — at risk of private key theft. Saudi financial institutions relying on third-party mobile SDKs need to act now.
Breaches & Data LeaksNorth Korean Hackers Drain $285M from Drift Protocol in 12 Minutes: What Saudi Financial Institutions Must Know
North Korean hackers drained $285M from Drift Protocol in just 12 minutes on April 1, 2026 using fake CVT tokens as collateral. Saudi CISOs must understand what this means for digital asset risk under SAMA's evolving framework.
Breaches & Data LeaksShinyHunters Breach Rockstar via Anodot: Saudi CISO Third-Party Alert
ShinyHunters extracted 78M records from Rockstar via Anodot, a third-party analytics vendor. SAMA CSCC mandates strict third-party risk controls — is your institution compliant?
Supply Chain & Third PartyFake Ledger Live on Apple's App Store Stole $9.5M in 7 Days — App Supply Chain Risk Is Now a Board-Level Issue for Saudi Financial Institutions
A fraudulent Ledger Live app slipped through Apple's review process and stole $9.5 million from 50+ victims in a single week. Here's what this means for your institution's third-party and app supply chain risk posture.
Malware & Threat ActorsAdobe's BPO Backdoor: How 'Mr. Raccoon' Stole 13M Support Tickets — and What Saudi Financial Institutions Must Learn About Vendor Risk
A threat actor called "Mr. Raccoon" compromised an Indian BPO contractor via RAT malware, exfiltrating 13M Adobe support tickets, 15K employee records, and unpublished HackerOne vulnerability reports — a masterclass in third-party risk gone wrong.
Breaches & Data LeaksBooking.com Breach Fuels Spear-Phishing Against Saudi Bank Employees
Booking.com confirmed hackers accessed customer reservation data. Saudi bank employees are now prime spear-phishing targets — here's your SAMA CSCC-aligned response.
From reading to doing
Is your organisation ready for an incident like this?
Fyntralink’s incident response team helps you contain an attack, investigate it and recover from it.
Incident Response
Professional and rapid response to security incidents — threat containment, digital forensics, and full recovery
SOC as-a-Service
24/7 managed Security Operations Center that detects and responds to threats before they become crises
Security Risk Assessment
Comprehensive cybersecurity risk assessment and professional risk register aligned with your strategic decisions