---
title: "Car Maker Targeted, Water Utility Infiltrated, Facebook Data Settlement, Cybersecurity News [April 15, 2024] | DuoCircle"
description: "From the latest phishing attacks aimed at a massive American car manufacturer, the impersonation tactics of Sandworm threat actors."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/"
---

Quick Answer

Cybersecurity stories from the week of April 15, 2024: the FIN7 group launched a phishing campaign aimed at IT staff of a major American car manufacturer, attempting to plant Anunak/Carbanak-style backdoors. Russia-linked Sandworm operators masqueraded as hacktivist groups in cyberattacks on US water utilities. Cerebral agreed to a $7 million settlement over a Facebook Pixel data-sharing breach. Google announced stricter measures against third-party YouTube apps that strip ads. And the FBI warned of a sharp rise in SMS road-toll phishing scams impersonating EZ-Pass, FasTrak, and similar services to harvest payment-card details.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Car%20Maker%20Targeted%2C%20Water%20Utility%20Infiltrated%2C%20Facebook%20Data%20Settlement%2C%20Cybersecurity%20News%20%5BApril%2015%2C%202024%5D&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F&title=Car%20Maker%20Targeted%2C%20Water%20Utility%20Infiltrated%2C%20Facebook%20Data%20Settlement%2C%20Cybersecurity%20News%20%5BApril%2015%2C%202024%5D "Share on Reddit") [ ](mailto:?subject=Car%20Maker%20Targeted%2C%20Water%20Utility%20Infiltrated%2C%20Facebook%20Data%20Settlement%2C%20Cybersecurity%20News%20%5BApril%2015%2C%202024%5D&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F "Share via Email") 

![Cybersecurity News](https://media.mailhop.org/duocircle/images/2024/04/smtp-server-mail-2.jpg) 

From the [latest phishing attacks](https://www.bleepingcomputer.com/news/security/need-to-know-key-takeaways-from-the-latest-phishing-attacks/) aimed at a massive American car manufacturer, the impersonation tactics of Sandworm threat actors, the details of the pixel data breach settlement, **Google’s ad-blocking** measures on YouTube, and the surge in SMS road toll phishing scams, we’re back again with the top [cybersecurity](/) news of the week. Stay tuned!

## FIN7 Phishing Attacks Aimed at IT Staff of American Car Manufacturer

FIN7 has been targeting **IT department employees** of a major [car manufacturer](https://www.cshub.com/attacks/news/telsa-data-breach-caused-by-insider-wrongdoing) in the United States. 

BlackBerry’s researchers came across the attack where the threat actors lured **employees with high-level privileges** by impersonating advanced [IP (Internet Protocol) scanner tools](https://appuals.com/what-is-ip-scanner/). The threat actors start with [spear-phishing emails](https://www.cbsnews.com/news/uk-sexting-spear-phishing-scam-mp-william-wragg-lawmaker-phone-numbers/) with links that are redirected to fake websites. These websites took the victims to a Dropbox page with an executable file.

When a victim executes the file, it starts a **multi-stage process**, with the [Anunak backdoor payload](https://www.bleepingcomputer.com/news/security/source-code-for-carbanak-backdoor-shared-with-larger-infosec-community/) installed on the system, one of the malware tools that FIN7 uses in its attacks. The executable file also installs **OpenSSH**, allowing the threat actors persistent access and lateral movement within the system. 

BlackBerry has not [shared](https://blogs.blackberry.com/en/2024/04/fin7-targets-the-united-states-automotive-industry) the name of the car manufacturing enterprise but did say that it’s **a major one**. 

## Russian Sandworm Cyber Group Masquerades as Activists in Water Utility Cyberattacks

The Russian [Sandworm hacking group](https://therecord.media/russia-sandworm-hacking-ukraine-telecom-internet-providers) has been **posing as a hacktivist** group to hide its online activities. 

Mandiant shared a report showing that the Sandworm threat actors are linked to **multiple Telegram channels**, which they used to spread information favoring Russia and amplifying their own activity. The Russian-aligned threat actor group uses [credential harvesting](https://securityaffairs.com/152199/hacking/citrix-netscaler-credential-harvesting-campaign.html) and [phishing emails](https://www.audacy.com/wbbm780/news/local/dont-be-fooled-by-phishing-emails-promising-a-free-piano) to gain initial access and has been using these online personas since the beginning of Russia’s invasion of Ukraine. The Telegram channels (XakNet Team, CyberArmyofRussia\_Reborn, and Solntsepek) are tied to the threat actors.

CyberArmyofRussia\_Reborn is closely linked to the group, and Mandiant [found](https://cloud.google.com/blog/topics/threat-intelligence/apt44-unearthing-sandworm) out that the group is being **used to leak the data** that the threat actors steal in their attacks. Sandworm has been causing all kinds of trouble since the beginning of the war and carrying out multiple attacks on the country’s critical infrastructure. 

Sandworm’s focus is on [sabotaging attacks](https://en.wikipedia.org/wiki/Sabotage) in Ukraine, espionage, and operations to change the perceptions (domestic and foreign) about **Russia’s power** and cyber capabilities. 

[![biggest breaches](https://media.mailhop.org/duocircle/images/2024/04/hosted-email-server-3.jpg)](https://media.mailhop.org/duocircle/images/2024/04/hosted-email-server-3.jpg)

## Cerebral Agrees to $7 Million Settlement Over Facebook Pixel Data Breach

The FTC (US Federal Trade Commission) ordered Cerebral, a telehealth enterprise, to pay $7 million as they **failed to handle** people’s [sensitive health data](https://www.usatoday.com/story/news/health/2024/02/18/health-data-breaches-hit-new-record-2023/72507651007/). 

_Cerebral suffered a [data breach](https://edition.cnn.com/2024/04/12/business/roku-security-breach-user-accounts/index.html) and sent out notices of said breach in 2023 to **over 3 million people** who had used its websites, applications, and services_. The information was exposed due to tracking pixels that the organization uses on its platform.

FTC issued a complaint highlighting the charges against Cerebral and Kyle Robertson, the former CEO of the organization, as they disclosed the personal health information of the platform’s users for ads and **did not follow the cancellation policies**. Cerebral [leaked data](https://www.crn.com/news/security/2024/unitedhealth-investigating-change-healthcare-data-leak-claims) from 3.2 million customers to LinkedIn, Snapchat, and TikTok. Plus, the organization failed to revoke the access of former employees to patient records. 

You can read all the details of the announcement that highlights all the other harmful practices that the organization carried out in this [report](https://www.ftc.gov/news-events/news/press-releases/2024/04/proposed-ftc-order-will-prohibit-telehealth-firm-cerebral-using-or-disclosing-sensitive-data). 

## Google to Intensify Measures Against Ad-Blocking Third-Party YouTube Applications

YouTube made an announcement this week that all [third-party applications](https://adguard.com/en/blog/adguard-third-party-blocking-apps.html) that block ads **violate its ToS (Terms of Service)**, and it will take action against the applications soon. 

_**Google shared its APIs** (Application Programming Interfaces) that allow developers around the world to integrate YouTube into their applications to show videos and data without it being hosted on the app._ However, many people have been [misusing the APIs](https://www.bleepingcomputer.com/news/security/trello-api-abused-to-link-email-addresses-to-15-million-accounts/) and creating applications that allow you to watch YouTube videos without any ads. Many of these are available to download on **Android and iOS**.

This week, Google [announced](https://support.google.com/youtube/thread/269521462?hl=en) that any applications that use the APIs to block advertisements will be shut off, and the users of the applications will have to deal with **extended buffering and errors**. Many people might dislike the decision, but YouTube has emphasized that if you want a premium experience of not seeing any ads while watching YouTube, you need to subscribe to the platform. The current fee is between $13.99 and $18.99\. 

_YouTube has been conducting experiments to take care of ad-blocking since 2023 and even [restricted such users to watching only 3 videos](https://www.bleepingcomputer.com/news/technology/youtube-tests-restricting-ad-blocker-users-to-3-video-views/)._ 

[![Phishing Scams](https://media.mailhop.org/duocircle/images/2024/04/dkim-validation-4671.jpg)](https://media.mailhop.org/duocircle/images/2024/04/dkim-validation-4671.jpg)

## FBI Alerts about Surge in SMS Road Toll Phishing Scams

In other news, the FBI (Federal Bureau of Investigation) warned US citizens about a new phishing campaign where threat actors are using [SMS phishing](/phishing-protection/mobile-hacking-on-the-rise-alongside-new-phishing-tactics/) (Smishing) to lure victims with **unpaid road toll messages**. 

The attacks surfaced at the beginning of March this year, and the FBI’s IC3 (Internet Crime Complaint Center) has received **thousands of complaints** since then. The FBI shared a public service [announcement](https://www.ic3.gov/Media/Y2024/PSA240412), which outlined that the threat actors are moving from state to state and have yet to reach many new ones.

You can avoid these scams because most of them share the language. The [threat actors](/email-security/threat-actors-attack-thousands-of-computers-following-the-ion-incident/) will **approach you with a text**, highlighting that you own money for unpaid tolls, and will have a link that impersonates your **state’s toll service name and phone numbers** to make it appear legitimate.

_But the links would lead you to [malicious sites](https://thehackernews.com/2024/03/hackers-using-sneaky-html-smuggling-to.html) where the threat actors will scam you out of your money, so keep an eye out._ If you do receive such a text, do not click on the link and **delete it promptly after reporting** the number. It’s always best to go to Google and **open the toll service’s genuine website** and check if you have any pending tolls from there. 

You should file a complaint with the [IC3](https://www.ic3.gov/) and add the scammer’s contact number and the website that was listed in the [phishing text](https://www.thestar.com.my/news/nation/2024/04/20/over-rm229000-lost-to-scams-via-text-messages) if you do receive one of these. It’s crucial to prioritize your [online safety](/email-security/data-privacy-and-protection-11-ways-to-protect-user-data/) by **being vigilant** and utilizing [phishing protection](/email/phishing-protection) measures. It’s also crucial to consider undergoing [phishing awareness training](/phishing-awareness-training) to better recognize and thwart such scams in the future.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F) [ ](https://twitter.com/intent/tweet?text=Car%20Maker%20Targeted%2C%20Water%20Utility%20Infiltrated%2C%20Facebook%20Data%20Settlement%2C%20Cybersecurity%20News%20%5BApril%2015%2C%202024%5D&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-17-of-2024%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Car Maker Targeted, Water Utility Infiltrated, Facebook Data Settlement, Cybersecurity News [April 15, 2024]","description":"From the latest phishing attacks aimed at a massive American car manufacturer, the impersonation tactics of Sandworm threat actors.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/","datePublished":"2024-04-22T15:30:06.000Z","dateModified":"2025-08-29T14:08:05.000Z","dateCreated":"2024-04-22T15:30:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1071,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/04/smtp-server-mail-2.jpg","caption":"Cybersecurity News","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Car Maker Targeted, Water Utility Infiltrated, Facebook Data Settlement, Cybersecurity News [April 15, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Car Maker Targeted, Water Utility Infiltrated, Facebook Data Settlement, Cybersecurity News [April 15, 2024]","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Car Maker Targeted, Water Utility Infiltrated, Facebook Data Settlement, Cybersecurity News [April 15, 2024]","description":"From the latest phishing attacks aimed at a massive American car manufacturer, the impersonation tactics of Sandworm threat actors.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/","datePublished":"2024-04-22T15:30:06.000Z","dateModified":"2025-08-29T14:08:05.000Z","dateCreated":"2024-04-22T15:30:06.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-17-of-2024/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1071,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2024/04/smtp-server-mail-2.jpg","caption":"Cybersecurity News","width":900,"height":506},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
