---
title: "Cyber Security News Update, Week 28 of 2021 | DuoCircle"
description: "You may be familiar with a few cyberattack strategies that the adversaries usually employ; however, if you haven’t been following current trends."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/"
---

Quick Answer

Six stories. Social-engineering campaigns are using personal details mined from data brokers and breaches to craft highly targeted spear-phishing. Polygon-based stablecoin SafeDollar's price collapsed to zero after a second flash-loan exploit drained the protocol in two weeks. Accenture researchers detailed the Hades ransomware crew's TTPs, linking it to Hafnium-style Exchange exploitation and Evil Corp affiliate networks. India's CERT-In is expanding its national cyber defense strategy after a wave of attacks on critical infrastructure. UK police warned of WhatsApp account takeovers in which scammers impersonate friends to harvest the six-digit verification code. And CISA launched the Cyber Security Evaluation Tool (CSET) and a self-assessment guide aligned to the NIST CSF for SMB use.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2028%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2028%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2028%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2021/07/email-smtp-service-3457.jpg) 

You may be familiar with a few cyberattack strategies that the adversaries usually employ; however, if you haven’t been following current trends, _you would be surprised by how innovative threat actors have become and the sophisticated methodologies they use to rob you of your credentials_. Targeted **phishing attacks** and customized attack schemes make it difficult to stay safe on the web without using robust **cybersecurity tools**. Here are this week’s latest security updates which help you learn more.

## Beware Of Personalized Cyberattack Schemes

[Email security services](/) go a long way in keeping malicious actors at bay, but what happens when attackers send you personalized texts related to some parcel delivery or suspicious credit card activity? _Over 20 cases get reported every day against these fraudulent messages from DHL_. These messages address victims by their name and aim to **extort payments** of up to €5,000 (about $5,900).

First identified in April 2021, _these fake DHL delivery messages are circulating alongside similarly concocted personal messages from MaltaPost._ In a typical text, the adversaries use an unknown number, address the victim by their name, notify of package delivery, and _seek payment confirmation by clicking on an attached link_.

In another scam, _the adversaries are impersonating the police and calling up victims with fake emergencies_ like suspicious activity in their e-ID account or an arrest warrant against their name. Over 200 such scams have been reported, with **around €100,000 lost** to these malicious calls and texts.

[![Awareness practices](https://media.mailhop.org/duocircle/images/2021/07/check-DMARC-record-5836.jpg)](https://media.mailhop.org/duocircle/images/2021/07/check-DMARC-record-5836.jpg)

Such scam texts and calls are not new, but this personalization to increase credibility is something people were unfamiliar with and hence this [initial chaos](https://timesofmalta.com/articles/view/parcel-delivery-scammers-targeting-people-with-personalised-messages.882985?&web%5Fview=true). In scenarios like these, basic cyber [awareness practices](/phishing-awareness-training) such as verifying the caller’s number, looking for relevance, being cautious of errors and omissions and _refraining from clicking on embedded links_ can help you avoid becoming a victim.

## SafeDollar Prices Come Down To Zero After Second Cyberattack In Two Weeks

An exploit caused _SafeDollar, the algorithmic stablecoin on Polygon to crash down to $0 after the adversaries launched an attack_ on 28th June 2021\. Consequently, 202,230 USD Coin and _46,000 USD Tether were lost_, affecting SafeDollar’s aim of being a less volatile and [stable cryptocurrency](https://finance.yahoo.com/news/stablecoin-safedollar-crashes-0-following-122357249.html?&web%5Fview=true).

A week ago, SafeDollar was the victim of another cyberattack which caused a **loss of 9,959 SDS**, and now its price has come down to zero. As it continues investigating the breach and **adopting cybersecurity** measures, SafeDollar has notified that the move forward and compensation plans will be disclosed shortly.

## Accenture Reveals New Details About The Hades Ransomware Gang

Accenture Security research recently revealed some interesting details about the ransomware gang Hades discovered in December last year. With over **seven billion-dollar companies** as victims since its discovery, _the Hades ransomware gang has successfully concealed the identity of its operators so far_.

While some researchers link Hades to a Russian hacker group, others doubt its Chinese ties. Accenture couldn’t pin down its origin, but here are the three things about Hades that Accenture is sure about:

- The new targets of Hades include consumer goods and services, manufacturing, insurance and distribution industry sectors.
- Hades’s operators have probably added the [Phoenix Cryptolocker](https://www.bleepingcomputer.com/news/security/insurance-giant-cna-hit-by-new-phoenix-cryptolocker-ransomware/) to avoid campaign links and attribution claims.
- _Hades attacks are known for their consistent tactics and procedures_, and the latest addition to their malicious actions are the destruction of **cloud backups** and targeted enumeration of cloud environments.
- Unlike other ransomware gangs, Hades’s operators do not provide **ransomware as a service** (RaaS) or an affiliate model for extra income.

The cybersecurity team at Accenture hints at several other possibilities, including the re-branding of [ransomware gangs](https://www.cyberscoop.com/hades-accenture-revil-hafnium/) like Avaddon, DarkSide and WastedLocker, which have all been non-functional for some time now.

## India To Strengthen Its Cyber Defence Strategies

The rift between India and China and the latter’s use of new-age weapons has made the Indian Department of Military Affairs (DMA) decide on sending around [100 military personnel](https://www.hindustantimes.com/india-news/india-military-personnel-to-train-in-us-on-cybersecurity-command-in-the-offing-101625025032655.html?&web%5Fview=true) to the US for training in **ransomware protection** and AI for warfare.

Under the Defence Cooperation Agreement and the 2016 Cyber Framework, _the US has agreed to train a hundred military personnel from India in the latest artificial intelligence_ (AI) technologies for future warfare and **cybersecurity technology.** Apart from the tri-service defence cyber agency, the Indian military plans to set up a full-fledged cyber command in Madhya Pradesh to prepare the Indian military to battle possible cyber adversaries.

## UK Police Warns Citizens Of Whatsapp Account Takeover Attacks

After similar reports being filed by WhatsApp users in India, _users in the UK are now getting requests for verification codes from strangers_ (adversaries). The Southwark Police in South London has warned users of WhatsApp account thefts where the adversaries approach the victims and ask them to share the six-digit verification code they have received or will receive via SMS.

When we register a new account on WhatsApp, the application usually sends us a **verification code** on our phone number to verify if we are the owner of that number. The hackers are targeting this verification system and creating WhatsApp accounts using the numbers of their victims. When the code is sent to the victim, these malicious actors impersonate WhatsApp customer support and _ask them to share the verification code_. Once a victim complies with these requests, all their contact numbers and future chats become accessible to the adversaries. These hackers can then **impersonate you**, trick people on your list to make payments, conduct [identity theft](/phishing-protection/recognizing-online-identity-thefts-and-how-enterprises-can-ensure-identity-theft-protection-for-their-employees/) and a host of other crimes.

That is why it is paramount to use cybersecurity tools and enable two-factor authentication (2FA) for WhatsApp.

## CISA Launches New Self-Assessment Tool For Organizations

_Ransomware attacks are so rampant that merely investing in a **ransomware protection** tool isn’t enough_. To this end, the US Cybersecurity and Infrastructure Security Agency (CISA) has launched the [Ransomware Readiness Assessment](https://www.zdnet.com/article/ransomware-this-new-free-tool-lets-you-test-if-your-cybersecurity-is-strong-enough-to-stop-an-attack/) (RRA) as part of its Cyber Security Evaluation Tool (CSET).

[![start a new assessment](https://media.mailhop.org/duocircle/images/2021/07/DMARC-generator-6835.jpg)](https://media.mailhop.org/duocircle/images/2021/07/DMARC-generator-6835.jpg)

_RRA shall help organizations self assess the efficacy of their cyber defence measures and recovery strategies_. The RRA gauges different levels of **ransomware threat** readiness to check. It allows organizations to recover the operational technology (OT), industrial control system (ICS), and information technology (IT) assets in case of any ransomware attack. To use the RRA, users must first install CSET and start the application. They can then [start a new assessment](https://www.bleepingcomputer.com/news/security/cisa-releases-new-ransomware-self-assessment-security-audit-tool/?&web%5Fview=true) and refer to the tutorial for further guidance.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2028%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-28-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 28 of 2021","description":"You may be familiar with a few cyberattack strategies that the adversaries usually employ; however, if you haven’t been following current trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/","datePublished":"2021-07-09T13:15:58.000Z","dateModified":"2025-05-27T13:12:11.000Z","dateCreated":"2021-07-09T13:15:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1049,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/07/email-smtp-service-3457.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 28 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 28 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 28 of 2021","description":"You may be familiar with a few cyberattack strategies that the adversaries usually employ; however, if you haven’t been following current trends.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/","datePublished":"2021-07-09T13:15:58.000Z","dateModified":"2025-05-27T13:12:11.000Z","dateCreated":"2021-07-09T13:15:58.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-28-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1049,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2021/07/email-smtp-service-3457.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
