---
title: "Cyber Security News Update, Week 52 of 2021 | DuoCircle"
description: "The Christmas holidays are a fragile period in the world of cybersecurity."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/"
---

Quick Answer

Week 52, 2021 cyber news: Echelon infostealer is dropped in the Smokes Night Telegram channel to harvest crypto wallet credentials from BitcoinCore, Exodus, AtomicWallet, Jaxx, and others; Group-IB exposes a global phishing scam impersonating 121 brands across 90 countries that targeted 10 million people via 60+ scam networks; PhishLabs reports H1 2021 phishing up 22% YoY; Meta sues unnamed actors over 39,000 phishing sites for Facebook, Instagram, WhatsApp, and Messenger that hid behind Ngrok relays; a Massachusetts man pleads guilty to selling rideshare driver PII as part of an 18-person ring; Me2B Alliance finds K-12 school apps leaking student data via WebView to advertisers, Google, and Facebook.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2052%20of%202021&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F&title=Cyber%20Security%20News%20Update%2C%20Week%2052%20of%202021 "Share on Reddit") [ ](mailto:?subject=Cyber%20Security%20News%20Update%2C%20Week%2052%20of%202021&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F "Share via Email") 

![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-validator-7845.jpg) 

The [Christmas holidays](/email-hosting/how-organizations-can-defend-themselves-against-bec-scams-during-the-holiday-season/) are a fragile period in the world of cybersecurity. Many organizations undergo unfortunate cyber incidents during this time, and the simplest way to avoid such instances is to learn from the mistakes of others. Here are the top [cybersecurity headlines](/announcements) the world over to help you plan your cyber moves better.

## Echelon Infostealer Deployed Through Telegram Channel

Of late, _adversaries have widely used Telegram to target cryptocurrency users_. The latest instance is the exploitation of the “Smokes Night” Telegram channel to spread the info stealer Echelon among crypto users. The attack scheme mainly [targets unsuspecting crypto](https://threatpost.com/telegram-steal-crypto-wallet-credentials/177266/) users who may have joined the discussion channel for crypto information. _Cybersecurity experts at SafeGuard first discovered the use of Echelon in Telegram_ channels in October. However, they reported that this credential stealer is widely used in crypto wallets, file-sharing and messaging platforms like BitcoinCore, Exodus, ByteCoin, AtomicWallet, Monera, Jaxx, Edge, Discord, Outlook, FileZilla, OpenVPN etc.

Researchers have no reason to believe that this **malware deployment** has anything to do with a coordinated campaign, its purpose seems confined to targeting new and unsuspecting users of the channel. While users have not engaged with the malicious message, there is no way to ascertain that the malware didn’t reach the targeted systems.

[![global phishing scam](https://media.mailhop.org/duocircle/images/2022/01/spf-record-generator-6743.jpg)](https://media.mailhop.org/duocircle/images/2022/01/spf-record-generator-6743.jpg)

## Phishing Remains The Most Popular Attack Vector in 2021

_Group-IB, the popular cybersecurity vendor recently identified a phishing campaign that has robbed users **across 90 countries** of millions of dollars_. The holiday season is just making it easier for them to use their malicious phishing scams. The adversaries of this [global phishing scam](https://web.archive.org/web/20211224075514/https://cyware.com/news/a-global-phishing-scam-that-cost-victims-80-million-per-month-4a34c3bb) impersonated 121 renowned brands and lured customers with fake giveaways and surveys. These surveys obviously led users to **phishing pages** that collected their personally identifiable information like names, contact numbers, addresses, payment card details etc. Group-IB identified **over 60 scam network**s, each owning over 70 domain names and using a variety of marketing means like pop-up notifications, emails, SMS etc. _More than 10 million people were targeted by this malicious scam_, with a majority of victims located in Asia, Africa and Europe.

In addition, a report by PhishLabs suggests that the number of [phishing attacks](/content/email-phishing-protection/how-to-mitigate-phishing-attacks) in the first half of 2021 is **22% more** than the attacks reported during the same period in 2020\. Since people are more aware of cyberattacks these days and take adequate email [phishing protection](/email/phishing-protection) measures, adversaries are exploring new and different ways of reaching their malicious objectives.

## Meta Files Federal Lawsuit Against Threat Actors Who Created 39k Phishing Websites

_Meta, Facebook’s parent organization, has filed a federal lawsuit against threat actors_ who created **over 39,000 phishing websites** impersonating the login pages of Facebook, Instagram, WhatsApp and Messenger. The [adversaries targeted unsuspecting users](https://thehackernews.com/2021/12/meta-sues-hackers-behind-facebook.html) of Meta’s digital properties and asked them to enter their usernames and passwords in the phished login pages. After discovering this scam, Meta seeks a $500,000 compensation from the unnamed threat actor.

The adversaries used a relay service called Ngrok, which redirects internet traffic to the fake websites in a manner that doesn’t reveal the actual location of the fraudulent infrastructure. _Meta has noted a drastic rise in such phishing attacks since March 2021_ and has worked with the relay service to shut down several **phishing websites**. This lawsuit comes as yet another cybersecurity move by Meta to uphold the privacy of its users.

## Massachusetts Man Pleads Guilty For Stealing & Selling Gig Workers’ Data

_A 36-year-old Massachusetts resident named Flavio Candido da Silva pleaded guilty in a Boston federal court for data theft and financial fraud_. The accused was found accessing the rideshare and delivery service accounts of unsuspecting individuals and [selling their personally identifiable information](https://www.bleepingcomputer.com/news/legal/rideshare-account-hacker-faces-up-to-22-years-in-prison/) on the dark web. Flavio is suspected to be a part of a larger cyber threat **group of 18 members** who deal in stealing and falsifying identity documents of rideshare users and then selling and renting these out to third parties. Currently, Flavio is pleading guilty to one instance of wire fraud and one case of [identity theft](/phishing-protection/recognizing-online-identity-thefts-and-how-enterprises-can-ensure-identity-theft-protection-for-their-employees/).

The user information compromised in the process includes the names, driver’s license details, DOBs & social security numbers of rideshare drivers. Flavio looks like a hardworking thief as he used several tactics to evade facial recognition checks in the delivery service provider and rideshare systems. _Flavio and the team caused a minor vehicle accident to get information and photographs of the victim or their license_. The threat actor also used GPS spoofing technology to give the impression that he was making deliveries. In this entire fraud scheme, Flavio caused victim organizations a **loss of over $200,000**.

Fortunately, such crimes won’t go unpunished, _Flavio and the team may get a sentence of up to 20 years for wire fraud in prison and up to 2 years for identity theft_. This is in addition to a **fine of $250,000** or more (nearing up to the gain/loss from the attack). Since threat actors like Flavio are all over the internet, gig workers must consider using cybersecurity tools and measures like **MFA to ensure their safety**.

[![email security](https://media.mailhop.org/duocircle/images/2022/01/spf-permerror-7534.jpg)](https://media.mailhop.org/duocircle/images/2022/01/spf-permerror-7534.jpg)

## K-12 School Apps Exposing Student Data, Reports Me2B Alliance

_A cybersecurity report by the non-profit Me2B Alliance states that K-12 school apps are operating with several serious [email security](/) risks_ which could share student data with advertising organizations and other third parties. This report is in continuation with [another report published](https://therecord.media/study-finds-serious-security-risks-in-k-12-school-apps/) by Me2B in May, where it studied 73 apps used in 38 schools. Its findings revealed that 60% of these apps sent student data to third parties, 50% shared data with Google, and 14% sent student data to Facebook.

Using the WebView features, developers can integrate web pages into their apps. While this is a handy feature to include dynamic details like calendars into the app, it also exposes student data. This puts students and their parents at high risk of being targeted by scammers. Several instances of the WebView feature going wrong have been recorded in the past where the attackers used expired URLs to launch [BEC attacks](/email-hosting/how-organizations-can-defend-themselves-against-bec-scams-during-the-holiday-season/), phishing and other advertising campaigns. Therefore, schools must remember to renew their domains and remove the expired ones from time to time.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F) [ ](https://twitter.com/intent/tweet?text=Cyber%20Security%20News%20Update%2C%20Week%2052%20of%202021&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-52-of-2021%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 52 of 2021","description":"The Christmas holidays are a fragile period in the world of cybersecurity.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/","datePublished":"2022-01-03T18:59:14.000Z","dateModified":"2025-05-26T13:03:48.000Z","dateCreated":"2022-01-03T18:59:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1021,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/01/spf-validator-7845.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cyber Security News Update, Week 52 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cyber Security News Update, Week 52 of 2021","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cyber Security News Update, Week 52 of 2021","description":"The Christmas holidays are a fragile period in the world of cybersecurity.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/","datePublished":"2022-01-03T18:59:14.000Z","dateModified":"2025-05-26T13:03:48.000Z","dateCreated":"2022-01-03T18:59:14.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-52-of-2021/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1021,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/01/spf-validator-7845.jpg","caption":"Cyber Security","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
