---
title: "Cybersecurity News Update, Week 7 of 2023 | DuoCircle"
description: "The weekly cybersecurity news roundup will provide you with the latest insights and updates on the ever-evolving landscape of cyber threats and defenses."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/"
---

Quick Answer

Week 7, 2023 cyber news: FTC reports romance scams cost \~70,000 Americans $1.3B in 2022 (median loss $4,400), with Facebook and Instagram named in over half the contacts and crypto plus wire transfers driving 60%+ of losses; Namecheap email tied to a SendGrid upstream system was abused to send MetaMask and DHL phishing; Oakland takes city systems offline after a ransomware attack; a December 1, 2022 ransomware attack on Heritage Provider Network exposes 3.3 million California patients SSNs and PHI; Reddit confirms a phishing-based intrusion that exposed source code and internal docs; SentinelLabs finds Google Ads phishing AWS logins via aws1-console-login\[.\]us and aws1-ec2-console\[.\]com.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%207%20of%202023&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2023%2F&title=Cybersecurity%20News%20Update%2C%20Week%207%20of%202023 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%207%20of%202023&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-7-of-2023%2F "Share via Email") 

![security updates](https://media.mailhop.org/duocircle/images/2023/02/windows-smtp-service-1.jpg) 

The weekly cybersecurity news roundup will provide you with the **latest insights** and updates on the ever-evolving landscape of cyber threats and defenses. This week’s updates aim to keep you informed on the latest cybersecurity trends and risks affecting organizations, from data breaches and [malware](/resources/malware-and-its-defense-mechanism) attacks to emerging technologies and **best practices** in information security.

## Romance Scams Cost 70,000 Americans $1.3 Billion in Losses Last Year, According to FTC

_The U.S. Federal Trade Commission (FTC) has reported that Americans suffered record losses of $1.3 billion in 2022 due to [romance scams](https://consumer.ftc.gov/articles/what-know-about-romance-scams), with a median loss of $4,400._

Romance scams, also known as **confidence fraud**, can cause emotional scars and significant financial losses. Scammers use fake online identities to gain the trust of their victims on **dating sites** and [social media](/email-security/ftc-social-media-scams-rob-us-citizens-of-770-million/) platforms.

Once a victim is lured in, the [scammer](https://economictimes.indiatimes.com/tech/tech-bytes/crypto-scammers-new-target-dating-apps/articleshow/89744244.cms) takes advantage of the **victim’s trust** to manipulate them into sending money or providing sensitive financial information, which can be used for other types of fraud. In 2022, nearly **70,000 people** reported being scammed, and the FTC has warned that these figures represent only a fraction of the actual harm caused by romance scams, as most victims do not report the crime. 

The FTC has also disclosed that **Facebook (28%)** and **Instagram (29%)** are the most popular platforms for fraudsters to contact their victims. Regarding payment methods, [cryptocurrency](https://www.moneycontrol.com/news/business/cryptocurrency/cryptocurrency-roundup-for-february-21-hong-kong-to-permit-retail-investors-to-trade-in-large-cap-cryptocurrencies-10132891.html) (34%) and bank wire transfers/payments (27%) accounted for over 60% of the reported losses to romance scams in 2022.

The FBI has [warned](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2023/02/romance-scammers-favorite-lies-exposed) that victims of romance scams may be **recruited** as “[money mules](https://www.fbi.gov/how-we-can-help-you/safety-resources/scams-and-safety/common-scams-and-crimes/money-mules)” and tricked into transferring money on behalf of the fraudsters.

[![malware](https://media.mailhop.org/duocircle/images/2023/02/spf-record-check-7411.jpg)](https://media.mailhop.org/duocircle/images/2023/02/spf-record-check-7411.jpg)

## NameCheap’s Email Compromised for Metamask and DHL Phishing Scams

Namecheap suffered an **email account breach** that resulted in a flood of MetaMask and DHL [phishing emails](/content/phishing-prevention/phishing-email).

The phishing campaign began around 4:30 PM ET and came from **SendGrid**, an email platform previously used by Namecheap to send renewal notices and **marketing emails**. The phishing emails impersonated DHL or MetaMask, attempting to steal recipients’ personal information and [cryptocurrency wallets](https://www.coindesk.com/tech/2023/02/24/crypto-wallet-firm-dfns-says-magic-links-have-critical-vulnerability/).

When recipients complained on Twitter, Namecheap CEO Richard Kirkendall confirmed that the account was breached and that they **disabled** email through SendGrid while they investigated the issue. 

The DHL phishing email pretended to be a **bill for a delivery fee** required to complete the package delivery. In contrast, the MetaMask phishing email pretended to be a required [KYC (Know Your Customer)](https://www.investopedia.com/terms/k/knowyourclient.asp) verification to prevent the wallet from being suspended.

Within the email, there was a **marketing link** originating from Namecheap which directed the recipient to a fraudulent MetaMask [phishing](/content/phishing-prevention/what-is-phishing) page. _The page then prompted the user to enter their ‘Secret Recovery Phrase’ or ‘Private key’._

Namecheap later [published a statement](https://web.archive.org/web/20230305211902/https://www.namecheap.com/status-updates/archives/74848) that their systems were not breached, but it was an issue at an **upstream system** they used for email.

## Ransomware Attack Shuts Down City of Oakland Systems

_The City of Oakland fell victim to a [ransomware attack](/resources/ryuk-ransomware-attacks), causing all systems to be taken **offline** until affected services were secured and restored._

The City’s Information Technology Department [collaborates](https://www.oaklandca.gov/news/2023/city-of-oakland-targeted-by-ransomware-attack-core-services-not-affected) with law enforcement to investigate the attack’s scope and severity, restore impacted services, and secure the network. The City is also developing a **response plan** to address the issue following industry best practices. Although the identity of the ransomware group behind the attack remains unknown, there have been **no ransom demands** or data theft reports yet.

The public should anticipate **delays** from the City while the situation is being monitored, according to the City’s statement. On the other hand, Oakland reporter Jaime Omar Yassin claimed that the City’s **under-staffing** within its IT department exposed it to ransomware attacks. _However, the attack did not affect core services such as 911 dispatch, fire, and emergency resources, which work normally._

As per Emsisoft threat analyst Brett Callow, at least six local US governments were [impacted](https://twitter.com/BrettCallow/status/1624141727408979969) by ransomware this year, with four having **stolen data**. Furthermore, ransomware attacks across government, educational, and healthcare verticals in the US public sector will have affected **more than 200 larger organizations in 2022**.

## California Medical Group Data Breach Affects 3.3 Million Patients

A ransomware attack has impacted multiple medical groups in the Heritage Provider Network in California, exposing **sensitive patient information** to [cybercriminals](https://www.businessinsider.in/international/news/its-not-just-you-cybercriminals-are-also-using-chatgpt-to-make-their-jobs-easier/articleshow/98245304.cms).

The affected **medical groups** are Regal Medical Group, Lakeside Medical Organization, ADOC Medical Group, and Greater Covina Medical. The entities **jointly issued a notice** of [data breach](/email-security/top-data-breaches-of-the-year-and-lessons-for-2022/) at the beginning of February and submitted a sample letter to the California Attorney General’s office.

The healthcare organizations [reported](https://ocrportal.hhs.gov/ocr/breach/breach%5Freport.jsf) on the U.S. Department of Health and Human Services breach portal that 3,300,638 patients’ data was exposed in the attack. According to the **breach notification**, the ransomware attack occurred on December 1, 2022, with Regal’s employees reporting **technical difficulties** the following day. 

A third-party [cybersecurity](/) expert investigated and determined that the organization’s servers were infected with malware, so a **system restoration** was initiated. Based on a review of the logs, the investigation found that **sensitive data** were compromised, including full name, Social Security Number (SSN), date of birth, address, medical diagnosis and treatment, laboratory test results, **prescription data**, radiology reports, health plan member number, and phone number.

_Impacted patients should be cautious of **targeted** phishing attacks, scams, [social engineering](/email-security/a-young-hacker-unleashes-social-engineering-attack-on-uber/), or extortion using stolen data. If you are unsure if an email or text is legitimate, **ignore it or contact your doctor** to confirm its validity._

[![cybersecurity](https://media.mailhop.org/duocircle/images/2023/02/buy-smtp-7412.jpg)](https://media.mailhop.org/duocircle/images/2023/02/buy-smtp-7412.jpg)

## Reddit Hacked by Cybercriminals to Steal Source Code and Internal Data

Reddit experienced a cyberattack in which [hackers](/email-security/hackers-leak-twitter-account-data-putting-235-million-worldwide-at-risk/) infiltrated internal business systems and stole **internal documents and source code**.

According to Reddit, the hackers deployed a phishing lure aimed at the company’s employees using a **landing page** that mimicked its intranet site. The purpose of this site was to capture the employees’ credentials and **2FA tokens**. The hackers accessed Reddit’s systems after one employee fell prey to the phishing scam. As a result, they were able to steal data and [source code](https://www.bleepingcomputer.com/news/security/oktas-source-code-stolen-after-github-repositories-hacked/). 

> In a security incident notice, Reddit explained that “after successfully obtaining a **single** [employee’s credentials](https://www.bitdefender.com/blog/hotforsecurity/coinbase-employee-credentials-stolen-in-recent-security-incident/), the attacker gained **access** to some internal docs, code, as well as some internal dashboards and business systems.”

After the employee **self-reported** the incident to Reddit’s security team, the organization began investigating the matter. Limited contact information for current and former employees as well as organizational contacts was found among the stolen data. _However, the attackers did not access credit card information, passwords, or ad performance data._

Reddit has **not disclosed** any further details about the phishing attack but disclosed all the [details they know](https://www.reddit.com/r/reddit/comments/10y427y/we%5Fhad%5Fa%5Fsecurity%5Fincident%5Fheres%5Fwhat%5Fwe%5Fknow/) with a blog.

## Malicious Google Ads Introduce AWS Phishing Sites into Search Results

A recent phishing campaign aimed at stealing Amazon Web Services (AWS) **login credentials** is leveraging Google Ads to sneak phishing sites into **Google Search**.

The **malicious ads** ranked second in Google search results for “aws,” right behind Amazon’s promoted search result. Researchers at Sentinel Labs [discovered](https://www.sentinelone.com/blog/cloud-credentials-phishing-malicious-google-ads-target-aws-logins/) the phishing campaign on January 30, 2023\. The ads take victims to a **blogger website** under the attackers’ control, a copy of a legitimate vegan food blog. _From there, the victim is **automatically** redirected to a fake AWS login page that requests their email address and password._ 

The [phishing domains](https://www.hackread.com/phishing-domains-popular-brands/) seen by Sentinel Labs include aws1-console-login\[.\]us and aws1-ec2-console\[.\]com. _The phishing pages disable right clicks, middle mouse buttons, or keyboard shortcuts to **prevent users** from navigating away from the page._ Sentinel Labs has reported the abuse to CloudFlare, which protected the phishing sites. However, the **malicious Google Ads** remain active even if the sites they link to are no longer online.

Cybercriminals have **increasingly** used Google Ads for phishing [password manager](https://www.bleepingcomputer.com/news/security/dashlane-password-manager-open-sourced-its-android-and-ios-apps/) accounts, achieving **initial network compromise** for ransomware deployment and malware distribution, among others.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 7 of 2023","description":"The weekly cybersecurity news roundup will provide you with the latest insights and updates on the ever-evolving landscape of cyber threats and defenses.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/","datePublished":"2023-02-13T16:49:15.000Z","dateModified":"2025-05-02T12:01:09.000Z","dateCreated":"2023-02-13T16:49:15.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1277,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/02/windows-smtp-service-1.jpg","caption":"security updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 7 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 7 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 7 of 2023","description":"The weekly cybersecurity news roundup will provide you with the latest insights and updates on the ever-evolving landscape of cyber threats and defenses.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/","datePublished":"2023-02-13T16:49:15.000Z","dateModified":"2025-05-02T12:01:09.000Z","dateCreated":"2023-02-13T16:49:15.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-7-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1277,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/02/windows-smtp-service-1.jpg","caption":"security updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
