---
title: "Cybersecurity News Update, Week 9 of 2023 | DuoCircle"
description: "As technology advances, the risks to personal and corporate security increase."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/"
---

Quick Answer

Week 9, 2023 cyber news: 19,444 Activision employee records leak from an Azure database after a December 2022 smishing attack on an HR employee; Stanford notifies \~900 Economics PhD applicants after a folder-permissions misconfiguration exposed application data between Dec 5, 2022 and Jan 24, 2023; FTC reports Americans lost $8.8B to scams in 2022 (up 30%), with investment fraud topping $3.8B; Symantec tracks new actor Clasiopa using custom Atharvan and open-source Lilith RAT against materials research; CERT-UA finds Russian UAC-0056 (Ember Bear) backdoors planted via web shells in December 2021; LastPass details how a keylogger on a senior DevOps engineer (one of four with S3 decryption keys) enabled the August/December vault theft.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%209%20of%202023&url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F&title=Cybersecurity%20News%20Update%2C%20Week%209%20of%202023 "Share on Reddit") [ ](mailto:?subject=Cybersecurity%20News%20Update%2C%20Week%209%20of%202023&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F "Share via Email") 

![cybersecurity](https://media.mailhop.org/duocircle/images/2023/02/spf-permerror.jpg) 

As technology advances, the risks to personal and corporate security increase, requiring businesses and individuals to **remain vigilant** in the face of emerging cyber threats. Our Weekly Cybersecurity Bulletin provides a comprehensive overview of the top [cybersecurity](/) news from around the world that caused an uproar in the past week, to keep you informed and **up-to-date** on the latest threats and trends in the industry.

## Activision Employee Data Allegedly Leaked by Hacker on Cybercrime Forum

In December 2022, an alleged data breach occurred at American game publisher Activision, with a threat actor **posting** the stolen data on a **hacking forum**.

The [hackers](/email-security/hackers-leak-twitter-account-data-putting-235-million-worldwide-at-risk/) claim to have obtained the data from the **Activision Azure database**. The leaked information comprises 19,444 unique records containing full names, phone numbers, job titles, locations, and email addresses of alleged Activision employees.

The **data dump** is free to all forum members in a text file. The potential data leak was first detected and reported on [Twitter](https://twitter.com/FalconFeedsio/status/1630144044021043201) by the threat intelligence platform FalconFeedsio.

The appearance of the employee database on the forum has raised concerns about an increased **risk of phishing** and [social engineering](/phishing-protection/social-engineering-is-a-growing-threat/) attacks on Activision employees. On February 21, 2023, Activision confirmed that it had suffered a **data breach** in early December 2022 after an **HR employee** fell prey to a [smishing (SMS-based phishing)](https://www.f-secure.com/en/articles/what-is-smishing) attempt.

However, the organization maintained that **no sensitive employee data**, game code, or player data had been accessed, and any leaked details about **upcoming game** content were already part of public [marketing materials](https://blog.thenounproject.com/what-are-marketing-materials/).

## Data Breach Impacting Ph.D. Applicants Disclosed by Stanford University

Stanford University suffered a data breach in December 2022 and January 2023\. During the breach, **admission information** for the Economics Ph.D. program was downloaded from the university’s website **without authorization**.

As a result, the university has [contacted](https://www.documentcloud.org/documents/23689774-stanford-university-economics-phd-data-breach) nearly 900 individuals who submitted **personal and health data** to its Department of Economics as part of the graduate application process, **notifying** them that their data was accessed without authorization.

> _The university stated that the breach occurred due to a [misconfiguration](https://www.webopedia.com/definitions/misconfiguration/) of a **folder’s settings** on the department’s website._

The incident was promptly investigated, and it was discovered that two downloads of the **application materials** occurred between December 5, 2022, and January 24, 2023\. _The exposed information includes applicants’ names, dates of birth, home addresses, email addresses, phone numbers, race, ethnicity, citizenship, and gender._ However, **no financial** or social security information was exposed as these data types were not part of the application files.

[![data breach](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-3497.jpg)](https://media.mailhop.org/duocircle/images/2023/02/spf-record-tester-3497.jpg)

After the [data breach](/email-security/top-data-breaches-of-the-year-and-lessons-for-2022/), Stanford University took several measures to address the situation. They immediately **blocked access to the files** that were downloaded without authorization. Furthermore, the university investigated and found **no evidence** to suggest that the accessed information had been misused.

## FTC Reports 30% Surge in Fraud Causing $8.8 Billion Loss to Americans in 2022

According to the U.S. FTC (Federal Trade Commission), Americans lost almost $8.8 billion to scams in 2022, a significant **increase of over 30%** compared to the previous year.

The FTC [reported](https://www.ftc.gov/news-events/news/press-releases/2023/02/new-ftc-data-show-consumers-reported-losing-nearly-88-billion-scams-2022) that 2.4 million consumers reported losing money to scammers in 2022, with the imposter and **online shopping scams** being the most common types of fraud reported. _The top five **fraud categories** also included scams involving prizes, sweepstakes, lotteries, investments, and business and job opportunities._

[Investment scams](https://www.tn.gov/attorneygeneral/working-for-tennessee/consumer/resources/materials/investment-scams.html#:~:text=Investment%20fraud%20happens%20when%20people,information%20about%20a%20real%20investment.) were the **leading** cause of reported losses, with consumers losing over $3.8 billion in 2022, more than double the reported loss in 2021\. **Imposter scams** were the second-highest category, with reported losses of $2.6 billion, up from $2.4 billion in 2021.

The FTC added 5.1 million consumer reports to its **secure online database**, the Consumer Sentinel Network, in 2022, with over 1.1 million reports of identity theft filed through the FTC’s IdentityTheft.gov website. Last month, the agency reported that nearly 70,000 people had reported record losses of $1.3 billion to [romance scams](https://www.independent.co.uk/news/uk/home-news/romance-scam-women-dating-fraud-valentines-day-northern-ireland-a8777121.html) in 2022.

_Consumers can use the FTC’s **ReportFraud.ftc.gov** website to report fraud attempts and file an [identity theft](/phishing-protection/recognizing-online-identity-thefts-and-how-enterprises-can-ensure-identity-theft-protection-for-their-employees/) report at IdentityTheft.gov._

## Clasiopa Hackers Utilize New Atharvan Malware for Targeted Attacks

According to security researchers, a group of hackers is using a RAT (Remote Access Trojan) named **Atharvan** to target organizations in the materials **research sector**.

The hackers are being tracked as Clasiopa by Symantec, a Broadcom enterprise. While Symantec analysts have found a clue indicating an **Indian threat actor**, little evidence supports any attribution theory. Symantec researchers [suggest](https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/clasiopa-materials-research) that Clasiopa may use **brute force** to gain access to public-facing servers.

_Once the hackers have compromised a system, they perform a series of actions that include checking the IP (Internet Protocol) address of the breached system, **disabling endpoint protection** products, deploying [malware](/resources/malware-and-its-defense-mechanism) to scan for specific files, and **exfiltrating** them as ZIP archives, clearing Sysmon logs and event logs to remove traces of malicious activity, and creating a scheduled task to list file names._

In addition to utilizing legitimate software such as Agile DGS and Agile FD signed with **outdated certificates**, Clasiopa also employs two [backdoors](https://www.tutorialspoint.com/what-is-a-backdoor-attack): the custom Atharvan and the open-source Lilith RAT. Atharvan is particularly **noteworthy** as it is a custom backdoor not seen in other attacks.

Clasiopa’s goals are currently **unclear**, but [cyber espionage](https://thehackernews.com/2022/11/chinese-cyber-espionage-hackers-using.html) motivates the attacks.

## Russian Hackers Allegedly Backdoored Ukrainian Government Websites in 2021

This week, multiple **government websites** in Ukraine were breached by Russian state hackers **using backdoors** that were planted as far back as December 2021, according to the CERT-UA (Computer Emergency Response Team of Ukraine).

CERT-UA discovered the attacks after a [web shell](https://www.geeksforgeeks.org/what-are-web-shells/) was found on a hacked website on Thursday, which the threat actors used to install additional malware. The web shell was created in December 2021 and was used to **deploy backdoors** in February 2022\. The attackers, tracked as **UAC-0056**, Ember Bear, or Lorec53 also used the GOST and Ngrok tools to deploy backdoors during the early stages of the attack.

Ukraine’s cybersecurity defense and **security agency**, SSSCIP, [confirmed](https://cip.gov.ua/en/news/viyavleno-kiberataku-na-nizku-ukrayinskikh-derzhavnikh-informaciinikh-resursiv) the attack and stated that SSSCIP, the Security Service of Ukraine, and the Cyber Police are working to **isolate** and investigate the cyber incident. SSSCIP clarified that the incident had not caused any essential system failures or disruptions that would affect the operation of Ukrainian public authorities.

[![phishing emails](https://media.mailhop.org/duocircle/images/2023/02/spf-validator-7934.jpg)](https://media.mailhop.org/duocircle/images/2023/02/spf-validator-7934.jpg)

The cybercrime group behind the attack has been **identified** as Ember Bear, a gang that emerged in March 2021 and primarily targets Ukrainian entities with backdoors, **information stealers**, and fake ransomware via [phishing emails](/content/phishing-prevention/phishing-email).

## Lastpass Breach in 2022 Involves DevOps Engineer Hacked to Steal Password Vault Data

LastPass has provided [details](https://support.lastpass.com/help/incident-2-additional-details-of-the-attack) regarding a coordinated second attack, during which a hacker accessed and **exfiltrated information** from Amazon AWS cloud storage servers for over two months.

LastPass disclosed a **breach in December** where partially encrypted password vault data and customer information were stolen.

The organization has now revealed how the **second attack** was executed, which involved using stolen information from an August breach, data from another breach, and an RCE (Remote Code Execution) [vulnerability](/email-security/two-zero-day-vulnerabilities-discovered-in-microsoft-exchange-server-patches-pending/) to install a keylogger on the device of a **senior DevOps engineer**, who was one of 4 with access to decryption keys for LastPass’ encrypted **Amazon S3 buckets**.

The [threat actor](/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/) successfully installed a keylogger on the engineer’s device by **exploiting** a third-party media software package vulnerability.

The threat actor then used the employee’s **master credentials** to gain access to the DevOps engineer’s LastPass corporate vault, enabling the threat actor to export the native corporate vault entries and the **content of shared folders**, which contained encrypted secure notes with access and [decryption keys](https://managementmania.com/en/decryption-key) required to access the AWS S3 LastPass production backups, other cloud-based storage resources, and some critical database backups.

LastPass has since updated its security posture, including **rotating sensitive credentials** and authentication keys/tokens, [revoking certificates](https://www.appviewx.com/education-center/what-is-certificate-revocation-and-when-should-i-do-it/#:~:text=Certificate%20revocation%20is%20the%20act,issued%20is%20no%20longer%20operational.), adding additional logging and alerting, and enforcing stricter **security policies**.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F) [ ](https://twitter.com/intent/tweet?text=Cybersecurity%20News%20Update%2C%20Week%209%20of%202023&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fcyber-security-news-update-week-9-of-2023%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 9 of 2023","description":"As technology advances, the risks to personal and corporate security increase.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/","datePublished":"2023-02-27T16:25:56.000Z","dateModified":"2025-04-25T12:01:37.000Z","dateCreated":"2023-02-27T16:25:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1280,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/02/spf-permerror.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Cybersecurity News Update, Week 9 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Cybersecurity News Update, Week 9 of 2023","item":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Cybersecurity News Update, Week 9 of 2023","description":"As technology advances, the risks to personal and corporate security increase.","url":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/","datePublished":"2023-02-27T16:25:56.000Z","dateModified":"2025-04-25T12:01:37.000Z","dateCreated":"2023-02-27T16:25:56.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/cyber-security-news-update-week-9-of-2023/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1280,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/02/spf-permerror.jpg","caption":"cybersecurity","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
