---
title: "Weekly Cyber News Updates, week 36 of 2022 | DuoCircle"
description: "Cybersecurity has become a constant learning curve, and individuals need cybersecurity awareness to stay protected from the latest cyber attacks and threats to."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/"
---

Quick Answer

Cybersecurity headlines for week 36 of 2022\. Starbucks Singapore confirmed a breach exposing data of 219,675 mobile app customers (names, gender, date of birth, mobile number, email, residential address). The threat actor known as Pompompurin validated the data on a hacking forum and reportedly sold a copy for 3,500 dollars. Starbucks Singapore notified affected customers by letter. The incident continued the year's pattern of regional consumer-app breaches feeding global hacking forums, and reinforced the importance of minimizing personal data collection in mobile apps and segmenting customer databases by region.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Weekly%20Cyber%20News%20Updates%2C%20week%2036%20of%202022&url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F&title=Weekly%20Cyber%20News%20Updates%2C%20week%2036%20of%202022 "Share on Reddit") [ ](mailto:?subject=Weekly%20Cyber%20News%20Updates%2C%20week%2036%20of%202022&body=Check out this article: undefined%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F "Share via Email") 

![cybersecurity updates](https://media.mailhop.org/duocircle/images/2022/09/spf-record-generator-1.jpg) 

Cybersecurity has become a constant learning curve, and individuals need cybersecurity awareness to stay protected from the **latest cyber attacks** and threats to digital lives. Positive and Negative, this week’s [cybersecurity](/) bulletin combines both ends as it brings the top cybersecurity news of the past week.

## Hackers Breach 219,000 Starbucks Customer Accounts

Starbucks Singapore suffered a [data breach](/email-security/top-data-breaches-of-the-year-and-lessons-for-2022/), putting the confidential data of 219,675 customers at risk. The news came as a shock when the threat actor behind the attack offered to sell the stolen database on a hacking forum.

The forum’s owner, Pompompurin, [backed](https://www.zdnet.com/article/starbucks-singapore-says-some-customer-data-leaked/) the validity of the data. This event prompted **Starbucks Singapore** to send out letters to its clientele to notify them of the data breach, highlighting that the victims’ names, gender, date of birth, mobile number, email, and residential address might be at risk. The data breach affected the customers who used the Starbucks mobile application, and the data seller is rumored to have sold a copy of the database for $3500.

The threat actor plans to sell four more copies of the stolen data, opening Starbucks customers up to [phishing](/content/phishing-prevention/what-is-phishing), impersonation, social engineering, and scams.

## Self-Spreading YouTube Malware Targeting Gaming Videos

There is a new self-spreading **YouTube malware** targeting gaming videos of individuals playing popular games such as _FIFA, Forza Horizon, Final Fantasy, Spider-Man, and Lego Star Wars._

The YouTube malware uploads malicious video tutorials instructing users to opt for **fake cheats and cracks**. The videos are accompanied by malware links to such fake cheats to install the malware bundle. [Researchers at Kaspersky](http://securelist.com/self-spreading-stealer-attacks-gamers-via-youtube/107407/) found a RAR archive in the bundle utilizing RedLine, one of the most significant information stealers that target **victims’ web browsers**.

The RAR archive also included a miner to take advantage of high-end gaming PCs of YouTube gamers and streamers by targeting graphics cards to mine cryptocurrency for the threat actors.

The **self-propagating mechanism** of the malware worked with batch files that run executables to steal cookies, download the malicious cheat video, avoid GitHub links reported, and upload the video to the victim’s YouTube account using their cookies. Streamers and gamers who frequently watch YouTube gaming videos are advised to avoid **videos advertising cheats**.

[![Phishing Campaign](https://media.mailhop.org/duocircle/images/2022/09/check-DMARC-record-4593.jpg)](https://media.mailhop.org/duocircle/images/2022/09/check-DMARC-record-4593.jpg)

## Iranian Cyber Criminals Utilize New Sock Puppet Phishing Campaign

An Iranian-aligned cybercriminal group was discovered using a sock puppet phishing campaign. The group, TA453, utilized a multi-persona impersonation technique to employ [social engineering](https://www.tessian.com/blog/examples-of-social-engineering-attacks/) and boost the trustworthiness of phishing emails.

The threat actors impersonated journalists and medical professionals to target academics, policy experts, and healthcare professionals. The threat actors used fake personas to generate **unsolicited email conversations**. The multi-persona impersonation approach kicked in as the initial email was CC’d to other fake personas who joined the conversation later to obscure the logical thinking of the targets.

The email conversations often ended with a phishing link to **OneDrive documents** that downloaded files laced with malicious macros. **Korg**, the name given to the download template, is a sophisticated malicious payload that utilizes its macros to gather and **exfiltrate information** from the user’s devices.

The sock puppet campaign was analyzed by [Proofpoint](https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo), which points out that the exfiltrated data has not been misused till now, indicating the possibility of future harm or another wave of malice at the end of cybercriminals.

## The US Recovers $30 Million in Crypto from Lazarus Hackers

The United States government recovered $30 million in cryptocurrency with blockchain specialists and its FBI (Federal Bureau of Investigation). The amount recovered was stolen by Lazarus, a **North Korean cybercriminal** group who stole the amount from the popular P2E (Play to Earn) game, Axie Infinity.

The news was dropped at the [AxieCon event](https://www.youtube.com/watch?t=20678&v=Y8FLGoWpsLU&feature=youtu.be), highlighting the recovery as a community achievement and the result of expert collaboration between government and private entities. Lazarus members followed a **5-stage approach** to steal the crypto from the platform, sending it to intermediary wallets, mixing the stolen Ether in batches with Tornado Case, swapping it for Bitcoin, and mixing the Bitcoin in batches once more.

**Chainalysis’ Crypto Incident Response** team also played a role in recovering the stolen crypto assets as they were able to trace the chain-hopping mechanism. The government utilized advanced tracing techniques to track the $30 million in crypto to cash points and quickly froze the funds once discovered.

An estimated [$620 million](https://www.bleepingcomputer.com/news/cryptocurrency/620-million-in-crypto-stolen-from-axie-infinitys-ronin-bridge/) was stolen by Lazarus as part of its hack. However, the event has established that crypto is not simple to launder or cash out. The recovered money will gradually circulate back into Axie Infinity’s treasury and its community.

## Greek Taxpayers Targeted by Phishing Links with Keyloggers

Greek individuals are targeted by a **unique phishing campaign** impersonating the official tax refund platform. The phishing page is identical to the official one and has an embedded keylogger that supplies victims’ credentials to the [threat actors](/email-security/threat-actors-abuse-linkedins-smart-links-in-evasive-email-phishing-attacks/).

The threat actors initiate an email thread impersonating the **Hellenic Tax Office** about a tax return amount. The email is accompanied by a phishing link to multiple crafted URLs (Uniform Resource Locators) that take the victim to a fake portal designed to add the details of the beneficiary bank account needed due to **validation issues**, as pointed out in the email.

The phishing page includes seven major Greek banks, taking the user to another **phishing page** as per the selection. These pages are also fake login portals themed after the specific bank and include a JavaScript keylogger to **capture all keystrokes** sent to the threat actor’s server.

The [keylogger](https://www.upguard.com/blog/what-is-a-keylogger#:~:text=A%20keylogger%20is%20a%20type,more%20than%20steal%20keyboard%20strokes.) approach allows threat actors to **steal login credentials** in real time without the need to log in at the victim’s side. Greek users should look out for unsolicited tax return emails requiring them to add beneficiary account details and report them.

[![threat actors](https://media.mailhop.org/duocircle/images/2022/09/What-is-a-DMARC-6619.jpg)](https://media.mailhop.org/duocircle/images/2022/09/What-is-a-DMARC-6619.jpg)

## Classified NATO Documents on the Dark Web

The EMGFA (Armed Forces General Staff Agency) of Portugal, the central agency that controls, plans, and operates the armed forces of Portugal, suffered a severe cyberattack.

American cyber-intelligence agents were the first to identify the sale of **NATO documents** on the dark web for interested parties. The news was conveyed to the US embassy in Lisbon, which tipped the Portuguese about the data breach, following which Portugal’s **GNS (National Security Office)** and national cybersecurity center deployed a team to aid the EMGFA in a complete network scan to identify the threat.

The NATO documents available for sale on the dark web were [reported by a local news channel](https://www.dn.pt/sociedade/documentos-portugueses-da-nato-apanhados-a-venda-na-darkweb--15146671.html), which validated the information by unnamed sources, outlining the leaked document of “extreme gravity.”

The EMMGFA has not released any official statement on the data breach. Still, experts believe it was a prolonged and undetected attack where threat actors utilized **bots programmed** to detect documents of specific nature to steal information.

## 200,000 Accounts Compromised in Corporate Credential Stuffing Attack

The North Face, an apparel business, suffered a credential stuffing attack that compromised the accounts of nearly 200,000 individuals.

The threat actors utilized fake login information from **prior data breaches** to attack individuals who reused the same password for their [North Face](https://www.thenorthface.com/en-us?%5Fsr=1) accounts. _Hackers were able to steal the victim’s full names, mobile numbers, gender, account creation date, order history, loyalty points, billing, and shipping information._

Since the brand does not store credit card information, the financial information of its clientele is safe. However, this is the second time that North Face has suffered a credential stuffing attack, the prior one occurring in 2020.

The North Face issued a notification to inform its customers about the breach. It has asked everyone to reset their passwords and remain vigilant for [phishing attacks](/resources/how-does-a-phishing-attack-work) from email senders impersonating its staff members.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F) [ ](https://twitter.com/intent/tweet?text=Weekly%20Cyber%20News%20Updates%2C%20week%2036%20of%202022&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fannouncements%2Fweekly-cyber-news-updates-week-36-of-2022-2%2F) Copy 

Related Articles

- [ ![spam](https://media.mailhop.org/duocircle/images/2021/07/sender-policy-framework-7535.jpg)  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam News ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)
- [ ![Cyber Security](https://media.mailhop.org/duocircle/images/2022/01/spf-flattening-7011.jpg)  Cyber Security News Update, Week 1 of 2022 News ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)
- [ ![Cybersecurity](https://media.mailhop.org/duocircle/images/2023/01/spf-validator-6824.jpg)  Cybersecurity News Update, Week 1 of 2023 News ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)
- [ ![cybersecurity](https://media.mailhop.org/duocircle/images/2024/01/phishing-protection.jpg)  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\] News ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

## Related Articles

[  News 3m  Alert: Fix SPF & DKIM Settings For Your Email Forwarding Set Up Through Microsoft o365 SMTP Server Or Your Emails May End Up In Spam  Jul 20, 2021 ](/blog/announcements/alert-fix-spf-dkim-settings-for-your-email-forwarding-set-up-through-microsoft-o365-smtp-server-or-your-emails-may-end-up-in-spam/)[  News 6m  Cyber Security News Update, Week 1 of 2022  Jan 7, 2022 ](/blog/announcements/cyber-security-news-update-week-1-of-2022/)[  News 7m  Cybersecurity News Update, Week 1 of 2023  Jan 1, 2023 ](/blog/announcements/cyber-security-news-update-week-1-of-2023/)[  News 5m  EasyPark Data Breach, Ohio Lottery Cyberattack, GTA 5 Leak, Cybersecurity News \[December 25, 2023\]  Jan 4, 2024 ](/blog/announcements/cyber-security-news-update-week-1-of-2024/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Weekly Cyber News Updates, week 36 of 2022","description":"Cybersecurity has become a constant learning curve, and individuals need cybersecurity awareness to stay protected from the latest cyber attacks and threats to.","url":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/","datePublished":"2022-09-23T16:42:20.000Z","dateModified":"2025-05-23T16:54:57.000Z","dateCreated":"2022-09-23T16:42:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1256,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/09/spf-record-generator-1.jpg","caption":"cybersecurity updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"News"},{"@type":"ListItem","position":3,"name":"Weekly Cyber News Updates, week 36 of 2022","item":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"News","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Weekly Cyber News Updates, week 36 of 2022","item":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Weekly Cyber News Updates, week 36 of 2022","description":"Cybersecurity has become a constant learning curve, and individuals need cybersecurity awareness to stay protected from the latest cyber attacks and threats to.","url":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/","datePublished":"2022-09-23T16:42:20.000Z","dateModified":"2025-05-23T16:54:57.000Z","dateCreated":"2022-09-23T16:42:20.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/announcements/weekly-cyber-news-updates-week-36-of-2022-2/"},"articleSection":"announcements","keywords":"News, Security, Updates","wordCount":1256,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2022/09/spf-record-generator-1.jpg","caption":"cybersecurity updates","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
