Wednesday , February 19 2025
phone
Photo: Websiteplanet

Business Leaders & Celebrities’ Accounts Exposed

Jeremiah Fowler, a cybersecurity researcher, found and informed WebsitePlanet about a database without password protection. It held around 121,000 user accounts of entrepreneurs and business leaders from Clarity.fm, a platform for connecting entrepreneurs with experts.

The database had 155,531 records, including 121,000 member profiles with personal and professional email addresses, hourly rates, past payments for consulting sessions, and internal ratings based on user feedback.

150 Gov.t Portal affected
Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

Indian government and educational websites, along with reputable financial brands, have experienced SEO poisoning, causing user traffic to be redirected...
Read More
150 Gov.t Portal affected  Black-Hat SEO Poisoning Indian “.gov.in, .ac.in” domain

CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

The Cyber Threat Intelligence Unit of BGD e-GOV CIRT has found 600 vulnerable PRTG instances in Bangladesh, affected by the...
Read More
CVE-2018-19410 Exposes 600 PRTG Instances in Bangladesh

Builder claims Rs 150 cr for data loss; AWS faces FIR In Bengaluru

Amazon Web Services (AWS) has been named in an FIR after a builder claimed damages to the tune of Rs...
Read More
Builder claims Rs 150 cr for data loss;  AWS faces FIR In Bengaluru

CISA Warns Active Exploitation of Apple iOS Security Flaw

CISA has issued an urgent warning about a critical zero-day vulnerability in Apple iOS and iPadOS, known as CVE-2025-24200, which...
Read More
CISA Warns Active Exploitation of Apple iOS Security Flaw

Massive IoT Data Breach Exposes 2.7 Billion Records

A major IoT data breach has exposed 2.7 billion records, including Wi-Fi network names, passwords, IP addresses, and device IDs....
Read More
Massive IoT Data Breach Exposes 2.7 Billion Records

SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

A serious authentication bypass vulnerability in SonicWall firewalls, called CVE-2024-53704, is currently being exploited, according to cybersecurity firms. The increase...
Read More
SonicWall Firewall Auth Bypass Vulnerability Exploited in Wild

AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

AMD has released security patches for two high-severity vulnerabilities in its System Management Mode (SMM). If exploited, these could let...
Read More
AMD Patches High-Severity SMM Vulns Affecting EPYC and Ryzen Processors

Lazarus Group Unleashes New Malware Against Developers Worldwide

Lazarus Group has initiated a complex global campaign aimed at software developers and cryptocurrency users. Operation Marstech Mayhem uses the...
Read More
Lazarus Group Unleashes New Malware Against Developers Worldwide

Daily Security Update Dated : 15.02.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated : 15.02.2025

Salt Typhoon to target Bangladeshi Universities, One identified

RedMike (Salt Typhoon) targeted university devices in Bangladesh, likely to access research in telecommunications, engineering, and technology, especially from institutions...
Read More
Salt Typhoon to target Bangladeshi Universities, One identified

Jeremiah Fowler believed the exposed records belonged to San Francisco-based Clarity.fm — a platform that connects entrepreneurs and professionals seeking advice or mentorship with experienced individuals in various fields. But he is not clear if the database was owned or managed by Clarity.fm or a third party contractor, websiteplane report reads.

Exposing personal and business email addresses can create major cybersecurity risks. Companies don’t disclose executive contacts to avoid harassment, spam, and security issues. Business leaders and investors are common targets for cybercriminals because of their wealth and access to funds, making them vulnerable to financial exploitation.

High-profile individuals often have connections to other investors, making them prime targets for cybercriminals. These criminals may try to misuse their personal information for social engineering or other fraudulent activities.

There is a growing risk of CEO fraud, also known as Business Email Compromise (BEC). This is when scammers impersonate the CEO to trick people into revealing sensitive information or making financial transactions. According to Forbes, CEO fraud cost the economy $26 billion from 2013 to 2019. In 2024, a criminal used deepfake technology to convince a finance worker to transfer $25 million. CEO fraud affects nearly 400 companies per day, with around 22,000 victims and $3 billion in losses over three years.

When contact information like personal or work emails is leaked, it’s crucial to take basic cybersecurity steps and reduce risks. It’s also important to inform people if their contact details have been exposed.

The database revealed a cloud storage account for profile pictures. Exposing additional storage accounts poses cybersecurity risks, allowing cybercriminals to launch targeted attacks and exploit vulnerabilities in the storage system or attempt credential theft using social engineering techniques.

According to researchers, nearly 98% of cyber crimes are a result of social engineering campaigns, which involve sharing sensitive information like credentials. This could lead to unauthorized access to the company’s cloud storage, allowing attackers to steal data or disrupt operations. Other serious risks include phishing, malware, and criminals gaining access to sensitive business accounts or internal documents due to exposed usernames and passwords from previous data breaches.

Jeremiah Fowler recommend that regular training sessions should be provided to employees to educate them about different types of social engineering attacks, including CEO fraud. This knowledge will help employees recognize suspicious requests and verify the authenticity of financial transactions, thus preventing fraud and safeguarding against financial loss and data theft. It is important to always verify requests for sensitive information or financial transactions, even if you believe you know the person you are communicating with. Use only official communication channels and known phone numbers to ensure the legitimacy of the interaction. Additionally, establish a clear approval process for financial transactions and changes to sensitive account information, requiring multiple layers of verification from multiple individuals or departments.

(Media Disclaimer: This report is based on research conducted internally and externally using different ways. The information provided is for reference only, and users are responsible for relying on it. Infosecbulletin is not liable for the accuracy or consequences of using this information by any means)

Check Also

January 2025

TRACKING RANSOMWARE
Akira Topped January 2025 as the Most Active Ransomware Threat

In January 2025, there were 510 global ransomware incidents, with Akira as the leading group …

Leave a Reply

Your email address will not be published. Required fields are marked *