Tuesday Morning Threat Report: Dec 30, 2025
The FBI warns AI images are being used in kidnapping scams, and 20+ million Aflac customers’ data is exposed in a breach
Tuesday Morning Threat Report: Dec 30, 2025
Where the news is always bad, but the analysis is always good.

Image by Markus Spiske on Pixabay
Good morning everybody! Happy Tuesday!
The FBI warns AI images are being used in kidnapping scams, and 20+ million Aflac customers’ data is exposed in a breach. Let’s dive in!
Top Stories:
This week’s biggest headlines. Analysis section below.
**FBI Warns AI-Manipulated Photos Used in Kidnapping Scams**: The FBI has warned that scammers are using publicly posted photos from social media, altering them with AI to make it look like the person is kidnapped, and then using the fake images to extort their families.
**86 Million Audio Files Stolen from Spotify by Anna’s Archive**: Anna’s Archive, a copyright-violating search engine, claims it has scraped 86 million audio files from Spotify and intends to release them publicly for free in the coming days.
**Chinese Scammers Use AI Images to Collect Refund Payouts**: Scammers in China are buying products, using AI to create hyper-realistic fake images showing the items as damaged, and submitting those images to fraudulently claim refunds.
**European Regulators Fine Apple for Limiting Targeted Ads**: Apple was fined $116 million by the Italian Competition Authority for mandating that all App Store apps follow its App Tracking Transparency framework, which requires companies to get user consent before tracking.
**University of Phoenix Breach Impacts 3.5 Million**: The University of Phoenix was breached by the Cl0p ransomware group by exploiting a vulnerability in Oracle E-Business Suite. The attack affected 3.5 million current and former students, exposing their names and bank routing numbers.
**MongoDB Vulnerability “MongoBleed” Under Active Exploitation**: A new vulnerability, dubbed “MongoBleed,” enables attackers to steal data from MongoDB databases without authentication. The flaw is being actively exploited, and an estimated 87,000 databases remain exposed worldwide.
**South Korea to Require Face Scans Prior to Buying SIM Card**: To combat scams, South Korea announced that mobile operators must verify new customers’ identities with a facial scan before issuing a phone number.
**Ubisoft’s Help Desk in India Bribed to Steal Customer Information*: Ubisoft, a French video game company behind major titles like Assassin’s Creed*, experienced a security breach after staff at its India-based help desk accepted bribes and shared customer information.
My Takeaways
Analysis based on this week’s news and my experience in the industry. More headlines below in the Lower Echelon.
Offshoring Help Desk: This week’s article describes a security breach at Ubisoft where hackers exploited weaknesses in the company’s support operations rather than directly breaching backend systems. Vx Underground detailed how Ubisoft’s help desk staff in India allegedly accepted bribes in exchange for access to customer information, including full names and IP addresses. This kind of insider vulnerability reportedly enabled attackers to take over Rainbow Six Siege video game accounts and contributed to broader security issues for the publisher.
A similar pattern of help desk‑linked compromise has emerged in a major lawsuit involving Clorox and Cognizant, an Indian IT services giant. In a complaint filed in California state court, Clorox alleges that in August 2023 hackers from the Scattered Spider group gained access to its network because Cognizant’s help desk staff provided employee login credentials and reset multi‑factor authentication without verifying the caller’s identity. Clorox says this lapse allowed attackers to penetrate its systems and cause widespread operational disruption, with the company seeking around $380 million in damages for remediation costs and business losses. The case is ongoing, and Cognizant has denied liability, arguing its role was limited to basic help desk services.
Both cases underscore that help desks are not just customer service roles, they perform a critical security function by controlling access to sensitive systems and data. When companies outsource these functions to underpaid or undertrained staff in lower-wage regions, they create vulnerabilities that cybercriminals are eager to exploit. Hackers can easily bribe employees who lack proper incentives or training, turning cost-saving measures into major financial and reputational risks. This highlights the importance of adequately compensating, training, and monitoring help desk personnel to ensure they act as a strong line of defense rather than a weak point in an organization’s security.
The Lower Echelon:
Interesting cybersecurity news that didn’t quite make the cut to be a top story.
**Aflac Data Breach Impacts 20+ Million Customers**: Aflac reported that a sophisticated cybercrime group breached its systems, exposing personal data, including Social Security numbers and government ID numbers, belonging to 22.65 million customers.
**Operation Sentinel Arrests Hundreds and Recovers $3 Million**: A coordinated law enforcement operation across 19 African countries, led by Interpol, resulted in the arrest of 574 suspects and the recovery of $3 million from cybercrime syndicates.
**Open Source AI KawaiiGPT Enables Anyone to Write Malware**: KawaiiGPT is a free, open-source AI that allows anyone to create malware or launch ransomware campaigns, raising concerns among researchers about lowering the barrier to cybercrime.
**Critical Vulnerability Uncovered in LangChain**: LangChain, a Python package that helps developers connect their applications with AI models, contains a critical vulnerability that could let attackers steal data or manipulate the AI model.
**Researchers Disclose Vulnerability, Company Alleges Blackmail**: After penetration testers found a flaw in Eurostar’s AI chatbot, they reported it through the company’s official vulnerability disclosure program. Eurostar misplaced the submission, and when the testers later followed up with the company’s head of security, he accused them of attempted blackmail.
**NPM Package with 50,000+ Downloads Steals WhatsApp Credentials**: “Lotusbail,” an NPM package available for six months with 56,000 downloads, is malware that steals WhatsApp credentials and monitors all messages sent and received on the account.
**Ukrainian Hacker Pleads Guilty to Ransomware Involvement**: Artem Aleksandrovych Stryzhak, a Ukrainian national, pleaded guilty to U.S. charges for his role in the Neifilim ransomware group.
**Personal Information on 21,000 Nissan Customers Leaked**: Nissan confirmed that hackers known as the Crimson Collective stole personal data, such as names and phone numbers, for 21,000 customers by breaching Red Hat’s GitLab.
On the right side of this page, you can follow and subscribe to receive this newsletter to your inbox weekly (no Medium account needed, just sign in with Google)!
Thanks for reading! See everyone next week!
메타데이터
- post_id
- 47d49a3dbd00
- slug
- tuesday-morning-threat-report-dec-30-2025-47d49a3dbd00
- url
- https://medium.com/@cyber_securiti/tuesday-morning-threat-report-dec-30-2025-47d49a3dbd00
- canonical_url
- https://medium.com/@cyber_securiti/tuesday-morning-threat-report-dec-30-2025-47d49a3dbd00
- author_url
- https://medium.com/@cyber_securiti
- status
- ok
- fetched_at
- 2026-06-22 12:55:45