<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[HumanSecIQ]]></title><description><![CDATA[HumanSecIQ helps organizations identify, measure, and reduce cybersecurity risk through Human Risk and AI Governance Assessments.]]></description><link>https://www.humanseciq.com/blog</link><generator>RSS for Node</generator><lastBuildDate>Fri, 11 Sep 2026 16:57:59 GMT</lastBuildDate><atom:link href="https://www.humanseciq.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Co-op Cyber Incident 2025: Third-Party Access and the Decision to Disconnect]]></title><description><![CDATA[The third UK retailer hit in a two-week wave detected its intruders in hours, cut its own network before the ransomware could fire, and never paid a penny. It still lost the data of all 6.5 million members and £206 million in sales. This is what the good outcome costs. Case type: Social engineering / attempted ransomware / data theft       Identified: Apr 22, 2025   Disclosed: Apr 30, 2025  Attribution: Scattered Spider affiliates / DragonForce RaaS Every breach in this series so far is a...]]></description><link>https://www.humanseciq.com/post/co-op-cyber-incident-2025-third-party-access-and-the-decision-to-disconnect</link><guid isPermaLink="false">6a4137213c06bdad5423d180</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 29 Jul 2025 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Marks &#38; Spencer Cyber Incident 2025: Help Desk Social Engineering and Identity Risk]]></title><description><![CDATA[The first and hardest-hit target of the UK retail wave. A few minutes of impersonation at an outsourced service desk, weeks of quiet access, every domain password reportedly harvested, and then the encryptor. M&#38;S never said whether it paid. Its accounts said statutory profit fell from $509 million to $4.4 million. Case type: Social engineering / ransomware Identified: Apr 19–21, 2025   Disclosed: Apr 22, 2025   Attribution: Scattered Spider (reported) / DragonForce ransomware Testifying to...]]></description><link>https://www.humanseciq.com/post/marks-spencer-cyber-incident-2025-help-desk-social-engineering-and-identity-risk</link><guid isPermaLink="false">6a4136a33c06bdad5423d059</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 17 Jun 2025 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Harrods Cyber Incident 2025: When Identity Defenses Actually Work]]></title><description><![CDATA[The third target of the UK retail wave cut its own internet access, kept trading, and said almost nothing. The wave broke against it. Months later, 430,000 customer records left anyway, through a supplier Harrods has never named. Both halves are the story Case type: Attempted intrusion / third-party data breach     Identified: Late Apr 2025; Sept 2025   Disclosed: May 1, 2025; Sept 26, 2025 Attribution: Wave linked to Scattered Spider / DragonForce; Sept actor unnamed By the time the...]]></description><link>https://www.humanseciq.com/post/harrods-cyber-incident-2025-when-identity-defenses-actually-work</link><guid isPermaLink="false">6a4136e397220de384b14062</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 03 Jun 2025 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Change Healthcare Breach 2024: Identity Controls and Industry-Wide Risk]]></title><description><![CDATA[One legacy portal without multi-factor authentication. Nine quiet days. Then a third of American healthcare stopped being able to pay for itself, 190 million people's medical data left, and a $22 million ransom was stolen by the ransomware gang from its own affiliate, who extorted again anyway. Case type: Ransomware / critical infrastructure disruption   Identified: Feb 21, 2024  Disclosed: Feb 21, 2024  Attribution: ALPHV/BlackCat affiliate; second extortion via RansomHub In late February...]]></description><link>https://www.humanseciq.com/post/change-healthcare-breach-2024-identity-controls-and-industry-wide-risk</link><guid isPermaLink="false">6a4135a597220de384b13da1</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 05 Nov 2024 05:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Snowflake Breaches 2024: Credential Theft and Shared Responsibility]]></title><description><![CDATA[No one hacked Snowflake. Attackers took passwords harvested by commodity malware, some stolen back in 2020 and never changed, and logged into customer data warehouses that asked for nothing more. Roughly 165 organizations, 560 million Ticketmaster records, nearly every AT&#38;T customer's call history, and a guilty plea two years later. Case type: Credential abuse / cloud data theft / extortion      Identified: May 23, 2024   Disclosed: May 31, 2024 Attribution: UNC5537 / ShinyHunters In the...]]></description><link>https://www.humanseciq.com/post/snowflake-breaches-2024-credential-theft-and-shared-responsibility</link><guid isPermaLink="false">6a4135ff97220de384b13e46</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Thu, 01 Aug 2024 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[CDK Global Cyberattack 2024: Vendor Concentration and Industry-Wide Disruption]]></title><description><![CDATA[One software company went down and roughly 15,000 car dealerships went back to pen and paper in the middle of quarter-end. A restoration that got knocked down mid-recovery, a reported $25 million ransom, and over a billion dollars in dealer losses that the ransom did nothing to prevent. Case type: Ransomware / SaaS supply chain outage      Identified: Jun 18, 2024   Disclosed: Jun 19, 2024 Attribution: BlackSuit (Royal / Conti lineage) On the morning of June 19, 2024, thousands of car...]]></description><link>https://www.humanseciq.com/post/cdk-global-cyberattack-2024-vendor-concentration-and-industry-wide-disruption</link><guid isPermaLink="false">6a4136526e9b33148fbd23b1</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 23 Jul 2024 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[MOVEit Transfer Breach 2023: Third-Party Risk at Scale]]></title><description><![CDATA[No one at 2,700 organizations clicked anything. Over a single holiday weekend, a zero-day in a trusted file-transfer product let a ransomware crew steal data at industrial scale, from companies, agencies, and universities, many of which had never heard of MOVEit until it took their data. Case type: Supply chain / zero-day exploitation       Identified: May 28–30, 2023   Disclosed: May 31, 2023 Attribution: Clop (TA505 / FIN11) Organizations spend enormous effort securing their own...]]></description><link>https://www.humanseciq.com/post/moveit-transfer-breach-2023-third-party-risk-at-scale</link><guid isPermaLink="false">6a41351c69b2dfbbf125fc1b</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 09 Jan 2024 05:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[23andMe Breach 2023: Credential Stuffing and the Cost of Password Reuse]]></title><description><![CDATA[Nobody broke into 23andMe. Old passwords from other companies' breaches were tried at the front door for five months, and about 14,000 still worked. A feature built to connect genetic relatives did the rest, exposing 6.9 million people, most of whom did nothing wrong. Case type: Credential stuffing / data scraping    Identified: Oct 5, 2023  Disclosed: Oct 6, 2023 Attribution: Actor using the handle "Golem" Organizations invest heavily in cybersecurity technologies, security monitoring, and...]]></description><link>https://www.humanseciq.com/post/23andme-breach-2023-credential-stuffing-and-the-cost-of-password-reuse</link><guid isPermaLink="false">6a4134cc6e9b33148fbd2097</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Sat, 09 Dec 2023 05:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[MGM Resorts Breach 2023: Business Continuity and Operational Resilience]]></title><description><![CDATA[Part one told how a ten-minute phone call breached MGM. This is what the next ten days cost: dark slot floors, handwritten check-ins, a refusal to pay, and a $100 million lesson in what operational resilience actually means. Case type: Ransomware / operational disruption  Identified: Sept 10, 2023   Disclosed: Sept 11, 2023 Attribution: Scattered Spider / ALPHV Part one of this case examined how a ten-minute phone call gave attackers the keys to MGM Resorts. This companion piece examines what...]]></description><link>https://www.humanseciq.com/post/mgm-resorts-breach-2023-business-continuity-and-operational-resilience</link><guid isPermaLink="false">6a41357297220de384b13d3b</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 17 Oct 2023 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[MGM Resorts Breach 2023: Help Desk Social Engineering and Operational Risk]]></title><description><![CDATA[A social engineering attack against MGM Resorts turned an identity-verification failure into widespread operational disruption. The incident shows how help desk processes, trusted identities, and human decisions can become part of the security boundary.]]></description><link>https://www.humanseciq.com/post/mgm-resorts-breach-2023-social-engineering</link><guid isPermaLink="false">6a41340c69b2dfbbf125fa0c</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 10 Oct 2023 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Caesars Entertainment Breach 2023: Social Engineering, Vendor Risk, and Extortion]]></title><description><![CDATA[Three weeks before MGM went dark, the same attackers called a help desk that worked for Caesars, and walked away with the loyalty database. No outage, no headlines at first, a negotiated ransom, and zero guarantees the data was ever deleted. Case type: Social engineering / vendor compromise / extortion Identified: Sept 7, 2023  Disclosed: Sept 14, 2023 Attribution: Scattered Spider (UNC3944) On August 18, 2023, attackers associated with Scattered Spider targeted the help desk of an outsourced...]]></description><link>https://www.humanseciq.com/post/caesars-entertainment-breach-2023-social-engineering-vendor-risk-and-extortion</link><guid isPermaLink="false">6a41345b97220de384b13ac9</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Sat, 23 Sep 2023 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[LastPass Breach 2022: Credential Security, Access, and Vendor Risk]]></title><description><![CDATA[What began as a compromised developer environment became a second-stage intrusion into cloud backup storage. The LastPass breach shows how credentials, privileged access, third-party software, and interconnected systems can turn one compromise into broader organizational risk.]]></description><link>https://www.humanseciq.com/post/lastpass-breach-2022-credential-security</link><guid isPermaLink="false">6a4133713c06bdad5423c996</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Thu, 12 Jan 2023 05:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Uber Breach 2022: MFA Fatigue and the Human Cost of One Approved Request]]></title><description><![CDATA[A contractor's stolen credentials, repeated MFA prompts, and one approved request gave an attacker access to Uber's internal systems. This breach shows how identity controls can fail when attackers exploit both technology and predictable human behavior.]]></description><link>https://www.humanseciq.com/post/uber-breach-2022-mfa-fatigue</link><guid isPermaLink="false">6a4132773c06bdad5423c7a2</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Mon, 07 Nov 2022 05:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Optus Breach 2022: API Exposure and the Cost of Weak Governance]]></title><description><![CDATA[No phishing, no malware, no stolen credentials. A four-year-old coding error, a forgotten domain, and an API that never asked who was calling exposed the records of roughly 9.5 million Australians. Some breaches aren't broken into. They're walked into. Case type: Data exposure / unauthenticated API Identified: Sept 20, 2022  Disclosed: Sept 22, 2022 Attribution: Unidentified actor, handle "optusdata" Cybersecurity breaches are often measured in records exposed, systems compromised, or...]]></description><link>https://www.humanseciq.com/post/optus-breach-2022-api-exposure-and-the-cost-of-weak-governance</link><guid isPermaLink="false">6a4133cb6e9b33148fbd1e9d</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Tue, 04 Oct 2022 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Cisco Breach 2022: MFA Fatigue and the Limits of a Trusted Login]]></title><description><![CDATA[Stolen credentials, repeated MFA prompts, and voice phishing gave an attacker access to Cisco's corporate VPN. The incident shows how trusted identities can become attack paths when authentication depends on both technical controls and human decisions.]]></description><link>https://www.humanseciq.com/post/cisco-breach-2022-mfa-fatigue</link><guid isPermaLink="false">6a41332869b2dfbbf125f857</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Thu, 01 Sep 2022 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item><item><title><![CDATA[Twilio Breach 2022: SMS Phishing and the Limits of MFA]]></title><description><![CDATA[SMS messages impersonating Twilio's IT team directed employees to fraudulent login pages, allowing attackers to capture credentials and access internal systems. The breach shows how phishing-resistant authentication and identity controls matter when attackers target the login process itself.]]></description><link>https://www.humanseciq.com/post/twilio-breach-2022-sms-phishing</link><guid isPermaLink="false">6a4132c03c06bdad5423c838</guid><category><![CDATA[Breach Analysis]]></category><pubDate>Mon, 15 Aug 2022 04:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/7a7e1d_a48405f092e14955b722ff75d5732465~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Rebecca Guy</dc:creator></item></channel></rss>