A 16-Year-Old Ransomware Kingpin, FBI Patch Fails, and Leaked Pentagon Records: Another Bad Week in Infosec | #ransomware | #cybercrime


It’s been a rough week for hackers looking to stay out of jail. Europol announced that it identified the leader of KillSec, a ransomware group allegedly responsible for an international extortion and data-theft spree. The kicker? He’s 16 years old. On top of that, the FBI revealed that a hacker allegedly linked to ShinyHunters was detained in Jordan this week (while simultaneously blaming its embarrassing data breach on a contractor who didn’t update software with a known vulnerability).

In other news, if you thought it’s only the United States that’s been struggling with the intersection between VPNs for privacy and state-sponsored mass surveillance, think again: A newly proposed Canadian law could make it difficult for VPNs in the country, and one company is even threatening to leave as a result. If you’re thinking about signing up for a VPN, now’s the time to take a look at the best ones available. It might sound counterintuitive, but you’re better off being prepared than caught on the back foot later. 

While we’re on that topic: Steer clear of no-name free VPNs. Scammers love them and hope you’ll download theirs and give them all of your data, or worse, access to your device. Just remember, while a VPN is an essential part of your security toolkit and will keep your ISP from snooping on you, it also keeps tabs on some things you do, so shop smart.

Now, let’s see what else is going on in the infosec world this week. 


Pentagon Breach Imperils Social Security Numbers and Military Records of Millions

Last week, the US Department of Defense announced that a breach of Pentagon personnel records at the Defense Manpower Data Center (DMDC) had impacted millions, according to both TechCrunch and CNN. The attackers responsible made off with Social Security numbers, names, dates of birth, military service records, civilian employment records, and, in some cases, even more details about specific people’s specialties and contact information. The attackers apparently had access to the servers storing the data for months, from October 2025 to July 2026, and, even worse, the data was unencrypted. It’s a bad look, but it’s not the first time we’ve covered a breach at the Pentagon. 

According to the Malwarebytes Blog, the department is already reaching out to affected individuals and offering the usual 12 months of credit and identity monitoring to help prevent misuse of the data. However, while the risk of the data being used for phishing or identity theft is real, others worry that it’s more valuable to people collecting information on defense personnel, both civilian and military, for other, less commercial purposes. CNN reports that 2.76 million living individuals had their data stolen, possibly including current and former defense personnel or their dependents, and 294,000 deceased individuals. Keep an eye on your inboxes.


500,000 Active Credentials Left Exposed on GitHub

I know we just discussed GitHub’s problems two weeks ago, but here’s a fresh one: Active usernames and passwords are exposed on the site, making them easy for anyone to exploit. SecurityWeek reports that researchers at Truffle Security identified more than a million exposed credentials in a scan of the site back in 2025, and after following up with a subsequent scan here in 2026, they found that over half of those—543,699, to be exact—remain exposed and unrevoked. This is even after GitHub took action to clamp down on the problem after the 2025 report. The company started scanning repositories for credentials, began alerting users that their credentials were exposed, and even set up default push protections to prevent affected repositories from being duplicated. 

However, GitHub’s measures don’t require users to revoke any credentials left exposed in a repo, and some developers continue hard-coding, even though it’s considered both lazy development and exceptionally poor security. That means they keep spreading, and the problem keeps growing. To its credit, GitHub is trying to address a problem it didn’t create, but the company will probably have to do more to stop it at this point.


South Korea Probes Bank Breaches Amid Suspected AI-Powered Attacks

You didn’t think we’d get out of this week without some AI-powered hacking, did you? This is some of the worst kind, too: Hackers targeted several South Korean financial institutions, including Shinhan Bank, Kookmin Bank, and others, according to Bleeping Computer. South Korea’s Financial Services Commission (FSC) held an emergency meeting earlier this month to address the attacks and told the public that, while on-site investigations are already underway, the attacks don’t appear to indicate that any particular known threat actor is responsible. Meanwhile, Yonhap, a Korean news agency, reported that one server used in the attacks contained language associated with ARTEX AI, an open-source penetration testing tool 

The breaches don’t seem to be about money. Instead, they’re about data, which might as well be the web’s real currency. Each of the banks involved reported tens of thousands of customers having had their data stolen, and officials are warning all financial institutions in the country to shore up their systems and share threat information with one another to coordinate a response.


Ask Our Expert: How Did a Breach Here Lead to a Breach There?

Do you have a question about online privacy or security? I’m here to help! You can submit your question here, and I may answer it in an upcoming SecurityWatch column and newsletter. If you’re not subscribed to the newsletter, head here to sign up, and check back each week for the latest updates from PCMag’s security team. Now, on to this week’s question! 

An anonymous reader asks: I’ve heard that there have been multiple hacks using AOL and then into credit unions. How do they get to the bank with a separate login and password?

Thanks so much for your question! This one is a little tricky, and what’s likely to have happened here is actually a little different from your question, but I’ll try to address both possibilities. 

Recommended by Our Editors

First of all, these types of things definitely happen; it’s not just an AOL thing. Sure, AOL is kind of an easy target because it’s been around for a while, and its customers are often older adults or longtime customers. But this could happen with any service and any data breach, so if you saw AOL here and rolled your eyes, lock back in, because this matters to you, too. 

Now, when your information is lost in a data breach, the first thing hackers do, if they don’t sell it on the dark web, is try to decrypt the data using known methods to see if they can extract something useful. If they do, or if the data isn’t encrypted in the first place, they try to use it immediately. So let’s say someone got a hold of some old AOL credentials. They may test them on AOL to see if they still work, but it’s more likely they’d try those same credentials elsewhere to see if they work on higher-value sites, such as credit unions, banks, and other financial institutions. 

The most sophisticated hackers compile leaked data into complete profiles of specific users, which can be used to target the services they’re known to use. So, for example, a group may already have a user profile and know who they use for email, what their account names are, which banks they use, where they shop, and so on. They may even already try to log in using older credentials leaked on the web, so when a new drop appears, they’ll grab the data and try again. That’s how someone might go from a leaked AOL password to a breached credit union account. After all, a hacker probably doesn’t care about what’s in your AOL account, but they’d love access to your bank and the money inside, or even any connected accounts of family and friends they can use for spearphishing or deepfake attacks.

Now, let’s back up a moment, and let’s say the password for that AOL account isn’t the same as the password for the credit union. In that case, the issue may still go back to that profile I mentioned. After all, it’s not just advertisers and data brokers who make highly detailed profiles of you. A new leak containing updated information about you might be the missing piece a hacker needs to access a completely different set of accounts. For example, maybe they had leaked credentials for a credit union account, but they didn’t have the recovery email used for it. Well, now that the AOL account has been breached, they do. Or maybe they knew they had a credit union password and an AOL account associated with it, but didn’t know which AOL account, and that part was just leaked in a new breach. 

Even worse, AI makes compiling and cross-referencing all of this data much easier than it used to be. Where hackers used to either have to keep track of it themselves, develop the tools to do it, or get those tools from other hacking groups, now it’s as simple as asking an AI chatbot to do the work for them, or vibe code a tool for it, so they stay under the radar of the AI company they use.

Your best defense, as always, is simple: good internet hygiene. Use a password manager to keep track of all your credentials and let it generate strong, unique passwords for every account. Do your best to avoid phishing attacks and other scams, and don’t just brush off data breaches when they happen. Take action to protect your accounts and data if any are compromised in a breach. Some tools will even alert you to those breaches so you can be proactive about changing passwords and keeping an eye on your personal data to make sure that if it leaks, it’s not useful to anyone, and personal data removal services will work to scrub whatever they can from the web so it doesn’t fall into the wrong hands.





Click Here For The Original Source.

——————————————————–

..........

.

.