WideOpenWest (WOW!), a major U.S. internet service provider, has reportedly fallen victim to Arkana, a newly emerging ransomware group. The attack, which stems from an infostealer infection in September 2024, is said to have compromised more than 403,000 customer accounts and granted attackers access to critical backend systems. This marks Arkana’s first high-profile breach, demonstrating their technical capabilities. The hackers gained access by exploiting two key platforms: AppianCloud, used for customer management, and Symphonica, which handles business workflows. Their entry point was traced back to stolen login credentials obtained from an employee’s device that had been infected with infostealer malware months prior to the ransomware deployment. To showcase their level of control, Arkana released a music video montage displaying their ability to manipulate network settings, access customer data, and modify server code. Cybersecurity experts suggest that the absence of multi-factor authentication (MFA) and weak network segmentation may have contributed to the breach. Arkana claims to have exfiltrated a vast amount of sensitive information, including usernames, passwords, security questions, email addresses, and account details. Additionally, they allege the theft of 2.2 million records containing personally identifiable information such as names, phone numbers, and device details. In an attempt to pressure WOW! into meeting their demands, the group publicly released personal details of the company’s CEO, Teresa L. Elder, and threatened further leaks if a ransom was not paid. This incident underscores the growing threat posed by infostealer malware as a precursor to ransomware attacks. Experts emphasize the importance of continuous credential monitoring, stronger authentication measures, and enhanced security controls to prevent such breaches. As of now, WOW! has not officially confirmed the incident.
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...
The FBI has issued a warning highlighting potential security and privacy risks associated with widely used mobile applications developed by Chinese companies. These applications, a...