French tax authority data breach affects 678,000 individuals
France’s General Directorate of Public Finances (DGFiP) has disclosed a significant data breach affecting approximately 678,000 individuals and businesses after attackers gained unauthorised access to internal tax systems. Investigators determined that the threat actor was able to access and extract sensitive information, including reference tax income, family quotient details, withholding tax rates, company identifiers, and certain property-related records. French authorities have stated that taxpayer online accounts, usernames, and passwords were not compromised; however, the exposed information could still be leveraged in targeted phishing, fraud, identity theft, and social engineering campaigns. The incident, which is currently under investigation with support from France’s national cybersecurity authorities, highlights the continued risk posed by attacks against government systems and the potential impact of large-scale personal data exposure on citizens and businesses.
Medusa ransomware hit over 500 critical infrastructure orgs
The Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and the Department of Health and Human Services (HHS), has warned that the Medusa ransomware operation has compromised more than 500 critical infrastructure organisations in the United States since June 2021. The ransomware-as-a-service (RaaS) group has targeted a wide range of sectors, including healthcare, government services, financial services, information technology, critical manufacturing, and the defence industrial base. According to the updated advisory, Medusa operators commonly obtain initial access through affiliate networks and initial access brokers before exploiting vulnerabilities, moving laterally across networks, exfiltrating data, and deploying ransomware as part of a double-extortion strategy. Federal agencies have urged organisations to prioritise patch management, network segmentation, and restricting access to remote services to reduce the risk of compromise, as the group continues to pose a significant threat to critical infrastructure environments.
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor known as “TheHatman” is claiming to have stolen and is attempting to sell approximately 3.6 million employee records allegedly obtained from the Microsoft Azure environments of several major organisations, including McDonald’s, Vodafone, Tata Consultancy Services (TCS), HCL Technologies, InterContinental Hotels Group (IHG), Gap Inc., and Kyndryl. According to the claims, the data was accessed using compromised credentials and includes employee names, email addresses, job titles, phone numbers, postal addresses, employee IDs, service accounts, and other directory information extracted from Microsoft Entra ID (formerly Azure Active Directory) tenants. While security researchers who reviewed samples believe the data appears authentic, several affected companies, including TCS and Gap, have stated that they found no evidence of a recent breach and suggested the information may be old or limited in scope. Regardless of the source, the exposure of employee directory data, privileged account information, and service account details could increase the risk of phishing, credential theft, social engineering, and targeted attacks against the organisations involved.
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
Security researchers have identified a new macOS information-stealing malware known as AmnesiaStealer, which uses ClickFix-style social engineering techniques and fake GitHub download pages to trick users into executing malicious Terminal commands. Once installed, the multi-stage malware targets a wide range of sensitive data, including Keychain credentials, browser information, Apple Notes, Telegram sessions, documents, and cryptocurrency wallet data. Its most notable capability is a remote browser control module that clones a victim’s Chromium-based browser profile and launches it in headless mode, allowing attackers to interact with active authenticated sessions in real time through the Chrome DevTools Protocol. This enables threat actors to access email, social media, financial, and business accounts without needing to steal passwords or bypass multi-factor authentication directly. The campaign demonstrates the growing sophistication of macOS-targeted threats and highlights the risks posed by social engineering attacks that abuse trusted platforms and user actions to gain initial access.
Analyst Insight
These incidents demonstrate how cyber threats continue to converge around the compromise of trusted identities, sensitive data, and critical services. The breach at France’s tax authority highlights the significant downstream risks associated with large-scale exposure of government-held personal and financial information, which can be leveraged to support targeted phishing, fraud, and identity-based attacks. The continued growth of the Medusa ransomware operation, with over 500 critical infrastructure victims, reinforces the effectiveness of the ransomware-as-a-service ecosystem and the role that initial access brokers and unpatched vulnerabilities play in enabling large-scale compromises. Meanwhile, claims surrounding the theft of millions of employee records from Microsoft Entra ID environments underscore the value threat actors place on corporate directory data, privileged account information, and service accounts, all of which can facilitate reconnaissance, credential attacks, and highly targeted social engineering campaigns. The emergence of AmnesiaStealer also highlights the increasing sophistication of information-stealing malware, demonstrating how attackers are evolving beyond credential theft to hijack authenticated browser sessions and bypass traditional security controls such as multi-factor authentication. Collectively, these developments emphasise the need for organisations to strengthen identity security, reduce privileged account exposure, implement rigorous patch and vulnerability management processes, validate software and data access controls, and maintain continuous monitoring capabilities to detect both opportunistic cybercriminal activity and more advanced intrusion campaigns before they escalate into significant business impacts.
