Latest / Tech Talks With Kinsoft / ADT – ShinyHunters Vishing Breach Hits 5.5M
Transcript
- 0:00Welcome to Tech Talks with Kinsoft. You know,
- 0:02ADT's entire brand is basically built on securing
- 0:05perimbers, right? Oh, absolutely. They're the
- 0:07ones you pay to lock down your physical house.
- 0:09Exactly. You put their sensors on every window,
- 0:11you have them monitor the alarms, all of that.
- 0:13But last month, attackers walked away with the
- 0:17personal data of 5 .5 million ADT customers.
- 0:21Which is just a staggering number. It really
- 0:24is. And the craziest part is that those attackers
- 0:26didn't have to break a single digital lock or
- 0:29burn some advanced zero -day exploit or even
- 0:32breach a firewall to do it. They literally just
- 0:34picked up the phone. Yeah, it's wild. So our
- 0:37mission today is to unpack this massive April
- 0:392026 data breach. We're relying on a really detailed
- 0:44security report from the ISMG Network's Bank
- 0:46Info Security, written by Matthew J. Schwartz.
- 0:49And we're looking at... Well, really, this cascading
- 0:52failure of centralized login systems and the
- 0:54inherent risks of human trust. Right, because
- 0:56this report is, honestly, it's a sobering look
- 0:59at modern attack chains. We're seeing a complete
- 1:01shift in the threat landscape. Well, the most
- 1:03sophisticated technical perimeters are just being
- 1:06bypassed entirely. The attackers aren't hacking
- 1:09the technology anymore. They're hacking the people
- 1:12operating the technology, which basically turns
- 1:15these massive, you know, multi -million dollar
- 1:18investments in corporate security completely
- 1:20inside out. So if we trace the timeline back
- 1:23before we get into the how, let's look at what
- 1:26actually happened. According to ADT's SEC filings,
- 1:30they first detected unauthorized access to their
- 1:33cloud environments around April 20th, 2026. Yeah,
- 1:37that was the initial detection. And then within
- 1:39just four days, this internal crisis totally
- 1:42exploded into public view. On April 24th, this
- 1:45extortion group known as Shiny Hunters listed
- 1:47ADT on their dark web leak site. Which is never
- 1:50where you want to see your company's name. Definitely
- 1:52not. And they stamped this really rigid pay or
- 1:55leak deadline on the data. Now, shiny hunters,
- 1:57they immediately claimed they had stolen over
- 2:0010 million customer records. Right. But there's
- 2:02always a discrepancy there, you know, between
- 2:04what an extortion group claims, mostly for marketing
- 2:06purposes, and the actual reality of the blast
- 2:09radius. Right. So what was the actual damage?
- 2:11Well, when breach tracking services like Have
- 2:14I Been Pround, when they analyzed the actual
- 2:16dump, the confirmed number settled at 5 .5 million
- 2:21unique. customer email addresses okay so about
- 2:24half of what they claimed exactly but alongside
- 2:27those emails shiny hunters exfiltrated names
- 2:29physical home addresses and phone numbers and
- 2:33in a smaller percentage of cases the data actually
- 2:35included dates of birth and the last four digits
- 2:38of social security number or tax IDs oh wow But
- 2:42I guess that leaves a lot of extremely sensitive
- 2:44data untouched, right? Because the report explicitly
- 2:47confirms that the actual physical home security
- 2:49systems, like the alarm panels and cameras inside
- 2:53people's houses, those were completely uncompromised.
- 2:56Yeah, that's a crucial point. The physical hardware
- 2:58was safe. payment card data was also safe, the
- 3:01breach was strictly contained to the customer
- 3:02CRM records. OK, but looking at that 5 .5 million
- 3:06number, have I been proud noted that 71 % of
- 3:09those exposed email addresses were actually already
- 3:11floating around in their database from previous
- 3:14totally unrelated breaches? Yeah, that's pretty
- 3:16common these days. Right. So let me push back
- 3:18here for a second. If the vast majority of these
- 3:21customers already have their basic information
- 3:23circulating on the dark web, does a breach like
- 3:27this actually you know, move the needle on their
- 3:30personal risk. Oh, it radically shifts their
- 3:33threat model. Wait, really? How? Because of a
- 3:35concept called contextual clustering. See, threat
- 3:39actors don't just view a stolen email address
- 3:41in isolation. When they acquire a database, they
- 3:44run automated scripts to cross -reference it
- 3:46with massive pre -existing troves of leaked data.
- 3:49Oh, I see. So an attacker might have had your
- 3:52email from like a low -spakes forum breach five
- 3:55years ago, but now, now they can connect. that
- 3:58email to the verified fact that you own a home,
- 4:01that you possess the disposable income to afford
- 4:04a premium ADT security tier. And most importantly,
- 4:08they have your current physical street address.
- 4:10That immediately weaponizes the data. It transforms
- 4:12like a generic mass spam campaign into a highly
- 4:15targeted spear phishing attack instead of a spray
- 4:18and pray email pretending to be PayPal. The attacker
- 4:21can send an SMS message saying, you know, ADT
- 4:24alert. Your panel at this specific street address
- 4:27is offline. Click here to authenticate. And the
- 4:31success rate of that kind of social engineering
- 4:33just skyrockets when the attacker wields that
- 4:36level of specific commercial context. They're
- 4:39manipulating the established trust between you,
- 4:42the customer, and the vendor. Right. And understanding
- 4:44that manipulation of trust is actually the key
- 4:47to understanding how Shiny Hunters breached ADT
- 4:49in the first place. Because ADT's external security
- 4:52perimeter is incredibly tight. So to get that
- 4:55data, Shiny Hunters didn't brute force a server.
- 4:58They executed a vishing campaign. campaign, right?
- 5:01Voice phishing. Voice phishing. They called an
- 5:02ADT employee, impersonated IT support, and basically
- 5:06just asked for access. To me, it's akin to a
- 5:08digital vampire. A vampire. Yeah. Like no matter
- 5:11how strong your digital locks are, the attacker
- 5:13cannot get in unless an employee actively invites
- 5:16them over the threshold by handing them the keys.
- 5:19That is a great way to put it. And shiny hunters,
- 5:21they actually emerged from this Western English
- 5:24speaking cybercrime community known as the comm.
- 5:27Oh, right. I've heard of them. Yeah. And they
- 5:29specialize in this exact social engineering playbook.
- 5:32It's really crucial to understand that they aren't
- 5:34just improvising on these calls. They use very
- 5:37sophisticated phishing as a service tool kits.
- 5:40So what does that look like behind the scenes?
- 5:42Well, the attacker is looking at a real time
- 5:43dashboard. When they call the employee and direct
- 5:46them to a fake login portal, that portal is actually
- 5:49acting as an adversary in the middle proxy. So
- 5:53even if the employee is using MFA like getting
- 5:56a push notification or a code on their phone.
- 5:59The toolkit just handles it. Exactly. The employee
- 6:02types the code into the fake site. The proxy
- 6:04intercepts the session cookie in real time. And
- 6:07the attacker uses that cookie to seamlessly log
- 6:10into the real system. The MFA is rendered entirely
- 6:13useless. Because the human is totally convinced
- 6:15they're talking to legitimate IT support. Corporations
- 6:20spend millions on security awareness training.
- 6:23Every employee takes those mandatory quizzes
- 6:26on spotting phishing and securing their credentials.
- 6:30So why does the IT help desk remain such a massive
- 6:33vulnerability to these vishing tactics? It really
- 6:36comes down to the fundamental psychology and
- 6:38the actual mandate of an IT help desk. What do
- 6:41you mean? Well, think about it. The entire performance
- 6:44metric for a support employee is based on time
- 6:47to resolution and helpfulness. Their professional
- 6:50identity is tied to reducing friction for their
- 6:53colleagues. That makes sense. They want to fix
- 6:55things fast. Right. So when an attacker calls
- 6:57in sounding super professional, professional
- 6:59but panicked, claiming they're, I don't know,
- 7:01an executive locked out of a critical system
- 7:0310 minutes before a board meeting, the help desk
- 7:06worker's immediate instinct is to solve the problem.
- 7:08Ah, so the attacker is weaponizing the employee's
- 7:11desire to just do a good job. Because security
- 7:14protocols, by their very nature, they introduce
- 7:17friction, right? Absolutely do. They demand verification,
- 7:20secondary checks, delays, and the attacker's
- 7:23goal is to convince the employee that bypassing
- 7:26that friction is not just acceptable, but urgently
- 7:30necessary for the company. Yeah, and it's nearly
- 7:32impossible to train out human empathy. You're
- 7:35basically asking a help desk worker to treat
- 7:37every panicked colleague as a potential hostile
- 7:40threat. Shiny Hunters exploits that cognitive
- 7:43dissonance perfectly. And once they bypass that
- 7:46human layer and capture the credentials, the
- 7:48architectural setup of the company basically
- 7:50does the rest of the work for them. Right. Let's
- 7:53talk about that architecture. Because the employee
- 7:55handed over their Okta credentials. And Okta,
- 7:57for those who don't know, it acts as the single
- 8:00sign -on or... SSO for the enterprise. Like Microsoft
- 8:02Entra or Google Workspace. Exactly. It's like
- 8:05the master key to the corporate building. It's
- 8:07brilliantly convenient. Employees log in once
- 8:09and they get access to their email, internal
- 8:12wikis, HR portals, everything. But that convenience
- 8:15has a massive downside. Right, because once shiny
- 8:18hunters compromised that single Okta session,
- 8:20they didn't just get into the lobby. The blast
- 8:22radius was massive. They pivoted directly from
- 8:25Okta into ADT's Salesforce environment. Yeah,
- 8:28and Salesforce is the VIP lounge in this scenario.
- 8:31It's the CRM where all the incredibly rich, enriched
- 8:34customer data resides. And this pivot from SSO
- 8:38to CRM is actually the signature move for shiny
- 8:40hunters. Really? That specific jump? Yes. They
- 8:43don't want to spend... weeks moving laterally
- 8:46through obscure legacy servers or trying to crack
- 8:48encrypted databases. They target the identity
- 8:51provider specifically to reach the CRM. But I
- 8:54want to clarify something here. They aren't exploiting
- 8:56a flaw in Salesforce's underlying code. Right.
- 8:59Salesforce itself isn't being hacked in the traditional
- 9:02sense. Correct. They are simply utilizing the
- 9:04legitimate access they just stole. The Okta integration
- 9:07means the attacker inherits whatever permissions
- 9:09the compromised employee had. Oh, I see. Furthermore,
- 9:12once inside the Salesforce environment, attackers
- 9:14look for misconfigured API integrations or overly
- 9:18permissive oath tokens. Like third -party marketing
- 9:20tools. Exactly. Many companies integrate analytics
- 9:23tools into their CRM. And if those connections
- 9:26aren't heavily restricted, an attack... Hacker
- 9:28can use them to siphon out those 5 .5 million
- 9:31records quietly and efficiently. And this playbook
- 9:34is highly scalable, isn't it? Yeah. The Bank
- 9:36Info Security Report points out that Shiny Hunters
- 9:38has used this exact SSO to Salesforce pipeline
- 9:41since the beginning of the year to compromise
- 9:44heavyweights like Harvard, the University of
- 9:46Pennsylvania. Match Group, various investment
- 9:48advisory firms. Yeah, they have essentially industrialized
- 9:52the process of turning a single vishing call
- 9:55into a massive data exfiltration. event. Because
- 9:58the underlying architecture of modern enterprise
- 10:00IT practically demands it. I mean, centralization
- 10:04equals efficiency, but it also creates this single
- 10:06point of catastrophic failure. That's the trade
- 10:09-off. When you aggregate all access into one
- 10:11identity provider and all customer data into
- 10:14one CRM, you are building a tremendously lucrative
- 10:17target for threat actors. They literally only
- 10:19need to trick one person to get the keys to the
- 10:22kingdom. Which brings us to the extortion phase.
- 10:24The fortress is bypassed, the Salesforce data
- 10:27is copied to the attacker's servers, and shiny
- 10:29hunters post their pay or leak ultimatum. on
- 10:32April 24th. Right. The pressure is on. For a
- 10:35company staring down that barrel, the incident
- 10:37response playbook comes into sharp focus. Now,
- 10:40the report cites Unit 221B, which is a threat
- 10:44intelligence firm that closely monitors these
- 10:46syndicates. And their mandate to victims is to
- 10:49absolutely never pay the ransom and to entirely
- 10:52refuse opening any channel of communication.
- 10:55Yeah, and Unit 221B's guidance is rooted in the
- 10:58operational mechanics of extortion groups. Why
- 11:01is even talking to them a bad idea? Because in
- 11:03gaving with the attackers, even just to stall
- 11:05for time or verify the data, it acts as a signal.
- 11:08It tells the threat actors that the victim organization
- 11:11values the stolen data and is in a state of panic.
- 11:14It qualifies the company as a viable mark. Exactly.
- 11:17And with a volatile group like shiny hunters
- 11:19showing any indication that you might pay triggers
- 11:21an immediate escalation into harassment attacks.
- 11:24And the harassment phase is where this evolves
- 11:25from just a passive threat into active psychological
- 11:28warfare. It gets really nasty. The report outlines
- 11:32how shiny hunters turns up the heat if they sense
- 11:34hesitation. They utilize DDoS botnets to overwhelm
- 11:39and knock the company's public -facing websites
- 11:41offline. Yep, completely disrupting their business.
- 11:44And they launch massive email bombing campaigns,
- 11:47flooding employee inboxes with thousands of messages
- 11:50a minute, so the company literally cannot communicate
- 11:53internally to coordinate a response. And the
- 11:56automation behind those harassment attacks is
- 11:58staggering. The threat actors don't do this manually.
- 12:02They feed the corporate domain and the scraped
- 12:04employee contact lists into stressor services
- 12:07available on the dark web. So they basically
- 12:08weaponize the company's own infrastructure against
- 12:11itself. Right, to create this paralyzing environment
- 12:13of chaos, forcing the executive team into a rushed
- 12:16panic decision to pay. It even breaches the digital
- 12:19divide into physical threats. The report details
- 12:22shiny hunters engaging in swatting attacks against
- 12:24company executives. Yeah, this is where it crosses
- 12:26a major line. They use anonymized VoIP services
- 12:29to call local police departments. claiming a
- 12:32violent hostage situation or a bomb threat at
- 12:35the physical home address of a CEO or board member.
- 12:38Swatting is frequently purchased as a service
- 12:40in underground forums. The attackers just outsource
- 12:43the physical intimidation. That is terrifying.
- 12:45It is. Think about it. When you're sitting in
- 12:47a boardroom dealing with paralyzed internal communications,
- 12:51a downed public website, and the knowledge that
- 12:54your family might be targeted by armed police
- 12:57at your home. The theoretical advice of a security
- 13:00firm feels... Very distant. And that is exactly
- 13:03where I want to push back on this hardline stance
- 13:05of never negotiate, because it's incredibly easy
- 13:08for threat intelligence analysts to sit in a
- 13:11secure facility and preach about not funding
- 13:13the cybercrime ecosystem. Sure. In theory. Right.
- 13:15But if you are ADT's management, you have a fiduciary
- 13:19duty to your shareholders and a responsibility
- 13:21to five point five million angry customers whose
- 13:24home addresses are about to be public. You have
- 13:27executives terrified for their physical safety.
- 13:30The temptation to quietly authorize a cryptocurrency
- 13:33transfer, make the problem go away and protect
- 13:36your people. has to be totally overwhelming the
- 13:39pressure is definitely unimaginable but the temptation
- 13:41relies on a critical fallacy which is the assumption
- 13:45that a transaction with a criminal syndicate
- 13:47functions like a legitimate business contract
- 13:50you are dealing with actors who operate entirely
- 13:53outside the bounds of law and ethics right there's
- 13:57no honor among thieves exactly there is zero
- 14:00cryptographic guarantee that paying the ransom
- 14:02results in the deletion of the data The data
- 14:05has already been copied. The toothpaste is out
- 14:07of the tube. And this introduces the reality
- 14:09of double extortion, which has completely upended
- 14:12the cyber insurance industry over the last few
- 14:14years. Precisely. A company pays the initial
- 14:16ransom, believing the crisis is averted. Six
- 14:19months later, the same group or an affiliate
- 14:21who bought the data from them returns and demands
- 14:24a second payment to keep the exact same data
- 14:27secret. So paying doesn't actually solve anything.
- 14:30No, paying doesn't mitigate the risk. It simply
- 14:32confirms to the criminal underground that your
- 14:35organization is willing and able to pay, effectively
- 14:38painting a much larger target on your back for
- 14:41future campaigns. It really is an unwinnable
- 14:43scenario once the data leaves the network. Which?
- 14:46Which I think brings us to the ultimate strategic
- 14:48lessons you need to take away from this entire
- 14:50sequence of events. Absolutely. Because this
- 14:53incident is a masterclass in realizing that the
- 14:56modern cybersecurity front line is no longer
- 14:59a firewall. or an intrusion detection system
- 15:01or some complex cryptographic algorithm. The
- 15:05front line is the human being answering the phone
- 15:08at the IT help desk. Yeah, and centralized convenience
- 15:10tools are non -negotiable for modern business
- 15:13operations. I mean, you cannot run a global enterprise
- 15:16without SSO or massive CRM platforms. They are
- 15:19incredible efficiency drivers. But the architectural
- 15:22reality is that they drastically raise the stakes
- 15:24of a single compromise session token. When you
- 15:27build a system where one human error can compromise
- 15:305 .5 million records, you have built a fragile
- 15:33system. If you put all your critical assets in
- 15:35one vault and give one person the ability to
- 15:39authorize access to that vault based on a phone
- 15:41call, you better be absolutely certain nobody
- 15:44can manipulate that person. Which is impossible.
- 15:47Right. Because as we've seen, human empathy and
- 15:50the desire to be helpful are the easiest things
- 15:52in the world to manipulate. So, I want to leave
- 15:56you with a final provocative concept to mull
- 15:58over. Okay, let's hear it. If our strongest,
- 16:01most expensive digital parameters can be entirely
- 16:04bypassed by an attacker, just asking politely
- 16:06over the phone. Perhaps the future of corporate
- 16:09security relies less on building higher technological
- 16:11walls. That's a good point. Perhaps it requires
- 16:14fundamentally redesigning how we distribute trust
- 16:17to the humans working inside those walls. We
- 16:20have to stop treating employees as the weakest
- 16:22link that just needs more training. and start
- 16:24designing architectures that assume the human
- 16:26will eventually be tricked, strictly limiting
- 16:28the blast radius when they inevitably are. It
- 16:31really demands a shift toward true zero -trust
- 16:33architecture, applied not just to devices and
- 16:36network traffic, but implicitly to human roles
- 16:38and administrative actions. Security must be
- 16:41resilient to human error rather than dependent
- 16:43on human perfection. Well said. To ensure your
- 16:46organization is building those resilient systems
- 16:48and isn't leaving a digital back window wide
- 16:51open for an attacker to walk through, you need
- 16:53to visit www .kinsoft .com .au. Go there to discuss
- 16:58your own security and IT needs with the experts
- 17:00who can help you navigate this incredibly complex
- 17:02landscape. Keep your parameters secure, but more
- 17:05importantly, build systems that survive when
- 17:07the perimeter inevitably fails. Thanks for listening.