Subtitle Icon
Blog Tag

Identity Security

Blog Meta Icon
August 31, 2026
Blog Meta Icon
10 minute read

Fifteen Months, One Phone Call: How the Same Attack Went From Marks & Spencer to Apollo Global Management

The same attack technique ran from UK retail in April 2025 to Wall Street in July 2026. Fifteen months, public the entire time, and the controls that stop it are neither new nor expensive.

Blog Meta Icon
June 21, 2026
Blog Meta Icon
11 minute read

Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.

On June 13, One Medical disclosed unauthorized access to a third-party file storage system holding archived records from its legacy Iora Health and One Medical Seniors patients, describing the scope as a limited subset of files at nine named clinics. Days earlier, on June 18, ShinyHunters posted One Medical to its dark-web leak site, claimed 8.8 terabytes of stolen data, and gave the company until June 22 to begin negotiating before publication. ShinyHunters has released no sample data, so the claim is unverified. This is the same actor, the same playbook, and the same trust gap Cloudskope documented in the Canvas/Instructure breach: a company describing the smallest defensible version of events while a threat actor describes the largest. For boards in healthcare and any regulated-data business, the lesson is not which number to believe. It is to treat both as unproven until the evidence settles it, and to plan for the larger one.

Blog Meta Icon
May 10, 2026
Blog Meta Icon
10 minute read

Most Common Passwords in 2026: What the Data Shows

The 2026 password data: 123456 is still #1, 65% of users reuse passwords across breaches. What boards and CISOs should be doing about it.

Blog Meta Icon
May 10, 2026
Blog Meta Icon
25 minute read

30 Biggest Data Breaches of All Time

Ranked by records: Yahoo, NPD, LinkedIn, Marriott, Canvas, T-Mobile, Equifax, Target, Capital One, Change Healthcare — and the regulatory fallout each produced.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

Scattered Spider Plea: The Playbook Is Now Commoditized

Scattered Spider operative 'TylerB' pleaded guilty. The real threat isn't the arrest — it's that the social engineering playbook is now commoditized.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

Microsoft Edge Stored Every Password in Cleartext

Microsoft Edge has been storing saved passwords in cleartext on disk. Any process with disk access can read them. What it means for enterprise password hygiene.