Notorious Ransomware Cartel Claims Breach of Tipalti, Putting Roblox and Twitch Data at Risk

In a stunning development, it has been alleged that the notorious ALPHV/BlackCat ransomware cartel has obtained sensitive data from accounting software provider Tipalti, potentially putting the data of Roblox and Twitch at risk. The cybercriminals reportedly breached Tipalti’s systems, gaining access to a vast amount of company information.

ALPHV Ransomware Targets Tipalti

The dark web blog used by the ALPHV ransomware cartel has posted Tipalti as one of its latest victims. Tipalti, a Canada-based accounting software fintech, has seemingly caught the attention of these cybercriminals.

Timeline of the Breach

According to the claims made by the cybercriminals, they managed to infiltrate Tipalti’s network in early September. Shockingly, they remained undetected for several months, giving them ample time to exfiltrate over 265 GB of highly sensitive company data.

Tipalti is known for providing businesses with accounts payable, procurement, and global payments automation software. With access to such a large volume of sensitive data, the breach poses a significant threat to the privacy and security of not only Tipalti, but also its clients.

ALPHV’s Targeted Strategy

ALPHV’s dark web blog post suggests a deliberate targeting of not just Tipalti, but also recognizable brands like Roblox and Twitch. It appears that the cybercriminals aim to use these high-profile examples to threaten Tipalti and potentially expose data from other customers.

Threats to Roblox

Roblox, a popular game platform and game creation system, has also found itself separately targeted by the ALPHV ransomware cartel. The cybercriminals have explicitly stated their intention to “individually extort affected parties such as their creators.” This comes after an earlier breach in early July 2022, where internal documents of Roblox Corporation were leaked online.

ALPHV/BlackCat Ransomware Operation

ALPHV operates as a Ransomware-as-a-Service (RaaS) business, selling malware subscriptions to criminals. Their activities have been highly active over the past 12 months, victimizing over 320 organizations worldwide, according to Ransomlooker, Cybernews’ ransomware monitoring tool.

The alleged breach of Tipalti by the ALPHV/BlackCat ransomware cartel has sent shockwaves through the cybersecurity world. The potential exposure of data from Roblox, Twitch, and other unsuspecting victims raises concerns over privacy and security for individuals and businesses alike. It serves as a stark reminder of the constant threat posed by cybercriminals and the need for robust security measures to prevent such breaches in the future.

Explore more

TamperedChef Malware Steals Data via Fake PDF Editors

I’m thrilled to sit down with Dominic Jainy, an IT professional whose deep expertise in artificial intelligence, machine learning, and blockchain extends into the critical realm of cybersecurity. Today, we’re diving into a chilling cybercrime campaign involving the TamperedChef malware, a sophisticated threat that disguises itself as a harmless PDF editor to steal sensitive data. In our conversation, Dominic will

How Are Attackers Using LOTL Tactics to Evade Detection?

Imagine a cyberattack so subtle that it slips through the cracks of even the most robust security systems, using tools already present on a victim’s device to wreak havoc without raising alarms. This is the reality of living-off-the-land (LOTL) tactics, a growing menace in the cybersecurity landscape. As threat actors increasingly leverage legitimate processes and native tools to mask their

UpCrypter Phishing Campaign Deploys Dangerous RATs Globally

Introduction Imagine opening an email that appears to be a routine voicemail notification, only to find that clicking on the attached file unleashes a devastating cyberattack on your organization, putting sensitive data and operations at risk. This scenario is becoming alarmingly common with the rise of a sophisticated phishing campaign utilizing a custom loader known as UpCrypter to deploy remote

How Are Iran-Nexus Hackers Targeting Global Governments?

In an era where digital warfare is as critical as physical conflict, a sophisticated spear-phishing campaign linked to Iranian-aligned hackers has emerged as a stark reminder of the vulnerabilities facing global diplomatic networks. Recently uncovered, this operation, attributed to the Homeland Justice group and Iran’s Ministry of Intelligence and Security (MOIS), has targeted embassies, consulates, and international organizations with alarming

Fintech Cybersecurity Threats – Review

Imagine a financial system so seamless that transactions happen in mere seconds, connecting millions of users to a digital economy with just a tap. Yet, beneath this convenience lies a looming danger: a single compromised credential can unleash chaos, draining millions from accounts before anyone notices. This scenario isn’t hypothetical—it played out in Brazil’s Pix instant payment system, a cornerstone