
Kratos Targets Outpost24, Intuitive Data Breached, Starbucks Staff Exposed
About this episode
No show notes were published with this episode.
Get every episode summarized
Each time DMARC Report publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
36 searchable segments. Every word is indexed and playable.
Full transcript
DMARC Report — Kratos Targets Outpost24, Intuitive Data Breached, Starbucks Staff Exposed. Machine-transcribed; use the interactive transcript above to jump the player to any line.
Kratos targets outposts 24, intuitive data breached, Starbucks staff exposed. Fishing attacks were the dominant cybersecurity threat last week, impacting multiple organizations through increasingly sophisticated tactics designed to bypass detection and exploit user trust. Security firm outposts 24 was targeted using Kratos, a fishing as a service kit. Attackers crafted a highly advanced multi-step campaign that impersonated JP Morgan within an existing email thread, enhancing credibility. The fishing email passed authentication checks, including DMARK, and even bypassed Cisco's secure email gateway. Victims were routed through a chain of legitimate services and domains before landing on a convincing Microsoft 365 credential harvesting page. A sea level executive ultimately fell victim, highlighting the effectiveness of the attack. Similarly, surgical robotics company Intuitive suffered a fishing breach that exposed employee and customer data. Attackers obtained employee credentials, enabling access to internal administrative systems
and sensitive records. While the company quickly activated incident response measures and secured affected systems, the breach prompted ongoing investigations and enhanced employee cybersecurity training. Notably, core robotic operations remained unaffected due to system-level isolation. Starbucks also experienced a fishing-related breach of its partner central employee portal, exposing around 900 employees. Attackers used fake login pages mimicking the official platform to capture credentials, allowing unauthorized account access without directly breaching infrastructure. Starbucks has since strengthened security controls and confirmed no customer data was impacted. A widespread fishing campaign has been exploiting legitimate websites, particularly WordPress domains, to target Microsoft Teams users. By embedding malicious content with entrusted sites, attackers significantly reduced detection risks and improved success rates. This campaign has also expanded to target other platforms like you, AEPAS, and Xfinity.
These incidents underscore a growing trend. Attackers are leveraging trusted services, authentic domains, and advanced evasion techniques to execute highly convincing fishing campaigns, making user awareness and robust security measures more critical than ever.
More episodes
More from DMARC Report

Why do you need to receive DMARC emails?
DMARC Report

How to set up DKIM in Google Workspace: A guide
DMARC Report

ChatGPT Gemini Users, Optimizely Vishing Breach, Telecom AI Protection
DMARC Report

Mail Check and Web Check to No Longer Be Available as NCSC Announces Retirement
DMARC Report