Skip to content
TrackPodcasts
Mar 19, 20262:21

Kratos Targets Outpost24, Intuitive Data Breached, Starbucks Staff Exposed

DMARC Report

About this episode

No show notes were published with this episode.

Get every episode summarized

Each time DMARC Report publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

36 searchable segments. Every word is indexed and playable.

Kratos Targets Outpost24, Intuitive Data Breached, Starbucks Staff Exposed

DMARC Report

0:00
2:21

Full transcript

DMARC ReportKratos Targets Outpost24, Intuitive Data Breached, Starbucks Staff Exposed. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Kratos targets outposts 24, intuitive data breached, Starbucks staff exposed. Fishing attacks were the dominant cybersecurity threat last week, impacting multiple organizations through increasingly sophisticated tactics designed to bypass detection and exploit user trust. Security firm outposts 24 was targeted using Kratos, a fishing as a service kit. Attackers crafted a highly advanced multi-step campaign that impersonated JP Morgan within an existing email thread, enhancing credibility. The fishing email passed authentication checks, including DMARK, and even bypassed Cisco's secure email gateway. Victims were routed through a chain of legitimate services and domains before landing on a convincing Microsoft 365 credential harvesting page. A sea level executive ultimately fell victim, highlighting the effectiveness of the attack. Similarly, surgical robotics company Intuitive suffered a fishing breach that exposed employee and customer data. Attackers obtained employee credentials, enabling access to internal administrative systems

and sensitive records. While the company quickly activated incident response measures and secured affected systems, the breach prompted ongoing investigations and enhanced employee cybersecurity training. Notably, core robotic operations remained unaffected due to system-level isolation. Starbucks also experienced a fishing-related breach of its partner central employee portal, exposing around 900 employees. Attackers used fake login pages mimicking the official platform to capture credentials, allowing unauthorized account access without directly breaching infrastructure. Starbucks has since strengthened security controls and confirmed no customer data was impacted. A widespread fishing campaign has been exploiting legitimate websites, particularly WordPress domains, to target Microsoft Teams users. By embedding malicious content with entrusted sites, attackers significantly reduced detection risks and improved success rates. This campaign has also expanded to target other platforms like you, AEPAS, and Xfinity.

These incidents underscore a growing trend. Attackers are leveraging trusted services, authentic domains, and advanced evasion techniques to execute highly convincing fishing campaigns, making user awareness and robust security measures more critical than ever.

More episodes

More from DMARC Report

View all episodes →