Between January and May 2025, there were 5,958 cases of unauthorized transactions linked to securities account takeovers in Japan, with losses exceeding 500 billion yen. Despite securities firms implementing mandatory multi-factor authentication to prevent such fraud, security experts warn that even one-time passwords can be bypassed, raising concerns about the effectiveness of current security measures. Concurrently, several cyberattacks have targeted major companies and financial firms in the United States and Kuwait. The Crypto24 hacking group claimed to have breached FORTÉ, formerly AVI Systems, exfiltrating 643 GB of data. The Chaos ransomware gang attacked Barnhart Crane & Rigging, leaking 360 GB of data. The Qilin ransomware gang breached Regents Capital Corporation, stealing 99 GB of data and threatening to release it on June 17, 2025. Arkana Security targeted Synopsys, a U.S.-based semiconductor software company with $6 billion in revenue, allegedly exfiltrating sensitive data related to over 41,000 corporate entities. In Kuwait, the NightSpire hacking group breached Green Flame Gas, exfiltrating 470 GB of data with a ransom deadline of June 10, 2025. Additionally, widespread phishing attacks have affected customers of various proprietary trading firms, prompting warnings for users to change passwords and calls for improved security practices within these firms.
Apparently there was a widespread phishing attack that impacted customers of a variety of prop firms. If you use any of these firms you should change your passwords to be safe. Here are a my initial thoughts on avoiding a repeat of this situation in the future. To prop firms: https://t.co/5utA1TFKUh
🚨PLEASE READ EVERYONE IMPORTANT!!!!! 🚨 We have received word that there has been two different cyberattacks/data leak issues going on in both some of the largest props and even smaller firms as well. Both seem to be from the same malicious hacking group. Users are being sent
証券口座、ワンタイムパスワードも突破の恐れ 同時進行で乗っ取り https://t.co/NKSTkxsxe5 証券口座の不正取引は5千億円を超えました。証券各社は被害を防ぐために「多要素認証」の必須化を進めますが、セキュリティー会社はそれも突破される恐れを指摘。どうやって防げばいいのでしょうか。