Security News > 2024 > February > Hackers steal data of 2 million in SQL injection, XSS attacks

Hackers steal data of 2 million in SQL injection, XSS attacks
2024-02-06 07:00

A threat group named 'ResumeLooters' has stolen the personal data of over two million job seekers after compromising 65 legitimate job listing and retail sites using SQL injection and cross-site scripting attacks.

ResumeLooters primarily employs SQL injection and XSS to breach targeted sites, mainly job-seeking and retail shops.

Acunetix - Web vulnerability scanner identifying common vulnerabilities like XSS and SQL injection and providing remediation reports.

ResumeLooters conducts these attacks for financial gain, attempting to sell stolen data to other cybercriminals via at least two Telegram accounts that use Chinese names, namely "渗透数据中心" and "万国数据阿力".

Keenan warns 1.5 million people of data breach after summer cyberattack.

MGM Resorts ransomware attack led to $100 million loss, data theft.


News URL

https://www.bleepingcomputer.com/news/security/hackers-steal-data-of-2-million-in-sql-injection-xss-attacks/