BlackFile actively extorting data-theft victims in retail and hospitality sector
2026-04-27T14:51:46Z•7dc60e2baa9ea96490eed1e0f6fdcc3505d44f94b0482c9bd7664ef7a9af9879
CISAChinaCiscoFISAFirestarterIoTSection-702Vercelcloud-securitydata-theftextortionfirewallgeofencenation-statepatchingpolicyprivacyransomwarerouter-compromisesignallingsupply-chainsurveillance-toolsswattingtelecomvulnerability
What happened
This feed aggregates multiple high-impact cybersecurity stories: BlackFile (linked to ‘The Com’) is actively extorting retail and hospitality victims and reportedly using swatting to increase pressure; Vercel’s compromise has broader customer and third‑party exposure; US/UK agencies warn Firestarter malware persisted on Cisco firewalls long after patches were applied; Dragos judges ZionSiphon — an AI-assisted water‑sector malware — largely ineffective; researchers map surveillance campaigns exploiting long‑known telecom signalling weaknesses and commercial surveillance tools; a multinational警告
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 7dc60e2baa9ea96490eed1e0f6fdcc3505d44f94b0482c9bd7664ef7a9af9879
- Enrichment time
- 2026-04-27T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.