BlackFile actively extorting data-theft victims in retail and hospitality sector

2026-04-27T14:51:46Z7dc60e2baa9ea96490eed1e0f6fdcc3505d44f94b0482c9bd7664ef7a9af9879
CISAChinaCiscoFISAFirestarterIoTSection-702Vercelcloud-securitydata-theftextortionfirewallgeofencenation-statepatchingpolicyprivacyransomwarerouter-compromisesignallingsupply-chainsurveillance-toolsswattingtelecomvulnerability

What happened

This feed aggregates multiple high-impact cybersecurity stories: BlackFile (linked to ‘The Com’) is actively extorting retail and hospitality victims and reportedly using swatting to increase pressure; Vercel’s compromise has broader customer and third‑party exposure; US/UK agencies warn Firestarter malware persisted on Cisco firewalls long after patches were applied; Dragos judges ZionSiphon — an AI-assisted water‑sector malware — largely ineffective; researchers map surveillance campaigns exploiting long‑known telecom signalling weaknesses and commercial surveillance tools; a multinational警告

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
7dc60e2baa9ea96490eed1e0f6fdcc3505d44f94b0482c9bd7664ef7a9af9879
Enrichment time
2026-04-27T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.