Crime crew impersonates help desk, abuses Microsoft Teams to steal your data

2026-04-25T19:24:07Za2360b64d8288ca1a24e70b37d3aface0e43ab73317684b952d1dfa7967745b5
backdoorcloud-securitydata-leakdata-theftev-chargersfast16firestarteridentity-theftiotmalwaremicrosoft-teamsnpmpasskeysrouterssnow-malwaresocial-engineeringsupply-chainteampcpthreat-intelwindows-admin-center

What happened

A security news roundup highlighting multiple active threats and systemic weaknesses: a crime group is impersonating helpdesk staff via Microsoft Teams and deploying custom ‘Snow’ malware to exfiltrate data; CISA/UK partners disclosed a previously unknown ‘Firestarter’ backdoor found on a US federal network; npm supply‑chain worm activity (with overlap to TeamPCP infections) continues to spread; and high‑profile data exposures surfaced (Carnival emails, 500k Biobank records, alleged French ID agency leak). Other notable items include warnings about China‑linked large proxy networks built from/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
a2360b64d8288ca1a24e70b37d3aface0e43ab73317684b952d1dfa7967745b5
Enrichment time
2026-04-25T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.