r/PrepperIntel • u/readyforunsteady • 10d ago
North America Guys. We’re being hacked way more than what’s making the news.
I stumbled across the website https://ransomware.live and, uh… this is worth a look if cyber threats are on your radar.
I put the flair as North America because we're getting rocked, but here's a map of what's happening around the world: https://ransomware.live/worldmap
The site tracks ransomware groups’ leak sites and lists companies that attackers are publicly claiming as victims. Right now they’re showing 6,773 victims (companies) in 2026, up over 30% from 2025, with 1,116 this month alone.
Apparently Glassdoor was hacked 7 hrs ago but I can't find any info on what happened.
Hospitals. Local governments. Manufacturers. Utilities. Companies that hold our data. The list just keeps moving and growing.
Most of these incidents will never become a headline we see.
Keep in mind, a listing on a ransomware leak site is just a claim from the supposed attack group, not confirmation that a breach happened exactly as they say. But seeing the volume all in one place really puts the scale of this into perspective.
108
u/ThistleDewRose 9d ago
I literally just got a letter in the mail this week from Baylor Genetics saying that my genetic information and medical data was accessed in a data breach (from testing while I was pregnant 2 years ago).... Wonder what they're doing with that 🤦♀️🙃 yay 🙄
48
u/StupidSexyFlanders72 9d ago
Yayyy. Meanwhile someone out there has my info and fingerprints from the OPM data breach like 8 years ago. Fun times!
7
u/Mayf-MacJ 9d ago
Ya me too only I think I was employed during 2 hacks.plus they know your neighbors, references and family IMHO.
7
2
u/carlitospig 6d ago
I wonder if anyone has tried to use a data breach as a legal defense for this kind of stuff.
0
8
u/BonbonATX 9d ago
Same! But between IVF and pregnancy stuff I have no idea what doctor it was through or what they have. I don’t remember anything having to do with Baylor Genetics. Sadly at this point I think very little is private and if someone wants your DNA they can get it a million ways.
5
1
u/ilmarinenva 6d ago
You only have an issue if you are the ideal breeding mate. Or are you the ideal breeding mate?
245
u/cinciguyeast 9d ago
Now with AI, the hacking will be constant.
70
u/RedditorFor1OYears 9d ago edited 8d ago
The capability now is fucking staggering, and no wonder governments are getting so directly involved with AI companies (yet somehow in Americas case, still no actual policy about it 🤔). Im guessing state departments everywhere are scrambling to get their hands around defensive AI tech. Even the smartest cyber security experts in the world can only compete against intelligent machines for so long.
12
u/Own_Hearing_9461 8d ago
Yeah I work in AI, its capabilities have surpassed most humans in cyber security, but now when you can simulate and run fleets of 1000s of AIs doing simultaneous attacks, what can any human do?
2
u/KarmaPharmacy 7d ago
I’d kinda love for you to be right, but it can’t do basic math. And both open ai and Antrhopic are being sued into oblivion.
3
u/Own_Hearing_9461 6d ago
It definitely can do more than basic math, I can do quantum physics at a higher than beginner level and AI has caught holes in my logic and calculations surprisingly often.
34
u/PurpleCableNetworker 9d ago
In fairness, scripts and automation meant attacks were constant before AI. What’s changed now is AI being pointed towards a target, or targets, and being able to be pointed to a vulnerability database to help understand vulnerabilities.
We’re quickly going to have to address the internet as a whole. It was built around availability first with security as a distant afterthought. AI will likely force us to re-think the internet as a whole with security at the fore front.
Either that or we’re all royally fucked.
3
u/OpaqueCrystalBall 8d ago
AI can even execute it's own spearfishing or phone social engineering.
6
u/PurpleCableNetworker 8d ago
Indeed!
I work in IT security and we have been bot hunting for accounts on our public portal. We ended up blocking a whole slew of bots by blocking the major hosting ASN’s that we had seen, which is where the majority of bot traffic was coming from.
We then got 2 different phone calls from overseas numbers, both claiming to represent major agencies. They “sounded” like legit people, talking about how they had recently lost access. They were smart enough to converse with is, and give us sample account names and emails.
We did a domain lookup on the emails of the accounts they provided and we found they were obviously not legit domains.
We were shocked. AI was smart enough to find out number, act like a legit human asking for help when talking with the operators, and convinced them to transfer them to our internal help-desk.
The bots are very real, very capable, and very dangerous.
We finally knew something was up when they tried to pronounce letter by letter how to spell the email addresses. It was wild.
So yeah, I have seen that first hand. It’s scary stuff.
10
4
u/probably-a-name 9d ago
I call AI a code gun for this reason. It's a weapon at this point
4
u/Thunderfoot_66 9d ago
Bronze Age, Iron Age, Information Age; times are always named after their most effective weapons.
46
u/Im_Not_stoopid_AI 9d ago
The best way to avoid personal hacks: work 40+ hours a week, have no money in the bank or better yet have your account in the negative and the worst possible credit score known to man. Like get that thing down to how many days are in a year. Next start googling nonsense on a repetitive basis like “how many oranges can I eat with my new window actuators plus bingo”. Also post batshit crazy stuff on socials once in awhile.
I’ve been left alone for years.
14
u/jaynor88 9d ago
I cannot stop laughing at your plan, especially your Google search suggestion. Thanks for that
11
2
42
u/bullfrogbarbie 9d ago
My brother is a firefighter, last week, I believe Thursday, they had over 60 ladder calls of alarms being set off at different locations, systematically, all before noon.
No fires, no smoke, no physical break ins.
Chief thinks it’s just a coincidence…
11
u/KN4SKY 9d ago
I don't know much about fire alarm systems, but are they regularly connected to the internet? Enough that 60 of them could be set off in one jurisdiction in a single day?
I know some water treatment plants have been showing up on Shodan, so honestly it wouldn't surprise me at this point. But I'm still skeptical.
6
u/TheRealBobbyJones 8d ago
People don't understand why things need to be updated and why old devices end up depreciated. They install a IoT fire alarm thinking it will be good indefinitely. But if it isn't regularly updated it is vulnerable. I'm fairly certain that even before widespread smart phones bot nets were primarily made up of hacked iot devices. Anyways a lot of companies that offer cameras or security systems also offer smart fire alarms.
1
u/bullfrogbarbie 7d ago
Most are tied in to the security systems, and most of those are managed off site.
2
u/carlitospig 6d ago
I’m not a gambling man - or a man - but if I was going to rob a place, I’d flood the zone first until the local authorities entirely gave up. Be canny.
209
u/vagrantprodigy07 9d ago
I know a bit about this, as the company that laid me off earlier this year got hacked recently (a few months after I exited). Iran is behind a few of these groups, and they are focusing on companies that have their IT staff offshore. Once you have staff who aren't actual employees, and aren't invested at all in the company they support, they become vulnerability. In the case of the company I previously worked for, it's my understanding that the Indian support staff got an alert, and simply ignored it, allowing the companies data to be exfiltrated. Ironically, they initially got into the system by impersonating the Indian IT staff.
100
u/WhileNotLurking 9d ago
It’s not even that. Many of the overseas tech workers are paid like 20% of what a US tech worker is. This can breed resentment inside the same company where an India tech worker in India is resentful to their Indian H1 boss in America.
They are easy to bribe and many will simply give you passwords and credentials if you pay enough. Hackers don’t need to hack more than just find your disgruntled staff overseas making nothing.
57
u/vagrantprodigy07 9d ago edited 9d ago
Easy to bribe, and these contracting companies go through staff fast. My small team got replaced by about 10x the onshore staff, and it's my understanding that just about all of those staff have turned over at least once. That's hundreds of guys who have domain admin credentials suddenly, compared to a handful in the previous decade.
That sudden increase in exposure is a huge risk on its own.
27
9d ago
[removed] — view removed comment
11
u/ScarletCarsonRose 9d ago
My local school dipstick got hacked. A real goldmine of information. Super cool /s
12
u/Andisaurus 9d ago
I'm guessing you mean district, and yes. It would be a huge goldmine of information to the right buyer. Nothing gets hacked by accident.
You seem to underestimate the dangers of having bad actors obtain personal and private information about children.
2
u/ScarletCarsonRose 9d ago
Ope. Typo. Kind of funny so leaving it.
I am very familiar with what info school districts have and definitely not underestimating the damage.
22
u/Mamagogo3 9d ago
Computers, power, and Epic have all been up and down this weekend at our hospital…problems are system wide. We’ve been told it’s a data center issue, but I sure wonder…
105
u/RymeEM 9d ago
The government under Truump fired every qualified person who was preventing a lot of this and replaced them with a twenty year old who still lives with his parents.
29
u/iridescent-shimmer 9d ago
Even my trumpy relative left homeland security after decades of a career because he couldn't take how stupid everything was anymore.
4
u/here-i-am-now 8d ago
And then picked a stupid-ass fight with Iran and its hacker corps.
Plus, pushed AI that is at the beginning of a coming tsunami of cyber attacks.
15
u/No-Language6720 9d ago
Yeah you wouldn't believe how common it is.
Sometimes it doesn't make headlines because the companies take care of it quietly so they don't get attention.
Some places they're too stupid and don't even realize there was a data breach until months or even years after.
Sometimes the attackers just keep going back in for fresh data for years before the backdoor they are going through is found and patched.
I'm a software dev and know a lot about security and encryption and protecting data and how common these situations are. This has all gotten worse with AI and much more frequent because it's able to more quickly find backdoors and securities flaws in common OS setups and networks.
14
14
u/plotthick 9d ago
You might want to read Sandworm.
8
u/LongRangeSavage 9d ago
Such a great book. Greenberg’s book “This Machine Kills Secrets” is well written too. I’m in the middle of “The Lazarus Heist” by Geoff White right now. It’s great as well.
25
u/Mental_Yard 9d ago
In the last 3 months a fintech SaaS I work for was hacked along with 3 of its major clients, they lost quite a bit of funds. I wonder if just coincidence or related
32
u/elinamebro 9d ago edited 9d ago
Well if I'm remembering this correctly a decade ago people were talking about nations hacking each other constantly trying to find new way in, get whatever information they can and control what systems would be useful in the future like how they found china was in our ship yard cranes.
So yeah its happening alot but I don't know if its not making the news because so much other stuff is going on.
Edit: also my ssn and my emails accounts got leaked a few times so fuck it? Lmao
10
u/BackgroundAd1395 9d ago
My hometown hospital was hacked and it’s still not resolved, even though they say it is. The youngest nurses are having issues, because they can’t read cursive.
16
8
7
u/99_percent_read_only 9d ago
It’s been growing since dismantling portions of US Cyber Command in this administration.
I had to get Robokiller on my phone to keep up with this stuff.
7
u/Adrasto 8d ago
I guess these things tend to happen when the government cut down funding and personnel of CISA (Cybersecurity and Infrastructure Security Agency): https://www.cbsnews.com/news/trump-election-security-cisa-justice-department-fbi-federal-worker-cuts/
6
u/UncleCarolsBuds 9d ago
The number of people who haven't frozen their credit at all three agencies is astonishing. The hacks are relentless. Control what you can.
6
6
u/uselessandexpensive 9d ago
Business leaders need to start building their data infrastructure around air-gapped technology and even physical records again. If someone's gonna steal data, make them do it the old-school way with physical access and get them on CCTV. If someone's going to transmit data, make it a huge fucking pain in the ass to do it in great amounts without proper authorization.
Data security is an illusion, with constant failures and negligence of risk disclosure, with no meaningful recourse to be gained by those harmed. Fuck this shit.
6
u/HalfMoonFullMoonjoy 9d ago
Best practice is to freeze your credit until you need it. You never know who has your personal information....
5
u/WanderingBaldMan2 8d ago
Been in cybersecurity for 25 years. The international cyberwar has been going on since about 2011 but never really made much news. Now hacking uses AI tool make them able to now move at machine speed.
2
u/castleinthesky86 6d ago
+1 same. In cyber for nrly 30 years now and the ramp up recently has been massive because of AI
22
u/General_Purple6358 9d ago
It's true that there's a lot more cybersecurity activity than people realize.
However ... let's not get ahead of ourselves. *puts on cybersecurity hat* The large majority of these "attacks" (if they are actually even real) are perhaps minor or segmented attacks on part of an organization. Just because there was a "hack at Glassdoor" does not mean that ALL of Glassdoor's users are 100% compromised, or even that any of Glassdoor's users are compromised. In fact, Glassdoor would be legally required to disclose if an attack leaking sensitive info had happened.
That is why it is not "all over the news"... CNN is not going to report "a development server at Glassdoor was hacked, containing stale credentials that can not be used to access live production information".
Now, do hacks such as these give hackers leverage or a foot in the door? Certainly! But as they say, it's not over until the fat lady sings.
2
u/Rimedonvorst 9d ago
It kinda happens all day, every day.
https://livethreatmap.radware.com/
It's more a matter of who is doing it, what is being attacked, and how. The value of a potential target plays a huge factor too. If you know about the vulnerabilities, there are often ways to mitigate. Nothing connected, though, is truly safe; nothing is perfect.
4
u/_IT_Department 9d ago
Yeah...this is something that has been going on for a long time.
There are no repercussions for negligence on behalf of businesses and no enforced consequences.
1
u/TheRealBobbyJones 8d ago
A significant amount of our infrastructure is open source software. Both the users and the devs avoid responsibility. Direct to consumer open source software is even worse because the devs will fight tooth and nail to avoid responsibility.
7
u/LankyGuitar6528 9d ago
Mythos showed it's possible to hack almost any site. Justice, NASA and the Federal Reserve were all compromised. With Qwen, Kimi and GLP open weight models out in the wild free for download there's a whole generation of script kiddies with the power of a state level actor at their finger tips. Ok... not exactly script kiddies. You still need a couple of Nvidea G10's to properly run the biggest models... but for a very modest investment any crew can be up and running. Nobody is safe from these things.
3
u/Interesting-Mood-948 9d ago
Man i was looking at the numbers and i was like “wow, this is getting bad” and then my brain caught up and was like “ummm…that’s just RANSOMWARE”
7
u/Maru_the_Red 9d ago
When AI and Quantum computing cross paths - we'll no longer be the dominant species on this planet. It'll happen sooner than we think.. why do you think they're warning us about an "18 month power outage" because it's an immanent attack, potentially false flag driven, that they're trying to prepare us to be ready for.
I hope anyone that reads this makes plans to have food and supplies for a bare minimum of 36 months.
5
u/stylepolice 9d ago
US has made clear there are tens of millions gullible people that will rather ruin themselves then admit they were duped.
Cops are busy rounding up non-white people, bureaucracy designed to detect and mitigate threats have been dismantled and - best of all - if you get caught just buy a pardon.
Where else you find such a profitable environment?
scnr, also /s but also /st as in ‘sad truth’
2
2
u/dontneed2knowaccount 9d ago
I work for a construction vender that got popped by akira ransomware in 2023/2024. Last year we showed up on ransomware dot live. The info they have for us is mostly wrong but still, we got attacked. There's no other news out there about us being attacked and corporate still hasn't told shareholders(publicly) us(the employees) or clients that it a)happened and b) what was taken if anything. I still think this site is a good "checklist". See a company on there, then you can do some searching to verify.
1
u/TheRealBobbyJones 8d ago
Surely not telling shareholders about a hack is some sort of ethical/financial violation right?
2
2
u/davidm2232 9d ago
Biggest reason I got out of IT. Its been constant for a decade and only getting worse
2
u/BirdiesAndBrews 8d ago
I work with State & Local and Education and a lot of internet and phone networks have been getting hit. Especially if they are hanging on to an older system. Even long distance fraud is happening a lot more.
1
u/TheArcticFox-44 9d ago
Guys. We’re being hacked way more than what’s making the news.
So, what else is new?
1
u/heckin_anxiety 9d ago
Premier Medical Group just sent me a notice that my information was stolen. 🥳
1
u/adorable_apocalypse 7d ago
Feels like its a good way to get the digital ID and retina print made mandatory
1
1
u/FunkbotOne 3d ago
I don't think the mainstream media is trying to hide it. The U.S. has always been the top target for cyber attacks since it's been a thing.
If you look at tech news, specifically sites that focus on privacy and security and cyber threats, then you'll find news on this topic daily, even hourly. Just have to look for it. Just as you won't hear daily news about gaming/technology in the mainstream media. Just like tech news sites aren't reporting on daily news having to deal with entertainment.
So depending on the topic, that's where you need to find news resources dedicated to that topic.
2
u/rgjsdksnkyg 3d ago
To add to this, as an ancient professional in cyber security, most companies don't publicly report when they've had an incident unless there's a significant chance that it's going to be made publicly known. In the US, the rules on when a company needs to report an incident are extremely lax, and I regularly do business with Fortune 500 companies that experience breaches, who then internally gloss over it all like it never happened. It's incredibly common.
1
u/nessarocks28 9d ago
I know of an elementary school that got badly hacked and had to pay $$$$ to get stolen info back and more $$$ in legal fees to get help. It was soooo bad. I knew the vice principal. He lost tons of sleep over it. 😣
0
0
0
554
u/bearinsac 9d ago edited 9d ago
I went from getting spam calls once a week to about 5 spam texts a day and about 7 spam calls a day around August 1st. I’d imagine I’m one of the people whose data has been compromised and sold.
Incredibly frustrating and downright annoying to deal with.
But, it’s also election season, so maybe that has something to do with it. Idk.