Awkward, Google put out a blog in June about teenagers phoning up orgs and getting access to their databases by asking for access.. and yesterday updated it to say they also got owned by the same kids. cloud.google.com/blog/topics/t…
The Cost of a Call: From Voice Phishing to Data Extortion
UNC6040 uses vishing to impersonate IT support, deceiving victims into granting access to their Salesforce instances.Google Threat Intelligence Group (Google Cloud)
João Tiago Rebelo (NAFO J-121)
in reply to Kevin Beaumont • • •Allan Chow
in reply to Kevin Beaumont • • •Will Hopkins 🌈📸
in reply to Kevin Beaumont • • •Andres
in reply to Kevin Beaumont • • •rk: it’s hyphen-minus actually
in reply to Kevin Beaumont • • •I did something similar in 1993 with the local university. I, 13 years old, wanted to get on the nascent Internet, still the mostly the domain of universities and governments.
I called them up and asked for the dialup number, which they gave me.
I dialed into the terminal server, which dropped me to a shell with the MOTD “now telnet to the VAX.”
But they didn’t limit where you could telnet to. So I just telnetted all over the net (talkers mostly) until I got caught.
#infosec