
Uncloaked: When the Company Selling Identity Protection Gets Phished Itself
Three stories this time, one with an irony sharp enough to be the headline on its own, plus a reminder that a vendor breach rarely stays contained to a single incident.
1. An identity-theft protection company was breached by a phone call
Aura, a Massachusetts-based company that sells identity theft protection, credit monitoring, and online security services, disclosed a breach affecting roughly 900,000 records, names, home addresses, phone numbers, emails, and additional marketing data. The entry point wasn't a technical exploit. An unauthorized party gained access to an employee account through a targeted voice phishing call, a live phone call, not an email, convincing enough to get a real employee to hand over access. ShinyHunters claimed responsibility.
Why it matters: every layer of technical scanning in the world doesn't close a gap that opens when a human being on the phone is convinced to do the wrong thing. Vishing works precisely because it targets the one part of a security posture that can't be patched. It's also, bluntly, a striking example of exactly the risk a company's own product exists to protect customers from, happening to the company itself.
2. Trezor's vendor breach kept getting worse, then turned into a phishing campaign
We covered Trezor's ShipMonk shipping-provider breach a few weeks ago. Since then, it's escalated twice. First, Trezor disclosed an additional 67,000 US customers affected, after finding ShipMonk had kept customer data it was contractually required to delete. Then, separately, attackers breached Brevo, Trezor's third-party email provider, and used it to send phishing emails to 347,000 addresses, fake "critical security alert" messages claiming a hardware vulnerability in Trezor's own devices, sent from what looked like Trezor's genuine support address. Roughly 2,500 recipients clicked the embedded malicious link.
Why it matters: the second incident is the sharper lesson. Attackers used a real vendor breach to send a fake security warning that looked exactly like the kind of thing a company would legitimately send after a real breach, weaponizing the very trust a security notification depends on. And the first incident, a vendor retaining data it was required to delete, is a reminder that vendor risk doesn't end when a contract says data gets deleted, it ends when you've actually verified that it was.
3. A telecom breach traced back to a vulnerability in third-party software
KDDI, a major Japanese telecom provider, disclosed a breach affecting an email platform it provides to six Japanese internet service providers. Up to 14.22 million email addresses and passwords, spanning active, dormant, and cancelled accounts, may have been exposed. The cause: attackers exploited a vulnerability in third-party software used inside the email system itself.
Why it matters: this is a scale reminder more than a novel mechanism, a single vulnerable dependency, once exploited, doesn't stay contained to one system, it cascades to everyone downstream of it, in this case six separate ISPs' worth of customers through one shared platform.
The thread connecting all three
A phone call that bypassed every technical control by targeting the person instead. A vendor breach that became the raw material for a more convincing phishing campaign than an attacker could have invented from scratch. A third-party software flaw that turned one compromise into fourteen million exposed accounts. None of these are new attack techniques. All three are reminders that the weakest link is rarely the thing you're actively monitoring.
Sources: Wikipedia on the Aura data breach · Privacy Guides on the Trezor/Brevo phishing campaign · The Hacker News on the Trezor/ShipMonk disclosure · Bright Defense on the KDDI breach
Decloak's platform and third-party domain checks help surface exactly the kind of exposed data and suspicious infrastructure attackers rely on for campaigns like these, alongside seven other attack surfaces. Scan your site free →