{"id":226760,"date":"2026-03-23T13:49:00","date_gmt":"2026-03-23T17:49:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/23\/2-7m-users-exposed-esecurity-planet\/"},"modified":"2026-03-23T14:05:13","modified_gmt":"2026-03-23T18:05:13","slug":"2-7m-users-exposed-esecurity-planet","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/23\/2-7m-users-exposed-esecurity-planet\/","title":{"rendered":"2.7M Users Exposed &#8211; eSecurity Planet"},"content":{"rendered":"<p><a href=\"https:\/\/esecurityplanet.com\/newsletter\/cybersecurity-insider\/2026-03-23\/\">2.7M Users Exposed &#8211; eSecurity Planet<\/a><\/p>\n<p><a href=\"https:\/\/esecurityplanet.com\/newsletter\/cybersecurity-insider\/2026-03-23\/\">https:\/\/esecurityplanet.com\/newsletter\/cybersecurity-insider\/2026-03-23\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-23 13:49:00<\/a><\/p>\n<p>Source Domain: <a href=\"esecurityplanet.com\">esecurityplanet.com<\/a><\/p>\n<td>\n<table class=\"row row-3\" align=\"center\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-size:auto\">\n<tr>\n<td>\n<table class=\"row-content stack\" align=\"center\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-color:#fff;background-image:url(https:\/\/media.sailthru.com\/composer\/images\/bazh\/axcjdfof\/uy2\/x5l\/3yt\/white-full.png);background-repeat:repeat;background-size:auto;border-radius:0;color:#000;width:640px;margin:0 auto\" width=\"640\">\n<tr>\n<td class=\"column column-1\" width=\"100%\" style=\"mso-table-lspace:0;mso-table-rspace:0;font-weight:400;text-align:left;border-bottom:12px solid #f6faff;padding-bottom:20px;padding-top:20px;vertical-align:top\">\n<table class=\"image_block block-1\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0\">\n<tr>\n<td class=\"pad\" style=\"width:100%;padding-right:0;padding-left:0\"><\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"row row-4\" align=\"center\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0\">\n<tr>\n<td>\n<table class=\"row-content stack\" align=\"center\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-color:#fff;border-radius:0;color:#000;width:640px;margin:0 auto\" width=\"640\">\n<tr>\n<td class=\"column column-1\" width=\"100%\" style=\"mso-table-lspace:0;mso-table-rspace:0;font-weight:400;text-align:left;padding-bottom:24px;padding-left:32px;padding-right:32px;padding-top:24px;vertical-align:top\">\n<table class=\"paragraph_block block-1\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:8px\">\n<p style=\"margin:0\">\n<strong>The threat surface keeps expanding\u2026 from the inside out.<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-2\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\">\n<p style=\"margin:0;margin-bottom:10px\">Today, silent access turns into mass disruption, trusted systems become attack vectors, and automation blurs the line between innovation and abuse.\u00a0<\/p>\n<p style=\"margin:0\">\nRead past newsletters <strong>here<\/strong>.<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"row row-5\" align=\"center\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-size:auto\">\n<tr>\n<td>\n<table class=\"row-content stack\" align=\"center\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-color:#e9effe;background-size:auto;border-radius:8px;color:#000;width:640px;margin:0 auto\" width=\"640\">\n<tr>\n<td class=\"column column-1\" width=\"100%\" style=\"mso-table-lspace:0;mso-table-rspace:0;font-weight:400;text-align:left;padding-bottom:32px;padding-left:32px;padding-right:32px;padding-top:32px;vertical-align:top\">\n<table class=\"paragraph_block block-1\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:12px\">\n<p style=\"margin:0\">Here\u2019s what you need to know:<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"image_block block-3\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0\">\n<tr>\n<td class=\"pad\" style=\"width:100%;padding-right:0;padding-left:0\"><img decoding=\"async\" src=\"https:\/\/media.sailthru.com\/composer\/images\/bazh\/axcjdfof\/hab\/8uv\/oxd\/advertise_csi_1.png\" style=\"display:block;height:auto;border:0;width:100%\" width=\"316.8\" alt=\"Advertise in Cybersecurity Insider\" title=\"Advertise in Cybersecurity Insider\" height=\"auto\"\/><\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"row row-6\" align=\"center\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0\">\n<tr>\n<td>\n<table class=\"row-content stack\" align=\"center\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;background-color:#fff;border-radius:8px;color:#000;width:640px;margin:0 auto\" width=\"640\">\n<tr>\n<td class=\"column column-1\" width=\"100%\" style=\"mso-table-lspace:0;mso-table-rspace:0;font-weight:400;text-align:left;padding-bottom:24px;padding-left:32px;padding-right:32px;padding-top:32px;vertical-align:top\">\n<table class=\"paragraph_block block-2\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:10px\">\n<p style=\"margin:0\"><strong>2.7 Million Impacted in Navia Data Breach<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-3\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:12px\">\n<p style=\"margin:0;margin-bottom:10px\">\nA benefits provider revealed attackers accessed its systems for weeks, <strong>exposing sensitive data of millions of users<\/strong>.\u00a0<\/p>\n<p style=\"margin:0\">Exposed data includes SSNs, birth dates, and benefits details \u2014 valuable for identity theft and targeted attacks.<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"image_block block-4\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:8px;width:100%;padding-right:0;padding-left:0\"><img decoding=\"async\" src=\"https:\/\/media.sailthru.com\/fss\/fvgzsn\/30e9b316-0ff3-442f-ac8f-3e6641ca79ac\/identity5.png\" style=\"display:block;height:auto;border:0;width:100%;border-radius:8px\" width=\"403\" alt=\"2.7 Million Impacted in Navia Data Breach\" title=\"2.7 Million Impacted in Navia Data Breach\" height=\"auto\"\/><\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-6\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:24px\">\n<p style=\"margin:0;margin-bottom:10px\">The company has begun notifying those impacted and no threat actor group has claimed responsibility at the time of publication.\u00a0<\/p>\n<p style=\"margin:0\">\nPrioritize detection engineering, specifically alerting on abnormal access to benefits and HR systems, enforce stricter data retention policies, and use DLP solutions.<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-7\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:10px\">\n<p style=\"margin:0\"><strong>FBI Seizes Handala Sites After Stryker Attack<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-8\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:24px\">\n<p style=\"margin:0;margin-bottom:10px\">\nFederal authorities seized infrastructure used by the Handala group <strong>after a cyberattack wiped roughly 80,000 devices at Stryker<\/strong>.\u00a0<\/p>\n<p style=\"margin:0;margin-bottom:10px\">\nThe group, tied to Iranian state interests, used privileged access to trigger mass device wipes via Microsoft Intune \u2014 highlighting how identity compromise can drive large-scale disruption.\u00a0<\/p>\n<p style=\"margin:0;margin-bottom:10px\">\nWhile the seizure shows growing law enforcement focus, the group plans to rebuild, and organizations using centralized device management remain at risk without strong admin controls.\u00a0<\/p>\n<p style=\"margin:0\">\nEnforce strict conditional access and privileged identity management (PIM) for domain and Intune admins, use privileged access management tools, and audit for unauthorized Global Admin accounts regularly.<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-9\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\" style=\"padding-bottom:10px\">\n<p style=\"margin:0\"><strong>Global Takedown Disrupts Massive IoT Botnets<\/strong><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<table class=\"paragraph_block block-10\" width=\"100%\" border=\"0\" cellpadding=\"0\" cellspacing=\"0\" role=\"presentation\" style=\"mso-table-lspace:0;mso-table-rspace:0;word-break:break-word\">\n<tr>\n<td class=\"pad\">\n<p style=\"margin:0;margin-bottom:10px\">\nAuthorities in the U.S., Germany, and Canada dismantled infrastructure behind multiple botnets used in large-scale cyberattacks.\u00a0<\/p>\n<p style=\"margin:0;margin-bottom:10px\">The takedown targeted Aisuru, Kimwolf, JackSkid, and Mossad \u2014 <strong>botnets that hijacked millions of IoT devices<\/strong> to launch large-scale DDoS attacks.\u00a0<\/p>\n<p style=\"margin:0;margin-bottom:10px\">Operating as cybercrime-as-a-service, they exploited poorly secured&#8230;<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<p><a href=\"https:\/\/esecurityplanet.com\/newsletter\/cybersecurity-insider\/2026-03-23\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2.7M Users Exposed &#8211; eSecurity Planet https:\/\/esecurityplanet.com\/newsletter\/cybersecurity-insider\/2026-03-23\/ Publish Date: 2026-03-23 13:49:00 Source Domain: esecurityplanet.com The&#8230;<\/p>\n","protected":false},"author":1,"featured_media":226761,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/media.sailthru.com\/composer\/images\/bazh\/axcjdfof\/2v2\/p40\/27w\/csi_logo_nopadding.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[30,34],"class_list":["post-226760","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-breach","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/226760"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=226760"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/226760\/revisions"}],"predecessor-version":[{"id":226762,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/226760\/revisions\/226762"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/226761"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=226760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=226760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=226760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}