Sign in

jon greig

@jgreig.bsky.social
956 followers 285 following 715 posts

cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to jonathangreig11@protonmail.com or signal: jgreig.51

PostsRepliesMedia
jon greig @jgreig.bsky.social · 09/10/2026
Heart monitor company iRhythm said more than 360,000 people had sensitive data leaked during a June cyberattack therecord.media/irhythm-data...
therecord.media
Hundreds of thousands impacted by data breach at biosensor firm iRhythm
A company known for wearable cardiac sensors, iRhythm, has begun notifying states of the impact of a data breach from the summer.
011
Reposted by jon greig
Raphael Satter @raphae.li · 09/10/2026
Scoop: I spoke to Pryx, a.k.a. Adem El Adeb, friend of ShinyHunters suspect Saif Al-Din Khader. El Adeb said Khader told him he was going to hack the FBI in *early* Sept. which (if true) pushes our timeline back a bit. El Adeb says he told Khader he was "crazy." www.reuters.com/legal/govern...
reuters.com
EXCLUSIVE: Friend of suspected FBI data thief says he warned 'crazy' teen not to hack bureau
A friend of the suspected thief of a massive cache of personal data from the FBI says he begged the teenager not to do it.
0158
Reposted by jon greig
Jason Koebler @jasonkoebler.bsky.social · 09/10/2026
Following our investigation into the White House's secretive ALPR database, Sen. Wyden is demanding a privacy review / more details: www.404media.co/following-40...
404media.co
Following 404 Media Investigation, Senator Demands Info About White House's License Plate Surveillance Program
Sen. Ron Wyden is seeking a privacy review report about the HIDTA license plate program.
06122
jon greig @jgreig.bsky.social · 09/10/2026
Another ShinyHunters member was allegedly arrested in Pennsylvania this week as the FBI seeks to catch the people responsible for the data breach that exposed troves of sensitive agent information therecord.media/shinyhunters...
therecord.media
FBI touts another ShinyHunters arrest in response to data breach
“We will continue to work closely with our partners to disrupt what’s left of the ShinyHunters group and their associates, no matter where they operate," FBI Director Kash Patel said.
010
jon greig @jgreig.bsky.social · 08/10/2026
The DOJ and 6 other countries took down two powerful hacking tools known as “Microscan” and “FishHub" that were maintained by Chinese company Integrity Tech and used for several state-sponsored hacking campaigns therecord.media/flax-typhoon...
therecord.media
International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Fla...
010
jon greig @jgreig.bsky.social · 07/10/2026
A cyberattack on Arizona’s court system gave hackers access to the information of more than 1.3 million people The hackers stole info from a court debt collection program, the Foster Care Review Board and systems handling active and inactive protective orders therecord.media/arizona-cour...
therecord.media
Arizona courts say hackers stole info on more than 1.3 million people
The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding ...
010
jon greig @jgreig.bsky.social · 07/10/2026
A group of OT experts want CISA to create a binding directive forcing federal agencies to institute basic cybersecurity measures Federal agencies rely on more than 8,000 buildings — all of which have an array of HVAC, power, water and building automation systems therecord.media/cyber-expert...
therecord.media
Cyber experts call on CISA to create mandatory federal OT rules
The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used to monitor and control critica...
010
jon greig @jgreig.bsky.social · 07/10/2026
More than 86,000 internet-facing Fortinet FortiGate firewalls and virtual private network (VPN) gateways have been compromised as part of an ongoing campaign tracked as FortiBleed, according to the FBI and Secret Service therecord.media/fortibleed-w...
therecord.media
FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
010
jon greig @jgreig.bsky.social · 07/10/2026
The Senate passed a healthcare cybersecurity bill last week that will force HHS to require all private healthcare-related entities adopt minimum cybersecurity standards like multifactor authentication therecord.media/senate-passe...
therecord.media
Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.
010
jon greig @jgreig.bsky.social · 05/10/2026
Wikimedia said it caught OpenAI agents trying to compromise a public note-taking tool, attempting to edit Wikipedia pages and causing site disruptions earlier this year therecord.media/wikimedia-fo...
therecord.media
Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool
Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.
175
jon greig @jgreig.bsky.social · 05/10/2026
The University of Illinois Chicago recently discovered a ransomware attack that limited access to some systems at its College of Medicine The Booba ransomware gang took credit for the incident on Friday therecord.media/ransomware-u...
therecord.media
University of Illinois Chicago affected by ransomware attack on medical school
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
000
Reposted by jon greig
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 29/09/2026
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns via @jgreig.bsky.social & @therecordmedia.bsky.social
therecord.media
ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site...
043
jon greig @jgreig.bsky.social · 02/10/2026
The mayor of Vicksburg, Mississippi said the city is dealing with a ransomware attack that shut down all city systems therecord.media/vicksburg-mi...
therecord.media
Mississippi mayor says ransomware incident led city to shut down systems
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
021
jon greig @jgreig.bsky.social · 02/10/2026
The Warlock ransomware strain was used to target a water utility, a telecommunications provider, a university and a regional government The victims are scattered across several Spanish and Portuguese-speaking countries therecord.media/warlock-rans...
therecord.media
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
040
jon greig @jgreig.bsky.social · 01/10/2026
Amir Barati was extradited from Montenegro today after US officials accused him of leading an Iranian effort to breach the email accounts of at least 8,000 US professors therecord.media/iran-montene...
therecord.media
Iranian accused of hacking American universities extradited from Montenegro
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
010
jon greig @jgreig.bsky.social · 01/10/2026
Chinese hackers impersonated former White House official Lynne Edwards Parker in phishing emails targeting AI-focused organizations during a campaign this year therecord.media/china-linked...
therecord.media
Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
010
jon greig @jgreig.bsky.social · 30/09/2026
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group said Wednesday The number of distinct vulnerabilities disclosed and exploited from Jan-Aug surpassed the totals for all of 2025 therecord.media/google-vulne...
therecord.media
Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
003
jon greig @jgreig.bsky.social · 29/09/2026
The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.” therecord.media/arizona-supr...
therecord.media
Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
011
jon greig @jgreig.bsky.social · 25/09/2026
Kiteworks said it “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some...systems for customers.” They urged customers to shut off the tool for six hours on Saturday therecord.media/kiteworks-ur...
therecord.media
Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to ...
000
jon greig @jgreig.bsky.social · 25/09/2026
The CEO of Bitget said North Korean hackers were behind a $387 million theft on Thursday therecord.media/crypto-ceo-a...
therecord.media
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
000
jon greig @jgreig.bsky.social · 24/09/2026
One of the key figures behind the Rydox cybercriminal marketplace pleaded guilty this week to aggravated identity theft and money laundering charges therecord.media/rydox-crimin...
therecord.media
Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell s...
000
jon greig @jgreig.bsky.social · 24/09/2026
Astrana became the latest healthcare tech company to report a data breach to the SEC. The company's software and tools are used across thousands of private practices across the US therecord.media/astrana-cybe...
therecord.media
Astrana latest healthcare tech firm to report data breach to SEC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
000
jon greig @jgreig.bsky.social · 23/09/2026
An Armenian ransomware operator for Ryuk was sentenced to two years in prison after helping the gang launch hundreds of attacks therecord.media/ransomware-r...
therecord.media
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
011
jon greig @jgreig.bsky.social · 23/09/2026
The FBI is investigating a breach perpetrated by the ShinyHunters cybercriminal group, which claimed it stole personal information on all FBI employees as retaliation for a May flash notice from the agency that they believe is innacurate therecord.media/fbi-investig...
therecord.media
FBI investigating alleged ShinyHunters breach of its jobs site
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
031
jon greig @jgreig.bsky.social · 22/09/2026
Two men were arrested in the UK for their alleged involvement in EvilTokens - an AI tool that helped cybercriminals comb through breached inboxes and provide the easiest options for how to scam people or steal their money therecord.media/two-arrested...
therecord.media
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts,...
000
jon greig @jgreig.bsky.social · 18/09/2026
Vietnam, Laos, Pakistan and Argentina arrested several local collaborators and seized funds tied to North Korea's IT worker campaign Chinese officials also kicked several North Koreans out of the country for espionage therecord.media/nations-take...
therecord.media
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
000
jon greig @jgreig.bsky.social · 16/09/2026
The NightmareStresser platform used to disrupt hundreds of educational institutions, government agencies and other organizations was seized on Tuesday by the Justice Department therecord.media/doj-takes-do...
therecord.media
DOJ takes down NightmareStresser DDoS platform
The DOJ announced the court-authorized takedown alongside Canadian officials, but declined to say if any arrests were conducted as part of the operation.
010
jon greig @jgreig.bsky.social · 15/09/2026
Law enforcement agencies in Norway are investigating whether Norwegian telecom Telenor aided crimes against humanity through its work providing customer data to the brutal military regime currently governing Myanmar therecord.media/norway-inves...
therecord.media
Norway announces investigations into telecom Telenor’s work with Myanmar junta
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
0289
jon greig @jgreig.bsky.social · 15/09/2026
CenterPoint Energy warned the SEC that hackers stole customer information after a cybercriminal offered the data for sale last week therecord.media/centerpoint-...
therecord.media
Electric and gas utility CenterPoint Energy warns of data breach after dark web post
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
011
jon greig @jgreig.bsky.social · 10/09/2026
The firm behind the phishing email blasts, Brevo, said 138 company accounts were breached 6 were used to send mass phishing emails and the attackers exported contacts for 43 other companies therecord.media/trezor-bitbo...
therecord.media
Multiple crypto companies warn customers of phishing emails after alleged provider breach
Subscribers to newsletters from Trezor, CoinTracking and BitBox received corrupted messages through an email provider that all three companies use.
000
jon greig @jgreig.bsky.social · 03/09/2026
haitiantimes.com/2026/09/03/o...
haitiantimes.com
Where Ohio Haitians can find legal help, food and other support
Find legal help, food, bus passes and other resources available to Haitian families in Springfield and across Ohio.
000
jon greig @jgreig.bsky.social · 01/09/2026
Nutex confirmed it is being extorted after patient and employee data was stolen by The Gentlemen ransomware gang therecord.media/nutex-health...
therecord.media
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
000
jon greig @jgreig.bsky.social · 01/09/2026
Five men pleaded guilty to involvement in an ATM jackpotting scheme after trying to install malware on ATMs in Kansas therecord.media/kansas-atm-j...
therecord.media
Five plead guilty in latest federal ATM jackpotting case
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
021
jon greig @jgreig.bsky.social · 31/08/2026
McKesson said on Saturday that the hackers exfiltrated data associated with customers in their oncology and surgical business units Shinyhunters took credit for the attack late on Friday therecord.media/mckesson-cyb...
therecord.media
Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
020
jon greig @jgreig.bsky.social · 27/08/2026
The ATF said it recently had a “major” cyber incident. The agency appeared on the Qilin ransomware leak site on Wednesday An ATF spox told me the issue “involved a standalone computer system containing information about targets of ATF investigations.”  therecord.media/doj-atf-cybe...
therecord.media
DOJ firearms agency says hackers breached system containing investigation targets
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried o...
000
jon greig @jgreig.bsky.social · 26/08/2026
The DOJ said today that Chinese hackers breached the Federal Reserve, NASA, the US Senate, DOE and more since 2018 using a tool called QScan therecord.media/qscan-qtrout...
therecord.media
US takes down alleged Chinese hacking tools used against Federal Reserve, DOJ and Senate
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.
010
jon greig @jgreig.bsky.social · 25/08/2026
After an alleged Akira ransomware attack last year, employee benefits tech provider Paylogix said thousands of people had SSNs, financial data, healthcare info and even digital signatures stolen by cybercriminals therecord.media/paylogix-cyb...
therecord.media
Employee benefits platform Paylogix says hackers stole financial and health
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
010
Reposted by jon greig
Ron Bowes @iagox86.bsky.social · 25/08/2026
My first advisory!
071
jon greig @jgreig.bsky.social · 25/08/2026
The U.S. sanctioned several Iranian nationals on Monday for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom therecord.media/iran-cyberat...
therecord.media
US sanctions Iranian cyber actors as UK discloses power plant attack
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
002
jon greig @jgreig.bsky.social · 24/08/2026
Members of Congress demanded a government watchdog examine the effect Trump staffing cuts have had on CISA's ability to protect critical infrastructure from cyberattacks therecord.media/lawmakers-ca...
therecord.media
Lawmakers call for investigation into impact of CISA staffing cuts
Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.
011
jon greig @jgreig.bsky.social · 21/08/2026
US Bank said a recent data theft claim from LockBit was traced back to a "fourth party" therecord.media/us-bank-says...
therecord.media
U.S. Bank says breach claims related to fourth-party incident
The bank said there is no evidence that its own systems, networks or data repositories were compromised.
000
jon greig @jgreig.bsky.social · 21/08/2026
Canada’s largest pediatric health center suffered a recent cybersecurity incident that exposed the personal information of current and former employees therecord.media/canada-hospi...
therecord.media
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is ti...
000
jon greig @jgreig.bsky.social · 19/08/2026
Federal agencies said there is an “active threat” targeting the Siemens PLCs of critical infrastructure organizations using AI-generated exploit scripts, in what they called an “evolution” in capabilities therecord.media/nsa-fbi-warn...
therecord.media
NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology
The National Security Agency (NSA), FBI and other federal agencies said the campaign is targeting Siemens S7 Series PLCs and was being fueled by “AI-assisted development” alongside exploitation of kno...
001
jon greig @jgreig.bsky.social · 18/08/2026
The FBI and CISA updated an advisory on the #Medusa ransomware to say that more than 500 organizations have been attacked by the group The group was responsible for a devastating attack on the largest hospital system in Mississippi earlier this year therecord.media/more-than-20...
therecord.media
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than ...
001
jon greig @jgreig.bsky.social · 18/08/2026
One of the largest universities in Texas is facing a wide range of disruptions following a cyberattack announced on Monday morning therecord.media/university-o...
therecord.media
University of Texas forced to take systems offline in San Antonio after cyberattack
The University of Texas at San Antonio, which serves 40,000 students across six campuses, said its IT team identified threat activity on its academic campus over the weekend and took some systems, inc...
020
jon greig @jgreig.bsky.social · 17/08/2026
Controversial debt consolidation firm Heights Finance said hackers stole SSNs, banking info and more during a May 2026 incident Nearly 750,000 people were affected therecord.media/financial-in...
therecord.media
Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
000
jon greig @jgreig.bsky.social · 13/08/2026
Its @martinmatishak.bsky.social !!!
230
jon greig @jgreig.bsky.social · 13/08/2026
The Trump admin wants to enlist cyber firms to surveil and hack cybercriminals with oversight by DOJ + DHS The memo says they will not sanction any operation that results in loss of life or “rise to the level of use of force or armed attack under international law.” therecord.media/trump-cyber-...
therecord.media
Trump taps cyber firms to go on offensive against criminals
The Trump administration will allow private companies to launch attacks on cybercrime organizations, the White House announced.
000
jon greig @jgreig.bsky.social · 12/08/2026
CISA gave federal agencies two weeks to patch a Microsoft bug that researchers said is being used in a North Korean campaign targeting people applying to jobs in the defense industry therecord.media/cisa-gives-f...
therecord.media
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
031
jon greig @jgreig.bsky.social · 11/08/2026
Municipalities across 4 states are dealing with cyberattacks that damaged critical services Suisun City in CA declared a state of emergency after a recent cyber incident therecord.media/cyberattacks...
therecord.media
Local governments in four states dealing with cyberattacks that have shut down services
Municipalities in California, Oklahoma, Wisconsin and Texas are all recovering from disruptive cyberattacks that have affected government operations.
030