CyberWire Daily

Kimsuky gets kim-sunk.

5 snips
Aug 12, 2025
Sean Deuby, Principal Technologist at Semperis, shares his expertise on ransomware and identity security challenges. He discusses the recent data leak from North Korean hackers, revealing alarming insights into their operations. The conversation also covers a ransomware attack on a Dutch lab that compromised medical data for hundreds of thousands. Deuby emphasizes how the rise of AI is reshaping cyber threats, while cybercriminals increasingly target identity systems. The importance of fundamental security practices in our evolving threat landscape is a key takeaway.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Kimsuky Leak Reveals Internal Tools

  • Two hackers leaked 8.9 GB of Kimsuky back-end data including phishing kits and operational logs.
  • The exposure may disrupt Kimsuky but long-term impact remains uncertain for analysts and defenders.
ADVICE

Report Breaches Immediately

  • Report breaches promptly: the Dutch lab waited nearly five weeks, violating the EU's 72-hour rule.
  • Delayed disclosure damaged trust and forced partners to move testing to other labs.
INSIGHT

Ransomware Economies Are Adaptive

  • RansomHub allegedly stole 500 GB from Manpower and later removed some data from its leak site.
  • Removal suggests some victims may pay ransoms, reflecting evolving extortion economics.
Get the Snipd Podcast app to discover more snips from this episode
Get the app