CAPTCHA Scam Triggers SMS Fraud

Plus, U.S. utility firm Itron discloses breach of internal IT network

Good morning! Here’s what’s up.

People

Heligan Strategic Advisory, a newly created specialist risk intelligence and investigations unit of the Heligan Group, has named Adam Irwin as managing partner of the new unit.

Clips ✂️

Infoblox, Fake CAPTCHA Scam Triggers SMS Fraud

As cybercriminals evolve their tactics, even routine web interactions are being weaponized to generate financial fraud across digital and telecom ecosystems. Infoblox has uncovered a new fraud scheme in which fake CAPTCHA pages are used to trigger international SMS charges, exposing users and telecom operators to hidden costs. The fake CAPTCHA SMS fraud tactic represents a new variation of international revenue share fraud, where users unknowingly authorize premium messaging activity while attempting to complete what appears to be a standard verification step.

According to Infoblox’s threat intelligence research, the attack begins with websites that mimic familiar CAPTCHA prompts. Instead of verifying human activity, these pages guide users through actions that result in sending international or premium SMS messages. Each message generates revenue that is shared among fraud operators through leased phone numbers, turning simple interactions into monetized events.

by Cyber Technology Insights

American utility firm Itron discloses breach of internal IT network

Utility technology company Itron, Inc. has disclosed that an unauthorized third party accessed some of its internal systems during a cyberattack.

The company states that it activated its cybersecurity response plan when detecting the activity last month, notified law enforcement authorities, and engaged external advisors to support the investigation and incident containment.

“On April 13, 2026, Itron, Inc. was notified that an unauthorized third party had gained access to certain of its systems,” the company says in an 8-K filing with the U.S. Securities and Exchange Commission (SEC).

“The company activated its cybersecurity response plan and launched an investigation with the support of external advisors to assess, mitigate, remediate, and contain the unauthorized activity.”

The unauthorized activity has now been blocked, and the company stated that it has observed no follow-up activity.

by BleepingComputer

ADT confirms data breach after ShinyHunters leak threat

Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid.

In a statement shared today, the company said it detected unauthorized access to customer and prospective customer data on April 20, after which it terminated the intrusion and launched an investigation.

This investigation determined that personal information was stolen during the breach.

"The investigation confirmed that the information involved was limited to names, phone numbers, and addresses," ADT told BleepingComputer.

"In a small percentage of cases, dates of birth and the last four digits of Social Security numbers or Tax IDs were included. Critically, no payment information — including bank accounts or credit cards — was accessed, and customer security systems were not affected or compromised in any way."

by BleepingComputer

One ransomware crew now drives half of all cyber claims: At-Bay

A single ransomware crew exploiting a single brand of firewall is now driving nearly half of all cyber insurance claims, At-Bay has warned, in a finding that recasts how underwriters and brokers should be thinking about risk selection.

The cyber carrier's 2026 InsurSec Report, drawn from more than 6,500 claims and 100,000 policy years, concluded that ransomware has entered an infrastructure-driven phase.

Attackers, it said, are no longer hunting by industry or company size but by the network appliances their targets happen to run.

Nearly three in four ransomware attacks, or 73%, began with a VPN in 2025 — a share that has almost doubled in two years.

Akira's SonicWall playbook

SonicWall topped the list of most-targeted VPNs for the first time, linked to 27% of ransomware claims. Akira alone accounted for more than 40%, the highest concentration of a single strain on At-Bay's books, with SonicWall appliances present in 86% of its attacks.

by Insurance Business

Medtronic says cyberattack on IT network has not disrupted operations

Medical device maker Medtronic said on Monday a cyberattack on its computer systems last week did not affect its products or ability ‌to meet patient needs, and is not expected to materially impact its business or financial results.

Medtronic said the attack that hit the network supporting its corporate IT systems did not impact its products, ⁠patient safety, manufacturing or distribution operations.

The incident, disclosed in a statement on Friday, underscores growing cyber risks for medical device makers, as attacks disrupt critical health services, raising concerns over patient safety and data security.

The IT network remain separate from those that support its products, manufacturing and distribution operations, Medtronic said on Friday.

Peer ‌Stryker last month reported a destructive cyberattack that delayed surgeries for patients and caused widespread disruption to its business, including its ability to process orders, make products and ship them to ⁠customers.

by Reuters

Board Oversight of AI: Do Boards Need AI Experts?

As the use of artificial intelligence (AI) across industries increases rapidly, many boards of directors are considering whether they have the expertise necessary to maintain effective oversight of AI-related opportunities and risks. As the SEC has made clear regarding cybersecurity, boards must find a way to exercise their supervisory obligations, even in technical areas, if those areas present enterprise risks. A frequent question in this context is whether boards should have a director who is an “AI expert.”

In this Debevoise Update, we highlight three considerations for boards evaluating the need for AI expertise in the boardroom.

Adding a Dedicated AI Expert May Present Challenges. While appointing a director with AI expertise may be appealing, it can present practical and governance challenges. First, the pool of individuals with both deep AI expertise and the qualifications to serve effectively as a public company director is limited.

by Debevoise & Plimpton

X