August at a glance
August was full of fast, low effort attacks. Google Ads contacts were stolen, PayPal accounts appeared on the dark web, and ransomware groups are increasing pressure on Australian targets. The common tactic this month is speed. Hackers are cashing in on quick wins instead of dragging out campaigns.
Google Ads CRM breach - new updates
Hacking group ShinyHunters convinced Google staff to approve a fake Salesforce app, which opened a path into a corporate Salesforce database.
A modified Data Loader was then used to pull business contact records and stored CRM notes tied to Ads accounts and outreach tools. No passwords or payment data were taken.

Why this matters
This data links real people to real campaigns and account structures. With that, an attacker can impersonate your marketing team, approach your customers with believable follow ups, or push fake ad credits/budget changes.
We’ve seen similar data reused in similar attacks months after the initial breach.
Gridware’s watchpoint team has tracked overlap between ShinyHunters and Scattered Spider tactics this year. Almost every attack this month has been caused by access given via phone, or help desks, and living off the land once inside.
If you want the deep dive, see our Google piece and the Scattered Spider blog articles.
Quick actions if your business uses Google ads
- Check Salesforce connected apps and remove anything unfamiliar
- Refresh tokens for Ads and CRM links, then set them up again
- Require approval before any new app connects to CRM or Ads
- Run a quick voice phishing drill with marketing and sales teams
PayPal data dump – Hackers say they have passwords, yet to be confirmed
A post on the dark web dataset claims to include more than 16 million PayPal accounts. Their records include email addresses, hashed passwords, and some linked details.
PayPal has not confirmed a new breach. Large dumps often mix fresh stolen data with older leaks, which makes verification messy.
We can’t say whether customers are in danger or not as of now.

Alleged leak of 16 million PayPal accounts surfaces on the dark web.
Even if parts of the dump are old, it gives criminals a pre validated list of PayPal users.
Expect invoice scams, refund scams, and ‘account locked’ prompts that look convincing. For businesses, finance and support inboxes are the likely targets.
Quick actions for PayPal users and businesses
- Turn on passkeys in PayPal and stop reusing passwords anywhere
- Turn on payment verification steps for any email based request
- setting your DMARC policy (Domain-based Message Authentication, Reporting and Conformance) to a stricter setting so attackers can’t easily send spoofed emails that look like they’re from your domain.
Australia’s ransomware payout rate - why attackers keep coming back
Recent research shows Australian victims pay ransom at much higher rates than the global average. Locally, 43% of organisations paid, compared to 32% worldwide.
The main driver is pressure to stay operational as fast as possible. When backups fail, vendor access drags, or recovery takes too long, paying seems like the only path back online.

Australia has become a prime target for ransomware groups, with payout rates higher here than the global average.
Why this happens
Sectors like healthcare, nonprofits, education, and government have severe consequences when systems are down. Boards usually weigh the impact of downtime against the cost of the ransom.
Insurance also shapes the decision, where some Australian policies still cover ransom payments, and that safety net can push leadership toward paying instead of holding out.
Attackers understand these dynamics. They focus on markets where the chance of payout is high, and the time pressure is immediate.
Australia has become one of those markets. That shift has changed attacker behaviour, with less emphasis on long dwell times and more focus on fast extortion cycles.
What changes the outcome
- You need backups that are tested and can’t be altered
- Your networks need to be designed to contain the impact of a breach
- You need an Incident Response playbook that names decision owners and actions
- You have clear positions pre agreed with legal and insurance, so time is never wasted
Scattered Spider - What we’ve learned from their latest moves
Earlier this month we broke down Scattered Spider’s methods in a webinar.
They use phone calls and support desks as their entry point, slipping in with a convincing story instead of a technical exploit. Once they’re inside the network, they spread fast and make use of the same tools your team does.
We’re seeing a clear overlap between Scattered Spider and other groups like ShinyHunters. These hacking groups are learning from each other, sharing tactics, and hitting small to midsized firms that struggle to keep phone and help desk verification secure.
If you missed it, we published the key takeaways from the session.

Salt Typhoon - Telecom breach shows state linked activity
Orange, the largest telecom in France, confirmed an attack tied to a group tracked as Salt Typhoon.
The group has been connected to state sponsored operations in China, and this incident adds to the picture of how telecom networks are being mapped and used at scale.
Salt Typhoon is one of several groups operating in the grey space between government interests and criminal activity. The part that should concern Australian businesses is how often these campaigns reach their target through a third party.
We’ve been tracking Salt Typhoon for some time, and their activity is moving closer to Australia. The sectors that hold the most sensitive data and run critical systems such as telecom, healthcare and government should treat this as a warning sign.




