Gridware Logo

August Cyber Recap

By Ahmed Khanji Updated 21 August 2025 5 min read

in 𝕏
August Cyber Recap

August at a glance

August was full of fast, low effort attacks. Google Ads contacts were stolen, PayPal accounts appeared on the dark web, and ransomware groups are increasing pressure on Australian targets. The common tactic this month is speed. Hackers are cashing in on quick wins instead of dragging out campaigns.

Hacking group ShinyHunters convinced Google staff to approve a fake Salesforce app, which opened a path into a corporate Salesforce database.

A modified Data Loader was then used to pull business contact records and stored CRM notes tied to Ads accounts and outreach tools. No passwords or payment data were taken.

Why this matters

This data links real people to real campaigns and account structures. With that, an attacker can impersonate your marketing team, approach your customers with believable follow ups, or push fake ad credits/budget changes.

We’ve seen similar data reused in similar attacks months after the initial breach.

Gridware’s watchpoint team has tracked overlap between ShinyHunters and Scattered Spider tactics this year. Almost every attack this month has been caused by access given via phone, or help desks, and living off the land once inside.

If you want the deep dive, see our Google piece and the Scattered Spider blog articles.

Quick actions if your business uses Google ads

  • Check Salesforce connected apps and remove anything unfamiliar
  • Refresh tokens for Ads and CRM links, then set them up again
  • Require approval before any new app connects to CRM or Ads
  • Run a quick voice phishing drill with marketing and sales teams

PayPal data dump – Hackers say they have passwords, yet to be confirmed

A post on the dark web dataset claims to include more than 16 million PayPal accounts. Their records include email addresses, hashed passwords, and some linked details.

PayPal has not confirmed a new breach. Large dumps often mix fresh stolen data with older leaks, which makes verification messy.

We can’t say whether customers are in danger or not as of now.

Alleged leak of 16 million PayPal accounts surfaces on the dark web.

Even if parts of the dump are old, it gives criminals a pre validated list of PayPal users.

Expect invoice scams, refund scams, and ‘account locked’ prompts that look convincing. For businesses, finance and support inboxes are the likely targets.

Quick actions for PayPal users and businesses

  • Turn on passkeys in PayPal and stop reusing passwords anywhere
  • Turn on payment verification steps for any email based request
  • setting your DMARC policy (Domain-based Message Authentication, Reporting and Conformance) to a stricter setting so attackers can’t easily send spoofed emails that look like they’re from your domain.

Australia’s ransomware payout rate - why attackers keep coming back

Recent research shows Australian victims pay ransom at much higher rates than the global average. Locally, 43% of organisations paid, compared to 32% worldwide.

The main driver is pressure to stay operational as fast as possible. When backups fail, vendor access drags, or recovery takes too long, paying seems like the only path back online.

Australia has become a prime target for ransomware groups, with payout rates higher here than the global average.

Why this happens

Sectors like healthcare, nonprofits, education, and government have severe consequences when systems are down. Boards usually weigh the impact of downtime against the cost of the ransom.

Insurance also shapes the decision, where some Australian policies still cover ransom payments, and that safety net can push leadership toward paying instead of holding out.

Attackers understand these dynamics. They focus on markets where the chance of payout is high, and the time pressure is immediate.

Australia has become one of those markets. That shift has changed attacker behaviour, with less emphasis on long dwell times and more focus on fast extortion cycles.

What changes the outcome

  • You need backups that are tested and can’t be altered
  • Your networks need to be designed to contain the impact of a breach
  • You need an Incident Response playbook that names decision owners and actions
  • You have clear positions pre agreed with legal and insurance, so time is never wasted

Scattered Spider - What we’ve learned from their latest moves

Earlier this month we broke down Scattered Spider’s methods in a webinar.

They use phone calls and support desks as their entry point, slipping in with a convincing story instead of a technical exploit. Once they’re inside the network, they spread fast and make use of the same tools your team does.

We’re seeing a clear overlap between Scattered Spider and other groups like ShinyHunters. These hacking groups are learning from each other, sharing tactics, and hitting small to midsized firms that struggle to keep phone and help desk verification secure.

If you missed it, we published the key takeaways from the session.

Salt Typhoon - Telecom breach shows state linked activity

Orange, the largest telecom in France, confirmed an attack tied to a group tracked as Salt Typhoon.

The group has been connected to state sponsored operations in China, and this incident adds to the picture of how telecom networks are being mapped and used at scale.

Salt Typhoon is one of several groups operating in the grey space between government interests and criminal activity. The part that should concern Australian businesses is how often these campaigns reach their target through a third party.

We’ve been tracking Salt Typhoon for some time, and their activity is moving closer to Australia. The sectors that hold the most sensitive data and run critical systems such as telecom, healthcare and government should treat this as a warning sign.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.