<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Identity Theft</title><description>Cybersecurity articles tagged #Identity Theft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Dark Web Service Nexus Sells 153M+ Driver Licenses</title><link>https://runtimerebel.com/blog/dark-web-service-nexus-sells-153m-driver-licenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/dark-web-service-nexus-sells-153m-driver-licenses</guid><description>A new dark web service, Nexus, is selling over 153 million drivers&apos; licenses from North America, likely sourced from an identity verification company.</description><pubDate>Wed, 02 Sep 2026 01:59:46 GMT</pubDate><category>Dark Web</category><category>Identity Theft</category><category>Data Breach</category><category>Nexus</category><category>Exploit Forum</category></item><item><title>Unlimited Technology Systems Data Breach Exposes 3.8M Records</title><link>https://runtimerebel.com/blog/unlimited-technology-systems-data-breach-exposes-3-8m-records</link><guid isPermaLink="true">https://runtimerebel.com/blog/unlimited-technology-systems-data-breach-exposes-3-8m-records</guid><description>Unlimited Technology Systems disclosed a data breach exposing PII and PHI of 3.8 million individuals, including Social Security numbers.</description><pubDate>Fri, 07 Aug 2026 08:47:50 GMT</pubDate><category>Data Breach</category><category>Healthcare</category><category>PHI</category><category>PII</category><category>Identity Theft</category></item><item><title>OAuth 2.0 Device Code Phishing Escalates to Industrial Threat</title><link>https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-2-0-device-code-phishing-escalates-to-industrial-threat</guid><description>Device code phishing, exploiting the OAuth 2.0 device authorization grant, is rapidly stealing access tokens. Learn how to defend against this growing threat.</description><pubDate>Fri, 31 Jul 2026 14:09:49 GMT</pubDate><category>Device Code Phishing</category><category>OAuth 2 0</category><category>Access Tokens</category><category>Phishing</category><category>Identity Theft</category></item><item><title>Man Sentenced for Hacking 750 Snapchat Accounts via Phishing</title><link>https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/man-sentenced-for-hacking-750-snapchat-accounts-via-phishing</guid><description>Illinois man Brandon Sudge sentenced to six years for large-scale Snapchat credential harvesting and theft of private content from over 750 victims.</description><pubDate>Fri, 24 Jul 2026 13:50:49 GMT</pubDate><category>Snapchat</category><category>Credential Harvesting</category><category>Identity Theft</category><category>Social Engineering</category></item><item><title>Upbound Group Breach: $13 Million Loss via Acima Lease Fraud</title><link>https://runtimerebel.com/blog/upbound-group-breach-13-million-loss-via-acima-lease-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/upbound-group-breach-13-million-loss-via-acima-lease-fraud</guid><description>Upbound Group discloses a massive data breach involving Acima customer data, resulting in $13 million in fraudulent leases and significant identity theft.</description><pubDate>Thu, 23 Jul 2026 02:51:43 GMT</pubDate><category>Upbound Group</category><category>Acima</category><category>Fintech Fraud</category><category>Identity Theft</category><category>SEC Disclosure</category></item><item><title>Email Account Takeover via 2FA Compromise: Mitigating Identity Theft Risk</title><link>https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/email-account-takeover-via-2fa-compromise-mitigating-identity-theft-risk</guid><description>An identity theft incident highlights how easily email account takeover via compromised 2FA can lead to broader security breaches. Learn to protect your digital identity.</description><pubDate>Wed, 22 Jul 2026 17:24:17 GMT</pubDate><category>Identity Theft</category><category>Account Takeover</category><category>2FA Bypass</category><category>Email Security</category><category>Phishing</category><category>Social Engineering</category></item><item><title>Scattered Spider Sentencing: Analysis of the £29M TfL Breach</title><link>https://runtimerebel.com/blog/scattered-spider-sentencing-analysis-of-the-ps29m-tfl-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/scattered-spider-sentencing-analysis-of-the-ps29m-tfl-breach</guid><description>Two Scattered Spider members sentenced for the 2024 TfL breach, costing £29 million and disrupting 148 systems. Learn about their TTPs and recovery costs.</description><pubDate>Fri, 17 Jul 2026 02:45:29 GMT</pubDate><category>Scattered Spider</category><category>Transport for London</category><category>National Crime Agency</category><category>Social Engineering</category><category>Identity Theft</category></item><item><title>Texas Data Breach Exposes 3M Driver&apos;s Licenses via Vendor</title><link>https://runtimerebel.com/blog/texas-data-breach-exposes-3m-driver-s-licenses-via-vendor</link><guid isPermaLink="true">https://runtimerebel.com/blog/texas-data-breach-exposes-3m-driver-s-licenses-via-vendor</guid><description>A data breach at a third-party vendor of the Texas Parks and Wildlife Department exposed over 3 million driver&apos;s licenses, impacting Texans&apos; PII.</description><pubDate>Fri, 19 Jun 2026 16:54:19 GMT</pubDate><category>Texas</category><category>Data Breach</category><category>TPWD</category><category>Third Party Risk</category><category>Driver S Licenses</category><category>PII Exposure</category><category>Identity Theft</category></item><item><title>University of Nottingham Data Breach: 450,000 Student Records Exposed</title><link>https://runtimerebel.com/blog/university-of-nottingham-data-breach-450000-student-records-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/university-of-nottingham-data-breach-450000-student-records-exposed</guid><description>Nottingham University confirms a data breach affecting over 450,000 students and alumni. Analyze the risks of identity theft and targeted phishing campaigns.</description><pubDate>Thu, 11 Jun 2026 09:38:44 GMT</pubDate><category>University of Nottingham</category><category>Higher Education</category><category>Data Privacy</category><category>PII Leak</category><category>Identity Theft</category></item><item><title>WFP Palestine Breach: 600,000 Gaza Households&apos; Data Exposed</title><link>https://runtimerebel.com/blog/wfp-palestine-breach-600000-gaza-households-data-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/wfp-palestine-breach-600000-gaza-households-data-exposed</guid><description>The UN World Food Programme confirms a data breach in its Palestine registration portal, exposing sensitive data for 600,000 households in the Gaza Strip.</description><pubDate>Thu, 04 Jun 2026 17:09:11 GMT</pubDate><category>UN World Food Programme</category><category>Gaza</category><category>Data Breach</category><category>Humanitarian Security</category><category>Identity Theft</category></item><item><title>French and Spanish Police Dismantle Major Fake ID Marketplace</title><link>https://runtimerebel.com/blog/french-and-spanish-police-dismantle-major-fake-id-marketplace</link><guid isPermaLink="true">https://runtimerebel.com/blog/french-and-spanish-police-dismantle-major-fake-id-marketplace</guid><description>Authorities dismantle a sophisticated marketplace supplying high-quality fraudulent identity documents to smuggling networks across the European Union.</description><pubDate>Thu, 04 Jun 2026 13:15:35 GMT</pubDate><category>Identity Theft</category><category>EU Law Enforcement</category><category>Smuggling Networks</category><category>Document Fraud</category></item><item><title>Dashlane Brute-Force Attack: Mitigation for Stolen Encrypted Vaults</title><link>https://runtimerebel.com/blog/dashlane-brute-force-attack-mitigation-for-stolen-encrypted-vaults</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-brute-force-attack-mitigation-for-stolen-encrypted-vaults</guid><description>Dashlane confirms a brute-force attack where fewer than 20 personal vaults were downloaded. Analyze the technical impact and mitigation strategies for users.</description><pubDate>Tue, 02 Jun 2026 05:40:26 GMT</pubDate><category>Dashlane</category><category>Brute Force</category><category>Password Manager</category><category>Identity Theft</category><category>MFA Bypass</category></item><item><title>Google Chrome DBSC: Preventing Account Takeover via Cookie Theft</title><link>https://runtimerebel.com/blog/google-chrome-dbsc-preventing-account-takeover-via-cookie-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-dbsc-preventing-account-takeover-via-cookie-theft</guid><description>Google Chrome rolls out Device Bound Session Credentials (DBSC) to protect users from session hijacking by cryptographically binding cookies to hardware.</description><pubDate>Fri, 29 May 2026 13:17:47 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Identity Theft</category><category>TPM</category></item><item><title>FBI Warning: Fake FIFA World Cup Sites Target Fans with Fraud</title><link>https://runtimerebel.com/blog/fbi-warning-fake-fifa-world-cup-sites-target-fans-with-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-fake-fifa-world-cup-sites-target-fans-with-fraud</guid><description>FBI warns of fraudulent websites impersonating FIFA for the 2026 World Cup, engaging in data theft, fake ticket sales, and hospitality scams.</description><pubDate>Thu, 28 May 2026 20:53:07 GMT</pubDate><category>FIFA World Cup 2026</category><category>Phishing</category><category>Fraud</category><category>Scam</category><category>FBI</category><category>Online Security</category><category>Identity Theft</category><category>Fake Tickets</category></item><item><title>Carnival Data Breach: 6 Million Customer Records Exposed</title><link>https://runtimerebel.com/blog/carnival-data-breach-6-million-customer-records-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/carnival-data-breach-6-million-customer-records-exposed</guid><description>A data breach at Carnival Cruise Line exposed personal information for nearly 6 million customers, raising significant identity theft risks.</description><pubDate>Thu, 28 May 2026 17:25:28 GMT</pubDate><category>Carnival</category><category>Data Breach</category><category>Personal Data</category><category>Identity Theft</category><category>Cruise Line</category><category>Customer Data</category></item><item><title>Romanian Hacker Sentenced for Breach of Oregon Government Networks</title><link>https://runtimerebel.com/blog/romanian-hacker-sentenced-for-breach-of-oregon-government-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/romanian-hacker-sentenced-for-breach-of-oregon-government-networks</guid><description>Adrian-Tiberiu Oprea sentenced to 56 months for a multi-year cyber campaign targeting Oregon government systems and dozens of U.S. organizations.</description><pubDate>Thu, 28 May 2026 13:25:37 GMT</pubDate><category>Adrian Tiberiu Oprea</category><category>Oregon Government</category><category>Identity Theft</category><category>Financial Fraud</category><category>Credential Theft</category></item><item><title>Ajax Football Club Hack: Suspect Arrested in Almere Data Breach</title><link>https://runtimerebel.com/blog/ajax-football-club-hack-suspect-arrested-in-almere-data-breach</link><guid isPermaLink="true">https://runtimerebel.com/blog/ajax-football-club-hack-suspect-arrested-in-almere-data-breach</guid><description>Dutch police arrested a 35-year-old suspect linked to the AFC Ajax data breach involving the theft of sensitive personal data of players and staff.</description><pubDate>Wed, 27 May 2026 09:16:44 GMT</pubDate><category>AFC Ajax</category><category>Dutch National Police</category><category>Data Breach</category><category>Identity Theft</category><category>Almere</category><category>Credential Theft</category></item><item><title>7-Eleven Data Breach: 185,000 Records Leaked by ShinyHunters</title><link>https://runtimerebel.com/blog/7-eleven-data-breach-185000-records-leaked-by-shinyhunters</link><guid isPermaLink="true">https://runtimerebel.com/blog/7-eleven-data-breach-185000-records-leaked-by-shinyhunters</guid><description>Analysis of the 7-Eleven data breach involving threat actor ShinyHunters, impacting 185,000 users and exposing sensitive PII including dates of birth.</description><pubDate>Tue, 26 May 2026 13:13:00 GMT</pubDate><category>7 Eleven</category><category>ShinyHunters</category><category>PII Leak</category><category>Data Breach</category><category>Identity Theft</category></item><item><title>Cyber-Enabled Cargo Theft: How Phishing and Identity Theft Hijack Freight</title><link>https://runtimerebel.com/blog/cyber-enabled-cargo-theft-how-phishing-and-identity-theft-hijack-freight</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyber-enabled-cargo-theft-how-phishing-and-identity-theft-hijack-freight</guid><description>Cyber-enabled cargo crime leverages stolen credentials and phishing to reroute freight, replacing traditional hijackings with digital fraud and identity theft.</description><pubDate>Thu, 14 May 2026 16:47:04 GMT</pubDate><category>Cargo Theft</category><category>Supply Chain Security</category><category>Nmfta</category><category>Identity Theft</category><category>Logistics Security</category></item><item><title>Gavril Sandu Extradited to US for Historical Phishing Scheme</title><link>https://runtimerebel.com/blog/gavril-sandu-extradited-to-us-for-historical-phishing-scheme</link><guid isPermaLink="true">https://runtimerebel.com/blog/gavril-sandu-extradited-to-us-for-historical-phishing-scheme</guid><description>Gavril Sandu, a Romanian national, faces US charges for a 2007-2008 phishing operation that targeted financial institutions and thousands of victims.</description><pubDate>Wed, 06 May 2026 12:48:13 GMT</pubDate><category>Gavril Sandu</category><category>Phishing</category><category>Identity Theft</category><category>Extradition</category><category>Cybercrime</category><category>Financial Fraud</category></item><item><title>FBI Warning: Cyber-Enabled Cargo Theft Losses Surge to $725 Million</title><link>https://runtimerebel.com/blog/fbi-warning-cyber-enabled-cargo-theft-losses-surge-to-725-million</link><guid isPermaLink="true">https://runtimerebel.com/blog/fbi-warning-cyber-enabled-cargo-theft-losses-surge-to-725-million</guid><description>FBI alerts logistics firms to a massive rise in cyber-enabled cargo theft involving identity theft and fraudulent carrier profiles. Protect your supply chain.</description><pubDate>Thu, 30 Apr 2026 16:37:05 GMT</pubDate><category>Cargo Theft</category><category>Logistics Security</category><category>Fraud</category><category>Identity Theft</category><category>Supply Chain Security</category></item><item><title>Roblox Account Hijacking: 610,000 Accounts Compromised and Sold</title><link>https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</link><guid isPermaLink="true">https://runtimerebel.com/blog/roblox-account-hijacking-610000-accounts-compromised-and-sold</guid><description>Ukrainian police arrested a group for hijacking 610,000 Roblox accounts and generating $225,000 in profits through illegal sales of user data.</description><pubDate>Wed, 29 Apr 2026 20:30:38 GMT</pubDate><category>Roblox</category><category>Account Takeover</category><category>Credential Stuffing</category><category>Cybercrime</category><category>Identity Theft</category></item><item><title>Detecting and Mitigating Money Mule Accounts to Prevent APP Fraud</title><link>https://runtimerebel.com/blog/detecting-and-mitigating-money-mule-accounts-to-prevent-app-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-and-mitigating-money-mule-accounts-to-prevent-app-fraud</guid><description>Learn how intelligence-driven mule account detection disrupts the fraud ecosystem and prevents Authorized Push Payment losses before funds are exfiltrated.</description><pubDate>Wed, 29 Apr 2026 08:56:59 GMT</pubDate><category>Money Mule</category><category>APP Fraud</category><category>Financial Crime</category><category>Fraud Detection</category><category>Identity Theft</category></item><item><title>France Titres Data Breach: Identity Documents Stolen by L33T Hacker</title><link>https://runtimerebel.com/blog/france-titres-data-breach-identity-documents-stolen-by-l33t-hacker</link><guid isPermaLink="true">https://runtimerebel.com/blog/france-titres-data-breach-identity-documents-stolen-by-l33t-hacker</guid><description>France Titres confirms a data breach after threat actor L33T claims to have stolen 400,000 files, including identity document scans and personal citizen data.</description><pubDate>Wed, 22 Apr 2026 00:42:34 GMT</pubDate><category>France Titres</category><category>L33T</category><category>Identity Theft</category><category>France</category><category>BreachForums</category></item><item><title>DraftKings Hacker Sentenced: Lessons in Credential Stuffing Defense</title><link>https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/draftkings-hacker-sentenced-lessons-in-credential-stuffing-defense</guid><description>Analysis of the sentencing of Kamerin Stokes following the 2022 DraftKings breach, detailing credential stuffing TTPs and account takeover prevention strategies.</description><pubDate>Fri, 17 Apr 2026 12:29:34 GMT</pubDate><category>DraftKings</category><category>Credential Stuffing</category><category>Account Takeover</category><category>Insider Threat</category><category>Identity Theft</category></item><item><title>DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud</title><link>https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</guid><description>Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.</description><pubDate>Thu, 16 Apr 2026 08:40:47 GMT</pubDate><category>DPRK</category><category>Laptop Farm</category><category>Insider Threat</category><category>Identity Theft</category><category>Lazarus Group</category></item><item><title>Hybrid Cybercrime: Mail Interception via Vacant Homes for Fraud</title><link>https://runtimerebel.com/blog/hybrid-cybercrime-mail-interception-via-vacant-homes-for-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/hybrid-cybercrime-mail-interception-via-vacant-homes-for-fraud</guid><description>Threat actors exploit vacant homes as &apos;drop addresses&apos; to intercept mail, enabling sophisticated hybrid cybercrime like identity theft and financial fraud.</description><pubDate>Thu, 02 Apr 2026 16:26:56 GMT</pubDate><category>Mail Interception</category><category>Hybrid Cybercrime</category><category>Identity Theft</category><category>Fraud</category><category>Physical Security</category></item><item><title>Hightower Holding Data Breach: 130,000 Records Compromised</title><link>https://runtimerebel.com/blog/hightower-holding-data-breach-130000-records-compromised</link><guid isPermaLink="true">https://runtimerebel.com/blog/hightower-holding-data-breach-130000-records-compromised</guid><description>Wealth management firm Hightower Holding reports a data breach affecting 130,000 people. Stolen data includes names, Social Security numbers, and driver&apos;s licenses.</description><pubDate>Thu, 26 Mar 2026 16:32:38 GMT</pubDate><category>Hightower Holding</category><category>PII Theft</category><category>Financial Services</category><category>Identity Theft</category></item><item><title>Navia Data Breach: 2.7M Individuals&apos; Sensitive Data Exposed</title><link>https://runtimerebel.com/blog/navia-data-breach-2-7m-individuals-sensitive-data-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/navia-data-breach-2-7m-individuals-sensitive-data-exposed</guid><description>Navia Benefit Solutions discloses a data breach exposing sensitive information for nearly 2.7 million individuals. Understand the impact and mitigation.</description><pubDate>Fri, 20 Mar 2026 00:36:12 GMT</pubDate><category>Navia</category><category>Data Breach</category><category>Personal Data</category><category>PHI</category><category>PII</category><category>Healthcare Data</category><category>Identity Theft</category></item><item><title>Starbucks Data Breach: Unauthorized Access to Partner Central Accounts</title><link>https://runtimerebel.com/blog/starbucks-data-breach-unauthorized-access-to-partner-central-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/starbucks-data-breach-unauthorized-access-to-partner-central-accounts</guid><description>Starbucks discloses a data breach affecting hundreds of employees, exposing SSNs and financial details via compromised Partner Central accounts in May 2024.</description><pubDate>Fri, 13 Mar 2026 12:20:01 GMT</pubDate><category>Starbucks</category><category>Partner Central</category><category>PII Exposure</category><category>Credential Stuffing</category><category>Identity Theft</category></item><item><title>LexisNexis Data Breach Confirmed: 400,000 Records Leaked</title><link>https://runtimerebel.com/blog/lexisnexis-data-breach-confirmed-400000-records-leaked</link><guid isPermaLink="true">https://runtimerebel.com/blog/lexisnexis-data-breach-confirmed-400000-records-leaked</guid><description>LexisNexis confirms data breach following hackers&apos; leak of 2GB of files, impacting 400,000 personal information records. Understand the implications.</description><pubDate>Wed, 04 Mar 2026 20:15:54 GMT</pubDate><category>LexisNexis</category><category>Data Breach</category><category>Personal Information</category><category>Data Leak</category><category>Identity Theft</category></item><item><title>Alabama Man Pleads Guilty to Extortion via Social Media Hijacking</title><link>https://runtimerebel.com/blog/alabama-man-pleads-guilty-to-extortion-via-social-media-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/alabama-man-pleads-guilty-to-extortion-via-social-media-hijacking</guid><description>Devin Deandre Moore admits to hijacking hundreds of accounts for sextortion. Analysis of the TTPs used in this large-scale digital extortion campaign.</description><pubDate>Mon, 02 Mar 2026 20:13:38 GMT</pubDate><category>Social Media Hacking</category><category>Extortion</category><category>Cyberstalking</category><category>Phishing</category><category>Identity Theft</category></item><item><title>Stolen Credentials and the Escalation of Agentic AI Attacks</title><link>https://runtimerebel.com/blog/stolen-credentials-and-the-escalation-of-agentic-ai-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/stolen-credentials-and-the-escalation-of-agentic-ai-attacks</guid><description>IBM X-Force reports 56% of 2025 vulnerabilities require no authentication, enabling agentic AI to weaponize stolen credentials and expand attack blast radius.</description><pubDate>Wed, 25 Feb 2026 16:33:22 GMT</pubDate><category>IBM X Force</category><category>Agentic AI</category><category>Identity Theft</category><category>Credential Access</category><category>Authentication Bypass</category></item><item><title>Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure</title><link>https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</guid><description>Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.</description><pubDate>Mon, 23 Feb 2026 16:26:29 GMT</pubDate><category>DPRK</category><category>Identity Theft</category><category>Remote Work Fraud</category><category>Insider Threat</category><category>Lazarus Group</category></item></channel></rss>