Multiple Threat Actors Exploiting EDRs to Acquire Sensitive Information
ID: 6a3647a5-a8cb-5d85-8ab7-7880ecf64800
STIX ID: report--6a3647a5-a8cb-5d85-8ab7-7880ecf64800
Feed Name: CloudSEK Blog
Threat actors are actively buying and selling services on underground forums to craft and place counterfeit Emergency Data Requests (EDRs) against major platforms (Apple, Snapchat, Twitter) by impersonating government/legal email accounts or exploiting compromised agency domains. These EDRs bypass standard legal process and verification, enabling large-scale PII harvesting and persistent access; actors offer significant payments, and the report recommends mitigations such as DMARC, MFA, strong password policies, and verification of EDR authenticity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
