logo

Multiple Threat Actors Exploiting EDRs to Acquire Sensitive Information

ID: 6a3647a5-a8cb-5d85-8ab7-7880ecf64800

STIX ID: report--6a3647a5-a8cb-5d85-8ab7-7880ecf64800

Feed Name: CloudSEK Blog

Threat Score
65/100

Date Published: 2022-08-11

Date Updated: 2026-04-27

...
...

Threat actors are actively buying and selling services on underground forums to craft and place counterfeit Emergency Data Requests (EDRs) against major platforms (Apple, Snapchat, Twitter) by impersonating government/legal email accounts or exploiting compromised agency domains. These EDRs bypass standard legal process and verification, enabling large-scale PII harvesting and persistent access; actors offer significant payments, and the report recommends mitigations such as DMARC, MFA, strong password policies, and verification of EDR authenticity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.