PrivacySignal
Breach

Online ad firm Adform’s script compromised to steal cryptocurrency

BleepingComputer · · International · Data Breaches

Adform, an online advertising company, had a script on its platform compromised in a supply-chain attack. The malicious code silently replaced cryptocurrency wallet addresses copied to users' clipboards with addresses controlled by the attacker, redirecting funds without the victim's knowledge.

Why this matters: You did not visit a shady site. You did not click a bad link. You just visited a normal website that happened to run Adform's ad code, and that was enough. This is the real threat of supply-chain attacks: the damage travels through trusted infrastructure. Clipboard hijacking is especially nasty because the whole point of copying a wallet address is to avoid mistakes. The attacker exploited that habit. Any site running third-party ad scripts is a potential delivery vehicle, and most visitors have no way to know what those scripts are doing in the background.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
HIPAA Journal · · US Federal

FTC Rescinds 2021 Policy Statement on Health App Data Breaches

The Federal Trade Commission has rescinded a 2021 policy statement that had extended the Health Breach Notification Rule to cover health apps and connected devices. The original statement had broadened consumer protections by requiring health technology companies outside traditional HIPAA coverage to notify users of data breaches.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

#breach#healthcare#regulation Read original →