< Back to all clusters
[TECHNOLOGY] · Italy, United States · 2 sources

AI‑driven insider leaks boost data‑breach extortion scams

The Verizon 2026 Data Breach Investigations Report shows that 60% of insider data misuse now stems from productivity‑driven adoption of AI tools rather than malicious intent. Security teams are confronting “Shadow AI” and autonomous agents such as those built on the Model Context Protocol (MCP), which can access enterprise systems with admin credentials, create blind spots in logs, and make forensic attribution nearly impossible.

Criminal groups are exploiting large‑scale breaches for extortion. Threat actors using information stolen by the ShinyHunters breach have sent emails claiming access to victims’ devices, threatening to publish intimate data unless a $2,000 Bitcoin ransom is paid. The messages cite compromised databases—including an Amtrak data set—to lend credibility to the threats.

Together, the rise of AI‑mediated insider leaks and the monetisation of breached data illustrate a shifting threat landscape where non‑malicious employee behaviour enables sophisticated extortion campaigns.

Entities: Amtrak · Model Context Protocol · Shadow AI · ShinyHunters · Verizon