A ransomware group attempted to attack dozens of major US financial and business firms by creating at least 72 fake websites to steal passwords and authentication data from employees at targeted companies such as Blackstone, Apollo Global Management, KKR, Bain Capital, Bridgewater Associates, TPG, CME Group, and Moody’s. The hackers called employees’ personal mobile phones, posing as IT support, and tricked them into updating passkeys or multi-factor authentication, then directed them to fake websites with credible-sounding names like “passkeyhelpdesk” or “secure-passkey.” Google said that over five weeks, the cybercriminal group set up digital traps for more than 200 companies, including non-financial firms like Uber, Zillow, Levi Strauss, and law firms Paul Hastings and Greenberg Traurig. In some cases, companies paid ransoms, but it has not been confirmed whether the attempted attacks on the named firms were successful.
Bain Capital is a target of a ransomware group's phishing attack, posing a cybersecurity threat.
Bridgewater AssociatesPrivate▼ Negative
Regulationrelevance
Targeted by ransomware group via fake websites to steal employee data
Greenberg TraurigPrivate± Mixed
relevance
Paul HastingsPrivate± Mixed
relevance
Related news
GlobalSingaporeJapanGermanyIndiaAustraliaUnited States
▲
Yubico and Okta Survey Finds 43% of Security Pros Still Use Passwords at Work
A new survey from Yubico and Okta found that 43% of cybersecurity and IT professionals still rely on passwords at work even though most know passkeys are more secure. The annual 2026 Global State of Authentication report, conducted by Talker Research, surveyed nearly 2,000 cybersecurity and IT professionals across nine countries, and found that 52% inherited passwords on their first day, establishing legacy onboarding defaults that dictate long-term security habits. The survey also found that 44% suffered an AI-driven attack in the last 12 months, with Singapore experiencing the highest rate globally at 58%, compared with Japan at 30% and Germany at 38%, while 39% of security professionals failed to distinguish AI-generated text from human writing. India at 68%, Australia at 60%, and the U.S. at 56% showed the highest proportion of workers very familiar with passkeys, yet 50% of U.S. security pros still use passwords at work, leading all surveyed markets in legacy password dependency. Yubico and Okta said they are partnering to streamline how enterprise identity systems issue, manage, and enforce hardware-backed credentials, embedding phishing resistance into modern access management platforms to help IT teams eliminate password dependencies without adding operational friction.
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) ▲Technology
Cybersecurity & Digital Trust › Identity & Access Management ▲Technology
OKTA · Demand · Positive Okta is partnering with Yubico to streamline enterprise issuance and enforcement of hardware-backed phishing-resistant credentials, expanding its identity platform offering.
Yubico · Demand · Positive Yubico co-authored the report and is partnering with Okta to embed hardware-backed phishing-resistant credentials into enterprise access management.
Tiny Completes $1.9 Million Acquisition of Oso Cloud
Tiny Ltd. has completed its acquisition of the assets comprising Oso Cloud, an enterprise software business specializing in authorization and access control, for approximately $1.9 million in cash consideration. The deal closed on October 1, 2026, and was funded with Tiny's balance sheet cash, comprising approximately $1.2 million paid at closing and an aggregate holdback of approximately $0.7 million for transition services and transaction adjustments. Founded in 2019, Oso Cloud had approximately $5.3 million in annualized recurring revenue at closing and served approximately 80 customers in security, fintech and developer software on recurring subscription contracts, including several multi-year agreements. Including Oso Cloud, Tiny's pro forma annualized recurring revenue would rise approximately 7.6 percent, from $70.0 million to approximately $75.4 million. Chief Executive Officer Austin Singhera said controlling access to sensitive data and critical systems is fundamental to how large enterprises operate securely, especially as new applications and AI tools reshape how work gets done.
Proof Appoints Jeremiah Glodoveza as Chief Marketing Officer
Proof, the identity authorization network, announced the appointment of Jeremiah Glodoveza as Chief Marketing Officer, tasking him with leading the company's global marketing, brand, and communications. Glodoveza joins from Nuvei, where as Senior Vice President, Head of Global Branding and Communications he led communications for its $2.75 billion acquisition of Payoneer and completed a company-wide rebrand. He previously built the global brand and demand engine at cross-border payments firm Nium and, at Early Warning Services, was a founding team member who helped launch Zelle. Proof, founded as Notarize, pioneered remote online notarization and drove its enactment into law across 47 U.S. states; its platform is now connected with Visa's global network and in commercial deployment with multiple Tier-1 U.S. banks. In recent months Proof launched x401, an open, issuer-neutral protocol for verifying the human authority behind AI agent actions, joined the FIDO Alliance, and launched a portable digital identity for banks after FinCEN and federal banking agencies recognized verifiable credentials under customer identification program rules.
Cybersecurity & Digital Trust › Identity & Access Management Talent
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) Talent
Proof (formerly Notarize) · Capital · Positive Proof appoints Jeremiah Glodoveza as Chief Marketing Officer to lead global marketing, brand, and communications.
Socure Adds Mobile Driver's License Verification via Google and Samsung Wallets
Socure has launched U.S. mobile driver's license verification within DocV, its identity verification product, allowing organizations to cryptographically verify mDLs against the issuing state authority when presented from Google Wallet and Samsung Wallet during remote onboarding and step-up flows. The launch follows a September 8, 2026 joint FAQ from FinCEN, the Federal Reserve Board, the FDIC, the OCC and the NCUA confirming that an unexpired, government-issued verifiable digital credential can qualify as documentary evidence under the Customer Identification Program Rule, provided the institution has the technology to extract the required information and still forms a reasonable belief of the customer's true identity. ABI Research projects the U.S. mDL install base will grow from 21.7 million in 2025 to 143 million by 2030, with 40 states issuing digital licenses; today 21 states issue mDLs conforming to the ISO/IEC 18013-5 standard, more than 8 million credentials are active, and roughly 45% of Americans live where one is available. Socure said mDL verification complements its physical document capture rather than replacing it, and that its DocV now supports remote presentation under Part 7 of the ISO standard from Google Wallet and Samsung Wallet, addressing the higher-risk remote verifications that have been supported unevenly across wallets. The announcement comes alongside an extension of Socure's partnership with Xcelerate Solutions to support public sector use cases under the Login.gov Next Generation Identity Proofing Blanket Purchase Agreement, operating within Socure's FedRAMP Moderate environment.
Socure · Demand · Positive Socure extended its partnership with Xcelerate Solutions for public sector use under the Login.gov Next Generation Identity Proofing BPA.
Xcelerate Solutions · Demand · Positive Xcelerate Solutions extended its partnership with Socure to support public sector identity proofing use cases under the Login.gov BPA.
005930.KO · Technology · Positive Socure's DocV now supports remote mDL presentation from Samsung Wallet, expanding the utility of Samsung's digital wallet credential.
GOOG · Technology · Positive Socure's DocV now supports remote mDL presentation from Google Wallet, expanding the utility of Google's digital wallet credential.
Okta Shares Rise as Morgan Stanley Lifts Price Target to $245
Morgan Stanley raised its price target on Okta to $245 from $200 while keeping an Overweight rating, sending the cybersecurity company's shares up 1% in morning trading Tuesday. Analyst Meta Marshall cited potential growth tied to the expanding use of artificial intelligence agents, following Okta's investor event earlier this month where investors assessed the company's prospects in agentic identity. Marshall said investor interest has been broadening beyond larger cybersecurity companies such as Palo Alto Networks and CrowdStrike, with Okta and Fortinet increasingly part of those discussions, while SentinelOne and SailPoint are considered in some cases. She expects the benefits from agentic identity to develop gradually for Okta, and pointed to work on technical debt as a factor that could support progress this year. Marshall maintained that the company has additional room to expand as AI-agent adoption develops.
Aembit Adds Okta Cross App Access Support, Alphabet Executive Helen Riley to Board
Aembit announced support for Okta's Cross App Access protocol to manage enterprise AI agent access, and revealed that Helen Riley, an executive at Alphabet's X, is joining its board of directors. The XAA integration is intended to streamline authorization and oversight for automated agent workflows used by corporate customers. The XAA integration and Helen Riley's board role are only part of the broader story around Okta's identity platform, and Simply Wall St flagged one warning sign for Okta. Okta positions itself as an identity partner for enterprises that want a single control point governing how humans and software agents reach critical systems, so moves around Cross App Access plug directly into how the firm aims to sit between corporate users, AI tools, and cloud infrastructure. The article points toward a $122 fair value for Okta.
Artificial Intelligence › Agentic AI & Autonomous Workflows ▲Technology
Cybersecurity & Digital Trust › AI Security & Agent Guardrails ▲Technology
Cybersecurity & Digital Trust › Workforce & Customer IAM (SSO/MFA) ▲Technology
Aembit · Technology · Positive Aembit announced support for Okta's Cross App Access protocol to manage enterprise AI agent access, a product/technology development.
OKTA · · Neutral Aembit adds support for Okta's Cross App Access protocol, but the article only notes a Simply Wall St warning sign and a $122 fair value with no concrete Okta development.