- Gone Phishing
- Posts
- Sea Turtle surfaces in Holland targeting IT, telecom
Sea Turtle surfaces in Holland targeting IT, telecom

Welcome to Gone Phishing, your daily cybersecurity newsletter that skewers cybercriminals like a Saturday afternoon BBQ πππ
Todayβs hottest cybersecurity news stories:
π Sea Turtle surfaces in Holland targeting IT, telecom π’
π¨βπ» Scammers infect hospital, threaten cancer patients π€
ποΈ West Virginia municipality falls victim to cyber carnage β‘
If you π a π’, π ( or π? π€) πππ
π Cybersecurity Alert: Sea Turtle Unleashes Espionage Campaign!
In a chilling development, Dutch security firm Hunt & Hackett reveals a fresh cyber espionage onslaught orchestrated by Sea Turtle, a TΓΌrkiye-based threat actor. π’ Targets include telecommunication, media, ISPs, IT-service providers, and Kurdish websites in the Netherlands, amplifying concerns over potential information theft. π±
Cosmic
Sea Turtle, also known as Cosmic Wolf, Marbled Dust, Teal Kurma, and UNC1326, gained notoriety in 2019 for state-sponsored attacks across the Middle East and North Africa. Their modus operandi involves exploiting vulnerabilities, especially through DNS hijacking and supply chain attacks.
Spies the limit π΅οΈββοΈ
Latest insights from Hunt & Hackett highlight Sea Turtle's persistent focus on espionage, utilising the SnappyTCP reverse TCP shell in attacks observed since 2021. π΅οΈββοΈ In a 2023 incident, a compromised cPanel account was exploited for initial access, demonstrating the group's evolving tactics.
Batten Down The Hatches β΅
To fortify against such threats, organisations are strongly urged to enforce robust password policies, implement 2FA, monitor SSH traffic, and maintain up-to-date systems. π‘οΈ Stay vigilant and secure your digital frontiers against the elusive Sea Turtle! ππ

Learn AI in 5 minutes a day. We'll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

Letβs hope the threatβs benign π
π¨ Disturbing Cyber Extortion Trends: Swatting Threats Target Hospital Patients! π₯
Extortionists are taking cyber threats to shocking new levels by targeting hospital patients, threatening to initiate bomb scares and other bogus reports that lead heavily armed police to victims' homes unless the medical centres pay hefty ransoms. π±
SWAT everβs next? π
In a recent incident at Seattle's Fred Hutchinson Cancer Center, after a cyber breach in November compromised patient records, criminals escalated their tactics by issuing direct swatting threats. The idea is to pressure hospitals into meeting ransom demands, utilising patients and media coverage as leverage. π―
Sleepless in Seattle π³
The unsettling trend extends beyond Seattle, with Integris Health in Oklahoma facing a similar "cyber event." Patients there received threatening emails, adding another layer of distress to an already dire situation. π
Time to ban the ran payment? π
As cybercriminals become more brazen, security experts warn of potential real-world violence connected to cyber-extortion, emphasising the urgent need for a ban on ransom payments. Organisations are urged to stay vigilant, enhance cybersecurity measures, and prepare for evolving threats. ππ©ββοΈπ

π£ Catch of the Day!! πππ¦
π The Motley Fool: βFool me once, shame on β shame on you. Fool me β you can't get fooled again.β Good olβ George Dubya π Let us tell whoβs not fooling around though; thatβs the CrΓΌe π at Motley Fool. Youβd be a fool (alright, enough already! π) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! π Kidding aside, if you check out their website theyβve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets π€ (LINK)
π΅ Wander: Find your happy place. Cue Happy Gilmore flashback ποΈβ³πποΈ Mmmm Happy Placeβ¦ π So, weβve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itβs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ποΈπ (LINK)
π Digital Ocean: If you build it they will come. Nope, weβre not talking about a baseball field for ghosts βΎπ»πΏ (Great movie, to be fair π). This is the Digital Ocean whoβve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youβll find yourself catching the buzz even if you canβt code (guilty π). But if you can and youβre looking for somewhere to test things out or launch something new or simply enhance what youβve got, weβd recommend checking out their services foβ sho π And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! πΏ (LINK)

Hackers: Almost heaven, West Virginia πΆππ
π¨ Beckley, WV Faces Cyber Crisis: City Hit by Cyberattack! π»π
Beckley, West Virginia, is under siege from a recent cyberattack, as announced in a Thursday notice on social media. City officials apologised for network issues and are actively investigating the incident's source, scope, and potential data impact. The city, located 50 minutes from the Virginia border, is at the heart of the Beckley metropolitan area, home to 115,000 people.
They Denver saw it coming πΈ
Beckley Mayor Rob Rappold confirmed the cyberattack but couldn't provide a restoration timeline. This incident adds to a wave of 2023 cyberattacks on small U.S. governments, with at least 95 entities targeted, as reported by cybersecurity company Emsisoft.
Is it a Hubers who of cyber-attacks π¬
In a parallel struggle, Huber Heights, Ohio, is still grappling with fallout from a November ransomware attack, remaining in a state of emergency. The city council allocated $350,000 for response efforts, covering cybersecurity, negotiation, and system updates.
City Manager Rick Dzik emphasised the uncertainty of data compromise, ranging from everyday work documents to personal information. The situation reflects a broader trend of rising cyber threats against municipalities. πποΈπ‘οΈ

ποΈ Extra, Extra! Read all about it!
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
The GeekAI: A daily 3 min newsletter on what matters in AI, with all the new AI things coming to market its good to stay ahead of the curve.
Libby Copa: The Rebel Newsletter helps writers strengthen their writing and creative practice, navigate the publishing world, and turn their art into an act of rebellion.
Techspresso: Receive a daily summary of the most important AI and Tech news, selected from 50+ media outlets (The Verge, Wired, Tech Crunch etc)
Let us know what you think!
So long and thanks for reading all the phish!
Give us a rating? |

