Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Data Privacy Weekly: Your Industry News Series

success-story

Quick answer: This edition of Data Privacy Weekly, covering the week of July 27, 2023, is led by the exposure of Russian cybercriminal "Megatraffer," who has trafficked fake and stolen code signing certificates since 2015 to help malware evade detection. Enterprises should verify the provenance and integrity of every code signing certificate used to sign third party software before deployment.

This week’s stories

  • The U.S. Securities and Exchange Commission (SEC) now requires public companies to disclose material cyberattacks within four days.
  • Russian cybercriminal "Megatraffer" has trafficked fake and stolen code signing certificates since 2015, helping malware evade detection.
  • A misconfigured Transport Layer Security (TLS) certificate caused a Microsoft SharePoint and Outlook outage.
  • Estee Lauder confirmed a data breach claimed by two separate ransomware groups.
  • Over 400,000 corporate credentials, including access to Salesforce, HubSpot, QuickBooks, and AWS, were found in stolen malware logs.

Published: July 2023. Updated: August 2026 (formatting and analysis refreshed; news content is an accurate historical record and has not been altered). Reviewed by Encryption Consulting’s Threat Intelligence team.

About this series: Data Privacy Weekly is Encryption Consulting’s recurring roundup of the data privacy and cybersecurity stories our team is tracking, published on a rolling basis with each edition covering a specific week. Read the previous edition (week of July 12, 2023) or the next edition (week of August 10, 2023).

01. SEC Mandates 4-Day Disclosure of Cyber Attacks by US Firms

New SEC rules mandate U.S. companies to disclose cyber attacks with a “material” impact within four days. SEC chair Gary Gensler emphasizes the need for consistent and comparable cybersecurity disclosure. The policy requires companies to reveal incident details, material risks, and remediation efforts.

However, disclosing specific technical information impeding response or remediation is not required. The move aims to enhance transparency, cyber defense, and data protection. Concerns are raised about the tight timeframe, as it may lead to inaccurate disclosures or security risks. Other countries have varying timeframes for reporting cyber incidents.

Enterprise implication: A four day disclosure clock means incident response, legal, and investor relations teams need a pre-agreed process for assessing materiality before an attack happens, not during one.

Recommended action: Map cyber incident reporting obligations across the SEC and any state or sector specific regulators now, and rehearse the materiality assessment process with legal and IR teams before an incident starts the four day countdown.

SEC Mandates 4-Day Disclosure of Cyber Attacks by US Firms
Russian Cybercriminal 'Megatraffer' Trafficking Fake Code-Signing Certificates

02. Russian Cybercriminal ‘Megatraffer’ Trafficking Fake Code-Signing Certificates

The investigation by Brian Krebs exposes the operations of Russian cybercriminal “Megatraffer,” who specializes in trafficking fake code-signing certificates. These certificates are crucial for ensuring the authenticity and security of software. Megatraffer’s scheme involves offering stolen or falsified certificates, making it easier for malware to spread undetected.

The cybercriminal has been active since 2015 and has expanded his business to various cybercriminal forums. He has also provided services to ransomware groups, including helping Conti with their malware. Intel 471, an American threat intelligence company, has identified Megatraffer as Konstantin Evgenievich Fetisov, an experienced cybercriminal involved in spam networks in the past.

Enterprise implication: Fake and stolen code signing certificates let malware present itself as trusted, signed software, bypassing the code signing based allowlisting and endpoint controls that many enterprises rely on for their own and their vendors’ software.

Recommended action: Verify code signing certificate provenance for third-party software before deployment, and centralize code signing key custody and issuance with a controlled platform such as Encryption Consulting’s CodeSign Secure rather than relying on standalone certificates whose issuance and storage cannot be independently verified.

03. TLS Error Causes Microsoft SharePoint Outage

Microsoft SharePoint experienced an embarrassing outage due to a Transport Layer Security (TLS) error. Around 8:00 pm BST, users reported difficulties accessing Outlook, Teams, and other Microsoft services, with 71% of complaints relating to Outlook. SharePoint accounted for about 18% of MS365 outage complaints. The problem arose from a wrongly added German TLS certificate to the main sharepoint.com domain. Fortunately, Microsoft fixed the issue in about 10 minutes. However, reports of disruptions continued until 10:00 pm BST and resurfaced at 8:00 am BST the next day. Such incidents emphasize the vulnerability of online services and the importance of suitable backups.

Enterprise implication: A single misapplied TLS certificate on a shared domain can take down mail, chat, and collaboration tools for an entire organization, showing how certificate lifecycle mistakes translate directly into business downtime.

Recommended action: Automate certificate lifecycle management and require pre-deployment validation of certificate scope and domain binding before any TLS certificate change reaches production.

TLS Error Causes Microsoft SharePoint Outage
Estée Lauder Faces Data Breach by Ransomware Groups

04. Estée Lauder Faces Data Breach by Ransomware Groups

Cosmetics giant Estée Lauder faces a data breach as two ransomware groups claim responsibility for stealing vast amounts of information. Estée Lauder confirmed the cybersecurity incident, stating that an unauthorized third party accessed some of its systems and obtained data. The extent of the compromised data is under assessment, and the company has engaged external cybersecurity experts and informed law enforcement. The Cl0p and BlackCat/Alphv ransomware gangs assert involvement, with the latter still claiming access despite intervention from Microsoft and Mandiant. This incident marks the second data breach for Estée Lauder, following a previous exposure of 440 million records in 2020.

Enterprise implication: A repeat breach at the same company shows that a single major incident does not guarantee lasting fixes; data protection controls need continuous validation, not a one-time response after the last incident.

Recommended action: Encrypt sensitive data at rest and in transit, enforce least-privilege access to limit what a single compromised account can reach, and confirm incident response retainer coverage before a breach occurs.

05. Over 400,000 Corporate Credentials Stolen by Malware

Over 400,000 corporate credentials were stolen by info-stealing malware. Cybersecurity analysis of 20 million malware logs from the dark web and Telegram channels exposed significant infiltration into business environments. Info-stealers target careless internet users but also impact corporate environments when employees use personal devices for work.

The analysis found 375,000 logs containing access to business applications like Salesforce, Hubspot, Quickbooks, AWS, and more. Cybercriminals value corporate credentials for potential profits in deploying backdoors, ransomware, and other attacks. Businesses are advised to enforce password managers and multi-factor authentication (MFA) and educate employees on avoiding common infection channels.

Enterprise implication: Info-stealing malware on unmanaged or personal devices creates a path into SaaS applications holding financial, sales, and infrastructure data, outside the reach of traditional network security controls.

Recommended action: Enforce multi-factor authentication (MFA) and a corporate password manager on every business application, and restrict access to sensitive SaaS platforms from unmanaged devices.

Over 400,000 Corporate Credentials Stolen by Malware

This Edition at a Glance

StoryCategoryReal-World Impact
SEC 4-Day Disclosure RuleRegulatory / CompliancePublic companies must now disclose material cyberattacks within four days, reshaping incident response timelines.
Megatraffer Fake Code-Signing CertificatesSupply Chain / Code SigningMalware signed with fraudulent certificates bypasses trust based security controls undetected.
Microsoft SharePoint TLS OutageCertificate ManagementA single misconfigured TLS certificate disrupted Outlook, Teams, and SharePoint access for hours.
Estée Lauder Ransomware BreachData Breach / RansomwareTwo ransomware groups claimed access to systems, the company’s second major breach since 2020.
400,000+ Stolen Corporate CredentialsCredential Theft / IdentityInfo-stealing malware exposed access to Salesforce, HubSpot, QuickBooks, and AWS accounts.

Limitations

  • This edition reflects publicly reported information available as of July 2023; some details, such as the full scope of the Estée Lauder breach, may have been clarified or updated by the companies involved since the original publication date.
  • Source articles are third party reporting and are linked below for reference; Encryption Consulting has not independently re-verified every technical claim in the original sources.
  • Formatting, structure, and the enterprise implication and recommended action analysis were refreshed in August 2026; the underlying news events, dates, and figures reflect July 2023 and have not been altered.
  • This edition covers five selected stories chosen for relevance to enterprise data protection and is not an exhaustive record of all data privacy or cybersecurity news from the period.

Frequently Asked Questions

What is the biggest story in this edition of Data Privacy Weekly?

The most significant story from the week of July 27, 2023 is the exposure of "Megatraffer," a Russian cybercriminal identified as Konstantin Evgenievich Fetisov, who has trafficked fake and stolen code signing certificates since 2015. These certificates let malware appear trusted, helping it bypass security controls, and Megatraffer has reportedly worked with ransomware groups including Conti.

What does the SEC’s new 4-day disclosure rule require?

Under rules championed by SEC chair Gary Gensler, U.S. public companies must disclose cyberattacks with a material impact within four days, including incident details, material risk, and remediation efforts. Companies are not required to disclose technical details that would impede an ongoing response.

What caused the Microsoft SharePoint outage covered in this edition?

The outage stemmed from a wrongly configured German TLS certificate applied to the main sharepoint.com domain. Microsoft resolved the immediate issue in about 10 minutes, but users reported intermittent disruptions to Outlook, Teams, and SharePoint for several hours afterward.

How many corporate credentials were exposed in the info-stealer malware story?

Analysis of roughly 20 million malware logs found more than 400,000 stolen corporate credentials, including 375,000 with access to business applications such as Salesforce, HubSpot, QuickBooks, and AWS, underscoring the risk personal device malware poses to enterprise accounts.

More from Data Privacy Weekly

This edition is part of Encryption Consulting’s ongoing Data Privacy Weekly series. Continue reading with the previous edition (week of July 12, 2023) or the next edition (week of August 10, 2023).

References