티스토리 뷰
My Company's Server Got Hacked, and Then Another Hacker Stole It From the First One?
실더 2026. 5. 15. 02:00
Wait, a Hacker Kicked Out Another Hacker?
Imagine someone secretly breaking into your company server and stealing money, and then one day another thief shows up, kicks out the first one, and takes over the operation. Sounds like a movie plot, right? Well, this actually happened in May 2026.
Security company SentinelOne discovered a malicious program called PCPJack. And you know what its first move is? It completely wipes out all traces of an existing hacking group called TeamPCP. It sneaks into servers that are already compromised and basically says "this is my territory now!" Turns out hackers fight over territory too, and they're dead serious about it.
So What Exactly Is PCPJack Stealing?
What's scary about PCPJack isn't that it targets just one server. It's a worm that spreads itself from an infected server to other servers on its own. A worm is malicious code that spreads from computer to computer without any human interaction—no clicking required.
And as it spreads, it does one thing: scoops up all kinds of account info and passwords. Here's what kind of stuff it's after:
| Type of Information Stolen | Specific Examples |
|---|---|
| Cloud Services | AWS, Google Cloud account keys |
| Developer Tools | Docker, Kubernetes login credentials |
| Business Messaging Apps | Slack tokens (can read messages) |
| Databases | MongoDB, Redis login info |
| Finance/Payments | Payment API keys, financial service credentials |
But that's not even the worst part. Instead of just using the stolen info for itself, it sells the credentials or uses them directly for spam, financial fraud, and blackmail. And the fact that it's even collecting Slack credentials? That's a clear sign they want to blackmail companies with employee conversations. That's some next-level threat right there.
How Does This Affect Me? More Than You'd Think
You might be thinking, "Well, I don't even use servers, so it's not my problem." But here's the thing—all those services you use every day? Online shopping, food delivery apps, your company's management systems? They're all running on servers somewhere. When those servers get hacked like this, your personal information becomes vulnerable too.
Office workers especially need to pay attention. You probably use Slack, Notion, Google Workspace, stuff like that at work, right? If hackers steal the login credentials for these tools, your conversations, contracts, and customer information all leak out. And honestly, that's not just your personal problem—it becomes a crisis for the entire company.
What You Can Do Right Now
Don't panic though. There are simple things you can do to seriously reduce the damage. If you're at a small company without a dedicated IT team, just focus on these three things.
Frequently Asked Questions
A. Absolutely—and honestly, you might be at even higher risk. PCPJack and similar worms aren't targeting specific companies. They automatically hunt for vulnerable servers exposed on the internet. Smaller companies often don't have security staff, so their configurations tend to be loose, which actually makes them easier targets.
A. Regularly check the "Login Activity" or "Active Sessions" menu in each service. If you see login attempts from unknown devices or weird countries, change your password immediately and log out all active sessions. And definitely make sure security alert emails are turned on.
That whole PCPJack story we just talked about—honestly, when you see it in the news it seems like "some IT stuff that has nothing to do with me," right? But once you understand it, you realize this threat is actually closer to your daily life than you'd think. The point is, you don't need some elaborate security setup. A few small habits can seriously prevent major damage. Keep that in mind! 😊
'Security News(Eng)' 카테고리의 다른 글
- Total
- Today
- Yesterday
- 랜섬웨어
- HackingAlert
- 정보보안
- 샤이니헌터스
- DataPrivacy
- 전자금융기반시설
- securitynews
- PrivacyProtection
- 전자금융기반시설취약점분석평가
- infosecurity
- 해킹주의
- 취약점
- SecurityTips
- Malware
- 스마트폰보안
- 2단계인증
- 사이버보안
- 보안상식
- 공급망공격
- 금취분평
- cve
- 해킹예방
- 보안꿀팁
- HackingPrevention
- 악성코드
- 개인정보유출
- 개인정보보호
- 보안뉴스
- supplychainattack
- cybersecurity
| 일 | 월 | 화 | 수 | 목 | 금 | 토 |
|---|---|---|---|---|---|---|
| 1 | 2 | 3 | 4 | 5 | 6 | |
| 7 | 8 | 9 | 10 | 11 | 12 | 13 |
| 14 | 15 | 16 | 17 | 18 | 19 | 20 |
| 21 | 22 | 23 | 24 | 25 | 26 | 27 |
| 28 | 29 | 30 |