Press release
After global password leak: Aphos warns of increase in identity fraud and phishing via partner accounts

Hackers use login data from password leaks for credential stuffing and identity theft attacks. ( (C) Aphos GmbH / Firewalls24)
Important: Aphos Gesellschaft f?r IT-Sicherheit is not itself affected. The security incidents observed concern organizations that are supported by Aphos and their business partners.
Identity misuse on two levels
According to the _Have I Been Pwned_ platform, the Synthient dataset made public at the beginning of November 2025 contains around 1.96 billion email addresses and over 1.3 billion passwords - many of which are still active. Attackers use this data not only for automated login attempts, but also for targeted attacks via compromised email accounts from legitimate organizations.
A typical pattern: a previously compromised email account of a business partner is used to distribute deceptively genuine phishing emails. These can contain fake payment requests, login links or manipulated documents. As the sender address actually belongs to the partner company, such messages are often not blocked by traditional security mechanisms and are barely recognizable as an attack for recipients.
Aphos Incident Response: Protection through experience and speed
The incident response team at Aphos GmbH is currently regularly involved in operations in which precisely such scenarios become reality. In several of the cases we have handled, attackers have been able to either gain direct access to networks or exploit internal relationships of trust via compromised email accounts from the affected customer organizations.
"We are increasingly seeing hybrid attack scenarios in which stolen access data and legitimate communication channels work together," explains Jan Spreier, incident response expert at Aphos. "The time from initial access to propagation in the network is getting shorter and shorter - what counts is an immediate response."
Aphos' Incident Response Service provides organizations with rapid support for containment, analysis and recovery following security incidents. Through close coordination with IT teams, structured forensics and pragmatic recommendations for action, damage can be limited and attack surfaces permanently reduced.
Technical protection measures with Sophos
In addition to organizational resilience, powerful technical protection mechanisms are crucial. As a fully technically accredited Platinum Partner and operator of the Sophos store Firewalls24.de, Aphos Gesellschaft f?r IT-Sicherheit relies specifically on the Sophos security platform.
* Sophos Email Security & Sophos DMARC Manager: With the cloud-based protection for incoming and outgoing emails, phishing attacks and spoofing attempts can be reliably detected and blocked. Sophos DMARC Manager also helps to protect your own domain from misuse by attackers - an important building block against attacks via compromised partner accounts.
* Sophos XDR (Extended Detection & Response): For organizations with their own IT security department, Sophos XDR provides extended detection and response capabilities across endpoints, servers, email, identities and more. The solution aggregates data from the entire environment in a central data lake and enables in-depth analysis of potential security incidents.
* Sophos MDR (Managed Detection & Response): Those who cannot or do not want to operate their own 24/7 security department benefit from the MDR service. A dedicated team of experts takes over continuous monitoring, threat analysis and incident response - around the clock, with short response times.
* ITDR extension (Identity Threat Detection & Response): The ITDR module is also available for both solutions - XDR as well as MDR. It enables the targeted monitoring of authentication processes, privileged accounts and suspicious login activities in order to detect identity misuse in an even more targeted manner.
With these solutions, a multi-layered defense strategy can be established that comprehensively addresses both technical attacks and the misuse of legitimate access data.
Recommendations for action from the Aphos Society
In view of the current threat situation, Aphos recommends the following steps:
* Immediately check affected mail addresses via HaveIBeenPwned.com and replace compromised passwords.
* Set up strong multi-factor authentication (MFA) for internal and external access.
* Monitoring for unusual login attempts, especially from cloud or VPN systems.
* Awareness training for employees to better recognize and report phishing attempts.
* Communication with partner companies if there are indications of compromised accounts.
Aphos Gesellschaft f?r IT-Sicherheit mbH
Mergenthalerallee 73-75
Eschborn 65760
Germany
https://firewalls24.de/
Herr Lennart Wyrwa
061965820160
marketing@aphos.de
Aphos Gesellschaft f?r IT-Sicherheit mbH is a specialized IT security provider with a focus on tailor-made cybersecurity solutions for companies, authorities and public institutions. As a technically fully accredited Sophos Platinum Partner, the company offers first-class consulting, comprehensive support and a broad portfolio of IT security solutions.
With Firewalls24.de, the store for IT security solutions from Sophos, Aphos GmbH enables fast and uncomplicated procurement of Sophos firewalls, switches, access points and Sophos Central licenses.
The combination of technical expertise, personal advice and great prices makes Aphos the ideal partner for companies of all sizes that rely on the highest security standards.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release After global password leak: Aphos warns of increase in identity fraud and phishing via partner accounts here
News-ID: 4267073 • Views: …
More Releases from Aphos GmbH
Firewalls24.de adds Sophos ITDR to its portfolio: Add-on for MDR and XDR with fo …
The IT security specialist Firewalls24 is expanding its range with Sophos ITDR, a new add-on to the proven Sophos MDR and Sophos XDR solutions. The module supplements the existing detection & response functions with targeted measures to detect and defend against identity attacks - one of the biggest gateways to modern cyber threats.
Identity Threat Detection & Response in focus
With Sophos ITDR, Sophos is introducing an extension that addresses identities as…
Sophos restructures security portfolio: More clarity for Endpoint, EDR, XDR and …
Sophos has revised its security portfolio and is providing significantly more transparency in the areas of endpoint protection and detection & response with a new product structure.
Uniform designations instead of product diversity
The aim of the reorganization is to standardize the previously fragmented designations for endpoint, server and detection & response solutions. The new core products are now:
* Sophos Endpoint
* Sophos EDR
* Sophos XDR
* Sophos MDR
The Intercept X nomenclature used to…
Phishing remains a top risk: New deception methods in email inboxes
Current threat analyses show that phishing continues to evolve - with targeted attacks, manipulative techniques and new formats.
Phishing: the perennial cyber threat
According to the latest _Sophos Threat Report 2025_, phishing continues to be one of the most effective methods of attack against companies, authorities and other organizations. Cyber criminals are increasingly using new tactics, such as manipulated SVG graphic files or deceptively real social engineering messages. The goal remains the…
Sophos releases Firewall OS v22 in Early Access - Focus on Secure by Design
Sophos has released version 22 of its firewall operating system Sophos Firewall OS as an early access release for XGS hardware firewalls as well as virtual and software firewalls with SFOS. The new release is all about Secure by Design - an architectural approach that drastically reduces attack surfaces at the operating system level.
New Xstream architecture & hardened kernel
At the heart of the new version is the completely revised Xstream…
More Releases for Sophos
Sophos Expands Cloud-Managed Security Portfolio with Server Protection
Dubai, UAE – November 20, 2014 – Sophos today announced the release of Sophos Cloud Server Protection, a high performance malware protection solution designed specifically for servers. The solution expands Sophos Cloud to a comprehensive security platform designed to protect desktops, laptops, mobile phones, tablets and now servers with the most effective and simplest to manage business security offering available.
Servers store large amounts of sensitive information…
Sophos Announces Expanded Security Offerings through AWS Marketplace
Dubai, UAE– November 12, 2014 – Sophos today announced the expansion of their product portfolio on AWS Marketplace with the addition of a new secure server option for customers on Amazon Web Services (AWS). Building on the success of the Sophos UTM Next Generation Firewall product, which is offered through AWS Marketplace, the new Sophos Secure OS delivers comprehensive security bundled with CentOS.
Secure AWS Servers
AWS provides a comprehensive, scalable cloud…
Sophos DeliversAdvanced Threat Protectionfor the Small and Mid-Market
Dubai, UAE– March 12, 2014 – Sophos today announced an extensive update to its award winning Unified Threat Management solution, Sophos UTM. With more than 100 new features, the highlight of the new UTM platform is bringing Advanced Threat Protection (ATP) to the small and mid market, capabilities that were previously only available to large enterprises.
Developed by SophosLabs, thisnew SophosUTM approach brings together multiple technologiesto rapidly identifyand isolate infected clients…
Sophos Acquires Cyberoam Technologies
Dubai, UAE – February 10, 2014 – Sophos announced today that it has acquired Cyberoam Technologies, a leading global provider of network security products. The acquisition expands and deepens Sophos’ already significant product portfolio in network security, by combining Cyberoam’s Unified Threat Management (UTM), next-generation firewall and network security expertise with Sophos’ existing award-winning network security solutions in UTM and wireless security.
“Sophos and Cyberoam create a winning combination at the…
Computerlinks and Sophos Host Inaugural Channel Event in Dubai
Dubai, UAE – March 4, 2013 – Sophos today announced that it will host an inaugural channel event with new value added distributor (VAD)Computerlinks on March 5th, 2013 at The Address Dubai Mall Hotel, Dubai. Senior executives from Sophos and Computerlinks will give channel partners an overview of the latest trends in security, and show how the two companies are working together to bring a new approach to keeping businesses…
Sophos Strengthens Senior Leadership Team
Dubai, UAE – February 27, 2013 – Sophos today announced the appointments of two new leaders to the company’s executive team. Michael Valentine has joined Sophos as senior vice president of worldwide sales and Ari Buchler has joined the company as general counsel and vice president of corporate development. Both will be based in the company’s North America headquarters in Boston, and will report to Sophos CEO Kris Hagerman.…