Breach news

Reported breaches, what was taken, and how the intrusion started.

994 reports

Aflac Incorporated

Aflac discloses network intrusion tied to insurance sector campaign

Hacking Insurance

Disneyland Paris

Anubis group claimed 64 GB of Disneyland Paris files from a contractor

Third-Party Data Breach Entertainment

Oxford City Council

Oxford City Council breach exposed 21 years of election worker records

Hacking Government

Krispy Kreme

Krispy Kreme breach exposed data on 161,676 people after 2024 attack

Ransomware Food & Beverage

Chain IQ

Chain IQ breach spilled contact data on more than 100,000 UBS employees

Hacking Business Services

Ocuco

Ocuco breach exposes health data of about 241,000 people

Ransomware Healthcare Technology

WestJet

WestJet investigates cyberattack affecting internal systems and app

Hacking Airline

Zoomcar Holdings, Inc.

Zoomcar discloses breach affecting 8.4 million users

Hacking Transportation

Yes24

Ransomware attack takes South Korean ticketing platform Yes24 offline

Ransomware E-commerce & Ticketing

Erie Insurance

Erie Insurance confirms cyberattack behind multi-week outage

Hacking Insurance

United Natural Foods, Inc.

Cyberattack on United Natural Foods disrupts grocery distribution

Hacking Food Distribution

Episource

Episource breach exposed health records of more than 5.4 million people

Hacking Healthcare

Jackson Health System

Jackson Health System fires employee over five-year patient data snooping

Malicious Insider Healthcare

Optima Tax Relief

Chaos ransomware group leaked 69 GB stolen from Optima Tax Relief

Ransomware Financial Services

KiranaPro

KiranaPro blames former employee after AWS and GitHub data wipe

Malicious Insider Retail

Illinois Department of Healthcare and Family Services

Illinois healthcare agency reports phishing breach affecting 933 people

Phishing Government

HM Revenue and Customs (HMRC)

HMRC says phishing fraud hit 100,000 tax accounts and cost 47 million pounds

Phishing Government

The North Face (VF Outdoor)

The North Face discloses April credential stuffing attack on customer accounts

Credential Compromise Retail

City of Durant, Oklahoma

Ransomware attack disrupts services for the city of Durant, Oklahoma

Ransomware Government

Cartier

Cartier tells clients names and email addresses were stolen in system breach

Hacking Retail

MainStreet Bank (MainStreet Bancshares, Inc.)

MainStreet Bank customer card data exposed in third-party vendor breach

Third-Party Data Breach Financial Services

Missouri Department of Conservation

Missouri Department of Conservation breach exposed employee health plan data

Hacking Government

DataPost

DataPost ransomware attack exposed data of 146 Income Insurance policyholders

Ransomware Business Services

Victoria's Secret & Co.

Victoria's Secret takes down U.S. website after security incident

Hacking Retail

Covenant Health

Covenant Health cyberattack disrupts hospitals in Maine and New Hampshire

Ransomware Healthcare

LexisNexis Risk Solutions

LexisNexis Risk Solutions breach on GitHub exposed data of 364,000 people

Credential Compromise Business Services

MathWorks

MathWorks confirms ransomware attack behind MATLAB service outages

Ransomware Technology

Tiffany & Co.

Tiffany & Co. discloses South Korean customer data breach at third-party platform

Third-Party Data Breach Retail

Adidas

Adidas discloses customer data breach at third-party service provider

Third-Party Data Breach Retail

West Lothian Council

West Lothian Council confirms school data stolen in Interlock ransomware attack

Ransomware Government

Cellcom

Cellcom confirms cyberattack behind week-long voice and text outage in Wisconsin

Hacking Telecommunications

Kettering Health

Interlock ransomware attack shuts down systems across Ohio's Kettering Health

Ransomware Healthcare

Peter Green Chilled

Ransomware attack on Peter Green Chilled disrupts UK supermarket food supplies

Ransomware Transportation & Logistics

Effortel

Effortel breach exposes data of 70,000 Belgian mobile customers

Hacking Telecommunications

Serviceaide

Serviceaide database exposure hit 483,000 Catholic Health patients

Misconfiguration Information Technology

MKA Accountants

Qilin ransomware gang lists Melbourne firm MKA Accountants as a victim

Ransomware Professional Services

Christian Dior Couture

Christian Dior Couture confirms customer data breach affecting Asian shoppers

Phishing Retail

Coinbase Global, Inc.

Coinbase says bribed overseas support agents leaked customer data

Malicious Insider Financial Services

Nova Scotia Power

Nova Scotia Power confirms theft of customer data in ransomware attack

Ransomware Utilities

Nucor Corporation

Nucor halts steel production at multiple sites after cyberattack

Hacking Manufacturing

Legal Aid Agency

U.K. Legal Aid Agency warns providers of security incident on its online systems

Hacking Government

City of Edinburgh Council

Edinburgh council resets school network passwords after phishing attack

Phishing Education

South African Airways

South African Airways says cyberattack disrupted website, app and internal systems

Hacking Aviation

Masimo Corporation

Masimo cyberattack slowed manufacturing at the medical device maker

Hacking Medical Devices

Oettinger Getränke

German brewer Oettinger confirms cyberattack claimed by RansomHouse

Ransomware Food and Beverage

Global Crossing Airlines (GlobalX)

Hacktivists breached deportation charter airline GlobalX and took flight manifests

Hacking Aviation

Harrods

Harrods restricted internet access after attempted intrusion on its systems

Hacking Retail

Texas Health and Human Services Commission

Texas HHSC says employees improperly accessed data of about 94,000 people

Malicious Insider Government

Co-op Group

Co-op Group confirmed member data theft after DragonForce intrusion

Ransomware Retail

Kintetsu World Express

Kintetsu World Express confirmed ransomware attack disrupted its systems

Ransomware Shipping & Logistics

Yale New Haven Health System

Yale New Haven Health breach exposed data on nearly 5.6 million patients

Hacking Healthcare

Barnstable County Sheriff's Office

Insider breach at Barnstable County Sheriff's Office exposed employee records

Malicious Insider Government

Marks & Spencer

Marks and Spencer halted online orders after DragonForce ransomware attack

Ransomware Retail

The Hertz Corporation

Hertz confirmed customer data theft through the Cleo file transfer exploit

Third-Party Data Breach Travel & Leisure

Sensata Technologies

Sensata Technologies ransomware attack halts shipping and production

Ransomware Manufacturing

Western Sydney University

Western Sydney University breach exposed records of 10,000 students

Hacking Education

SK Group

Qilin ransomware gang claims 1TB theft from SK Group's U.S. arm

Ransomware Conglomerate

Blue Shield of California

Blue Shield of California sent member health data to Google Ads by misconfiguration

Misconfiguration Healthcare

Oregon Department of Environmental Quality

Oregon environmental agency shuts down network after cyberattack

Ransomware Government

WooCommerce (Automattic)

Hacker claims WooCommerce data breach, Automattic denies its systems were hit

Third-Party Data Breach E-commerce Software

Office of the Comptroller of the Currency

U.S. bank regulator OCC discloses year-long email system breach

Hacking Government

NASCAR

Medusa ransomware group claimed a NASCAR breach and demanded $4 million

Ransomware Sports & Entertainment

Caisse Nationale de Sécurité Sociale (CNSS), Morocco

Morocco's social security fund CNSS had data on nearly 2 million people leaked

Hacking Government

DBS Bank

DBS and Bank of China Singapore customer data exposed by vendor ransomware

Third-Party Data Breach Financial Services

Fall River Public Schools

Fall River Public Schools in Massachusetts hit by ransomware attack

Ransomware Education

AustralianSuper

AustralianSuper and rival funds hit by coordinated credential stuffing

Credential Compromise Pensions and Retirement Savings

WK Kellogg Co.

WK Kellogg confirms employee data breach tied to Cleo file transfer flaws

Supply Chain Attack Food and Beverage Manufacturing

Central Texas Pediatric Orthopedics

Central Texas Pediatric Orthopedics breach affected 140,000 patients

Hacking Healthcare

State Bar of Texas

State Bar of Texas confirmed data theft after an attack claimed by INC Ransom

Ransomware Legal Services

Twilio

Twilio denies SendGrid breach after hacker offers 848,000 records for sale

Hacking Technology

Royal Mail Group

Royal Mail data leaked after breach at supplier Spectos

Third-Party Data Breach Postal and Logistics

City of Baltimore

City of Baltimore lost $1.5 million to a vendor impersonation scheme

Business Email Compromise Government

Lower Sioux Indian Community

Ransomware attack disrupted Lower Sioux Indian Community casino and health services

Ransomware Tribal Government

Samsung Germany

Samsung Germany support tickets leaked after four-year-old credentials were reused

Credential Compromise Technology

Laborers' International Union of North America Local 1184

LiUNA Local 1184 notified members of a 2024 ransomware data breach

Ransomware Labor Union

Parcel Plus

Parcel Plus tax clients had refunds redirected after spear phishing attack

Phishing Professional Services

German Association for East European Studies (DGO)

German East European studies association breached again, Russia suspected

Hacking Non-profit Research

Nine Entertainment

Nine exposed 16,000 Australian newspaper subscribers through a supplier lapse

Third-Party Data Breach Media

New South Wales Department of Communities and Justice

NSW justice department breach exposed 9,000 court files including violence orders

Hacking Government

Lee University

Lee University notifies about 137,000 people a year after network breach

Ransomware Education

Western Alliance Bank

Western Alliance Bank notifies 21,899 customers after Cleo file transfer breach

Third-Party Data Breach Financial Services

Oracle

Oracle denies cloud breach as researchers back hacker's six million record claim

Hacking Technology

ALN Medical Management, LLC

ALN Medical Management discloses 2024 breach of third-party hosted systems

Hacking Healthcare

Ukrzaliznytsia

Cyberattack knocks out Ukrainian railway Ukrzaliznytsia's online ticketing

Hacking Transportation

University of Notre Dame Australia

University of Notre Dame Australia struggles to recover from January cyberattack

Ransomware Education

Pennsylvania State Education Association

PSEA notified more than 517,000 people after Rhysida claimed 2024 breach

Ransomware Non-profit

James Pascoe Group

James Pascoe Group cyberattack disrupts Farmers and Whitcoulls stores

Ransomware Retail

Ganong Bros. Ltd.

Ganong Bros. chocolate plant disrupted by ransomware attack claimed by Play

Ransomware Manufacturing

Yap State Department of Health Services

Ransomware forced Micronesia's Yap health department offline

Ransomware Government

Bis Industries

Bis Industries investigates RansomHub claims over December 2024 attack

Ransomware Mining Services

Sunflower Medical Group

Sunflower Medical Group breach exposed data on nearly 221,000 patients

Ransomware Healthcare

Sorbonne Université

FunkSec claimed a breach at Sorbonne Universite; the university called it limited

Ransomware Education

Lake Washington Vascular

Lake Washington Vascular restored from backups after Qilin ransomware attack

Ransomware Healthcare

Bank of America

Bank of America warned customers after document destruction vendor mishandled records

Third-Party Data Breach Financial Services

Chicago Public Schools

Chicago Public Schools says Cleo vendor breach exposed 700,000 students

Supply Chain Attack Education

NTT Communications Corporation

NTT Communications breach exposed data on nearly 18,000 corporate customers

Hacking Telecommunications

Carruth Compliance Consulting

Carruth Compliance Consulting breach exposed data on tens of thousands of school staff

Ransomware Business Services

Berkeley Research Group

Berkeley Research Group discloses ransomware attack during LBO debt sale

Ransomware Business Services

National Presto Industries

National Presto Industries disrupted by March 2025 cyberattack

Ransomware Manufacturing

Australian New Zealand Clinical Trials Registry

Clinical trials registry ANZCTR taken offline after University of Sydney breach

Hacking Healthcare

Orange Group

Orange Group confirms breach of Romanian back office systems

Hacking Telecommunications

Cleveland Municipal Court

Cyber incident closed Cleveland Municipal Court for more than two weeks

Ransomware Government

Anne Arundel County, Maryland

Anne Arundel County closed buildings after ransomware attack on its network

Ransomware Government

DISA Global Solutions, Inc.

DISA Global Solutions breach exposed data on 3.3 million screening subjects

Hacking Business Services

HCRG Care Group

Medusa gang demanded $2m from UK healthcare provider HCRG Care Group

Ransomware Healthcare

Inspira Financial Trust, LLC

Call center contractor accessed data on 2,308 Inspira Financial savers

Third-Party Data Breach Financial Services

Rainbow District School Board

Rainbow District School Board cyberattack exposed decades of student and staff data

Ransomware Education

Hipshipper

Hipshipper left 14.3 million shipping records exposed in open cloud bucket

Misconfiguration Transportation & Logistics

Genea

Genea discloses breach after Termite ransomware attack on IVF clinics

Ransomware Healthcare

NioCorp Developments Ltd.

NioCorp Developments lost $500,000 to an email compromise scam

Business Email Compromise Mining & Natural Resources

The Agency

Rhysida claimed a ransomware attack on London talent agency The Agency

Ransomware Media & Entertainment

Office of the Attorney General of Virginia

Cyberattack knocked the Virginia Attorney General's office offline

Hacking Government

Unimicron Technology

Sarcoma ransomware group claims 377 GB stolen from PCB maker Unimicron

Ransomware Manufacturing

Nippon Steel

BianLian claims theft of 500 GB from Nippon Steel's US operations

Ransomware Manufacturing

Mars Hydro

Unsecured Mars Hydro database exposed 2.7 billion IoT records

Misconfiguration Manufacturing

Pinehurst Radiology Associates, PLLC

Pinehurst Radiology Associates closed indefinitely after cyberattack

Hacking Healthcare

Sault Ste. Marie Tribe of Chippewa Indians

Ransomware shut Kewadin Casinos and Sault Tribe services across Michigan

Ransomware Travel & Leisure

Memorial Hospital and Manor

Memorial Hospital and Manor notified 120,085 people after ransomware attack

Ransomware Healthcare

Sanrio Entertainment

Sanrio Entertainment ransomware attack put up to 2 million records at risk

Ransomware Entertainment

CPI UK

Ransomware attack halted book printer CPI UK's production for weeks

Ransomware Printing & Publishing

IMI plc

IMI plc disclosed unauthorised access to its systems in a stock exchange filing

Hacking Engineering

Grubhub

Grubhub breach traced to a third-party customer support provider

Third-Party Data Breach Online Food Delivery

Lee Enterprises

Cyberattack halted printing and publishing across Lee Enterprises newspapers

Ransomware Media

Community Health Center, Inc.

Community Health Center breach exposed data on more than 1 million patients

Hacking Healthcare

Tata Technologies

Tata Technologies reports ransomware attack in stock exchange filing

Ransomware Engineering Services

Mizuno USA

Mizuno USA said attackers spent two months copying files from its network

Ransomware Manufacturing

DeepSeek

DeepSeek left a database of chat logs and API keys exposed online

Misconfiguration Technology (Artificial Intelligence)

New York Blood Center Enterprises

Ransomware attack on New York Blood Center disrupts collections

Ransomware Healthcare

Smiths Group plc

Smiths Group discloses unauthorized access to its systems

Hacking Engineering & Manufacturing

ARDEX Australia

Medusa ransomware group claims attack on ARDEX Australia

Ransomware Construction Products

The British Museum

British Museum partly closed after dismissed contractor shut down systems

Malicious Insider Arts and Culture

Conduent

Conduent confirms cyberattack behind US government service outages

Hacking Business Services

Mortgage Investors Group

Mortgage Investors Group discloses December breach after Black Basta claim

Ransomware Financial Services

Hewlett Packard Enterprise

HPE investigates IntelBroker claim of stolen source code and repositories

Hacking Technology

Divimast

Akira ransomware lists Italian ERP consultancy Divimast on its leak site

Ransomware Information Technology

Otelier

Otelier breach exposes hotel guest reservations for Marriott, Hilton and Hyatt

Credential Compromise Hospitality Technology

Chemeketa Community College

Chemeketa Community College staff data exposed in Carruth Compliance breach

Third-Party Data Breach Education

Avery Products Corporation

Avery says card skimmer sat on its website for nearly five months

Hacking Manufacturing

Willow Pays

Willow Pays left customer bill payment database open on the internet

Misconfiguration Financial Services

Roseltorg

Roseltorg confirms cyberattack on Russia's state procurement platform

Hacking Government

Eindhoven University of Technology (TU/e)

Eindhoven University of Technology shuts down network after cyberattack

Hacking Education

Unacast

Unacast tells Norwegian regulator hackers took Gravy Analytics location data

Credential Compromise Technology

Geodesy, Cartography and Cadastre Office of the Slovak Republic (UGKK)

Ransomware shuts Slovakia's land registry office UGKK, stalling property deals

Ransomware Government

Alcool NB Liquor (NB Liquor)

NB Liquor shut down point of sale systems after suspected cyberattack

Hacking Retail

Indiana University Health

Indiana University Health email compromise exposed patient records

Credential Compromise Healthcare

International Civil Aviation Organization

ICAO confirms recruitment database breach affecting nearly 12,000 people

Hacking Government

PowerSchool

PowerSchool breach exposes K-12 student and teacher records worldwide

Credential Compromise Education Technology

Policía de Seguridad Aeroportuaria

Argentina's airport security police hit by payroll data breach

Hacking Government

RegionTransService LLC

Ukraine's HUR claims destructive attack on rail firm RegionTransService

Hacking Logistics & Transport

Fraunhofer Institute for Industrial Engineering IAO

Ransomware attack hit Germany's Fraunhofer IAO research institute in Stuttgart

Ransomware Research & Education

Bank of America

Bank of America notifies loan customers after third-party provider breach

Third-Party Data Breach Banking & Finance

Las Palmas Del Sol Healthcare (El Paso Healthcare System, Ltd.)

Las Palmas Del Sol Healthcare told 1,854 patients a former employee viewed their records

Malicious Insider Healthcare

DE Photo

DE Photo hit by back-to-back intrusions over Christmas 2024

Hacking Photography Services

U.S. Department of the Treasury

Chinese state hackers breached US Treasury workstations through BeyondTrust

Supply Chain Attack Government

Nikki-Universal Co., Ltd.

Nikki-Universal confirms ransomware attack on its servers

Ransomware Chemical Manufacturing

Youth Eastside Services

Youth Eastside Services breach exposed mental health client records in Washington

Ransomware Healthcare

Turks and Caicos Islands Government

Turks and Caicos government recovers from pre-Christmas ransomware attack

Ransomware Government

Center for Vein Restoration

Center for Vein Restoration breach exposed data on 446,094 patients and staff

Hacking Healthcare

Wood County, Ohio

Ransomware sends Wood County, Ohio emergency dispatch back to pen and paper

Ransomware Government

Artivion

Artivion tells SEC cyberattack disrupted order and shipping processes

Ransomware Medical Devices

Kurita Water Industries (Kurita America Inc.)

Ransomware hit Kurita Water Industries' US arm, exposing customer and staff data

Ransomware Water Treatment

Luka Rijeka d.d. (Port of Rijeka)

8Base ransomware group claimed a data theft at Croatia's Port of Rijeka

Ransomware Logistics & Transport

Chemonics International

Chemonics International discloses 2023 intrusion affecting 263,136 people

Hacking Government Contractor

BT Group

BT Group confirms attempted attack on conferencing unit claimed by Black Basta

Ransomware Telecommunications

ENGlobal Corporation

ENGlobal discloses ransomware attack that limited access to its IT systems

Ransomware Energy

Refinadora Costarricense de Petróleo (RECOPE)

Ransomware forced Costa Rica's state fuel company RECOPE to sell fuel manually

Ransomware Energy & Utility

Uganda - Bank of Uganda

Bank of Uganda lost millions after international payments were diverted

Hacking Finance

Italy - Bologna FC 1909

Bologna FC confirmed ransomware attack after RansomHub leaked club data

Ransomware Sports and Entertainment

U.S. Veterans Health Administration

Veterans Health Administration notifies 2,302 veterans after vendor attack

Third-Party Data Breach Government Healthcare

UK - Alder Hey Children's NHS Foundation Trust

INC Ransom published data stolen from Alder Hey Children's NHS trust

Ransomware Healthcare

Cabot Financial (Ireland)

Cabot Financial Ireland tells High Court 394,000 files were stolen

Hacking Financial Services

City of Hoboken, New Jersey

Ransomware attack shut down City of Hoboken government operations

Ransomware Government

Wirral University Teaching Hospital NHS Foundation Trust

Wirral University Teaching Hospital NHS trust declares major incident after cyberattack

Hacking Healthcare

Vogue Homes

KillSec claims data theft from Australian home builder Vogue Homes

Ransomware Construction

Texas Tech University Health Sciences Center

Texas Tech University Health Sciences Center breach hit 1.46 million patients

Ransomware Healthcare

Starbucks

Starbucks fell back on manual payroll after Blue Yonder ransomware attack

Supply Chain Attack Food and Beverage Retail

Pacific Pulmonary Medical Group

Everest gang dumped Pacific Pulmonary Medical Group patient records

Credential Compromise Healthcare

Japan - Kumamoto Prefecture Anti-Violence Movement Promotion Center

Kumamoto anti-violence counseling center warned of possible data leak

Phishing Nonprofit

Blue Yonder

Blue Yonder ransomware attack disrupts grocery and retail supply chains

Ransomware Software

Finastra

Finastra investigates breach of internal file transfer platform

Credential Compromise Financial Technology

Bojangles' Restaurants, Inc.

Bojangles notifies employees of data breach months after intrusion

Hacking Restaurants

International Game Technology

International Game Technology takes systems offline after cyberattack

Hacking Gambling Technology

T-Mobile US

T-Mobile named in Salt Typhoon espionage campaign against US telecoms

Hacking Telecommunications

Government of Mexico (gob.mx)

RansomHub claimed 313 GB stolen from Mexican government legal office

Ransomware Government

Hungarian Defence Procurement Agency (VBU)

Hungary confirmed INC Ransom hack of its defence procurement agency

Ransomware Government

DemandScience

DemandScience confirms leaked 122 million record database came from its systems

Hacking Business Services

American Associated Pharmacies

Embargo ransomware group claimed attack on American Associated Pharmacies

Ransomware Pharmacy

Alberta Innovates

Alberta Innovates confirmed unauthorized access to its network

Hacking Government Agency

TEAM Software

TEAM Software breach exposed personal data on 99,525 people

Hacking Software

BBS Financial Services, LLC

BBS Financial Services paid a ransom after breach affecting 70,168 people

Ransomware Accounting Services

Amazon

Amazon employee contact data surfaced in MOVEit leak from a vendor

Third-Party Data Breach Retail

Hot Topic

Hot Topic breach exposed records on nearly 57 million retail customers

Third-Party Data Breach Retail

Ahold Delhaize USA

Ahold Delhaize cyberattack disrupted US grocery pharmacies and online orders

Hacking Retail

Newpark Resources

Newpark Resources discloses ransomware attack in SEC filing

Ransomware Energy

Standard Bank

Standard Bank employee copied client data to an unprotected personal device

Malicious Insider Banking

Schneider Electric

Schneider Electric investigated Hellcat theft of 40GB from its Jira server

Ransomware Energy

Nokia

Nokia denied breach after IntelBroker leaked contractor source code

Third-Party Data Breach Telecommunications

Belle Tire Distributors

Belle Tire notifies nearly 30,000 people after June 2024 network intrusion

Hacking Automotive Retail

Housing Authority of the City of Los Angeles (HACLA)

Los Angeles housing authority HACLA confirms second ransomware attack

Ransomware Government

Van Wagner Group

Van Wagner Group breach exposed Social Security numbers of 5,354 people

Hacking Advertising and Marketing

South East Technological University

Cyberattack shut down IT systems at South East Technological University

Hacking Education

Microlise

Microlise cyberattack knocked out DHL and Serco vehicle tracking in the UK

Ransomware Technology

Interbank

Interbank confirms customer data breach after dark web listing

Hacking Financial Services

Australian Nursing Home Foundation

Abyss ransomware claims 1.5TB from Australian Nursing Home Foundation

Ransomware Healthcare

AEP GmbH

German pharmaceutical wholesaler AEP hit by ransomware attack

Ransomware Healthcare

Free SAS

French ISP Free confirms breach of subscriber data

Hacking Telecommunications

Landmark Admin, LLC

Landmark Admin breach exposed data of more than 800,000 insurance customers

Ransomware Insurance Services

BronxWorks Inc.

BronxWorks disclosed 2023 email breach exposing client and employee data

Hacking Non-profit

Arkansas Blue Cross and Blue Shield

Vendor breach at Healthmine exposed Arkansas Blue Cross member data

Third-Party Data Breach Health Insurance

Johnson & Johnson, Inc. (insurance firm)

Insurance firm Johnson & Johnson disclosed August 2024 breach affecting 3,200

Hacking Insurance

Berufsbildungszentrum Schaffhausen (BBZ)

Ransomware attack blocked systems at Swiss vocational school BBZ Schaffhausen

Ransomware Education

Kansas City Hospice & Palliative Care

BlackSuit ransomware listed Kansas City Hospice and Palliative Care

Ransomware Healthcare

Nidec Corporation

Nidec confirms 50,694 files leaked from Vietnamese subsidiary

Ransomware Manufacturing

Globe Life Inc.

Globe Life extorted over data stolen from American Income Life

Hacking Insurance

Cisco Systems

Cisco traces IntelBroker data leak to public DevHub portal

Misconfiguration Technology

Funlab

Funlab confirms Lynx ransomware attack on Australian entertainment group

Ransomware Entertainment

Varsity Brands

Varsity Brands breach exposed data of more than 65,000 people

Hacking Apparel Manufacturing

Casio Computer Co., Ltd.

Casio confirms data theft after Underground ransomware attack

Ransomware Consumer Electronics

Intesa Sanpaolo

Intesa Sanpaolo insider accessed 3,500 accounts including Italy's prime minister

Malicious Insider Banking

Calgary Public Library

Calgary Public Library closed all branches after cyberattack

Hacking Government

Axis Health System

Axis Health System investigates Rhysida ransomware attack in Colorado

Ransomware Healthcare

Perfection Fresh

Perfection Fresh confirms breach after Sarcoma ransomware listing

Ransomware Agriculture

Fidelity Investments

Fidelity Investments breach exposed personal data of 77,099 customers

Hacking Financial Services

Game Freak

Game Freak confirms server breach behind Pokemon TeraLeak data dump

Hacking Video Games

The Plastic Bag Company

Sarcoma ransomware group leaks data from Sydney's The Plastic Bag Company

Ransomware Manufacturing

Internet Archive

Internet Archive breach exposed 31 million user records

Hacking Nonprofit

American Water Works Company, Inc.

American Water pauses billing after cyberattack on internal systems

Hacking Utilities

ADT Inc.

ADT discloses second breach in two months after partner credentials stolen

Credential Compromise Home Security

Wayne County, Michigan

Cyberattack shut down Wayne County, Michigan websites and county offices

Ransomware Government

Ward Transport & Logistics Corp.

Ward Transport and Logistics notified victims of March 2024 network breach

Ransomware Transportation and Logistics

Red Barrels

Red Barrels breach delayed Outlast development after 1.8TB theft claim

Ransomware Video Games

Dutch National Police

Dutch national police breach exposes contact details of every officer

Hacking Government

Agence France-Presse

Agence France-Presse reported potential data breach after cyberattack

Hacking Media

Casino Fandango

Casino Fandango disclosed June 2024 breach of its computer network

Hacking Hospitality and Gaming

MoneyGram International

MoneyGram confirms cyberattack behind days-long global outage

Hacking Financial Services

City of Arkansas City, Kansas

Arkansas City, Kansas water plant switches to manual after cyberattack

Hacking Government

MC2 Data

MC2 Data left 2.2TB background check database exposed online

Human Error Data Brokerage

Dell Technologies

Hacker claimed two Dell Technologies breaches within days in September 2024

Hacking Technology

Total Tools

Total Tools data breach exposed about 38,000 customer accounts

Hacking Retail

Compass Group Australia

Compass Group Australia confirmed Medusa ransomware attack

Ransomware Food Services

Fireworks Software, Inc.

Fireworks Software breach exposed data tied to Rowan College at Burlington County

Hacking Software

Elitecare Emergency Hospital

Elitecare Emergency Hospital notifies 24,754 patients of data breach

Hacking Healthcare

Kawasaki Motors Europe

Kawasaki Motors Europe restored servers after RansomHub attack

Ransomware Automotive

David's Bridal

David's Bridal notified customers and staff of January 2024 data breach

Hacking Retail

Fortinet

Fortinet confirmed customer data taken from third-party cloud file drive

Third-Party Data Breach Technology

Industrial and Commercial Bank of China (ICBC), London branch

Hunters International claimed 6.6TB theft from ICBC's London branch

Ransomware Financial Services

Access Sports Medicine and Orthopaedics

Access Sports Medicine breach exposed data on about 88,000 patients

Ransomware Healthcare

Aramark

Aramark employees phished through fake myPay site in payroll diversion scheme

Phishing Food Services

Slim CD, Inc.

Slim CD breach exposed card data for about 1.7 million people

Hacking Payment Processing

T. Rowe Price Retirement Plan Services

T. Rowe Price named in Infosys McCamish breach affecting 6 million people

Third-Party Data Breach Financial Services

KemperSports

KemperSports breach exposed Social Security numbers of over 62,000 people

Hacking Hospitality

Avis Rent A Car System

Avis breach of a business application exposed data on 299,006 customers

Hacking Travel & Tourism

Charles Darwin School

Ransomware attack closed Charles Darwin School in Bromley for three days

Ransomware Education

Nationwide Recovery Service

Nationwide Recovery Service reports breach of debt collection records

Hacking Debt Collection

Highline Public Schools

Highline Public Schools closed for three days after a cyberattack

Ransomware Education

St. Charles Parish Government

St. Charles Parish lost over $1.2 million to a vendor email compromise

Business Email Compromise Government

Centers for Medicare & Medicaid Services

CMS said a MOVEit hack at contractor WPS exposed 946,801 Medicare beneficiaries

Third-Party Data Breach Healthcare

Planned Parenthood of Montana

RansomHub claimed a cyberattack on Planned Parenthood of Montana

Ransomware Healthcare

Tewkesbury Borough Council

Tewkesbury Borough Council shut down its systems after a suspected cyberattack

Human Error Government

Tracelo

Tracelo phone tracking service breach exposed 1.4 million customers and targets

Hacking Location Tracking Service

Mt. Carmel Behavioral Healthcare

Mt. Carmel Behavioral Healthcare disclosed email breach exposing patient data

Phishing Healthcare

JAS Worldwide

JAS Worldwide confirms ransomware attack behind freight operation disruptions

Ransomware Logistics

Toronto District School Board

Toronto District School Board says student data stolen in June ransomware attack

Ransomware Education

Dick's Sporting Goods

Dick's Sporting Goods discloses intrusion and locks employees out of email

Hacking Retail

Fota Wildlife Park

Fota Wildlife Park told customers to cancel cards after a website breach

Hacking Tourism & Attractions

USAA

USAA notified about 32,000 members after update error misdelivered documents

Misconfiguration Insurance

Young Consulting

Young Consulting breach exposed data on 954,177 people, including Blue Shield members

Ransomware Software

Meli

Qilin ransomware gang claims 215 GB theft from Australian charity Meli

Ransomware Nonprofit

Port of Seattle (Seattle-Tacoma International Airport)

Rhysida ransomware attack disrupted Seattle-Tacoma International Airport systems

Ransomware Aviation

Bloom Hearing Specialists

Bloom Hearing Specialists ransomware attack exposed patient and staff records

Ransomware Healthcare

Halliburton Company

Halliburton took systems offline after August 2024 cyberattack

Hacking Energy Services

Caja Los Andes

Unsecured database at Chile's Caja Los Andes exposed data on 10 million people

Misconfiguration Financial Services

Oregon Zoo

Oregon Zoo warned 117,000 online ticket buyers of payment card theft

Hacking Zoos and Attractions

Toyota

Toyota confirms customer data exposed after 240 GB leak blamed on third party

Third-Party Data Breach Automotive

Microchip Technology Incorporated

Microchip Technology cut manufacturing output after August 2024 cyberattack

Hacking Semiconductor Manufacturing

VeriSource Services, Inc.

VeriSource Services disclosed February 2024 breach of employee benefits data

Hacking Employee Benefits Administration

CannonDesign

CannonDesign notified 13,000 people of 2023 AvosLocker ransomware breach

Ransomware Architecture and Engineering

FlightAware

FlightAware configuration error exposed account data for over three years

Misconfiguration Aviation Technology

Specialty Networks, Inc.

Specialty Networks breach exposed data on more than 411,000 patients

Hacking Healthcare Technology

City of Flint, Michigan

Ransomware attack knocked City of Flint payment and phone systems offline

Ransomware Municipal Government

The Washington Times

Rhysida ransomware group put Washington Times data up for auction

Ransomware Media

AutoCanada Inc.

AutoCanada disclosed cyberattack on its internal IT systems

Hacking Automotive Retail

Rodl Management, Inc.

Rodl Management breach exposed tax client data from Jamestown and JT Tax Services

Hacking Professional Services

Grand Palais Reunion des musees nationaux

Ransomware attack hit Grand Palais and dozens of French museums during Paris Olympics

Ransomware Museums and Cultural Venues

ZB Financial Holdings

Mad Liberator leaked ZB Financial Holdings data after Zimbabwe group refused ransom

Ransomware Financial Services

Sable International

BianLian emailed Sable International customers after immigration firm breach

Hacking Immigration Services

Fresnillo plc

Fresnillo disclosed unauthorised access to IT systems and data

Hacking Mining

McDowall Affleck

RansomHub claimed 470GB of data from engineering firm McDowall Affleck

Ransomware Engineering

Jerico Pictures Inc. (National Public Data)

National Public Data faced suit over a claimed 2.9 billion record breach

Hacking Data Brokerage

OneBlood

Ransomware attack on OneBlood disrupted blood supply across the Southeast

Ransomware Nonprofit Blood Services

C-Edge Technologies

Ransomware at C-Edge Technologies knocked roughly 300 Indian banks offline

Ransomware Financial Services

Gemini

Gemini discloses breach at banking partner exposing customer account details

Third-Party Data Breach Cryptocurrency Exchange

Lite-On Technology Corporation

RansomEXX claimed a 142GB data theft from Taiwan's Lite-On Technology

Ransomware Electronics Manufacturing

Squirrel

Squirrel breach exposed ID documents of up to 600 New Zealand investors

Hacking Financial Services

Leidos Holdings

Leidos internal documents leaked online after third-party vendor breach

Third-Party Data Breach IT Services

Split Airport

Akira ransomware attack disrupts flights at Croatia's Split Airport

Ransomware Aviation

FirstNet (AT&T)

AT&T reversed course and said most FirstNet numbers were in the breached data

Third-Party Data Breach Public Safety Communications

Superior Court of Los Angeles County

Ransomware closed all 36 Los Angeles County Superior Court courthouses

Ransomware Judiciary

Wattle Range Council

LockBit posts data stolen from South Australia's Wattle Range Council

Ransomware Local Government

Michigan Medicine

Michigan Medicine notifies about 57,000 patients after email account breach

Hacking Healthcare

City of Columbus, Ohio

Rhysida claimed 6.5TB of data from the City of Columbus ransomware attack

Ransomware Municipal Government

Pueblo County School District 70

Pueblo County School District 70 disclosed ransomware breach of student records

Ransomware Education

Atlassian (Trello)

Trello data on 15 million users leaked after an open API was scraped

Hacking Software

Rite Aid

Rite Aid says June cyberattack exposed data on 2.2 million people

Ransomware Retail Pharmacy

The Walt Disney Company

Disney investigates leak of 1.1 TB of internal Slack data

Hacking Entertainment

Bassett Furniture Industries

Bassett Furniture halted manufacturing after ransomware encrypted data files

Ransomware Furniture Manufacturing

AT&T

AT&T discloses theft of call and text records for nearly all wireless customers

Credential Compromise Telecommunications

Goshen Central School District

Goshen Central School District hit by ransomware attack

Ransomware Education

Sibanye-Stillwater

Sibanye-Stillwater cyberattack hit the mining group's IT systems worldwide

Hacking Mining

Advance Auto Parts

Advance Auto Parts notifies 2.3 million after Snowflake-linked breach

Credential Compromise Retail

The Heritage Foundation

SiegedSec leaks Heritage Foundation data in protest over Project 2025

Hacking Think Tank

Roblox

Roblox developer conference attendee data exposed in FNTech vendor breach

Third-Party Data Breach Gaming

Florida Department of Health

Florida Department of Health data published after RansomHub attack

Ransomware Government

Elite Fitness

Elite Fitness confirms DragonForce ransomware attack in New Zealand

Ransomware Retail

Roll20

Roll20 discloses breach of an administrative account exposing user records

Hacking Gaming

Alabama State Department of Education

Alabama State Department of Education breached in a halted ransomware attack

Hacking Education

Fédération Internationale de l'Automobile (FIA)

FIA discloses data breach after phishing attacks on two email accounts

Phishing Sports Governing Body

HealthEquity, Inc.

HealthEquity breach traced to a compromised business partner account

Credential Compromise Health Benefits Administration

Patelco Credit Union

Patelco Credit Union ransomware attack shuts down banking systems for weeks

Ransomware Financial Services

Mass General Brigham

Mass General Brigham fired staff who let outsiders view patient records

Malicious Insider Healthcare

Federated Co-operatives Limited

Federated Co-operatives cyberattack disrupted Co-op stores and fuel cardlocks

Ransomware Retail and Wholesale

TeamViewer

TeamViewer's corporate network was breached by APT29

Credential Compromise Software

Kadokawa Corporation

Kadokawa confirmed a ransomware attack on its data centre and Niconico

Ransomware Media and Entertainment

University Hospital Centre Zagreb (KBC Zagreb)

LockBit claims attack on Croatia's largest hospital, KBC Zagreb

Ransomware Healthcare

Cambridge University Press & Assessment

Cambridge University Press & Assessment hit by INC Ransom attack

Ransomware Publishing

Evolve Bank & Trust

LockBit's claimed Federal Reserve hack was really Evolve Bank & Trust data

Ransomware Banking

Neiman Marcus Group

Neiman Marcus confirmed a Snowflake-linked breach affecting 64,472 people

Credential Compromise Retail

Geisinger

Geisinger notified over a million patients after a vendor insider breach

Third-Party Data Breach Healthcare

National Health Laboratory Service (NHLS)

Ransomware halts test reporting at South Africa's National Health Laboratory Service

Ransomware Healthcare

Pusat Data Nasional (Indonesia National Data Center)

Indonesia's Pusat Data Nasional crippled by Brain Cipher ransomware

Ransomware Government

Financial Business and Consumer Solutions

Debt collector FBCS breach grew from 1.9 million to more than 3 million people

Hacking Debt Collection

Jollibee Foods Corporation

Jollibee investigated a data breach affecting 11 million customers

Hacking Food Service

Disability Rights Wisconsin

Disability Rights Wisconsin email breach exposed 19,150 Medicaid members

Hacking Nonprofit

Accenture

Accenture disputed a BreachForums claim of 32,000 leaked employee records

Hacking Professional Services

CDK Global

CDK Global ransomware attack halted software at 15,000 car dealerships

Ransomware Software

Victoria Racing Club

Medusa ransomware gang demanded US$700,000 from Victoria Racing Club

Ransomware Sports and Recreation

Truist Bank

Truist Bank confirms October 2023 breach after employee data listed for sale

Hacking Banking

Newberg-Dundee School District

Newberg-Dundee School District hit by ransomware in June 2024

Ransomware Education

Life360 (Tile)

Life360 says hacker stole Tile customer data and tried to extort the company

Credential Compromise Consumer Technology

City of Cleveland, Ohio

City of Cleveland confirms ransomware attack that closed City Hall for two weeks

Ransomware Municipal Government

Vietnam Post

Ransomware attack took Vietnam Post's delivery systems offline

Ransomware Postal Services

Verny

Cyberattack forces Russian discount chain Verny to take cash only across 1,000 stores

Hacking Retail

Synnovis

Synnovis ransomware attack disrupts pathology services at London NHS hospitals

Ransomware Healthcare

Heineken

Heineken employee data offered for sale after 888 claimed a breach

Hacking Food and Beverage

King's College Hospital NHS Foundation Trust

Synnovis ransomware attack disrupted King's College Hospital and other London trusts

Supply Chain Attack Healthcare

Christian Democratic Union (CDU)

Germany's CDU took IT systems offline after a serious cyberattack

Hacking Politics

Easterseals Central Illinois

Rhysida ransomware gang demanded $1.3 million from Easterseals Central Illinois

Ransomware Non-profit

Ticketek Australia

Ticketek Australia customer data exposed via third-party cloud platform

Third-Party Data Breach Ticketing

Snowflake

Snowflake says up to 165 customer accounts hit in credential theft campaign

Credential Compromise Cloud Computing

Guardian Childcare

Guardian Childcare breach exposed scanned ID documents of Australian families

Hacking Childcare

Live Nation Entertainment (Ticketmaster)

Live Nation disclosed Ticketmaster data theft from a third-party cloud database

Third-Party Data Breach Entertainment and Ticketing

Everbridge

Everbridge told customers attackers reached corporate files after employee phishing

Phishing Software

BBC

BBC Pension Scheme breach exposed data on more than 25,000 members

Hacking Broadcasting

Smith & Caughey's

Smith & Caughey's crypto-locked by ransomware on the day it announced its closure

Ransomware Retail

The Seattle Public Library

Ransomware attack knocked The Seattle Public Library's systems offline

Ransomware Public Library

Decathlon

Decathlon confirmed Spanish employee email addresses leaked from third-party app

Third-Party Data Breach Retail

Sav-Rx (A&A Services)

Sav-Rx breach exposed data of 2.8 million prescription plan members

Hacking Pharmacy Benefits

Cencora

Eleven drug companies disclose patient data loss from Cencora breach

Hacking Pharmaceutical Services

TRC Staffing Services, Inc. (TRC Talent Solutions)

TRC Talent Solutions ransomware breach exposed 158,593 job seekers

Ransomware Staffing

Welsh Rugby Union

Welsh Rugby Union investigated leak of supporters club member data

Misconfiguration Sports Governing Body

Albany County, New York

Albany County, New York investigates possible cybersecurity breach

Hacking Government

Merrill Lynch, Pierce, Fenner & Smith Incorporated

Merrill email error exposed Social Security numbers of Walmart 401(k) savers

Human Error Financial Services

First Nations Health Authority

First Nations Health Authority reported a cyberattack on its corporate network

Hacking Healthcare

American Radio Relay League (ARRL)

ARRL cyberattack takes Logbook of The World offline

Ransomware Membership Association

Guam Seventh-Day Adventist Clinic

Guam Seventh-Day Adventist Clinic email breach exposed 56,635 people

Hacking Healthcare

MediSecure

MediSecure ransomware attack hits Australian e-prescription provider

Ransomware Healthcare Technology

Rockford Public Schools

Ransomware attack knocks out Rockford Public Schools network

Ransomware Education

Nissan North America

Nissan North America breach exposed Social Security numbers of 53,000 employees

Ransomware Automotive

Affiliated Dermatologists & Dermatologic Surgeons, P.A.

Affiliated Dermatologists breach hit about 380,000 patients and staff

Ransomware Healthcare

Banco Santander

Santander says third-party database breach hit customers and staff

Third-Party Data Breach Banking

Keytronic

Keytronic confirms data theft after Black Basta ransomware attack

Ransomware Electronics Manufacturing

Palomar Health Medical Group

Palomar Health Medical Group cyberattack knocked outpatient systems offline for months

Hacking Healthcare

MedStar Health

MedStar Health email breach exposed data on about 183,000 patients

Hacking Healthcare

DocGo

DocGo discloses cyberattack that exposed patient health data

Hacking Healthcare

City of Wichita, Kansas

Ransomware forces the City of Wichita to shut down its network

Ransomware Municipal Government

Monash Health

Monash Health records exposed in ZircoDATA ransomware breach

Third-Party Data Breach Healthcare

Dropbox

Dropbox Sign production systems breached, user credentials exposed

Hacking Technology

Firstmac Limited

Firstmac confirms breach after EMBARGO ransomware attack

Ransomware Financial Services

JPMorgan Chase

Software flaw at J.P. Morgan exposed data on 451,000 retirement savers

Misconfiguration Financial Services

Kaiser Foundation Health Plan (Kaiser Permanente)

Kaiser Permanente website trackers exposed data on 13.4 million members

Misconfiguration Healthcare

London Drugs

London Drugs closed all 79 stores across Western Canada after a ransomware attack

Ransomware Retail Pharmacy

State Security Committee of the Republic of Belarus (KGB)

Cyber-Partisans claim breach of Belarus state security service

Hacking Government

Coffee County, Georgia

Coffee County, Georgia cut its link to the state voter roll after a cyberattack

Ransomware Local Government

LivaNova

LivaNova notified about 130,000 people after LockBit ransomware attack

Ransomware Medical Devices

Skanlog

Ransomware at Nordic distributor Skanlog empties Systembolaget shelves

Ransomware Logistics

Tipton Municipal Utilities

Russia-linked group claimed cyberattack on Tipton, Indiana wastewater plant

Hacking Water Utility

Grodno Azot

Cyber-Partisans encrypt systems at Belarusian fertilizer maker Grodno Azot

Ransomware Chemical Manufacturing

Carpetright

Carpetright cyberattack halts UK store and online trading for a week

Hacking Retail

The MITRE Corporation

MITRE said nation-state hackers breached its NERVE network via Ivanti zero-days

Hacking Nonprofit Research

Pandemonium Rocks

Pandemonium Rocks refund form exposed ticketholders' bank details

Misconfiguration Live Events

District of Columbia Department of Insurance, Securities and Banking (DISB)

LockBit claimed DC insurance regulator data taken via Tyler Technologies cloud

Third-Party Data Breach Government

Frontier Communications Parent, Inc.

Frontier Communications disclosed April 2024 breach of its IT environment

Hacking Telecommunications

Solano County Library

Ransomware took Solano County's SPLASH library network offline for weeks

Ransomware Public Libraries

Octapharma Plasma

Ransomware shut Octapharma Plasma donation centers across 35 US states

Ransomware Healthcare

Centre Hospitalier Simone Veil de Cannes (CHC-SV)

Cannes hospital CHC-SV reverted to paper after LockBit ransomware attack

Ransomware Healthcare

United Nations Development Programme (UNDP)

UNDP confirmed data theft after ransomware attack on Copenhagen IT systems

Ransomware International Development

Wells Fargo

Wells Fargo employee sent customer data to a personal account

Malicious Insider Banking

The Heritage Foundation

Heritage Foundation shut down its network after April 2024 cyberattack

Hacking Think Tank

Sisense

CISA warned Sisense customers to reset credentials after vendor breach

Hacking Business Analytics Software

City of Saint-Nazaire

Ransomware paralyzed Saint-Nazaire and four neighboring French communes

Ransomware Municipal Government

U.S. Environmental Protection Agency (EPA)

EPA denies breach after hacker posts 8.5 million contact records

Hacking Government

The Home Depot

Home Depot confirmed a vendor exposed employee data leaked by IntelBroker

Third-Party Data Breach Retail

New Mexico Highlands University

New Mexico Highlands University canceled a week of classes after ransomware attack

Ransomware Higher Education

CVS Group plc

CVS Group took systems offline after unauthorised access to UK IT servers

Hacking Veterinary Services

EBlock Corp.

EBlock notified nearly 2,000 people of breach of legacy ABS Auto Auctions systems

Hacking Automotive Auctions

Panera Bread

Panera Bread ransomware attack caused week-long nationwide IT outage

Ransomware Restaurants

Jackson County, Missouri

Jackson County, Missouri declared a state of emergency after ransomware attack

Ransomware Local Government

Omni Hotels & Resorts

Daixin ransomware attack took Omni Hotels & Resorts systems offline for a week

Ransomware Hospitality

IxMetro PowerHost

SEXi ransomware encrypted IxMetro PowerHost's ESXi servers and its backups

Ransomware Hosting and Data Centers

AT&T

AT&T confirmed data on 73 million current and former customers leaked online

Hacking Telecommunications

Hot Topic, Inc.

Hot Topic notifies customers after November 2023 credential stuffing attacks

Credential Compromise Retail

Activision Blizzard

Activision warns players after infostealer malware harvested gaming logins

Credential Compromise Video Games

Carolina Foods Inc.

Black Basta claims ransomware attack on snack maker Carolina Foods

Ransomware Food Manufacturing

The Big Issue Group

Qilin ransomware gang leaked data stolen from The Big Issue Group

Ransomware Media

Giant Tiger Stores Limited

Giant Tiger customer contact data exposed in third-party vendor breach

Third-Party Data Breach Retail

Communications Workers Union (CWU)

UK Communications Workers Union confirms cyberattack on its IT systems

Hacking Trade Union

Air Europa

Air Europa told customers passport and ID data was exposed in 2023 breach

Hacking Airline

Radiant Logistics

Radiant Logistics isolated Canadian operations after March 2024 cyberattack

Hacking Logistics

Crinetics Pharmaceuticals

LockBit claimed attack on Crinetics Pharmaceuticals and demanded $4 million

Ransomware Pharmaceuticals

MediaWorks

MediaWorks said 403,000 New Zealanders' data was taken in competition hack

Hacking Media and Broadcasting

Office of the Colorado State Public Defender

Colorado public defender says ransomware attack exposed client data

Ransomware Government

International Monetary Fund (IMF)

IMF said 11 email accounts were compromised in a February 2024 breach

Hacking International Financial Institution

NHS Dumfries and Galloway

NHS Dumfries and Galloway hit by focused and ongoing cyberattack

Ransomware Healthcare

Fujitsu

Fujitsu confirms malware on work computers and possible data theft

Hacking Technology

Scranton School District

Ransomware attack knocks out Scranton School District systems

Ransomware Education

Nations Direct Mortgage

Nations Direct Mortgage notified 83,000 people of a December 2023 breach

Hacking Financial Services

France Travail

France Travail breach exposes data on up to 43 million job seekers

Credential Compromise Government

EquiLend

EquiLend tells employees data was stolen in January ransomware attack

Ransomware Financial Services

MarineMax

Rhysida claims ransomware attack on boat retailer MarineMax

Ransomware Retail

Cybersecurity and Infrastructure Security Agency (CISA)

CISA took two systems offline after Ivanti gateway flaws were exploited

Hacking Government

Roku

Roku disclosed credential stuffing attack affecting 15,363 accounts

Credential Compromise Streaming Media

Leicester City Council

Leicester City Council shut down IT systems and phone lines after cyberattack

Ransomware Municipal Government

Jersey Financial Services Commission (JFSC)

Jersey Financial Services Commission registry flaw exposed 66,806 records

Misconfiguration Financial Regulator

South St. Paul Public Schools

South St. Paul Public Schools took systems offline after network intrusion

Ransomware Education

Duvel Moortgat

Ransomware halted brewing at Duvel Moortgat's Belgian and US sites

Ransomware Food and Beverage

Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)

FINTRAC took corporate systems offline after a March 2024 cyber incident

Hacking Government

Scottish Ambulance Service

Scottish Ambulance Service apologizes after first responder spreadsheet emailed in error

Human Error Emergency Services

American Express

American Express warns cardholders of breach at third-party merchant processor

Third-Party Data Breach Financial Services

Fidelity Investments Life Insurance Company

Fidelity Investments Life Insurance notified 28,000 after Infosys McCamish breach

Third-Party Data Breach Insurance

Chunghwa Telecom

Chunghwa Telecom breach put 1.7TB of Taiwanese government data on the dark web

Hacking Telecommunications

YX International

YX International left SMS database of one-time passcodes exposed online

Misconfiguration Telecommunications

Cutout.Pro

Cutout.Pro records for about 20 million accounts leaked on hacking forum

Hacking Technology

U-Haul International, Inc.

U-Haul notified 67,000 customers after reservation system breach

Credential Compromise Vehicle Rental

City of Hamilton, Ontario

Ransomware disabled most of the City of Hamilton's network for weeks

Ransomware Municipal Government

Quik Pawn Shop

Akira ransomware group claimed an attack on Alabama's Quik Pawn Shop

Ransomware Consumer Lending

Royal Canadian Mounted Police (RCMP)

Royal Canadian Mounted Police opened criminal probe into network cyberattack

Hacking Law Enforcement

Das Team AG (dasteam ag)

Black Basta leaked 200GB stolen from Swiss staffing firm Das Team AG

Ransomware Staffing and Recruitment

Malawi Department of Immigration and Citizenship Services

Malawi halts passport printing after immigration system hack and ransom demand

Hacking Government

Tangerine Telecom

Tangerine Telecom breach exposed data on 232,000 Australian customers

Credential Compromise Telecommunications

Change Healthcare

Cyberattack on Change Healthcare disrupted US pharmacies and claims processing

Ransomware Healthcare Technology

Robert Half International

IntelBroker and Sanggiero claimed a data breach at staffing firm Robert Half

Hacking Staffing and Recruitment

Stratford-on-Avon District Council

Stratford-on-Avon council insider took 79,000 resident email addresses

Malicious Insider Local Government

Golden Corral Corporation

Golden Corral breach exposed data on more than 183,000 employees

Hacking Restaurants

INTEGRIS Health

INTEGRIS Health said a 2023 breach exposed data on 2.4 million patients

Hacking Healthcare

PSI Software SE

Ransomware attack forced German control systems vendor PSI Software offline

Ransomware Industrial Software

Washington County, Pennsylvania

Washington County, Pennsylvania paid a $350,000 ransom after January cyberattack

Ransomware Local Government

Trans-Northern Pipelines

ALPHV claimed a data theft at Canada's Trans-Northern Pipelines

Hacking Energy

Bank of America

Bank of America notified 57,028 customers after Infosys McCamish breach

Third-Party Data Breach Financial Services

Varta AG

Cyberattack halted production at German battery maker Varta AG

Hacking Manufacturing

Prudential Financial

Prudential Financial disclosed breach of employee and contractor data

Ransomware Financial Services

Slobozia County Emergency Hospital

Slobozia hospital among Romanian hospitals hit by Hipocrate ransomware attack

Ransomware Healthcare

Hyundai Motor Europe

Black Basta claimed three terabytes of data from Hyundai Motor Europe

Ransomware Automotive

WinStar World Casino and Resort

WinStar app customer data exposed by unsecured Dexiga database

Misconfiguration Casinos and Gaming

Service Employees International Union (SEIU) Local 1000

LockBit ransomware attack disrupted SEIU Local 1000 in California

Ransomware Labor Union

Medical Management Resource Group, LLC (American Vision Partners)

Medical Management Resource Group breach hit 2.35 million eye care patients

Hacking Healthcare Services

Municipality of Korneuburg, Austria

Ransomware attack on Austria's Korneuburg municipality postponed funerals

Ransomware Municipal Government

AnyDesk

AnyDesk confirms attackers breached its production systems

Hacking Software

Football Australia

Football Australia exposed player passports and contracts through leaked AWS keys

Human Error Sports Governing Body

Ann & Robert H. Lurie Children's Hospital of Chicago

Ransomware attack took Lurie Children's Hospital systems offline for weeks

Ransomware Healthcare

City of Jacksonville Beach, Florida

Jacksonville Beach said ransomware attack exposed data on about 49,000 people

Ransomware Municipal Government

Keenan & Associates

Keenan & Associates breach exposed data of more than 1.5 million people

Hacking Insurance

Global Affairs Canada

Global Affairs Canada breach exposed employee data through a compromised VPN

Hacking Government

Schneider Electric

Cactus ransomware hit Schneider Electric's Sustainability Business division

Ransomware Energy Management

Fulton County, Georgia

Cyberattack knocked out Fulton County, Georgia government systems

Ransomware Local Government

Freehold Township School District

Freehold Township School District closes schools after cybersecurity incident

Hacking Education

Hewlett Packard Enterprise

Russian group APT29 read Hewlett Packard Enterprise email for seven months

Hacking Technology

Caravan and Motorhome Club

Caravan and Motorhome Club outage in UK traced to a cyberattack

Ransomware Membership Organization

Southern Water

Black Basta claims ransomware attack on UK utility Southern Water

Ransomware Water Utilities

Jason's Deli

Jason's Deli customer accounts breached in credential stuffing attack

Credential Compromise Restaurants

City of Frederick, Maryland

City of Frederick lost $280,527 to a phishing driven wire fraud scheme

Business Email Compromise Municipal Government

DENHAM the Jeanmaker

DENHAM the Jeanmaker confirms cyberattack linked to Akira ransomware

Ransomware Fashion Retail

Bucks County, Pennsylvania

Bucks County, Pennsylvania loses emergency dispatch system in ransomware attack

Ransomware Local Government

Microbe & Lab (CoronaLab)

Dutch COVID testing lab CoronaLab exposed 1.3 million records in open database

Misconfiguration Medical Laboratory

GALA Hispanic Theatre

GALA Hispanic Theatre recovers $255,000 drained in bank fraud

Business Email Compromise Arts and Culture

Trezor

Trezor support portal breach exposes contact data of 66,000 users

Third-Party Data Breach Cryptocurrency

Veolia North America

Veolia North America discloses ransomware attack on Municipal Water division

Ransomware Water Utilities

Microsoft

Microsoft says Midnight Blizzard read senior leaders' corporate email

Credential Compromise Technology

Tilbury District Family Health Team

Tilbury District Family Health Team patient data taken in TransForm ransomware attack

Third-Party Data Breach Healthcare

Foxsemicon Integrated Technology

LockBit defaces Foxsemicon website and claims 5TB of stolen data

Ransomware Semiconductor Manufacturing

Kansas State University

Kansas State University cyberattack knocks out VPN, email and campus services

Hacking Higher Education

Hal Leonard Australia

Qilin leaks 37.6 GB of data from music publisher Hal Leonard Australia

Ransomware Music Publishing

Water for People

Medusa gang listed nonprofit Water for People with a $300,000 demand

Ransomware Nonprofit

Clearview Resources Ltd.

Clearview Resources loses C$1.5 million to email account takeover

Business Email Compromise Energy

Lush

Lush confirms cyber incident later described as a ransomware attack

Ransomware Retail

Inspiring Vacations

Inspiring Vacations left 112,000 travel records in an open cloud bucket

Misconfiguration Travel

HMG Healthcare

HMG Healthcare breach hit residents and staff at 40 nursing facilities

Hacking Healthcare

Toronto Zoo

Toronto Zoo discloses ransomware incident, employee records taken

Ransomware Zoo

Midwives of Windsor

Midwives of Windsor tells clients an email account was breached in April 2023

Credential Compromise Healthcare

Cooper Aerobics

Cooper Aerobics notifies patients almost a year after network intrusion

Hacking Healthcare

Housing Authority of the County of San Bernardino

San Bernardino County housing authority breach exposed 18,689 people

Hacking Local Government

Orrick, Herrington & Sutcliffe

Orrick law firm breach exposed data on more than 637,000 people

Hacking Legal Services

Gallery Systems

Gallery Systems ransomware attack took museum collection databases offline

Ransomware Software

HealthEC LLC

HealthEC breach exposed records of about 4.5 million patients

Hacking Healthcare Technology

Communaute de communes du Pays Fouesnantais

Cyberattack shut down IT services across France's Pays Fouesnantais

Ransomware Local Government

Court Services Victoria

Court Services Victoria breach exposed years of court hearing recordings

Ransomware Government

Orbit Chain

Orbit Chain lost about $81 million in New Year's Eve bridge exploit

Hacking Cryptocurrency

Memorial University of Newfoundland

Memorial University delays Grenfell Campus classes after ransomware attack

Ransomware Higher Education

Katholische Hospitalvereinigung Ostwestfalen

LockBit ransomware hit three German hospitals run by KHO on Christmas Eve

Ransomware Healthcare

Fallon Ambulance Service

Defunct Fallon Ambulance Service breach exposed data on 911,757 people

Ransomware Emergency Medical Services

National Amusements

National Amusements disclosed a December 2022 breach affecting 82,128 people

Hacking Media and Entertainment

Mint Mobile

Mint Mobile told customers a hacker obtained their account data

Hacking Telecommunications

Ateam Inc.

Ateam Google Drive misconfiguration exposed data on 935,779 people

Misconfiguration Technology

Comcast Xfinity

Comcast Xfinity breach exposed data of 35.8 million customers via Citrix Bleed

Hacking Telecommunications

Insomniac Games

Rhysida leaks 1.67TB of Insomniac Games data after Sony studio refuses ransom

Ransomware Video Games

VF Corporation

VF Corporation reported a ransomware attack in one of the first SEC cyber filings

Ransomware Apparel and Footwear

Fred Hutchinson Cancer Center

Fred Hutchinson Cancer Center ransomware attack led to extortion of patients

Ransomware Healthcare

Ledger

Ledger Connect Kit compromised after phishing attack on a former employee

Phishing Cryptocurrency Hardware

Delta Dental of California

Delta Dental of California MOVEit breach affected nearly 7 million people

Hacking Dental Insurance

London Public Library

London Public Library in Ontario shut down services after a cyberattack

Hacking Public Library

Asper Biogene

Asper Biogene breach exposed genetic and health data of 10,000 in Estonia

Hacking Genetic Testing

Kyivstar

Kyivstar cyberattack knocked out mobile service for millions in Ukraine

Hacking Telecommunications

Greater Richmond Transit Company (GRTC)

Greater Richmond Transit Company hit by Play ransomware over Thanksgiving

Ransomware Public Transportation

Norton Healthcare

Norton Healthcare ransomware breach exposed data on 2.5 million people

Ransomware Healthcare

City of Huber Heights, Ohio

Huber Heights, Ohio spends months rebuilding after BlackSuit ransomware attack

Ransomware Municipal Government

Binghamstown/Drum Group Water Scheme

Hacktivists cut water to Irish group scheme over Israeli-made pump controller

Hacking Water Utility

Austal USA

Austal USA confirms data incident after Hunters International leak claim

Hacking Shipbuilding

HTC Global Services

HTC Global Services confirms cyberattack after ALPHV leaks stolen files

Ransomware IT Services

Nissan Oceania

Nissan warns Australian and New Zealand customers after Akira ransomware breach

Ransomware Automotive

WeMystic

WeMystic left 13.3 million user records exposed in an open database

Misconfiguration Consumer Web Services

Staples

Staples took systems offline after a Cyber Monday intrusion

Hacking Office Supply Retail

Japan Aerospace Exploration Agency (JAXA)

JAXA confirms intruders reached its internal network

Hacking Government

Yanfeng Automotive Interiors

Qilin ransomware group claims attack on auto supplier Yanfeng

Ransomware Automotive Manufacturing

ZeroedIn Technologies

ZeroedIn Technologies breach exposed data of about 2 million Dollar Tree workers

Hacking Human Resources Technology

National Aerospace Laboratories

LockBit claims ransomware attack on India's National Aerospace Laboratories

Ransomware Aerospace Research

Ardent Health Services

Ardent Health Services ransomware attack diverted ambulances at US hospitals

Ransomware Healthcare

Municipal Water Authority of Aliquippa

Cyber Av3ngers hijacked a controller at Aliquippa's water authority

Hacking Water Utility

Indian Hotels Company Limited (Taj Hotels)

Taj Hotels investigates claimed leak of data on 1.5 million guests

Hacking Hospitality

Fidelity National Financial (FNF)

Fidelity National Financial shut down systems after ALPHV ransomware attack

Ransomware Title Insurance

Brookfield Global Relocation Services (BGRS)

BGRS and SIRVA Canada breach exposed decades of federal relocation files

Ransomware Relocation Services

Idaho National Laboratory

Idaho National Laboratory confirmed HR system breach claimed by SiegedSec

Hacking Nuclear Research

Service public de l'assainissement francilien (SIAAP)

Paris-area wastewater agency SIAAP hit by cyberattack

Hacking Water Utility

Blue Shield of California

Blue Shield of California members hit by MOVEit breach at vision benefits vendor

Third-Party Data Breach Health Insurance

Toyota Financial Services

Medusa ransomware hit Toyota Financial Services in Europe and Africa

Ransomware Automotive Finance

MeridianLink

MeridianLink confirmed a cyberattack after ALPHV reported it to the SEC

Ransomware Financial Software

Stanley Steemer

Stanley Steemer breach exposed data on about 67,000 customers

Hacking Consumer Services

Samsung Electronics

Samsung UK store breach exposed contact details of 2019 and 2020 shoppers

Hacking Consumer Electronics

City of Long Beach, California

Long Beach declared a local emergency after a November 2023 network breach

Hacking Municipal Government

DP World Australia

DP World Australia halts four container ports after network intrusion

Hacking Ports and Logistics

Washington State Department of Transportation

Cyberattack disrupts Washington State Department of Transportation services

Hacking Government

Henry County Schools

Henry County Schools network shut down by BlackSuit ransomware attack

Ransomware Education

Industrial and Commercial Bank of China (ICBC)

ICBC's US broker-dealer hit by LockBit ransomware, disrupting Treasury trades

Ransomware Financial Services

State of Maine

State of Maine says MOVEit breach exposed data on 1.3 million people

Hacking Government

Electric Ireland

Electric Ireland says contractor staff member accessed 8,000 customers' data

Malicious Insider Energy

Marina Bay Sands

Marina Bay Sands breach exposed data on 665,000 loyalty members

Hacking Hospitality

Sutter Health

Sutter Health says MOVEit breach at vendor Welltok exposed 845,000 patients

Supply Chain Attack Healthcare

Shimano

LockBit claims 4.5TB of data stolen from bicycle component maker Shimano

Ransomware Manufacturing

Cook County Health

Cook County Health notifies 1.2 million patients of breach at vendor PJ&A

Third-Party Data Breach Healthcare

Boeing

Boeing confirms cyberattack on its parts and distribution business

Ransomware Aerospace

Queretaro Intercontinental Airport

Queretaro Intercontinental Airport confirms cyberattack claimed by LockBit

Ransomware Aviation

The British Library

Rhysida ransomware attack kept British Library services offline for weeks

Ransomware Libraries and Archives

Mr. Cooper Group

Mr. Cooper shuts down systems after cyberattack, blocking mortgage payments

Hacking Financial Services

Truepill (Postmeds Inc.)

Truepill breach exposed prescription records of about 2.3 million patients

Hacking Pharmacy

Allied Pilots Association

Ransomware hits Allied Pilots Association, the American Airlines pilots union

Ransomware Labor Union

Sudwestfalen IT

Ransomware at Sudwestfalen IT disrupts more than 70 German municipalities

Ransomware IT Services

Ace Hardware

Ace Hardware cyberattack downs 1,202 devices and halts online orders

Hacking Retail

Toronto Public Library

Toronto Public Library cyberattack takes down digital services at 100 branches

Ransomware Public Libraries

Stanford University

Akira claimed 430 GB from Stanford's public safety department

Ransomware Higher Education

Clark County School District (CCSD)

Hackers emailed stolen student records to Clark County School District parents

Hacking Education

American Family Insurance

American Family Insurance confirmed a cyberattack behind week-long outages

Hacking Insurance

Seiko Group Corporation

Seiko says ransomware attack exposed about 60,000 items of personal data

Ransomware Manufacturing

Welltok

Welltok MOVEit breach exposed data on 8.5 million US patients

Hacking Healthcare Software

Grupo GTD

Rorschach ransomware disrupts Chilean telecom operator Grupo GTD

Ransomware Telecommunications

Orange County District Attorney's Office

Orange County District Attorney shut down IT systems after a cyberattack

Hacking Government

TransForm Shared Service Organization

Ransomware at TransForm knocked out systems at six Ontario health facilities

Ransomware Healthcare IT

Westchester Medical Center Health Network (WMCHealth)

WMCHealth diverted ambulances after a cyberattack on Hudson Valley hospitals

Hacking Healthcare

Kwik Trip

Kwik Trip confirmed a cyberattack caused its two-week systems outage

Hacking Retail

D-Link

D-Link confirmed a phishing attack exposed old registration records

Phishing Networking Hardware

Arietis Health, LLC

Arietis Health reported a MOVEit breach affecting nearly 2 million patients

Hacking Healthcare Billing

Ampersand

Ampersand confirmed ransomware attack claimed by Black Basta

Ransomware Advertising

Henry Schein

Henry Schein confirms a cybersecurity incident as ALPHV claims the attack

Ransomware Healthcare

Morrison Community Hospital

BlackCat claimed 5TB data theft from Morrison Community Hospital

Ransomware Healthcare

Quality Service Installation (QSI), Inc.

ALPHV claimed 5TB of data from ATM installer Quality Service Installation

Ransomware Banking Technology

CDW

LockBit demanded $80 million from CDW after breaching Sirius Federal servers

Ransomware Technology Services

Perry Johnson & Associates (PJ&A)

PJ&A transcription breach exposed data of nearly 9 million patients

Hacking Medical Transcription

LDLC ASVEL Villeurbanne

LDLC ASVEL confirmed data theft after NoEscape ransomware listing

Ransomware Sports

Shadow

Shadow said hacker stole customer data after employee lured on Discord

Credential Compromise Cloud Gaming

Simpson Manufacturing

Simpson Manufacturing took systems offline after October 2023 cyberattack

Hacking Manufacturing

Volex plc

Volex said attackers accessed IT systems and data at international sites

Hacking Electronics Manufacturing

Lyca Mobile

Lyca Mobile confirmed customer data theft after cyberattack

Hacking Telecommunications

District of Columbia Board of Elections (DCBOE)

DC Board of Elections says voter roll was stolen from its hosting provider

Third-Party Data Breach Government

Flagstar Bank

Flagstar Bank told 837,000 customers their data was taken in Fiserv MOVEit breach

Third-Party Data Breach Financial Services

23andMe

23andMe user profiles scraped after credential stuffing attack

Credential Compromise Consumer Genetics

The Royal Women's Hospital

Royal Women's Hospital notified 192 patients after staff email account hacked

Credential Compromise Healthcare

Sony Interactive Entertainment

Sony Interactive Entertainment notified about 6,800 people of MOVEit breach

Hacking Video Games

Estes Express Lines

Estes Express Lines confirms cyberattack behind multi-day IT outage

Ransomware Transportation and Logistics

First Judicial Circuit Court of Florida

ALPHV claimed ransomware attack on Florida's First Judicial Circuit Court

Ransomware Government

Motel One

Motel One confirms data theft after ALPHV/BlackCat ransomware attack

Ransomware Hospitality

McLaren Health Care

McLaren Health Care confirms ransomware attack claimed by ALPHV/BlackCat

Ransomware Healthcare

Builders Mutual Insurance Company

Builders Mutual Insurance notified 64,761 people of a 2022 network intrusion

Hacking Insurance

World Baseball Softball Confederation (WBSC)

World Baseball Softball Confederation exposed 4,600 passport scans in open AWS bucket

Misconfiguration Sports Governing Body

European Telecommunications Standards Institute (ETSI)

ETSI says attackers stole its online user database

Hacking Standards Body

Flair Airlines

Flair Airlines left database and email credentials exposed on its website

Misconfiguration Airline

BORN Ontario (Better Outcomes Registry & Network)

BORN Ontario says MOVEit breach exposed health data on 3.4 million people

Supply Chain Attack Healthcare

Auckland University of Technology

Auckland University of Technology hit by cyberattack claimed by Monti ransomware

Ransomware Higher Education

Pizza Hut Australia

Pizza Hut Australia told 193,000 customers their data was accessed

Hacking Restaurants

Progressive Leasing

Progressive Leasing discloses cyberattack that exposed Social Security numbers

Ransomware Consumer Leasing

Air Canada

Air Canada says internal system breached, limited employee data accessed

Hacking Airline

Lakeland Community College

Lakeland Community College notified 285,948 people of a data breach

Ransomware Higher Education

International Criminal Court

International Criminal Court detected intrusion into its information systems

Hacking Judiciary

City of Pittsburg, Kansas

Cyberattack knocked out email, phones and payments in Pittsburg, Kansas

Hacking Local Government

Virginia Department of Medical Assistance Services

Virginia Medicaid agency reports breach affecting 1.2 million people

Hacking Government

Shell (BG Group Australia)

Shell says BG Group Australia employee data taken in MOVEit breach

Supply Chain Attack Oil and Gas

Greater Manchester Police

Greater Manchester Police officer data exposed in supplier ransomware attack

Supply Chain Attack Law Enforcement

Caesars Entertainment

Caesars Entertainment disclosed loyalty database theft and paid a ransom

Ransomware Hospitality and Gaming

Auckland Transport

Auckland Transport ticketing systems disrupted by ransomware attack

Ransomware Public Transport

ORBCOMM

ORBCOMM ransomware attack knocked out trucking fleet management and ELDs

Ransomware Transportation Technology

Airbus

Airbus supplier data leaked after credentials stolen from airline employee

Credential Compromise Aerospace

MGM Resorts International

MGM Resorts shut down IT systems across its casinos after a cyberattack

Ransomware Hospitality and Gaming

Canadian Nurses Association

Canadian Nurses Association confirmed data theft after Snatch leaked 37GB

Ransomware Professional Association

Dymocks

Dymocks blamed an external data partner for a breach of 836,000 customers

Third-Party Data Breach Retail

International Joint Commission

NoEscape claimed an 80GB theft from the US-Canada International Joint Commission

Ransomware Government

Sabre Corporation

Dunghill Leak claimed a 1.3TB data theft from travel technology firm Sabre

Ransomware Travel Technology

Johnson & Johnson

IBM breach exposed Johnson & Johnson's Janssen CarePath patient data

Third-Party Data Breach Pharmaceuticals

NXP Semiconductors

NXP Semiconductors told portal account holders their contact data was exposed

Hacking Semiconductors

Zaun

LockBit attack on UK fencing maker Zaun exposed military site documents

Ransomware Manufacturing

Freecycle

Freecycle disclosed a breach affecting more than 7 million members

Hacking Nonprofit

TissuPath

TissuPath patient records leaked after breach at a third-party IT supplier

Supply Chain Attack Healthcare

Mom's Meals (PurFoods, LLC)

Mom's Meals discloses ransomware breach affecting more than 1.2 million people

Ransomware Healthcare Services

Metropolitan Police Service

Metropolitan Police supplier breach exposed details of 47,000 officers and staff

Supply Chain Attack Law Enforcement

Ohio History Connection

Ohio History Connection ransomware attack exposed data on about 7,600 people

Ransomware Nonprofit

Pôle emploi

Pole emploi says MOVEit breach at a contractor exposed data on 10 million people

Supply Chain Attack Government

Pareto Phone

Pareto Phone breach leaked Australian charity donor data to the dark web

Ransomware Telemarketing

University of Minnesota

University of Minnesota investigates claim that 7 million records were stolen

Hacking Higher Education

GEICO

GEICO tells employees their data was exposed in MOVEit-linked vendor breach

Supply Chain Attack Insurance

CloudNordic

CloudNordic and AzeroCloud lost nearly all customer data in ransomware attack

Ransomware Cloud Hosting

Energy One

Energy One takes systems offline after cyberattack on Australian and UK operations

Hacking Energy Software

auDA (.au Domain Administration)

auDA finds no evidence of breach after NoEscape claimed to hold its data

Ransomware Internet Infrastructure

Tesla, Inc.

Tesla blamed insider wrongdoing for breach affecting 75,000 employees

Malicious Insider Automotive

Swan Retail

Swan Retail cyberattack knocks around 300 UK independent retailers offline

Hacking Retail Software

Prince George's County Public Schools

Cyberattack on Prince George's County Public Schools hit 4,500 accounts

Hacking Education

The Clorox Company

Clorox took systems offline after unauthorized activity on its network

Hacking Consumer Goods Manufacturing

Colorado Department of Health Care Policy and Financing

Colorado health agency notified 4.1 million people after IBM MOVEit breach

Supply Chain Attack Government Health Agency

Freeport-McMoRan Inc.

Freeport-McMoRan disclosed a cybersecurity incident affecting its IT systems

Hacking Mining

Cumbria Constabulary

Cumbria police accidentally published names and salaries of all staff

Human Error Law Enforcement

Indiana Family and Social Services Administration

Indiana FSSA said Maximus MOVEit breach exposed 744,000 Medicaid members

Supply Chain Attack Government Health Agency

Alberta Dental Service Corporation

Ransomware at Alberta Dental Service Corporation hit 1.47 million people

Ransomware Health Benefits Administration

Rapattoni Corporation

Rapattoni cyberattack froze MLS property listings across the US

Hacking Real Estate Technology

The Electoral Commission (United Kingdom)

UK Electoral Commission revealed hack exposing 40 million voters' details

Hacking Government Agency

Police Service of Northern Ireland

PSNI accidentally published details of about 10,000 officers and staff

Human Error Law Enforcement

Colorado Department of Higher Education

Colorado Department of Higher Education breach exposed 16 years of records

Ransomware State Government

Prospect Medical Holdings

Prospect Medical Holdings cyberattack shut hospital services in four states

Ransomware Healthcare

Aristocrat Leisure Limited

Aristocrat Leisure confirmed employee data stolen through MOVEit flaw

Hacking Gaming Technology

Oregon Health Plan

MOVEit breach at PH Tech exposed 1.7 million Oregon Health Plan members

Supply Chain Attack Health Insurance

Hot Topic

Hot Topic disclosed credential stuffing attacks on Rewards accounts

Credential Compromise Retail

Health Employers Association of British Columbia

Cyberattack on B.C. health recruitment sites exposed up to 240,000 records

Hacking Healthcare

The Prudential Insurance Company of America

Prudential said MOVEit hack at vendor PBI exposed 320,840 people

Supply Chain Attack Insurance

Tempur Sealy International

Tempur Sealy shut down IT systems after July 2023 cyberattack

Hacking Manufacturing

Southern Association of Independent Schools (SAIS)

Unsecured SAIS database exposed 682,000 school records

Misconfiguration Education

Allegheny County, Pennsylvania

Allegheny County MOVEit breach exposed data on more than 950,000 people

Hacking Local Government

Maximus Inc.

Maximus says MOVEit hack exposed data on up to 11 million people

Supply Chain Attack Government Services

National Disability Insurance Agency

Australia's disability agency assessed exposure from the HWL Ebsworth hack

Third-Party Data Breach Government Agency

Rite Aid

Rite Aid says vendor software flaw exposed data on 24,400 customers

Supply Chain Attack Retail Pharmacy

Pacific Premier Bancorp

Pacific Premier Bancorp customer data stolen in vendor's MOVEit breach

Supply Chain Attack Financial Services

CardioComm Solutions

CardioComm Solutions took systems offline after cyberattack

Hacking Medical Technology

Yamaha Canada Music

Yamaha Canada Music confirmed attack claimed by two ransomware gangs

Ransomware Musical Instruments

1st Source Corporation

1st Source Bank reports about 450,000 records exposed in MOVEit hack

Supply Chain Attack Financial Services

TSG Interactive US Services Limited (PokerStars)

PokerStars US notifies 110,291 people of MOVEit related data theft

Supply Chain Attack Online Gaming

George County, Mississippi

Ransomware encrypts all three servers at George County, Mississippi

Ransomware Local Government

Tampa General Hospital

Tampa General Hospital says data on 1.2 million patients was stolen

Ransomware Healthcare

The Estee Lauder Companies

Estee Lauder confirmed data theft as Clop and BlackCat both claimed attacks

Ransomware Consumer Goods

TOMRA Systems ASA

TOMRA isolates systems after extensive cyberattack on Norwegian group

Hacking Industrial Technology

Charter Oak Federal Credit Union

Charter Oak Federal Credit Union pulls online banking offline after attack

Hacking Financial Services

Hillsborough County, Florida

Hillsborough County notified more than 70,000 people after MOVEit breach

Supply Chain Attack Local Government

Sun Life Financial

Sun Life US members exposed in MOVEit breach at vendor PBI

Third-Party Data Breach Insurance

Choice Hotels International

Choice Hotels confirmed Radisson guest records taken in MOVEit attacks

Supply Chain Attack Hospitality

Razer

Razer investigated claims that Razer Gold data and source code were stolen

Hacking Consumer Electronics

HCA Healthcare

HCA Healthcare breach exposed data on about 11 million patients

Hacking Healthcare

Ventia

Ventia took key systems offline after weekend cyberattack

Hacking Infrastructure Services

AutoZone

AutoZone notified 184,995 people of a MOVEit-related data breach

Hacking Automotive Parts Retail

University of the West of Scotland

University of the West of Scotland data auctioned by Rhysida ransomware gang

Ransomware Higher Education

Deutsche Bank

Deutsche Bank customer data exposed in service provider's MOVEit breach

Third-Party Data Breach Banking

National Institutes of Health Federal Credit Union (NIHFCU)

NIH Federal Credit Union notified 14,706 members after an email account breach

Credential Compromise Financial Services

ZooTampa at Lowry Park

ZooTampa disclosed cyberattack claimed by BlackSuit ransomware group

Ransomware Leisure and Attractions

Port of Nagoya

Ransomware halted container operations at Japan's Port of Nagoya

Ransomware Ports and Logistics

daa (Dublin Airport Authority)

About 2,000 Dublin Airport staff had pay data taken in the Aon MOVEit breach

Third-Party Data Breach Aviation

Imagine360, LLC

Imagine360 notifies over 112,000 after two file transfer breaches

Hacking Healthcare

Barts Health NHS Trust

BlackCat claimed a seven terabyte data theft from Barts Health NHS Trust

Ransomware Healthcare

U.S. Department of Health and Human Services (HHS)

HHS told Congress a MOVEit breach at contractors affected more than 100,000 people

Third-Party Data Breach Federal Government

Advanced Medical Management, LLC

Advanced Medical Management breach exposed data on 319,485 people

Hacking Healthcare

Taiwan Semiconductor Manufacturing Company (TSMC)

TSMC faced a $70 million LockBit ransom after supplier Kinmax was breached

Third-Party Data Breach Semiconductor Manufacturing

Dozor-Teleport CJSC

Russian satellite operator Dozor-Teleport knocked offline in June 2023 hack

Hacking Telecommunications

U.S. Patent and Trademark Office (USPTO)

USPTO exposed about 61,000 trademark applicants' home addresses for three years

Misconfiguration Federal Government

Law Foundation of Silicon Valley

Ransomware at the Law Foundation of Silicon Valley exposed data on 42,525 people

Ransomware Legal Services

Suncor Energy

Suncor Energy cyberattack disrupted payments at Petro-Canada stations

Hacking Oil and Gas

Pilot Credentials

Pilot Credentials breach exposed data on American and Southwest pilot applicants

Hacking Recruitment Technology

California Public Employees' Retirement System (CalPERS)

CalPERS said 769,000 retirees were exposed by a vendor's MOVEit breach

Third-Party Data Breach Public Pension Fund

Gen Digital

Gen Digital said employee data was exposed in the MOVEit breach

Supply Chain Attack Consumer Software

Reddit

BlackCat threatened to leak 80GB of Reddit data taken in a February breach

Phishing Social Media

Smartpay Holdings

Smartpay confirmed customer data was stolen in a ransomware attack

Ransomware Payments

U.S. Department of Agriculture

USDA said fewer than 30 employees may have been hit by a vendor's MOVEit breach

Third-Party Data Breach Federal Government

Louisiana Office of Motor Vehicles

Louisiana warned all driver's license and ID holders were exposed in MOVEit breach

Hacking State Government

Development Bank of Southern Africa

Development Bank of Southern Africa disclosed an Akira ransomware attack

Ransomware Banking

Comisión Nacional de Valores (CNV), Argentina

Medusa ransomware group attacked Argentina's National Securities Commission

Ransomware Financial Regulator

Intellihartx

Intellihartx told about 490,000 people data was taken in GoAnywhere hack

Hacking Healthcare Services

Ofcom

Ofcom said MOVEit hack took data on 412 staff and companies it regulates

Hacking Government Regulator

FIIG Securities

ALPHV claimed theft of 385GB from Australian bond broker FIIG Securities

Ransomware Financial Services

Jamaica Ministry of National Security

Jamaica's Ministry of National Security confirmed cyberattack on JamaicaEye website

Hacking Government

Government of Nova Scotia

Nova Scotia government detailed scope of MOVEit data theft affecting about 100,000

Hacking Regional Government

UK National Health Service (NHS)

NHS research data on 1.1 million patients accessed in University of Manchester hack

Third-Party Data Breach Healthcare

Infotel JSC

Ukrainian hacktivists took Russian bank connectivity provider Infotel JSC offline

Hacking Telecommunications

Mahony Horner Lawyers

Mahony Horner Lawyers warned clients of leak after IT provider was hacked

Third-Party Data Breach Legal Services

Pflegia

German healthcare recruiter Pflegia exposed job seeker files in open AWS bucket

Misconfiguration Recruitment

Ascension Seton

Ascension Seton disclosed breach of two legacy websites run by vendor Vertex

Third-Party Data Breach Healthcare

Zellis

MOVEit zero-day at payroll provider Zellis exposed staff data at BA, BBC and Boots

Supply Chain Attack Payroll Services

Hillsborough County Supervisor of Elections

Hillsborough County elections office breach exposed data on 58,000 Florida voters

Hacking Local Government

iSpace, Inc.

iSpace notified consumers of a breach exposing Social Security and health data

Hacking Business Services

Casepoint

BlackCat claimed a breach of legal platform Casepoint used by US agencies

Ransomware Legal Technology

SimpleTire

SimpleTire left 2.8 million customer records in an open database

Misconfiguration Retail

Idaho Falls Community Hospital

Cyberattack forced Idaho Falls Community Hospital to divert ambulances

Hacking Healthcare

Ejercito de Chile (Chilean Army)

Rhysida ransomware group published documents stolen from the Chilean Army

Ransomware Military

Onix Group

Onix Group ransomware attack exposed data on about 320,000 patients and employees

Ransomware Real Estate and Healthcare Services

MCNA Dental

MCNA Dental breach affected 8.9 million people after LockBit attack

Ransomware Health Insurance

Xplain

Play ransomware attack on Swiss supplier Xplain reached federal government data

Ransomware IT Services

Insurance Information Bureau of India

Insurance Information Bureau of India hit by ransomware, refused $250,000 demand

Ransomware Insurance

City of Augusta, Georgia

BlackByte ransomware gang claimed attack on the City of Augusta, Georgia

Ransomware Municipal Government

Apria Healthcare

Apria Healthcare disclosed 2019 and 2021 breaches affecting 1.87 million people

Hacking Healthcare

Suzuki Motorcycle India

Cyberattack halted production at Suzuki Motorcycle India for about a week

Hacking Manufacturing

Uintah Basin Healthcare

Uintah Basin Healthcare breach affected 103,974 patients in rural Utah

Hacking Healthcare

Bank Syariah Indonesia

LockBit published 1.5TB of data stolen from Bank Syariah Indonesia

Ransomware Banking

Fresh Del Monte Produce

Fresh Del Monte Produce notified employees after network intrusion

Hacking Agriculture

Collectivité Territoriale de Martinique

Rhysida claimed the ransomware attack on Martinique's territorial government

Ransomware Regional Government

ScanSource

ScanSource confirmed ransomware attack behind multi-day outages

Ransomware Technology Distribution

Credit Control Corporation

Credit Control Corporation disclosed March 2023 breach affecting hundreds of thousands

Hacking Debt Collection

airBaltic

airBaltic sent booking details to the wrong passengers after email system error

Human Error Aviation

Lacroix

Lacroix shut three electronics plants for a week after ransomware attack

Ransomware Electronics Manufacturing

Toyota Motor Corporation

Toyota cloud misconfiguration exposed vehicle data for 2.15 million customers

Misconfiguration Automotive

Ambulance Victoria

Ambulance Victoria exposed paramedic drug and alcohol test results on staff intranet

Human Error Emergency Services

U.S. Department of Transportation

US Department of Transportation breach exposed data on 237,000 federal employees

Hacking Government

Illinois Department of Healthcare and Family Services

Illinois benefits portal breach exposed Medicaid, SNAP and TANF recipient data

Credential Compromise Government

ABB

Black Basta ransomware hits Swiss automation giant ABB

Ransomware Industrial Technology

Murfreesboro Medical Clinic & SurgiCenter

Murfreesboro Medical Clinic shut down for two weeks after a ransomware attack

Ransomware Healthcare

TechnologyOne

TechnologyOne halts ASX trading after back-office systems breached

Hacking Software

National Gallery of Canada

National Gallery of Canada recovers from ransomware attack

Ransomware Arts and Culture

NextGen Healthcare

NextGen Healthcare breach exposed data on more than one million patients

Credential Compromise Health IT

Crown Princess Mary Cancer Centre

Medusa ransomware group claims data from Sydney's Crown Princess Mary Cancer Centre

Ransomware Healthcare

Constellation Software

ALPHV claims ransomware attack on Constellation Software

Ransomware Software

La Malle Postale

La Malle Postale left data on about 90,000 hiking clients publicly exposed

Misconfiguration Transportation

City of Dallas, Texas

Royal ransomware disrupted City of Dallas police, court and dispatch systems

Ransomware Municipal Government

Sysco Corporation

Sysco discloses breach affecting customer, supplier and employee data

Hacking Food Distribution

AvidXchange

AvidXchange hit by RansomHouse in its second ransomware incident of 2023

Ransomware Financial Technology

HWL Ebsworth

ALPHV ransomware group claims 4TB of data from Australian law firm HWL Ebsworth

Ransomware Legal Services

UnitedHealthcare

UnitedHealthcare notified members after credential stuffing attack on its mobile app

Credential Compromise Health Insurance

Americold Realty Trust

Americold network breach shut down cold storage operations

Ransomware Cold Storage and Logistics

National Small-bore Rifle Association

Cyber attack on the UK National Small-bore Rifle Association exposes member data

Hacking Sports and Recreation

Amnesty International Australia

Amnesty International Australia disclosed a December 2022 hack four months later

Hacking Non-Profit

Diocese of Las Vegas

Diocese of Las Vegas disclosed a data breach affecting parishioners and donors

Hacking Religious Organization

Hardenhuish School

Hardenhuish School in Wiltshire disrupted by a ransomware attack

Ransomware Education

Bitmarck

Bitmarck took systems offline across German health insurers after a cyberattack

Hacking Healthcare IT

EdisonLearning

Royal ransomware gang claimed 20GB of data stolen from EdisonLearning

Ransomware Education Services

CIC Group, Inc.

CIC Group notified 4,500 people after a breach exposed Social Security numbers

Hacking Engineering and Construction

Yellow Pages Group

Yellow Pages Canada confirmed Black Basta attack after data leak

Ransomware Digital Media and Directories

American Bar Association

American Bar Association breach exposed credentials of 1.4 million members

Hacking Professional Association

Fincantieri Marine Group

Ransomware attack halted work at Fincantieri Marine Group's Wisconsin shipyard

Ransomware Shipbuilding

Consumer Financial Protection Bureau

Former CFPB employee sent data on 256,000 consumers to a personal email

Malicious Insider Government Agency

Point32Health

Point32Health ransomware attack disrupted Harvard Pilgrim member services

Ransomware Health Insurance

Evide

Ransomware at Derry data firm Evide hit charities serving abuse survivors

Ransomware Information Technology Services

Gateway Casinos & Entertainment

Gateway Casinos ransomware attack closed 14 Ontario properties

Ransomware Gaming and Hospitality

CommScope

Vice Society leaked CommScope employee data after March ransomware attack

Ransomware Network Infrastructure Manufacturing

NCR Corporation

BlackCat ransomware knocked out NCR's Aloha point-of-sale platform

Ransomware Payment Technology

Dimas Volvo

Brazilian Volvo dealer Dimas Volvo leaked database credentials for a year

Misconfiguration Automotive Retail

Coles Group

Coles customer credit card data caught up in Latitude Financial breach

Third-Party Data Breach Retail

Rheinmetall

Rheinmetall cyberattack hit civilian division, defence business unaffected

Ransomware Defence and Automotive Manufacturing

NorthOne

Unsecured database exposed over a million NorthOne-branded invoices

Misconfiguration Financial Technology

Enzo Biochem

Enzo Biochem said ransomware attack exposed test data on 2.47 million people

Ransomware Biotechnology

Kodi

Kodi disclosed forum breach affecting about 400,000 users

Credential Compromise Software

Lürssen

Lürssen hit by ransomware attack over the Easter weekend

Ransomware Shipbuilding

Webster Bank

Webster Bank customer data exposed in Guardian Analytics vendor breach

Third-Party Data Breach Banking

SD Worx

SD Worx shut down UK and Ireland payroll systems after cyberattack

Hacking Payroll and HR Services

Groupe Nordik

Groupe Nordik breach exposed gift certificate buyers' card data

Hacking Hospitality

Micro-Star International (MSI)

Money Message ransomware gang claimed 1.5TB theft from MSI

Ransomware Computer Hardware

Pacific Union College

Pacific Union College discloses ransomware breach affecting 56,041 people

Ransomware Higher Education

Camden County Police Department

Camden County Police Department locked out of case files by ransomware

Ransomware Law Enforcement

Municipality of Herselt

Cyberattack shut municipal services in Herselt, Belgium

Supply Chain Attack Local Government

ACRO Criminal Records Office

UK's ACRO Criminal Records Office pulled portal offline after cyber incident

Hacking Government

Proskauer Rose

Proskauer Rose left confidential client M&A files exposed on an unsecured cloud server

Misconfiguration Legal Services

OCR Labs

OCR Labs exposed credentials tied to banking clients in misconfigured file

Misconfiguration Identity Verification

Royal Dutch Football Association (KNVB)

Royal Dutch Football Association says hackers stole employee data

Ransomware Sports

Capita plc

Capita cyberattack disrupted Microsoft 365 access and exposed client data

Ransomware Business Services

Western Digital

Western Digital network breach takes My Cloud services offline

Hacking Computer Hardware

TMX Finance

TMX Finance discloses breach affecting 4.8 million TitleMax and InstaLoan customers

Hacking Consumer Lending

Meriton

Meriton breach exposes staff financial records and guest incident reports

Hacking Hospitality and Property

PharMerica

PharMerica breach exposed data of 5.8 million patients

Ransomware Healthcare

Lumen Technologies

Lumen Technologies discloses two separate cyberattacks in SEC filing

Ransomware Telecommunications

Crown Resorts

Crown Resorts confirms Clop extortion attempt after GoAnywhere zero-day

Supply Chain Attack Casinos and Entertainment

Twitter

Twitter source code leaked on GitHub, company subpoenas for leaker's identity

Malicious Insider Social Media

NCB Management Services

NCB Management breach grows past 1.5 million, starting with Bank of America customers

Hacking Debt Collection

Walsall Healthcare NHS Trust

Walsall Healthcare NHS Trust contains cyberattack on its network

Hacking Healthcare

City of Toronto

City of Toronto confirms data theft through GoAnywhere file transfer vendor

Supply Chain Attack Municipal Government

Alliance Healthcare Espana

Cyberattack on Alliance Healthcare Espana disrupts Spanish medicine distribution

Hacking Pharmaceutical Distribution

City of Oak Ridge, Tennessee

Malware attack disrupts services in the City of Oak Ridge, Tennessee

Hacking Municipal Government

US Wellness Inc.

US Wellness vendor breach exposed Blue Cross Blue Shield of Arizona members

Supply Chain Attack Healthcare Services

QIMR Berghofer Medical Research Institute

QIMR Berghofer skin cancer study data exposed in Datatime breach

Third-Party Data Breach Medical Research

Puerto Rico Aqueduct and Sewer Authority (PRASA)

Vice Society claims cyberattack on Puerto Rico water utility PRASA

Ransomware Water Utility

National Basketball Association

NBA notifies fans after breach at third-party email provider

Third-Party Data Breach Sports

Hitachi Energy

Hitachi Energy confirms employee data breach in Clop GoAnywhere campaign

Supply Chain Attack Energy Technology

Docomo Pacific

Docomo Pacific cyberattack knocks out internet and phone services in Guam and the CNMI

Hacking Telecommunications

Latitude Financial

Latitude Financial says stolen staff login led to theft of 328,000 records

Credential Compromise Financial Services

GSC Game World

GSC Game World breached, hackers threaten to leak STALKER 2 material

Hacking Video Game Development

Lansing Community College

Lansing Community College breach exposed data on 757,832 people

Hacking Higher Education

Essendant

LockBit claims ransomware attack behind Essendant's multi-week outage

Ransomware Wholesale Distribution

NorthStar Emergency Medical Services

NorthStar EMS notifies about 82,000 patients of 2022 network intrusion

Hacking Emergency Medical Services

CHU Saint-Pierre

Cyberattack diverts ambulances from Brussels hospital CHU Saint-Pierre

Hacking Healthcare

Postal Prescription Service (Healthy Options Inc., Kroger)

Kroger's Postal Prescription Service exposed 82,466 customers' details

Human Error Pharmacy

AT&T

AT&T notifies about 9 million customers after marketing vendor breach

Third-Party Data Breach Telecommunications

DC Health Link

DC Health Link breach exposes data on 56,000 people including members of Congress

Misconfiguration Health Insurance

Black & McDonald

Ransomware hits Black & McDonald, contractor to Canada's military

Ransomware Engineering and Construction

Acer

Acer confirms breach of repair technician document server

Hacking Technology Manufacturing

SundaySky Inc.

SundaySky notifies 37,095 people after files copied from its cloud servers

Hacking Marketing Technology

Cerebral

Cerebral tells 3.1 million people tracking pixels leaked their health data

Human Error Telehealth

Royal Dirkzwager

Play ransomware group hits Dutch maritime firm Royal Dirkzwager

Ransomware Maritime Logistics

Hospital Clínic de Barcelona

RansomHouse attack forces Hospital Clínic de Barcelona to cancel surgeries

Ransomware Healthcare

Denver Public Schools

Denver Public Schools breach exposed employee Social Security numbers

Hacking Education

WH Smith PLC

WH Smith said attackers stole current and former employee data

Hacking Retail

Chick-fil-A

Chick-fil-A confirmed 71,473 accounts hit by credential stuffing

Credential Compromise Restaurants

Minneapolis Public Schools

Medusa ransomware gang leaked Minneapolis Public Schools student records

Ransomware Education

Group 1001 Insurance Holdings

Group 1001 insurance units restored operations after February ransomware attack

Ransomware Insurance

DISH Network Corporation

DISH Network confirms ransomware attack behind multi-day outage

Ransomware Telecommunications

U.S. Marshals Service

U.S. Marshals Service ransomware attack hit a sensitive investigative system

Ransomware Federal Government

Southeastern Louisiana University

Southeastern Louisiana University took its network offline after cyberattack

Hacking Higher Education

Reventics, LLC

Reventics breach exposed data on more than 250,000 patients

Ransomware Healthcare Services

Cornell University

Cornell ticket buyers hit by AudienceView Campus platform breach

Supply Chain Attack Higher Education

The Good Guys

The Good Guys told 1.85 million loyalty members of a supplier breach

Third-Party Data Breach Retail

Dole plc

Dole shut down North American operations after ransomware attack

Ransomware Agribusiness

U.S. Department of Defense

U.S. Department of Defense notified 20,600 people of 2023 email exposure

Misconfiguration Federal Government

Tusla, Ireland's Child and Family Agency

Tusla began notifying 20,000 people whose data was stolen in the 2021 HSE attack

Third-Party Data Breach Government

Lehigh Valley Health Network

Lehigh Valley Health Network refused ransom after BlackCat attack on physician practice

Ransomware Healthcare

Stanford University

Stanford University exposed files of 897 economics PhD applicants

Misconfiguration Higher Education

U.S. Federal Bureau of Investigation

FBI confirmed a cyber incident on its own network at the New York field office

Hacking Federal Government

City of Hilliard, Ohio

City of Hilliard, Ohio lost $219,000 to a vendor impersonation scam

Business Email Compromise Municipal Government

RailYatri

RailYatri data on more than 31 million users posted to a hacking forum

Hacking Travel Technology

Burton Snowboards

Burton Snowboards halted online orders after a February 2023 cyber incident

Hacking Sporting Goods

Liverpool University Hospitals NHS Foundation Trust

Liverpool University Hospitals NHS trust leaked payroll data of 14,000 staff

Human Error Healthcare

City of Oakland, California

Oakland declared a local emergency after ransomware took city systems offline

Ransomware Local Government

Pepsi Bottling Ventures LLC

Pepsi Bottling Ventures breach hit more than 28,000 employees and contractors

Hacking Food and Beverage

Indigo Books & Music Inc.

Indigo Books & Music shut down its website after a cyberattack

Ransomware Retail

Weee!

Weee! confirmed a breach after order data for 1.1 million customers leaked

Hacking Retail

Aguas e Energia do Porto

LockBit claimed a ransomware attack on Porto's municipal water utility

Ransomware Utilities

MKS Instruments, Inc.

Ransomware at MKS Instruments halted production at some facilities

Ransomware Manufacturing

Vesuvius plc

Vesuvius plc shut down systems after cyber incident at steel industry supplier

Ransomware Manufacturing

Munster Technological University

Munster Technological University closed Cork campuses after ransomware attack

Ransomware Higher Education

PeopleConnect, the parent company of TruthFinder and Instant Checkmate

TruthFinder and Instant Checkmate Suffer Data Breach: 20 Million Customers Affected

Hacking Background Checking Services

988 Suicide and Crisis Lifeline

Cyberattack on vendor Intrado knocked out 988 Lifeline calls for nearly a day

Supply Chain Attack Public Health

Sharp HealthCare

Sharp HealthCare notified about 63,000 patients after a web server breach

Hacking Healthcare

Atlantic General Hospital (Maryland)

Maryland’s Atlantic General Hospital hit by Ransomware: Patient Care Impacted

Ransomware Healthcare

ION Group

LockBit ransomware attack on ION Group disrupted global derivatives trading

Ransomware Financial Software

Planet Ice

Planet Ice breach exposed data on more than 240,000 UK skating customers

Hacking Leisure and Entertainment

Charter Communications

Telecom Giant Charter Communications Discloses Vendor Security Breach: Customer Data Exposed

Supply Chain Attack Telecommunications

JD Sports Fashion plc

JD Sports data breach hit around 10 million UK customers

Hacking Retail

Exco Technologies

Cyber Attack Cripples Exco Technologies: Three Production Facilities Still Recovering

Hacking Manufacturer of diecast auto parts and tools

Running Room

Running Room Canada Data Breach - Customer Data Compromised

Hacking Sporting goods retail

Zacks Investment Research

Zacks Investment Research Confirms Data Breach Affecting 280,000 Customers

Hacking Investment Research and Analysis

Solar Industries India Limited

BlackCat claimed a 2TB theft from Indian defence manufacturer Solar Industries

Ransomware Defence Manufacturing

GoTo (formerly LogMeIn)

GoTo (formerly LogMeIn) Suffers Data Breach

Credential Compromise Enterprise software

Five Guys Enterprises, LLC

Five Guys Data Breach: Job Applicant Information Compromised

Ransomware Food Service

SAIF Corporation

SAIF Data Breach: Oregon's Leading Workers' Compensation Provider Experiences Security Incident

Hacking Oregon Workers' Compensation Insurance and Benefits

Cott Systems

400 Local Governments Forced to Resort to Manual Processes as a Result of Cott Systems Cyber Attack

Hacking Government Records Management

Toronto Hospital for Sick Children (SickKids Hospital)

Toronto’s SickKids Hospital Confirms Ransomware Attack

Ransomware Healthcare

Superior Plus

Superior Plus Discloses Ransomware Attack Over The Weekend

Ransomware Distribution, Propane

Desjardins

Desjardins Class Action Lawsuit Over 2019 Breach Settles For $200M

Malicious Insider Financial Services

DNA Diagnostics Center (DDC)

DNA Testing Centre Admits To Data Breach Affecting Over 2 Million People

Credential Compromise Healthcare Services

MonoX

Hackers Victimize MonoX Leaving Losses Up To $30M in Digital Tokens

Hacking Fintech, Cryptocurrency

Gale Healthcare Solutions

30K Healthcare Workers’ Info Found On Unprotected Database

Misconfiguration Healthcare, Staffing Services

Lake County Board of Commissioners

FBI Investigating Attempted Data Breach During Election Fraud

Malicious Insider Government, Local Services

Butler County Community College

Classes Cancelled As School Recovers From Ransomware Attack

Ransomware Education

Supernus Pharmaceuticals

Ransomware Gang Threatens to Leak 1.5TB of Data

Ransomware Pharmaceutical

The Virginia Division of Legislative Automated Systems (DLAS)

Virginia’s Government IT Agency Hit By Ransomware

Ransomware Government, Technology Services

Cox Communications

Fraudster Impersonates Support Agent In Cox Vishing Attack

Phishing Media, Digital Cable Provider

Atalanta

Food Importer Admits Data Breach After Previous Ransomware Attack

Ransomware Food & Beverage, Distributor/Importer

Governor General of Canada

Governor General of Canada Detects Internal Network Breach

Hacking Federal Government

Social Enterprise for Canada (SEC)

Ontario Non-Profit Warning Clients After Ransomware Attack

Ransomware Non-Profit, Family Services

Kronos, Ultimate Group

Ransomware Attack Could Affect Customer Payroll Services For Weeks

Ransomware Technology, Payroll Services

Planned Parenthood

400,000 Patients’ Information Compromised In Ransomware Attack

Ransomware Healthcare, Non-Profit

GoDaddy

Over 1 Million Users Affected In GoDaddy Data Breach

Credential Compromise Technology, Web Hosting

Toronto Transit Commission (TTC)

Toronto Transit System Hit By Ransomware Attack

Ransomware Government Agency, Transportation

Schreiber Foods

Ransomware Shuts Down Production Distribution For Schreiber Foods

Ransomware Agriculture, Manufacturer

PracticeMax

Patient Data Exposed In 3rd Party Healthcare Ransomware Attack

Ransomware Healthcare Services, Technology

National Rifle Association (NRA)

Threat Actors Demand Ransom from NRA After Leaking Files On Dark Web

Ransomware Advocacy Group

CoinMarketCap

3.1 Million Users’ Email Addresses Leaked In Data Breach

Hacking Technology, Financial

Ferrara Candy Company

Candy Maker Hit By Ransomware During Halloween Rush

Ransomware Food and Beverage, Manufacturer

Sinclair Broadcast Group

Ransomware Knocks Programs Offline for Nationwide Broadcast Group

Ransomware Media

Hewlett Packard Enterprise (HPE)

Stolen Access Key Used to Breach HPE’s Aruba Central

Credential Compromise Technology, Manufacturing

Robinhood

7 Million Users Affected In Robinhood Data Breach

Phishing Fintech

West Virginia Parkways Authority

Cyberattack on Government Agency Disrupts Computer Systems

Ransomware Government Agency, Transportation

Federal Bureau of Investigation (FBI)

FBI Email System Compromised In Cyberattack

Business Email Compromise Federal Government, Agency

Newfoundland and Labrador Health

Experts Deem N.L. Cyberattack as Canada’s Worst Ever

Ransomware Government, Healthcare

Electronic Warfare Associates

US Defense Contractor Reveals Employee Phishing Attack

Phishing Government, Defense Contractor

Diamond Comic Distributors

Major Comic Book Distributor Hit By Ransomware

Ransomware Distributor, Publications & Entertainment

Rideau Valley Health Centre

Ransomware Attack On Ottawa Clinic Disrupts Patient Care

Ransomware Healthcare, Medical Clinic

IKEA

IKEA Hit By Ongoing, Highly Sophisticated Reply-Chain Attack

Phishing Retail

Ronmor Holdings

Calgary Real Estate Developer Hit By Ransomware Attack

Ransomware Real Estate

California Pizza Kitchen

Over 100,000 Employees Affected By California Pizza Kitchen Data Breach

Hacking Food & Beverage, Restaurant

Defence Construction Canada

Defence Construction Canada Recovering After Cyber Attack On IT Systems

Hacking Construction, Federal Government

Turner Construction Co.

5,600 Construction Employees Potentially Impacted By Phishing Scam

Phishing Construction

Clark Builders

Edmonton Construction Company Warns Industry After $11.8M Phishing Scam

Phishing Construction

Professional Excavators and Construction

Over $100k In Ransomware Recovery Costs for Calgary Construction

Ransomware Construction

Kemptville District Hospital

Ontario Hospital Resumes Emergency Services After ‘Cyber Incident’

Hacking Healthcare, Medical

University of Colorado

30,000 University Students Potentially Impacted By 3rd Party Data Breach

Hacking Education

Olympus Corporation of the Americas

Global Medical Manufacturer’s IT Systems Down After 2nd Consecutive Ransomware Attack

Ransomware Manufacturer, Medical Technology

Durham Regional Government

Hackers Leak More Troubling Data for Local Ontario Government

Ransomware Government, Municipal

Sandhills Global

Systems And Operations Shut Down For Digital Publisher After Ransomware

Ransomware Technology, Digital Publishing

Twitch

Twitch Suffers Massive Source Code Data Breach

Misconfiguration Technology, Streaming Platform

Premier Patient Healthcare

Terminated Executive Turns Insider Threat After 37,000 Patients’ Data Compromised

Malicious Insider Healthcare

Oregon Eye Specialists

Independent Optometry Chain Hit By Employee Email Breach

Credential Compromise Healthcare, Optometry

Unity Health Toronto

Toronto Hospital Network Investigating After Malicious Insider Threatens Data Exposure

Third-Party Data Breach Healthcare

Next Level Apparel

Several Employee Email Accounts Compromised in Phishing Attack

Phishing Manufacturer, Clothing

Coinbase

Hackers Steal Cryptocurrency from 6,000 Coinbase Users

Hacking Technology, Financial App

Neiman Marcus

4.9 Million Affected by Retail Giant Neiman Marcus Data Breach

Hacking Retail

Navistar

Employees Seek Class Action Lawsuit After Info Stolen In Data Breach

Hacking Manufacturing, Automobile

MoneyLion

Fintech Customer Accounts Locked After Credential Stuffing Attack

Credential Compromise Financial, Fintech

Marcus & Millichap

Ransomware Group Targets Commercial Real Estate Firm

Ransomware Real Estate

Marketron

Thousands of Customers Impacted By Marketron Ransomware Attack

Ransomware Technology, Marketing Services

Portpass

Privacy Breach Could Affect 650K Canadians Using COVID-19 Passport App

Misconfiguration Technology, Vaccine Passport Platform

Epik

Hacktivist Group Anonymous Leaks 180GB of Far-Right Data

Hacking Technology, Web Hosting

New Cooperative And Crystal Valley Cooperative

Twin Ransomware Attacks Halt Business For Agriculture Industry

Ransomware Manufacturing, Agriculture

Simon Eye And US Vision

Hackers Victimize Healthcare Providers in Dual Hacking Breaches

Hacking Healthcare, Optometry

Dotty’s

F&B Customer’s Data Exposed In Ransomware Attack

Ransomware Food and Beverage, Gaming

TTEC

TTEC Ransomware Attack Encrypts Data Disrupting Business Operations

Ransomware Technology, Customer Service Provider

Walgreen’s

Millions Possible Affected By Walgreen’s Website Error

Misconfiguration Retail, Pharmacy

United Nations

Hackers Infiltrate United Nations IT Networks

Hacking Intergovernmental Organization

Texas Right To Life

Hundreds of Job Applicants’ Data Exposed on Misconfigured Website

Misconfiguration Political Rights Organization

Pacific City Bank

Ransomware Attack Hits Community Bank

Ransomware Financial

Career Group Inc.

Company Warns 49,000 Customers After Ransom Paid In Cyber Attack

Ransomware Staffing Agency

DuPage Medical Group

600,000 Patients Warned After Medical Group Discovers Data Breach

Hacking Healthcare, Medical

Austin Cancer Centers

Cyber Attack Exposes Over 36,000 Cancer Clinic Patients’ Data

Ransomware Healthcare

Canpar Express

No Explanation on Ransomware Attack Leaves Customers Complaining

Ransomware Logistics

Canada Revenue Agency

Thousands Affected By CRA Data Breach

Credential Compromise Government

Twitter

Major Bitcoin Scam Rocks Twitter

Hacking Social Media

MGM Resorts

Over 142 Million Affected in MGM Resorts Data Breach

Credential Compromise Travel, Hotel

PEI Provincial Government

$900,000 In Costs For PEI Taxpayers After Ransomware Attack (Update)

Ransomware Government

OneClass

Over 1 Million Students’ Personal Info Exposed on Unsecured Database

Misconfiguration Education

Chartered Professional Accountants of Canada (CPA)

329,000 Affected By CPA Canada Phishing Attack

Phishing Financial

Northwest Territories Power Corporation (NTPC)

NTPC Customers Facing “Financial Hardships” After Ransomware Attack

Ransomware Services, Utilities Provider

GoDaddy

Approximately 28,000 GoDaddy Users Affected by Data Breach

Hacking Technology, Web Hosting

World Health Organization

450 Active WHO Email Credentials Leaked Online

Credential Compromise Not-For-Profit, Healthcare

The Ottawa Hospital

Ottawa Police Warning New COVID-19 Hospital Phishing Scam

Phishing Healthcare

Quebec Treasury Board

360,000 Quebec Teachers Affected By Data Breach

Credential Compromise Education

PEI Government

PEI Government Investigating Ransomware Attack

Ransomware Government

Simon Fraser University

SFU Ransomware Attack Compromises Personal Info for Students, Faculty & Alumni

Ransomware Education

Southern First Nations Network of Care

Non-Profit IT Systems Paralyzed for 6 Weeks In Ransomware Attack

Ransomware Non-Profit

Public Service and Procurement Canada

Canadian Government's Internal Data Breach: 69,000 Federal Workers' Information Compromised

Human Error Government

Confederation College

Malware Disables Canadian College’s IT Systems

Hacking Education

Canadian Government, Federal Departments

144,000 Canadians’ Personal Info Mishandled by Federal Departments

Human Error Government

Rogers Communication

Rogers Communications Notified of Minor Data Leak

Misconfiguration Technology, Telecommunications

Bird Construction

Ransomware Hits Canadian Federal Contractor Bird Construction

Ransomware Construction

City of Corner Brook

City’s Privacy Breach Handed Over to Provincial Privacy Commissioner

Misconfiguration Government, Municipality

eHealth

eHealth Sask Sees Downtime Costs Escalate After Ransomware Attack

Ransomware Medical Services

PlanetDrugsDirect

Hackers Access Personal Health Info From Online Pharmacy

Hacking Online Retail, Healthcare

Plenty of Fish

Plenty of Fish Private User Info Accidental Data Leaked

Misconfiguration Technology, Dating Services App

CIBC, Scotiabank, RBC, TD Canada Trust

2 Year Phishing Campaign Targeting Major Canadian Banks Uncovered

Phishing Financial Services

Andrew Agencies

Financial Company Sees 245 Computers Encrypted with Ransomware

Ransomware Financial Services

Life Labs

15 Million Canadians Potentially Affected By Life Labs’ Massive Data Breach

Ransomware Medical Services

Shaw

Shaw Warns Customers of Potential Data Leak 6 Months Later

Lost or Stolen Device Technology & Communications

Craftsman Collision

$100s of Thousands in Ransomware Remediation For Craftsman Collision

Ransomware Service, Automobile Repair

City of Woodstock

Local Canadian Govt Accrues $667,000 in Costs After Ransomware

Ransomware Local Government

Alectra Utilities

Utilities Company Urging Customers To Be Alert After Data Breach

Misconfiguration Utilities Distributor

Waterloo Catholic District School Board

ON Catholic School Faces Rising Downtime Costs After Ransomware

Ransomware Education

Waterloo Brewing Company

$2.1 Million Lost In Phishing Attack for Waterloo Brewing

Business Email Compromise Food and Beverage, Manufacturing

Nunavut Government Services Impacted By Ransomware

Ransomware Government

Pipestone Kin-Ability Centre

Over $400K Siphoned In Not-For-Profit System Hack

Hacking Not-for-Profit, Health Services

Ontario Science Centre

3rd Party Data Breach Affects Ontario Science Centre

Third-Party Data Breach Educational Institution

TransUnion

37,000 Potentially Affected By TransUnion Data Breach

Credential Compromise Financial

PAL Airlines

Hacked Email Provides Access To Airline’s Sensitive Data

Credential Compromise Travel, Airlines

National Basketball Association Canada (NBA Canada)

NBA Canada Suffers Massive Data Breach

Misconfiguration Entertainment

Listowel Wingham Hospital Alliance

Ontario Hospital Network Faces Increasing Downtime Costs After Ransomware

Ransomware Medical, Health Services

DoorDash

Nearly 5 Million DoorDash Users Impacted After Server Hack

Hacking Food and Beverage

Scotiabank

Scotiabank's Major Security Breach: 25 Million Scotiabank Customers’ Data Left Exposed

Misconfiguration Financial

Yves Rocher

Yves Rocher Data Leak Impacts 2.5 Million Canadians

Misconfiguration Retail

Eastern Ontario Municipality

$7-$10K Ransom Request Refused by Municipal Ontario Government

Ransomware Government, Municipal

Boyd Group Income Fund

Well Prepared Boyd Group Hit By Ransomware Attack

Ransomware Service, Automobile Repair

Desjardins

Former Credit Union Employee Creates Data Breach Affecting 2.9 Million Customers

Malicious Insider Financial Services

City of Burlington

BEC Phishing Scam Tricks City into Transferring $530K

Business Email Compromise Government

Nova Scotia Health Authority

2,841 Patients Impacted by Phishing Attack

Phishing Government, Health Services

Freedom Mobile

Thousands Impacted By Freedom Mobile Server Leak

Misconfiguration Technology, Telecommunications

Mitsubishi Aerospace

Ransomware Leaves Mitsubishi Aerospace Without Internet and Network Access

Ransomware Technology

BC Pension Corporation

8,000 People Warned After BC Pension Plan Data Leak

Lost or Stolen Device Government

Precise Parklink

Small Risk, High Costs After Ransomware hits CIRA Parking Garage

Ransomware Service, Parking Garage

Norsk Hydro ASA

Norsk Hydro ransomware attack forced aluminum plants onto manual operations

Ransomware Manufacturing

Natural Health Services Ltd.

Alberta Patients Warned After Data Breach Exposes Medical Info

Hacking Healthcare, Retail

Container World

Richmond, BC Facility’s System Shutdown in Lieu of Ransom Payment

Ransomware Logistics

NWT Department of Health and Social Services

40K Canadians Potentially Impacted By Lost Gov’t Employee Laptop

Lost or Stolen Device Government, Healthcare

500px

14.8 Million Accounts Exposed In 500px Data Breach

Hacking Technology

CarePartners

CarePartners Ransomware Attack: $60K Bitcoin Demand Threatens Data Exposure

Ransomware Healthcare

Canada Revenue Agency (CRA)

Thousands of Canadians Affected As CRA Employees Caught Snooping

Malicious Insider Government Agency

Coast Capital Savings

$100’s of Thousands Stolen as Coast Capital Members Targeted In Phishing Ring

Phishing Financial