-
Hertz Global Holdings
December 1, 2024
•
[ data leak, supply chain attack, vulnerability exploit ]
Hertz confirmed that customer personal data was stolen through exploitation of zero-day vulnerabilities in its vendor Cleo Communications managed file transfer platform between October and December 2024. The company completed analysis on April 2 2025 and disclosed the breach publicly on April 10 2025. The compromised data included names, contact information, drivers license numbers, and limited payment and identification information. No encryption or operational disruption was reported.
-
At least one undisclosed government or financial organization
December 1, 2024
•
[ malware, espionage, data theft ]
Kaspersky tracks PassiveNeuron using bespoke Neursite and NeuralExecutor implants, often gaining RCE on exposed Windows servers (e.g., via MSSQL) and then staging modular plugins for stealthy collection through compromised internal servers. Campaign-level report without a single victim suitable for event coding.
-
Port of Rijeka
November 30, 2024
•
[ ransomware, financial, leak ]
The 8Base ransomware group hits Croatias Port of Rijeka, stealing sensitive data, including contracts and accounting info.
-
Krispy Kreme
November 29, 2024
•
[ ransomware, malware, retail ]
US doughnut chain Krispy Kreme reveals it suffered a cyberattack in November that impacted portions of its business operations, including placing online orders. The Play ransomware gang claims responsibility for the attack.
-
Kurita America
November 29, 2024
•
[ ransomware, malware, manufacturing ]
The U.S. subsidiary of Kurita Water, a Japanese water treatment company says ransomware actors have stolen data from systems and encrypted some servers.
-
Bologna Football Club 1909
November 29, 2024
•
[ ransomware, leak ]
Bologna Football Club 1909 confirms it suffered a ransomware attack after its stolen data is leaked online by the RansomHub extortion group.
-
Stoli Group USA
November 29, 2024
•
[ ransomware, malware, manufacturing ]
Stoli Group's U.S. companies file for bankruptcy following an August ransomware attack and Russian authorities seizing the company's remaining distilleries in the country.
-
Alder Hey Children’s Hospital
November 28, 2024
•
[ ransomware, malware, healthcare ]
Alder Hey Childrens Hospital says it is investigating claims that its systems may have been breached and that patient records and other information was stolen, after the ransomware group INC Ransom adds Alder Hey to its leak site.
-
Bank of Uganda
November 28, 2024
Ugandan officials confirms that the countrys central bank system was hacked by financially-motivated cybercriminals, following several media reports claiming that a Southeast Asian hacker group breached the Bank of Ugandas accounts and stole as much as $17 million.
-
Cabot Financial
November 28, 2024
•
[ hack, finance ]
A cyber attack targets acquisition and credit servicing firm Cabot involving the theft of some 394,000 data files, including material related to its direct customers and its loan book.
-
Permanent Electoral Authority (AEP) of Romania
November 28, 2024
Romanias national security council warns that cyber-attacks are being used to influence the fairness of the countrys live presidential election, strongly suggesting that Russia could be behind these cyber influence attempts.
-
Liverpool Heart and Chest
November 28, 2024
The INC Ransom group begins leaking on its dark website data allegedly stolen from IT systems shared by Alder Hey Children's NHS Foundation Trust and Liverpool Heart and Chest's NHS Foundation Trust.
-
American Heart of Poland
November 28, 2024
•
[ hack, healthcare ]
American Heart of Poland receives a fine of 330,000, after suffering a hacking incident.
-
Alder Hey Children’s Hospital
November 28, 2024
•
[ ransomware, data leak, healthcare ]
Alder Hey Childrens Hospital says it is investigating claims that its systems may have been breached and that patient records and other information was stolen, after the ransomware group INC Ransom adds Alder Hey to its leak site.
-
Refinadora Costarricense de Petróleo
November 27, 2024
•
[ ransomware, malware, energy ]
Refinadora Costarricense de Petrleo (RECOPE), the state-owned energy provider for Costa Rica is hit with a ransomware attack, requiring the company to shift to manual operations and call in help from abroad.
-
City of Hoboken
November 27, 2024
•
[ ransomware, malware, government ]
The city of Hoboken shuts down its government offices after an early morning ransomware attack caused widespread issues.
-
Fourlis Group (IKEA franchise operator)
November 27, 2024
•
[ ransomware, data leak ]
A ransomware attack on November 27 2024 disrupted Fourlis Groups IT infrastructure supporting IKEA operations in Greece and other regional markets. The company reported that forensic investigators did not prove the leakage of personal data, confirming no verified exfiltration. The attack caused significant operational disruption, with reported recovery costs of approximately 20 million ( US $23 million) but no ransom payment.
-
Refinadora Costarricense de Petróleo
November 27, 2024
•
[ ransomware, energy, critical infrastructure ]
Refinadora Costarricense de Petrleo (RECOPE), the state-owned energy provider for Costa Rica is hit with a ransomware attack, requiring the company to shift to manual operations and call in help from abroad.
-
Douglasville-Douglas County Water & Sewer Authority
November 26, 2024
•
[ ransomware, data leak ]
The DouglasvilleDouglas County Water & Sewer Authority was targeted by the Lynx ransomware group on November 26 2024. Attackers claimed responsibility on a leak site on January 14 2025, later removed. The authority rebuilt and restored its systems with minimal data loss and reported no evidence of customer or employee data theft. Data exfiltration remains unconfirmed.
-
University Diagnostic Medical Imaging (UDMI)
November 26, 2024
•
[ data leak ]
On November 26 2024, University Diagnostic Medical Imaging in New York detected unauthorized access to its systems that exposed patient information including names, addresses, dates of birth, referring physicians, and treatment data. The breach affected 138,080 individuals and was disclosed publicly in February 2025.