-
Word & Brown Insurance Administrators, Inc.
October 23, 2024
•
[ data leak ]
Word & Brown Insurance Administrators, Inc. experienced unauthorized access to an employee workstation on or about October 23, 2024. The attacker accessed and copied insurance administration records containing personal and health-related information for clients and employees. No encryption or operational disruption was reported. Disclosure was filed December 23, 2024.
-
Transak
October 21, 2024
A recent data breach at the crypto payment processor Transak exposes the information of more than 92,000 people after an employee's laptop was accessed.
-
Gold Coast Health Plan
October 21, 2024
•
[ data leak, third-party breach, account takeover ]
Gold Coast Health Plan reported that a contracted vendor (Conduent Business Solutions) suffered a cyberattack involving compromise of a single employee email account, which allowed unauthorized access to certain files during a window from Oct. 21, 2024 to Jan. 13, 2025. The vendor discovered the incident on Jan. 13, 2025 and began an investigation with law enforcement notification. A later forensic review determined that information for 540 plan members could have been exposed, listing specific claim-related and membership data elements; the release stated that Social Security numbers and financial information were not accessed or disclosed.
-
The Wayback Machine
October 20, 2024
The Internet Archive is breached again, this time on their Zendesk email support platform after repeated warnings that threat actors stole exposed GitLab authentication tokens.
-
Undisclosed cryptocurrency market-making firm
October 20, 2024
•
[ data exfiltration, cryptocurrency, state-sponsored attack ]
Recorded Future observed C2 reconnaissance followed by FTP exfiltration from a market-making firm in the UAE during the Contagious Interview campaign (OctNov 2024). Attributed to the NGB 3rd Technical Surveillance Bureau (North Korea).
-
Undisclosed online casino operator
October 20, 2024
•
[ Data exfiltration, State-sponsored attack, Reconnaissance ]
Recorded Future analysis identified reconnaissance and FTP exfiltration traffic from a Costa Rican online casino targeted in the Contagious Interview campaign (OctNov 2024), attributed to the NGB 3rd Technical Surveillance Bureau (North Korea).
-
Hot Topic
October 19, 2024
In October 2024, retailer Hot Topic suffered a data breach that exposed 57 million unique email addresses. The impacted data also included physical addresses, phone numbers, purchases, genders, dates of birth and partial credit data containing card type, expiry and last 4 digits.
-
Grupo Aeroportuario del Centro Norte
October 18, 2024
Grupo Aeroportuario del Centro Norte announces that a cyber incident forced its IT team to turn to backup systems. The RansomHub operation claims to be responsible for the incident, and threatens to leak 3 terabytes of stolen data.
-
Cyprus’ critical infrastructure and government websites
October 18, 2024
•
[ hack, government ]
Cyprus critical infrastructure and government websites are targeted in a series of coordinated cyberattacks claimed by several pro-Palestine hacker groups.
-
Social
October 18, 2024
•
[ financial, misconfiguration, finance ]
Tapioca DAO suffers a $4.5 million exploit after an attacker compromised its native token's vesting contract.
-
Ou Medicine (Ou Health)
October 18, 2024
•
[ phishing, data leak ]
Ou Health reported unauthorized access to two email accounts impacting patient information.
-
-
Moldova’s parliamentary email servers
October 17, 2024
Moldovas parliamentary email servers are hit by a cyberattack just ahead of the countrys presidential election and a referendum on joining the European Union.
-
Free
October 17, 2024
•
[ leak, technology ]
In October 2024, French ISP "Free" suffered a data breach which was subsequently posted for sale and later, leaked publicly. The data included 14M unique email addresses along with names, physical addresses, phone numbers, genders, dates of birth and for many records, IBAN bank account numbers. Free advised that the numbers were "not enough to make a direct debit from a bank".
-
Moldova’s parliamentary email servers
October 17, 2024
•
[ cyberattack, email security, election interference ]
Moldovas parliamentary email servers are hit by a cyberattack just ahead of the countrys presidential election and a referendum on joining the European Union.
-
DoctorsToYou
October 16, 2024
•
[ ransomware, malware, healthcare ]
The RansomHub ransomware group adds a listing for DoctorsToYou in New York to their leak site. After they realize the organization is non-profit, they claim to return the data and provide a decryptor.
-
Undisclosed organization
October 16, 2024
An undisclosed company is hacked after accidentally hiring a North Korean cyber criminal as a remote IT worker.
-
Radiant Capital
October 16, 2024
More than $50 million worth of cryptocurrency is stolen from decentralized finance platform Radiant Capital.
-
Westmoreland County
October 16, 2024
•
[ social, phishing, government ]
Municipal Authority of Westmoreland County officials say the water and sewer utility has recovered more than $826,000 that was stolen in what it called a vendor impersonator scheme.
-
Johnson & Johnson
October 16, 2024
•
[ leak, finance ]
Insurance company Johnson & Johnson discloses a data breach impacting the personal information of thousands of people.