-
Undisclosed nuclear-related organization
October 1, 2024
•
[ espionage, malware, energy ]
Researchers at Kaspersky reveal that the Lazarus Group, the threat actor linked to the Democratic People's Republic of Korea (DPRK), has been observed leveraging a "complex infection chain" targeting at least two employees belonging to an unnamed nuclear-related organization. The attacks, part of Operation Dream Job, culminated in the deployment of a new modular backdoor referred to as CookiePlus,
-
Switch
October 1, 2024
•
[ leak, misconfiguration, technology ]
In October 2024, the Hungarian IT headhunting service Switch inadvertently exposed thousands of customer records via a public GitHub repository. The exposed data contained job applications with names, email addresses and in some cases, commentary on the applicant.
-
Tecta America Corporation
October 1, 2024
•
[ hack ]
Tecta America discovered suspicious network activity around October 1, 2024. Investigation revealed that between September 20October 2, an unauthorized actor accessed or acquired files. Impacted data includes names, Social Security numbers, drivers licenses, and financial account info for approximately 22,573 individuals Notifications sent January 2, 2025, and credit monitoring offered.
-
Heartland Community Health Center
October 1, 2024
•
[ phishing, data leak ]
Clinic reported email account breach exposing sensitive patient and insurance information.
-
Andy Frain Services
October 1, 2024
•
[ ransomware, data leak ]
Physical security firm reported a ransomware intrusion in Oct 2024 attributed to Black Basta with exfiltration of a wide range of data; notices sent to ~100k people in May 2025.
-
Onsite Mammography
October 1, 2024
•
[ phishing, data leak ]
Phishing attack compromised a single employees email account, enabling exfiltration of PII and PHI data affecting over 350,000 individuals; no encryption involved.
-
sqgame.net
October 1, 2024
•
[ supply chain attack, malware, backdoor ]
ScarCruft/INKY SQUID compromised Windows and Android components of the sqgame.net gaming platform serving ethnic Koreans in China's Yanbian region, trojanizing game files and update components with RokRAT and BirdCall backdoors. ESET estimated the compromise began in late 2024, with Android malware development beginning around October 2024 and Windows update components malicious since at least November 2024.
-
Barbados Revenue Authority
September 30, 2024
230GB of records from the Barbados Revenue Authority, such as property tax records and vehicle owners registration records, are being offered for sale.
-
Rackspace
September 30, 2024
Rackspace tells customers that threat actors exploited a zero-day vulnerability in ScienceLogic, a third-party application it was using, and abused that vulnerability to break into its internal performance monitoring environment.
-
Byte Federal
September 30, 2024
US Bitcoin ATM operator Byte Federal discloses a data breach that exposed the data of 58,000 customers after its systems were breached using a GitLab vulnerability.
-
Hunter Health Clinic
September 30, 2024
•
[ phishing, data leak ]
Clinic said an unauthorized party accessed one employee mailbox around Sept 30, 2024; on May 1, 2025 it confirmed files with PHI/PII may have been accessed; notices issued May 15.
-
digiDirect
September 29, 2024
In September 2024, a data breach sourced from the Australian retailer digiDirect was published to a popular hacking forum. The breach exposed over 300k rows of data including email and physical address, name, phone number and date of birth. Approximately half the email addresses were on domains from external marketplaces including Amazon, eBay and Westfield.
-
Dove Healthcare
September 29, 2024
•
[ phishing, data leak ]
Healthcare provider disclosed email account compromise containing patient and employee information.
-
Richmond Community Schools
September 28, 2024
•
[ ransomware, malware, education ]
Richmond Community Schools in Indiana posts to social media that student and staff information in the PowerSchool software system was breached in a ransomware attack.
-
Rafic Hariri International Airport
September 28, 2024
•
[ hack, government ]
The Israeli cyber army allegedly hacks into the control tower of the Rafic Hariri International Airport in Beirut, and threatens an Iranian civilian plane attempting to land, forcing it to return.
-
SelectBlinds
September 28, 2024
•
[ financial, malware, retail ]
More than 200,000 who shopped for blinds or window dressing this year had their credit card information and other data stolen after threat actors placed malware on the website of SelectBlinds, a major retailer.
-
Internet Archive
September 28, 2024
•
[ hack, technology ]
In September 2024, the digital library of internet sites Internet Archive suffered a data breach that exposed 31M records. The breach exposed user records including email addresses, screen names and bcrypt password hashes.
-
University Medical Center Health System
September 27, 2024
•
[ ransomware, malware, healthcare ]
University Medical Center Health System (UMC) in Lubbock is forced to divert ambulances after a ransomware attack shuts down many of its systems.
-
National Dutch police (Politie)
September 27, 2024
•
[ espionage, government ]
The National Dutch police (Politie) says that a state actor was likely behind a data breach detected the previous week.
-
AFP (Agence France-Presse)
September 27, 2024
•
[ hack ]
Global news agency AFP (Agence France-Presse) warns that it suffered a cyberattack, which impacted IT systems and content delivery services for its partners.