-
Framingham Heart Study, managed by Boston University
September 8, 2024
•
[ leak, education ]
Boston Universitys renowned Framingham Heart Study (FHS) is breached by threat actors, who gained access to the data of participantsboth living and deceasedof the countrys longest running, multigenerational heart study.
-
Great Plains Regional Medical Center
September 8, 2024
•
[ ransomware, malware, healthcare ]
Great Plains Regional Medical Center in Oklahoma notifies over 133,000 individuals that their personal information was compromised in a ransomware attack.
-
-
Tendam
September 7, 2024
•
[ ransomware, malware, retail ]
Spanish fashion multinational Tendam is hit with a ransomware attack by the Medusa group. The attackers claim to have stolen 724.59 GB of confidential data from the company's servers and are demanding a ransom of $800,000.
-
Free Russia Foundation
September 7, 2024
The U.S.-based Free Russia Foundation nonprofit says it is investigating a data breach after thousands of emails and documents supposedly related to its work are published online. The organization suspects that the incident is linked to the Kremlin-sponsored group tracked as Coldriver
-
Cardiology of Virginia
September 7, 2024
•
[ ransomware, malware, healthcare ]
Cardiology of Virginia patient data appears to be up for sale after an alleged RansomHub ransomware attack.
-
Charles Darwin School
September 6, 2024
•
[ ransomware, malware, education ]
The Charles Darwin School in south London is hit with a ransomware attack.
-
Physical Medicine & Rehabilitation Center
September 6, 2024
•
[ leak, healthcare ]
The Physical Medicine & Rehabilitation Center posts a notice on its website about an incident in July that affected patients at their New Jersey and New York locations. The Meow Leaks claims responsibility for the attack.
-
Boulanger
September 6, 2024
In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 967k unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum.
-
Boulanger
September 6, 2024
•
[ hack, leak, retail ]
In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 2M unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum. The data was provided to HIBP by a source who requested it be attributed to "leidhall".
-
Cultura
September 6, 2024
•
[ hack, retail ]
In September 2024, French retailer Cultura was the victim of a cyber attack they attributed to an external IT service provider. The resultant data breach included almost 1.5M unique email addresses along with names, phone numbers, physical addresses and orders. Cultura advised that all affected customers had been notified about the incident.
-
Zenith American Solutions, Inc.
September 6, 2024
•
[ phishing, data leak ]
Unauthorized access to Zenith American Solutions network discovered September 6 2024 after an employee email account was compromised via phishing; over 12,000 individuals names, dates of birth, Social Security numbers, and benefit-plan documents potentially accessed. The firm notified regulators January 2025 and publicly disclosed in June 2025. No actor attribution or ransom demand reported.
-
Boulanger
September 6, 2024
•
[ data breach, PII, retail ]
In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 2M unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum.
-
Tewkesbury Borough Council
September 5, 2024
•
[ hack, government ]
The Tewkesbury Borough Council shouts down its systems following a cyber attack.
-
Penpie
September 5, 2024
Threat actors steak about $27 million worth of cryptocurrency from the Penpie decentralized finance (DeFi) protocol.
-
Undisclosed organization
September 5, 2024
•
[ ransomware, malware ]
Researchers at Palo Alto discover a ransomware incident where the threat actor Jumpy Pisces, tied to North Korea, collaborated with the Play ransomware group.
-
Cisco
September 4, 2024
•
[ leak, malware, technology ]
Ciscos site for selling company-themed merchandise is offline and under maintenance due to threat actors compromising it with JavaScript code that steals sensitive customer details provided at checkout exploiting CVE-2024-34102.
-
Latvian government and critical infrastructure websites
September 4, 2024
According to Latvian cybersecurity officials, politically motivated threat actors linked to Russia and Belarus are targeting Latvian government and critical infrastructure websites in a new wave of cyberattacks.
-
Plaisted Companies, Inc.
September 4, 2024
•
[ data leak ]
On or around September 4 2024, Plaisted Companies, Inc. experienced unauthorized access to internal application servers storing personal data. The company reported potential exposure of files containing personally identifiable information and began notifications on March 26 2025. No encryption, data theft confirmation, or ransom activity was reported.
-
VK
September 3, 2024
•
[ leak, technology ]
A threat actor using the alias HikkI-Chan leaks the personal details of over 390 million VK users (specifically, 390,425,719) on the notorious cybercrime and hacker platform Breach Forums. The data was stolen from a third-party.