-
Czech News Agency (CTK)
April 24, 2024
•
[ hack, government ]
An unidentified threat actor hacks the website of Czech News Agency (CTK) a government-owned Czech news service, and publishes a fake story claiming that an assassination attempt had been made against the newly elected Slovak president, Petr Pellegrini.
-
Dropbox
April 24, 2024
Cloud storage firm Dropbox says threat actors breached production systems for its Dropbox Sign eSignature platform and gained access to authentication tokens, MFA keys, hashed passwords, and customer information.
-
Piping Rock
April 24, 2024
In April 2024, 2.1M email addresses from the online health products store Piping Rock were publicly posted to a popular hacking forum. The data also included names, phone numbers and physical addresses. The account posting the data had previously posted multiple other data breaches which all appear to have been obtained from the Shopify service used by the respective websites.
-
Skanlog
April 23, 2024
•
[ ransomware, malware, retail ]
Skanlog, the Swedish logistics company that works with Swedens alcohol retail monopoly Systembolagethas, is hit with a ransomware attacks and prompts warnings from the countrys sole liquor retailer that its top shelves in stores around the country may be empty by the end of the week.
-
Tappware
April 23, 2024
•
[ hack, misconfiguration, technology ]
In April 2024, a substantial volume of data was taken from the Bangladeshi IT services provider Tappware and published to a popular hacking forum. Comprising of 95k unique email addresses, the data also included extensive labour information on local citizens including names, physical addresses, job titles, dates of birth, genders and scans of government issued national identity (NID) cards.
-
Skanlog
April 23, 2024
•
[ ransomware, logistics, supply chain disruption ]
Skanlog, the Swedish logistics company that works with Swedens alcohol retail monopoly Systembolagethas, is hit with a ransomware attacks and prompts warnings from the countrys sole liquor retailer that its top shelves in stores around the country may be empty by the end of the week.
-
Tipton Wastewater Treatment Plant
April 20, 2024
•
[ hack ]
The Cyber Army of Russia claims responsibility for a cyber attack to the Tipton Wastewater Treatment Plant. An investigation by Mandiant claims that this group may be linked operationally to APT44 GRU Sandworm
-
Volkswagen
April 20, 2024
•
[ espionage, manufacturing ]
Threat actors associated with the Chinese government are believed to have hacked into Volkswagen systems in an effort to steal valuable data between 2011 and 2014.
-
Chivo
April 20, 2024
The threat group CiberInteligenciaSV releases what it says is sensitive information linked to El Salvador's state-operated bitcoin wallet Chivo, releasing source code on the criminal forum BreachForums.
-
Ukrainian armed forces
April 19, 2024
The Computer Emergency Team of Ukraine (CERT-UA) warns that threat actors from the group UAC-0184 are increasingly trying to plant data-stealing malware on messaging apps used by the Ukrainian armed forces.
-
Hedgey Finance
April 19, 2024
•
[ financial, finance ]
Token infrastructure platform Hedgey Finance undergoes two simultaneous exploits that resulted in a combined loss of $44.7 million
-
Union Hospital
April 18, 2024
•
[ ransomware, malware, healthcare ]
The Union Hospital in Hong Kong is hit with an alleged LockBit ransomware attack.
-
Government of British Columbia
April 18, 2024
•
[ hack, government ]
The Government of British Columbia is investigating multiple "cybersecurity incidents" that have impacted the Canadian province's government networks.
-
Synlab Italia
April 18, 2024
•
[ ransomware, malware, healthcare ]
Synlab Italia suspends all its medical diagnostic and testing services after a ransomware attack forced its IT systems to be taken offline. The BlackBasta ransomware gang claims responsibility for the attack.
-
Summit Pathology and Summit Pathology Laboratories
April 18, 2024
•
[ ransomware, healthcare ]
Summit Pathology and Summit Pathology Laboratories (Summit) in Colorado notify of a breach affecting 1,813,538 patients. The Medusa ransomware gang is allegedly responsible for the breach.
-
Sport 2000
April 18, 2024
•
[ leak, retail ]
In April 2024, the French sporting equipment manufacturer Sport 2000 announced it had suffered a data breach. The data was subsequently put up for sale on a popular hacking forum and included 4.4M rows with 3.2M unique email addresses alongside names, physical addresses, phone numbers, dates of birth and purchases made by store name. The data was provided to HIBP by a source who requested it be attributed to "oathnet.ru".
-
Mobile Guardian
April 17, 2024
The names and e-mail addresses of parents and teachers of 127 primary and secondary schools are leaked after Mobile Guardian, a mobile platform on students personal learning devices is hacked.
-
Grodno Azot
April 17, 2024
•
[ hack, manufacturing ]
Belarusian politically motivated hacktivists from the Belarusian Cyber-Partisans group claim to have attacked the countrys largest state-run manufacturer of fertilizers, Grodno Azot, for its alleged involvement in political repression, sanctions evasion, and human rights violations.
-
New York Bill Drafting Commission
April 17, 2024
•
[ hack, malware, government ]
The New York Bill Drafting Commission is taken down by a malware attack.
-
T2
April 17, 2024
In April 2024, 95k records from the T2 tea store were posted to a popular hacking forum. Data included email and physical addresses, names, phone numbers, dates of birth, purchases and passwords stored as scrypt hashes.