-
Seneca
February 29, 2024
Threat actors steal $6 million from the Seneca stablecoin protocol across the Ethereum and Arbitrum networks by exploiting a bug in the protocol's smart contract approval mechanisms
-
Chunghwa Telecom
February 29, 2024
•
[ espionage, leak, government ]
The Taiwan ministry of national defense says that threat actors stole sensitive information including military and government documents from Chunghwa Telecom, Taiwans largest telecom company and sold it on the dark web.
-
Chelan County Public Utility District
February 29, 2024
•
[ energy ]
The Chelan County Public Utility District is impacted by a cybersecurity event" that kept a nationwide vendor from mailing and emailing statements.
-
U.S. Cybersecurity and Infrastructure Security Agency (CISA)
February 29, 2024
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) discloses that threat actors breached their systems in February through vulnerabilities in Ivanti products
-
Multiple organizations in the U.S.
February 29, 2024
•
[ ransomware, malware, government ]
The U.S. cybersecurity and intelligence agencies CISA, FBI, and MS-ISAC warn of Phobos ransomware attacks targeting government and critical infrastructure entities.
-
SurveyLama
February 29, 2024
•
[ leak, technology ]
SurveyLama suffers a data breach in February 2024, which exposes the sensitive data of 4.4 million users.
-
Organizations in Japan
February 28, 2024
•
[ espionage, malware, technology ]
Japan's Computer Security Incident Response Team (JPCERT/CC) warns that the notorious North Korean hacking group Lazarus has uploaded four malicious PyPI packages to infect developers with malware.
-
Dohman, Akerlund & Eddy
February 28, 2024
•
[ leak, healthcare ]
Accounting firm Dohman, Akerlund & Eddy ("DA&E") announces a data incident that impacted some protected health information of 82,000 people.
-
LDLC
February 28, 2024
•
[ hack, retail ]
In March 2024, French retailer LDLC disclosed a data breach that impacted customers of their physical stores. The data was previously listed for sale on a popular hacking forum and contained 1.26M unique email addresses along with names, phone numbers and physical addresses. The data was provided to HIBP by a source who requested it be attributed to "oathnet.ru".
-
DemandScience by Pure Incubation
February 28, 2024
In early 2024, a large corpus of data from DemandScience (a company owned by Pure Incubation), appeared for sale on a popular hacking forum. Later attributed to a leak from a decommissioned legacy system, the breach contained extensive data that was largely business contact information aggregated from public sources. Specifically, the data included 122M unique corporate email addresses, physical addresses, phone numbers, employers and job titles. It also included names and for many individuals, a link to their LinkedIn profile.
-
Cencora
February 27, 2024
•
[ hack, manufacturing ]
Pharmaceutical giant Cencora says they suffered a cyberattack where threat actors stole data from corporate IT systems.
-
Municipality of Bjuv
February 27, 2024
•
[ ransomware, government ]
The Akira ransomware group threatens to leak nearly 200GB of stolen data from Bjuv Municipalitys systems.
-
Hochschule Kempten
February 27, 2024
•
[ hack, education ]
Hochschule Kempten, a university of applied sciences in the city of Kempten in Germany, announces being targeted by a criminal cyberattack that forced the institution to take down its IT infrastructure.
-
Pepco Group
February 27, 2024
•
[ financial, retail ]
European discount retailer Pepco Group reveals that its Hungarian business has lost a significant amount of money (15.5 Million) to cybercriminals.
-
U.S. healthcare organizations
February 27, 2024
•
[ ransomware, malware, healthcare ]
The FBI, CISA, and the Department of Health and Human Services (HHS) warn U.S. healthcare organizations of targeted ALPHV/Blackcat ransomware attacks.
-
VeriSource Services, Inc.
February 27, 2024
•
[ data leak ]
VeriSource Services, Inc., a Texas-based HR and benefits administration firm, suffered a data breach in February 2024 after an unauthorized party accessed and downloaded approximately 4 million employee and dependent records from its systems. No encryption or operational disruption occurred. Disclosure was made in April 2025 following forensic review.
-
Quik Pawn Shop
February 26, 2024
•
[ ransomware, malware, finance ]
The Akira ransomware group claims responsibility for a cyber attack to Quik Pawn Shop.
-
Das Team Ag
February 26, 2024
Das Team Ag, a job placement agency with 25 branches across Switzerland and the Principality of Liechtenstein, confirms that they fell victim to a cyberattack by the Black Basta ransomware group.
-
Cutout.Pro
February 26, 2024
•
[ hack, misconfiguration, technology ]
In February 2024, the AI-powered visual design platform Cutout.Pro suffered a data breach that exposed 20M records. The data included email and IP addresses, names and salted MD5 password hashes which were subsequently broadly distributed on a popular hacking forum and Telegram channels.
-
Los Angeles Airport
February 24, 2024
•
[ hack, government ]
IntelBroker claims to have breached the database of the Los Angeles Airport, exploiting a vulnerability in the CRM system, and resulting in the compromise of 2.5 million records of plane owners.