-
Innovative Renal Care
February 21, 2024
•
[ data leak ]
Between February 21 and March 1, 2024, an unauthorized party accessed Innovative Renal Cares computer network and copied sensitive files. The breach exposed personal and health-related data including names, Social Security numbers, financial details, medical information, and prescriptions. The company filed a notice with the Massachusetts Attorney General on February 14, 2025, and began sending notification letters to impacted individuals. No encryption of systems or files was reported.
-
American Renal Management
February 21, 2024
•
[ data leak ]
IRC detected suspicious activity (2/29/2024); investigation found unauthorized access to certain systems (2/213/1/2024) with copying of internal files containing PII/PHI; IRC notified regulators and began mailing letters on 2/14/2025; credit monitoring offered and security measures enhanced.
-
Individuals in China
February 20, 2024
•
[ financial, malware, finance ]
China's Ministry of Industry and Information Technology warns local netizens that fake wallet apps for the nation's central bank digital currency (CBDC) are already circulating and being abused by scammers.
-
Organization in the defense sector
February 19, 2024
•
[ espionage, malware, technology ]
Germany's federal intelligence agency (BfV) and South Korea's National Intelligence Service (NIS) warn that Lazarus group's "Operation Dream Job," was also used against the defense sector.
-
University of Manchester
February 19, 2024
•
[ hack, ddos, education ]
The University of Manchester is hit with a DDoS attack. The Anonymous Sudan group claims responsibility for the attack.
-
University of Cambridge
February 19, 2024
•
[ hack, ddos, education ]
The University of Cambridge is hit with a DDoS attack. The Anonymous Sudan group claims responsibility for the attack.
-
FixedFloat
February 19, 2024
•
[ hack, malware, finance ]
FixedFloat, a decentralized crypto exchange, is hacked via a crypto drainer, for at least $26 million worth of Bitcoin and Ethereum.
-
Los Angeles County Department of Health Services
February 19, 2024
•
[ hack, phishing, government ]
The Los Angeles County Department of Health Services discloses a data breach after thousands of patients' personal and health information was exposed in a phishing attack impacting over two dozen employees.
-
Several popular Ukrainian media outlets including Ukrainska Pravda and Liga.net
February 18, 2024
Russian hackers attacked several popular Ukrainian media outlets, posting fake news related to the war.
-
Tangerine
February 18, 2024
•
[ leak, misconfiguration, technology ]
In February 2024, the Australian Telco Tangerine suffered a data breach that exposed over 200k customer records. Attributed to a legacy customer database, the data included physical and email addresses, names, phone numbers and dates of birth. Whilst the Tangerine login process involves sending a one-time password after entering an email address and phone number, it previously used a traditional password which was also exposed as a bcrypt hash.
-
El Al plane flying from Phuket to Ben-Gurion
February 17, 2024
"Hostile elements" attempt to take over the communication network of an El Al plane flying from Phuket to Ben-Gurion Airport and divert it from its destination.
-
Otolaryngology Associates
February 17, 2024
•
[ ransomware, malware, healthcare ]
Otolaryngology Associates notifies 316,802 patients about a ransomware attack.
-
Medical Billing Specialists, Inc.
February 17, 2024
•
[ data leak ]
Network disruption Feb 17, 2024; investigation confirmed unauthorized access to systems with sensitive data; notices filed 07-01-2025.
-
Russian prison system
February 16, 2024
Within hours of opposition leader Alexey Navalnys death, a group of anti-Kremlin hackers deface the website of a prison contractors website,and also appear to have stolen a database containing information on hundreds of thousands of Russian prisonersand their relatives and contacts.
-
East Central University
February 16, 2024
•
[ ransomware, malware, education ]
East Central University in Ada, Oklahoma, announces that it is investigating a BlackSuit ransomware attack that took place in February.
-
MV Behshad
February 15, 2024
•
[ espionage, hack, government ]
The U.S. conducts a cyberattack against MV Behshad, an Iranian military ship that had been collecting intelligence on cargo vessels in the Red Sea and the Gulf of Aden. Goal is to prohibit the sharing of information with Houthi rebels.
-
PSI Software SE
February 15, 2024
•
[ ransomware, malware, technology ]
PSI Software SE, a German software developer for complex production and logistics processes suffers a ransomware attack that impacts its internal infrastructure.
-
DemandScience (formerly Pure Incubation)
February 15, 2024
•
[ leak, government ]
The business contact information for 122 million people circulating since February 2024 is now confirmed to have been stolen from DemandScience, a B2B demand generation platform.
-
APT28, a.k.a. Fancy Bear and Sednit
February 14, 2024
The FBI takes down a botnet of small office/home office (SOHO) Ubiquiti routers used by Russia's Main Intelligence Directorate of the General Staff (GRU) to proxy malicious traffic and to target the United States and its allies in spearphishing and credential theft attacks.
-
Staff member of the South Korean President Yoon Suk Yeol
February 14, 2024
South Korean President Yoon Suk Yeols office discloses that presumed North Korean threat actors breached the personal emails of one of his staff members ahead of Yoons trip to Europe in November.