-
Gallivan
March 3, 2023
Gallivan, the provider of the student health, dental, and wellness program for students at the University of Guelph, notifies students of a data breach which included access to personal information, occurred exploiting the CVE-2023-0669 Fortra GoAnywhere MFT Vulnerability.
-
Gaston College
March 3, 2023
•
[ ransomware, malware, education ]
Gaston College posts a "System Interruption" notice after the school confirmed that it was the victim of a ransomware attack
-
Henrico Doctors Hospital
March 3, 2023
•
[ leak, healthcare ]
Henrico Doctors' Hospital notifies 990 patients that some of their protected health information was compromised in a data breach.
-
Parques Reunidos Group
March 3, 2023
The BianLian ransomware group claims to have stolen employee information, including passport details, as well as information on the company's partners, data on park-related incidents, financial records, internal emails and legal documents from Parques Reunidos Group, a Spanish amusement park company.
-
Traditions Bank
March 3, 2023
Traditions Bank files a notice of data breach after learning that an unauthorized party removed files containing confidential customer information from the bank's computer system.
-
Pixowl Games
March 2, 2023
•
[ social, malware, technology ]
The Sandbox blockchain game warns its community that a security incident caused some users to receive fraudulent emails impersonating the game, trying to infect them with malware.
-
Concorde Investment Partners
March 2, 2023
•
[ hack, phishing, finance ]
Concorde Investment Partners, parent company to Concorde Investment Services, Concorde Asset Management, and Concorde Insurance Agency (collectively "Concorde"), files a notice of data breach after discovering that an unauthorized party was able to access an employee's email account.
-
Bettuzzi And Partners
March 2, 2023
•
[ ransomware, malware, finance ]
Bettuzzi And Partners, an Italian accounting firm is hit with a RansomEXX ransomware attack.
-
GunAuction
March 2, 2023
•
[ hack, leak, retail ]
Hackers breach GunAuction.com, a website that allows people to buy and sell guns, exposing the identities of 550,000 users.
-
Vertex
March 2, 2023
•
[ ransomware, malware, healthcare ]
Ascension postes a notice describing a "security incident" after learning that a ransomware cyberattack at Vertex, one of the company's vendors resulted in leaked patient data.
-
WH Smith
March 2, 2023
•
[ leak, retail ]
British retailer WH Smith suffers a data breach that exposes information belonging to current and former employees.
-
Codman Square Health Center
March 1, 2023
•
[ ransomware, malware, finance ]
Codman Square Health Center files a notice of data breach after learning that a ransomware attack targeting the company's IT system compromised confidential patient information.
-
Azienda Ospedaliero-Universitaria di Parma (Hospital of Parma)
March 1, 2023
•
[ hack, healthcare ]
The Hospital of Parma suffers a cyber attack.
-
Chippewa County
March 1, 2023
•
[ leak, government, healthcare ]
The Chippewa County Human Resources Division notifies that the laptop computer of an employee was compromised and 25-35MB of data was stolen from the device, including information protected under HIPAA.
-
Poland's tax service
March 1, 2023
•
[ hack, ddos, government ]
Poland's tax service website is hit by a DDoS attack believed to have been carried out by Russian hackers.
-
Group 1001
March 1, 2023
•
[ ransomware, malware, finance ]
The insurance company Group 1001 restores the operations after suffering a ransomware attack.
-
Einhaus Group
March 1, 2023
•
[ ransomware, malware, finance ]
The Royal ransomware group encrypted all systems of the Germany-based Einhaus Group in March 2023, resulting in total operational paralysis across its 5,000 retail points. Despite paying ~200K in Bitcoin ransom, the company went bankrupt. Several Royal group suspects were arrested and crypto assets seized, but operations were not restored.
-
Hatch Bank
February 28, 2023
Hatch Bank, a digital-first bank that provides infrastructure for fintech companies offering their own brand credit cards, confirms that attackers exploited the Fortra's GoAnywhere CVE-2023-0669 zero-day vulnerability in the company's internal file transfer software that allowed access to thousands of customer Social Security numbers.
-
Veris Residential
February 28, 2023
•
[ leak ]
Veris Residential files a notice of data breach following a cybersecurity incident that leaked confidential consumer information.
-
Association of Southeast Asian Nations (ASEAN)
February 28, 2023
•
[ espionage, government ]
Chinese state-sponsored threat actors managed to breach the mail servers operated by the Association of Southeast Asian Nations, stealing a trove of data that may have contained strategic information about the economy and politics of member countries.