-
Singtel
December 25, 2020
Singtel and the QIMR Berghofer Medical Research Institute disclosed data breaches caused by a vulnerability in the Accellion FTA secure file transfer software. "A third-party file sharing system provided by Accellion called FTA has been illegally accessed through a zero-day vulnerability or previously unknown vulnerability. Singtel uses this system to share information internally as well as with external stakeholders and organisations," Singtel announced in a security incident notification.
-
Aurora Cannabis
December 25, 2020
•
[ leak ]
A data breach at Aurora Cannabis has exposed the personal information of an unknown number of the Canadian company's current and former employees.
-
Practice First Medical Management Solutions
December 25, 2020
•
[ ransomware, malware, healthcare ]
A vendor of billing and coding services to health centers is hit by a ransomware attack, protected health information of over 1.2 million people is stolen.
-
BitGrail
December 24, 2020
A former BitGrail administrator has been found to be responsible for a 120 million euro fraud that was the result of a bug exploit. The defendant in the case purposefully failed to fix the bug and allowed hackers to steal from BitGrail.
-
Finalyse
December 24, 2020
•
[ ransomware, malware, finance ]
The Belgian financial consultant Finalyse has fallen victim to a ransomware attack.
-
OmniTRAX
December 24, 2020
•
[ ransomware, malware ]
Colorado-based short line rail operator and logistics provider OmniTRAX was hit by a recent ransomware attack and data theft that targeted its corporate parent, Broe Group
-
Freedom Finance
December 24, 2020
•
[ leak, finance ]
Russian broker Freedom Finance has admitted to a data leak after the information of 16,000 clients appeared on several shadow forums.
-
Scottish Environment Protection Agency
December 24, 2020
•
[ ransomware, malware, government ]
The Scottish Environment Protection Agency is targeted in a cyberattack which has impacted its contact center, internal systems, processes and internal communications. The incident is revealed to be a ransomware attack by the Conti gang.
-
Transform Hospital Group
December 24, 2020
•
[ ransomware, malware, healthcare ]
Transform Hospital Group has been attacked by the REvil ransomware threat actors.
-
Citrix
December 24, 2020
•
[ hack, ddos, technology ]
Citrix has confirmed that a DDoS attack is affecting its Application Delivery Controller (ADC) networking appliances.
-
Innovaphone
December 24, 2020
•
[ hack ]
Innovaphone has been hit by a hacker. The company believes that the hacker's motive was vandalism.
-
Sangoma Technologies
December 24, 2020
Sangoma has disclosed a data breach after files that were stolen by the Conti ransomware threat actors were published online after an attack.
-
The Hospital Group
December 24, 2020
•
[ ransomware, malware, healthcare ]
The REvil ransomware gang hacks The Hospital Group and threatens to release before-and-after pictures of celebrity clients.
-
US Department of Justice
December 24, 2020
•
[ hack, malware, government ]
The Department of Justice has revealed that hackers have accessed its networks as a result of the SolarWinds hack. The attackers breached the Department's Office 365 system and read its emails.
-
University of California
December 24, 2020
•
[ hack, misconfiguration, education ]
In December 2020, the University of California suffered a data breach due to vulnerability in in a third-party provider, Accellion. The breach exposed extensive personal data on both students and staff including 547 thousand unique email addresses, names, dates of birth, genders, social security numbers, ethnicities and other academic related data attributes. Further analysis is available in Exploring the Impact of the UC Data Breach. The data was provided to HIBP courtesy of Cyril Gorlla.
-
MEO
December 24, 2020
•
[ leak, misconfiguration, retail ]
In early 2023, a corpus of data sourced from the New Zealand based face mask company MEO was discovered. Dating back to December 2020, the data contained over 8k customer records including names, addresses, phone numbers and passwords stored as MD5 Wordpress hashes. MEO did not respond to multiple attempts to report the breach.
-
Innovative Solution for Healthcare
December 23, 2020
•
[ hack, misconfiguration, healthcare ]
Innovative Solution for Healthcare (iSofH) misconfigured a database of sensitive patient data which was then attacked by the meow bot.
-
Livecoin
December 23, 2020
The Russian cryptocurrency exchange Livecoin was hacked. The hackers took control of Livecoin's infrastructure and withdrew funds from accounts after modifying exchange rates, generating massive profits.
-
Proliance Surgeons, Inc.
December 23, 2020
•
[ financial, misconfiguration, healthcare ]
Proliance Surgeons has disclosed a data breach where payment card information may have been exposed for customers who made online payments on Proliance's platform.
-
Gastroenterology Consultants Ltd
December 23, 2020
•
[ ransomware, malware, healthcare ]
Gastroenterology Consultants Ltd have some data dumped from the Conti ransomware group.