-
PIK-Group
February 28, 2019
•
[ hack, malware ]
Researcher Marco Ramilli publishes the analysis of a malware allegedly designed to target PIK-Group, the largest real estate and homebuilder company in Russia.
-
Lifebear
February 28, 2019
•
[ hack, technology ]
In early 2019, the Japanese schedule app Lifebear appeared for sale on a dark web marketplace amongst a raft of other hacked websites. The breach exposed almost 3.7M unique email addresses, usernames and passwords stored as salted MD5 hashes. The data was provided to HIBP by a source who requested it be attributed to "nano@databases.pw".
-
Estante Virtual
February 28, 2019
•
[ leak, misconfiguration, retail ]
In February 2019, the Brazilian book store Estante Virtual suffered a data breach that impacted 5.4M customers. The exposed data included names, usernames, email and physical addresses, phone numbers, dates of birth and unsalted SHA-1 password hashes.
-
Florida Keys Community College
February 27, 2019
•
[ social, phishing, education ]
Florida Keys Community College discovers that it became the target of a phishing email campaign that compromised several employee email account credentials back in October 2018.
-
Pasquotank-Camden Emergency Medical Service
February 27, 2019
•
[ hack, healthcare ]
Pasquotank-Camden Emergency Medical Service notifies 40,000 individuals after an unauthorized intrusion from outside the U.S. occurred in late December 2018.
-
Zillow
February 27, 2019
•
[ hack, misconfiguration, technology ]
Zillow is sued for $60 million after a hacker manages to gain access to a property's Zillow listing page, and update its information.
-
Topps
February 27, 2019
•
[ financial, malware, retail ]
Sports trading card and collectible company Topps issues a data breach notification stating that it was affected by a Magecart attack, which possibly exposed the payment and address information of its customers.
-
Wolverine Solutions Group (WSG)
February 27, 2019
•
[ ransomware, malware, healthcare ]
Wolverine Solutions Group (WSG) says that it discovered its systems had suffered a ransomware infection on September 25 last year. More than 700 companies and 1.2 million patients are affected.
-
Embassy Bangladesh in Egypt
February 27, 2019
•
[ hack, malware, government ]
Researchers from Trustwave reveal that the web site for the Bangladeshi Embassy in Cairo has been compromised so that it distributes malicious Word documents, which install malware downloaders onto an infected computer.
-
Aurora City Schools
February 26, 2019
•
[ financial, education ]
Aurora City Schools investigates a 'sophisticated' financial cyber-security breach.
-
Verifications.io
February 25, 2019
•
[ leak, misconfiguration, technology ]
In February 2019, the email address validation service verifications.io suffered a data breach. Discovered by Bob Diachenko and Vinny Troia, the breach was due to the data being stored in a MongoDB instance left publicly facing without a password and resulted in 763 million unique email addresses being exposed. Many records within the data also included additional personal attributes such as names, phone numbers, IP addresses, dates of birth and genders. No passwords were included in the data. The Verifications.io website went offline during the disclosure process, although an archived copy remains viewable.
-
Pakistani Users
February 24, 2019
Researchers from Group-IB discover two new databases with a total of 69,189 Pakistani banks' cards, shown up for sale on the dark web. Meezan Bank is among the victims of the breach.
-
GameSalad
February 24, 2019
•
[ hack, education ]
In February 2019, the education and game creation website Game Salad suffered a data breach. The incident impacted 1.5M accounts and exposed email addresses, usernames, IP addresses and passwords stored as SHA-256 hashes. The data was provided to HIBP by a source who requested it be attributed to "JimScott.Sec@protonmail.com".
-
Apex Human Capital Management
February 23, 2019
•
[ ransomware, malware, technology ]
Payroll software provider Apex Human Capital Management suffers a ransomware attack that severs payroll management services for hundreds of the company's customers for nearly three days. The company decides to pay the ransom.
-
EOS Cryptocurrency
February 23, 2019
•
[ hack, misconfiguration, finance ]
A hacker steals $7.7 million worth of EOS cryptocurrency after one of the 21 maintainers of an EOS blacklist fails to update it. The maintainer is identified in eos.games.
-
Pompano Beach
February 23, 2019
Pompano Beach is the latest municipality to warn its residents (4,000 people) of the Click2Gov breach.
-
ATM (Azienda Trasporti Milanese)
February 22, 2019
•
[ hack, government ]
Unknown attackers break into the systems of ATM (the public company responsible for public transportation in Milan).
-
Embassy of Russia in Austria
February 22, 2019
•
[ hack, ddos, government ]
After receiving complaints for the impossibility to book appointments, the Russian embassy in Austria discovers to be the victim of a DDoS attack via automated requests made by IP addresses from Iraq, Thailand, Indonesia and other countries.
-
US bank customers from 40 states
February 22, 2019
Joker's Stash, a well-known underground marketplace for selling stolen credit card dumps, advertises the "DaVinci Breach," a dump containing the card details for over 2.15 million US bank customers from 40 states.
-
Rutland Regional Medical Center
February 22, 2019
Rutland Regional Medical Center notifies patients after an employee email accounts hacked back in December 2018.