-
Health Now Networks
March 25, 2017
•
[ leak, misconfiguration, healthcare ]
In March 2017, the telemarketing service Health Now Networks left a database containing hundreds of thousands of medical records exposed. There were over 900,000 records in total containing significant volumes of personal information including names, dates of birth, various medical conditions and operator notes on the individuals' health. The data included over 320k unique email addresses.
-
Factual
March 22, 2017
In March 2017, a file containing 8M rows of data allegedly sourced from data aggregator Factual was compiled and later exchanged on the premise it was a "breach". The data contained 2.5M unique email addresses alongside business names, addresses and phone numbers. After consultation with Factual, they advised the data was "publicly available information about businesses and other points of interest that Factual makes available on its website and to customers".
-
Wind Tre
March 20, 2017
•
[ hack, technology ]
Italy's data protection authority, Garante Privacy, has ordered Wind Tre to write to customers to notify them of a data breach following a cyber attack that occurred on 20 March.
-
boaec
March 15, 2017
•
[ hack ]
The Anonymous deface the official website of Boa Esporte, a second division football club in the state of Minas Gerais, after the team hired goalkeeper Bruno Fernandes das Dores de Souza convicted for murdering his ex-girlfriend.
-
Dun & Bradstreet
March 15, 2017
•
[ leak, misconfiguration, technology ]
A Dun & Bradstreet 52GB database containing about 33.6 million records with very specific details about each of the people involved from job title to email address is exposed.
-
Wishbone App
March 15, 2017
•
[ hack, technology ]
Hackers steal 2.2 million email addresses and 287,000 cellphone numbers from popular teen quiz App Wishbone users, many of whom are young women under the age of 18.
-
Statistics Canada
March 14, 2017
•
[ hack, government ]
The Canadian government confirms that the Statistics Canada website is hacked and taken offline for over two days. In the aftermath of the cyberattack parts of the Canada Revenue Agency's (CRA) site is also reportedly taken offline by authorities as a precaution.
-
Mountain Home Water Department
March 14, 2017
•
[ ransomware, malware, government ]
The servers of Mountain Home Water Department fall victim to a ransomware attack.
-
Master Deeds
March 14, 2017
•
[ leak, misconfiguration, finance ]
In March 2017, a 27GB database backup file named "Master Deeds" was sent to HIBP by a supporter of the project. Upon detailed analysis later that year, the file was found to contain the personal data of tens of millions of living and deceased South African residents. The data included extensive personal attributes such as names, addresses, ethnicities, genders, birth dates, government issued personal identification numbers and 2.2 million email addresses. At the time of publishing, it's alleged the data was sourced from Dracore Data Sciences (Dracore is yet to publicly confirm or deny the data was sourced from their systems). On 18 October 2017, the file was found to have been published to a publicly accessible web server where it was located at the root of an IP address with directory listing enabled. The file was dated 8 April 2015.
-
Welsh NHS
March 13, 2017
•
[ leak, healthcare ]
Details of thousands of medical staff of Welsh NHS are stolen from a private contractor's computer server (Landauer). The breach happened in October 2016 and the total number of affected staff is 4,766.
-
fifthharmony
March 12, 2017
•
[ hack ]
A Kurdish hacker going by the online handle of "Rekan Error" defaces the official website of Fifth Harmony, an American girl group formed on the second season of The X Factor US in July 2012 and posts messages against ISIS and Turkey.
-
Queensland School Photography
March 9, 2017
•
[ financial, education ]
Queensland School Photography emails students' parents to notify that payment card information has been compromised.
-
GMO Payment Gateway Inc
March 9, 2017
GMO Payment Gateway confirms data leakage from two client websites, due to the Apache Struts vulnerability. The victims are the Tokyo Metropolitan Government, and the Japan Housing Finance Agency. The total leaked records are more than 700,000.
-
Ster-Kinekor
March 9, 2017
•
[ leak, misconfiguration, retail ]
In 2016, the South African cinema company Ster-Kinekor had a security flaw which leaked a large amount of customer data via an enumeration vulnerability in the API of their old website. Whilst more than 6 million accounts were leaked by the flaw, the exposed data only contained 1.6 million unique email addresses. The data also included extensive personal information such as names, addresses, birthdates, genders and plain text passwords.
-
Verifone
March 7, 2017
•
[ hack, finance ]
Credit and debit card payments giant Verifone investigates a breach of its internal computer networks that appears to have impacted a number of companies running its point-of-sale solutions.
-
Center for American Progress
March 6, 2017
New reports reveal that Russian hackers are targeting U.S. progressive groups in a new wave of attacks. According to the report, at least a dozen groups have faced extortion attempts since the U.S. presidential election. The ransom demands are accompanied by samples of sensitive data in the hackers' possession.
-
University of Idaho
March 6, 2017
•
[ social, phishing, education ]
University of Idaho notifies 257 employees after a phishing incident.
-
Henok Gabisa
March 6, 2017
A threat actor targeted Ethiopian dissidents for the purpose of espionage, using commercially available spyware sold by Cyberbit, an Israel-based company. Most notably, the actor targeted the Oromia Media Network and some individuals associated with it.
-
Advertisement board in Mexico City
March 4, 2017
•
[ hack, technology ]
A digital advertisement board owned by Grupo Carteleras located on a busy road in Mexico City is hacked on Friday and features a pornographic video for a few minutes.
-
Pennsylvania Senate Democrats
March 3, 2017
•
[ ransomware, malware, government ]
The Pennsylvania Senate Democrats are hit by a ransomware attack that locks senators and employees out of their computer network.