-
Unknown Organization
September 9, 2016
•
[ hack, ddos, finance ]
Turkish hackers have launched DoS (Denial-of-Service) attacks against the web servers of the Austrian National Bank (OeNB).
-
KrebsOnSecurity
September 9, 2016
•
[ hack, ddos, technology ]
Security researcher Brian Krebs' website KrebsOnSecurity comes under "heavy and sustainable" attack after two 18 year-old Israeli hackers were arrested over their connection with a DDoS-for-hire service called vDOS.
-
Unknown Organization
September 9, 2016
•
[ hack, technology ]
Popular science website EurekAlert!, which handles embargoed reports on health, medicine, and technology is hacked. The announcement in the website states that usernames and passwords to the service have been compromised. The hacker has also leaked two embargoed reports.
-
vDoS
September 8, 2016
•
[ hack, leak, ddos ]
vDos, a "booter" service that has earned in excess of $600,000 over the past two years helping customers coordinate more than 150,000 DDoS attacks is massively hacked, spilling secrets about tens of thousands of paying customers and their targets.
-
Hutton Hotel
September 7, 2016
The Hutton Hotel says it engaged a third-party cyber security firm after it was notified of a possible breach by its payment processor. The investigation found that malware designed to capture card data had been installed on the hotel's payment processing system.
-
Vienna Airport
September 7, 2016
•
[ hack ]
Austrian police investigates a failed cyberattack on Vienna's airport saying they are looking into the authenticity of a claim of responsibility from a Turkish nationalist group.
-
Unknown Organization
September 7, 2016
•
[ hack, ddos, government ]
Servers belonging to the Project on Crowdsourced Imagery Analysis (PCIA), hosting data about nuclear tests, have been the subject of DDoS attacks just two days before North Korea's most recent nuclear tests.
-
eThekwini Municipality
September 7, 2016
In September 2016, the new eThekwini eServices website in South Africa was launched with a number of security holes that lead to the leak of over 98k residents' personal information and utility bills across 82k unique email addresses. Emails were sent prior to launch containing passwords in plain text and the site allowed anyone to download utility bills without sufficient authentication. Various methods of customer data enumeration was possible and phishing attacks began appearing the day after launch.
-
Rambler
September 6, 2016
Nearly 100 million usernames and passwords from the Russian internet giant Rambler surface online in the latest in a long line of hacks that first occurred back in 2012.
-
San Francisco Exploratorium Museum
September 6, 2016
•
[ social, phishing, education ]
The San Francisco Exploratorium Museum admits to have fallen victim to a Spear Phishing Attack.
-
University of Alaska
September 6, 2016
University of Alaska officials announces that an attacker using employee credentials may have accessed student information of approximately 5,400 individuals.
-
Real Estate Mogul
September 6, 2016
•
[ hack, misconfiguration, finance ]
In September 2016, the real estate investment site Real Estate Mogul had a Mongo DB instance compromised and 5GB of data downloaded by an unauthorised party. The data contained real estate listings including addresses and the names, phone numbers and 308k unique email addresses of the sellers. Real Estate Mogul was advised of the incident in September 2018 and stated that they "found no instance of user account credentials like usernames and passwords nor billing information within this file".
-
uuu9
September 6, 2016
•
[ leak, technology ]
In September 2016, data was allegedly obtained from the Chinese website known as uuu9.com and contained 7.5M accounts. Whilst there is evidence that the data is legitimate, due to the difficulty of emphatically verifying the Chinese breach it has been flagged as "unverified". The data in the breach contains email addresses and user names. Read more about Chinese data breaches in Have I Been Pwned.
-
Brazzers
September 5, 2016
•
[ leak, misconfiguration, technology ]
Nearly 800,000 accounts for popular porn site Brazzers have been exposed in a data breach.
-
Digimon
September 5, 2016
•
[ leak, misconfiguration, technology ]
In September 2016, over 16GB of logs from a service indicated to be digimon.co.in were obtained, most likely from an unprotected Mongo DB instance. The service ceased running shortly afterwards and no information remains about the precise nature of it. Based on enquiries made via Twitter, it appears to have been a mail service possibly based on PowerMTA and used for delivering spam. The logs contained information including 7.7M unique email recipients (names and addresses), mail server IP addresses, email subjects and tracking information including mail opens and clicks.
-
ClixSense
September 4, 2016
•
[ hack, misconfiguration, technology ]
In September 2016, the paid-to-click site ClixSense suffered a data breach which exposed 2.4 million subscriber identities. The breached data was then posted online by the attackers who claimed it was a subset of a larger data breach totalling 6.6 million records. The leaked data was extensive and included names, physical, email and IP addresses, genders and birth dates, account balances and passwords stored as plain text.
-
NemoWeb
September 4, 2016
•
[ leak, misconfiguration, technology ]
In September 2016, almost 21GB of data from the French website used for "standardised and decentralized means of exchange for publishing newsgroup articles" NemoWeb was leaked from what appears to have been an unprotected Mongo DB. The data consisted of a large volume of emails sent to the service and included almost 3.5M unique addresses, albeit many of them auto-generated. Multiple attempts were made to contact the operators of NemoWeb but no response was received.
-
Variety
September 3, 2016
•
[ hack, misconfiguration, technology ]
Entertainment news site Variety is briefly taken over by the infamous hacker group OurMine. The hacking collective manages to break into Variety's content management system and defaces the site with a post of their own claiming responsibility for the attack.
-
Twitter
September 3, 2016
•
[ hack, misconfiguration, technology ]
A group of hackers dubbed Spain Squad claims to have found a way to seize inactive and suspended Twitter accounts, and sells them on the social network.
-
Ukrainian alleged pro-Russian Journalists
September 3, 2016
Myrotvorets, a group of Ukrainian nationalist hackers, leaks the personal details of local journalists they consider pro-Russian for the second time in four months.