Claim Expert
January 1, 2025
•[ data leak, data exfiltration ]
Data exfiltration and exposure of Pick n Pay customer information (~105 k records) from Claim Experts system by Bashe group; no encryption or operational disruption reported
Undisclosed cryptocurrency market-making firm
October 20, 2024
•[ data exfiltration, cryptocurrency, state-sponsored attack ]
Recorded Future observed C2 reconnaissance followed by FTP exfiltration from a market-making firm in the UAE during the Contagious Interview campaign (OctNov 2024). Attributed to the NGB 3rd Technical Surveillance Bureau (North Korea).
Undisclosed online casino operator
October 20, 2024
•[ Data exfiltration, State-sponsored attack, Reconnaissance ]
Recorded Future analysis identified reconnaissance and FTP exfiltration traffic from a Costa Rican online casino targeted in the Contagious Interview campaign (OctNov 2024), attributed to the NGB 3rd Technical Surveillance Bureau (North Korea).
The European House – Ambrosetti spa
April 1, 2024
•[ technical vulnerability, data exfiltration, unprotected passwords ]
Unauthorized access to The European House Ambrosetti systems through a technical vulnerability in April 2024 resulted in exfiltration of account data for 61,670 people, including employees of client companies and internal staff using online services. Italy's data protection authority later fined the company for inadequate security, unprotected passwords, and delayed notification to affected individuals.