Pepe Jeans
September 12, 2024
•[ hack, retail ]
Pepe Jeans is also hit by the same spree of cyber attacks targeting the French retailers.
Instituto Nacional de Deportes de Chile
September 12, 2024
•[ hack, government ]
In September 2024, the Instituto Nacional de Deportes de Chile (Chile's National Sports Institute) suffered a data breach. The incident exposed 1.7M rows of data with 320k unique email addresses alongside names, dates of birth, genders and bcrypt password hashes. The newest records in the data date back to August 2022, suggesting the breach may be of an older data set.
Retina Group of Florida
September 11, 2024
•[ hack, healthcare ]
RG of FL reported a Hacking/IT Network Server breach (HHS) affecting 152,691 people; activity occurred Nov 69, 2024, detected Nov 9; data potentially include PII/PHI (names, DOB, SSN, DL, medical info); notifications began mid-Sept 2025.
Highline Public Schools
September 8, 2024
•[ hack, education ]
Highline Public Schools, a K-12 district in Washington state, shuts down all schools and cancels school activities after its technology systems were compromised in a cyberattack.
Boulanger
September 6, 2024
•[ hack, leak, retail ]
In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 2M unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum. The data was provided to HIBP by a source who requested it be attributed to "leidhall".
Cultura
September 6, 2024
•[ hack, retail ]
In September 2024, French retailer Cultura was the victim of a cyber attack they attributed to an external IT service provider. The resultant data breach included almost 1.5M unique email addresses along with names, phone numbers, physical addresses and orders. Cultura advised that all affected customers had been notified about the incident.
Tewkesbury Borough Council
September 5, 2024
•[ hack, government ]
The Tewkesbury Borough Council shouts down its systems following a cyber attack.
Transport for London
September 2, 2024
•[ hack, government ]
Transport for London (TfL), the city's transport authority, is investigating an ongoing cyberattack.
Deutsche Flugsicherung
September 1, 2024
•[ hack, government ]
Deutsche Flugsicherung, the German state-owned company responsible for the countrys air traffic control, has confirmed being hit by a cyberattack.
Hesley Group (UK care provider)
September 1, 2024
•[ hack, healthcare ]
In September 2024, a cyberattack against Hesley Group led to unauthorized access to HR folders, with a small amount of sensitive staff data stolen. Exfiltrated information included PII and employment/medical records (names, contact details, bank details, salary, criminal record, medical data, etc.). No encryption or ransomware involved. The attackers remain unidentified. The incident was publicly disclosed in August 2025 after regulatory notifications.
Banham Poultry
August 28, 2024
•[ hack, misconfiguration, manufacturing ]
Banham Poultry, based in Attleborough, said criminals had remotely accessed its system in the early hours of 18 August, stealing the personal details of the staff.
Canvey Island Infant School
August 27, 2024
•[ hack, malware, education ]
Canvey Island Infant School says its IT system has been compromised after being hit by a cyber attack during the summer holiday.
Fur Affinity
August 22, 2024
•[ hack, phishing, technology ]
Fur Affinity, a popular social networking website for the furry community, is compromised, after threat actors successfully gained control of the websites domain, redirecting users to phishing sites, crypto scams and other malicious content.
Halliburton
August 21, 2024
•[ hack, energy ]
Halliburton, one of the world's largest providers of services to the energy industry, confirms a cyberattack that forced it to shut down some of its systems earlier this week.
Zee Media Corporation Limited
August 21, 2024
•[ hack, misconfiguration, technology ]
A group of Bangladeshi hacktivists, operating under the alias SYSTEMADMINBD, defaces the official website of Zee Media Corporation Limited, accusing the media giant of making fun of the situation in Bangladesh, referring to the ongoing floods caused by heavy rainfall.
Monobank
August 19, 2024
•[ hack, ddos, finance ]
Threat actors target Monobank, one of Ukraines most popular online banks with a massive distributed denial-of-service (DDoS) attack, primarily focusing on a service used by Ukrainians to raise donations for the military.
AuthoraCare Collective
August 18, 2024
•[ hack, healthcare ]
Between August 1822, 2024, an unauthorized actor accessed AuthoraCare Collectives network, compromising protected health information of approximately 58,019 people. The review concluded on October 21, 2024, and notification letters were issued January 2, 2025. AuthoraCare offered credit monitoring services to those affected.
North Miami City Hall
August 16, 2024
•[ hack, government ]
A cyber incident leaves the North Miami City Hall closed for nearly a week
Multiple organizations
August 15, 2024
•[ hack, misconfiguration, technology ]
Researchers at Sysdig discover a large-scale malicious operation named "EmeraldWhale" scanning for exposed Git configuration files to steal over 15,000 cloud account credentials from thousands of private repositories.
schenkYOU
August 15, 2024
•[ hack, retail ]
In September 2024, data from the online German gift store schenkYOU was put up for sale on a popular hacking forum. Obtained the month before, the data included 237k unique email addresses alongside names, dates of birth and salted SHA-256 password hashes. The standalone store was subsequently shut down with all traffic redirected to their Amazon store.