StockX
August 1, 2019
•[ hack, retail ]
StockX, a popular site for buying and selling sneakers and other apparel, resets customer passwords after it is hacked back in May. More than 6.8 million records were stolen.
Randolph County
July 30, 2019
•[ hack, government ]
The Randolph County website is defaced.
Los Angeles Police Department
July 29, 2019
•[ hack, government ]
A suspected hacker claims to have stolen the personal information of about 2,500 LAPD officers, trainees, and recruits, along with approximately 17,500 police officer applicants.
Capital One
July 29, 2019
•[ hack, finance ]
Capital One discloses a data breach impacting 100 million people in the United States, and 6 million in Canada. Data between 2005 and 2019 was accessed and related to information on consumers at the time when they applied for a credit card.
Watertown City School District
July 27, 2019
•[ hack, education ]
The Watertown City School District is the latest to be hit with a cyberattack.
Comodo
July 27, 2019
•[ hack, misconfiguration, technology ]
A hacker gain access to internal files and documents owned by security company and former SSL certificate issuer Comodo by using an email address and password mistakenly exposed on the internet (GitHub).
Club Penguin Rewritten (July 2019)
July 27, 2019
•[ hack, technology ]
In July 2019, the children's gaming site Club Penguin Rewritten (CPRewritten) suffered a data breach (note: CPRewritten is an independent recreation of Disney's Club Penguin game). In addition to an earlier data breach that impacted 1.7 million accounts, the subsequent breach exposed 4 million unique email addresses alongside IP addresses, usernames and passwords stored as bcrypt hashes.
DNForum
July 26, 2019
•[ hack, brute-force, technology ]
DNForum.com sends out password reset requests to its users after attempts to access the accounts.
City of Concord
July 26, 2019
•[ hack, misconfiguration, government ]
The City of Concord website is defaced with offensive images.
Club Penguin Rewritten
July 26, 2019
•[ insider, hack, leak ]
A disgruntled administrator leaves a backdoor in Club Penguin Rewritten (a kids' gaming website) that enabled hackers to steal login data for a little over 4 million accounts.
Brazilian President Jair Bolsonaro
July 25, 2019
•[ hack, government ]
The Brazilian Justice Ministry reveals that cellphones used by President Jair Bolsonaro were a target of cyber attacks.
MGM Resorts
July 25, 2019
•[ hack, leak, misconfiguration ]
In July 2019, MGM Resorts discovered a data breach of one of their cloud services. The breach included 10.6M guest records with 3.1M unique email addresses stemming back to 2017. The exposed data included email and physical addresses, names, phone numbers and dates of birth and was subsequently shared on a popular hacking forum in February 2020 where it was extensively redistributed. The data was provided to HIBP by Under The Breach.
APT17 (AKA Deputy Dog and Axiom)
July 24, 2019
•[ espionage, hack, government ]
Intrusion Truth, an online group of anonymous cyber-security analysts, reveals the details of APT17 (AKA Deputy Dog and Axiom) another cyber-espionage hacking group linked to the Chinese government.
Undisclosed streaming service
July 24, 2019
•[ hack, ddos, technology ]
Researchers from Imperva reveal that an undisclosed streaming service was hit by a massive DDoS attack that lasted for 13 days, launched from 402,000 different IPs, with a peak flow of 292,000 requests per second.
University of Hawaii
July 23, 2019
•[ education, hack, misconfiguration ]
Personal information for as many as 70,000 public school students may have been compromised after Graduation Alliance, a University of Hawaii vendor, detected "suspicious" unauthorized access to one of its servers.
Milton Keynes Council
July 22, 2019
•[ hack, government ]
The planning portal of Milton Keynes Council is crippled by a cyber attack.
Cracked.to
July 21, 2019
•[ hack, technology ]
In July 2019, the hacking website Cracked.to suffered a data breach. There were 749k unique email addresses spread across 321k forum users and other tables in the database. A rival hacking website claimed responsibility for breaching the MyBB based forum which disclosed email and IP addresses, usernames, private messages and passwords stored as bcrypt hashes.
Jessica Alba's Twitter Account
July 20, 2019
•[ hack, technology ]
Jessica Alba's Twitter Account is hacked and starts to post racial tweets.
Midlands Technical College
July 19, 2019
•[ hack, malware, education ]
Cyber criminals hit Midlands Technical College computers with a malware.
Metropolitan Police's Twitter account
July 19, 2019
•[ hack, misconfiguration, education ]
The Metropolitan Police's Twitter account is hit by hackers who post a series of bizarre messages. The breach is due to the compromise of the MyNewsDesk platform.