National Public Data
April 9, 2024
•[ leak, technology ]
In April 2024, a large trove of data made headlines as having exposed "3 billion people" due to a breach of the National Public Data background check service. The initial corpus of data released in the breach contained billions of rows of personal information, including US social security numbers. Further partial data sets were later released including extensive personal information and 134M unique email addresses, although the origin and accuracy of the data remains in question. This breach has been flagged as "unverified" and a full description of the incident is in the link above.
Home Depot
April 6, 2024
•[ leak, misconfiguration, retail ]
Home Depot confirms that it suffered a data breach after one of its SaaS vendors mistakenly exposed a small sample of limited employee data, which could potentially be used in targeted phishing attacks.
boAt
April 5, 2024
•[ leak, retail ]
A threat actor, with the moniker "ShopifyGUY," leaks personal information belonging to 7.5 million of customers of boAt, a consumer electronics company in India.
Diabetes WA
April 2, 2024
•[ leak, healthcare ]
Diabetes WA discloses a data breach affecting people who engaged with its telehealth service.
City of Hope
April 2, 2024
•[ leak, healthcare ]
Cancer treatment and research center City of Hope warns that a data breach exposed the sensitive information of over 820,000 patients.
Undisclosed organizations in El Salvador
April 1, 2024
•[ leak ]
Researchers from Resecurity identify a massive leak of the personally identifiable information (PII) of over five million citizens from El Salvador on the Dark Web, impacting more than 80% of the countrys population.
Nottingham Rehab Supplies Healthcare
March 30, 2024
•[ ransomware, leak, malware ]
Multiple UK councils warned that citizens personal data may have been breached following a ransomware attack on a medical equipment supplier Nottingham Rehab Supplies (NRS) Healthcare. RansomHub said it successfully breached the firm on 30 March, stealing hundreds of thousands of sensitive documents.
"More than 600k private documents was downloaded, including: Accounting, HR, Financial reports, Reception, Contracts and much more, the group said on its leak site.
Samsung Germany Customer Tickets
March 30, 2024
•[ leak, malware, technology ]
In March 2025, data from Samsung Germany was compromised in a data breach of their logistics provider, Spectos. Allegedly due to credentials being obtained by malware running on a Spectos employee's machine, the breach included 216k unique email addresses along with names, physical addresses, items purchased from Samsung Germany and related support tickets and shipping tracking numbers.
Giant Tiger
March 25, 2024
•[ leak, retail ]
A threat actor claims responsibility for a data breach to Giant Tiger and leaks 2.8 million customer records on a forum.
boAt
March 25, 2024
•[ leak, manufacturing ]
In March 2024, the Indian audio and wearables brand boAt suffered a data breach that exposed 7.5M customer records. The data included physical and email address, names and phone numbers, all of which were subsequently published to a popular clear web hacking forum.
Emergency Medical Services Authority
March 22, 2024
•[ leak, malware, healthcare ]
Emergency Medical Services Authority (EMSA) says, it identified suspicious activity in its IT network and is mailing letters to patients whose information may have been involved.
KIM
March 20, 2024
•[ leak, technology ]
The Russian threat actors from UAC-0165 disrupts the network of KIM, a local ISP in Ukraine and claims to have obtained the client database and internal documentation.
AT&T
March 16, 2024
•[ leak, technology ]
Two threat actors (ShinyHunters and MajorNelson) put on sale 71 million records allegedly stolen from AT&T in 2021. However the company claims the data did not originate from its systems. Approximately one month later AT&T confirms the breach adding that the real number of impacted users is 51 million.
National Diagnostic Imaging
March 16, 2024
•[ leak, healthcare ]
Birth Choice of San Marcos notifies patients of a breach at National Diagnostic Imaging.
France Travail
March 13, 2024
•[ leak, government ]
France Travail, formerly known as Ple Emploi, warns that threat actors breached its systems and may leak or exploit personal details of an estimated 43 million individuals.
Mintlify
March 13, 2024
•[ leak, misconfiguration, technology ]
Documentation startup Mintlify says dozens of customers had GitHub tokens exposed in a data breach at the start of the month.
Panda Restaurant Group
March 10, 2024
•[ leak ]
Panda Restaurant Group discloses a data breach after threat actors compromised its corporate systems and stole the personal information of an undisclosed number of associates.
Giant Tiger
March 4, 2024
•[ leak, misconfiguration, retail ]
In March 2024, Canadian discount store Giant Tiger suffered a data breach that exposed 2.8M customer records. Attributed to a vendor of the retailer, the breach included physical and email addresses, names and phone numbers.
Fair Vote Canada
March 2, 2024
•[ leak, misconfiguration, government ]
In March 2024, the Canadian national citizens' campaign for proportional representation Fair Vote Canada suffered a data breach. The incident was attributed to "a well-meaning volunteer" who inadvertently exposed data from 2020 which included 134k unique email addresses, names, physical addresses, phone numbers and, for some individuals, date and amount of a donation.
Mr Green Gaming
March 1, 2024
•[ leak, misconfiguration ]
Mr Green Gaming, a game community, suffers a breach when an inactive admin account is exploited, resulting in the leak of personal details belonging to 27,000 members.