Shadow PC
October 11, 2023
•[ leak, manufacturing ]
Shadow PC, a provider of high-end cloud computing services, warns customers of a data breach that exposed customers' private information, as a threat actor claims to be selling the stolen data for over 500,000 customers.
FBI's Law Enforcement Enterprise Portal (LEEP)
October 3, 2023
•[ leak, government ]
A dark web user dubbed @FEDCREDS is found selling account credentials allegedly from the Law Enforcement Enterprise Portal (LEEP).
23andMe
October 2, 2023
•[ leak, brute-force, healthcare ]
23andMe confirms to be aware of user data from its platform circulating on hacker forums and attributes the leak to a credential-stuffing attack.
Prestige Care and Prestige Senior Living
October 2, 2023
•[ ransomware, leak, healthcare ]
The ALPHV (BlackCat) ransomware lists Prestige Care and Prestige Senior Living in their leak site, claiming to have 260 GB of files.
Cascade Family Dental
October 1, 2023
•[ ransomware, leak, healthcare ]
The Monti ransomware group adds Cascade Family Dental to their leak site
Facebook Marketplace
October 1, 2023
•[ leak, hack, technology ]
In February 2024, 200k Facebook Marketplace records allegedly obtained from a Meta contractor in October 2023 were posted to a popular hacking forum. The data contained 77k unique email addresses alongside names, phone numbers, Facebook profile IDs and geographic locations. The data also contained bcrypt password hashes, although there is no indication these belong to the corresponding Facebook accounts.
Fairmont Federal Credit Union
September 30, 2023
•[ leak, financial, finance ]
Between September 30 and October 18, 2023, Fairmont Federal Credit Union in West Virginia experienced unauthorized access to its internal file servers and databases. Attackers exfiltrated sensitive personal, financial, and limited medical information of about 187,000 members. No data encryption or ransomware activity was reported.
Arietis Health
September 28, 2023
•[ leak, sqlinjection, healthcare ]
Arietis Health is added to the list of entities affected by the MOVEit breach. 1,975,066 individuals are affected.
Blue Ridge Electric Membership Corporation
September 27, 2023
•[ leak, energy ]
Blue Ridge Electric Membership Corporation (Blue Ridge Energy) files a notice after discovering that a data breach at Meridian, one of Blue Ridge Energy's vendors, experienced a data security incident.
GI Medical Services
September 27, 2023
•[ leak, healthcare ]
Lost Trust Team adds GI Medical Services in New York to a new leak site.
European Telecommunications Standards Institute (ETSI)
September 27, 2023
•[ leak, technology ]
The European Telecommunications Standards Institute (ETSI) reveals that threat actors have stolen a database identifying its users.
West Virginia University Health System
September 26, 2023
•[ leak, sqlinjection, healthcare ]
West Virginia University Health System posts a website notice informing patients of a third-party data breach involving an incident that occurred at Nuance Communications exploiting the MOVEit vulnerability.
Sony
September 26, 2023
•[ hack, leak, retail ]
Sony it is investigating allegations of a cyberattack as different hackers have stepped up to claim responsibility for the purported hack and the subsequent leak of 3.14 GB of data.
Hospital for Sick Children (SickKids)
September 25, 2023
•[ leak, healthcare ]
The Hospital for Sick Children, more commonly known as SickKids, discloses to be among the healthcare providers impacted by the recent breach at BORN Ontario.
Okta
September 23, 2023
•[ leak, technology, healthcare ]
Okta warns nearly 5,000 current and former employees that their personal information was exposed after Rightway Healthcare, a third-party vendor was breached.
OpenSea
September 23, 2023
•[ leak, misconfiguration, finance ]
A third-party security incident may have reportedly exposed user information of NFT marketplace OpenSea, including API keys.
CSC ServiceWorks
September 23, 2023
•[ leak ]
CSC ServiceWorks, a leading provider of commercial laundry services and air vending solutions, discloses a data breach after the personal information of over 35,000 individuals was exposed in a 2023 cyberattack.
UBS Financial Services
September 22, 2023
•[ leak, malware, finance ]
Sovos Compliance files another notice of data breach on behalf of UBS Financial Services affected by a data breach at Sovos involving the MOVEit file transfer application.
Celink
September 22, 2023
•[ leak, sqlinjection, finance ]
Sovos Compliance files another notice of data breach on behalf of Celink affected by a data breach at Sovos involving the MOVEit file transfer application.
Mulkay Cardiology Consultants
September 22, 2023
•[ ransomware, leak, healthcare ]
The NoEscape ransomware gang lists Mulkay Cardiology Consultants to their leak site, claiming to have stolen 60GB of data on more than 30,000 patients.