One Community Health
April 20, 2021
•[ ransomware, leak, malware ]
Oregon health clinic suffers ransomware attack, exfiltrated data is dumped on Pysa leak site.
University of Wisconsin Health
April 20, 2021
•[ leak, misconfiguration, healthcare ]
UW Health notifies over 4,000 patients of a data breach allowing unauthroized access to their Epic MyChart patient portal.
Metropolitan Police Department of the District of Columbia
April 19, 2021
•[ ransomware, leak, malware ]
The Metropolitan Police Department of the District of Columbia confirms that they suffered a cyberattack after the Babuk ransomware gang leaked screenshots of stolen data.
Jones Family Dental
April 15, 2021
•[ leak, healthcare ]
Jones Family Dental suffers a data breach potentially revealing the personal information of patients.
Houston Rockets
April 15, 2021
•[ ransomware, leak, malware ]
The Houston Rockets are hit by the Babuk ransomware gang that threatens to leak 500 Gb of data.
Celsius Network
April 14, 2021
•[ leak, phishing, finance ]
Cryptocurrency rewards platform Celsius Network discloses a security breach exposing customer information that led to a phishing attack.
WorkForce West Virginia
April 13, 2021
•[ leak, healthcare ]
WorkForce West Virginia suffers a data breach when an unauthorized individual accessed an employment services database.
United Valor Solutions
April 11, 2021
•[ leak, misconfiguration, healthcare ]
Security researcher Jeremiah Fowler discovers a database exposed, containing 200,000 records, containing evidence that the data might be accessed by criminals.
illinois Office of the Attorney General
April 10, 2021
•[ ransomware, leak, malware ]
The operators of the DoppelPaymer ransomware leak a large collection of files from the Illinois Office of the Attorney General.
DigitalOcean
April 9, 2021
•[ leak, technology ]
DigitalOcean emails customers warning of a data breach involving customers' billing data.
Phone House España
April 8, 2021
•[ ransomware, leak, malware ]
In April 2021, the Spanish retailer Phone House allegedly suffered a ransomware attack that also exposed significant volumes of customer data. Attributed to the Babuk ransomware, a collection of data alleged to be a subset of a larger corpus was posted to a dark web site and contained 5.2M email addresses along with names, nationalities, genders, dates of birth, phone numbers and physical addresses. Phone House has been threatened with further releases if a ransom is not paid.
Upstox
April 8, 2021
•[ finance, leak ]
In April 2021, Indian brokerage firm Upstox suffered a data breach. The incident exposed extensive personal information on over 100k customers including names, genders, dates of birth, physical addresses, banking information and passwords stored as bcrypt hashes. Extensive "know your customer" information was also exposed including scans of bank statements, cheques and identity documents complete with Aadhaar numbers. The data was provided to HIBP by a source who requested it be attributed to "white_peacock@riseup.net".
Douglas Elliman
April 7, 2021
•[ leak ]
Thousands of New York residents who live in buildings run by Douglas Elliman's property management arm may have had their personal information compromised after the company's IT network is breached.
Eduro Healthcare
April 7, 2021
•[ ransomware, leak, malware ]
The Astro Team ransomware threat actors dump 40GB patient-related files allegedly from Eduro Healthcare.
Coughlin & Cerhart, LLP
April 5, 2021
•[ leak ]
New York law firm suffers data breach revealing client personal information.
Consolidated High School District 230
April 5, 2021
•[ leak, education ]
Illinois school district suffers attack, 10 GB of data is leaked online.
MobiKwik
March 30, 2021
•[ leak, finance ]
MobiKwik says it is investigating claims of data breach after a website claimed to have exposed private information of nearly 100 million users of the Indian mobile payments startup.
Yeshiva University
March 29, 2021
•[ leak, vulnerability, education ]
TA505 leaks the data belonging to the Yeshiva University stolen exploiting the Accellion vulnerability.
Bases Conversion and Development Authority (BCDA)
March 29, 2021
•[ ransomware, leak, malware ]
Lorenz executed exfiltration of data and ransomeware in targeted network. Data presented on dark web "leak site"
ParkMobile
March 26, 2021
•[ leak, technology ]
Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app that's popular in North America.