Covve
February 20, 2020
•[ leak, misconfiguration, technology ]
In February 2020, a massive trove of personal information referred to as "db8151dd" was provided to HIBP after being found left exposed on a publicly facing Elasticsearch server. Later identified as originating from the Covve contacts app, the exposed data included extensive personal information and interactions between Covve users and their contacts. The data was provided to HIBP by dehashed.com.
Monroe County Hospital & Clinics
February 17, 2020
•[ leak, phishing, healthcare ]
More than 7,000 patients of Monroe County Hospital & Clinics are notified that their personal information may have been leaked in a phishing attack occurred on December 2019.
Slickwraps
February 16, 2020
•[ leak, retail ]
In February 2020, the online store for consumer electronics wraps Slickwraps suffered a data breach. The incident resulted in the exposure of 858k unique email addresses across customer records and newsletter subscribers. Additional impacted data included names, physical addresses, phone numbers and purchase histories.
Bear Creek High
February 15, 2020
•[ leak, education ]
School officials in Lodi are investigating after student data is breached at two different schools: Bear Creek High and Ronald E. McNair High.
Straffic
February 14, 2020
•[ leak, misconfiguration, technology ]
In February 2020, Israeli marketing company Straffic exposed a database with 140GB of personal data. The publicly accessible Elasticsearch database contained over 300M rows with 49M unique email addresses. Exposed data also included names, phone numbers, physical addresses and genders. In their breach disclosure message, Straffic stated that "it is impossible to create a totally immune system, and these things can occur".
Nedbank
February 13, 2020
•[ leak, finance ]
Nedbank discloses a security incident that impacts the personal details of 1.7 million users. The bank says the breach occurred at Computer Facilities (Pty) Ltd, a South African company the bank was using to send out marketing and promotional campaigns.
FHN
February 12, 2020
•[ leak, healthcare ]
Illinois healthcare system FHN notifies its patients of a data breach that occurred in February.
Home Chef
February 10, 2020
•[ leak, retail ]
In early 2020, the food delivery service Home Chef suffered a data breach which was subsequently sold online. The breach exposed the personal information of almost 9 million customers including names, IP addresses, post codes, the last 4 digits of credit card numbers and passwords stored as bcrypt hashes. The data was provided to HIBP by dehashed.com.
Idaho Central Credit Union
February 6, 2020
•[ leak, finance ]
Idaho Central Credit Union informs some customers of two data breaches that impacted the financial institution.
NEC
January 30, 2020
•[ leak, malware, manufacturing ]
NEC confirms to have been hit with a cyberattack since 2018 that resulted in unauthorized access to its internal network and the exposure of 28,000 files.
An Ukrainian government job portal
January 21, 2020
•[ leak, misconfiguration, government ]
The https://career.gov.ua has leaked the personal data of an unidentified number of job applicants. It is unclear whether the leak was a result of cyberattack or human error.
100 UPS Store Locations
January 21, 2020
•[ leak, phishing, retail ]
Sensitive personal and financial information of UPS Store customers is exposed in a phishing incident affecting roughly 100 local store locations between September 29, 2019, and January 13, 2020.
Mitsubishi Electric
January 20, 2020
•[ leak, manufacturing ]
Mitsubishi Electric discloses a security breach that might have caused the leak of personal and confidential corporate information. The breach was detected on June 28, 2019. It was later revealed that the breach may have resulted in the theft of data on a hypersonic missile.
LimeLeads
January 14, 2020
•[ leak, misconfiguration, technology ]
49 million user records extracted from a misconfigured Elasticsearch database by US data broker LimeLeads are put up for sale online.
MobiFriends
January 6, 2020
•[ leak, technology ]
In January 2020, the Barcelona-based dating app MobiFriends suffered a data breach that exposed 3.5 million unique email addresses. The data also included usernames, genders, dates of birth and MD5 password hashes. The data was provided to HIBP by a source who requested it be attributed to "white_peacock@riseup.net".
HTC Mania
January 4, 2020
•[ hack, leak, technology ]
In January 2020, the Spanish mobile phone forum HTC Mania suffered a data breach of the vBulletin based site. The incident exposed 1.5M member email addresses, usernames, IP addresses, dates of birth and salted MD5 password hashes and password histories. Data from the breach was subsequently redistributed on popular hacking websites.
Alomere Health
January 3, 2020
•[ leak, healthcare ]
The personal and medical information of 49,351 patients is exposed following a security incident involving two employees' email accounts.
Filmai.in
January 1, 2020
•[ leak, misconfiguration, technology ]
In approximately 2019 or 2020, the Lithuanian movie streaming service Filmai.in suffered a data breach exposing 645k email addresses, usernames and plain text passwords.
National Health Information Center (NCZI) of Slovakia
January 1, 2020
•[ leak, misconfiguration, healthcare ]
poor security
Unknown agency(believed to be tied to United States Census Bureau)
January 1, 2020
•[ leak, misconfiguration, financial ]
accidentally published