Boulanger
September 8, 2024
•[ leak, retail ]
Boulanger, a French retailer, says in a statement that threat actors accessed customers' delivery addresses but no banking data was leaked.
Framingham Heart Study, managed by Boston University
September 8, 2024
•[ leak, education ]
Boston Universitys renowned Framingham Heart Study (FHS) is breached by threat actors, who gained access to the data of participantsboth living and deceasedof the countrys longest running, multigenerational heart study.
Physical Medicine & Rehabilitation Center
September 6, 2024
•[ leak, healthcare ]
The Physical Medicine & Rehabilitation Center posts a notice on its website about an incident in July that affected patients at their New Jersey and New York locations. The Meow Leaks claims responsibility for the attack.
Boulanger
September 6, 2024
•[ hack, leak, retail ]
In September 2024, French electronics retailer Boulanger suffered a data breach that exposed over 27M rows of data. The data included 2M unique email addresses along with names, physical addresses, phone numbers and latitude and longitude. The data was later publicly published to a popular hacking forum. The data was provided to HIBP by a source who requested it be attributed to "leidhall".
Cisco
September 4, 2024
•[ leak, malware, technology ]
Ciscos site for selling company-themed merchandise is offline and under maintenance due to threat actors compromising it with JavaScript code that steals sensitive customer details provided at checkout exploiting CVE-2024-34102.
VK
September 3, 2024
•[ leak, technology ]
A threat actor using the alias HikkI-Chan leaks the personal details of over 390 million VK users (specifically, 390,425,719) on the notorious cybercrime and hacker platform Breach Forums. The data was stolen from a third-party.
Tracelo
September 2, 2024
•[ leak, technology ]
A threat actor using the alias Satanic claims to have breached Tracelo, a smartphone geolocation tracking service. As a result, the hacker has leaked the personal details of over 1.4 million individuals (1,459,014) on the notorious Breach Forums.
Australian Cancer Research Foundation
August 30, 2024
•[ leak, healthcare ]
The Australian Cancer Research Foundation (ACRF) sent an email to its donors late on Friday afternoon, 30 August, warning them of a data security incident.
NHS
August 29, 2024
•[ leak, healthcare ]
Several NHS staff in Scotland have had their mobile phone numbers revealed in a cyber security incident involving a third-party supplier to several health boards.
MC2 Data
August 18, 2024
•[ leak, misconfiguration, technology ]
In August 2024, data aggregator MC2 Data left a database publicly accessible without a password which was subsequently discovered by a security researcher. The breach exposed the personal information of 2.1M subscribers to the service which was marketed under a series of different brand names. The data included email addresses, names and salted SHA-256 password hashes.
Explore Talent (August 2024)
August 15, 2024
•[ leak, misconfiguration, technology ]
In August 2024, a slew of security vulnerabilities were identified with a conglomerate of online services which included the talent network Explore Talent. A vulnerable API exposed the personal records of 11.4M users of the service of which 8.9M unique email addresses were provided to HIBP. This incident is separate to the Explore Talent breach which occurred in 2022 and was loaded into HIBP in July 2024.
Tracki
August 15, 2024
•[ leak, misconfiguration, technology ]
In August 2024, a slew of security vulnerabilities were identified with a conglomerate of online services which included the GPS tracking service Tracki. Multiple vulnerabilities exposed the personal records of 372k users of the service including names and email addresses.
Welhof
August 14, 2024
•[ leak, retail ]
In August 2024, the Dutch appliance store Welhof suffered a data breach. The incident exposed over 100k unique email addresses along with names, physical addresses and the value of purchases made. The data was provided to HIBP by a source who requested it be attributed to "oathnet.ru".
Star Health and Allied Insurance
August 13, 2024
•[ leak, misconfiguration, finance ]
Stolen customer data including medical reports from India's biggest health insurer, Star Health, is publicly accessible via chatbots on Telegram
CreditRiskMonitor
August 7, 2024
•[ leak, finance ]
CreditRiskMonitor, a provider of intelligence and analytics for credit and supply chain professionals, discloses a data breach impacting employees and contractors.
Beech Acres Parenting Center
August 5, 2024
•[ hack, leak, healthcare ]
Beech Acres Parenting Center, a nonprofit in Cincinnati, Ohio, reported a data breach involving unauthorized access from AprilAugust 2024 that exposed employee and client personal information, including SSNs and health-related data. No service disruption or encryption was reported.
Avis
August 3, 2024
•[ leak, automotive ]
American car rental giant Avis notifies over 299,000 customers that unknown attackers breached one of its business applications last month and stole some of their personal information.
Not SOCRadar
August 3, 2024
•[ leak, misconfiguration, technology ]
In August 2024, over 332M rows of email addresses were posted to a popular hacking forum. The post alleged the addresses were scraped from cybersecurity firm SOCRadar, however an investigation on their behalf concluded that "the actor merely utilised functionalities inherent in the platform's standard offerings, designed to gather information from publicly available sources". There is no suggestion the incident compromised SOCRadar's security or posed any risk to their customers. In total, the data set contained 282M unique addresses of valid email address format.
Truffaut
August 1, 2024
•[ leak, retail ]
Truffaut, another retailer in France also suffers a breach impacting around 277,000 records.
Fresnillo PLC
July 30, 2024
•[ hack, leak, manufacturing ]
Fresnillo PLC, the world's largest silver producer and a top global producer of gold, copper, and zinc, said attackers gained access to data stored on its systems during a recent cyberattack.