Singapore Telecommunications
June 15, 2024
•[ espionage, technology ]
The Chinese threat actors from Volt Typhoon reportedly breached Singapore Telecommunications (SingTel) over the summer as part of their ongoing attacks against critical infrastructure operators.
Pure Storage
June 10, 2024
•[ hack, misconfiguration, technology ]
Pure Storage, a leading provider of cloud storage systems and services, confirms that attackers breached its Snowflake workspace and gained access to what the company describes as telemetry information.
Absolute Telecom
June 9, 2024
•[ hack, technology ]
GhostR claims to have stolen over 34 gigabytes of data belonging to Singapore-based telecom company Absolute Telecom PTE Ltd.
mSpy (2024)
June 9, 2024
•[ hack, leak, technology ]
In June 2024, a huge trove of data from spyware maker mSpy was obtained by hacktivists and published online. Comprising of 142GB of user data and support tickets along with 176GB of more than half a million attachments, the data contained 2.4M unique email addresses, IP addresses names and photos. The data was predominantly support tickets seeking help to install the spyware on target devices, whilst the attachments contained various data including screen grans of financial transactions, photos of credit cards and nude selfies.
New York Times
June 8, 2024
•[ leak, misconfiguration, technology ]
The New York Times confirms that internal source code and data was leaked on the 4chan message board after being stolen from the company's GitHub repositories in January 2024.
Multiple organizations
June 3, 2024
•[ hack, malware, technology ]
A massive trove of 361 million email addresses from credentials stolen by password-stealing malware, in credential stuffing attacks, and from data breaches is added to the Have I Been Pwned data breach notification service.
Official Microsoft India account on X (formerly Twitter)
June 3, 2024
•[ financial, hack, phishing ]
The official Microsoft India account on X (formerly Twitter), with over 211,000 followers, is hijacked by cryptocurrency scammers to impersonate Roaring Kitty, the handle used by notorious meme stock trader Keith Gill.
Hugging Face
May 31, 2024
•[ hack, technology ]
AI platform Hugging Face says that its Spaces platform was breached, allowing threat actors to access authentication secrets for its members.
Internet Archive
May 26, 2024
•[ hack, ddos, technology ]
The Internet Archive is hit with a prolonged DDoS attack.
pcTattletale
May 25, 2024
•[ hack, sqlinjection, technology ]
In May 2024, the spyware service pcTattletale suffered a data breach that defaced the website and posted tens of gigabytes of data to the homepage, allegedly due to pcTattletale not responding to a previous security vulnerability report. The breach exposed data including membership records, infected PC names, captured messages and extensive logs of IP addresses and device information.
Everbridge
May 21, 2024
•[ hack, technology ]
Everbridge, an American software company focused on crisis management and public warning solutions, notifies customers that unknown attackers had accessed files containing business and user data in a recent corporate systems breach.
BBC
May 21, 2024
•[ leak, misconfiguration, technology ]
The BBC discloses a data security incident that occurred on May 21, involving unauthorized access to files hosted on a cloud-based service, compromising the personal information of BBC Pension Scheme members.
Patriot Mobile
May 21, 2024
•[ leak, technology ]
U.S. cell carrier Patriot Mobile experiences a data breach that included subscribers personal information, including full names, email addresses, home ZIP codes and account PINs.
Ticketmaster
May 20, 2024
•[ leak, misconfiguration, technology ]
Live Nation confirms that Ticketmaster suffered a data breach after its data was stolen from a third-party cloud database provider, which is believed to be Snowflake. The data of 560 million users is potentially affected.
Newsquest Media Group
May 13, 2024
•[ hack, technology ]
A group declaring itself to be first-class Russian hackers deface potentially hundreds of local and regional British newspaper websites belonging to Newsquest Media Group.
Balticom
May 9, 2024
•[ hack, technology ]
Balticom, a Latvian television network, is also hijacked to air the Moscow parade
PyPI
May 9, 2024
•[ hack, malware, technology ]
GhostAction abused malicious GitHub Actions workflows to exfiltrate thousands of secrets (incl. PyPI tokens). PyPI found no evidence of malicious package publishes, revoked affected tokens, and issued guidance; campaign window early Sept 2025
The Post Millennial
May 2, 2024
•[ hack, misconfiguration, technology ]
In May 2024, the conservative news website The Post Millennial suffered a data breach. The breach resulted in the defacement of the website and links posted to 3 different corpuses of data including hundreds of writers and editors (IP, physical address and email exposed), tens of thousands of subscribers to the site (name, email, username, phone and plain text password exposed), and tens of millions of email addresses from thousands of mailing lists alleged to have been used by The Post Millennial (this has not been independently verified). The mailing lists appear to be sourced from various campaigns not necessarily run by The Post Millennial and contain a variety of different personal attributes including name, phone and physical address (depending on the campaign). The data was subsequently posted to a popular hacking forum and extensively torrented.
Brosix and Chatox
May 1, 2024
•[ hack, misconfiguration, technology ]
Brosix and Chatox promised secure messaging, but threat actors accessed unprotected backups containing highly sensitive pharmacy and patient communications
Multiple Airlines
April 25, 2024
•[ espionage, ddos, technology ]
State officials from Lithuania and Estonia blame Russia for GPS jamming of commercial flights.