Reading view
Ceva Logistics Operations Disrupted by Cyberattack
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.
Corporate Data Stolen in Levi Strauss Cyberattack
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.
The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
3.8 Million Impacted by Unlimited Technology Systems Data Breach
Hackers stole personal, medical, and health insurance information from a company’s data center.
The post 3.8 Million Impacted by Unlimited Technology Systems Data Breach appeared first on SecurityWeek.
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion, the Justice Department said Wednesday.
Connor Moucka earned $495,000 by extorting his victims, offering stolen data for sale online, and in one case re-extorted a victim with stolen data of a government official and members of a then-former government official’s immediate family, authorities said.
Moucka and his alleged co-conspirators John Binns and Cameron Wagenius stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.
“Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a statement. “Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.”
Authorities arrested Moucka relatively quickly because he caused significant damage, said Allison Nixon, chief research officer at Unit 221B.
“His gang went on a spree of maximizing harm, which directly correlated to maximizing the resources devoted to stopping it,” she said.
“His behavior was bizarre throughout. Even while stealing data and extorting victims, he did many unnecessary things like threatening me because he thought I was working on his case. I was not working on his case before he threatened me,” Nixon added.
Moucka, who used several aliases online, including “Waifu,” “Judische,” “Catist” and “Ellyel8,” was arrested Oct. 30, 2024, in Kitchener, a city in the Canadian province of Ontario, at the behest of U.S. authorities. He was extradited to the United States in March 2025.
Moucka and his co-conspirators used stolen credentials to access the data storage platform’s customers’ accounts en masse. Records of more than 100 million people were exposed by the data theft campaign, including call and text history records, banking and other financial information, payroll records, government ID numbers and other personally identifiable data.
Officials said victim companies bore more than $9.5 million in losses combined, not including losses attributable to their respective customers.
Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.
Researchers said Moucka and his co-conspirators are all associated with The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion and various forms of cybercrime.
“His legacy is one of failure. He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” Nixon said.
“The pay-or-leak business model was popularized by him and his gang,” and his claims of data deletion were a lie, she added. “With copycat gangs, defenders grapple with the uncertainty of whether the threat actors are honest.”
Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy. He is scheduled for sentencing Oct. 27 and faces up to 32 years in prison.
The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.
Apple’s ‘Private Relay’ Is Exposing Users’ Real IP Addresses
311,000 Impacted by Brown Health Medical Group-MA Data Breach
Hackers stole personal information, medical records, and financial information from the organization’s server.
The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations
The list of people behind companies, foundations and trusteeships is part of efforts to combat money laundering and terror financing.
The post Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations appeared first on SecurityWeek.
River Bank Says Hackers Deleted Data Stolen in Ransomware Attack
The bank holding company was hacked in June, but the investigation into the incident continues.
The post River Bank Says Hackers Deleted Data Stolen in Ransomware Attack appeared first on SecurityWeek.
Brinks Home Discloses Data Breach as Hackers Leak Files
The physical security firm says its alarm monitoring and system functionality have not been affected.
The post Brinks Home Discloses Data Breach as Hackers Leak Files appeared first on SecurityWeek.
CareCloud Data Breach Impacts Over 350,000
In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.
The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek.
FTC and States Act Against Hims & Hers for Deceptive and Unlawful Privacy Practices
Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
ShinyHunters Claims Ernst & Young Hack
Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.
The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.
Origin Energy Data Breach Affects 900,000 Australians
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.
The post Origin Energy Data Breach Affects 900,000 Australians appeared first on SecurityWeek.
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.
The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek.
MCBS Data Breach Affects 1.2 Million Individuals
The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.
The post MCBS Data Breach Affects 1.2 Million Individuals appeared first on SecurityWeek.
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.
The post Data Breach Confirmed After Australian Energy Giant Origin Is Hacked appeared first on SecurityWeek.
Chick-fil-A Accounts Get Fried in Credential Stuffing Attack
Threat actors used credentials obtained from other companies to hack into Chick-fil-A One accounts.
The post Chick-fil-A Accounts Get Fried in Credential Stuffing Attack appeared first on SecurityWeek.
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company.
The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.