Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches

By: Dissent
14 October 2025 at 13:33
NEW YORK – New York Attorney General Letitia James today secured $14.2 million from eight car insurance companies for failing to protect the private information of more than 825,000 New Yorkers. The data breaches were part of a hacking campaign that targeted car insurance companies’ quoting tools and stole people’s personal information, including driver’s license...

Source

Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records

By: Dissent
13 October 2025 at 15:49
In a special edition of “No need to hack when it’s leaking,” DataBreaches reports on a software vendor that, despite multiple attempts by multiple parties, continues to expose confidential and sealed court records.  Overview As a matter of policy, DataBreaches does not publish unredacted stolen or leaked data if it would expose personally identifiable or...

Source

From sizzle to drizzle to fizzle: The massive data leak that wasn’t (1)

By: Dissent
12 October 2025 at 11:52
After days of endlessly urging Salesforce or companies to pay them so that their data would not be leaked, the deadline for Salesforce to pay came and went. And as it went, ScatteredLAPSUS$Hunters leaked data from six of the 39 companies listed on its dark web leak site. But that’s where the massive leak that...

Source

In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. (1)1)

By: Dissent
11 October 2025 at 14:57
In November 2021, when “g0retrance” defaced the website of the Massachusetts Interscholastic Athletic Association (MIAA) with a message saying “PWNED,” the hacker, who also used the moniker “netsaosa,” left a message under it “should have listened to my emails instead of ignoring me … don’t worry, this is harmless. just to get ur attention :)” Boston.com...

Source

Watsonville Community Hospital had a data breach — or two. It would be helpful to know which.

By: Dissent
10 October 2025 at 17:38
On December 8, 2024, DataBreaches reported that Watsonville Community Hospital in California was continuing to respond to what they referred to as a cyberattack on November 29. No gang had claimed responsibility at that point, patients hadn’t been notified yet, and the hospital wasn’t stating whether the attack involved encryption of any files. Weeks later,...

Source

Discord Confirms 70,000 Government IDs Exposed in Third-Party Breach

By: Dissent
9 October 2025 at 07:34
Divya reports: The popular communication platform Discord is confronting a major extortion attempt after cybercriminals breached one of its third-party customer service providers, compromising sensitive user data including government identification photos used for age verification. Threat actors claim to have exfiltrated 1.5 terabytes of sensitive information, including over 2.1 million government-issued identification photos. However, Discord disputes these figures, stating that...

Source

Policyholder Plot Twist: Cyber Insurer Sues Policyholder’s Cyber Pros

By: Dissent
8 October 2025 at 21:41
Veronica P. Adams and Andrea DeField of Hunton Andrews Kurth write: Last month, Ace American Insurance Company filed a subrogation action against its insured’s cybersecurity and technology vendors, alleging missteps by the technology companies. See Ace American Insurance Company v. Congruity 360, Trustwave Holdings, Case No. 2:25-cv-15657 (D.N.J. Sep. 15, 2025). Ace seeks to recover the $500,000...

Source

Just days before its data might be leaked, Qantas Airways obtained a permanent injunction

By: Dissent
4 October 2025 at 16:07
In July, DataBreaches reported that Qantas had obtained a preliminary injunction prohibiting the publication of any customer data stolen from it in a cyberattack by “persons unknown.”  Those defendants were served with the injunction via email and online means. Although Qantas did not reveal who signed the ransom note, ShinyHunters and Scattered Spider didn’t hesitate...

Source

PowerSchool hit by Salesloft Drift campaign, but hackers claim that there is no risk of harm or ransom

By: Dissent
4 October 2025 at 08:36
As noted on Reddit, PowerSchool appears to have been one of many victims of the Salesloft Drift/Salesforce campaign by Scattered LAPSUS$ Hunters. Like many other victims, PowerSchool did not disclose the incident publicly, but they did, however, post a notice in their closed users group. The notice was removed shortly thereafter, and several people have...

Source

More Salesforce customer attacks revealed in new leak site by Scattered LAPSUS$ Hunters (1)

By: Dissent
3 October 2025 at 10:34
In their newest escalation of activities since saying “goodbye” and then determinedly trying to create more chaos on Telegram. the Scattered LAPSUS$ Hunters collective (for lack of a better word right now), has opened up a leak site in both clear net and onion versions. In its debut, the group has targeted Salesforce, and is...

Source

Judge throws out lawsuit against Columbus over data breach

By: Dissent
2 October 2025 at 19:20
Fox28 reports: A Franklin County judge dismissed a lawsuit against the city of Columbus, which claimed it failed to follow industry standards and federal guidelines for data security. The lawsuit was filed last year after the ransomware group Rhysida claimed it stole over 6 terabytes of city data and posted it for sale. The incident caused the city to shut down multiple systems...

Source

AI-driven medical benefits servicer hit with data breach

By: Dissent
1 October 2025 at 06:03
Chad Van Alstin reports: Healthcare Interactive, a company that develops AI-based medical insurance benefit enrollment and billing solutions, confirmed last week that it experienced a data breach that involved personal data from customers being moved offsite by hackers. The exact number of impacted individuals was not revealed. However, the company said stolen data included names,...

Source

Georgia Tech Research Corporation Agrees to Pay $875,000 to Resolve Civil Cyber-Fraud Litigation

By: Dissent
30 September 2025 at 17:51
The governmment continues to enforce contractors’ obligations to adhere to cybersecurity standards in their Department of Defense (DoD, now Department of War) contracts. A press release today reveals another enforcement action: Georgia Tech Research Corporation (GTRC) has agreed to pay the United States $875,000 to resolve allegations that it violated the False Claims Act and federal common...

Source

ApolloMD notifies patients of 11 physician practices affected by a June cyberattack

By: Dissent
26 September 2025 at 12:43
On June 12, 2025, Qilin added ApolloMD to their darkweb leak site with a date of June 6. They claimed to have 238 GB of files. ApolloMD, headquartered in Georgia, is a business associate to hospitals and health systems, providing them with services to enhance clinical operations and patient care, and to optimize financial performance....

Source

‘No Harm, No Foul:’ Courts Take Tougher Line on Data-Breach Suits

By: Dissent
26 September 2025 at 09:06
Angus Loten reports: A deluge of data-breach lawsuits has a growing number of U.S. judges insisting victims show exactly how their leaked personal data caused “tangible harm,” a high bar that is getting more cases tossed out of court. Judges are also requiring plaintiffs to trace any damages back to a particular breach—a tougher condition...

Source

Medical Associates of Brevard notifies 246,711 patients after cyberattack

By: Dissent
19 September 2025 at 11:28
On January 23, 2025, the Bian Lian ransomware gang added the Medical Associates of Brevard (“MAB”) to its dark web leak site. At the time, they listed the types of data they claimed to have acquired, but did not provide any screenshots or proof of claims. Months later, BianLian went offline. What happened to any...

Source

Two teenage suspected Scattered Spider members charged in UK over TfL hack; U.S. unseals charges (1)

By: Dissent
18 September 2025 at 09:36
Alexander Martin reports: Two suspected members of the Scattered Spider cybercrime collective have been arrested and charged in the United Kingdom following an investigation into the hack of Transport for London (TfL) last year. The National Crime Agency (NCA) announced on Thursday that Thalha Jubair, 19, from East London, and Owen Flowers, 18, from Walsall,...

Source

Survival Flight reports second cybersecurity incident in less than a year (1)

By: Dissent
18 September 2025 at 09:08
Survival Flight is an Arizona-headquartered firm that provides ground and air emergency medical transportation services. On August 12, they issued a substitute notice saying that on July 17, they had discovered a cybersecurity incident affecting its IT systems. In their substitute notice, which has not been updated as of this publication, they wrote: The investigation...

Source

JLR ‘cyber shockwave ripping through UK industry’ as supplier share price plummets by 55%

By: Dissent
17 September 2025 at 18:54
Alexander Martin reports: Shares in a British automaker supplier plummeted 55% Wednesday as it warned that a cyberattack on Jaguar Land Rover (JLR) was impacting its business, adding to concerns that the incident is sending a “shockwave” through the country’s industrial sector, according to a senior politician. Shares in Autins, a company providing specialist insulation...

Source

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

By: Dissent
17 September 2025 at 17:23
Lawrence Abrams reports: The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens. For the past year, the threat actors have been targeting Salesforce customers in data theft attacks using social engineering and malicious OAuth applications to breach Salesforce instances and download data. The stolen data...

Source

❌
❌