โŒ

Normal view

There are new articles available, click to refresh the page.
Today โ€” 19 October 2025Main stream

Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees

By: Dissent
18 October 2025 at 20:39
On October 16 and 17, the ScatteredLAPSUS$Hunters Telegram channel repeatedly violated Telegramโ€™s TOS by leaking personal information on people โ€” and in this case, information on employees of the Department of Justice (DOJ/FBI), U.S. Attorneys Office (DOJ/USAO), the Department of Homeland Security (DHS), and the Federal Aviation Authority (FAA). DataBreaches did not report on it...

Source

Yesterday โ€” 18 October 2025Main stream

Data BreachesProsper Data Breach Impacts 17.6 Million Accounts

By: Dissent
17 October 2025 at 19:36
Ionut Arghire reports: More than 17 million individuals were likely impacted by a data breach at peer-to-peer lending marketplace Prosper, data breach notification service Have I Been Pwned warns. Prosper disclosed the incident last month, noting that hackers accessed its network and stole confidential, proprietary, and personal information from its systems. According to the US-based...

Source

Before yesterdayMain stream

Govโ€™t seeks police probe of KT for allegedly obstructing data breach investigation

By: Dissent
16 October 2025 at 06:49
Yonhap News reports: The Ministry of Science and ICT said Monday it has asked the police to investigate allegations that KT obstructed a government probe into the companyโ€™s unauthorized mobile payment breaches. In late August, unauthorized mobile payments worth a combined 240 million won ($168,000) were reported in Seoul and nearby areas after the personal...

Source

Oracle silently fixes zero-day exploit leaked by ShinyHunters

By: Dissent
16 October 2025 at 06:45
Lawrence Abrams reports: Oracle has silently fixed an Oracle E-Business Suite vulnerability (CVE-2025-61884) that was actively exploited to breach servers, with a proof-of-concept exploit publicly leaked by the ShinyHunters extortion group. The flaw was addressed with an out-of-band security update released over the weekend, which Oracle said could be used to access โ€œsensitive resources.โ€ โ€œThis...

Source

Capita hit with ยฃ14m fine for personal data breach in 2023 cyber attack

By: Dissent
15 October 2025 at 09:01
The Information Commissionerโ€™s Office has fined Capita plc and Capita Pension Solutions Ltd a combined ยฃ14m following a cyber attack in April 2023 which saw hackers gain access to over 6m peopleโ€™s data. Stroud News & Journal reports: Outsourcing giant Capita has been fined ยฃ14 million by the Information Commissionerโ€™s Office (ICO) for failing to...

Source

Discord blamed a vendor for its data breach โ€” now the vendor says it was โ€˜not hackedโ€™

By: Dissent
14 October 2025 at 13:42
Jay Peters reports: 5CA is a customer service support company that works with Discord. Recently, the chat platformย said the vendor had been breachedย as part of a โ€œsecurity incidentโ€ where 70,000 government ID photos may have leaked. Now, 5CA saysย in a post on its websiteย that it was โ€œnot hacked.โ€ According to Discord, โ€œthis incident impacted a...

Source

$19M in Settlements Underscore Cybersecurity Risks for TPAs and Insurers

By: Dissent
14 October 2025 at 07:27
Steven L. Imber, Justin T. Liby, Jennifer L. Osborn, Zachary R. Dyer, and Pavel (Pasha) A. Sternberg of Polsinelli PC write: In two separate but related actions, third party administrators (TPAs) and their insurance business partners agreed to substantial settlements to resolve allegations that they failed to adequately safeguard sensitive data from cyberattacks.ย  In the...

Source

Months After Being Notified, a Software Vendor is Still Exposing Confidential and Sealed Court Records

By: Dissent
13 October 2025 at 15:49
In a special edition of โ€œNo need to hack when itโ€™s leaking,โ€ DataBreaches reports on a software vendor that, despite multiple attempts by multiple parties, continues to expose confidential and sealed court records.ย  Overview As a matter of policy, DataBreaches does not publish unredacted stolen or leaked data if it would expose personally identifiable or...

Source

From sizzle to drizzle to fizzle: The massive data leak that wasnโ€™t (1)

By: Dissent
12 October 2025 at 11:52
After days of endlessly urging Salesforce or companies to pay them so that their data would not be leaked, the deadline for Salesforce to pay came and went. And as it went, ScatteredLAPSUS$Hunters leaked data from six of the 39 companies listed on its dark web leak site. But thatโ€™s where the massive leak that...

Source

In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. (1)1)

By: Dissent
11 October 2025 at 14:57
In November 2021, when โ€œg0retranceโ€ defaced the website of the Massachusetts Interscholastic Athletic Association (MIAA) with a message saying โ€œPWNED,โ€ the hacker, who also used the moniker โ€œnetsaosa,โ€ left a message under itย โ€œshould have listened to my emails instead of ignoring me โ€ฆ donโ€™t worry, this is harmless. just to get ur attention :)โ€ Boston.com...

Source

They were victims of a massive data breach in 2009. Interior Health denied it for a decade.

By: Dissent
11 October 2025 at 13:28
Harvey Cashore, Eva Uguen-Csenge,ย  and Mark Kelley report: Kelowna nurse Ashley Stone sits down at her kitchen table, opens a bulky blue folder containing a paper trail of 10 years of multiple frauds committed in her name by imposters and gets right to the point. โ€œItโ€™s just been a nightmare.โ€ She says sheโ€™s had to...

Source

Telstra Denies Scattered Spider Data Breach Claims Amid Ransom Threats

By: Dissent
10 October 2025 at 17:13
IT Security News reports: Telstra, one of Australiaโ€™s leading telecommunications companies, has denied claims made by the hacker group Scattered Spider that it suffered a massive data breach compromising nearly 19 million personal records. The company issued a statement clarifying that its internal systems remain secure and that the data in question was scraped from...

Source

SonicWall Says All Firewall Backups Were Accessed by Hackers

By: Dissent
9 October 2025 at 17:41
Waqas reports: In September 2025, SonicWall reported a data breach of its cloud backup service, stating that fewer than 5% of its customers were affected. At the time, the issue appeared contained and under investigation. That changed today after SonicWall and incident response firm Mandiant confirmed that the attackers had accessed backup configuration files for...

Source

Missing Risk Analysis Cost NY CPA Firm $175Kโ€”But Not the Big Group Whose Data Was Breached in 2019

By: Dissent
9 October 2025 at 09:41
Theresa Defino reports: Covered entities (CEs) and business associates (BAs) might be forgiven if the most recent HHS Office for Civil Rights (OCR) HIPAA enforcement action evoked little more than a yawn. Yes, the $175,000 payment isnโ€™t a particularly large amount, and the sole alleged violation is a retread. Actually, itโ€™s the 10th in OCRโ€™s...

Source

Discord Confirms 70,000 Government IDs Exposed in Third-Party Breach

By: Dissent
9 October 2025 at 07:34
Divya reports: The popular communication platform Discord is confronting a major extortion attempt after cybercriminals breached one of its third-party customer service providers, compromising sensitive user data including government identification photos used for age verification. Threat actors claim to have exfiltratedย 1.5 terabytesย of sensitive information, including overย 2.1 million government-issued identification photos. However,ย Discordย disputes these figures, stating that...

Source

Shad Whiteโ€™s office finds nearly a third of Mississippiโ€™s state agencies fail cybersecurity requirements

By: Dissent
9 October 2025 at 07:16
Stephanie Cunningham reports: According to Mississippi State Auditor Shad White, a third of state offices are at risk of cybercrimes due to not meeting cybersecurity assessment requirements according to a report released yesterday, Tuesday, Oct. 7. Auditor Shad White stated in the release, โ€œPart of our role in my office according to state regulations is...

Source

Policyholder Plot Twist: Cyber Insurer Sues Policyholderโ€™s Cyber Pros

By: Dissent
8 October 2025 at 21:41
Veronica P. Adams and Andrea DeField of Hunton Andrews Kurth write: Last month, Ace American Insurance Company filed a subrogation action against its insuredโ€™s cybersecurity and technology vendors, alleging missteps by the technology companies.ย Seeย Ace American Insurance Company v. Congruity 360, Trustwave Holdings, Case No. 2:25-cv-15657 (D.N.J. Sep. 15, 2025). Ace seeks to recover the $500,000...

Source

Qantas says โ€˜legal protections in placeโ€™ as ScatteredLAPSUS$Hunters group threatens to release personal data

By: Dissent
8 October 2025 at 11:27
NOTE from DataBreaches.net: The injunction Qantas obtained is limited in terms of who it covers. It does NOT cover all journalists and media. It only covers those who are under the jurisdiction of the NSW Supreme Court. Most journalists and media are not covered by the injunction, such as DataBreaches, and many may decide to...

Source

US law firm with major political clients hacked in spying spree linked to China

By: Dissent
8 October 2025 at 09:02
Sean Lyngaas of CNN reports: Suspected Chinese government-backed hackers have breached computer systems of U.S. law firm Williams & Connolly, which has represented some of Americaโ€™s most powerful politicians, as part of a larger spying campaign against multiple law firms, according to a letter the firm sent clients and a source familiar with the hack....

Source

Salesforce Tells Clients It Wonโ€™t Pay Hackers for Extortion

By: Dissent
8 October 2025 at 08:03
Margi Murphy, Jake Bleiberg, and Brody Ford report: Salesforce Inc. told customers Tuesday that it wonโ€™t pay a ransom demand from a hacker who claimed to have stolen a large amount of client data and threatened to publish it, according to an email seen by Bloomberg News. The company said in a security notification that...

Source

โŒ
โŒ