Posts

Showing posts with the label Data Breach

UK govt links 2021 Electoral Commission breach to Exchange server

Image
By Sergiu Gatlan,  Bleeping Computer The United Kingdom's Information Commissioner's Office (ICO) revealed today that the Electoral Commission was breached in August 2021 because it failed to patch its on-premise Microsoft Exchange Server against ProxyShell vulnerabilities. In March, the U.K. National Cyber Security Centre (NCSC) attributed the UK Electoral Commission breach to a Chinese state-backed threat actor. Tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207, these security flaws were chained to hack into the commission's Exchange Server 2016 and deploy web shells, which allowed the attackers to gain persistence after installing web shells and backdoors. While Microsoft released security updates in May 2021 that fixed the ProxyShell vulnerability chain, the commission failed to patch its systems promptly, exposing them to attacks. The attack and the deployed malware were discovered on October 28, 2021, when an employee found that the Commission's Exchan...

HealthEquity says data breach impacts 4.3 million people

Image
By Bill Toulas,  Bleeping Computer HSA provider HealthEquity has determined that a cybersecurity incident disclosed earlier this month has compromised the information of 4,300,000 people. HealthEquity, one of the largest HSA custodians in the U.S., specializes in providing health savings accounts (HSAs), flexible spending accounts (FSAs), health reimbursement arrangements (HRAs), and 401(k) retirement plans. In a Form 8-K filing submitted on July 2, 2024, the company disclosed that threat actors stole members' sensitive health data using a partner's compromised credentials. An investigation determined that the breach occurred on March 9, 2024, but was only verified by the firm on June 26, following an internal investigation. "We discovered some unauthorized access to and potential disclosure of protected health information and/or personally identifiable information stored in an unstructured data repository outside our core systems," reads the data breach notice to be...

Crooks Steal Phone, SMS Records for Nearly All AT&T Customers

Image
By  KrebsOnSecurity AT&T Corp . disclosed today that a new data breach has exposed phone call and text message records for roughly 110 million people — nearly all of its customers. AT&T said it delayed disclosing the incident in response to “national security and public safety concerns,” noting that some of the records included data that could be used to determine where a call was made or text message sent. AT&T also acknowledged the customer records were exposed in a cloud database that was protected only by a username and password (no multi-factor authentication needed). In a regulatory filing with the U.S. Securities and Exchange Commission today, AT&T said cyber intruders accessed an AT&T workspace on a third-party cloud platform in April, downloading files containing customer call and text interactions between May 1 and October 31, 2022, as well as on January 2, 2023. The company said the stolen data includes records of calls and texts for mobile providers...

A hacker posted nearly 10 billion passwords online- likely the biggest leak ever

Image
By  Hindustan Times This could be the largest such compilation of leaked passwords ever and the file contains passwords compromised in both recent and old data breaches. A file containing almost 10 billion passwords was reportedly posted on an online hacking forum. This could be the largest such compilation of leaked passwords ever and the file contains passwords compromised in both recent and old data breaches all over the world, Semafor reported. Owing to this, there could be an increased chance of credential stuffing attacks in which one compromised password used for a user’s account can be reused by a hacker to break into another account. The report claimed that not all the passwords in the file appeared to be new which means that they have been leaked previously and this increases the chance of “credential stuffing.” As per the practice, a bad actor can take a user’s known password and try to reuse it to break into other accounts in their name, Cybernews, a cybersecurity-focus...

Former IT employee accessed data of over 1 million US patients

Image
By Bill Toulas,  Bleeping Computer Geisinger , a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of Nuance , an IT services provider contracted by the organization. Geisinger is a non-profit organization that operates 134 care sites, ten hospitals, and the Geisinger Health Plan, serving a total of 1.2 million people. It employs 26,000 staff, including 1,600 doctors, and is considered one of Pennsylvania’s most important organizations. An announcement published earlier this week explains that in November 2023, Geisinger detected unauthorized access to its patients’ database by a former Nuance employee. Nuance was promptly informed and took action to block the former employee’s access to Geisinger’s systems holding patient records. “On Nov. 29, 2023, Geisinger discovered and immediately notified Nuance that a former Nuance employee had accessed certain Geisinger patient information two days after the employee had been terminated,” ...

Change Healthcare lists the medical data stolen in ransomware attack

Image
By Lawrence Abrams,  Bleeping Computer UnitedHealth has confirmed for the first time what types of medical and patient data were stolen in the massive Change Healthcare ransomware attack, stating that data breach notifications will be mailed in July. On Thursday, the company published a data breach notification warning that the ransomware attack exposed a "substantial quantity of data" for a "substantial proportion of people in America." While UnitedHealth has not explicitly shared how many people were affected, UnitedHealth CEO Andrew Witty stated during a congressional hearing that "maybe a third" of all American's health data was exposed in the attack. According to the data breach notification, a massive trove of sensitive information was stolen, including: Health insurance information (such as primary, secondary or other health plans/policies, insurance companies, member/group ID numbers, and Medicaid-Medicare-government payor ID numbers); Health i...

London hospitals cancel over 800 operations after ransomware attack

Image
By Sergiu Gatlan,  Bleeping Computer NHS England revealed today that multiple London hospitals impacted by last week’s Synnovis ransomware attack were forced to cancel hundreds of planned operations and appointments. Formerly known as Viapath, Synnovis was established as GSTS Pathology in 2009 and switched to the Synnovis brand in October 2022. The organization was established as a partnership between SYNLAB UK & Ireland, Guy's and St Thomas' NHS Foundation Trust, and the King's College Hospital NHS Foundation Trust. Ongoing service disruptions at Guy's and St Thomas' NHS Foundation Trust, King's College Hospital NHS Foundation Trust, and primary care providers across South East London result from Synnovis being locked out of its systems by a June 3 attack linked to the Qilin ransomware operation. While memos issued by hospital officials revealed this "ongoing critical incident" has had a "major impact" on their procedures and operations ...

Nissan North America data breach impacts over 53,000 employees

Image
By Bill Toulas,  Bleeping Computer Nissan North America (Nissan) suffered a data breach last year when a threat actor targeted the company's external VPN and shut down systems to receive a ransom. The car maker discovered the breach in early November 2023 and discovered recently that the incident exposed personal data belonging to more than 53,000 current and former employees. “As shared during the Nissan Town Hall meeting on December 5, 2023, Nissan learned on November 7, 2023, that it was the victim of a targeted cyberattack. Upon learning of the attack, Nissan promptly notified law enforcement and began taking immediate actions to investigate, contain, and successfully terminate the threat,” the company said in a notification to impacted individuals. Nissan disclosed that the threat actor targeted its external VPN and then shut down certain company systems before asking for a ransom. The company notes that none of its systems were encrypted during the attack. Working with extern...

Singing River Health System: Data of 895,000 stolen in ransomware attack

Image
By Bill Toulas,  Bleeping Computer The Singing River Health System is warning that it is now estimating that 895,204 people are impacted by a ransomware attack it suffered in August 2023. Singing River Health System is a major healthcare provider located in Mississippi, operating the Singing River Hospital in Pascagoula, Ocean Springs Hospital , and the Singing River Gulfport Hospital , collectively providing over 700 beds. The health system, which employs over 3,500 people, also operates two hospices, four pharmacies, six imaging centers, ten specialty centers, and twelve medical clinics in the Gulf Coast region. On August 19, 2023, Singing River announced that it had been targeted by a sophisticated ransomware attack, which resulted in operational disruptions at its hospitals and potentially data theft. Singing River was added to the HHS' Office for Civil Rights breach portal in late August, with a temporary figure of 501 impacted individuals. On September 13, 2023, the healthca...

Dell hacker claims they had access to systems for nearly three weeks

Image
By Solomon Klappholz, IT Pro The hacker trying to sell a Dell database containing 49 million customer records claims he was able to persist on the company’s systems for several weeks The threat actor behind the recent Dell data breach that exposed 49 million customer records claims they were able to access internal systems for weeks before being discovered.  The hacker, Menelik, was reported to be selling access to a database storing 49 million records related to systems purchased from Dell between 2017 and 2024. Dell disclosed the breach on 9 May, notifying customers that their names, addresses, and Dell customer info were exposed, warning them to watch out for social engineering attacks impersonating the technology giant. Menelik told TechCrunch they were able to gain access to the database by registering several accounts on a Dell portal as a partner that resells Dell products and services. According to Menelik, the process of registering and being approved as a partner was re...

Dell warns of data breach, 49 million customers allegedly affected

Image
By Lawrence Abrams, Bleeping Computer Dell is warning customers of a data breach after a threat actor claimed to have stolen information for approximately 49 million customers. The computer maker began emailing data breach notifications to customers yesterday, stating that a Dell portal containing customer information related to purchases was breached. "We are currently investigating an incident involving a Dell portal, which contains a database with limited types of customer information related to purchases from Dell," reads a Dell data breach notification. "We believe there is not a significant risk to our customers given the type of information involved." Dell states that the following information was accessed by the threat actor during the breach: Name Physical address Dell hardware and order information, including service tag, item description, date of order, and related warranty information The company stresses that the stolen information does not include fina...

Conservative News Websites Hacked, Replaced With Page Leaking Private Information

Image
By Charlie Nash,  Mediaite Two conservative news websites – Human Events and The Post Millennial – were hacked on Thursday evening and replaced with a page leaking private information. Both websites were taken down by unnamed hackers and replaced with a fake coming out letter purported to be written by Post Millennial senior editor Andy Ngo. “Dear Readers of The Post Millennial, I am writing to you today to share something deeply personal and important to me,” the letter opened. “After much soul-searching, I have come to the realization that I am a trans individual, and I would like to officially introduce myself as Angelina Ngo, a woman.” At the end of the letter, the hacker concluded, “P.S. I am also sharing with you all of our mailing lists, our subscriber database and the personal details of all our writers and editors,” along with links to download the private information. The official Twitter accounts for both Human Events and The Post Millennial – which was acquired by ...

Kaiser Permanente: Data breach may impact 13.4 million patients

Image
By Bill Toulas, Bleeping Computer Healthcare service provider Kaiser Permanente disclosed a data security incident that may impact 13.4 million people in the United States. Kaiser Permanente is an integrated managed care consortium and one of the largest nonprofit health plans in the U.S. It operates 40 hospitals and 618 medical facilities in California, Colorado, the District of Columbia, Georgia, Hawaii, Maryland, Oregon, Virginia, and Washington. In a statement, the organization said that information from "approximately 13.4 million current and former members and patients" was leaked to third-party trackers installed on its websites and mobile applications. “Kaiser Permanente has determined that certain online technologies, previously installed on its websites and mobile applications, may have transmitted personal information to third-party vendors Google, Microsoft Bing, and X (Twitter) when members and patients accessed its websites or mobile applications” - Kaiser Perma...

American Express credit cards exposed in third-party data breach

Image
By Lawrence Abrams,  Bleeping Computer American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant processor was hacked. This incident was not caused by a data breach at American Express, but rather at a merchant processor in which American Express Card member data was processed.  In a data breach notification filed with the state of Massachusetts under "American Express Travel Related Services Company," the company warned customers their credit cards may have been stolen. "We became aware that a third party service provider engaged by numerous merchants experienced unauthorized access to its system," explains the data breach notification. "Account information of some of our Card Members, including some of your account information, may have been involved. It is important to note that American Express owned or controlled systems were not compromised by this incident, and we are providing this notice to you a...

Digital security giant Entrust breached by ransomware gang

Image
By Lawrence Abrams,  Bleeping Computer Digital security giant Entrust has confirmed that it suffered a cyberattack where threat actors breached their network and stole data from internal systems. Entrust is a security firm focused on online trust and identity management, offering a wide range of services, including encrypted communications, secure digital payments, and ID issuance solutions. Depending on what data was stolen, this attack could impact a large number of critical, and sensitive, organizations who use Entrust for identity management and authentication.  This includes US government agencies, such as the Department of Energy, Department of Homeland Security, the Department of the Treasury, the Department of Health & Human Services, the Department of Veterans Affairs, the Department of Agriculture, and many more.

Neopets data breach exposes personal data of 69 million members

By Lawrence Abrams,  Bleeping Computer Virtual pet website Neopets has suffered a data breach leading to the theft of source code and a database containing the personal information of over 69 million members. Neopets is a popular website where members can own, raise, and play games with their virtual pets. Neopets recently launched NFTs that will be used as part of an online Metaverse game. On Tuesday, a hacker known as 'TarTarX' began selling the source code and database for the Neopets.com website for four bitcoins, worth approximately $94,000 at today's prices. In a conversation with BleepingComputer, TarTarX says that they stole the database and approximately 460MB (compressed) of source code for the neopets.com website. The seller claims that this database contains the account information of over 69 million members, and in a screenshot shared with BleepingComputer, you can see the data includes members' usernames, names, email addresses, zip code, date of birth, ge...

Hackers steal 50,000 credit cards from 300 U.S. restaurants

By Bill Toulas,  Bleeping Computer Payment card details from customers of more than 300 restaurants have been stolen in two web-skimming campaigns targeting three online ordering platforms. Web-skimmers, or Magecart malware, are typically JavaScript code that collects credit card data when online shoppers type it on the checkout page. Recently, Recorded Future’s threat detection tools identified two Magecart campaigns injecting malicious code into the online ordering portals of MenuDrive, Harbortouch, and InTouchPOS. As a result, 50,000 payment cards were stolen and have already been offered for sale on various marketplaces on the dark web.

Software Engineer Joshua Schulte Convicted In Biggest Theft Ever Of CIA Secrets

By Larry Neumeister and Tom Hays,  Huffpost A former CIA software engineer was convicted Wednesday of federal charges accusing him of the biggest theft of classified information in CIA history. Joshua Schulte, who chose to defend himself at a New York City retrial, had told jurors in closing arguments that the CIA and FBI made him a scapegoat for an embarrassing public release of a trove of CIA secrets by WikiLeaks in 2017. Schulte watched without visibly reacting as U.S. District Judge Jesse M. Furman announced the guilty verdict on nine counts, which was reached in mid-afternoon by a jury that had deliberated since Friday. The so-called Vault 7 leak revealed how the CIA hacked Apple and Android smartphones in overseas spying operations, and efforts to turn internet-connected televisions into listening devices. Prior to his arrest, Schulte had helped create the hacking tools as a coder at the agency’s headquarters in Langley, Virginia. A sentencing date was not immediately set bec...

City contractor goes out for drinks after work, loses memory stick containing personal data on nearly half a million residents

By CBS A Japanese city has been left with more than a headache after admitting a contractor lost a USB containing personal data on all 460,000 residents during a night out. The western city of Amagasaki said Thursday that a private contractor, whose name has not been disclosed, was carrying the memory stick when he went to have drinks after work. But the individual, who was working on a municipal pandemic relief program, lost the bag containing the USB on Tuesday evening.  "We deeply regret that we have profoundly harmed the public's trust in the administration of the city," an Amagasaki official told a press conference. The information was copied onto the USB to facilitate its transfer to a call center in nearby Osaka. It included the names, genders, addresses, birthdays and other personal information of all the city's residents, as well as tax data and bank account information on some locals, the city said. But there may be a silver lining, as the city says the data...

Flagstar Bank discloses data breach impacting 1.5 million customers

By Bill Toulas,  Bleeping Computer Flagstar Bank is notifying 1.5 million customers of a data breach where hackers accessed personal data during a December cyberattack. Flagstar is a Michigan-based financial services provider and one of the largest banks in the United States, having total assets of over $30 billion. According to data breach notifications sent to exposed customers, Flagstar experienced a security incident in December 2021 when intruders breached the bank’s corporate network.  After an investigation, the bank discovered on June 2nd that the threat actors accessed sensitive customer details, including full names and social security numbers. “Upon learning of the incident, we promptly activated our incident response plan, engaged external cybersecurity professionals experienced in handling these types of incidents, and reported the matter to federal law enforcement,” explains the notice. “We have no evidence that any of the information has been misused. Neverthele...