Category / 76 entries / page 1 of 8 / feed available

Data Breaches

All 76 analyses the site publishes — the same list the Data Breaches index carries. All 76 are scored against the four invariants; the matrix below is that evidence.

How this category scores against the four invariants

BreachHSFPECEGRSCA
LinkedIn Password Breach
Home Depot Data Breach April 2014
Change Healthcare February 2024 Data Breach
Los Angeles Unified School District (LAUSD) Ransomware Breach
Marriott International Data Breach of 2018
Target Data Breach 2013
Anthem Data Breach Incident Analysis
Yahoo Data Breach August 2013
British Library Ransomware Attack October 2023
MGM Grand Data Breach - September 2023
Yum! Brands Ransomware Data Breach
Office of Personnel Management Data Breach 2015
SolarWinds Supply Chain Attack
JPMorgan Chase Data Breach
Fujitsu Malware Attack 2024
Google Aurora Incident
Norsk Hydro Ransomware Attack - March 2019
2017 Equifax Data Breach
eBay Data Breach Analysis
Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)
Indian Council of Medical Research Data Breach 2023
PharMerica Data Breach March 2023
Heartland Payment Systems Data Breach
Greece Government Data Breach 2012
Microsoft Exchange Server Breach
Army National Guard Salt Typhoon Network Compromise (March–December 2024)
TJX Companies Inc. Data Breach
American Express Data Breach March 2024
Twitter 2020 Data Breach Incident
Conduent Business Services Data Breach (January 2025)
Discord Data Breach March 2023
National Public Data Breach of April 2024
Activision HR Data Breach 2023
JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)
PowerSchool Student Information System Data Breach (December 2024)
U-Haul Data Breach
23andMe Data Breach
Chick-fil-A Data Breach March 2023
MailChimp January 2023 Data Breach
Adobe 2013 Data Breach
Copay Cryptocurrency Wallet Data Breach
Norton Life Lock Credential Stuffing Data Breach
NotPetya Ransomware Attack
Google Fi Data Breach Linked to T-Mobile Incident
Capital One Data Breach 2019
2016 Uber Data Breach
AdultFriendFinder Data Breach
ChatGPT Data Breach
Aadhaar Data Breach
MOVEit Data Breach June 2023
Microsoft Email Accounts Security Breach
MySpace Data Breach
U.S. Department of the Treasury BeyondTrust Breach December 2024
Samsung Data Breach November 2023
Allianz Life Insurance Company of North America Data Breach (July 2025)
NCB Management Services Data Breach February 2023
Qantas Airways Customer Data Breach (June 2025)
Tesla Massive Data Breach
Cash App Data Breach - April 2022
T-Mobile January 2023 Data Breach
Sina Weibo Data Breach 2020
Consumer Financial Protection Bureau Data Breach
Yahoo Intellectual Property Theft
2014 Uber Data Breach
Facebook Data Breach 2019
Real Estate Wealth Network Data Breach
DuoLingo Data Breach August 2023
Pegasus Airlines Data Exposure
South Georgia Medical Center Data Theft
LinkedIn Data Scraping Incident
Alibaba Taobao Data Breach
First American Financial Corp Data Breach
Deep Root Analytics Data Breach
Australian Immigration Department G20 Data Breach
Court Ventures (Experian) Data Breach
California Department of Child Support Services Data Breach

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

076

JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)

Contained by: PEC, EGR

JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.

075

Allianz Life Insurance Company of North America Data Breach (July 2025)

A threat actor used social engineering to access a third-party cloud-based CRM used by Allianz Life Insurance Company of North America and exfiltrated sensitive personal information. The incident affected approximately 1.5 million customers, financial professionals, and select employees, with exposed data potentially including names, addresses, dates of birth, Social Security numbers, email addresses, and phone numbers. The responsible threat actor or group was not confirmed, although the breach was linked in reporting to a broader campaign associated with ShinyHunters, Scattered Spider, and UNC6040.

074

Qantas Airways Customer Data Breach (June 2025)

An attacker socially engineered an overseas contact-centre agent into authorizing an attacker-controlled data-extraction application against the agent’s legitimate CRM access. Approximately 5.7 million unique Qantas customer records were affected, including names, email addresses, Frequent Flyer information and, for subsets, addresses, dates of birth, phone numbers, gender and meal preferences. Qantas said passwords, PINs, payment, financial, passport and Frequent Flyer login data were not accessed. The initial intruder attribution was not confirmed; later reporting identified Scattered Lapsus$ Hunters as the collective that reportedly published some records after extortion activity.

073

Conduent Business Services Data Breach (January 2025)

Contained by: EGR

Conduent Business Services discovered unauthorized access to a limited portion of its environment on January 13, 2025, after access that began on October 21, 2024. The actor exfiltrated client-associated files containing personal, medical, health-insurance, claims, and Social Security information; SafePay claimed responsibility and alleged theft of 8.5 terabytes, but the role and volume were not independently confirmed. Publicly reported impact reached at least 25 million people, while later HHS OCR figures and state reports remained inconsistent and unresolved.

072

PowerSchool Student Information System Data Breach (December 2024)

Prevented by: HSF

An unauthorized party used a compromised credential with password-only access to the PowerSource customer-support portal and exported student and teacher data from PowerSchool SIS environments. Exposed information varied by customer and could include names, contact details, dates of birth, addresses, SSNs or SINs, medical information, grades, parent or guardian data, and passwords. DOJ-related reporting placed the affected population at approximately 62 million individuals, although other reported figures were not reconciled. Matthew D. Lane later pleaded guilty to conduct related to the breach, while subsequent extortion attempts indicated that stolen data may have remained available.

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

070

Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)

Prevented by: PEC, EGR

The China-linked Salt Typhoon cyber-espionage campaign compromised at least eight U.S. telecommunications providers, with a ninth operator subsequently identified, and affected providers in more than 20 other countries. Attackers accessed carrier infrastructure and surveillance-adjacent systems and collected customer call data, metadata, law-enforcement surveillance-request data, and selected private communications involving government and politically prominent individuals. The campaign exploited exposed and vulnerable network devices, compromised credentials, and trusted provider relationships; officials and congressional testimony reported that more than one million users may have been affected.

069

National Public Data Breach of April 2024

Prevented by: HSF

In April 2024, National Public Data experienced a significant breach that exposed Social Security Numbers, addresses, and phone numbers of hundreds of millions of Americans. This breach, attributed to a security lapse involving administrative credential exposure, allowed unauthorized access to up to 2.9 billion records. The threat actor identified as USDoD exploited this vulnerability, selling the compromised data on the dark web.

068

American Express Data Breach March 2024

Prevented by: EGR

In March 2024, American Express disclosed a data breach caused by unauthorized access to a third-party merchant processor, exposing customer names, account numbers, and expiration dates. The breach resulted from a point-of-sale attack, impacting vendor management systems, without directly compromising American Express’s internal databases. While the specific threat actors remain unidentified, the breach underscores potential risks to customer data integrity.

067

Army National Guard Salt Typhoon Network Compromise (March–December 2024)

Prevented by: EGR · Contained by: HSF

A PRC-associated Salt Typhoon actor extensively compromised the Army National Guard network of an unidentified U.S. state from March through December 2024. The actor reportedly accessed or exfiltrated administrator credentials, network configurations and diagrams, a geographic map, and service-member personally identifiable information, while collecting configuration and traffic involving Guard networks in every other state and at least four territories. NJCCIC reported entry through a weakly configured remote-access service, followed by lateral spread and control of several privileged accounts, although the complete attack chain was not publicly established.

RSS feed for this category →

Now playing Bandcamp