<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data Breaches on Security Blueprints</title>
    <link>https://securityblueprints.io/categories/data-breaches/</link>
    <description>Recent content in Data Breaches on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/categories/data-breaches/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Allianz Life Insurance Company of North America Data Breach (July 2025)</title>
      <link>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</guid>
      <description>Executive Summary Incident summary On July 16, 2025, a threat actor used social engineering to access a third-party, cloud-based customer relationship management (CRM) system used by Allianz Life Insurance Company of North America. Allianz Life’s official account states that it became aware of suspicious activity on July 17 at 12:17 p.m. CDT and terminated access to accounts associated with that activity at 2:17 p.m. CDT. (agportal-s3bucket.s3.amazonaws.com ) The company reported no indication that the threat actor accessed its company network or systems outside the CRM; this does not establish that the CRM was deliberately isolated.</description>
    </item>
    <item>
      <title>Qantas Airways Customer Data Breach (June 2025)</title>
      <link>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</link>
      <pubDate>Sat, 28 Jun 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</guid>
      <description>Executive Summary On 30 June 2025, Qantas detected unusual activity on a third-party platform used by an overseas airline contact centre. The OAIC’s later account states that an agent had been socially engineered on 28 June and that the attacker used the agent’s legitimate CRM access to connect a third-party data-extraction application; Qantas froze and revoked the associated account on 30 June. (oaic.gov.au ) Qantas publicly disclosed the incident on 2 July and subsequently reported approximately 5.</description>
    </item>
    <item>
      <title>Conduent Business Services Data Breach (January 2025)</title>
      <link>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</link>
      <pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</guid>
      <description>Executive Summary Conduent Business Services, a business-process outsourcing provider for government agencies, health plans, and other enterprises, discovered on January 13, 2025 that an unauthorized third party had accessed a limited portion of its environment and that client-associated files had been exfiltrated. Subsequent investigation placed the beginning of unauthorized access on October 21, 2024. Conduent restored affected systems within days, and in some cases within hours, but the data review and notification process continued through 2025 and into 2026.</description>
    </item>
    <item>
      <title>PowerSchool Student Information System Data Breach (December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</link>
      <pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</guid>
      <description>Executive Summary On December 28, 2024, PowerSchool said it became aware that an unauthorized party had exfiltrated personal information from PowerSchool Student Information System (SIS) environments through the PowerSource customer-support portal. Later reporting and forensic summaries place unauthorized activity earlier: CrowdStrike found evidence beginning December 19, while customer guidance reported data first stolen on December 22. PowerSchool notified affected customers on January 7, 2025 and publicly posted an incident disclosure on January 13.</description>
    </item>
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>National Public Data Breach of April 2024</title>
      <link>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</link>
      <pubDate>Mon, 01 Apr 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</guid>
      <description>Executive Summary In April 2024, National Public Data (NPD) became the subject of a significant data breach, compromising sensitive personal information of hundreds of millions of Americans. The breach was attributed to a security oversight, specifically the inadvertent publication of administrative credentials, leading to unauthorized access to NPD&amp;rsquo;s databases. This event highlights substantial gaps in cybersecurity practices and emphasizes the critical need for robust protection and risk management strategies.&#xA;Incident Overview Chronological Sequence of Events December 2023</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>Army National Guard Salt Typhoon Network Compromise (March–December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</guid>
      <description>Executive Summary Between March and December 2024, Salt Typhoon extensively compromised the Army National Guard network of an unidentified U.S. state. A June 11, 2025 Department of Homeland Security Office of Intelligence and Analysis memorandum, obtained through a Freedom of Information Act request and circulated in June, described the incident; public reporting began in July 2025 (bleepingcomputer.com ; nbcnews.com ). The intrusion persisted for approximately nine months, but the sources do not provide an exact discovery date or a separate resolution date (bleepingcomputer.</description>
    </item>
    <item>
      <title>Fujitsu Malware Attack 2024</title>
      <link>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</guid>
      <description>Executive Summary In March 2024, Fujitsu identified a malware infection on its corporate network, indicating a notable cybersecurity breach that potentially compromised customer information. Details of the breach were made public on March 15, 2024, highlighting unauthorized access achieved using advanced malware techniques (source , source , source ).&#xA;Severity of Impact The incident is classified as severe, as it may involve sensitive customer data exposure. Although certain data access was confirmed, no misuse evidence has emerged so far (source ).</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>U-Haul Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/u-haul-data-breach/</link>
      <pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/u-haul-data-breach/</guid>
      <description>Executive Summary The U-Haul data breach was publicly disclosed in February 2024, impacting approximately 67,000 customers across the United States and Canada. Initially discovered on December 5, 2023, unauthorized individuals accessed an internal system by exploiting stolen credentials, exposing sensitive personal information, including customer names and driver’s license numbers. Financial information remained unaffected (BleepingComputer ; SecurityWeek ).&#xA;Severity of the Impact The exposure of personal identifiers poses risks such as identity theft, although the absence of financial data reduction slightly limits potential damage.</description>
    </item>
    <item>
      <title>23andMe Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/23andme-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/23andme-data-breach/</guid>
      <description>Executive Summary In December 2023, 23andMe, a leader in consumer genetic testing, disclosed a data breach resulting from credential stuffing attacks, compromising the personal data of approximately 6.9 million users. This type of attack utilized stolen credentials from unrelated data breaches, impacting user accounts by exploiting weak password practices.&#xA;Key Dates Breach Discovery: Initial indications arose on October 4, 2023, with public acknowledgment on October 6, 2023. Formal Disclosure: Comprehensive disclosure of the breach&amp;rsquo;s details occurred in December 2023.</description>
    </item>
    <item>
      <title>Real Estate Wealth Network Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/real-estate-wealth-network-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/real-estate-wealth-network-data-breach/</guid>
      <description>Executive Summary The Real Estate Wealth Network (REWN) data breach in December 2023 involved the unauthorized exposure of over 1.5 billion records due to a cloud misconfiguration. This extensive breach was discovered by cybersecurity researcher Jeremiah Fowler on December 20, 2023. Public disclosure followed on December 26, 2023. The breach predominantly exposed personal and property information, posing significant risks such as identity theft and financial fraud.&#xA;Key Details Breach Date: December 2023 Discovery Date: December 20, 2023 Severity: Exposure of personal data including Social Security numbers and property ownership details Root Cause: Cloud configuration error, an internal oversight Impact Affected Individuals: Millions, including both private citizens and high-profile figures Consequences: Risks of identity theft, financial fraud, harassment, and privacy invasion Response REWN secured the database after the breach was disclosed and plans to conduct a forensic audit to assess potential unauthorized access.</description>
    </item>
    <item>
      <title>Samsung Data Breach November 2023</title>
      <link>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</link>
      <pubDate>Mon, 13 Nov 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/samsung-data-breach-november-2023/</guid>
      <description>Executive Summary On November 13, 2023, Samsung Electronics detected a data breach originating from a vulnerability in a third-party application. This breach affected customers who made purchases through the Samsung UK online store between July 1, 2019, and June 30, 2020, exposing personal information, including names, phone numbers, postal addresses, and email addresses. Samsung notified affected customers on November 16, 2023.&#xA;Severity of Impact The breach&amp;rsquo;s significance lies in the exposure of sensitive personal information, even though financial data and passwords were not compromised.</description>
    </item>
    <item>
      <title>British Library Ransomware Attack October 2023</title>
      <link>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</link>
      <pubDate>Sat, 28 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</guid>
      <description>Executive Summary The British Library experienced a ransomware attack carried out by the Rhysida ransomware group in 2023. This cyber incident was identified on October 28, 2023. Public announcements regarding ongoing technology outages followed on November 17, 2023. The attack demonstrated vulnerabilities within the library&amp;rsquo;s IT infrastructure, resulting in significant disruptions due to data encryption.&#xA;Severity of the Impact The ransomware attack severely affected services, disrupting digital and physical operations including public Wi-Fi and possibly internal human resources files.</description>
    </item>
    <item>
      <title>Indian Council of Medical Research Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</link>
      <pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</guid>
      <description>Executive Summary In 2023, the Indian Council of Medical Research (ICMR) experienced a significant data breach, resulting in the unauthorized access and theft of approximately 815 million records. The data compromised included sensitive personal information such as Aadhaar IDs, passport details, names, phone numbers, and addresses. The threat actor, identified as pwn0001, advertised the stolen data for sale on the dark web (source , source , source ).&#xA;Incident Details Discovery Date: October 9, 2023, when the data sale was announced on dark web forums.</description>
    </item>
    <item>
      <title>MGM Grand Data Breach - September 2023</title>
      <link>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</link>
      <pubDate>Fri, 08 Sep 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mgm-grand-cyberattack/</guid>
      <description>Executive Summary In September 2023, MGM Resorts International experienced a major cyberattack attributed to the hacking group Scattered Spider, known for its association with the ALPHV/BlackCat ransomware group. The attack resulted in significant disruptions to operations at MGM&amp;rsquo;s Las Vegas venues, including the MGM Grand and Bellagio, with estimated financial losses ranging from $80 million to $100 million. This incorporates direct impacts on revenue and heightened cybersecurity expenses. The attackers exploited vulnerabilities in service desk operations through social engineering tactics like vishing, which allowed unauthorized system access.</description>
    </item>
    <item>
      <title>DuoLingo Data Breach August 2023</title>
      <link>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</link>
      <pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</guid>
      <description>Executive Summary In August 2023, DuoLingo experienced a significant data exposure incident caused by a data scraping attack targeting an exposed Application Programming Interface (API). The breach affected approximately 2.6 million users, with personal data such as names, email addresses, and other identifiable information being posted online (source 1 , source 4 ).&#xA;Severity of Impact The exposure compromised personal information of approximately 2.6 million users, including critical identifiers like login names and email addresses, heightening risks for phishing and other cyber threats (source 3 , source 6 ).</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Tesla Massive Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/tesla-massive-data-breach/</link>
      <pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/tesla-massive-data-breach/</guid>
      <description>Executive Summary The Tesla Massive Data Breach, discovered in May 2023, was a significant incident involving the unauthorized disclosure of sensitive data by two former employees to Handelsblatt, a German media outlet. On May 10, 2023, this breach came to light when Handelsblatt informed Tesla of their possession of approximately 100 gigabytes of confidential data, involving over 23,000 internal files (CentralEyes , Hackread ).&#xA;Severity of Impact The breach impacted over 75,735 individuals, including both current and former employees.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Yum! Brands Ransomware Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</link>
      <pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</guid>
      <description>Executive Summary In January 2023, Yum! Brands, which owns KFC, Taco Bell, and Pizza Hut, fell victim to a ransomware attack, resulting in a data breach. This incident compromised corporate and employee data and was publicly disclosed by Yum! Brands in April 2023. Formal notifications to employees and potentially affected individuals about the data compromise began around the same time.&#xA;Discovery and Disclosure The ransomware attack was first identified in January 2023.</description>
    </item>
    <item>
      <title>Discord Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</link>
      <pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</guid>
      <description>Executive Summary Incident Overview In March 2023, Discord faced a data breach due to security vulnerabilities at a third-party service provider. This led to the compromise of customer data. The breach was identified on March 29, 2023, publicly disclosed by May 12, 2023, and user notifications commenced on August 21, 2023 (BleepingComputer ).&#xA;Severity of Impact The breach exposed sensitive personal information of approximately 180 users, including names and state or driver&amp;rsquo;s license numbers, highlighting privacy concerns despite its limited scope relative to Discord&amp;rsquo;s extensive user base (HackRead ; Economic Times ).</description>
    </item>
    <item>
      <title>ChatGPT Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</link>
      <pubDate>Mon, 20 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chatgpt-data-breach/</guid>
      <description>Executive Summary Overview of the Incident In March 2023, OpenAI&amp;rsquo;s ChatGPT platform experienced a data breach caused by a bug in the open-source library, Redis-py, used by the service. This issue resulted in the exposure of sensitive user data, including names, emails, payment addresses, and partial credit card details (last four digits and expiration dates). The breach was identified on March 20, 2023, during a service outage, revealing private information in error source .</description>
    </item>
    <item>
      <title>PharMerica Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</link>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, PharMerica, a prominent U.S. pharmacy services provider, encountered a notable data breach affecting approximately 5,815,591 individuals. This incident compromised sensitive patient information, impacting both PharMerica and its parent company, BrightSpring Health Services (source ).&#xA;Breach Timeline Intrusion Period: Unauthorized access was gained from March 12 to 13, 2023. Discovery Date: The breach was discovered on March 14, 2023. Public Disclosure: Notifications were issued to individuals on May 12, 2023.</description>
    </item>
    <item>
      <title>Chick-fil-A Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</link>
      <pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, Chick-fil-A confirmed a data breach resulting from unauthorized login activity via a credential stuffing attack. This attack, utilizing previously leaked credentials, enabled access to customer accounts through Chick-fil-A&amp;rsquo;s mobile application (TechRadar ).&#xA;Breach Details Unauthorized access occurred between December 18, 2022, to February 12, 2023, impacting approximately 71,473 accounts (less than 2% of users). The exposed information included names, email addresses, Chick-fil-A One membership details, and partial payment information (ClassAction.</description>
    </item>
    <item>
      <title>Consumer Financial Protection Bureau Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</link>
      <pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</guid>
      <description>Executive Summary In 2023, the Consumer Financial Protection Bureau (CFPB) experienced a significant data breach due to internal security lapses. An employee transferred confidential records via email to a personal account, compromising the data of approximately 256,000 individuals. This incident underscores critical deficiencies in CFPB&amp;rsquo;s data protection protocols and has raised considerable concerns over internal security measures. Source Severity of Impact The breach affected records from seven financial institutions; however, some reports suggest this number could be higher.</description>
    </item>
    <item>
      <title>Google Fi Data Breach Linked to T-Mobile Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</guid>
      <description>Executive Summary Incident Overview: In February 2023, Google Fi suffered a data breach due to vulnerabilities originating from a prior T-Mobile security incident. This breach exposed Google Fi customers&amp;rsquo; phone numbers and related technical details, posing significant risks such as SIM swap attacks and unauthorized account activities (source ).&#xA;Key Dates: The association with T-Mobile&amp;rsquo;s broader data breach was identified on January 19, 2023. Affected individuals received notifications in early February 2023 (source ).</description>
    </item>
    <item>
      <title>NCB Management Services Data Breach February 2023</title>
      <link>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</guid>
      <description>Executive Summary In February 2023, NCB Management Services experienced a significant data breach due to an unauthorized system compromise, exposing sensitive personal and financial information. The breach was detected on February 4, 2023, affecting clients associated with major financial institutions including Capital One, Bank of America, and TD Bank.&#xA;Severity of the Impact The breach compromised data for over 1 million individuals, with specific numbers varying by institution: approximately 16,779 Capital One customers and nearly 495,000 Bank of America customers were directly impacted.</description>
    </item>
    <item>
      <title>Norton Life Lock Credential Stuffing Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</link>
      <pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</guid>
      <description>Executive Summary In January 2023, Norton LifeLock reported a data breach due to a credential stuffing attack, allowing attackers to exploit previously compromised passwords to access over 6,000 customer accounts. The incident highlighted vulnerabilities within password management services, raising concerns about the security of stored credentials [source1 ].&#xA;Severity of Impact The breach exposed personal data, including names, phone numbers, and mailing addresses, and potentially compromised credentials stored in the Norton Password Manager.</description>
    </item>
    <item>
      <title>MailChimp January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</link>
      <pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</guid>
      <description>Executive Summary Incident Overview In January 2023, MailChimp was subjected to a data breach due to a social engineering attack that affected its internal customer support tool. This breach, the second in a span of six months, indicates potential weaknesses in MailChimp&amp;rsquo;s defensive measures.&#xA;Key Dates and Discovery Details The breach was discovered on January 11, 2023, during a routine security review and was publicly disclosed on January 19, 2023. This prompt notification ensured that stakeholders were adequately informed.</description>
    </item>
    <item>
      <title>Activision HR Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</link>
      <pubDate>Sun, 04 Dec 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</guid>
      <description>Executive Summary In December 2022, Activision, a leading video game developer, encountered a data breach caused by a sophisticated SMS phishing attack targeting a Human Resources (HR) employee. This breach resulted in unauthorized access to internal data, including employee names, phone numbers, email addresses, job titles, and workplace locations. Despite discrepancies regarding the exact public disclosure date, the breach became widely acknowledged in February 2023, highlighting substantial risks to employee data security [TechCrunch ] [Intrix ].</description>
    </item>
    <item>
      <title>T-Mobile January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</link>
      <pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</guid>
      <description>Executive Summary In January 2023, T-Mobile disclosed a significant data breach that affected approximately 37 million current customers. The breach, initiated through unauthorized access to an API, began in late November 2022. T-Mobile detected the breach on January 5, 2023, and publicly disclosed it on January 19, 2023.&#xA;Technical Details The breach was facilitated through a vulnerability in an API, which allowed attackers to access personal data, including names, billing addresses, email addresses, phone numbers, and dates of birth.</description>
    </item>
    <item>
      <title>Los Angeles Unified School District (LAUSD) Ransomware Breach</title>
      <link>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</link>
      <pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</guid>
      <description>Executive Summary In September 2022, the Los Angeles Unified School District (LAUSD), the second-largest school district in the United States, experienced a significant ransomware attack orchestrated by the Vice Society gang. This incident, detected over the Labor Day holiday weekend, compromised more than 1,000 schools, affecting approximately 600,000 students and staff members. Sensitive data, including psychological evaluations and Social Security numbers, was exposed and disseminated on the dark web following LAUSD&amp;rsquo;s decision not to pay the ransom source .</description>
    </item>
    <item>
      <title>Pegasus Airlines Data Exposure</title>
      <link>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</link>
      <pubDate>Tue, 01 Mar 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</guid>
      <description>Executive Summary Incident Overview In March 2022, Pegasus Airlines faced a data exposure due to a misconfiguration in an AWS S3 bucket by a system administrator. This incident led to the exposure of approximately 23 million files, containing Personally Identifiable Information (PII) and critical operational data (source ).&#xA;Severity of Impact The breach involved 6.5 terabytes of sensitive data, including sensitive operational information, crew identification details, plaintext passwords, secret keys, insurance documents, and safety guidelines.</description>
    </item>
    <item>
      <title>Yahoo Intellectual Property Theft</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-intellectual-property-theft/</link>
      <pubDate>Fri, 11 Feb 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-intellectual-property-theft/</guid>
      <description>Executive Summary In February 2022, Yahoo experienced a significant insider threat incident involving the alleged theft of intellectual property by Qian Sang, a former employee. The breach occurred when Sang, upon receiving a job offer from direct competitor The Trade Desk, allegedly exfiltrated approximately 570,000 pages of proprietary information. This data included:&#xA;Source code Advertising algorithms Internal strategy documents The stolen information was related to Yahoo&amp;rsquo;s demand-side platform (DSP) for real-time ad buying, known as AdLearn.</description>
    </item>
    <item>
      <title>Cash App Data Breach - April 2022</title>
      <link>https://securityblueprints.io/data-breaches/cash-app-data-breach/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/cash-app-data-breach/</guid>
      <description>Executive Summary In April 2022, Block, the parent company of Cash App, disclosed a significant data breach involving unauthorized access by a former employee, who downloaded sensitive financial information from approximately 8.2 million users. This exposure included brokerage account details and stock trading activities. The breach was publicly announced on April 4, 2022 (source ). Despite the breadth of affected data, no personally identifiable information such as usernames, passwords, or Social Security numbers was compromised (source ).</description>
    </item>
    <item>
      <title>South Georgia Medical Center Data Theft</title>
      <link>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</link>
      <pubDate>Fri, 12 Nov 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</guid>
      <description>Executive Summary The November 2021 data breach at South Georgia Medical Center (SGMC) was caused by a former employee downloading patient data onto a USB drive without authorization. This incident underscores the risks associated with insider threats and highlights the necessity for stringent data security protocols.&#xA;Incident Details Breach Type: Insider data theft involving unauthorized transfer of patient information. Compromised Data: Included protected health information such as patient names, birth dates, and test results.</description>
    </item>
    <item>
      <title>LinkedIn Data Scraping Incident</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</link>
      <pubDate>Thu, 01 Apr 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</guid>
      <description>Executive Summary In April 2021, LinkedIn reported a significant data scraping incident involving approximately 700 million user records, totaling over 93% of its user base. The breach was disclosed in June 2021 after data was discovered being sold on dark web forums by the hacker known as &amp;ldquo;GOD User TomLiner,&amp;rdquo; who intended to sell the dataset for an estimated $5,000 to $6,600.&#xA;Severity of the Impact The breach&amp;rsquo;s significance lies in the vast volume of exposed personal information, such as full names, email addresses, phone numbers, LinkedIn IDs, and sensitive data like gender, industry, and inferred salaries.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</link>
      <pubDate>Sun, 03 Jan 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</guid>
      <description>Executive Summary In January 2021, Microsoft Exchange email servers were targeted in a significant cyberattack that exploited multiple zero-day vulnerabilities, affecting over 30,000 organizations in the United States. Initially detected by Volexity on January 3, 2021, the breach was publicly acknowledged by Microsoft on March 2, 2021, upon releasing emergency patches (source , source ).&#xA;Severity of the Impact Globally, the breach compromised up to 250,000 servers, impacting critical sectors such as government, banking, and infrastructure, thereby posing risks to operational integrity and data confidentiality (source , source ).</description>
    </item>
    <item>
      <title>Twitter 2020 Data Breach Incident</title>
      <link>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</link>
      <pubDate>Wed, 15 Jul 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</guid>
      <description>Executive Summary In July 2020, a critical cybersecurity breach, termed the Twitter 2020 Data Breach, occurred, wherein a 17-year-old hacker, Graham Ivan Clark, along with accomplices, exploited vulnerabilities in Twitter’s security infrastructure. They gained unauthorized access to Twitter&amp;rsquo;s internal network, commandeering numerous high-profile accounts to disseminate a Bitcoin scam.&#xA;Key Dates Breach Occurrence: July 15, 2020 Public Disclosure: July 15, 2020 Severity of Impact The breach affected highly influential accounts such as those of Barack Obama and Elon Musk, resulting in fraudulent tweets promoting a Bitcoin scam.</description>
    </item>
    <item>
      <title>Sina Weibo Data Breach 2020</title>
      <link>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</link>
      <pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</guid>
      <description>Executive Summary In March 2020, Sina Weibo, a leading Chinese microblogging platform, experienced a significant data breach impacting approximately 538 million users. The breach was publicly acknowledged when an attacker leveraged a logic flaw in the Sina Weibo API to access and sell personal user information on the dark web for about USD 250. This breach exposed sensitive details such as real names, usernames, gender, location, and phone numbers for 172 million users, though passwords were not compromised.</description>
    </item>
    <item>
      <title>Alibaba Taobao Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</link>
      <pubDate>Fri, 01 Nov 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</guid>
      <description>Executive Summary In November 2019, Alibaba&amp;rsquo;s Taobao platform experienced a breach involving unauthorized data scraping activities by a developer. This breach involved collecting 1.1 billion pieces of user data, including usernames and mobile numbers, over several months until discovered in July 2020. Officially acknowledged on June 16, 2021, the breach stands as significant due to its volume and impact.&#xA;Severity of Impact The breach is one of the largest data leaks recorded, affecting approximately 710 million Taobao users.</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>Capital One Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</link>
      <pubDate>Wed, 17 Jul 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</guid>
      <description>Executive Summary In July 2019, Capital One experienced a significant data breach that compromised over 100 million customer records. This breach occurred due to a server-side request forgery (SSRF) exploiting a misconfigured Web Application Firewall (WAF) in their systems. The attack was orchestrated by Paige A. Thompson, a former software engineer at Amazon Web Services (AWS), leveraging insider knowledge and scanning for vulnerabilities using the misconfigured AWS resources.&#xA;Key Dates Attack Period: March 22-23, 2019 Discovery Date: July 19, 2019 Public Disclosure: July 29, 2019 Severity of Impact This breach ranks among the largest in history, affecting approximately 100 million individuals in the United States and around 6 million in Canada, approximately 106 million individuals combined.</description>
    </item>
    <item>
      <title>First American Financial Corp Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</link>
      <pubDate>Fri, 24 May 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</guid>
      <description>Executive Summary In May 2019, a data breach at First American Financial Corp. resulted in the exposure of approximately 885 million file records due to inadequate security measures on their web portal. The breach came to light when a real estate developer discovered the vulnerability, and cybersecurity journalist Brian Krebs publicly disclosed it on May 24, 2019. The exposed records included sensitive financial documents such as bank account numbers, mortgage-related documents, and Social Security numbers, with records dating back to 2003.</description>
    </item>
    <item>
      <title>Facebook Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</link>
      <pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</guid>
      <description>Executive Summary In April 2019, a significant data breach affected Facebook, exposing the personal information of over 530 million users across 106 countries. The breach involved the improper access and sharing of two datasets, revealing sensitive information such as phone numbers, account names, Facebook ID numbers, and email addresses. The exposure occurred due to the misuse of Facebook&amp;rsquo;s &amp;lsquo;contact importer&amp;rsquo; feature and improperly secured third-party applications hosted on Amazon Web Services (AWS) servers.</description>
    </item>
    <item>
      <title>Norsk Hydro Ransomware Attack - March 2019</title>
      <link>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</link>
      <pubDate>Tue, 19 Mar 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</guid>
      <description>Executive Summary In March 2019, Norsk Hydro, a significant global aluminum producer, encountered a ransomware attack via the LockerGoga malware. This attack caused substantial disruptions across 160 locations, impacting over 20,000 systems worldwide, and forced the company to shift to manual operations (source ).&#xA;Key Dates Discovery and Disclosure Date: March 19, 2019 Severity of Impact The attack resulted in significant financial repercussions, with initial losses estimated at $40 million USD within the first week, subsequently summing to over 350 million Norwegian krone (source ).</description>
    </item>
    <item>
      <title>Marriott International Data Breach of 2018</title>
      <link>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</link>
      <pubDate>Fri, 30 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</guid>
      <description>Executive Summary In 2018, Marriott International suffered a data breach that compromised approximately 500 million guest records. This breach, dating back to 2014, primarily affected the Starwood guest reservation system, which was acquired by Marriott in 2016. Personal data exposed included names, addresses, phone numbers, email addresses, passport numbers, and credit card details (source , source ).&#xA;Severity of Impact This breach is noted for its wide scale, causing significant exposure of personal data and inflicting reputational damage on Marriott.</description>
    </item>
    <item>
      <title>Copay Cryptocurrency Wallet Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</link>
      <pubDate>Tue, 27 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</guid>
      <description>Executive Summary In November 2018, the Copay cryptocurrency wallet, developed by BitPay, experienced a data breach due to a malicious update to the event-stream Node.js library, specifically within its flatmap-stream dependency. Unauthorized access to users&amp;rsquo; private keys and cryptocurrency funds was achieved, significantly impacting wallets containing over 100 Bitcoins or 1000 Bitcoin Cash source .&#xA;Key Dates August 5, 2018: Initial release of the flatmap-stream package. September 9, 2018: Integration of flatmap-stream into event-stream.</description>
    </item>
    <item>
      <title>Aadhaar Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</link>
      <pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</guid>
      <description>Executive Summary In January 2018, a significant data breach compromised Aadhaar, the world&amp;rsquo;s largest identification database, managed by the Unique Identification Authority of India (UIDAI). The breach affected personal information—biometric and financial data—of approximately 1.1 billion Indian citizens. The affected information was allegedly retailed for as little as ₹500 via WhatsApp, pointing to extensive security flaws (Legal Service India , FirstPost ).&#xA;Severity of Impact The exposure of biometric details like fingerprints and iris scans poses severe risks related to identity theft and fraud, thus threatening the privacy and security of citizens.</description>
    </item>
    <item>
      <title>2017 Equifax Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</link>
      <pubDate>Sat, 29 Jul 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</guid>
      <description>Executive Summary The 2017 Equifax data breach marked a critical event in data security, caused by exploiting a known vulnerability, CVE-2017-5638, in the Apache Struts web application framework. Unauthorized access led to the exposure of sensitive information of approximately 145.5 million individuals.&#xA;Severity of Impact This breach was one of the largest in history, significantly affecting Personally Identifiable Information (PII), including names, Social Security numbers, birth dates, and, in certain instances, driver&amp;rsquo;s license numbers and credit card data.</description>
    </item>
    <item>
      <title>NotPetya Ransomware Attack</title>
      <link>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</link>
      <pubDate>Tue, 27 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/notpetya-ransomware-attack/</guid>
      <description>Executive Summary The NotPetya ransomware attack in June 2017 is considered one of the most destructive cyber incidents on record. Originating through a compromised update of MeDoc, a Ukrainian accounting software, the malware propagated swiftly, impacting organizations across more than 65 countries within hours of being detected on June 27, 2017. The event highlighted significant vulnerabilities in software supply chains.&#xA;Severity of the Impact NotPetya inflicted damages exceeding $10 billion globally, with significant disruptions in healthcare, logistics, and government sectors.</description>
    </item>
    <item>
      <title>Deep Root Analytics Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</link>
      <pubDate>Mon, 12 Jun 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/deep-root-analytics-data-breach/</guid>
      <description>Executive Summary In 2017, a data breach at Deep Root Analytics exposed the sensitive information of approximately 198 million U.S. voters. This information, linked to the Republican National Committee (RNC), was leaked due to a misconfigured Amazon Web Services (AWS) S3 bucket, which lacked adequate security settings. The breach included personal information such as names, addresses, birth dates, phone numbers, political affiliations, and predictive modeling data on ethnicities and religious orientations.</description>
    </item>
    <item>
      <title>2016 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</link>
      <pubDate>Mon, 14 Nov 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</guid>
      <description>Executive Summary On November 14, 2016, a data breach exposed records of approximately 57 million Uber users and 600,000 driver license numbers. The breach occurred when hackers exploited Uber&amp;rsquo;s systems by using stolen credentials to access its GitHub repository, subsequently gaining entry into an AWS S3 bucket containing sensitive user data such as names, email addresses, and phone numbers. For further details, refer to this source .&#xA;Key Events November 14, 2016: Attackers demanded a ransom for stolen data deletion.</description>
    </item>
    <item>
      <title>AdultFriendFinder Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</guid>
      <description>Executive Summary The AdultFriendFinder data breach, a significant incident in 2016, compromised approximately 412 million user accounts across platforms under FriendFinder Networks, including AdultFriendFinder.com, Cams.com, and Penthouse.com. This breach unveiled notable security vulnerabilities within the company&amp;rsquo;s systems.&#xA;Breach Details The breach occurred in October 2016 when attackers exploited Local File Inclusion (LFI) vulnerabilities within the website&amp;rsquo;s architecture, enabling unauthorized access to sensitive information. This data was publicly posted on November 13, 2016.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>Anthem Data Breach Incident Analysis</title>
      <link>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</guid>
      <description>Executive Summary The data breach at Anthem Inc. in 2015 stands as a critical incident in healthcare cybersecurity, involving unauthorized access to approximately 78.8 million records. The breach was disclosed publicly on February 4, 2015, illustrating significant weaknesses within the protection of Personal Identifiable Information (PII) in healthcare systems. This incident underscores a vital need for enhanced cybersecurity measures in the sector, emphasizing the risks associated with large-scale data compromises.</description>
    </item>
    <item>
      <title>Australian Immigration Department G20 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</link>
      <pubDate>Fri, 07 Nov 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</guid>
      <description>Executive Summary In 2015, the Australian Immigration Department was involved in a data breach releasing sensitive personal details of G20 world leaders due to an administrative error. The error occurred when an employee improperly used the autocomplete function in Microsoft Outlook, resulting in sensitive information being sent to an unintended recipient. This incident compromised data such as passport numbers, visa information, and birth dates of leaders including Barack Obama, Vladimir Putin, and Angela Merkel (ABC News ).</description>
    </item>
    <item>
      <title>JPMorgan Chase Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</link>
      <pubDate>Sun, 01 Jun 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</guid>
      <description>Executive Summary In June 2014, JPMorgan Chase became the target of a significant data breach, compromising data from over 76 million households and 7 million small businesses. The breach, discovered in July and publicly disclosed in September 2014, highlighted substantial deficiencies in the bank’s cybersecurity framework (source ).&#xA;Severity of Impact Approximately 83 million accounts were affected, with exposed data including names, addresses, phone numbers, and email addresses. However, no financial data or Social Security numbers were compromised, reducing the risk of direct financial fraud, yet increasing chances for phishing and identity theft (source ).</description>
    </item>
    <item>
      <title>2014 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</link>
      <pubDate>Mon, 12 May 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</guid>
      <description>Executive Summary In 2014, Uber experienced a significant data breach, where approximately 50,000 consumers&amp;rsquo; sensitive information, particularly names and driver&amp;rsquo;s license numbers, was accessed without authorization. This incident arose from the mishandling of an unencrypted Amazon Web Services (AWS) access key that was inadvertently published on GitHub, thereby allowing attackers unauthorized system access. (source , source )&#xA;Key Dates:&#xA;May 12, 2014: Attackers gained access to Uber&amp;rsquo;s AWS account by exploiting a publicly exposed AWS access key on GitHub.</description>
    </item>
    <item>
      <title>Home Depot Data Breach April 2014</title>
      <link>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</link>
      <pubDate>Tue, 01 Apr 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</guid>
      <description>Executive Summary In April 2014, Home Depot faced a significant data breach resulting in the theft of over 56 million payment card records. Custom-built malware targeted Home Depot&amp;rsquo;s point-of-sale (POS) systems, affecting customers across the United States and Canada. The breach was detected in September 2014.&#xA;Severity of Impact The breach is among the largest recorded in retail history, with anticipated financial consequences projected to potentially reach $179 million, encompassing immediate response and legal costs.</description>
    </item>
    <item>
      <title>eBay Data Breach Analysis</title>
      <link>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</link>
      <pubDate>Fri, 28 Feb 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</guid>
      <description>Executive Summary In early 2014, eBay, a leading online marketplace, experienced a significant data breach, which was publicly disclosed in May 2014. Unauthorized access to approximately 145 million user records occurred due to compromised employee credentials. The breach period spanned late February to early March 2014 (CRN , NY Times ).&#xA;Severity and Impact The breach is considered extensive, with unauthorized access to records including names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates.</description>
    </item>
    <item>
      <title>Target Data Breach 2013</title>
      <link>https://securityblueprints.io/data-breaches/target-data-breach-2013/</link>
      <pubDate>Wed, 18 Dec 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/target-data-breach-2013/</guid>
      <description>Executive Summary In December 2013, Target Corporation fell victim to a major data breach, impacting its operational security and customer trust by exposing approximately 110 million customer records, including financial and personal information. The breach became public after security researcher Brian Krebs disclosed it, revealing that unauthorized access was gained via compromised credentials from a third-party vendor, Fazio Mechanical Services (1) (2) .&#xA;Severity of Impact The breach led to the disclosure of 40 million credit and debit card numbers and 70 million records containing personal information, marking it as one of the significant incidents in retail data breaches.</description>
    </item>
    <item>
      <title>Adobe 2013 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</link>
      <pubDate>Thu, 03 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</guid>
      <description>Executive Summary In October 2013, Adobe became the victim of a cyberattack that compromised nearly 153 million user records, ranking as one of the largest breaches in cybersecurity history (source ). The attack resulted in the exposure of encrypted customer credit card information and user account details, prompting concerns about Adobe&amp;rsquo;s cybersecurity protocols (source ).&#xA;Key Details Breach Discovery: Internal discovery occurred on September 17, 2013, with public disclosure by Adobe on October 3, 2013 (source ).</description>
    </item>
    <item>
      <title>Court Ventures (Experian) Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</link>
      <pubDate>Tue, 01 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</guid>
      <description>Executive Summary In October 2013, a significant data breach involving Court Ventures was publicly reported. This breach followed Experian&amp;rsquo;s acquisition of Court Ventures in March 2012 and involved unauthorized access to a database containing sensitive information of approximately 200 million individuals. The breach was perpetuated by Hieu Minh Ngo, a Vietnamese national, exploiting the database via a business relationship between Court Ventures and US Info Search. Compromised data included Social Security numbers and credit card details (source ).</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
    <item>
      <title>MySpace Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/myspace-data-breach/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/myspace-data-breach/</guid>
      <description>Executive Summary The MySpace data breach disclosed in June 2016 affected over 360 million user accounts, underscoring substantial deficiencies in the company&amp;rsquo;s data security measures. At the time, MySpace utilized weak hashing algorithms like SHA-1 without salting, a method known for its cryptographic weaknesses. Users&amp;rsquo; widespread password reuse across different services amplified the breach&amp;rsquo;s repercussions. Consequently, MySpace updated its security practices post-breach, transitioning to double-salted hashes.&#xA;Technical Details The breach highlighted significant vulnerabilities due to inadequate security measures.</description>
    </item>
    <item>
      <title>Greece Government Data Breach 2012</title>
      <link>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</guid>
      <description>Executive Summary In 2012, the Greece government experienced a significant data breach that led to the unauthorized exposure of 9,000,000 records, affecting approximately 83% of the nation&amp;rsquo;s population. This breach involved sensitive information, including addresses, ID card data, tax ID numbers, and license plate numbers.&#xA;A sophisticated hacking attack exploited vulnerabilities in the government’s IT infrastructure, with a 35-year-old hacker identified as the primary suspect who allegedly sought to monetize the stolen data.</description>
    </item>
    <item>
      <title>LinkedIn Password Breach</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-password-breach/</link>
      <pubDate>Fri, 01 Jun 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-password-breach/</guid>
      <description>Executive Summary In 2012, LinkedIn experienced a significant data breach affecting its user base. Initially reported to have compromised 6.5 million hashed passwords, the breach&amp;rsquo;s true extent, revealed in 2016, affected over 117 million accounts. The compromised passwords were stored using the SHA1 hashing algorithm without salting, making them vulnerable to brute force and rainbow table attacks. These inadequacies exposed LinkedIn users to substantial risks as the leaked credentials circulated on cybercrime forums like LeakedSource.</description>
    </item>
    <item>
      <title>California Department of Child Support Services Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</link>
      <pubDate>Mon, 12 Mar 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</guid>
      <description>Executive Summary Breach Name: California Department of Child Support Services Breach Date: 2012 Discovery Date: March 12, 2012 Disclosure Date: March 29, 2012 Incident Overview In 2012, the California Department of Child Support Services (DCSS) suffered a data breach due to the loss of magnetic tape cartridges, which occurred during a disaster recovery exercise managed by IBM and Iron Mountain Inc. Between Boulder, Colorado, and Sacramento, California, four of fifteen tapes went missing, containing the sensitive information of approximately 800,000 individuals.</description>
    </item>
    <item>
      <title>Google Aurora Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-aurora-incident/</link>
      <pubDate>Tue, 01 Dec 2009 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-aurora-incident/</guid>
      <description>Executive Summary The Google Aurora incident, occurring in December 2009, was a significant cybersecurity breach affecting Google and multiple other corporations in various industries, particularly technology. The attack aimed to steal intellectual property and unauthorized Gmail access of Chinese human rights activists. It is widely attributed to state-sponsored entities linked to the Chinese government, employing sophisticated cyber espionage tactics.&#xA;Major Threat Actors The attack is attributed to entities based in China, utilizing Advanced Persistent Threat (APT) techniques.</description>
    </item>
    <item>
      <title>Heartland Payment Systems Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</link>
      <pubDate>Wed, 26 Dec 2007 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</guid>
      <description>Executive Summary Heartland Payment Systems experienced a major data breach compromising approximately 130 million payment card records, marking one of the largest breaches involving consumer credit and debit card information. The breach originated from SQL injection attacks and malware deployment starting around December 26, 2007, and was discovered by authorities in October 2008. Public disclosure followed on January 20, 2009. This information is corroborated by multiple sources (source , source , source ).</description>
    </item>
    <item>
      <title>TJX Companies Inc. Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</link>
      <pubDate>Fri, 01 Jul 2005 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</guid>
      <description>Executive Summary The TJX Companies Inc., a major retailer with brands such as TJ Maxx and Marshalls, suffered a significant data breach disclosed in January 2007, affecting approximately 94 million records. The breach revealed critical vulnerabilities in TJX&amp;rsquo;s data protection protocols and stands as one of the largest security incidents in retail history.&#xA;Key Dates Initial Intrusion: July 2005 Discovery: December 2006 Public Disclosure: January 17, 2007 (source ) Severity of Impact The data breach involved 94 million records, including credit and debit card data and personal information such as driver&amp;rsquo;s license numbers.</description>
    </item>
  </channel>
</rss>
