Category / 76 entries / page 2 of 8 / feed available

Data Breaches

All 76 analyses the site publishes — the same list the Data Breaches index carries.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

066

Fujitsu Malware Attack 2024

Prevented by: PEC, EGR

In March 2024, Fujitsu experienced a significant cybersecurity breach involving malware on its corporate network. The incident potentially exposed customer information, though there is no evidence of data misuse. The malware used sophisticated evasion techniques, indicating a high level of attacker skill, but the threat actors remain unidentified. The breach primarily affected Fujitsu’s operations in Japan, impacting 49 computers.

065

Change Healthcare February 2024 Data Breach

Prevented by: HSF, PEC, EGR

The Change Healthcare breach in February 2024 involved a ransomware attack by the BlackCat group, significantly disrupting pharmacy operations. Approximately 6TB of sensitive data, including health records, was potentially compromised. The attack exploited vulnerabilities in Citrix remote-access software, highlighting security weaknesses in multi-factor authentication.

063

23andMe Data Breach

Prevented by: HSF

In December 2023, a data breach at genetic testing company 23andMe exposed the personal data of approximately 6.9 million users to unauthorized access. The breach, executed through credential stuffing, compromised user profiles and familial connections, leaving sensitive personal data vulnerable. It underscored the need for robust password practices and security measures such as multi-factor authentication.

061

Samsung Data Breach November 2023

A vulnerability in a third-party application used by Samsung led to a data breach affecting UK customers who made purchases via the Samsung UK online store. The breach exposed personal information including names, phone numbers, postal addresses, and emails. The unauthorized access was the result of exploiting the vulnerability, with the specifics around the threat actors and exact details remaining undisclosed.

060

British Library Ransomware Attack October 2023

Prevented by: HSF, PEC · Contained by: EGR

In October 2023, the British Library was targeted by the Rhysida ransomware group, resulting in the encryption and leak of approximately 490,191 files, amounting to 573 GB of data. The breach illustrated vulnerabilities in security protocols due to compromised credentials and the absence of Multi-Factor Authentication (MFA), significantly disrupting library operations and potentially exposing sensitive internal data.

059

Indian Council of Medical Research Data Breach 2023

Prevented by: HSF, EGR

In October 2023, the Indian Council of Medical Research experienced a major data breach that led to the exposure of 815 million records, including Aadhaar IDs, passport details, names, phone numbers, and addresses. The data was compromised by a hacker identified as pwn0001, who made the information available for sale on the dark web. The breach involved significant security vulnerabilities, particularly in access controls and encryption practices, indicating a need for improved data protection measures.

058

MGM Grand Data Breach - September 2023

Prevented by: HSF, PEC · Contained by: EGR

In September 2023, MGM Resorts International experienced a major cyberattack orchestrated by the Scattered Spider group, leading to significant operational disruptions and an estimated $80 million in financial losses. The attackers exploited social engineering methods, particularly vishing, to breach MGM’s systems and compromise personal data including names, driver’s license numbers, and Social Security numbers. This attack underscores vulnerabilities in service desk operations and highlights the use of sophisticated ransomware tactics.

057

DuoLingo Data Breach August 2023

In August 2023, DuoLingo suffered a data breach affecting over 2.6 million users due to a data scraping attack exploiting an exposed API. Compromised data included names and email addresses, posing risks for phishing attacks. The attack was carried out by unidentified threat actors utilizing automated scripts to extract data from the vulnerable API.

RSS feed for this category →

Now playing Bandcamp