<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data Exfiltration on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/data-exfiltration/</link>
    <description>Recent content in Data Exfiltration on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/data-exfiltration/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Allianz Life Insurance Company of North America Data Breach (July 2025)</title>
      <link>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</guid>
      <description>Executive Summary Incident summary On July 16, 2025, a threat actor used social engineering to access a third-party, cloud-based customer relationship management (CRM) system used by Allianz Life Insurance Company of North America. Allianz Life’s official account states that it became aware of suspicious activity on July 17 at 12:17 p.m. CDT and terminated access to accounts associated with that activity at 2:17 p.m. CDT. (agportal-s3bucket.s3.amazonaws.com ) The company reported no indication that the threat actor accessed its company network or systems outside the CRM; this does not establish that the CRM was deliberately isolated.</description>
    </item>
    <item>
      <title>Qantas Airways Customer Data Breach (June 2025)</title>
      <link>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</link>
      <pubDate>Sat, 28 Jun 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</guid>
      <description>Executive Summary On 30 June 2025, Qantas detected unusual activity on a third-party platform used by an overseas airline contact centre. The OAIC’s later account states that an agent had been socially engineered on 28 June and that the attacker used the agent’s legitimate CRM access to connect a third-party data-extraction application; Qantas froze and revoked the associated account on 30 June. (oaic.gov.au ) Qantas publicly disclosed the incident on 2 July and subsequently reported approximately 5.</description>
    </item>
    <item>
      <title>Conduent Business Services Data Breach (January 2025)</title>
      <link>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</link>
      <pubDate>Mon, 13 Jan 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/conduent-business-services-data-breach-january-2025/</guid>
      <description>Executive Summary Conduent Business Services, a business-process outsourcing provider for government agencies, health plans, and other enterprises, discovered on January 13, 2025 that an unauthorized third party had accessed a limited portion of its environment and that client-associated files had been exfiltrated. Subsequent investigation placed the beginning of unauthorized access on October 21, 2024. Conduent restored affected systems within days, and in some cases within hours, but the data review and notification process continued through 2025 and into 2026.</description>
    </item>
    <item>
      <title>PowerSchool Student Information System Data Breach (December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</link>
      <pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</guid>
      <description>Executive Summary On December 28, 2024, PowerSchool said it became aware that an unauthorized party had exfiltrated personal information from PowerSchool Student Information System (SIS) environments through the PowerSource customer-support portal. Later reporting and forensic summaries place unauthorized activity earlier: CrowdStrike found evidence beginning December 19, while customer guidance reported data first stolen on December 22. PowerSchool notified affected customers on January 7, 2025 and publicly posted an incident disclosure on January 13.</description>
    </item>
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>Army National Guard Salt Typhoon Network Compromise (March–December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</guid>
      <description>Executive Summary Between March and December 2024, Salt Typhoon extensively compromised the Army National Guard network of an unidentified U.S. state. A June 11, 2025 Department of Homeland Security Office of Intelligence and Analysis memorandum, obtained through a Freedom of Information Act request and circulated in June, described the incident; public reporting began in July 2025 (bleepingcomputer.com ; nbcnews.com ). The intrusion persisted for approximately nine months, but the sources do not provide an exact discovery date or a separate resolution date (bleepingcomputer.</description>
    </item>
    <item>
      <title>Fujitsu Malware Attack 2024</title>
      <link>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</guid>
      <description>Executive Summary In March 2024, Fujitsu identified a malware infection on its corporate network, indicating a notable cybersecurity breach that potentially compromised customer information. Details of the breach were made public on March 15, 2024, highlighting unauthorized access achieved using advanced malware techniques (source , source , source ).&#xA;Severity of Impact The incident is classified as severe, as it may involve sensitive customer data exposure. Although certain data access was confirmed, no misuse evidence has emerged so far (source ).</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>U-Haul Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/u-haul-data-breach/</link>
      <pubDate>Tue, 05 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/u-haul-data-breach/</guid>
      <description>Executive Summary The U-Haul data breach was publicly disclosed in February 2024, impacting approximately 67,000 customers across the United States and Canada. Initially discovered on December 5, 2023, unauthorized individuals accessed an internal system by exploiting stolen credentials, exposing sensitive personal information, including customer names and driver’s license numbers. Financial information remained unaffected (BleepingComputer ; SecurityWeek ).&#xA;Severity of the Impact The exposure of personal identifiers poses risks such as identity theft, although the absence of financial data reduction slightly limits potential damage.</description>
    </item>
    <item>
      <title>23andMe Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/23andme-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/23andme-data-breach/</guid>
      <description>Executive Summary In December 2023, 23andMe, a leader in consumer genetic testing, disclosed a data breach resulting from credential stuffing attacks, compromising the personal data of approximately 6.9 million users. This type of attack utilized stolen credentials from unrelated data breaches, impacting user accounts by exploiting weak password practices.&#xA;Key Dates Breach Discovery: Initial indications arose on October 4, 2023, with public acknowledgment on October 6, 2023. Formal Disclosure: Comprehensive disclosure of the breach&amp;rsquo;s details occurred in December 2023.</description>
    </item>
    <item>
      <title>British Library Ransomware Attack October 2023</title>
      <link>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</link>
      <pubDate>Sat, 28 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/british-library-ransomware-attack-october-2023/</guid>
      <description>Executive Summary The British Library experienced a ransomware attack carried out by the Rhysida ransomware group in 2023. This cyber incident was identified on October 28, 2023. Public announcements regarding ongoing technology outages followed on November 17, 2023. The attack demonstrated vulnerabilities within the library&amp;rsquo;s IT infrastructure, resulting in significant disruptions due to data encryption.&#xA;Severity of the Impact The ransomware attack severely affected services, disrupting digital and physical operations including public Wi-Fi and possibly internal human resources files.</description>
    </item>
    <item>
      <title>Indian Council of Medical Research Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</link>
      <pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</guid>
      <description>Executive Summary In 2023, the Indian Council of Medical Research (ICMR) experienced a significant data breach, resulting in the unauthorized access and theft of approximately 815 million records. The data compromised included sensitive personal information such as Aadhaar IDs, passport details, names, phone numbers, and addresses. The threat actor, identified as pwn0001, advertised the stolen data for sale on the dark web (source , source , source ).&#xA;Incident Details Discovery Date: October 9, 2023, when the data sale was announced on dark web forums.</description>
    </item>
    <item>
      <title>DuoLingo Data Breach August 2023</title>
      <link>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</link>
      <pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</guid>
      <description>Executive Summary In August 2023, DuoLingo experienced a significant data exposure incident caused by a data scraping attack targeting an exposed Application Programming Interface (API). The breach affected approximately 2.6 million users, with personal data such as names, email addresses, and other identifiable information being posted online (source 1 , source 4 ).&#xA;Severity of Impact The exposure compromised personal information of approximately 2.6 million users, including critical identifiers like login names and email addresses, heightening risks for phishing and other cyber threats (source 3 , source 6 ).</description>
    </item>
    <item>
      <title>MOVEit Data Breach June 2023</title>
      <link>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</link>
      <pubDate>Thu, 01 Jun 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/moveit-data-breach-june-2023/</guid>
      <description>Executive Summary In June 2023, a significant data breach involving the MOVEit Transfer software began; within its first weeks it had affected over 200 organizations globally, a toll that continued climbing for more than a year afterward (Axios ). This breach was triggered by exploiting a zero-day vulnerability, CVE-2023-34362, within the MOVEit Transfer tool by Progress Software Corporation. The Clop ransomware group, using its Ransomware as a Service (RaaS) model, claimed responsibility for the data theft operations.</description>
    </item>
    <item>
      <title>Tesla Massive Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/tesla-massive-data-breach/</link>
      <pubDate>Wed, 10 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/tesla-massive-data-breach/</guid>
      <description>Executive Summary The Tesla Massive Data Breach, discovered in May 2023, was a significant incident involving the unauthorized disclosure of sensitive data by two former employees to Handelsblatt, a German media outlet. On May 10, 2023, this breach came to light when Handelsblatt informed Tesla of their possession of approximately 100 gigabytes of confidential data, involving over 23,000 internal files (CentralEyes , Hackread ).&#xA;Severity of Impact The breach impacted over 75,735 individuals, including both current and former employees.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Yum! Brands Ransomware Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</link>
      <pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</guid>
      <description>Executive Summary In January 2023, Yum! Brands, which owns KFC, Taco Bell, and Pizza Hut, fell victim to a ransomware attack, resulting in a data breach. This incident compromised corporate and employee data and was publicly disclosed by Yum! Brands in April 2023. Formal notifications to employees and potentially affected individuals about the data compromise began around the same time.&#xA;Discovery and Disclosure The ransomware attack was first identified in January 2023.</description>
    </item>
    <item>
      <title>Discord Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</link>
      <pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</guid>
      <description>Executive Summary Incident Overview In March 2023, Discord faced a data breach due to security vulnerabilities at a third-party service provider. This led to the compromise of customer data. The breach was identified on March 29, 2023, publicly disclosed by May 12, 2023, and user notifications commenced on August 21, 2023 (BleepingComputer ).&#xA;Severity of Impact The breach exposed sensitive personal information of approximately 180 users, including names and state or driver&amp;rsquo;s license numbers, highlighting privacy concerns despite its limited scope relative to Discord&amp;rsquo;s extensive user base (HackRead ; Economic Times ).</description>
    </item>
    <item>
      <title>PharMerica Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</link>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, PharMerica, a prominent U.S. pharmacy services provider, encountered a notable data breach affecting approximately 5,815,591 individuals. This incident compromised sensitive patient information, impacting both PharMerica and its parent company, BrightSpring Health Services (source ).&#xA;Breach Timeline Intrusion Period: Unauthorized access was gained from March 12 to 13, 2023. Discovery Date: The breach was discovered on March 14, 2023. Public Disclosure: Notifications were issued to individuals on May 12, 2023.</description>
    </item>
    <item>
      <title>Consumer Financial Protection Bureau Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</link>
      <pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</guid>
      <description>Executive Summary In 2023, the Consumer Financial Protection Bureau (CFPB) experienced a significant data breach due to internal security lapses. An employee transferred confidential records via email to a personal account, compromising the data of approximately 256,000 individuals. This incident underscores critical deficiencies in CFPB&amp;rsquo;s data protection protocols and has raised considerable concerns over internal security measures. Source Severity of Impact The breach affected records from seven financial institutions; however, some reports suggest this number could be higher.</description>
    </item>
    <item>
      <title>Google Fi Data Breach Linked to T-Mobile Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</guid>
      <description>Executive Summary Incident Overview: In February 2023, Google Fi suffered a data breach due to vulnerabilities originating from a prior T-Mobile security incident. This breach exposed Google Fi customers&amp;rsquo; phone numbers and related technical details, posing significant risks such as SIM swap attacks and unauthorized account activities (source ).&#xA;Key Dates: The association with T-Mobile&amp;rsquo;s broader data breach was identified on January 19, 2023. Affected individuals received notifications in early February 2023 (source ).</description>
    </item>
    <item>
      <title>NCB Management Services Data Breach February 2023</title>
      <link>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ncb-management-services-data-breach-february-2023/</guid>
      <description>Executive Summary In February 2023, NCB Management Services experienced a significant data breach due to an unauthorized system compromise, exposing sensitive personal and financial information. The breach was detected on February 4, 2023, affecting clients associated with major financial institutions including Capital One, Bank of America, and TD Bank.&#xA;Severity of the Impact The breach compromised data for over 1 million individuals, with specific numbers varying by institution: approximately 16,779 Capital One customers and nearly 495,000 Bank of America customers were directly impacted.</description>
    </item>
    <item>
      <title>MailChimp January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</link>
      <pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</guid>
      <description>Executive Summary Incident Overview In January 2023, MailChimp was subjected to a data breach due to a social engineering attack that affected its internal customer support tool. This breach, the second in a span of six months, indicates potential weaknesses in MailChimp&amp;rsquo;s defensive measures.&#xA;Key Dates and Discovery Details The breach was discovered on January 11, 2023, during a routine security review and was publicly disclosed on January 19, 2023. This prompt notification ensured that stakeholders were adequately informed.</description>
    </item>
    <item>
      <title>T-Mobile January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</link>
      <pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</guid>
      <description>Executive Summary In January 2023, T-Mobile disclosed a significant data breach that affected approximately 37 million current customers. The breach, initiated through unauthorized access to an API, began in late November 2022. T-Mobile detected the breach on January 5, 2023, and publicly disclosed it on January 19, 2023.&#xA;Technical Details The breach was facilitated through a vulnerability in an API, which allowed attackers to access personal data, including names, billing addresses, email addresses, phone numbers, and dates of birth.</description>
    </item>
    <item>
      <title>Los Angeles Unified School District (LAUSD) Ransomware Breach</title>
      <link>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</link>
      <pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</guid>
      <description>Executive Summary In September 2022, the Los Angeles Unified School District (LAUSD), the second-largest school district in the United States, experienced a significant ransomware attack orchestrated by the Vice Society gang. This incident, detected over the Labor Day holiday weekend, compromised more than 1,000 schools, affecting approximately 600,000 students and staff members. Sensitive data, including psychological evaluations and Social Security numbers, was exposed and disseminated on the dark web following LAUSD&amp;rsquo;s decision not to pay the ransom source .</description>
    </item>
    <item>
      <title>Yahoo Intellectual Property Theft</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-intellectual-property-theft/</link>
      <pubDate>Fri, 11 Feb 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-intellectual-property-theft/</guid>
      <description>Executive Summary In February 2022, Yahoo experienced a significant insider threat incident involving the alleged theft of intellectual property by Qian Sang, a former employee. The breach occurred when Sang, upon receiving a job offer from direct competitor The Trade Desk, allegedly exfiltrated approximately 570,000 pages of proprietary information. This data included:&#xA;Source code Advertising algorithms Internal strategy documents The stolen information was related to Yahoo&amp;rsquo;s demand-side platform (DSP) for real-time ad buying, known as AdLearn.</description>
    </item>
    <item>
      <title>Cash App Data Breach - April 2022</title>
      <link>https://securityblueprints.io/data-breaches/cash-app-data-breach/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/cash-app-data-breach/</guid>
      <description>Executive Summary In April 2022, Block, the parent company of Cash App, disclosed a significant data breach involving unauthorized access by a former employee, who downloaded sensitive financial information from approximately 8.2 million users. This exposure included brokerage account details and stock trading activities. The breach was publicly announced on April 4, 2022 (source ). Despite the breadth of affected data, no personally identifiable information such as usernames, passwords, or Social Security numbers was compromised (source ).</description>
    </item>
    <item>
      <title>South Georgia Medical Center Data Theft</title>
      <link>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</link>
      <pubDate>Fri, 12 Nov 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</guid>
      <description>Executive Summary The November 2021 data breach at South Georgia Medical Center (SGMC) was caused by a former employee downloading patient data onto a USB drive without authorization. This incident underscores the risks associated with insider threats and highlights the necessity for stringent data security protocols.&#xA;Incident Details Breach Type: Insider data theft involving unauthorized transfer of patient information. Compromised Data: Included protected health information such as patient names, birth dates, and test results.</description>
    </item>
    <item>
      <title>Sina Weibo Data Breach 2020</title>
      <link>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</link>
      <pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</guid>
      <description>Executive Summary In March 2020, Sina Weibo, a leading Chinese microblogging platform, experienced a significant data breach impacting approximately 538 million users. The breach was publicly acknowledged when an attacker leveraged a logic flaw in the Sina Weibo API to access and sell personal user information on the dark web for about USD 250. This breach exposed sensitive details such as real names, usernames, gender, location, and phone numbers for 172 million users, though passwords were not compromised.</description>
    </item>
    <item>
      <title>SolarWinds Supply Chain Attack</title>
      <link>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</link>
      <pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/solarwinds-supply-chain-attack/</guid>
      <description>Executive Summary The SolarWinds Supply Chain Attack represents a pivotal cyber incident with substantial global repercussions. This sophisticated breach resulted in the compromise of SolarWinds&amp;rsquo; software development infrastructure, spreading malicious updates within their Orion software. The attack, initiated in September 2019, culminated with the distribution of malicious updates starting in March 2020, which were installed by over 18,000 SolarWinds customers. This infiltration allowed attackers unauthorized access for data theft and espionage, as publicly disclosed in December 2020.</description>
    </item>
    <item>
      <title>Marriott International Data Breach of 2018</title>
      <link>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</link>
      <pubDate>Fri, 30 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/marriott-international-data-breach-of-2018/</guid>
      <description>Executive Summary In 2018, Marriott International suffered a data breach that compromised approximately 500 million guest records. This breach, dating back to 2014, primarily affected the Starwood guest reservation system, which was acquired by Marriott in 2016. Personal data exposed included names, addresses, phone numbers, email addresses, passport numbers, and credit card details (source , source ).&#xA;Severity of Impact This breach is noted for its wide scale, causing significant exposure of personal data and inflicting reputational damage on Marriott.</description>
    </item>
    <item>
      <title>Copay Cryptocurrency Wallet Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</link>
      <pubDate>Tue, 27 Nov 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/copay-cryptocurrency-wallet-data-breach/</guid>
      <description>Executive Summary In November 2018, the Copay cryptocurrency wallet, developed by BitPay, experienced a data breach due to a malicious update to the event-stream Node.js library, specifically within its flatmap-stream dependency. Unauthorized access to users&amp;rsquo; private keys and cryptocurrency funds was achieved, significantly impacting wallets containing over 100 Bitcoins or 1000 Bitcoin Cash source .&#xA;Key Dates August 5, 2018: Initial release of the flatmap-stream package. September 9, 2018: Integration of flatmap-stream into event-stream.</description>
    </item>
    <item>
      <title>Aadhaar Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</link>
      <pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</guid>
      <description>Executive Summary In January 2018, a significant data breach compromised Aadhaar, the world&amp;rsquo;s largest identification database, managed by the Unique Identification Authority of India (UIDAI). The breach affected personal information—biometric and financial data—of approximately 1.1 billion Indian citizens. The affected information was allegedly retailed for as little as ₹500 via WhatsApp, pointing to extensive security flaws (Legal Service India , FirstPost ).&#xA;Severity of Impact The exposure of biometric details like fingerprints and iris scans poses severe risks related to identity theft and fraud, thus threatening the privacy and security of citizens.</description>
    </item>
    <item>
      <title>2017 Equifax Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</link>
      <pubDate>Sat, 29 Jul 2017 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2017-equifax-data-breach/</guid>
      <description>Executive Summary The 2017 Equifax data breach marked a critical event in data security, caused by exploiting a known vulnerability, CVE-2017-5638, in the Apache Struts web application framework. Unauthorized access led to the exposure of sensitive information of approximately 145.5 million individuals.&#xA;Severity of Impact This breach was one of the largest in history, significantly affecting Personally Identifiable Information (PII), including names, Social Security numbers, birth dates, and, in certain instances, driver&amp;rsquo;s license numbers and credit card data.</description>
    </item>
    <item>
      <title>2016 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</link>
      <pubDate>Mon, 14 Nov 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</guid>
      <description>Executive Summary On November 14, 2016, a data breach exposed records of approximately 57 million Uber users and 600,000 driver license numbers. The breach occurred when hackers exploited Uber&amp;rsquo;s systems by using stolen credentials to access its GitHub repository, subsequently gaining entry into an AWS S3 bucket containing sensitive user data such as names, email addresses, and phone numbers. For further details, refer to this source .&#xA;Key Events November 14, 2016: Attackers demanded a ransom for stolen data deletion.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>JPMorgan Chase Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</link>
      <pubDate>Sun, 01 Jun 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</guid>
      <description>Executive Summary In June 2014, JPMorgan Chase became the target of a significant data breach, compromising data from over 76 million households and 7 million small businesses. The breach, discovered in July and publicly disclosed in September 2014, highlighted substantial deficiencies in the bank’s cybersecurity framework (source ).&#xA;Severity of Impact Approximately 83 million accounts were affected, with exposed data including names, addresses, phone numbers, and email addresses. However, no financial data or Social Security numbers were compromised, reducing the risk of direct financial fraud, yet increasing chances for phishing and identity theft (source ).</description>
    </item>
    <item>
      <title>2014 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</link>
      <pubDate>Mon, 12 May 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</guid>
      <description>Executive Summary In 2014, Uber experienced a significant data breach, where approximately 50,000 consumers&amp;rsquo; sensitive information, particularly names and driver&amp;rsquo;s license numbers, was accessed without authorization. This incident arose from the mishandling of an unencrypted Amazon Web Services (AWS) access key that was inadvertently published on GitHub, thereby allowing attackers unauthorized system access. (source , source )&#xA;Key Dates:&#xA;May 12, 2014: Attackers gained access to Uber&amp;rsquo;s AWS account by exploiting a publicly exposed AWS access key on GitHub.</description>
    </item>
    <item>
      <title>Home Depot Data Breach April 2014</title>
      <link>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</link>
      <pubDate>Tue, 01 Apr 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/home-depot-data-breach-april-2014/</guid>
      <description>Executive Summary In April 2014, Home Depot faced a significant data breach resulting in the theft of over 56 million payment card records. Custom-built malware targeted Home Depot&amp;rsquo;s point-of-sale (POS) systems, affecting customers across the United States and Canada. The breach was detected in September 2014.&#xA;Severity of Impact The breach is among the largest recorded in retail history, with anticipated financial consequences projected to potentially reach $179 million, encompassing immediate response and legal costs.</description>
    </item>
    <item>
      <title>Adobe 2013 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</link>
      <pubDate>Thu, 03 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</guid>
      <description>Executive Summary In October 2013, Adobe became the victim of a cyberattack that compromised nearly 153 million user records, ranking as one of the largest breaches in cybersecurity history (source ). The attack resulted in the exposure of encrypted customer credit card information and user account details, prompting concerns about Adobe&amp;rsquo;s cybersecurity protocols (source ).&#xA;Key Details Breach Discovery: Internal discovery occurred on September 17, 2013, with public disclosure by Adobe on October 3, 2013 (source ).</description>
    </item>
    <item>
      <title>Court Ventures (Experian) Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</link>
      <pubDate>Tue, 01 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/court-ventures-experian-data-breach/</guid>
      <description>Executive Summary In October 2013, a significant data breach involving Court Ventures was publicly reported. This breach followed Experian&amp;rsquo;s acquisition of Court Ventures in March 2012 and involved unauthorized access to a database containing sensitive information of approximately 200 million individuals. The breach was perpetuated by Hieu Minh Ngo, a Vietnamese national, exploiting the database via a business relationship between Court Ventures and US Info Search. Compromised data included Social Security numbers and credit card details (source ).</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
    <item>
      <title>MySpace Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/myspace-data-breach/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/myspace-data-breach/</guid>
      <description>Executive Summary The MySpace data breach disclosed in June 2016 affected over 360 million user accounts, underscoring substantial deficiencies in the company&amp;rsquo;s data security measures. At the time, MySpace utilized weak hashing algorithms like SHA-1 without salting, a method known for its cryptographic weaknesses. Users&amp;rsquo; widespread password reuse across different services amplified the breach&amp;rsquo;s repercussions. Consequently, MySpace updated its security practices post-breach, transitioning to double-salted hashes.&#xA;Technical Details The breach highlighted significant vulnerabilities due to inadequate security measures.</description>
    </item>
    <item>
      <title>Greece Government Data Breach 2012</title>
      <link>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/greece-government-data-breach-2012/</guid>
      <description>Executive Summary In 2012, the Greece government experienced a significant data breach that led to the unauthorized exposure of 9,000,000 records, affecting approximately 83% of the nation&amp;rsquo;s population. This breach involved sensitive information, including addresses, ID card data, tax ID numbers, and license plate numbers.&#xA;A sophisticated hacking attack exploited vulnerabilities in the government’s IT infrastructure, with a 35-year-old hacker identified as the primary suspect who allegedly sought to monetize the stolen data.</description>
    </item>
    <item>
      <title>LinkedIn Password Breach</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-password-breach/</link>
      <pubDate>Fri, 01 Jun 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-password-breach/</guid>
      <description>Executive Summary In 2012, LinkedIn experienced a significant data breach affecting its user base. Initially reported to have compromised 6.5 million hashed passwords, the breach&amp;rsquo;s true extent, revealed in 2016, affected over 117 million accounts. The compromised passwords were stored using the SHA1 hashing algorithm without salting, making them vulnerable to brute force and rainbow table attacks. These inadequacies exposed LinkedIn users to substantial risks as the leaked credentials circulated on cybercrime forums like LeakedSource.</description>
    </item>
    <item>
      <title>Google Aurora Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-aurora-incident/</link>
      <pubDate>Tue, 01 Dec 2009 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-aurora-incident/</guid>
      <description>Executive Summary The Google Aurora incident, occurring in December 2009, was a significant cybersecurity breach affecting Google and multiple other corporations in various industries, particularly technology. The attack aimed to steal intellectual property and unauthorized Gmail access of Chinese human rights activists. It is widely attributed to state-sponsored entities linked to the Chinese government, employing sophisticated cyber espionage tactics.&#xA;Major Threat Actors The attack is attributed to entities based in China, utilizing Advanced Persistent Threat (APT) techniques.</description>
    </item>
    <item>
      <title>Heartland Payment Systems Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</link>
      <pubDate>Wed, 26 Dec 2007 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</guid>
      <description>Executive Summary Heartland Payment Systems experienced a major data breach compromising approximately 130 million payment card records, marking one of the largest breaches involving consumer credit and debit card information. The breach originated from SQL injection attacks and malware deployment starting around December 26, 2007, and was discovered by authorities in October 2008. Public disclosure followed on January 20, 2009. This information is corroborated by multiple sources (source , source , source ).</description>
    </item>
    <item>
      <title>TJX Companies Inc. Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</link>
      <pubDate>Fri, 01 Jul 2005 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/tjx-companies-inc.-data-breach/</guid>
      <description>Executive Summary The TJX Companies Inc., a major retailer with brands such as TJ Maxx and Marshalls, suffered a significant data breach disclosed in January 2007, affecting approximately 94 million records. The breach revealed critical vulnerabilities in TJX&amp;rsquo;s data protection protocols and stands as one of the largest security incidents in retail history.&#xA;Key Dates Initial Intrusion: July 2005 Discovery: December 2006 Public Disclosure: January 17, 2007 (source ) Severity of Impact The data breach involved 94 million records, including credit and debit card data and personal information such as driver&amp;rsquo;s license numbers.</description>
    </item>
  </channel>
</rss>
