<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Phishing on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/phishing/</link>
    <description>Recent content in Phishing on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/phishing/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Qantas Airways Customer Data Breach (June 2025)</title>
      <link>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</link>
      <pubDate>Sat, 28 Jun 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</guid>
      <description>Executive Summary On 30 June 2025, Qantas detected unusual activity on a third-party platform used by an overseas airline contact centre. The OAIC’s later account states that an agent had been socially engineered on 28 June and that the attacker used the agent’s legitimate CRM access to connect a third-party data-extraction application; Qantas froze and revoked the associated account on 30 June. (oaic.gov.au ) Qantas publicly disclosed the incident on 2 July and subsequently reported approximately 5.</description>
    </item>
    <item>
      <title>Discord Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</link>
      <pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</guid>
      <description>Executive Summary Incident Overview In March 2023, Discord faced a data breach due to security vulnerabilities at a third-party service provider. This led to the compromise of customer data. The breach was identified on March 29, 2023, publicly disclosed by May 12, 2023, and user notifications commenced on August 21, 2023 (BleepingComputer ).&#xA;Severity of Impact The breach exposed sensitive personal information of approximately 180 users, including names and state or driver&amp;rsquo;s license numbers, highlighting privacy concerns despite its limited scope relative to Discord&amp;rsquo;s extensive user base (HackRead ; Economic Times ).</description>
    </item>
    <item>
      <title>MailChimp January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</link>
      <pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</guid>
      <description>Executive Summary Incident Overview In January 2023, MailChimp was subjected to a data breach due to a social engineering attack that affected its internal customer support tool. This breach, the second in a span of six months, indicates potential weaknesses in MailChimp&amp;rsquo;s defensive measures.&#xA;Key Dates and Discovery Details The breach was discovered on January 11, 2023, during a routine security review and was publicly disclosed on January 19, 2023. This prompt notification ensured that stakeholders were adequately informed.</description>
    </item>
    <item>
      <title>Activision HR Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</link>
      <pubDate>Sun, 04 Dec 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</guid>
      <description>Executive Summary In December 2022, Activision, a leading video game developer, encountered a data breach caused by a sophisticated SMS phishing attack targeting a Human Resources (HR) employee. This breach resulted in unauthorized access to internal data, including employee names, phone numbers, email addresses, job titles, and workplace locations. Despite discrepancies regarding the exact public disclosure date, the breach became widely acknowledged in February 2023, highlighting substantial risks to employee data security [TechCrunch ] [Intrix ].</description>
    </item>
    <item>
      <title>Twitter 2020 Data Breach Incident</title>
      <link>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</link>
      <pubDate>Wed, 15 Jul 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</guid>
      <description>Executive Summary In July 2020, a critical cybersecurity breach, termed the Twitter 2020 Data Breach, occurred, wherein a 17-year-old hacker, Graham Ivan Clark, along with accomplices, exploited vulnerabilities in Twitter’s security infrastructure. They gained unauthorized access to Twitter&amp;rsquo;s internal network, commandeering numerous high-profile accounts to disseminate a Bitcoin scam.&#xA;Key Dates Breach Occurrence: July 15, 2020 Public Disclosure: July 15, 2020 Severity of Impact The breach affected highly influential accounts such as those of Barack Obama and Elon Musk, resulting in fraudulent tweets promoting a Bitcoin scam.</description>
    </item>
    <item>
      <title>Norsk Hydro Ransomware Attack - March 2019</title>
      <link>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</link>
      <pubDate>Tue, 19 Mar 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norsk-hydro-ransomware-attack/</guid>
      <description>Executive Summary In March 2019, Norsk Hydro, a significant global aluminum producer, encountered a ransomware attack via the LockerGoga malware. This attack caused substantial disruptions across 160 locations, impacting over 20,000 systems worldwide, and forced the company to shift to manual operations (source ).&#xA;Key Dates Discovery and Disclosure Date: March 19, 2019 Severity of Impact The attack resulted in significant financial repercussions, with initial losses estimated at $40 million USD within the first week, subsequently summing to over 350 million Norwegian krone (source ).</description>
    </item>
    <item>
      <title>Anthem Data Breach Incident Analysis</title>
      <link>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/anthem-data-breach-incident-analysis/</guid>
      <description>Executive Summary The data breach at Anthem Inc. in 2015 stands as a critical incident in healthcare cybersecurity, involving unauthorized access to approximately 78.8 million records. The breach was disclosed publicly on February 4, 2015, illustrating significant weaknesses within the protection of Personal Identifiable Information (PII) in healthcare systems. This incident underscores a vital need for enhanced cybersecurity measures in the sector, emphasizing the risks associated with large-scale data compromises.</description>
    </item>
    <item>
      <title>JPMorgan Chase Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</link>
      <pubDate>Sun, 01 Jun 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jpmorgan-chase-data-breach/</guid>
      <description>Executive Summary In June 2014, JPMorgan Chase became the target of a significant data breach, compromising data from over 76 million households and 7 million small businesses. The breach, discovered in July and publicly disclosed in September 2014, highlighted substantial deficiencies in the bank’s cybersecurity framework (source ).&#xA;Severity of Impact Approximately 83 million accounts were affected, with exposed data including names, addresses, phone numbers, and email addresses. However, no financial data or Social Security numbers were compromised, reducing the risk of direct financial fraud, yet increasing chances for phishing and identity theft (source ).</description>
    </item>
    <item>
      <title>eBay Data Breach Analysis</title>
      <link>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</link>
      <pubDate>Fri, 28 Feb 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</guid>
      <description>Executive Summary In early 2014, eBay, a leading online marketplace, experienced a significant data breach, which was publicly disclosed in May 2014. Unauthorized access to approximately 145 million user records occurred due to compromised employee credentials. The breach period spanned late February to early March 2014 (CRN , NY Times ).&#xA;Severity and Impact The breach is considered extensive, with unauthorized access to records including names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates.</description>
    </item>
    <item>
      <title>Target Data Breach 2013</title>
      <link>https://securityblueprints.io/data-breaches/target-data-breach-2013/</link>
      <pubDate>Wed, 18 Dec 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/target-data-breach-2013/</guid>
      <description>Executive Summary In December 2013, Target Corporation fell victim to a major data breach, impacting its operational security and customer trust by exposing approximately 110 million customer records, including financial and personal information. The breach became public after security researcher Brian Krebs disclosed it, revealing that unauthorized access was gained via compromised credentials from a third-party vendor, Fazio Mechanical Services (1) (2) .&#xA;Severity of Impact The breach led to the disclosure of 40 million credit and debit card numbers and 70 million records containing personal information, marking it as one of the significant incidents in retail data breaches.</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
  </channel>
</rss>
