Tag / 21 entries / page 1 of 3 / feed available

Sensitive Information

21 of the 76 analyses in Data Breaches carry this tag. All 21 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

076

JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)

Contained by: PEC, EGR

JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.

075

Allianz Life Insurance Company of North America Data Breach (July 2025)

A threat actor used social engineering to access a third-party cloud-based CRM used by Allianz Life Insurance Company of North America and exfiltrated sensitive personal information. The incident affected approximately 1.5 million customers, financial professionals, and select employees, with exposed data potentially including names, addresses, dates of birth, Social Security numbers, email addresses, and phone numbers. The responsible threat actor or group was not confirmed, although the breach was linked in reporting to a broader campaign associated with ShinyHunters, Scattered Spider, and UNC6040.

072

PowerSchool Student Information System Data Breach (December 2024)

Prevented by: HSF

An unauthorized party used a compromised credential with password-only access to the PowerSource customer-support portal and exported student and teacher data from PowerSchool SIS environments. Exposed information varied by customer and could include names, contact details, dates of birth, addresses, SSNs or SINs, medical information, grades, parent or guardian data, and passwords. DOJ-related reporting placed the affected population at approximately 62 million individuals, although other reported figures were not reconciled. Matthew D. Lane later pleaded guilty to conduct related to the breach, while subsequent extortion attempts indicated that stolen data may have remained available.

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

070

Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)

Prevented by: PEC, EGR

The China-linked Salt Typhoon cyber-espionage campaign compromised at least eight U.S. telecommunications providers, with a ninth operator subsequently identified, and affected providers in more than 20 other countries. Attackers accessed carrier infrastructure and surveillance-adjacent systems and collected customer call data, metadata, law-enforcement surveillance-request data, and selected private communications involving government and politically prominent individuals. The campaign exploited exposed and vulnerable network devices, compromised credentials, and trusted provider relationships; officials and congressional testimony reported that more than one million users may have been affected.

067

Army National Guard Salt Typhoon Network Compromise (March–December 2024)

Prevented by: EGR · Contained by: HSF

A PRC-associated Salt Typhoon actor extensively compromised the Army National Guard network of an unidentified U.S. state from March through December 2024. The actor reportedly accessed or exfiltrated administrator credentials, network configurations and diagrams, a geographic map, and service-member personally identifiable information, while collecting configuration and traffic involving Guard networks in every other state and at least four territories. NJCCIC reported entry through a weakly configured remote-access service, followed by lateral spread and control of several privileged accounts, although the complete attack chain was not publicly established.

065

Change Healthcare February 2024 Data Breach

Prevented by: HSF, PEC, EGR

The Change Healthcare breach in February 2024 involved a ransomware attack by the BlackCat group, significantly disrupting pharmacy operations. Approximately 6TB of sensitive data, including health records, was potentially compromised. The attack exploited vulnerabilities in Citrix remote-access software, highlighting security weaknesses in multi-factor authentication.

063

23andMe Data Breach

Prevented by: HSF

In December 2023, a data breach at genetic testing company 23andMe exposed the personal data of approximately 6.9 million users to unauthorized access. The breach, executed through credential stuffing, compromised user profiles and familial connections, leaving sensitive personal data vulnerable. It underscored the need for robust password practices and security measures such as multi-factor authentication.

059

Indian Council of Medical Research Data Breach 2023

Prevented by: HSF, EGR

In October 2023, the Indian Council of Medical Research experienced a major data breach that led to the exposure of 815 million records, including Aadhaar IDs, passport details, names, phone numbers, and addresses. The data was compromised by a hacker identified as pwn0001, who made the information available for sale on the dark web. The breach involved significant security vulnerabilities, particularly in access controls and encryption practices, indicating a need for improved data protection measures.

050

PharMerica Data Breach March 2023

Prevented by: PEC, EGR

In March 2023, PharMerica experienced a major data breach affecting approximately 5.8 million individuals. The incident involved the compromise of extensive patient data, including Social Security numbers, health records, and insurance information. The breach was executed by the Money Message ransomware group using double extortion tactics, leading to significant privacy risks and identity theft concerns.

RSS feed for this tag →

Now playing Bandcamp