<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Sensitive Information on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/sensitive-information/</link>
    <description>Recent content in Sensitive Information on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/sensitive-information/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Allianz Life Insurance Company of North America Data Breach (July 2025)</title>
      <link>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</link>
      <pubDate>Wed, 16 Jul 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/allianz-life-insurance-company-of-north-america-data-breach-july-2025/</guid>
      <description>Executive Summary Incident summary On July 16, 2025, a threat actor used social engineering to access a third-party, cloud-based customer relationship management (CRM) system used by Allianz Life Insurance Company of North America. Allianz Life’s official account states that it became aware of suspicious activity on July 17 at 12:17 p.m. CDT and terminated access to accounts associated with that activity at 2:17 p.m. CDT. (agportal-s3bucket.s3.amazonaws.com ) The company reported no indication that the threat actor accessed its company network or systems outside the CRM; this does not establish that the CRM was deliberately isolated.</description>
    </item>
    <item>
      <title>PowerSchool Student Information System Data Breach (December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</link>
      <pubDate>Thu, 19 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/powerschool-student-information-system-data-breach-december-2024/</guid>
      <description>Executive Summary On December 28, 2024, PowerSchool said it became aware that an unauthorized party had exfiltrated personal information from PowerSchool Student Information System (SIS) environments through the PowerSource customer-support portal. Later reporting and forensic summaries place unauthorized activity earlier: CrowdStrike found evidence beginning December 19, while customer guidance reported data first stolen on December 22. PowerSchool notified affected customers on January 7, 2025 and publicly posted an incident disclosure on January 13.</description>
    </item>
    <item>
      <title>U.S. Department of the Treasury BeyondTrust Breach December 2024</title>
      <link>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</link>
      <pubDate>Mon, 02 Dec 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/us-department-of-the-treasury-beyondtrust-breach-december-2024/</guid>
      <description>Executive Summary Key facts:&#xA;Who: Treasury initially attributed the intrusion generically to &amp;ldquo;a China state-sponsored Advanced Persistent Threat (APT) actor&amp;rdquo; (wired.com ; bleepingcomputer.com ); a Wednesday Bloomberg report later attributed it to Silk Typhoon (formerly Hafnium); OFAC separately sanctioned contractor Yin Kecheng, a Shanghai-based, decade-active actor tied to China&amp;rsquo;s Ministry of State Security, on January 17, 2025, as &amp;ldquo;associated with the recent compromise&amp;rdquo; (bleepingcomputer.com ; techcrunch.com ; home.treasury.gov ). China&amp;rsquo;s embassy denied involvement (en.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>Army National Guard Salt Typhoon Network Compromise (March–December 2024)</title>
      <link>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/army-national-guard-salt-typhoon-network-compromise-marchdecember-2024/</guid>
      <description>Executive Summary Between March and December 2024, Salt Typhoon extensively compromised the Army National Guard network of an unidentified U.S. state. A June 11, 2025 Department of Homeland Security Office of Intelligence and Analysis memorandum, obtained through a Freedom of Information Act request and circulated in June, described the incident; public reporting began in July 2025 (bleepingcomputer.com ; nbcnews.com ). The intrusion persisted for approximately nine months, but the sources do not provide an exact discovery date or a separate resolution date (bleepingcomputer.</description>
    </item>
    <item>
      <title>Change Healthcare February 2024 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</link>
      <pubDate>Mon, 12 Feb 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/change-healthcare-february-2024-data-breach/</guid>
      <description>Executive Summary The Change Healthcare data breach involved a ransomware attack in February 2024, attributed to the BlackCat group, also known as ALPHV. This cyber assault led to considerable disruptions within pharmacy operations and potentially exposed sensitive client data. source Severity of Impact The breach significantly impacted Change Healthcare&amp;rsquo;s extensive network, which comprises over 1.6 million healthcare professionals, 70,000 pharmacies, and 8,000 healthcare facilities. The breach&amp;rsquo;s financial impact is estimated at $872 million, highlighting the substantial economic consequences.</description>
    </item>
    <item>
      <title>23andMe Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/23andme-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/23andme-data-breach/</guid>
      <description>Executive Summary In December 2023, 23andMe, a leader in consumer genetic testing, disclosed a data breach resulting from credential stuffing attacks, compromising the personal data of approximately 6.9 million users. This type of attack utilized stolen credentials from unrelated data breaches, impacting user accounts by exploiting weak password practices.&#xA;Key Dates Breach Discovery: Initial indications arose on October 4, 2023, with public acknowledgment on October 6, 2023. Formal Disclosure: Comprehensive disclosure of the breach&amp;rsquo;s details occurred in December 2023.</description>
    </item>
    <item>
      <title>Indian Council of Medical Research Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</link>
      <pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/indian-council-of-medical-research-data-breach-2023/</guid>
      <description>Executive Summary In 2023, the Indian Council of Medical Research (ICMR) experienced a significant data breach, resulting in the unauthorized access and theft of approximately 815 million records. The data compromised included sensitive personal information such as Aadhaar IDs, passport details, names, phone numbers, and addresses. The threat actor, identified as pwn0001, advertised the stolen data for sale on the dark web (source , source , source ).&#xA;Incident Details Discovery Date: October 9, 2023, when the data sale was announced on dark web forums.</description>
    </item>
    <item>
      <title>PharMerica Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</link>
      <pubDate>Mon, 13 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pharmerica-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, PharMerica, a prominent U.S. pharmacy services provider, encountered a notable data breach affecting approximately 5,815,591 individuals. This incident compromised sensitive patient information, impacting both PharMerica and its parent company, BrightSpring Health Services (source ).&#xA;Breach Timeline Intrusion Period: Unauthorized access was gained from March 12 to 13, 2023. Discovery Date: The breach was discovered on March 14, 2023. Public Disclosure: Notifications were issued to individuals on May 12, 2023.</description>
    </item>
    <item>
      <title>Los Angeles Unified School District (LAUSD) Ransomware Breach</title>
      <link>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</link>
      <pubDate>Thu, 01 Sep 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/los-angeles-unified-school-district-lausd-ransomware-breach/</guid>
      <description>Executive Summary In September 2022, the Los Angeles Unified School District (LAUSD), the second-largest school district in the United States, experienced a significant ransomware attack orchestrated by the Vice Society gang. This incident, detected over the Labor Day holiday weekend, compromised more than 1,000 schools, affecting approximately 600,000 students and staff members. Sensitive data, including psychological evaluations and Social Security numbers, was exposed and disseminated on the dark web following LAUSD&amp;rsquo;s decision not to pay the ransom source .</description>
    </item>
    <item>
      <title>Cash App Data Breach - April 2022</title>
      <link>https://securityblueprints.io/data-breaches/cash-app-data-breach/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/cash-app-data-breach/</guid>
      <description>Executive Summary In April 2022, Block, the parent company of Cash App, disclosed a significant data breach involving unauthorized access by a former employee, who downloaded sensitive financial information from approximately 8.2 million users. This exposure included brokerage account details and stock trading activities. The breach was publicly announced on April 4, 2022 (source ). Despite the breadth of affected data, no personally identifiable information such as usernames, passwords, or Social Security numbers was compromised (source ).</description>
    </item>
    <item>
      <title>South Georgia Medical Center Data Theft</title>
      <link>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</link>
      <pubDate>Fri, 12 Nov 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</guid>
      <description>Executive Summary The November 2021 data breach at South Georgia Medical Center (SGMC) was caused by a former employee downloading patient data onto a USB drive without authorization. This incident underscores the risks associated with insider threats and highlights the necessity for stringent data security protocols.&#xA;Incident Details Breach Type: Insider data theft involving unauthorized transfer of patient information. Compromised Data: Included protected health information such as patient names, birth dates, and test results.</description>
    </item>
    <item>
      <title>Microsoft Exchange Server Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</link>
      <pubDate>Sun, 03 Jan 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-exchange-server-breach/</guid>
      <description>Executive Summary In January 2021, Microsoft Exchange email servers were targeted in a significant cyberattack that exploited multiple zero-day vulnerabilities, affecting over 30,000 organizations in the United States. Initially detected by Volexity on January 3, 2021, the breach was publicly acknowledged by Microsoft on March 2, 2021, upon releasing emergency patches (source , source ).&#xA;Severity of the Impact Globally, the breach compromised up to 250,000 servers, impacting critical sectors such as government, banking, and infrastructure, thereby posing risks to operational integrity and data confidentiality (source , source ).</description>
    </item>
    <item>
      <title>Aadhaar Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</link>
      <pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</guid>
      <description>Executive Summary In January 2018, a significant data breach compromised Aadhaar, the world&amp;rsquo;s largest identification database, managed by the Unique Identification Authority of India (UIDAI). The breach affected personal information—biometric and financial data—of approximately 1.1 billion Indian citizens. The affected information was allegedly retailed for as little as ₹500 via WhatsApp, pointing to extensive security flaws (Legal Service India , FirstPost ).&#xA;Severity of Impact The exposure of biometric details like fingerprints and iris scans poses severe risks related to identity theft and fraud, thus threatening the privacy and security of citizens.</description>
    </item>
    <item>
      <title>AdultFriendFinder Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</guid>
      <description>Executive Summary The AdultFriendFinder data breach, a significant incident in 2016, compromised approximately 412 million user accounts across platforms under FriendFinder Networks, including AdultFriendFinder.com, Cams.com, and Penthouse.com. This breach unveiled notable security vulnerabilities within the company&amp;rsquo;s systems.&#xA;Breach Details The breach occurred in October 2016 when attackers exploited Local File Inclusion (LFI) vulnerabilities within the website&amp;rsquo;s architecture, enabling unauthorized access to sensitive information. This data was publicly posted on November 13, 2016.</description>
    </item>
    <item>
      <title>Office of Personnel Management Data Breach 2015</title>
      <link>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</link>
      <pubDate>Wed, 01 Apr 2015 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/office-of-personnel-management-data-breach-2015/</guid>
      <description>Executive Summary In 2015, the U.S. Office of Personnel Management (OPM) faced a significant data breach resulting in the exposure of sensitive information of approximately 21.5 million individuals. This incident, one of the largest in U.S. government history, involved an initial breach affecting 4.2 million personnel records and a subsequent larger breach involving detailed background investigation data. This report details the technical and organizational failures that led to the breach and assesses its impact.</description>
    </item>
    <item>
      <title>eBay Data Breach Analysis</title>
      <link>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</link>
      <pubDate>Fri, 28 Feb 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</guid>
      <description>Executive Summary In early 2014, eBay, a leading online marketplace, experienced a significant data breach, which was publicly disclosed in May 2014. Unauthorized access to approximately 145 million user records occurred due to compromised employee credentials. The breach period spanned late February to early March 2014 (CRN , NY Times ).&#xA;Severity and Impact The breach is considered extensive, with unauthorized access to records including names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates.</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
    <item>
      <title>MySpace Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/myspace-data-breach/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/myspace-data-breach/</guid>
      <description>Executive Summary The MySpace data breach disclosed in June 2016 affected over 360 million user accounts, underscoring substantial deficiencies in the company&amp;rsquo;s data security measures. At the time, MySpace utilized weak hashing algorithms like SHA-1 without salting, a method known for its cryptographic weaknesses. Users&amp;rsquo; widespread password reuse across different services amplified the breach&amp;rsquo;s repercussions. Consequently, MySpace updated its security practices post-breach, transitioning to double-salted hashes.&#xA;Technical Details The breach highlighted significant vulnerabilities due to inadequate security measures.</description>
    </item>
    <item>
      <title>California Department of Child Support Services Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</link>
      <pubDate>Mon, 12 Mar 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/california-department-of-child-support-services-data-breach/</guid>
      <description>Executive Summary Breach Name: California Department of Child Support Services Breach Date: 2012 Discovery Date: March 12, 2012 Disclosure Date: March 29, 2012 Incident Overview In 2012, the California Department of Child Support Services (DCSS) suffered a data breach due to the loss of magnetic tape cartridges, which occurred during a disaster recovery exercise managed by IBM and Iron Mountain Inc. Between Boulder, Colorado, and Sacramento, California, four of fifteen tapes went missing, containing the sensitive information of approximately 800,000 individuals.</description>
    </item>
  </channel>
</rss>
