Tag / 38 entries / page 1 of 4 / feed available

User Data

38 of the 76 analyses in Data Breaches carry this tag. All 38 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

074

Qantas Airways Customer Data Breach (June 2025)

An attacker socially engineered an overseas contact-centre agent into authorizing an attacker-controlled data-extraction application against the agent’s legitimate CRM access. Approximately 5.7 million unique Qantas customer records were affected, including names, email addresses, Frequent Flyer information and, for subsets, addresses, dates of birth, phone numbers, gender and meal preferences. Qantas said passwords, PINs, payment, financial, passport and Frequent Flyer login data were not accessed. The initial intruder attribution was not confirmed; later reporting identified Scattered Lapsus$ Hunters as the collective that reportedly published some records after extortion activity.

070

Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)

Prevented by: PEC, EGR

The China-linked Salt Typhoon cyber-espionage campaign compromised at least eight U.S. telecommunications providers, with a ninth operator subsequently identified, and affected providers in more than 20 other countries. Attackers accessed carrier infrastructure and surveillance-adjacent systems and collected customer call data, metadata, law-enforcement surveillance-request data, and selected private communications involving government and politically prominent individuals. The campaign exploited exposed and vulnerable network devices, compromised credentials, and trusted provider relationships; officials and congressional testimony reported that more than one million users may have been affected.

069

National Public Data Breach of April 2024

Prevented by: HSF

In April 2024, National Public Data experienced a significant breach that exposed Social Security Numbers, addresses, and phone numbers of hundreds of millions of Americans. This breach, attributed to a security lapse involving administrative credential exposure, allowed unauthorized access to up to 2.9 billion records. The threat actor identified as USDoD exploited this vulnerability, selling the compromised data on the dark web.

068

American Express Data Breach March 2024

Prevented by: EGR

In March 2024, American Express disclosed a data breach caused by unauthorized access to a third-party merchant processor, exposing customer names, account numbers, and expiration dates. The breach resulted from a point-of-sale attack, impacting vendor management systems, without directly compromising American Express’s internal databases. While the specific threat actors remain unidentified, the breach underscores potential risks to customer data integrity.

066

Fujitsu Malware Attack 2024

Prevented by: PEC, EGR

In March 2024, Fujitsu experienced a significant cybersecurity breach involving malware on its corporate network. The incident potentially exposed customer information, though there is no evidence of data misuse. The malware used sophisticated evasion techniques, indicating a high level of attacker skill, but the threat actors remain unidentified. The breach primarily affected Fujitsu’s operations in Japan, impacting 49 computers.

063

23andMe Data Breach

Prevented by: HSF

In December 2023, a data breach at genetic testing company 23andMe exposed the personal data of approximately 6.9 million users to unauthorized access. The breach, executed through credential stuffing, compromised user profiles and familial connections, leaving sensitive personal data vulnerable. It underscored the need for robust password practices and security measures such as multi-factor authentication.

057

DuoLingo Data Breach August 2023

In August 2023, DuoLingo suffered a data breach affecting over 2.6 million users due to a data scraping attack exploiting an exposed API. Compromised data included names and email addresses, posing risks for phishing attacks. The attack was carried out by unidentified threat actors utilizing automated scripts to extract data from the vulnerable API.

054

Microsoft Email Accounts Security Breach

In May 2023, Microsoft suffered a data breach conducted by China-based hackers, Storm-0558, who used forged authentication tokens to access customer email accounts. This breach impacted governmental entities, resulting in the unauthorized access and potential exfiltration of approximately 60,000 unclassified emails, emphasizing the breach’s serious national security implications.

053

Yum! Brands Ransomware Data Breach

Prevented by: PEC, EGR · Contained by: HSF

In January 2023, Yum! Brands, owner of KFC, Taco Bell, and Pizza Hut, experienced a data breach following a ransomware attack. The breach exposed sensitive employee information, including names and Social Security Numbers. While corporate data was compromised, no customer data was initially reported as affected. Unknown cybercriminals were responsible for the attack, which led to temporary closures of restaurants in the UK.

052

Discord Data Breach March 2023

Prevented by: HSF

In March 2023, a data breach occurred at Discord due to security vulnerabilities at a third-party service provider, compromising sensitive personal information of approximately 180 users including names and driver’s license numbers. The breach was facilitated through unauthorized access, likely achieved via compromised credentials due to phishing or social engineering. No specific threat actors were identified in the report.

RSS feed for this tag →

Now playing Bandcamp