Breach news

Reported breaches, what was taken, and how the intrusion started.

994 reports

Aflac Incorporated

Aflac discloses network intrusion tied to insurance sector campaign

HackingInsurance

Disneyland Paris

Anubis group claimed 64 GB of Disneyland Paris files from a contractor

Third-Party Data BreachEntertainment

Krispy Kreme

Krispy Kreme breach exposed data on 161,676 people after 2024 attack

RansomwareFood & Beverage

Oxford City Council

Oxford City Council breach exposed 21 years of election worker records

HackingGovernment

Chain IQ

Chain IQ breach spilled contact data on more than 100,000 UBS employees

HackingBusiness Services

Ocuco

Ocuco breach exposes health data of about 241,000 people

RansomwareHealthcare Technology

WestJet

WestJet investigates cyberattack affecting internal systems and app

HackingAirline

Zoomcar Holdings, Inc.

Zoomcar discloses breach affecting 8.4 million users

HackingTransportation

Yes24

Ransomware attack takes South Korean ticketing platform Yes24 offline

RansomwareE-commerce & Ticketing

Erie Insurance

Erie Insurance confirms cyberattack behind multi-week outage

HackingInsurance

United Natural Foods, Inc.

Cyberattack on United Natural Foods disrupts grocery distribution

HackingFood Distribution

Episource

Episource breach exposed health records of more than 5.4 million people

HackingHealthcare

Illinois Department of Healthcare and Family Services

Illinois healthcare agency reports phishing breach affecting 933 people

PhishingGovernment

Jackson Health System

Jackson Health System fires employee over five-year patient data snooping

Malicious InsiderHealthcare

KiranaPro

KiranaPro blames former employee after AWS and GitHub data wipe

Malicious InsiderRetail

Optima Tax Relief

Chaos ransomware group leaked 69 GB stolen from Optima Tax Relief

RansomwareFinancial Services

HM Revenue and Customs (HMRC)

HMRC says phishing fraud hit 100,000 tax accounts and cost 47 million pounds

PhishingGovernment

The North Face (VF Outdoor)

The North Face discloses April credential stuffing attack on customer accounts

Credential CompromiseRetail

Cartier

Cartier tells clients names and email addresses were stolen in system breach

HackingRetail

City of Durant, Oklahoma

Ransomware attack disrupts services for the city of Durant, Oklahoma

RansomwareGovernment

MainStreet Bank (MainStreet Bancshares, Inc.)

MainStreet Bank customer card data exposed in third-party vendor breach

Third-Party Data BreachFinancial Services

Missouri Department of Conservation

Missouri Department of Conservation breach exposed employee health plan data

HackingGovernment

DataPost

DataPost ransomware attack exposed data of 146 Income Insurance policyholders

RansomwareBusiness Services

Victoria's Secret & Co.

Victoria's Secret takes down U.S. website after security incident

HackingRetail

Covenant Health

Covenant Health cyberattack disrupts hospitals in Maine and New Hampshire

RansomwareHealthcare

LexisNexis Risk Solutions

LexisNexis Risk Solutions breach on GitHub exposed data of 364,000 people

Credential CompromiseBusiness Services

MathWorks

MathWorks confirms ransomware attack behind MATLAB service outages

RansomwareTechnology

Tiffany & Co.

Tiffany & Co. discloses South Korean customer data breach at third-party platform

Third-Party Data BreachRetail

Adidas

Adidas discloses customer data breach at third-party service provider

Third-Party Data BreachRetail

West Lothian Council

West Lothian Council confirms school data stolen in Interlock ransomware attack

RansomwareGovernment

Cellcom

Cellcom confirms cyberattack behind week-long voice and text outage in Wisconsin

HackingTelecommunications

Kettering Health

Interlock ransomware attack shuts down systems across Ohio's Kettering Health

RansomwareHealthcare

Peter Green Chilled

Ransomware attack on Peter Green Chilled disrupts UK supermarket food supplies

RansomwareTransportation & Logistics

Effortel

Effortel breach exposes data of 70,000 Belgian mobile customers

HackingTelecommunications

Serviceaide

Serviceaide database exposure hit 483,000 Catholic Health patients

MisconfigurationInformation Technology

MKA Accountants

Qilin ransomware gang lists Melbourne firm MKA Accountants as a victim

RansomwareProfessional Services

Christian Dior Couture

Christian Dior Couture confirms customer data breach affecting Asian shoppers

PhishingRetail

Coinbase Global, Inc.

Coinbase says bribed overseas support agents leaked customer data

Malicious InsiderFinancial Services

Nova Scotia Power

Nova Scotia Power confirms theft of customer data in ransomware attack

RansomwareUtilities

Nucor Corporation

Nucor halts steel production at multiple sites after cyberattack

HackingManufacturing

City of Edinburgh Council

Edinburgh council resets school network passwords after phishing attack

PhishingEducation

Legal Aid Agency

U.K. Legal Aid Agency warns providers of security incident on its online systems

HackingGovernment

Masimo Corporation

Masimo cyberattack slowed manufacturing at the medical device maker

HackingMedical Devices

Oettinger Getränke

German brewer Oettinger confirms cyberattack claimed by RansomHouse

RansomwareFood and Beverage

South African Airways

South African Airways says cyberattack disrupted website, app and internal systems

HackingAviation

Global Crossing Airlines (GlobalX)

Hacktivists breached deportation charter airline GlobalX and took flight manifests

HackingAviation

Harrods

Harrods restricted internet access after attempted intrusion on its systems

HackingRetail

Co-op Group

Co-op Group confirmed member data theft after DragonForce intrusion

RansomwareRetail

Texas Health and Human Services Commission

Texas HHSC says employees improperly accessed data of about 94,000 people

Malicious InsiderGovernment

Kintetsu World Express

Kintetsu World Express confirmed ransomware attack disrupted its systems

RansomwareShipping & Logistics

Barnstable County Sheriff's Office

Insider breach at Barnstable County Sheriff's Office exposed employee records

Malicious InsiderGovernment

Yale New Haven Health System

Yale New Haven Health breach exposed data on nearly 5.6 million patients

HackingHealthcare

Marks & Spencer

Marks and Spencer halted online orders after DragonForce ransomware attack

RansomwareRetail

The Hertz Corporation

Hertz confirmed customer data theft through the Cleo file transfer exploit

Third-Party Data BreachTravel & Leisure

Sensata Technologies

Sensata Technologies ransomware attack halts shipping and production

RansomwareManufacturing

SK Group

Qilin ransomware gang claims 1TB theft from SK Group's U.S. arm

RansomwareConglomerate

Western Sydney University

Western Sydney University breach exposed records of 10,000 students

HackingEducation

Blue Shield of California

Blue Shield of California sent member health data to Google Ads by misconfiguration

MisconfigurationHealthcare

Oregon Department of Environmental Quality

Oregon environmental agency shuts down network after cyberattack

RansomwareGovernment

WooCommerce (Automattic)

Hacker claims WooCommerce data breach, Automattic denies its systems were hit

Third-Party Data BreachE-commerce Software

Caisse Nationale de Sécurité Sociale (CNSS), Morocco

Morocco's social security fund CNSS had data on nearly 2 million people leaked

HackingGovernment

NASCAR

Medusa ransomware group claimed a NASCAR breach and demanded $4 million

RansomwareSports & Entertainment

Office of the Comptroller of the Currency

U.S. bank regulator OCC discloses year-long email system breach

HackingGovernment

DBS Bank

DBS and Bank of China Singapore customer data exposed by vendor ransomware

Third-Party Data BreachFinancial Services

Fall River Public Schools

Fall River Public Schools in Massachusetts hit by ransomware attack

RansomwareEducation

AustralianSuper

AustralianSuper and rival funds hit by coordinated credential stuffing

Credential CompromisePensions and Retirement Savings

Central Texas Pediatric Orthopedics

Central Texas Pediatric Orthopedics breach affected 140,000 patients

HackingHealthcare

WK Kellogg Co.

WK Kellogg confirms employee data breach tied to Cleo file transfer flaws

Third-Party Data BreachFood and Beverage Manufacturing

State Bar of Texas

State Bar of Texas confirmed data theft after an attack claimed by INC Ransom

RansomwareLegal Services

Twilio

Twilio denies SendGrid breach after hacker offers 848,000 records for sale

HackingTechnology

Royal Mail Group

Royal Mail data leaked after breach at supplier Spectos

Third-Party Data BreachPostal and Logistics

City of Baltimore

City of Baltimore lost $1.5 million to a vendor impersonation scheme

Business Email CompromiseGovernment

Lower Sioux Indian Community

Ransomware attack disrupted Lower Sioux Indian Community casino and health services

RansomwareTribal Government

Laborers' International Union of North America Local 1184

LiUNA Local 1184 notified members of a 2024 ransomware data breach

RansomwareLabor Union

Samsung Germany

Samsung Germany support tickets leaked after four-year-old credentials were reused

Credential CompromiseTechnology

Parcel Plus

Parcel Plus tax clients had refunds redirected after spear phishing attack

PhishingProfessional Services

German Association for East European Studies (DGO)

German East European studies association breached again, Russia suspected

HackingNon-profit Research

Nine Entertainment

Nine exposed 16,000 Australian newspaper subscribers through a supplier lapse

Third-Party Data BreachMedia

New South Wales Department of Communities and Justice

NSW justice department breach exposed 9,000 court files including violence orders

HackingGovernment

Lee University

Lee University notifies about 137,000 people a year after network breach

RansomwareEducation

Oracle

Oracle denies cloud breach as researchers back hacker's six million record claim

HackingTechnology

Western Alliance Bank

Western Alliance Bank notifies 21,899 customers after Cleo file transfer breach

Third-Party Data BreachFinancial Services

ALN Medical Management, LLC

ALN Medical Management discloses 2024 breach of third-party hosted systems

HackingHealthcare

Ukrzaliznytsia

Cyberattack knocks out Ukrainian railway Ukrzaliznytsia's online ticketing

HackingTransportation

University of Notre Dame Australia

University of Notre Dame Australia struggles to recover from January cyberattack

RansomwareEducation

Pennsylvania State Education Association

PSEA notified more than 517,000 people after Rhysida claimed 2024 breach

RansomwareNon-profit

James Pascoe Group

James Pascoe Group cyberattack disrupts Farmers and Whitcoulls stores

RansomwareRetail

Ganong Bros. Ltd.

Ganong Bros. chocolate plant disrupted by ransomware attack claimed by Play

RansomwareManufacturing

Yap State Department of Health Services

Ransomware forced Micronesia's Yap health department offline

RansomwareGovernment

Bis Industries

Bis Industries investigates RansomHub claims over December 2024 attack

RansomwareMining Services

Sorbonne Université

FunkSec claimed a breach at Sorbonne Universite; the university called it limited

RansomwareEducation

Lake Washington Vascular

Lake Washington Vascular restored from backups after Qilin ransomware attack

RansomwareHealthcare

Sunflower Medical Group

Sunflower Medical Group breach exposed data on nearly 221,000 patients

RansomwareHealthcare

Bank of America

Bank of America warned customers after document destruction vendor mishandled records

Third-Party Data BreachFinancial Services

Chicago Public Schools

Chicago Public Schools says Cleo vendor breach exposed 700,000 students

Third-Party Data BreachEducation

NTT Communications Corporation

NTT Communications breach exposed data on nearly 18,000 corporate customers

HackingTelecommunications

Berkeley Research Group

Berkeley Research Group discloses ransomware attack during LBO debt sale

RansomwareBusiness Services

Carruth Compliance Consulting

Carruth Compliance Consulting breach exposed data on tens of thousands of school staff

RansomwareBusiness Services

National Presto Industries

National Presto Industries disrupted by March 2025 cyberattack

RansomwareManufacturing

Australian New Zealand Clinical Trials Registry

Clinical trials registry ANZCTR taken offline after University of Sydney breach

HackingHealthcare

Orange Group

Orange Group confirms breach of Romanian back office systems

HackingTelecommunications

Anne Arundel County, Maryland

Anne Arundel County closed buildings after ransomware attack on its network

RansomwareGovernment

Cleveland Municipal Court

Cyber incident closed Cleveland Municipal Court for more than two weeks

RansomwareGovernment

DISA Global Solutions, Inc.

DISA Global Solutions breach exposed data on 3.3 million screening subjects

HackingBusiness Services

HCRG Care Group

Medusa gang demanded $2m from UK healthcare provider HCRG Care Group

RansomwareHealthcare

Hipshipper

Hipshipper left 14.3 million shipping records exposed in open cloud bucket

MisconfigurationTransportation & Logistics

Inspira Financial Trust, LLC

Call center contractor accessed data on 2,308 Inspira Financial savers

Third-Party Data BreachFinancial Services

Rainbow District School Board

Rainbow District School Board cyberattack exposed decades of student and staff data

RansomwareEducation

Genea

Genea discloses breach after Termite ransomware attack on IVF clinics

RansomwareHealthcare

NioCorp Developments Ltd.

NioCorp Developments lost $500,000 to an email compromise scam

Business Email CompromiseMining & Natural Resources

The Agency

Rhysida claimed a ransomware attack on London talent agency The Agency

RansomwareMedia & Entertainment

Nippon Steel

BianLian claims theft of 500 GB from Nippon Steel's US operations

RansomwareManufacturing

Unimicron Technology

Sarcoma ransomware group claims 377 GB stolen from PCB maker Unimicron

RansomwareManufacturing

Office of the Attorney General of Virginia

Cyberattack knocked the Virginia Attorney General's office offline

HackingGovernment

Mars Hydro

Unsecured Mars Hydro database exposed 2.7 billion IoT records

MisconfigurationManufacturing

Pinehurst Radiology Associates, PLLC

Pinehurst Radiology Associates closed indefinitely after cyberattack

HackingHealthcare

Sault Ste. Marie Tribe of Chippewa Indians

Ransomware shut Kewadin Casinos and Sault Tribe services across Michigan

RansomwareTravel & Leisure

CPI UK

Ransomware attack halted book printer CPI UK's production for weeks

RansomwarePrinting & Publishing

Memorial Hospital and Manor

Memorial Hospital and Manor notified 120,085 people after ransomware attack

RansomwareHealthcare

Sanrio Entertainment

Sanrio Entertainment ransomware attack put up to 2 million records at risk

RansomwareEntertainment

IMI plc

IMI plc disclosed unauthorised access to its systems in a stock exchange filing

HackingEngineering

Community Health Center, Inc.

Community Health Center breach exposed data on more than 1 million patients

HackingHealthcare

Grubhub

Grubhub breach traced to a third-party customer support provider

Third-Party Data BreachOnline Food Delivery

Lee Enterprises

Cyberattack halted printing and publishing across Lee Enterprises newspapers

RansomwareMedia

Tata Technologies

Tata Technologies reports ransomware attack in stock exchange filing

RansomwareEngineering Services

Mizuno USA

Mizuno USA said attackers spent two months copying files from its network

RansomwareManufacturing

DeepSeek

DeepSeek left a database of chat logs and API keys exposed online

MisconfigurationTechnology (Artificial Intelligence)

New York Blood Center Enterprises

Ransomware attack on New York Blood Center disrupts collections

RansomwareHealthcare

Smiths Group plc

Smiths Group discloses unauthorized access to its systems

HackingEngineering & Manufacturing

ARDEX Australia

Medusa ransomware group claims attack on ARDEX Australia

RansomwareConstruction Products

The British Museum

British Museum partly closed after dismissed contractor shut down systems

Malicious InsiderArts and Culture

Conduent

Conduent confirms cyberattack behind US government service outages

HackingBusiness Services

Hewlett Packard Enterprise

HPE investigates IntelBroker claim of stolen source code and repositories

HackingTechnology

Mortgage Investors Group

Mortgage Investors Group discloses December breach after Black Basta claim

RansomwareFinancial Services

Chemeketa Community College

Chemeketa Community College staff data exposed in Carruth Compliance breach

Third-Party Data BreachEducation

Divimast

Akira ransomware lists Italian ERP consultancy Divimast on its leak site

RansomwareInformation Technology

Otelier

Otelier breach exposes hotel guest reservations for Marriott, Hilton and Hyatt

Credential CompromiseHospitality Technology

Avery Products Corporation

Avery says card skimmer sat on its website for nearly five months

HackingManufacturing

Willow Pays

Willow Pays left customer bill payment database open on the internet

MisconfigurationFinancial Services

Roseltorg

Roseltorg confirms cyberattack on Russia's state procurement platform

HackingGovernment

Eindhoven University of Technology (TU/e)

Eindhoven University of Technology shuts down network after cyberattack

HackingEducation

Geodesy, Cartography and Cadastre Office of the Slovak Republic (UGKK)

Ransomware shuts Slovakia's land registry office UGKK, stalling property deals

RansomwareGovernment

Unacast

Unacast tells Norwegian regulator hackers took Gravy Analytics location data

Credential CompromiseTechnology

Indiana University Health

Indiana University Health email compromise exposed patient records

Credential CompromiseHealthcare

Alcool NB Liquor (NB Liquor)

NB Liquor shut down point of sale systems after suspected cyberattack

HackingRetail

International Civil Aviation Organization

ICAO confirms recruitment database breach affecting nearly 12,000 people

HackingGovernment

PowerSchool

PowerSchool breach exposes K-12 student and teacher records worldwide

Credential CompromiseEducation Technology

Policía de Seguridad Aeroportuaria

Argentina's airport security police hit by payroll data breach

HackingGovernment

RegionTransService LLC

Ukraine's HUR claims destructive attack on rail firm RegionTransService

HackingLogistics & Transport

Bank of America

Bank of America notifies loan customers after third-party provider breach

Third-Party Data BreachBanking & Finance

Fraunhofer Institute for Industrial Engineering IAO

Ransomware attack hit Germany's Fraunhofer IAO research institute in Stuttgart

RansomwareResearch & Education

DE Photo

DE Photo hit by back-to-back intrusions over Christmas 2024

HackingPhotography Services

Las Palmas Del Sol Healthcare (El Paso Healthcare System, Ltd.)

Las Palmas Del Sol Healthcare told 1,854 patients a former employee viewed their records

Malicious InsiderHealthcare

U.S. Department of the Treasury

Chinese state hackers breached US Treasury workstations through BeyondTrust

Supply Chain AttackGovernment

Nikki-Universal Co., Ltd.

Nikki-Universal confirms ransomware attack on its servers

RansomwareChemical Manufacturing

Youth Eastside Services

Youth Eastside Services breach exposed mental health client records in Washington

RansomwareHealthcare

Turks and Caicos Islands Government

Turks and Caicos government recovers from pre-Christmas ransomware attack

RansomwareGovernment

Center for Vein Restoration

Center for Vein Restoration breach exposed data on 446,094 patients and staff

HackingHealthcare

Wood County, Ohio

Ransomware sends Wood County, Ohio emergency dispatch back to pen and paper

RansomwareGovernment

Artivion

Artivion tells SEC cyberattack disrupted order and shipping processes

RansomwareMedical Devices

Kurita Water Industries (Kurita America Inc.)

Ransomware hit Kurita Water Industries' US arm, exposing customer and staff data

RansomwareWater Treatment

Luka Rijeka d.d. (Port of Rijeka)

8Base ransomware group claimed a data theft at Croatia's Port of Rijeka

RansomwareLogistics & Transport

BT Group

BT Group confirms attempted attack on conferencing unit claimed by Black Basta

RansomwareTelecommunications

Chemonics International

Chemonics International discloses 2023 intrusion affecting 263,136 people

HackingGovernment Contractor

ENGlobal Corporation

ENGlobal discloses ransomware attack that limited access to its IT systems

RansomwareEnergy

Refinadora Costarricense de Petróleo (RECOPE)

Ransomware forced Costa Rica's state fuel company RECOPE to sell fuel manually

RansomwareEnergy & Utility

Uganda - Bank of Uganda

Bank of Uganda lost millions after international payments were diverted

HackingFinance

Italy - Bologna FC 1909

Bologna FC confirmed ransomware attack after RansomHub leaked club data

RansomwareSports and Entertainment

U.S. Veterans Health Administration

Veterans Health Administration notifies 2,302 veterans after vendor attack

Third-Party Data BreachGovernment Healthcare

UK - Alder Hey Children's NHS Foundation Trust

INC Ransom published data stolen from Alder Hey Children's NHS trust

RansomwareHealthcare

Cabot Financial (Ireland)

Cabot Financial Ireland tells High Court 394,000 files were stolen

HackingFinancial Services

City of Hoboken, New Jersey

Ransomware attack shut down City of Hoboken government operations

RansomwareGovernment

Wirral University Teaching Hospital NHS Foundation Trust

Wirral University Teaching Hospital NHS trust declares major incident after cyberattack

HackingHealthcare

Starbucks

Starbucks fell back on manual payroll after Blue Yonder ransomware attack

Third-Party Service DisruptionFood and Beverage Retail

Texas Tech University Health Sciences Center

Texas Tech University Health Sciences Center breach hit 1.46 million patients

RansomwareHealthcare

Vogue Homes

KillSec claims data theft from Australian home builder Vogue Homes

RansomwareConstruction

Pacific Pulmonary Medical Group

Everest gang dumped Pacific Pulmonary Medical Group patient records

Credential CompromiseHealthcare

Blue Yonder

Blue Yonder ransomware attack disrupts grocery and retail supply chains

RansomwareSoftware

Japan - Kumamoto Prefecture Anti-Violence Movement Promotion Center

Kumamoto anti-violence counseling center warned of possible data leak

PhishingNonprofit

Bojangles' Restaurants, Inc.

Bojangles notifies employees of data breach months after intrusion

HackingRestaurants

Finastra

Finastra investigates breach of internal file transfer platform

Credential CompromiseFinancial Technology

International Game Technology

International Game Technology takes systems offline after cyberattack

HackingGambling Technology

Government of Mexico (gob.mx)

RansomHub claimed 313 GB stolen from Mexican government legal office

RansomwareGovernment

T-Mobile US

T-Mobile named in Salt Typhoon espionage campaign against US telecoms

HackingTelecommunications

DemandScience

DemandScience confirms leaked 122 million record database came from its systems

HackingBusiness Services

Hungarian Defence Procurement Agency (VBU)

Hungary confirmed INC Ransom hack of its defence procurement agency

RansomwareGovernment

Alberta Innovates

Alberta Innovates confirmed unauthorized access to its network

HackingGovernment Agency

American Associated Pharmacies

Embargo ransomware group claimed attack on American Associated Pharmacies

RansomwarePharmacy

TEAM Software

TEAM Software breach exposed personal data on 99,525 people

HackingSoftware

Amazon

Amazon employee contact data surfaced in MOVEit leak from a vendor

Third-Party Data BreachRetail

BBS Financial Services, LLC

BBS Financial Services paid a ransom after breach affecting 70,168 people

RansomwareAccounting Services

Hot Topic

Hot Topic breach exposed records on nearly 57 million retail customers

Third-Party Data BreachRetail

Ahold Delhaize USA

Ahold Delhaize cyberattack disrupted US grocery pharmacies and online orders

HackingRetail

Newpark Resources

Newpark Resources discloses ransomware attack in SEC filing

RansomwareEnergy

Standard Bank

Standard Bank employee copied client data to an unprotected personal device

Malicious InsiderBanking

Nokia

Nokia denied breach after IntelBroker leaked contractor source code

Third-Party Data BreachTelecommunications

Schneider Electric

Schneider Electric investigated Hellcat theft of 40GB from its Jira server

RansomwareEnergy

Belle Tire Distributors

Belle Tire notifies nearly 30,000 people after June 2024 network intrusion

HackingAutomotive Retail

Housing Authority of the City of Los Angeles (HACLA)

Los Angeles housing authority HACLA confirms second ransomware attack

RansomwareGovernment

South East Technological University

Cyberattack shut down IT systems at South East Technological University

HackingEducation

Van Wagner Group

Van Wagner Group breach exposed Social Security numbers of 5,354 people

HackingAdvertising and Marketing

Microlise

Microlise cyberattack knocked out DHL and Serco vehicle tracking in the UK

RansomwareTechnology

Interbank

Interbank confirms customer data breach after dark web listing

HackingFinancial Services

Australian Nursing Home Foundation

Abyss ransomware claims 1.5TB from Australian Nursing Home Foundation

RansomwareHealthcare

AEP GmbH

German pharmaceutical wholesaler AEP hit by ransomware attack

RansomwareHealthcare

Free SAS

French ISP Free confirms breach of subscriber data

HackingTelecommunications

BronxWorks Inc.

BronxWorks disclosed 2023 email breach exposing client and employee data

HackingNon-profit

Landmark Admin, LLC

Landmark Admin breach exposed data of more than 800,000 insurance customers

RansomwareInsurance Services

Arkansas Blue Cross and Blue Shield

Vendor breach at Healthmine exposed Arkansas Blue Cross member data

Third-Party Data BreachHealth Insurance

Johnson & Johnson, Inc. (insurance firm)

Insurance firm Johnson & Johnson disclosed August 2024 breach affecting 3,200

HackingInsurance

Berufsbildungszentrum Schaffhausen (BBZ)

Ransomware attack blocked systems at Swiss vocational school BBZ Schaffhausen

RansomwareEducation

Kansas City Hospice & Palliative Care

BlackSuit ransomware listed Kansas City Hospice and Palliative Care

RansomwareHealthcare

Globe Life Inc.

Globe Life extorted over data stolen from American Income Life

HackingInsurance

Nidec Corporation

Nidec confirms 50,694 files leaked from Vietnamese subsidiary

RansomwareManufacturing

Cisco Systems

Cisco traces IntelBroker data leak to public DevHub portal

MisconfigurationTechnology

Funlab

Funlab confirms Lynx ransomware attack on Australian entertainment group

RansomwareEntertainment

Varsity Brands

Varsity Brands breach exposed data of more than 65,000 people

HackingApparel Manufacturing

Axis Health System

Axis Health System investigates Rhysida ransomware attack in Colorado

RansomwareHealthcare

Calgary Public Library

Calgary Public Library closed all branches after cyberattack

HackingGovernment

Casio Computer Co., Ltd.

Casio confirms data theft after Underground ransomware attack

RansomwareConsumer Electronics

Intesa Sanpaolo

Intesa Sanpaolo insider accessed 3,500 accounts including Italy's prime minister

Malicious InsiderBanking

Fidelity Investments

Fidelity Investments breach exposed personal data of 77,099 customers

HackingFinancial Services

Game Freak

Game Freak confirms server breach behind Pokemon TeraLeak data dump

HackingVideo Games

Perfection Fresh

Perfection Fresh confirms breach after Sarcoma ransomware listing

RansomwareAgriculture

The Plastic Bag Company

Sarcoma ransomware group leaks data from Sydney's The Plastic Bag Company

RansomwareManufacturing

Internet Archive

Internet Archive breach exposed 31 million user records

HackingNonprofit

ADT Inc.

ADT discloses second breach in two months after partner credentials stolen

Credential CompromiseHome Security

American Water Works Company, Inc.

American Water pauses billing after cyberattack on internal systems

HackingUtilities

Wayne County, Michigan

Cyberattack shut down Wayne County, Michigan websites and county offices

RansomwareGovernment

Red Barrels

Red Barrels breach delayed Outlast development after 1.8TB theft claim

RansomwareVideo Games

Ward Transport & Logistics Corp.

Ward Transport and Logistics notified victims of March 2024 network breach

RansomwareTransportation and Logistics

Agence France-Presse

Agence France-Presse reported potential data breach after cyberattack

HackingMedia

Dutch National Police

Dutch national police breach exposes contact details of every officer

HackingGovernment

Casino Fandango

Casino Fandango disclosed June 2024 breach of its computer network

HackingHospitality and Gaming

City of Arkansas City, Kansas

Arkansas City, Kansas water plant switches to manual after cyberattack

HackingGovernment

MoneyGram International

MoneyGram confirms cyberattack behind days-long global outage

HackingFinancial Services

MC2 Data

MC2 Data left 2.2TB background check database exposed online

Human ErrorData Brokerage

Dell Technologies

Hacker claimed two Dell Technologies breaches within days in September 2024

HackingTechnology

Total Tools

Total Tools data breach exposed about 38,000 customer accounts

HackingRetail

Compass Group Australia

Compass Group Australia confirmed Medusa ransomware attack

RansomwareFood Services

Fireworks Software, Inc.

Fireworks Software breach exposed data tied to Rowan College at Burlington County

HackingSoftware

Elitecare Emergency Hospital

Elitecare Emergency Hospital notifies 24,754 patients of data breach

HackingHealthcare

David's Bridal

David's Bridal notified customers and staff of January 2024 data breach

HackingRetail

Kawasaki Motors Europe

Kawasaki Motors Europe restored servers after RansomHub attack

RansomwareAutomotive

Fortinet

Fortinet confirmed customer data taken from third-party cloud file drive

Third-Party Data BreachTechnology

Access Sports Medicine and Orthopaedics

Access Sports Medicine breach exposed data on about 88,000 patients

RansomwareHealthcare

Industrial and Commercial Bank of China (ICBC), London branch

Hunters International claimed 6.6TB theft from ICBC's London branch

RansomwareFinancial Services

Aramark

Aramark employees phished through fake myPay site in payroll diversion scheme

PhishingFood Services

Slim CD, Inc.

Slim CD breach exposed card data for about 1.7 million people

HackingPayment Processing

T. Rowe Price Retirement Plan Services

T. Rowe Price named in Infosys McCamish breach affecting 6 million people

Third-Party Data BreachFinancial Services

Avis Rent A Car System

Avis breach of a business application exposed data on 299,006 customers

HackingTravel & Tourism

Charles Darwin School

Ransomware attack closed Charles Darwin School in Bromley for three days

RansomwareEducation

KemperSports

KemperSports breach exposed Social Security numbers of over 62,000 people

HackingHospitality

Nationwide Recovery Service

Nationwide Recovery Service reports breach of debt collection records

HackingDebt Collection

Highline Public Schools

Highline Public Schools closed for three days after a cyberattack

RansomwareEducation

Centers for Medicare & Medicaid Services

CMS said a MOVEit hack at contractor WPS exposed 946,801 Medicare beneficiaries

Third-Party Data BreachHealthcare

St. Charles Parish Government

St. Charles Parish lost over $1.2 million to a vendor email compromise

Business Email CompromiseGovernment

Planned Parenthood of Montana

RansomHub claimed a cyberattack on Planned Parenthood of Montana

RansomwareHealthcare

Tewkesbury Borough Council

Tewkesbury Borough Council shut down its systems after a suspected cyberattack

Human ErrorGovernment

Tracelo

Tracelo phone tracking service breach exposed 1.4 million customers and targets

HackingLocation Tracking Service

Mt. Carmel Behavioral Healthcare

Mt. Carmel Behavioral Healthcare disclosed email breach exposing patient data

PhishingHealthcare

JAS Worldwide

JAS Worldwide confirms ransomware attack behind freight operation disruptions

RansomwareLogistics

Toronto District School Board

Toronto District School Board says student data stolen in June ransomware attack

RansomwareEducation

Dick's Sporting Goods

Dick's Sporting Goods discloses intrusion and locks employees out of email

HackingRetail

Fota Wildlife Park

Fota Wildlife Park told customers to cancel cards after a website breach

HackingTourism & Attractions

USAA

USAA notified about 32,000 members after update error misdelivered documents

MisconfigurationInsurance

Meli

Qilin ransomware gang claims 215 GB theft from Australian charity Meli

RansomwareNonprofit

Young Consulting

Young Consulting breach exposed data on 954,177 people, including Blue Shield members

RansomwareSoftware

Port of Seattle (Seattle-Tacoma International Airport)

Rhysida ransomware attack disrupted Seattle-Tacoma International Airport systems

RansomwareAviation

Bloom Hearing Specialists

Bloom Hearing Specialists ransomware attack exposed patient and staff records

RansomwareHealthcare

Halliburton Company

Halliburton took systems offline after August 2024 cyberattack

HackingEnergy Services

Caja Los Andes

Unsecured database at Chile's Caja Los Andes exposed data on 10 million people

MisconfigurationFinancial Services

Microchip Technology Incorporated

Microchip Technology cut manufacturing output after August 2024 cyberattack

HackingSemiconductor Manufacturing

Oregon Zoo

Oregon Zoo warned 117,000 online ticket buyers of payment card theft

HackingZoos and Attractions

Toyota

Toyota confirms customer data exposed after 240 GB leak blamed on third party

Third-Party Data BreachAutomotive

CannonDesign

CannonDesign notified 13,000 people of 2023 AvosLocker ransomware breach

RansomwareArchitecture and Engineering

VeriSource Services, Inc.

VeriSource Services disclosed February 2024 breach of employee benefits data

HackingEmployee Benefits Administration

FlightAware

FlightAware configuration error exposed account data for over three years

MisconfigurationAviation Technology

Specialty Networks, Inc.

Specialty Networks breach exposed data on more than 411,000 patients

HackingHealthcare Technology

City of Flint, Michigan

Ransomware attack knocked City of Flint payment and phone systems offline

RansomwareMunicipal Government

The Washington Times

Rhysida ransomware group put Washington Times data up for auction

RansomwareMedia

AutoCanada Inc.

AutoCanada disclosed cyberattack on its internal IT systems

HackingAutomotive Retail

Rodl Management, Inc.

Rodl Management breach exposed tax client data from Jamestown and JT Tax Services

HackingProfessional Services

Grand Palais Reunion des musees nationaux

Ransomware attack hit Grand Palais and dozens of French museums during Paris Olympics

RansomwareMuseums and Cultural Venues

ZB Financial Holdings

Mad Liberator leaked ZB Financial Holdings data after Zimbabwe group refused ransom

RansomwareFinancial Services

Sable International

BianLian emailed Sable International customers after immigration firm breach

HackingImmigration Services

Fresnillo plc

Fresnillo disclosed unauthorised access to IT systems and data

HackingMining

McDowall Affleck

RansomHub claimed 470GB of data from engineering firm McDowall Affleck

RansomwareEngineering

Jerico Pictures Inc. (National Public Data)

National Public Data faced suit over a claimed 2.9 billion record breach

HackingData Brokerage

C-Edge Technologies

Ransomware at C-Edge Technologies knocked roughly 300 Indian banks offline

RansomwareFinancial Services

OneBlood

Ransomware attack on OneBlood disrupted blood supply across the Southeast

RansomwareNonprofit Blood Services

Gemini

Gemini discloses breach at banking partner exposing customer account details

Third-Party Data BreachCryptocurrency Exchange

Lite-On Technology Corporation

RansomEXX claimed a 142GB data theft from Taiwan's Lite-On Technology

RansomwareElectronics Manufacturing

Squirrel

Squirrel breach exposed ID documents of up to 600 New Zealand investors

HackingFinancial Services

Leidos Holdings

Leidos internal documents leaked online after third-party vendor breach

Third-Party Data BreachIT Services

Split Airport

Akira ransomware attack disrupts flights at Croatia's Split Airport

RansomwareAviation

FirstNet (AT&T)

AT&T reversed course and said most FirstNet numbers were in the breached data

Third-Party Data BreachPublic Safety Communications

Wattle Range Council

LockBit posts data stolen from South Australia's Wattle Range Council

RansomwareLocal Government

Superior Court of Los Angeles County

Ransomware closed all 36 Los Angeles County Superior Court courthouses

RansomwareJudiciary

Michigan Medicine

Michigan Medicine notifies about 57,000 patients after email account breach

HackingHealthcare

City of Columbus, Ohio

Rhysida claimed 6.5TB of data from the City of Columbus ransomware attack

RansomwareMunicipal Government

Pueblo County School District 70

Pueblo County School District 70 disclosed ransomware breach of student records

RansomwareEducation

Atlassian (Trello)

Trello data on 15 million users leaked after an open API was scraped

HackingSoftware

Rite Aid

Rite Aid says June cyberattack exposed data on 2.2 million people

RansomwareRetail Pharmacy

Bassett Furniture Industries

Bassett Furniture halted manufacturing after ransomware encrypted data files

RansomwareFurniture Manufacturing

The Walt Disney Company

Disney investigates leak of 1.1 TB of internal Slack data

HackingEntertainment

AT&T

AT&T discloses theft of call and text records for nearly all wireless customers

Credential CompromiseTelecommunications

Goshen Central School District

Goshen Central School District hit by ransomware attack

RansomwareEducation

Sibanye-Stillwater

Sibanye-Stillwater cyberattack hit the mining group's IT systems worldwide

HackingMining

Advance Auto Parts

Advance Auto Parts notifies 2.3 million after Snowflake-linked breach

Credential CompromiseRetail

The Heritage Foundation

SiegedSec leaks Heritage Foundation data in protest over Project 2025

HackingThink Tank

Roblox

Roblox developer conference attendee data exposed in FNTech vendor breach

Third-Party Data BreachGaming

Florida Department of Health

Florida Department of Health data published after RansomHub attack

RansomwareGovernment

Elite Fitness

Elite Fitness confirms DragonForce ransomware attack in New Zealand

RansomwareRetail

Alabama State Department of Education

Alabama State Department of Education breached in a halted ransomware attack

HackingEducation

Fédération Internationale de l'Automobile (FIA)

FIA discloses data breach after phishing attacks on two email accounts

PhishingSports Governing Body

Roll20

Roll20 discloses breach of an administrative account exposing user records

HackingGaming

HealthEquity, Inc.

HealthEquity breach traced to a compromised business partner account

Credential CompromiseHealth Benefits Administration

Patelco Credit Union

Patelco Credit Union ransomware attack shuts down banking systems for weeks

RansomwareFinancial Services

Mass General Brigham

Mass General Brigham fired staff who let outsiders view patient records

Malicious InsiderHealthcare

Cambridge University Press & Assessment

Cambridge University Press & Assessment hit by INC Ransom attack

RansomwarePublishing

Federated Co-operatives Limited

Federated Co-operatives cyberattack disrupted Co-op stores and fuel cardlocks

RansomwareRetail and Wholesale

Kadokawa Corporation

Kadokawa confirmed a ransomware attack on its data centre and Niconico

RansomwareMedia and Entertainment

University Hospital Centre Zagreb (KBC Zagreb)

LockBit claims attack on Croatia's largest hospital, KBC Zagreb

RansomwareHealthcare

TeamViewer

TeamViewer's corporate network was breached by APT29

Credential CompromiseSoftware

Evolve Bank & Trust

LockBit's claimed Federal Reserve hack was really Evolve Bank & Trust data

RansomwareBanking

Neiman Marcus Group

Neiman Marcus confirmed a Snowflake-linked breach affecting 64,472 people

Credential CompromiseRetail

Geisinger

Geisinger notified over a million patients after a vendor insider breach

Third-Party Data BreachHealthcare

Pusat Data Nasional (Indonesia National Data Center)

Indonesia's Pusat Data Nasional crippled by Brain Cipher ransomware

RansomwareGovernment

National Health Laboratory Service (NHLS)

Ransomware halts test reporting at South Africa's National Health Laboratory Service

RansomwareHealthcare

Financial Business and Consumer Solutions

Debt collector FBCS breach grew from 1.9 million to more than 3 million people

HackingDebt Collection

Jollibee Foods Corporation

Jollibee investigated a data breach affecting 11 million customers

HackingFood Service

Disability Rights Wisconsin

Disability Rights Wisconsin email breach exposed 19,150 Medicaid members

HackingNonprofit

Accenture

Accenture disputed a BreachForums claim of 32,000 leaked employee records

HackingProfessional Services

CDK Global

CDK Global ransomware attack halted software at 15,000 car dealerships

RansomwareSoftware

Victoria Racing Club

Medusa ransomware gang demanded US$700,000 from Victoria Racing Club

RansomwareSports and Recreation

Newberg-Dundee School District

Newberg-Dundee School District hit by ransomware in June 2024

RansomwareEducation

Truist Bank

Truist Bank confirms October 2023 breach after employee data listed for sale

HackingBanking

Life360 (Tile)

Life360 says hacker stole Tile customer data and tried to extort the company

Credential CompromiseConsumer Technology

City of Cleveland, Ohio

City of Cleveland confirms ransomware attack that closed City Hall for two weeks

RansomwareMunicipal Government

Vietnam Post

Ransomware attack took Vietnam Post's delivery systems offline

RansomwarePostal Services

Heineken

Heineken employee data offered for sale after 888 claimed a breach

HackingFood and Beverage

Synnovis

Synnovis ransomware attack disrupts pathology services at London NHS hospitals

RansomwareHealthcare

King's College Hospital NHS Foundation Trust

Synnovis ransomware attack disrupted King's College Hospital and other London trusts

Third-Party Service DisruptionHealthcare

Verny

Cyberattack forces Russian discount chain Verny to take cash only across 1,000 stores

HackingRetail

Christian Democratic Union (CDU)

Germany's CDU took IT systems offline after a serious cyberattack

HackingPolitics

Easterseals Central Illinois

Rhysida ransomware gang demanded $1.3 million from Easterseals Central Illinois

RansomwareNon-profit

Guardian Childcare

Guardian Childcare breach exposed scanned ID documents of Australian families

HackingChildcare

Live Nation Entertainment (Ticketmaster)

Live Nation disclosed Ticketmaster data theft from a third-party cloud database

Third-Party Data BreachEntertainment and Ticketing

Snowflake

Snowflake says up to 165 customer accounts hit in credential theft campaign

Credential CompromiseCloud Computing

Ticketek Australia

Ticketek Australia customer data exposed via third-party cloud platform

Third-Party Data BreachTicketing

Everbridge

Everbridge told customers attackers reached corporate files after employee phishing

PhishingSoftware

BBC

BBC Pension Scheme breach exposed data on more than 25,000 members

HackingBroadcasting

Smith & Caughey's

Smith & Caughey's crypto-locked by ransomware on the day it announced its closure

RansomwareRetail

Decathlon

Decathlon confirmed Spanish employee email addresses leaked from third-party app

Third-Party Data BreachRetail

Sav-Rx (A&A Services)

Sav-Rx breach exposed data of 2.8 million prescription plan members

HackingPharmacy Benefits

The Seattle Public Library

Ransomware attack knocked The Seattle Public Library's systems offline

RansomwarePublic Library

Cencora

Eleven drug companies disclose patient data loss from Cencora breach

HackingPharmaceutical Services

Albany County, New York

Albany County, New York investigates possible cybersecurity breach

HackingGovernment

TRC Staffing Services, Inc. (TRC Talent Solutions)

TRC Talent Solutions ransomware breach exposed 158,593 job seekers

RansomwareStaffing

Welsh Rugby Union

Welsh Rugby Union investigated leak of supporters club member data

MisconfigurationSports Governing Body

Merrill Lynch, Pierce, Fenner & Smith Incorporated

Merrill email error exposed Social Security numbers of Walmart 401(k) savers

Human ErrorFinancial Services

First Nations Health Authority

First Nations Health Authority reported a cyberattack on its corporate network

HackingHealthcare

American Radio Relay League (ARRL)

ARRL cyberattack takes Logbook of The World offline

RansomwareMembership Association

Guam Seventh-Day Adventist Clinic

Guam Seventh-Day Adventist Clinic email breach exposed 56,635 people

HackingHealthcare

MediSecure

MediSecure ransomware attack hits Australian e-prescription provider

RansomwareHealthcare Technology

Affiliated Dermatologists & Dermatologic Surgeons, P.A.

Affiliated Dermatologists breach hit about 380,000 patients and staff

RansomwareHealthcare

Nissan North America

Nissan North America breach exposed Social Security numbers of 53,000 employees

RansomwareAutomotive

Rockford Public Schools

Ransomware attack knocks out Rockford Public Schools network

RansomwareEducation

Banco Santander

Santander says third-party database breach hit customers and staff

Third-Party Data BreachBanking

Keytronic

Keytronic confirms data theft after Black Basta ransomware attack

RansomwareElectronics Manufacturing

Palomar Health Medical Group

Palomar Health Medical Group cyberattack knocked outpatient systems offline for months

HackingHealthcare

DocGo

DocGo discloses cyberattack that exposed patient health data

HackingHealthcare

MedStar Health

MedStar Health email breach exposed data on about 183,000 patients

HackingHealthcare

City of Wichita, Kansas

Ransomware forces the City of Wichita to shut down its network

RansomwareMunicipal Government

Monash Health

Monash Health records exposed in ZircoDATA ransomware breach

Third-Party Data BreachHealthcare

Dropbox

Dropbox Sign production systems breached, user credentials exposed

HackingTechnology

Firstmac Limited

Firstmac confirms breach after EMBARGO ransomware attack

RansomwareFinancial Services

JPMorgan Chase

Software flaw at J.P. Morgan exposed data on 451,000 retirement savers

MisconfigurationFinancial Services

Kaiser Foundation Health Plan (Kaiser Permanente)

Kaiser Permanente website trackers exposed data on 13.4 million members

MisconfigurationHealthcare

London Drugs

London Drugs closed all 79 stores across Western Canada after a ransomware attack

RansomwareRetail Pharmacy

State Security Committee of the Republic of Belarus (KGB)

Cyber-Partisans claim breach of Belarus state security service

HackingGovernment

Coffee County, Georgia

Coffee County, Georgia cut its link to the state voter roll after a cyberattack

RansomwareLocal Government

LivaNova

LivaNova notified about 130,000 people after LockBit ransomware attack

RansomwareMedical Devices

Skanlog

Ransomware at Nordic distributor Skanlog empties Systembolaget shelves

RansomwareLogistics

Carpetright

Carpetright cyberattack halts UK store and online trading for a week

HackingRetail

Grodno Azot

Cyber-Partisans encrypt systems at Belarusian fertilizer maker Grodno Azot

RansomwareChemical Manufacturing

Tipton Municipal Utilities

Russia-linked group claimed cyberattack on Tipton, Indiana wastewater plant

HackingWater Utility

The MITRE Corporation

MITRE said nation-state hackers breached its NERVE network via Ivanti zero-days

HackingNonprofit Research

Pandemonium Rocks

Pandemonium Rocks refund form exposed ticketholders' bank details

MisconfigurationLive Events

District of Columbia Department of Insurance, Securities and Banking (DISB)

LockBit claimed DC insurance regulator data taken via Tyler Technologies cloud

Third-Party Data BreachGovernment

Frontier Communications Parent, Inc.

Frontier Communications disclosed April 2024 breach of its IT environment

HackingTelecommunications

Solano County Library

Ransomware took Solano County's SPLASH library network offline for weeks

RansomwarePublic Libraries

Octapharma Plasma

Ransomware shut Octapharma Plasma donation centers across 35 US states

RansomwareHealthcare

Centre Hospitalier Simone Veil de Cannes (CHC-SV)

Cannes hospital CHC-SV reverted to paper after LockBit ransomware attack

RansomwareHealthcare

United Nations Development Programme (UNDP)

UNDP confirmed data theft after ransomware attack on Copenhagen IT systems

RansomwareInternational Development

The Heritage Foundation

Heritage Foundation shut down its network after April 2024 cyberattack

HackingThink Tank

Wells Fargo

Wells Fargo employee sent customer data to a personal account

Malicious InsiderBanking

City of Saint-Nazaire

Ransomware paralyzed Saint-Nazaire and four neighboring French communes

RansomwareMunicipal Government

Sisense

CISA warned Sisense customers to reset credentials after vendor breach

HackingBusiness Analytics Software

CVS Group plc

CVS Group took systems offline after unauthorised access to UK IT servers

HackingVeterinary Services

EBlock Corp.

EBlock notified nearly 2,000 people of breach of legacy ABS Auto Auctions systems

HackingAutomotive Auctions

U.S. Environmental Protection Agency (EPA)

EPA denies breach after hacker posts 8.5 million contact records

HackingGovernment

The Home Depot

Home Depot confirmed a vendor exposed employee data leaked by IntelBroker

Third-Party Data BreachRetail

New Mexico Highlands University

New Mexico Highlands University canceled a week of classes after ransomware attack

RansomwareHigher Education

Panera Bread

Panera Bread ransomware attack caused week-long nationwide IT outage

RansomwareRestaurants

Jackson County, Missouri

Jackson County, Missouri declared a state of emergency after ransomware attack

RansomwareLocal Government

Omni Hotels & Resorts

Daixin ransomware attack took Omni Hotels & Resorts systems offline for a week

RansomwareHospitality

IxMetro PowerHost

SEXi ransomware encrypted IxMetro PowerHost's ESXi servers and its backups

RansomwareHosting and Data Centers

AT&T

AT&T confirmed data on 73 million current and former customers leaked online

HackingTelecommunications

Hot Topic, Inc.

Hot Topic notifies customers after November 2023 credential stuffing attacks

Credential CompromiseRetail

Activision Blizzard

Activision warns players after infostealer malware harvested gaming logins

Credential CompromiseVideo Games

Carolina Foods Inc.

Black Basta claims ransomware attack on snack maker Carolina Foods

RansomwareFood Manufacturing

The Big Issue Group

Qilin ransomware gang leaked data stolen from The Big Issue Group

RansomwareMedia

Communications Workers Union (CWU)

UK Communications Workers Union confirms cyberattack on its IT systems

HackingTrade Union

Giant Tiger Stores Limited

Giant Tiger customer contact data exposed in third-party vendor breach

Third-Party Data BreachRetail

Air Europa

Air Europa told customers passport and ID data was exposed in 2023 breach

HackingAirline

Radiant Logistics

Radiant Logistics isolated Canadian operations after March 2024 cyberattack

HackingLogistics

Crinetics Pharmaceuticals

LockBit claimed attack on Crinetics Pharmaceuticals and demanded $4 million

RansomwarePharmaceuticals

MediaWorks

MediaWorks said 403,000 New Zealanders' data was taken in competition hack

HackingMedia and Broadcasting

Office of the Colorado State Public Defender

Colorado public defender says ransomware attack exposed client data

RansomwareGovernment

Fujitsu

Fujitsu confirms malware on work computers and possible data theft

HackingTechnology

International Monetary Fund (IMF)

IMF said 11 email accounts were compromised in a February 2024 breach

HackingInternational Financial Institution

NHS Dumfries and Galloway

NHS Dumfries and Galloway hit by focused and ongoing cyberattack

RansomwareHealthcare

Scranton School District

Ransomware attack knocks out Scranton School District systems

RansomwareEducation

Nations Direct Mortgage

Nations Direct Mortgage notified 83,000 people of a December 2023 breach

HackingFinancial Services

France Travail

France Travail breach exposes data on up to 43 million job seekers

Credential CompromiseGovernment

EquiLend

EquiLend tells employees data was stolen in January ransomware attack

RansomwareFinancial Services

MarineMax

Rhysida claims ransomware attack on boat retailer MarineMax

RansomwareRetail

Cybersecurity and Infrastructure Security Agency (CISA)

CISA took two systems offline after Ivanti gateway flaws were exploited

HackingGovernment

Roku

Roku disclosed credential stuffing attack affecting 15,363 accounts

Credential CompromiseStreaming Media

Jersey Financial Services Commission (JFSC)

Jersey Financial Services Commission registry flaw exposed 66,806 records

MisconfigurationFinancial Regulator

Leicester City Council

Leicester City Council shut down IT systems and phone lines after cyberattack

RansomwareMunicipal Government

Duvel Moortgat

Ransomware halted brewing at Duvel Moortgat's Belgian and US sites

RansomwareFood and Beverage

South St. Paul Public Schools

South St. Paul Public Schools took systems offline after network intrusion

RansomwareEducation

Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)

FINTRAC took corporate systems offline after a March 2024 cyber incident

HackingGovernment

American Express

American Express warns cardholders of breach at third-party merchant processor

Third-Party Data BreachFinancial Services

Scottish Ambulance Service

Scottish Ambulance Service apologizes after first responder spreadsheet emailed in error

Human ErrorEmergency Services

Chunghwa Telecom

Chunghwa Telecom breach put 1.7TB of Taiwanese government data on the dark web

HackingTelecommunications

Fidelity Investments Life Insurance Company

Fidelity Investments Life Insurance notified 28,000 after Infosys McCamish breach

Third-Party Data BreachInsurance

YX International

YX International left SMS database of one-time passcodes exposed online

MisconfigurationTelecommunications

Cutout.Pro

Cutout.Pro records for about 20 million accounts leaked on hacking forum

HackingTechnology

U-Haul International, Inc.

U-Haul notified 67,000 customers after reservation system breach

Credential CompromiseVehicle Rental

City of Hamilton, Ontario

Ransomware disabled most of the City of Hamilton's network for weeks

RansomwareMunicipal Government

Quik Pawn Shop

Akira ransomware group claimed an attack on Alabama's Quik Pawn Shop

RansomwareConsumer Lending

Royal Canadian Mounted Police (RCMP)

Royal Canadian Mounted Police opened criminal probe into network cyberattack

HackingLaw Enforcement

Das Team AG (dasteam ag)

Black Basta leaked 200GB stolen from Swiss staffing firm Das Team AG

RansomwareStaffing and Recruitment

Change Healthcare

Cyberattack on Change Healthcare disrupted US pharmacies and claims processing

RansomwareHealthcare Technology

Malawi Department of Immigration and Citizenship Services

Malawi halts passport printing after immigration system hack and ransom demand

HackingGovernment

Tangerine Telecom

Tangerine Telecom breach exposed data on 232,000 Australian customers

Credential CompromiseTelecommunications

Robert Half International

IntelBroker and Sanggiero claimed a data breach at staffing firm Robert Half

HackingStaffing and Recruitment

Stratford-on-Avon District Council

Stratford-on-Avon council insider took 79,000 resident email addresses

Malicious InsiderLocal Government

Golden Corral Corporation

Golden Corral breach exposed data on more than 183,000 employees

HackingRestaurants

INTEGRIS Health

INTEGRIS Health said a 2023 breach exposed data on 2.4 million patients

HackingHealthcare

PSI Software SE

Ransomware attack forced German control systems vendor PSI Software offline

RansomwareIndustrial Software

Washington County, Pennsylvania

Washington County, Pennsylvania paid a $350,000 ransom after January cyberattack

RansomwareLocal Government

Bank of America

Bank of America notified 57,028 customers after Infosys McCamish breach

Third-Party Data BreachFinancial Services

Trans-Northern Pipelines

ALPHV claimed a data theft at Canada's Trans-Northern Pipelines

HackingEnergy

Varta AG

Cyberattack halted production at German battery maker Varta AG

HackingManufacturing

Prudential Financial

Prudential Financial disclosed breach of employee and contractor data

RansomwareFinancial Services

Slobozia County Emergency Hospital

Slobozia hospital among Romanian hospitals hit by Hipocrate ransomware attack

RansomwareHealthcare

Hyundai Motor Europe

Black Basta claimed three terabytes of data from Hyundai Motor Europe

RansomwareAutomotive

WinStar World Casino and Resort

WinStar app customer data exposed by unsecured Dexiga database

MisconfigurationCasinos and Gaming

Service Employees International Union (SEIU) Local 1000

LockBit ransomware attack disrupted SEIU Local 1000 in California

RansomwareLabor Union

Municipality of Korneuburg, Austria

Ransomware attack on Austria's Korneuburg municipality postponed funerals

RansomwareMunicipal Government

Medical Management Resource Group, LLC (American Vision Partners)

Medical Management Resource Group breach hit 2.35 million eye care patients

HackingHealthcare Services

AnyDesk

AnyDesk confirms attackers breached its production systems

HackingSoftware

Football Australia

Football Australia exposed player passports and contracts through leaked AWS keys

Human ErrorSports Governing Body

City of Jacksonville Beach, Florida

Jacksonville Beach said ransomware attack exposed data on about 49,000 people

RansomwareMunicipal Government

Ann & Robert H. Lurie Children's Hospital of Chicago

Ransomware attack took Lurie Children's Hospital systems offline for weeks

RansomwareHealthcare

Global Affairs Canada

Global Affairs Canada breach exposed employee data through a compromised VPN

HackingGovernment

Keenan & Associates

Keenan & Associates breach exposed data of more than 1.5 million people

HackingInsurance

Schneider Electric

Cactus ransomware hit Schneider Electric's Sustainability Business division

RansomwareEnergy Management

Fulton County, Georgia

Cyberattack knocked out Fulton County, Georgia government systems

RansomwareLocal Government

Freehold Township School District

Freehold Township School District closes schools after cybersecurity incident

HackingEducation

Caravan and Motorhome Club

Caravan and Motorhome Club outage in UK traced to a cyberattack

RansomwareMembership Organization

Hewlett Packard Enterprise

Russian group APT29 read Hewlett Packard Enterprise email for seven months

HackingTechnology

City of Frederick, Maryland

City of Frederick lost $280,527 to a phishing driven wire fraud scheme

Business Email CompromiseMunicipal Government

DENHAM the Jeanmaker

DENHAM the Jeanmaker confirms cyberattack linked to Akira ransomware

RansomwareFashion Retail

Jason's Deli

Jason's Deli customer accounts breached in credential stuffing attack

Credential CompromiseRestaurants

Southern Water

Black Basta claims ransomware attack on UK utility Southern Water

RansomwareWater Utilities

Bucks County, Pennsylvania

Bucks County, Pennsylvania loses emergency dispatch system in ransomware attack

RansomwareLocal Government

Microbe & Lab (CoronaLab)

Dutch COVID testing lab CoronaLab exposed 1.3 million records in open database

MisconfigurationMedical Laboratory

GALA Hispanic Theatre

GALA Hispanic Theatre recovers $255,000 drained in bank fraud

Business Email CompromiseArts and Culture

Trezor

Trezor support portal breach exposes contact data of 66,000 users

Third-Party Data BreachCryptocurrency

Microsoft

Microsoft says Midnight Blizzard read senior leaders' corporate email

Credential CompromiseTechnology

Veolia North America

Veolia North America discloses ransomware attack on Municipal Water division

RansomwareWater Utilities

Tilbury District Family Health Team

Tilbury District Family Health Team patient data taken in TransForm ransomware attack

Third-Party Data BreachHealthcare

Foxsemicon Integrated Technology

LockBit defaces Foxsemicon website and claims 5TB of stolen data

RansomwareSemiconductor Manufacturing

Kansas State University

Kansas State University cyberattack knocks out VPN, email and campus services

HackingHigher Education

Hal Leonard Australia

Qilin leaks 37.6 GB of data from music publisher Hal Leonard Australia

RansomwareMusic Publishing

Water for People

Medusa gang listed nonprofit Water for People with a $300,000 demand

RansomwareNonprofit

Clearview Resources Ltd.

Clearview Resources loses C$1.5 million to email account takeover

Business Email CompromiseEnergy

Lush

Lush confirms cyber incident later described as a ransomware attack

RansomwareRetail

Inspiring Vacations

Inspiring Vacations left 112,000 travel records in an open cloud bucket

MisconfigurationTravel

HMG Healthcare

HMG Healthcare breach hit residents and staff at 40 nursing facilities

HackingHealthcare

Toronto Zoo

Toronto Zoo discloses ransomware incident, employee records taken

RansomwareZoo

Cooper Aerobics

Cooper Aerobics notifies patients almost a year after network intrusion

HackingHealthcare

Midwives of Windsor

Midwives of Windsor tells clients an email account was breached in April 2023

Credential CompromiseHealthcare

Housing Authority of the County of San Bernardino

San Bernardino County housing authority breach exposed 18,689 people

HackingLocal Government

Orrick, Herrington & Sutcliffe

Orrick law firm breach exposed data on more than 637,000 people

HackingLegal Services

Gallery Systems

Gallery Systems ransomware attack took museum collection databases offline

RansomwareSoftware

HealthEC LLC

HealthEC breach exposed records of about 4.5 million patients

HackingHealthcare Technology

Court Services Victoria

Court Services Victoria breach exposed years of court hearing recordings

RansomwareGovernment

Communaute de communes du Pays Fouesnantais

Cyberattack shut down IT services across France's Pays Fouesnantais

RansomwareLocal Government

Memorial University of Newfoundland

Memorial University delays Grenfell Campus classes after ransomware attack

RansomwareHigher Education

Orbit Chain

Orbit Chain lost about $81 million in New Year's Eve bridge exploit

HackingCryptocurrency

Fallon Ambulance Service

Defunct Fallon Ambulance Service breach exposed data on 911,757 people

RansomwareEmergency Medical Services

Katholische Hospitalvereinigung Ostwestfalen

LockBit ransomware hit three German hospitals run by KHO on Christmas Eve

RansomwareHealthcare

National Amusements

National Amusements disclosed a December 2022 breach affecting 82,128 people

HackingMedia and Entertainment

Mint Mobile

Mint Mobile told customers a hacker obtained their account data

HackingTelecommunications

Ateam Inc.

Ateam Google Drive misconfiguration exposed data on 935,779 people

MisconfigurationTechnology

Comcast Xfinity

Comcast Xfinity breach exposed data of 35.8 million customers via Citrix Bleed

HackingTelecommunications

Insomniac Games

Rhysida leaks 1.67TB of Insomniac Games data after Sony studio refuses ransom

RansomwareVideo Games

VF Corporation

VF Corporation reported a ransomware attack in one of the first SEC cyber filings

RansomwareApparel and Footwear

Fred Hutchinson Cancer Center

Fred Hutchinson Cancer Center ransomware attack led to extortion of patients

RansomwareHealthcare

Asper Biogene

Asper Biogene breach exposed genetic and health data of 10,000 in Estonia

HackingGenetic Testing

Delta Dental of California

Delta Dental of California MOVEit breach affected nearly 7 million people

HackingDental Insurance

Ledger

Ledger Connect Kit compromised after phishing attack on a former employee

PhishingCryptocurrency Hardware

London Public Library

London Public Library in Ontario shut down services after a cyberattack

HackingPublic Library

Kyivstar

Kyivstar cyberattack knocked out mobile service for millions in Ukraine

HackingTelecommunications

Greater Richmond Transit Company (GRTC)

Greater Richmond Transit Company hit by Play ransomware over Thanksgiving

RansomwarePublic Transportation

City of Huber Heights, Ohio

Huber Heights, Ohio spends months rebuilding after BlackSuit ransomware attack

RansomwareMunicipal Government

Norton Healthcare

Norton Healthcare ransomware breach exposed data on 2.5 million people

RansomwareHealthcare

Binghamstown/Drum Group Water Scheme

Hacktivists cut water to Irish group scheme over Israeli-made pump controller

HackingWater Utility

Austal USA

Austal USA confirms data incident after Hunters International leak claim

HackingShipbuilding

HTC Global Services

HTC Global Services confirms cyberattack after ALPHV leaks stolen files

RansomwareIT Services

Nissan Oceania

Nissan warns Australian and New Zealand customers after Akira ransomware breach

RansomwareAutomotive

Staples

Staples took systems offline after a Cyber Monday intrusion

HackingOffice Supply Retail

WeMystic

WeMystic left 13.3 million user records exposed in an open database

MisconfigurationConsumer Web Services

Japan Aerospace Exploration Agency (JAXA)

JAXA confirms intruders reached its internal network

HackingGovernment

National Aerospace Laboratories

LockBit claims ransomware attack on India's National Aerospace Laboratories

RansomwareAerospace Research

Yanfeng Automotive Interiors

Qilin ransomware group claims attack on auto supplier Yanfeng

RansomwareAutomotive Manufacturing

ZeroedIn Technologies

ZeroedIn Technologies breach exposed data of about 2 million Dollar Tree workers

HackingHuman Resources Technology

Ardent Health Services

Ardent Health Services ransomware attack diverted ambulances at US hospitals

RansomwareHealthcare

Municipal Water Authority of Aliquippa

Cyber Av3ngers hijacked a controller at Aliquippa's water authority

HackingWater Utility

Indian Hotels Company Limited (Taj Hotels)

Taj Hotels investigates claimed leak of data on 1.5 million guests

HackingHospitality

Fidelity National Financial (FNF)

Fidelity National Financial shut down systems after ALPHV ransomware attack

RansomwareTitle Insurance

Brookfield Global Relocation Services (BGRS)

BGRS and SIRVA Canada breach exposed decades of federal relocation files

RansomwareRelocation Services

Idaho National Laboratory

Idaho National Laboratory confirmed HR system breach claimed by SiegedSec

HackingNuclear Research

Service public de l'assainissement francilien (SIAAP)

Paris-area wastewater agency SIAAP hit by cyberattack

HackingWater Utility

Blue Shield of California

Blue Shield of California members hit by MOVEit breach at vision benefits vendor

Third-Party Data BreachHealth Insurance

Toyota Financial Services

Medusa ransomware hit Toyota Financial Services in Europe and Africa

RansomwareAutomotive Finance

City of Long Beach, California

Long Beach declared a local emergency after a November 2023 network breach

HackingMunicipal Government

MeridianLink

MeridianLink confirmed a cyberattack after ALPHV reported it to the SEC

RansomwareFinancial Software

Samsung Electronics

Samsung UK store breach exposed contact details of 2019 and 2020 shoppers

HackingConsumer Electronics

Stanley Steemer

Stanley Steemer breach exposed data on about 67,000 customers

HackingConsumer Services

DP World Australia

DP World Australia halts four container ports after network intrusion

HackingPorts and Logistics

Washington State Department of Transportation

Cyberattack disrupts Washington State Department of Transportation services

HackingGovernment

Henry County Schools

Henry County Schools network shut down by BlackSuit ransomware attack

RansomwareEducation

Industrial and Commercial Bank of China (ICBC)

ICBC's US broker-dealer hit by LockBit ransomware, disrupting Treasury trades

RansomwareFinancial Services

State of Maine

State of Maine says MOVEit breach exposed data on 1.3 million people

HackingGovernment

Electric Ireland

Electric Ireland says contractor staff member accessed 8,000 customers' data

Malicious InsiderEnergy

Marina Bay Sands

Marina Bay Sands breach exposed data on 665,000 loyalty members

HackingHospitality

Cook County Health

Cook County Health notifies 1.2 million patients of breach at vendor PJ&A

Third-Party Data BreachHealthcare

Shimano

LockBit claims 4.5TB of data stolen from bicycle component maker Shimano

RansomwareManufacturing

Sutter Health

Sutter Health says MOVEit breach at vendor Welltok exposed 845,000 patients

Third-Party Data BreachHealthcare

Boeing

Boeing confirms cyberattack on its parts and distribution business

RansomwareAerospace

Queretaro Intercontinental Airport

Queretaro Intercontinental Airport confirms cyberattack claimed by LockBit

RansomwareAviation

The British Library

Rhysida ransomware attack kept British Library services offline for weeks

RansomwareLibraries and Archives

Mr. Cooper Group

Mr. Cooper shuts down systems after cyberattack, blocking mortgage payments

HackingFinancial Services

Allied Pilots Association

Ransomware hits Allied Pilots Association, the American Airlines pilots union

RansomwareLabor Union

Sudwestfalen IT

Ransomware at Sudwestfalen IT disrupts more than 70 German municipalities

RansomwareIT Services

Truepill (Postmeds Inc.)

Truepill breach exposed prescription records of about 2.3 million patients

HackingPharmacy

Ace Hardware

Ace Hardware cyberattack downs 1,202 devices and halts online orders

HackingRetail

Toronto Public Library

Toronto Public Library cyberattack takes down digital services at 100 branches

RansomwarePublic Libraries

Stanford University

Akira claimed 430 GB from Stanford's public safety department

RansomwareHigher Education

Clark County School District (CCSD)

Hackers emailed stolen student records to Clark County School District parents

HackingEducation

American Family Insurance

American Family Insurance confirmed a cyberattack behind week-long outages

HackingInsurance

Seiko Group Corporation

Seiko says ransomware attack exposed about 60,000 items of personal data

RansomwareManufacturing

Welltok

Welltok MOVEit breach exposed data on 8.5 million US patients

HackingHealthcare Software

Grupo GTD

Rorschach ransomware disrupts Chilean telecom operator Grupo GTD

RansomwareTelecommunications

Orange County District Attorney's Office

Orange County District Attorney shut down IT systems after a cyberattack

HackingGovernment

TransForm Shared Service Organization

Ransomware at TransForm knocked out systems at six Ontario health facilities

RansomwareHealthcare IT

Westchester Medical Center Health Network (WMCHealth)

WMCHealth diverted ambulances after a cyberattack on Hudson Valley hospitals

HackingHealthcare

Kwik Trip

Kwik Trip confirmed a cyberattack caused its two-week systems outage

HackingRetail

D-Link

D-Link confirmed a phishing attack exposed old registration records

PhishingNetworking Hardware

Ampersand

Ampersand confirmed ransomware attack claimed by Black Basta

RansomwareAdvertising

Arietis Health, LLC

Arietis Health reported a MOVEit breach affecting nearly 2 million patients

HackingHealthcare Billing

Henry Schein

Henry Schein confirms a cybersecurity incident as ALPHV claims the attack

RansomwareHealthcare

Morrison Community Hospital

BlackCat claimed 5TB data theft from Morrison Community Hospital

RansomwareHealthcare

Quality Service Installation (QSI), Inc.

ALPHV claimed 5TB of data from ATM installer Quality Service Installation

RansomwareBanking Technology

CDW

LockBit demanded $80 million from CDW after breaching Sirius Federal servers

RansomwareTechnology Services

Perry Johnson & Associates (PJ&A)

PJ&A transcription breach exposed data of nearly 9 million patients

HackingMedical Transcription

LDLC ASVEL Villeurbanne

LDLC ASVEL confirmed data theft after NoEscape ransomware listing

RansomwareSports

Shadow

Shadow said hacker stole customer data after employee lured on Discord

Credential CompromiseCloud Gaming

Simpson Manufacturing

Simpson Manufacturing took systems offline after October 2023 cyberattack

HackingManufacturing

Volex plc

Volex said attackers accessed IT systems and data at international sites

HackingElectronics Manufacturing

District of Columbia Board of Elections (DCBOE)

DC Board of Elections says voter roll was stolen from its hosting provider

Third-Party Data BreachGovernment

Flagstar Bank

Flagstar Bank told 837,000 customers their data was taken in Fiserv MOVEit breach

Third-Party Data BreachFinancial Services

Lyca Mobile

Lyca Mobile confirmed customer data theft after cyberattack

HackingTelecommunications

23andMe

23andMe user profiles scraped after credential stuffing attack

Credential CompromiseConsumer Genetics

The Royal Women's Hospital

Royal Women's Hospital notified 192 patients after staff email account hacked

Credential CompromiseHealthcare

Sony Interactive Entertainment

Sony Interactive Entertainment notified about 6,800 people of MOVEit breach

HackingVideo Games

Estes Express Lines

Estes Express Lines confirms cyberattack behind multi-day IT outage

RansomwareTransportation and Logistics

First Judicial Circuit Court of Florida

ALPHV claimed ransomware attack on Florida's First Judicial Circuit Court

RansomwareGovernment

Motel One

Motel One confirms data theft after ALPHV/BlackCat ransomware attack

RansomwareHospitality

Builders Mutual Insurance Company

Builders Mutual Insurance notified 64,761 people of a 2022 network intrusion

HackingInsurance

McLaren Health Care

McLaren Health Care confirms ransomware attack claimed by ALPHV/BlackCat

RansomwareHealthcare

World Baseball Softball Confederation (WBSC)

World Baseball Softball Confederation exposed 4,600 passport scans in open AWS bucket

MisconfigurationSports Governing Body

European Telecommunications Standards Institute (ETSI)

ETSI says attackers stole its online user database

HackingStandards Body

Flair Airlines

Flair Airlines left database and email credentials exposed on its website

MisconfigurationAirline

BORN Ontario (Better Outcomes Registry & Network)

BORN Ontario says MOVEit breach exposed health data on 3.4 million people

HackingHealthcare

Auckland University of Technology

Auckland University of Technology hit by cyberattack claimed by Monti ransomware

RansomwareHigher Education

Pizza Hut Australia

Pizza Hut Australia told 193,000 customers their data was accessed

HackingRestaurants

Progressive Leasing

Progressive Leasing discloses cyberattack that exposed Social Security numbers

RansomwareConsumer Leasing

Air Canada

Air Canada says internal system breached, limited employee data accessed

HackingAirline

International Criminal Court

International Criminal Court detected intrusion into its information systems

HackingJudiciary

Lakeland Community College

Lakeland Community College notified 285,948 people of a data breach

RansomwareHigher Education

City of Pittsburg, Kansas

Cyberattack knocked out email, phones and payments in Pittsburg, Kansas

HackingLocal Government

Virginia Department of Medical Assistance Services

Virginia Medicaid agency reports breach affecting 1.2 million people

HackingGovernment

Auckland Transport

Auckland Transport ticketing systems disrupted by ransomware attack

RansomwarePublic Transport

Caesars Entertainment

Caesars Entertainment disclosed loyalty database theft and paid a ransom

RansomwareHospitality and Gaming

Greater Manchester Police

Greater Manchester Police officer data exposed in supplier ransomware attack

Third-Party Data BreachLaw Enforcement

ORBCOMM

ORBCOMM ransomware attack knocked out trucking fleet management and ELDs

RansomwareTransportation Technology

Shell (BG Group Australia)

Shell says BG Group Australia employee data taken in MOVEit breach

HackingOil and Gas

Airbus

Airbus supplier data leaked after credentials stolen from airline employee

Credential CompromiseAerospace

Canadian Nurses Association

Canadian Nurses Association confirmed data theft after Snatch leaked 37GB

RansomwareProfessional Association

MGM Resorts International

MGM Resorts shut down IT systems across its casinos after a cyberattack

RansomwareHospitality and Gaming

Dymocks

Dymocks blamed an external data partner for a breach of 836,000 customers

Third-Party Data BreachRetail

International Joint Commission

NoEscape claimed an 80GB theft from the US-Canada International Joint Commission

RansomwareGovernment

Johnson & Johnson

IBM breach exposed Johnson & Johnson's Janssen CarePath patient data

Third-Party Data BreachPharmaceuticals

Sabre Corporation

Dunghill Leak claimed a 1.3TB data theft from travel technology firm Sabre

RansomwareTravel Technology

NXP Semiconductors

NXP Semiconductors told portal account holders their contact data was exposed

HackingSemiconductors

Freecycle

Freecycle disclosed a breach affecting more than 7 million members

HackingNonprofit

TissuPath

TissuPath patient records leaked after breach at a third-party IT supplier

Third-Party Data BreachHealthcare

Zaun

LockBit attack on UK fencing maker Zaun exposed military site documents

RansomwareManufacturing

Mom's Meals (PurFoods, LLC)

Mom's Meals discloses ransomware breach affecting more than 1.2 million people

RansomwareHealthcare Services

Metropolitan Police Service

Metropolitan Police supplier breach exposed details of 47,000 officers and staff

Third-Party Data BreachLaw Enforcement

Ohio History Connection

Ohio History Connection ransomware attack exposed data on about 7,600 people

RansomwareNonprofit

Pareto Phone

Pareto Phone breach leaked Australian charity donor data to the dark web

RansomwareTelemarketing

Pôle emploi

Pole emploi says MOVEit breach at a contractor exposed data on 10 million people

Third-Party Data BreachGovernment

CloudNordic

CloudNordic and AzeroCloud lost nearly all customer data in ransomware attack

RansomwareCloud Hosting

GEICO

GEICO tells employees their data was exposed in MOVEit-linked vendor breach

Third-Party Data BreachInsurance

University of Minnesota

University of Minnesota investigates claim that 7 million records were stolen

HackingHigher Education

auDA (.au Domain Administration)

auDA finds no evidence of breach after NoEscape claimed to hold its data

RansomwareInternet Infrastructure

Energy One

Energy One takes systems offline after cyberattack on Australian and UK operations

HackingEnergy Software

Tesla, Inc.

Tesla blamed insider wrongdoing for breach affecting 75,000 employees

Malicious InsiderAutomotive

Swan Retail

Swan Retail cyberattack knocks around 300 UK independent retailers offline

HackingRetail Software

The Clorox Company

Clorox took systems offline after unauthorized activity on its network

HackingConsumer Goods Manufacturing

Prince George's County Public Schools

Cyberattack on Prince George's County Public Schools hit 4,500 accounts

HackingEducation

Colorado Department of Health Care Policy and Financing

Colorado health agency notified 4.1 million people after IBM MOVEit breach

Third-Party Data BreachGovernment Health Agency

Cumbria Constabulary

Cumbria police accidentally published names and salaries of all staff

Human ErrorLaw Enforcement

Freeport-McMoRan Inc.

Freeport-McMoRan disclosed a cybersecurity incident affecting its IT systems

HackingMining

Indiana Family and Social Services Administration

Indiana FSSA said Maximus MOVEit breach exposed 744,000 Medicaid members

Third-Party Data BreachGovernment Health Agency

Alberta Dental Service Corporation

Ransomware at Alberta Dental Service Corporation hit 1.47 million people

RansomwareHealth Benefits Administration

Rapattoni Corporation

Rapattoni cyberattack froze MLS property listings across the US

HackingReal Estate Technology

Police Service of Northern Ireland

PSNI accidentally published details of about 10,000 officers and staff

Human ErrorLaw Enforcement

The Electoral Commission (United Kingdom)

UK Electoral Commission revealed hack exposing 40 million voters' details

HackingGovernment Agency

Colorado Department of Higher Education

Colorado Department of Higher Education breach exposed 16 years of records

RansomwareState Government

Aristocrat Leisure Limited

Aristocrat Leisure confirmed employee data stolen through MOVEit flaw

HackingGaming Technology

Prospect Medical Holdings

Prospect Medical Holdings cyberattack shut hospital services in four states

RansomwareHealthcare

Oregon Health Plan

MOVEit breach at PH Tech exposed 1.7 million Oregon Health Plan members

Third-Party Data BreachHealth Insurance

Health Employers Association of British Columbia

Cyberattack on B.C. health recruitment sites exposed up to 240,000 records

HackingHealthcare

Hot Topic

Hot Topic disclosed credential stuffing attacks on Rewards accounts

Credential CompromiseRetail

The Prudential Insurance Company of America

Prudential said MOVEit hack at vendor PBI exposed 320,840 people

Third-Party Data BreachInsurance

Tempur Sealy International

Tempur Sealy shut down IT systems after July 2023 cyberattack

HackingManufacturing

Southern Association of Independent Schools (SAIS)

Unsecured SAIS database exposed 682,000 school records

MisconfigurationEducation

Allegheny County, Pennsylvania

Allegheny County MOVEit breach exposed data on more than 950,000 people

HackingLocal Government

Maximus Inc.

Maximus says MOVEit hack exposed data on up to 11 million people

HackingGovernment Services

National Disability Insurance Agency

Australia's disability agency assessed exposure from the HWL Ebsworth hack

Third-Party Data BreachGovernment Agency

CardioComm Solutions

CardioComm Solutions took systems offline after cyberattack

HackingMedical Technology

Pacific Premier Bancorp

Pacific Premier Bancorp customer data stolen in vendor's MOVEit breach

Third-Party Data BreachFinancial Services

Rite Aid

Rite Aid says vendor software flaw exposed data on 24,400 customers

HackingRetail Pharmacy

1st Source Corporation

1st Source Bank reports about 450,000 records exposed in MOVEit hack

HackingFinancial Services

Yamaha Canada Music

Yamaha Canada Music confirmed attack claimed by two ransomware gangs

RansomwareMusical Instruments

George County, Mississippi

Ransomware encrypts all three servers at George County, Mississippi

RansomwareLocal Government

TSG Interactive US Services Limited (PokerStars)

PokerStars US notifies 110,291 people of MOVEit related data theft

HackingOnline Gaming

Tampa General Hospital

Tampa General Hospital says data on 1.2 million patients was stolen

RansomwareHealthcare

The Estee Lauder Companies

Estee Lauder confirmed data theft as Clop and BlackCat both claimed attacks

HackingConsumer Goods

Charter Oak Federal Credit Union

Charter Oak Federal Credit Union pulls online banking offline after attack

HackingFinancial Services

TOMRA Systems ASA

TOMRA isolates systems after extensive cyberattack on Norwegian group

HackingIndustrial Technology

Hillsborough County, Florida

Hillsborough County notified more than 70,000 people after MOVEit breach

HackingLocal Government

Sun Life Financial

Sun Life US members exposed in MOVEit breach at vendor PBI

Third-Party Data BreachInsurance

Choice Hotels International

Choice Hotels confirmed Radisson guest records taken in MOVEit attacks

Third-Party Data BreachHospitality

HCA Healthcare

HCA Healthcare breach exposed data on about 11 million patients

HackingHealthcare

Razer

Razer investigated claims that Razer Gold data and source code were stolen

HackingConsumer Electronics

Ventia

Ventia took key systems offline after weekend cyberattack

HackingInfrastructure Services

AutoZone

AutoZone notified 184,995 people of a MOVEit-related data breach

HackingAutomotive Parts Retail

Deutsche Bank

Deutsche Bank customer data exposed in service provider's MOVEit breach

Third-Party Data BreachBanking

University of the West of Scotland

University of the West of Scotland data auctioned by Rhysida ransomware gang

RansomwareHigher Education

National Institutes of Health Federal Credit Union (NIHFCU)

NIH Federal Credit Union notified 14,706 members after an email account breach

Credential CompromiseFinancial Services

Port of Nagoya

Ransomware halted container operations at Japan's Port of Nagoya

RansomwarePorts and Logistics

ZooTampa at Lowry Park

ZooTampa disclosed cyberattack claimed by BlackSuit ransomware group

RansomwareLeisure and Attractions

daa (Dublin Airport Authority)

About 2,000 Dublin Airport staff had pay data taken in the Aon MOVEit breach

Third-Party Data BreachAviation

Barts Health NHS Trust

BlackCat claimed a seven terabyte data theft from Barts Health NHS Trust

RansomwareHealthcare

Imagine360, LLC

Imagine360 notifies over 112,000 after two file transfer breaches

Third-Party Data BreachHealthcare

Advanced Medical Management, LLC

Advanced Medical Management breach exposed data on 319,485 people

HackingHealthcare

Dozor-Teleport CJSC

Russian satellite operator Dozor-Teleport knocked offline in June 2023 hack

HackingTelecommunications

U.S. Department of Health and Human Services (HHS)

HHS told Congress a MOVEit breach at contractors affected more than 100,000 people

Third-Party Data BreachFederal Government

Taiwan Semiconductor Manufacturing Company (TSMC)

TSMC faced a $70 million LockBit ransom after supplier Kinmax was breached

Third-Party Data BreachSemiconductor Manufacturing

U.S. Patent and Trademark Office (USPTO)

USPTO exposed about 61,000 trademark applicants' home addresses for three years

MisconfigurationFederal Government

Law Foundation of Silicon Valley

Ransomware at the Law Foundation of Silicon Valley exposed data on 42,525 people

RansomwareLegal Services

Suncor Energy

Suncor Energy cyberattack disrupted payments at Petro-Canada stations

HackingOil and Gas

Pilot Credentials

Pilot Credentials breach exposed data on American and Southwest pilot applicants

HackingRecruitment Technology

California Public Employees' Retirement System (CalPERS)

CalPERS said 769,000 retirees were exposed by a vendor's MOVEit breach

Third-Party Data BreachPublic Pension Fund

Gen Digital

Gen Digital said employee data was exposed in the MOVEit breach

HackingConsumer Software

Reddit

BlackCat threatened to leak 80GB of Reddit data taken in a February breach

PhishingSocial Media

Smartpay Holdings

Smartpay confirmed customer data was stolen in a ransomware attack

RansomwarePayments

U.S. Department of Agriculture

USDA said fewer than 30 employees may have been hit by a vendor's MOVEit breach

Third-Party Data BreachFederal Government

Louisiana Office of Motor Vehicles

Louisiana warned all driver's license and ID holders were exposed in MOVEit breach

HackingState Government

Development Bank of Southern Africa

Development Bank of Southern Africa disclosed an Akira ransomware attack

RansomwareBanking

FIIG Securities

ALPHV claimed theft of 385GB from Australian bond broker FIIG Securities

RansomwareFinancial Services

Intellihartx

Intellihartx told about 490,000 people data was taken in GoAnywhere hack

Third-Party Data BreachHealthcare Services

Comisión Nacional de Valores (CNV), Argentina

Medusa ransomware group attacked Argentina's National Securities Commission

RansomwareFinancial Regulator

Ofcom

Ofcom said MOVEit hack took data on 412 staff and companies it regulates

HackingGovernment Regulator

Jamaica Ministry of National Security

Jamaica's Ministry of National Security confirmed cyberattack on JamaicaEye website

HackingGovernment

Infotel JSC

Ukrainian hacktivists took Russian bank connectivity provider Infotel JSC offline

HackingTelecommunications

Mahony Horner Lawyers

Mahony Horner Lawyers warned clients of leak after IT provider was hacked

Third-Party Data BreachLegal Services

UK National Health Service (NHS)

NHS research data on 1.1 million patients accessed in University of Manchester hack

Third-Party Data BreachHealthcare

Government of Nova Scotia

Nova Scotia government detailed scope of MOVEit data theft affecting about 100,000

HackingRegional Government

Pflegia

German healthcare recruiter Pflegia exposed job seeker files in open AWS bucket

MisconfigurationRecruitment

Ascension Seton

Ascension Seton disclosed breach of two legacy websites run by vendor Vertex

Third-Party Data BreachHealthcare

Zellis

MOVEit zero-day at payroll provider Zellis exposed staff data at BA, BBC and Boots

Third-Party Data BreachPayroll Services

Hillsborough County Supervisor of Elections

Hillsborough County elections office breach exposed data on 58,000 Florida voters

HackingLocal Government

iSpace, Inc.

iSpace notified consumers of a breach exposing Social Security and health data

HackingBusiness Services

Casepoint

BlackCat claimed a breach of legal platform Casepoint used by US agencies

RansomwareLegal Technology

Idaho Falls Community Hospital

Cyberattack forced Idaho Falls Community Hospital to divert ambulances

HackingHealthcare

SimpleTire

SimpleTire left 2.8 million customer records in an open database

MisconfigurationRetail

Ejercito de Chile (Chilean Army)

Rhysida ransomware group published documents stolen from the Chilean Army

RansomwareMilitary

MCNA Dental

MCNA Dental breach affected 8.9 million people after LockBit attack

RansomwareHealth Insurance

Onix Group

Onix Group ransomware attack exposed data on about 320,000 patients and employees

RansomwareReal Estate and Healthcare Services

Insurance Information Bureau of India

Insurance Information Bureau of India hit by ransomware, refused $250,000 demand

RansomwareInsurance

Xplain

Play ransomware attack on Swiss supplier Xplain reached federal government data

RansomwareIT Services

Apria Healthcare

Apria Healthcare disclosed 2019 and 2021 breaches affecting 1.87 million people

HackingHealthcare

City of Augusta, Georgia

BlackByte ransomware gang claimed attack on the City of Augusta, Georgia

RansomwareMunicipal Government

Suzuki Motorcycle India

Cyberattack halted production at Suzuki Motorcycle India for about a week

HackingManufacturing

Bank Syariah Indonesia

LockBit published 1.5TB of data stolen from Bank Syariah Indonesia

RansomwareBanking

Collectivité Territoriale de Martinique

Rhysida claimed the ransomware attack on Martinique's territorial government

RansomwareRegional Government

Fresh Del Monte Produce

Fresh Del Monte Produce notified employees after network intrusion

HackingAgriculture

ScanSource

ScanSource confirmed ransomware attack behind multi-day outages

RansomwareTechnology Distribution

Uintah Basin Healthcare

Uintah Basin Healthcare breach affected 103,974 patients in rural Utah

HackingHealthcare

airBaltic

airBaltic sent booking details to the wrong passengers after email system error

Human ErrorAviation

Credit Control Corporation

Credit Control Corporation disclosed March 2023 breach affecting hundreds of thousands

HackingDebt Collection

Lacroix

Lacroix shut three electronics plants for a week after ransomware attack

RansomwareElectronics Manufacturing

Ambulance Victoria

Ambulance Victoria exposed paramedic drug and alcohol test results on staff intranet

Human ErrorEmergency Services

Illinois Department of Healthcare and Family Services

Illinois benefits portal breach exposed Medicaid, SNAP and TANF recipient data

Credential CompromiseGovernment

Toyota Motor Corporation

Toyota cloud misconfiguration exposed vehicle data for 2.15 million customers

MisconfigurationAutomotive

U.S. Department of Transportation

US Department of Transportation breach exposed data on 237,000 federal employees

HackingGovernment

ABB

Black Basta ransomware hits Swiss automation giant ABB

RansomwareIndustrial Technology

Murfreesboro Medical Clinic & SurgiCenter

Murfreesboro Medical Clinic shut down for two weeks after a ransomware attack

RansomwareHealthcare

TechnologyOne

TechnologyOne halts ASX trading after back-office systems breached

HackingSoftware

National Gallery of Canada

National Gallery of Canada recovers from ransomware attack

RansomwareArts and Culture

NextGen Healthcare

NextGen Healthcare breach exposed data on more than one million patients

Credential CompromiseHealth IT

Constellation Software

ALPHV claims ransomware attack on Constellation Software

RansomwareSoftware

Crown Princess Mary Cancer Centre

Medusa ransomware group claims data from Sydney's Crown Princess Mary Cancer Centre

RansomwareHealthcare

La Malle Postale

La Malle Postale left data on about 90,000 hiking clients publicly exposed

MisconfigurationTransportation

City of Dallas, Texas

Royal ransomware disrupted City of Dallas police, court and dispatch systems

RansomwareMunicipal Government

AvidXchange

AvidXchange hit by RansomHouse in its second ransomware incident of 2023

RansomwareFinancial Technology

Sysco Corporation

Sysco discloses breach affecting customer, supplier and employee data

HackingFood Distribution

HWL Ebsworth

ALPHV ransomware group claims 4TB of data from Australian law firm HWL Ebsworth

RansomwareLegal Services

Americold Realty Trust

Americold network breach shut down cold storage operations

RansomwareCold Storage and Logistics

Amnesty International Australia

Amnesty International Australia disclosed a December 2022 hack four months later

HackingNon-Profit

Diocese of Las Vegas

Diocese of Las Vegas disclosed a data breach affecting parishioners and donors

HackingReligious Organization

National Small-bore Rifle Association

Cyber attack on the UK National Small-bore Rifle Association exposes member data

HackingSports and Recreation

UnitedHealthcare

UnitedHealthcare notified members after credential stuffing attack on its mobile app

Credential CompromiseHealth Insurance

Hardenhuish School

Hardenhuish School in Wiltshire disrupted by a ransomware attack

RansomwareEducation

Bitmarck

Bitmarck took systems offline across German health insurers after a cyberattack

HackingHealthcare IT

EdisonLearning

Royal ransomware gang claimed 20GB of data stolen from EdisonLearning

RansomwareEducation Services

CIC Group, Inc.

CIC Group notified 4,500 people after a breach exposed Social Security numbers

HackingEngineering and Construction

Yellow Pages Group

Yellow Pages Canada confirmed Black Basta attack after data leak

RansomwareDigital Media and Directories

American Bar Association

American Bar Association breach exposed credentials of 1.4 million members

HackingProfessional Association

Fincantieri Marine Group

Ransomware attack halted work at Fincantieri Marine Group's Wisconsin shipyard

RansomwareShipbuilding

Consumer Financial Protection Bureau

Former CFPB employee sent data on 256,000 consumers to a personal email

Malicious InsiderGovernment Agency

Point32Health

Point32Health ransomware attack disrupted Harvard Pilgrim member services

RansomwareHealth Insurance

CommScope

Vice Society leaked CommScope employee data after March ransomware attack

RansomwareNetwork Infrastructure Manufacturing

Evide

Ransomware at Derry data firm Evide hit charities serving abuse survivors

RansomwareInformation Technology Services

Gateway Casinos & Entertainment

Gateway Casinos ransomware attack closed 14 Ontario properties

RansomwareGaming and Hospitality

Coles Group

Coles customer credit card data caught up in Latitude Financial breach

Third-Party Data BreachRetail

Dimas Volvo

Brazilian Volvo dealer Dimas Volvo leaked database credentials for a year

MisconfigurationAutomotive Retail

NCR Corporation

BlackCat ransomware knocked out NCR's Aloha point-of-sale platform

RansomwarePayment Technology

NorthOne

Unsecured database exposed over a million NorthOne-branded invoices

MisconfigurationFinancial Technology

Rheinmetall

Rheinmetall cyberattack hit civilian division, defence business unaffected

RansomwareDefence and Automotive Manufacturing

Enzo Biochem

Enzo Biochem said ransomware attack exposed test data on 2.47 million people

RansomwareBiotechnology

Kodi

Kodi disclosed forum breach affecting about 400,000 users

Credential CompromiseSoftware

Lürssen

Lürssen hit by ransomware attack over the Easter weekend

RansomwareShipbuilding

SD Worx

SD Worx shut down UK and Ireland payroll systems after cyberattack

HackingPayroll and HR Services

Webster Bank

Webster Bank customer data exposed in Guardian Analytics vendor breach

Third-Party Data BreachBanking

Groupe Nordik

Groupe Nordik breach exposed gift certificate buyers' card data

HackingHospitality

Micro-Star International (MSI)

Money Message ransomware gang claimed 1.5TB theft from MSI

RansomwareComputer Hardware

Pacific Union College

Pacific Union College discloses ransomware breach affecting 56,041 people

RansomwareHigher Education

ACRO Criminal Records Office

UK's ACRO Criminal Records Office pulled portal offline after cyber incident

HackingGovernment

Camden County Police Department

Camden County Police Department locked out of case files by ransomware

RansomwareLaw Enforcement

Municipality of Herselt

Cyberattack shut municipal services in Herselt, Belgium

Supply Chain AttackLocal Government

OCR Labs

OCR Labs exposed credentials tied to banking clients in misconfigured file

MisconfigurationIdentity Verification

Proskauer Rose

Proskauer Rose left confidential client M&A files exposed on an unsecured cloud server

MisconfigurationLegal Services

Royal Dutch Football Association (KNVB)

Royal Dutch Football Association says hackers stole employee data

RansomwareSports

Capita plc

Capita cyberattack disrupted Microsoft 365 access and exposed client data

RansomwareBusiness Services

Western Digital

Western Digital network breach takes My Cloud services offline

HackingComputer Hardware

TMX Finance

TMX Finance discloses breach affecting 4.8 million TitleMax and InstaLoan customers

HackingConsumer Lending

Meriton

Meriton breach exposes staff financial records and guest incident reports

HackingHospitality and Property

PharMerica

PharMerica breach exposed data of 5.8 million patients

RansomwareHealthcare

Crown Resorts

Crown Resorts confirms Clop extortion attempt after GoAnywhere zero-day

HackingCasinos and Entertainment

Lumen Technologies

Lumen Technologies discloses two separate cyberattacks in SEC filing

RansomwareTelecommunications

Twitter

Twitter source code leaked on GitHub, company subpoenas for leaker's identity

Malicious InsiderSocial Media

NCB Management Services

NCB Management breach grows past 1.5 million, starting with Bank of America customers

HackingDebt Collection

City of Toronto

City of Toronto confirms data theft through GoAnywhere file transfer vendor

Third-Party Data BreachMunicipal Government

Walsall Healthcare NHS Trust

Walsall Healthcare NHS Trust contains cyberattack on its network

HackingHealthcare

Alliance Healthcare Espana

Cyberattack on Alliance Healthcare Espana disrupts Spanish medicine distribution

HackingPharmaceutical Distribution

City of Oak Ridge, Tennessee

Malware attack disrupts services in the City of Oak Ridge, Tennessee

HackingMunicipal Government

US Wellness Inc.

US Wellness vendor breach exposed Blue Cross Blue Shield of Arizona members

Third-Party Data BreachHealthcare Services

QIMR Berghofer Medical Research Institute

QIMR Berghofer skin cancer study data exposed in Datatime breach

Third-Party Data BreachMedical Research

Puerto Rico Aqueduct and Sewer Authority (PRASA)

Vice Society claims cyberattack on Puerto Rico water utility PRASA

RansomwareWater Utility

Docomo Pacific

Docomo Pacific cyberattack knocks out internet and phone services in Guam and the CNMI

HackingTelecommunications

Hitachi Energy

Hitachi Energy confirms employee data breach in Clop GoAnywhere campaign

Third-Party Data BreachEnergy Technology

National Basketball Association

NBA notifies fans after breach at third-party email provider

Third-Party Data BreachSports

Latitude Financial

Latitude Financial says stolen staff login led to theft of 328,000 records

Credential CompromiseFinancial Services

GSC Game World

GSC Game World breached, hackers threaten to leak STALKER 2 material

HackingVideo Game Development

Lansing Community College

Lansing Community College breach exposed data on 757,832 people

HackingHigher Education

Essendant

LockBit claims ransomware attack behind Essendant's multi-week outage

RansomwareWholesale Distribution

NorthStar Emergency Medical Services

NorthStar EMS notifies about 82,000 patients of 2022 network intrusion

HackingEmergency Medical Services

CHU Saint-Pierre

Cyberattack diverts ambulances from Brussels hospital CHU Saint-Pierre

HackingHealthcare

Postal Prescription Service (Healthy Options Inc., Kroger)

Kroger's Postal Prescription Service exposed 82,466 customers' details

Human ErrorPharmacy

AT&T

AT&T notifies about 9 million customers after marketing vendor breach

Third-Party Data BreachTelecommunications

Black & McDonald

Ransomware hits Black & McDonald, contractor to Canada's military

RansomwareEngineering and Construction

DC Health Link

DC Health Link breach exposes data on 56,000 people including members of Congress

MisconfigurationHealth Insurance

Acer

Acer confirms breach of repair technician document server

HackingTechnology Manufacturing

SundaySky Inc.

SundaySky notifies 37,095 people after files copied from its cloud servers

HackingMarketing Technology

Cerebral

Cerebral tells 3.1 million people tracking pixels leaked their health data

Human ErrorTelehealth

Royal Dirkzwager

Play ransomware group hits Dutch maritime firm Royal Dirkzwager

RansomwareMaritime Logistics

Hospital Clínic de Barcelona

RansomHouse attack forces Hospital Clínic de Barcelona to cancel surgeries

RansomwareHealthcare

Denver Public Schools

Denver Public Schools breach exposed employee Social Security numbers

HackingEducation

Chick-fil-A

Chick-fil-A confirmed 71,473 accounts hit by credential stuffing

Credential CompromiseRestaurants

WH Smith PLC

WH Smith said attackers stole current and former employee data

HackingRetail

Group 1001 Insurance Holdings

Group 1001 insurance units restored operations after February ransomware attack

RansomwareInsurance

Minneapolis Public Schools

Medusa ransomware gang leaked Minneapolis Public Schools student records

RansomwareEducation

DISH Network Corporation

DISH Network confirms ransomware attack behind multi-day outage

RansomwareTelecommunications

Southeastern Louisiana University

Southeastern Louisiana University took its network offline after cyberattack

HackingHigher Education

U.S. Marshals Service

U.S. Marshals Service ransomware attack hit a sensitive investigative system

RansomwareFederal Government

Cornell University

Cornell ticket buyers hit by AudienceView Campus platform breach

Third-Party Data BreachHigher Education

Reventics, LLC

Reventics breach exposed data on more than 250,000 patients

RansomwareHealthcare Services

The Good Guys

The Good Guys told 1.85 million loyalty members of a supplier breach

Third-Party Data BreachRetail

Dole plc

Dole shut down North American operations after ransomware attack

RansomwareAgribusiness

U.S. Department of Defense

U.S. Department of Defense notified 20,600 people of 2023 email exposure

MisconfigurationFederal Government

Lehigh Valley Health Network

Lehigh Valley Health Network refused ransom after BlackCat attack on physician practice

RansomwareHealthcare

Tusla, Ireland's Child and Family Agency

Tusla began notifying 20,000 people whose data was stolen in the 2021 HSE attack

Third-Party Data BreachGovernment

U.S. Federal Bureau of Investigation

FBI confirmed a cyber incident on its own network at the New York field office

HackingFederal Government

Stanford University

Stanford University exposed files of 897 economics PhD applicants

MisconfigurationHigher Education

City of Hilliard, Ohio

City of Hilliard, Ohio lost $219,000 to a vendor impersonation scam

Business Email CompromiseMunicipal Government

RailYatri

RailYatri data on more than 31 million users posted to a hacking forum

HackingTravel Technology

Burton Snowboards

Burton Snowboards halted online orders after a February 2023 cyber incident

HackingSporting Goods

Liverpool University Hospitals NHS Foundation Trust

Liverpool University Hospitals NHS trust leaked payroll data of 14,000 staff

Human ErrorHealthcare

City of Oakland, California

Oakland declared a local emergency after ransomware took city systems offline

RansomwareLocal Government

Pepsi Bottling Ventures LLC

Pepsi Bottling Ventures breach hit more than 28,000 employees and contractors

HackingFood and Beverage

Aguas e Energia do Porto

LockBit claimed a ransomware attack on Porto's municipal water utility

RansomwareUtilities

Indigo Books & Music Inc.

Indigo Books & Music shut down its website after a cyberattack

RansomwareRetail

Weee!

Weee! confirmed a breach after order data for 1.1 million customers leaked

HackingRetail

MKS Instruments, Inc.

Ransomware at MKS Instruments halted production at some facilities

RansomwareManufacturing

Munster Technological University

Munster Technological University closed Cork campuses after ransomware attack

RansomwareHigher Education

Vesuvius plc

Vesuvius plc shut down systems after cyber incident at steel industry supplier

RansomwareManufacturing

PeopleConnect, the parent company of TruthFinder and Instant Checkmate

TruthFinder and Instant Checkmate Suffer Data Breach: 20 Million Customers Affected

HackingBackground Checking Services

988 Suicide and Crisis Lifeline

Cyberattack on vendor Intrado knocked out 988 Lifeline calls for nearly a day

Third-Party Service DisruptionPublic Health

Sharp HealthCare

Sharp HealthCare notified about 63,000 patients after a web server breach

HackingHealthcare

Atlantic General Hospital (Maryland)

Maryland’s Atlantic General Hospital hit by Ransomware: Patient Care Impacted

RansomwareHealthcare

ION Group

LockBit ransomware attack on ION Group disrupted global derivatives trading

RansomwareFinancial Software

Planet Ice

Planet Ice breach exposed data on more than 240,000 UK skating customers

HackingLeisure and Entertainment

JD Sports Fashion plc

JD Sports data breach hit around 10 million UK customers

HackingRetail

Charter Communications

Telecom Giant Charter Communications Discloses Vendor Security Breach: Customer Data Exposed

Third-Party Data BreachTelecommunications

Exco Technologies

Cyber Attack Cripples Exco Technologies: Three Production Facilities Still Recovering

HackingManufacturer of diecast auto parts and tools

Running Room

Running Room Canada Data Breach - Customer Data Compromised

HackingSporting goods retail

Zacks Investment Research

Zacks Investment Research Confirms Data Breach Affecting 280,000 Customers

HackingInvestment Research and Analysis

Solar Industries India Limited

BlackCat claimed a 2TB theft from Indian defence manufacturer Solar Industries

RansomwareDefence Manufacturing

GoTo (formerly LogMeIn)

GoTo (formerly LogMeIn) Suffers Data Breach

Credential CompromiseEnterprise software

Five Guys Enterprises, LLC

Five Guys Data Breach: Job Applicant Information Compromised

RansomwareFood Service

SAIF Corporation

SAIF Data Breach: Oregon's Leading Workers' Compensation Provider Experiences Security Incident

HackingOregon Workers' Compensation Insurance and Benefits

Cott Systems

400 Local Governments Forced to Resort to Manual Processes as a Result of Cott Systems Cyber Attack

HackingGovernment Records Management

Toronto Hospital for Sick Children (SickKids Hospital)

Toronto’s SickKids Hospital Confirms Ransomware Attack

RansomwareHealthcare

Gale Healthcare Solutions

30K Healthcare Workers’ Info Found On Unprotected Database

MisconfigurationHealthcare, Staffing Services

Butler County Community College

Classes Cancelled As School Recovers From Ransomware Attack

RansomwareEducation

Desjardins

Desjardins Class Action Lawsuit Over 2019 Breach Settles For $200M

Malicious InsiderFinancial Services

DNA Diagnostics Center (DDC)

DNA Testing Centre Admits To Data Breach Affecting Over 2 Million People

Credential CompromiseHealthcare Services

Lake County Board of Commissioners

FBI Investigating Attempted Data Breach During Election Fraud

Malicious InsiderGovernment, Local Services

Atalanta

Food Importer Admits Data Breach After Previous Ransomware Attack

RansomwareFood & Beverage, Distributor/Importer

Cox Communications

Fraudster Impersonates Support Agent In Cox Vishing Attack

PhishingMedia, Digital Cable Provider

MonoX

Hackers Victimize MonoX Leaving Losses Up To $30M in Digital Tokens

HackingFintech, Cryptocurrency

Supernus Pharmaceuticals

Ransomware Gang Threatens to Leak 1.5TB of Data

RansomwarePharmaceutical

Superior Plus

Superior Plus Discloses Ransomware Attack Over The Weekend

RansomwareDistribution, Propane

The Virginia Division of Legislative Automated Systems (DLAS)

Virginia’s Government IT Agency Hit By Ransomware

RansomwareGovernment, Technology Services

Governor General of Canada

Governor General of Canada Detects Internal Network Breach

HackingFederal Government

Social Enterprise for Canada (SEC)

Ontario Non-Profit Warning Clients After Ransomware Attack

RansomwareNon-Profit, Family Services

Kronos, Ultimate Group

Ransomware Attack Could Affect Customer Payroll Services For Weeks

RansomwareTechnology, Payroll Services

Planned Parenthood

400,000 Patients’ Information Compromised In Ransomware Attack

RansomwareHealthcare, Non-Profit

GoDaddy

Over 1 Million Users Affected In GoDaddy Data Breach

Credential CompromiseTechnology, Web Hosting

CoinMarketCap

3.1 Million Users’ Email Addresses Leaked In Data Breach

HackingTechnology, Financial

Robinhood

7 Million Users Affected In Robinhood Data Breach

PhishingFintech

Ronmor Holdings

Calgary Real Estate Developer Hit By Ransomware Attack

RansomwareReal Estate

Ferrara Candy Company

Candy Maker Hit By Ransomware During Halloween Rush

RansomwareFood and Beverage, Manufacturer

West Virginia Parkways Authority

Cyberattack on Government Agency Disrupts Computer Systems

RansomwareGovernment Agency, Transportation

Newfoundland and Labrador Health

Experts Deem N.L. Cyberattack as Canada’s Worst Ever

RansomwareGovernment, Healthcare

Federal Bureau of Investigation (FBI)

FBI Email System Compromised In Cyberattack

Business Email CompromiseFederal Government, Agency

IKEA

IKEA Hit By Ongoing, Highly Sophisticated Reply-Chain Attack

PhishingRetail

Diamond Comic Distributors

Major Comic Book Distributor Hit By Ransomware

RansomwareDistributor, Publications & Entertainment

California Pizza Kitchen

Over 100,000 Employees Affected By California Pizza Kitchen Data Breach

HackingFood & Beverage, Restaurant

PracticeMax

Patient Data Exposed In 3rd Party Healthcare Ransomware Attack

RansomwareHealthcare Services, Technology

Sinclair Broadcast Group

Ransomware Knocks Programs Offline for Nationwide Broadcast Group

RansomwareMedia

Rideau Valley Health Centre

Ransomware Attack On Ottawa Clinic Disrupts Patient Care

RansomwareHealthcare, Medical Clinic

Schreiber Foods

Ransomware Shuts Down Production Distribution For Schreiber Foods

RansomwareAgriculture, Manufacturer

Hewlett Packard Enterprise (HPE)

Stolen Access Key Used to Breach HPE’s Aruba Central

Credential CompromiseTechnology, Manufacturing

National Rifle Association (NRA)

Threat Actors Demand Ransom from NRA After Leaking Files On Dark Web

RansomwareAdvocacy Group

Toronto Transit Commission (TTC)

Toronto Transit System Hit By Ransomware Attack

RansomwareGovernment Agency, Transportation

Electronic Warfare Associates

US Defense Contractor Reveals Employee Phishing Attack

PhishingGovernment, Defense Contractor

Turner Construction Co.

5,600 Construction Employees Potentially Impacted By Phishing Scam

PhishingConstruction

Defence Construction Canada

Defence Construction Canada Recovering After Cyber Attack On IT Systems

HackingConstruction, Federal Government

Clark Builders

Edmonton Construction Company Warns Industry After $11.8M Phishing Scam

PhishingConstruction

Professional Excavators and Construction

Over $100k In Ransomware Recovery Costs for Calgary Construction

RansomwareConstruction

University of Colorado

30,000 University Students Potentially Impacted By 3rd Party Data Breach

HackingEducation

Kemptville District Hospital

Ontario Hospital Resumes Emergency Services After ‘Cyber Incident’

HackingHealthcare, Medical

Olympus Corporation of the Americas

Global Medical Manufacturer’s IT Systems Down After 2nd Consecutive Ransomware Attack

RansomwareManufacturer, Medical Technology

Durham Regional Government

Hackers Leak More Troubling Data for Local Ontario Government

Third-Party Data BreachGovernment, Municipal

Sandhills Global

Systems And Operations Shut Down For Digital Publisher After Ransomware

RansomwareTechnology, Digital Publishing

Twitch

Twitch Suffers Massive Source Code Data Breach

MisconfigurationTechnology, Streaming Platform

Premier Patient Healthcare

Terminated Executive Turns Insider Threat After 37,000 Patients’ Data Compromised

Malicious InsiderHealthcare

Oregon Eye Specialists

Independent Optometry Chain Hit By Employee Email Breach

Credential CompromiseHealthcare, Optometry

Unity Health Toronto

Toronto Hospital Network Investigating After Malicious Insider Threatens Data Exposure

Third-Party Data BreachHealthcare

Next Level Apparel

Several Employee Email Accounts Compromised in Phishing Attack

PhishingManufacturer, Clothing

Coinbase

Hackers Steal Cryptocurrency from 6,000 Coinbase Users

HackingTechnology, Financial App

Neiman Marcus

4.9 Million Affected by Retail Giant Neiman Marcus Data Breach

HackingRetail

Navistar

Employees Seek Class Action Lawsuit After Info Stolen In Data Breach

HackingManufacturing, Automobile

MoneyLion

Fintech Customer Accounts Locked After Credential Stuffing Attack

Credential CompromiseFinancial, Fintech

Marcus & Millichap

Ransomware Group Targets Commercial Real Estate Firm

RansomwareReal Estate

Marketron

Thousands of Customers Impacted By Marketron Ransomware Attack

RansomwareTechnology, Marketing Services

Portpass

Privacy Breach Could Affect 650K Canadians Using COVID-19 Passport App

MisconfigurationTechnology, Vaccine Passport Platform

Epik

Hacktivist Group Anonymous Leaks 180GB of Far-Right Data

HackingTechnology, Web Hosting

New Cooperative And Crystal Valley Cooperative

Twin Ransomware Attacks Halt Business For Agriculture Industry

RansomwareManufacturing, Agriculture

Simon Eye And US Vision

Hackers Victimize Healthcare Providers in Dual Hacking Breaches

HackingHealthcare, Optometry

Dotty’s

F&B Customer’s Data Exposed In Ransomware Attack

RansomwareFood and Beverage, Gaming

TTEC

TTEC Ransomware Attack Encrypts Data Disrupting Business Operations

RansomwareTechnology, Customer Service Provider

Walgreen’s

Millions Possible Affected By Walgreen’s Website Error

MisconfigurationRetail, Pharmacy

United Nations

Hackers Infiltrate United Nations IT Networks

HackingIntergovernmental Organization

Texas Right To Life

Hundreds of Job Applicants’ Data Exposed on Misconfigured Website

MisconfigurationPolitical Rights Organization

Pacific City Bank

Ransomware Attack Hits Community Bank

RansomwareFinancial

Career Group Inc.

Company Warns 49,000 Customers After Ransom Paid In Cyber Attack

RansomwareStaffing Agency

DuPage Medical Group

600,000 Patients Warned After Medical Group Discovers Data Breach

HackingHealthcare, Medical

Austin Cancer Centers

Cyber Attack Exposes Over 36,000 Cancer Clinic Patients’ Data

RansomwareHealthcare

Canpar Express

No Explanation on Ransomware Attack Leaves Customers Complaining

RansomwareLogistics

Canada Revenue Agency

Thousands Affected By CRA Data Breach

Credential CompromiseGovernment

Twitter

Major Bitcoin Scam Rocks Twitter

HackingSocial Media

MGM Resorts

Over 142 Million Affected in MGM Resorts Data Breach

Credential CompromiseTravel, Hotel

PEI Provincial Government

$900,000 In Costs For PEI Taxpayers After Ransomware Attack (Update)

RansomwareGovernment

OneClass

Over 1 Million Students’ Personal Info Exposed on Unsecured Database

MisconfigurationEducation

Chartered Professional Accountants of Canada (CPA)

329,000 Affected By CPA Canada Phishing Attack

PhishingFinancial

Northwest Territories Power Corporation (NTPC)

NTPC Customers Facing “Financial Hardships” After Ransomware Attack

RansomwareServices, Utilities Provider

GoDaddy

Approximately 28,000 GoDaddy Users Affected by Data Breach

HackingTechnology, Web Hosting

World Health Organization

450 Active WHO Email Credentials Leaked Online

Credential CompromiseNot-For-Profit, Healthcare

The Ottawa Hospital

Ottawa Police Warning New COVID-19 Hospital Phishing Scam

PhishingHealthcare

Quebec Treasury Board

360,000 Quebec Teachers Affected By Data Breach

Credential CompromiseEducation

PEI Government

PEI Government Investigating Ransomware Attack

RansomwareGovernment

Simon Fraser University

SFU Ransomware Attack Compromises Personal Info for Students, Faculty & Alumni

RansomwareEducation

Southern First Nations Network of Care

Non-Profit IT Systems Paralyzed for 6 Weeks In Ransomware Attack

RansomwareNon-Profit

Public Service and Procurement Canada

Canadian Government's Internal Data Breach: 69,000 Federal Workers' Information Compromised

Human ErrorGovernment

Confederation College

Malware Disables Canadian College’s IT Systems

HackingEducation

Canadian Government, Federal Departments

144,000 Canadians’ Personal Info Mishandled by Federal Departments

Human ErrorGovernment

Rogers Communication

Rogers Communications Notified of Minor Data Leak

MisconfigurationTechnology, Telecommunications

Bird Construction

Ransomware Hits Canadian Federal Contractor Bird Construction

RansomwareConstruction

City of Corner Brook

City’s Privacy Breach Handed Over to Provincial Privacy Commissioner

MisconfigurationGovernment, Municipality

eHealth

eHealth Sask Sees Downtime Costs Escalate After Ransomware Attack

RansomwareMedical Services

PlanetDrugsDirect

Hackers Access Personal Health Info From Online Pharmacy

HackingOnline Retail, Healthcare

CIBC, Scotiabank, RBC, TD Canada Trust

2 Year Phishing Campaign Targeting Major Canadian Banks Uncovered

PhishingFinancial Services

Plenty of Fish

Plenty of Fish Private User Info Accidental Data Leaked

MisconfigurationTechnology, Dating Services App

Andrew Agencies

Financial Company Sees 245 Computers Encrypted with Ransomware

RansomwareFinancial Services

Craftsman Collision

$100s of Thousands in Ransomware Remediation For Craftsman Collision

RansomwareService, Automobile Repair

Life Labs

15 Million Canadians Potentially Affected By Life Labs’ Massive Data Breach

RansomwareMedical Services

Shaw

Shaw Warns Customers of Potential Data Leak 6 Months Later

Lost or Stolen DeviceTechnology & Communications

City of Woodstock

Local Canadian Govt Accrues $667,000 in Costs After Ransomware

RansomwareLocal Government

Alectra Utilities

Utilities Company Urging Customers To Be Alert After Data Breach

MisconfigurationUtilities Distributor

Waterloo Catholic District School Board

ON Catholic School Faces Rising Downtime Costs After Ransomware

RansomwareEducation

Waterloo Brewing Company

$2.1 Million Lost In Phishing Attack for Waterloo Brewing

Business Email CompromiseFood and Beverage, Manufacturing

Nunavut Government Services Impacted By Ransomware

Nunavut Government Services Impacted By Ransomware

RansomwareGovernment

Pipestone Kin-Ability Centre

Over $400K Siphoned In Not-For-Profit System Hack

HackingNot-for-Profit, Health Services

Ontario Science Centre

3rd Party Data Breach Affects Ontario Science Centre

Third-Party Data BreachEducational Institution

TransUnion

37,000 Potentially Affected By TransUnion Data Breach

Credential CompromiseFinancial

PAL Airlines

Hacked Email Provides Access To Airline’s Sensitive Data

Credential CompromiseTravel, Airlines

National Basketball Association Canada (NBA Canada)

NBA Canada Suffers Massive Data Breach

MisconfigurationEntertainment

Listowel Wingham Hospital Alliance

Ontario Hospital Network Faces Increasing Downtime Costs After Ransomware

RansomwareMedical, Health Services

DoorDash

Nearly 5 Million DoorDash Users Impacted After Server Hack

HackingFood and Beverage

Scotiabank

Scotiabank's Major Security Breach: 25 Million Scotiabank Customers’ Data Left Exposed

MisconfigurationFinancial

Yves Rocher

Yves Rocher Data Leak Impacts 2.5 Million Canadians

MisconfigurationRetail

Eastern Ontario Municipality

$7-$10K Ransom Request Refused by Municipal Ontario Government

RansomwareGovernment, Municipal

Boyd Group Income Fund

Well Prepared Boyd Group Hit By Ransomware Attack

RansomwareService, Automobile Repair

Desjardins

Former Credit Union Employee Creates Data Breach Affecting 2.9 Million Customers

Malicious InsiderFinancial Services

City of Burlington

BEC Phishing Scam Tricks City into Transferring $530K

Business Email CompromiseGovernment

Nova Scotia Health Authority

2,841 Patients Impacted by Phishing Attack

PhishingGovernment, Health Services

Freedom Mobile

Thousands Impacted By Freedom Mobile Server Leak

MisconfigurationTechnology, Telecommunications

Mitsubishi Aerospace

Ransomware Leaves Mitsubishi Aerospace Without Internet and Network Access

RansomwareTechnology

BC Pension Corporation

8,000 People Warned After BC Pension Plan Data Leak

Lost or Stolen DeviceGovernment

Precise Parklink

Small Risk, High Costs After Ransomware hits CIRA Parking Garage

RansomwareService, Parking Garage

Norsk Hydro ASA

Norsk Hydro ransomware attack forced aluminum plants onto manual operations

RansomwareManufacturing

Natural Health Services Ltd.

Alberta Patients Warned After Data Breach Exposes Medical Info

HackingHealthcare, Retail

Container World

Richmond, BC Facility’s System Shutdown in Lieu of Ransom Payment

RansomwareLogistics

NWT Department of Health and Social Services

40K Canadians Potentially Impacted By Lost Gov’t Employee Laptop

Lost or Stolen DeviceGovernment, Healthcare

500px

14.8 Million Accounts Exposed In 500px Data Breach

HackingTechnology

CarePartners

CarePartners Ransomware Attack: $60K Bitcoin Demand Threatens Data Exposure

RansomwareHealthcare

Canada Revenue Agency (CRA)

Thousands of Canadians Affected As CRA Employees Caught Snooping

Malicious InsiderGovernment Agency

Coast Capital Savings

$100’s of Thousands Stolen as Coast Capital Members Targeted In Phishing Ring

PhishingFinancial