Breach news
Reported breaches, what was taken, and how the intrusion started.
994 reports
Aflac Incorporated
Aflac discloses network intrusion tied to insurance sector campaign
HackingInsuranceDisneyland Paris
Anubis group claimed 64 GB of Disneyland Paris files from a contractor
Third-Party Data BreachEntertainmentKrispy Kreme
Krispy Kreme breach exposed data on 161,676 people after 2024 attack
RansomwareFood & BeverageOxford City Council
Oxford City Council breach exposed 21 years of election worker records
HackingGovernmentChain IQ
Chain IQ breach spilled contact data on more than 100,000 UBS employees
HackingBusiness ServicesOcuco
Ocuco breach exposes health data of about 241,000 people
RansomwareHealthcare TechnologyWestJet
WestJet investigates cyberattack affecting internal systems and app
HackingAirlineZoomcar Holdings, Inc.
Zoomcar discloses breach affecting 8.4 million users
HackingTransportationYes24
Ransomware attack takes South Korean ticketing platform Yes24 offline
RansomwareE-commerce & TicketingErie Insurance
Erie Insurance confirms cyberattack behind multi-week outage
HackingInsuranceUnited Natural Foods, Inc.
Cyberattack on United Natural Foods disrupts grocery distribution
HackingFood DistributionEpisource
Episource breach exposed health records of more than 5.4 million people
HackingHealthcareIllinois Department of Healthcare and Family Services
Illinois healthcare agency reports phishing breach affecting 933 people
PhishingGovernmentJackson Health System
Jackson Health System fires employee over five-year patient data snooping
Malicious InsiderHealthcareKiranaPro
KiranaPro blames former employee after AWS and GitHub data wipe
Malicious InsiderRetailOptima Tax Relief
Chaos ransomware group leaked 69 GB stolen from Optima Tax Relief
RansomwareFinancial ServicesHM Revenue and Customs (HMRC)
HMRC says phishing fraud hit 100,000 tax accounts and cost 47 million pounds
PhishingGovernmentThe North Face (VF Outdoor)
The North Face discloses April credential stuffing attack on customer accounts
Credential CompromiseRetailCartier
Cartier tells clients names and email addresses were stolen in system breach
HackingRetailCity of Durant, Oklahoma
Ransomware attack disrupts services for the city of Durant, Oklahoma
RansomwareGovernmentMainStreet Bank (MainStreet Bancshares, Inc.)
MainStreet Bank customer card data exposed in third-party vendor breach
Third-Party Data BreachFinancial ServicesMissouri Department of Conservation
Missouri Department of Conservation breach exposed employee health plan data
HackingGovernmentDataPost
DataPost ransomware attack exposed data of 146 Income Insurance policyholders
RansomwareBusiness ServicesVictoria's Secret & Co.
Victoria's Secret takes down U.S. website after security incident
HackingRetailCovenant Health
Covenant Health cyberattack disrupts hospitals in Maine and New Hampshire
RansomwareHealthcareLexisNexis Risk Solutions
LexisNexis Risk Solutions breach on GitHub exposed data of 364,000 people
Credential CompromiseBusiness ServicesMathWorks
MathWorks confirms ransomware attack behind MATLAB service outages
RansomwareTechnologyTiffany & Co.
Tiffany & Co. discloses South Korean customer data breach at third-party platform
Third-Party Data BreachRetailAdidas
Adidas discloses customer data breach at third-party service provider
Third-Party Data BreachRetailWest Lothian Council
West Lothian Council confirms school data stolen in Interlock ransomware attack
RansomwareGovernmentCellcom
Cellcom confirms cyberattack behind week-long voice and text outage in Wisconsin
HackingTelecommunicationsKettering Health
Interlock ransomware attack shuts down systems across Ohio's Kettering Health
RansomwareHealthcarePeter Green Chilled
Ransomware attack on Peter Green Chilled disrupts UK supermarket food supplies
RansomwareTransportation & LogisticsEffortel
Effortel breach exposes data of 70,000 Belgian mobile customers
HackingTelecommunicationsServiceaide
Serviceaide database exposure hit 483,000 Catholic Health patients
MisconfigurationInformation TechnologyMKA Accountants
Qilin ransomware gang lists Melbourne firm MKA Accountants as a victim
RansomwareProfessional ServicesChristian Dior Couture
Christian Dior Couture confirms customer data breach affecting Asian shoppers
PhishingRetailCoinbase Global, Inc.
Coinbase says bribed overseas support agents leaked customer data
Malicious InsiderFinancial ServicesNova Scotia Power
Nova Scotia Power confirms theft of customer data in ransomware attack
RansomwareUtilitiesNucor Corporation
Nucor halts steel production at multiple sites after cyberattack
HackingManufacturingCity of Edinburgh Council
Edinburgh council resets school network passwords after phishing attack
PhishingEducationLegal Aid Agency
U.K. Legal Aid Agency warns providers of security incident on its online systems
HackingGovernmentMasimo Corporation
Masimo cyberattack slowed manufacturing at the medical device maker
HackingMedical DevicesOettinger Getränke
German brewer Oettinger confirms cyberattack claimed by RansomHouse
RansomwareFood and BeverageSouth African Airways
South African Airways says cyberattack disrupted website, app and internal systems
HackingAviationGlobal Crossing Airlines (GlobalX)
Hacktivists breached deportation charter airline GlobalX and took flight manifests
HackingAviationHarrods
Harrods restricted internet access after attempted intrusion on its systems
HackingRetailCo-op Group
Co-op Group confirmed member data theft after DragonForce intrusion
RansomwareRetailTexas Health and Human Services Commission
Texas HHSC says employees improperly accessed data of about 94,000 people
Malicious InsiderGovernmentKintetsu World Express
Kintetsu World Express confirmed ransomware attack disrupted its systems
RansomwareShipping & LogisticsBarnstable County Sheriff's Office
Insider breach at Barnstable County Sheriff's Office exposed employee records
Malicious InsiderGovernmentYale New Haven Health System
Yale New Haven Health breach exposed data on nearly 5.6 million patients
HackingHealthcareMarks & Spencer
Marks and Spencer halted online orders after DragonForce ransomware attack
RansomwareRetailThe Hertz Corporation
Hertz confirmed customer data theft through the Cleo file transfer exploit
Third-Party Data BreachTravel & LeisureSensata Technologies
Sensata Technologies ransomware attack halts shipping and production
RansomwareManufacturingSK Group
Qilin ransomware gang claims 1TB theft from SK Group's U.S. arm
RansomwareConglomerateWestern Sydney University
Western Sydney University breach exposed records of 10,000 students
HackingEducationBlue Shield of California
Blue Shield of California sent member health data to Google Ads by misconfiguration
MisconfigurationHealthcareOregon Department of Environmental Quality
Oregon environmental agency shuts down network after cyberattack
RansomwareGovernmentWooCommerce (Automattic)
Hacker claims WooCommerce data breach, Automattic denies its systems were hit
Third-Party Data BreachE-commerce SoftwareCaisse Nationale de Sécurité Sociale (CNSS), Morocco
Morocco's social security fund CNSS had data on nearly 2 million people leaked
HackingGovernmentNASCAR
Medusa ransomware group claimed a NASCAR breach and demanded $4 million
RansomwareSports & EntertainmentOffice of the Comptroller of the Currency
U.S. bank regulator OCC discloses year-long email system breach
HackingGovernmentDBS Bank
DBS and Bank of China Singapore customer data exposed by vendor ransomware
Third-Party Data BreachFinancial ServicesFall River Public Schools
Fall River Public Schools in Massachusetts hit by ransomware attack
RansomwareEducationAustralianSuper
AustralianSuper and rival funds hit by coordinated credential stuffing
Credential CompromisePensions and Retirement SavingsCentral Texas Pediatric Orthopedics
Central Texas Pediatric Orthopedics breach affected 140,000 patients
HackingHealthcareWK Kellogg Co.
WK Kellogg confirms employee data breach tied to Cleo file transfer flaws
Third-Party Data BreachFood and Beverage ManufacturingState Bar of Texas
State Bar of Texas confirmed data theft after an attack claimed by INC Ransom
RansomwareLegal ServicesTwilio
Twilio denies SendGrid breach after hacker offers 848,000 records for sale
HackingTechnologyRoyal Mail Group
Royal Mail data leaked after breach at supplier Spectos
Third-Party Data BreachPostal and LogisticsCity of Baltimore
City of Baltimore lost $1.5 million to a vendor impersonation scheme
Business Email CompromiseGovernmentLower Sioux Indian Community
Ransomware attack disrupted Lower Sioux Indian Community casino and health services
RansomwareTribal GovernmentLaborers' International Union of North America Local 1184
LiUNA Local 1184 notified members of a 2024 ransomware data breach
RansomwareLabor UnionSamsung Germany
Samsung Germany support tickets leaked after four-year-old credentials were reused
Credential CompromiseTechnologyParcel Plus
Parcel Plus tax clients had refunds redirected after spear phishing attack
PhishingProfessional ServicesGerman Association for East European Studies (DGO)
German East European studies association breached again, Russia suspected
HackingNon-profit ResearchNine Entertainment
Nine exposed 16,000 Australian newspaper subscribers through a supplier lapse
Third-Party Data BreachMediaNew South Wales Department of Communities and Justice
NSW justice department breach exposed 9,000 court files including violence orders
HackingGovernmentLee University
Lee University notifies about 137,000 people a year after network breach
RansomwareEducationOracle
Oracle denies cloud breach as researchers back hacker's six million record claim
HackingTechnologyWestern Alliance Bank
Western Alliance Bank notifies 21,899 customers after Cleo file transfer breach
Third-Party Data BreachFinancial ServicesALN Medical Management, LLC
ALN Medical Management discloses 2024 breach of third-party hosted systems
HackingHealthcareUkrzaliznytsia
Cyberattack knocks out Ukrainian railway Ukrzaliznytsia's online ticketing
HackingTransportationUniversity of Notre Dame Australia
University of Notre Dame Australia struggles to recover from January cyberattack
RansomwareEducationPennsylvania State Education Association
PSEA notified more than 517,000 people after Rhysida claimed 2024 breach
RansomwareNon-profitJames Pascoe Group
James Pascoe Group cyberattack disrupts Farmers and Whitcoulls stores
RansomwareRetailGanong Bros. Ltd.
Ganong Bros. chocolate plant disrupted by ransomware attack claimed by Play
RansomwareManufacturingYap State Department of Health Services
Ransomware forced Micronesia's Yap health department offline
RansomwareGovernmentBis Industries
Bis Industries investigates RansomHub claims over December 2024 attack
RansomwareMining ServicesSorbonne Université
FunkSec claimed a breach at Sorbonne Universite; the university called it limited
RansomwareEducationLake Washington Vascular
Lake Washington Vascular restored from backups after Qilin ransomware attack
RansomwareHealthcareSunflower Medical Group
Sunflower Medical Group breach exposed data on nearly 221,000 patients
RansomwareHealthcareBank of America
Bank of America warned customers after document destruction vendor mishandled records
Third-Party Data BreachFinancial ServicesChicago Public Schools
Chicago Public Schools says Cleo vendor breach exposed 700,000 students
Third-Party Data BreachEducationNTT Communications Corporation
NTT Communications breach exposed data on nearly 18,000 corporate customers
HackingTelecommunicationsBerkeley Research Group
Berkeley Research Group discloses ransomware attack during LBO debt sale
RansomwareBusiness ServicesCarruth Compliance Consulting
Carruth Compliance Consulting breach exposed data on tens of thousands of school staff
RansomwareBusiness ServicesNational Presto Industries
National Presto Industries disrupted by March 2025 cyberattack
RansomwareManufacturingAustralian New Zealand Clinical Trials Registry
Clinical trials registry ANZCTR taken offline after University of Sydney breach
HackingHealthcareOrange Group
Orange Group confirms breach of Romanian back office systems
HackingTelecommunicationsAnne Arundel County, Maryland
Anne Arundel County closed buildings after ransomware attack on its network
RansomwareGovernmentCleveland Municipal Court
Cyber incident closed Cleveland Municipal Court for more than two weeks
RansomwareGovernmentDISA Global Solutions, Inc.
DISA Global Solutions breach exposed data on 3.3 million screening subjects
HackingBusiness ServicesHCRG Care Group
Medusa gang demanded $2m from UK healthcare provider HCRG Care Group
RansomwareHealthcareHipshipper
Hipshipper left 14.3 million shipping records exposed in open cloud bucket
MisconfigurationTransportation & LogisticsInspira Financial Trust, LLC
Call center contractor accessed data on 2,308 Inspira Financial savers
Third-Party Data BreachFinancial ServicesRainbow District School Board
Rainbow District School Board cyberattack exposed decades of student and staff data
RansomwareEducationGenea
Genea discloses breach after Termite ransomware attack on IVF clinics
RansomwareHealthcareNioCorp Developments Ltd.
NioCorp Developments lost $500,000 to an email compromise scam
Business Email CompromiseMining & Natural ResourcesThe Agency
Rhysida claimed a ransomware attack on London talent agency The Agency
RansomwareMedia & EntertainmentNippon Steel
BianLian claims theft of 500 GB from Nippon Steel's US operations
RansomwareManufacturingUnimicron Technology
Sarcoma ransomware group claims 377 GB stolen from PCB maker Unimicron
RansomwareManufacturingOffice of the Attorney General of Virginia
Cyberattack knocked the Virginia Attorney General's office offline
HackingGovernmentMars Hydro
Unsecured Mars Hydro database exposed 2.7 billion IoT records
MisconfigurationManufacturingPinehurst Radiology Associates, PLLC
Pinehurst Radiology Associates closed indefinitely after cyberattack
HackingHealthcareSault Ste. Marie Tribe of Chippewa Indians
Ransomware shut Kewadin Casinos and Sault Tribe services across Michigan
RansomwareTravel & LeisureCPI UK
Ransomware attack halted book printer CPI UK's production for weeks
RansomwarePrinting & PublishingMemorial Hospital and Manor
Memorial Hospital and Manor notified 120,085 people after ransomware attack
RansomwareHealthcareSanrio Entertainment
Sanrio Entertainment ransomware attack put up to 2 million records at risk
RansomwareEntertainmentIMI plc
IMI plc disclosed unauthorised access to its systems in a stock exchange filing
HackingEngineeringCommunity Health Center, Inc.
Community Health Center breach exposed data on more than 1 million patients
HackingHealthcareGrubhub
Grubhub breach traced to a third-party customer support provider
Third-Party Data BreachOnline Food DeliveryLee Enterprises
Cyberattack halted printing and publishing across Lee Enterprises newspapers
RansomwareMediaTata Technologies
Tata Technologies reports ransomware attack in stock exchange filing
RansomwareEngineering ServicesMizuno USA
Mizuno USA said attackers spent two months copying files from its network
RansomwareManufacturingDeepSeek
DeepSeek left a database of chat logs and API keys exposed online
MisconfigurationTechnology (Artificial Intelligence)New York Blood Center Enterprises
Ransomware attack on New York Blood Center disrupts collections
RansomwareHealthcareSmiths Group plc
Smiths Group discloses unauthorized access to its systems
HackingEngineering & ManufacturingARDEX Australia
Medusa ransomware group claims attack on ARDEX Australia
RansomwareConstruction ProductsThe British Museum
British Museum partly closed after dismissed contractor shut down systems
Malicious InsiderArts and CultureConduent
Conduent confirms cyberattack behind US government service outages
HackingBusiness ServicesHewlett Packard Enterprise
HPE investigates IntelBroker claim of stolen source code and repositories
HackingTechnologyMortgage Investors Group
Mortgage Investors Group discloses December breach after Black Basta claim
RansomwareFinancial ServicesChemeketa Community College
Chemeketa Community College staff data exposed in Carruth Compliance breach
Third-Party Data BreachEducationDivimast
Akira ransomware lists Italian ERP consultancy Divimast on its leak site
RansomwareInformation TechnologyOtelier
Otelier breach exposes hotel guest reservations for Marriott, Hilton and Hyatt
Credential CompromiseHospitality TechnologyAvery Products Corporation
Avery says card skimmer sat on its website for nearly five months
HackingManufacturingWillow Pays
Willow Pays left customer bill payment database open on the internet
MisconfigurationFinancial ServicesRoseltorg
Roseltorg confirms cyberattack on Russia's state procurement platform
HackingGovernmentEindhoven University of Technology (TU/e)
Eindhoven University of Technology shuts down network after cyberattack
HackingEducationGeodesy, Cartography and Cadastre Office of the Slovak Republic (UGKK)
Ransomware shuts Slovakia's land registry office UGKK, stalling property deals
RansomwareGovernmentUnacast
Unacast tells Norwegian regulator hackers took Gravy Analytics location data
Credential CompromiseTechnologyIndiana University Health
Indiana University Health email compromise exposed patient records
Credential CompromiseHealthcareAlcool NB Liquor (NB Liquor)
NB Liquor shut down point of sale systems after suspected cyberattack
HackingRetailInternational Civil Aviation Organization
ICAO confirms recruitment database breach affecting nearly 12,000 people
HackingGovernmentPowerSchool
PowerSchool breach exposes K-12 student and teacher records worldwide
Credential CompromiseEducation TechnologyPolicía de Seguridad Aeroportuaria
Argentina's airport security police hit by payroll data breach
HackingGovernmentRegionTransService LLC
Ukraine's HUR claims destructive attack on rail firm RegionTransService
HackingLogistics & TransportBank of America
Bank of America notifies loan customers after third-party provider breach
Third-Party Data BreachBanking & FinanceFraunhofer Institute for Industrial Engineering IAO
Ransomware attack hit Germany's Fraunhofer IAO research institute in Stuttgart
RansomwareResearch & EducationDE Photo
DE Photo hit by back-to-back intrusions over Christmas 2024
HackingPhotography ServicesLas Palmas Del Sol Healthcare (El Paso Healthcare System, Ltd.)
Las Palmas Del Sol Healthcare told 1,854 patients a former employee viewed their records
Malicious InsiderHealthcareU.S. Department of the Treasury
Chinese state hackers breached US Treasury workstations through BeyondTrust
Supply Chain AttackGovernmentNikki-Universal Co., Ltd.
Nikki-Universal confirms ransomware attack on its servers
RansomwareChemical ManufacturingYouth Eastside Services
Youth Eastside Services breach exposed mental health client records in Washington
RansomwareHealthcareTurks and Caicos Islands Government
Turks and Caicos government recovers from pre-Christmas ransomware attack
RansomwareGovernmentCenter for Vein Restoration
Center for Vein Restoration breach exposed data on 446,094 patients and staff
HackingHealthcareWood County, Ohio
Ransomware sends Wood County, Ohio emergency dispatch back to pen and paper
RansomwareGovernmentArtivion
Artivion tells SEC cyberattack disrupted order and shipping processes
RansomwareMedical DevicesKurita Water Industries (Kurita America Inc.)
Ransomware hit Kurita Water Industries' US arm, exposing customer and staff data
RansomwareWater TreatmentLuka Rijeka d.d. (Port of Rijeka)
8Base ransomware group claimed a data theft at Croatia's Port of Rijeka
RansomwareLogistics & TransportBT Group
BT Group confirms attempted attack on conferencing unit claimed by Black Basta
RansomwareTelecommunicationsChemonics International
Chemonics International discloses 2023 intrusion affecting 263,136 people
HackingGovernment ContractorENGlobal Corporation
ENGlobal discloses ransomware attack that limited access to its IT systems
RansomwareEnergyRefinadora Costarricense de Petróleo (RECOPE)
Ransomware forced Costa Rica's state fuel company RECOPE to sell fuel manually
RansomwareEnergy & UtilityUganda - Bank of Uganda
Bank of Uganda lost millions after international payments were diverted
HackingFinanceItaly - Bologna FC 1909
Bologna FC confirmed ransomware attack after RansomHub leaked club data
RansomwareSports and EntertainmentU.S. Veterans Health Administration
Veterans Health Administration notifies 2,302 veterans after vendor attack
Third-Party Data BreachGovernment HealthcareUK - Alder Hey Children's NHS Foundation Trust
INC Ransom published data stolen from Alder Hey Children's NHS trust
RansomwareHealthcareCabot Financial (Ireland)
Cabot Financial Ireland tells High Court 394,000 files were stolen
HackingFinancial ServicesCity of Hoboken, New Jersey
Ransomware attack shut down City of Hoboken government operations
RansomwareGovernmentWirral University Teaching Hospital NHS Foundation Trust
Wirral University Teaching Hospital NHS trust declares major incident after cyberattack
HackingHealthcareStarbucks
Starbucks fell back on manual payroll after Blue Yonder ransomware attack
Third-Party Service DisruptionFood and Beverage RetailTexas Tech University Health Sciences Center
Texas Tech University Health Sciences Center breach hit 1.46 million patients
RansomwareHealthcareVogue Homes
KillSec claims data theft from Australian home builder Vogue Homes
RansomwareConstructionPacific Pulmonary Medical Group
Everest gang dumped Pacific Pulmonary Medical Group patient records
Credential CompromiseHealthcareBlue Yonder
Blue Yonder ransomware attack disrupts grocery and retail supply chains
RansomwareSoftwareJapan - Kumamoto Prefecture Anti-Violence Movement Promotion Center
Kumamoto anti-violence counseling center warned of possible data leak
PhishingNonprofitBojangles' Restaurants, Inc.
Bojangles notifies employees of data breach months after intrusion
HackingRestaurantsFinastra
Finastra investigates breach of internal file transfer platform
Credential CompromiseFinancial TechnologyInternational Game Technology
International Game Technology takes systems offline after cyberattack
HackingGambling TechnologyGovernment of Mexico (gob.mx)
RansomHub claimed 313 GB stolen from Mexican government legal office
RansomwareGovernmentT-Mobile US
T-Mobile named in Salt Typhoon espionage campaign against US telecoms
HackingTelecommunicationsDemandScience
DemandScience confirms leaked 122 million record database came from its systems
HackingBusiness ServicesHungarian Defence Procurement Agency (VBU)
Hungary confirmed INC Ransom hack of its defence procurement agency
RansomwareGovernmentAlberta Innovates
Alberta Innovates confirmed unauthorized access to its network
HackingGovernment AgencyAmerican Associated Pharmacies
Embargo ransomware group claimed attack on American Associated Pharmacies
RansomwarePharmacyTEAM Software
TEAM Software breach exposed personal data on 99,525 people
HackingSoftwareAmazon
Amazon employee contact data surfaced in MOVEit leak from a vendor
Third-Party Data BreachRetailBBS Financial Services, LLC
BBS Financial Services paid a ransom after breach affecting 70,168 people
RansomwareAccounting ServicesHot Topic
Hot Topic breach exposed records on nearly 57 million retail customers
Third-Party Data BreachRetailAhold Delhaize USA
Ahold Delhaize cyberattack disrupted US grocery pharmacies and online orders
HackingRetailNewpark Resources
Newpark Resources discloses ransomware attack in SEC filing
RansomwareEnergyStandard Bank
Standard Bank employee copied client data to an unprotected personal device
Malicious InsiderBankingNokia
Nokia denied breach after IntelBroker leaked contractor source code
Third-Party Data BreachTelecommunicationsSchneider Electric
Schneider Electric investigated Hellcat theft of 40GB from its Jira server
RansomwareEnergyBelle Tire Distributors
Belle Tire notifies nearly 30,000 people after June 2024 network intrusion
HackingAutomotive RetailHousing Authority of the City of Los Angeles (HACLA)
Los Angeles housing authority HACLA confirms second ransomware attack
RansomwareGovernmentSouth East Technological University
Cyberattack shut down IT systems at South East Technological University
HackingEducationVan Wagner Group
Van Wagner Group breach exposed Social Security numbers of 5,354 people
HackingAdvertising and MarketingMicrolise
Microlise cyberattack knocked out DHL and Serco vehicle tracking in the UK
RansomwareTechnologyInterbank
Interbank confirms customer data breach after dark web listing
HackingFinancial ServicesAustralian Nursing Home Foundation
Abyss ransomware claims 1.5TB from Australian Nursing Home Foundation
RansomwareHealthcareAEP GmbH
German pharmaceutical wholesaler AEP hit by ransomware attack
RansomwareHealthcareFree SAS
French ISP Free confirms breach of subscriber data
HackingTelecommunicationsBronxWorks Inc.
BronxWorks disclosed 2023 email breach exposing client and employee data
HackingNon-profitLandmark Admin, LLC
Landmark Admin breach exposed data of more than 800,000 insurance customers
RansomwareInsurance ServicesArkansas Blue Cross and Blue Shield
Vendor breach at Healthmine exposed Arkansas Blue Cross member data
Third-Party Data BreachHealth InsuranceJohnson & Johnson, Inc. (insurance firm)
Insurance firm Johnson & Johnson disclosed August 2024 breach affecting 3,200
HackingInsuranceBerufsbildungszentrum Schaffhausen (BBZ)
Ransomware attack blocked systems at Swiss vocational school BBZ Schaffhausen
RansomwareEducationKansas City Hospice & Palliative Care
BlackSuit ransomware listed Kansas City Hospice and Palliative Care
RansomwareHealthcareGlobe Life Inc.
Globe Life extorted over data stolen from American Income Life
HackingInsuranceNidec Corporation
Nidec confirms 50,694 files leaked from Vietnamese subsidiary
RansomwareManufacturingCisco Systems
Cisco traces IntelBroker data leak to public DevHub portal
MisconfigurationTechnologyFunlab
Funlab confirms Lynx ransomware attack on Australian entertainment group
RansomwareEntertainmentVarsity Brands
Varsity Brands breach exposed data of more than 65,000 people
HackingApparel ManufacturingAxis Health System
Axis Health System investigates Rhysida ransomware attack in Colorado
RansomwareHealthcareCalgary Public Library
Calgary Public Library closed all branches after cyberattack
HackingGovernmentCasio Computer Co., Ltd.
Casio confirms data theft after Underground ransomware attack
RansomwareConsumer ElectronicsIntesa Sanpaolo
Intesa Sanpaolo insider accessed 3,500 accounts including Italy's prime minister
Malicious InsiderBankingFidelity Investments
Fidelity Investments breach exposed personal data of 77,099 customers
HackingFinancial ServicesGame Freak
Game Freak confirms server breach behind Pokemon TeraLeak data dump
HackingVideo GamesPerfection Fresh
Perfection Fresh confirms breach after Sarcoma ransomware listing
RansomwareAgricultureThe Plastic Bag Company
Sarcoma ransomware group leaks data from Sydney's The Plastic Bag Company
RansomwareManufacturingInternet Archive
Internet Archive breach exposed 31 million user records
HackingNonprofitADT Inc.
ADT discloses second breach in two months after partner credentials stolen
Credential CompromiseHome SecurityAmerican Water Works Company, Inc.
American Water pauses billing after cyberattack on internal systems
HackingUtilitiesWayne County, Michigan
Cyberattack shut down Wayne County, Michigan websites and county offices
RansomwareGovernmentRed Barrels
Red Barrels breach delayed Outlast development after 1.8TB theft claim
RansomwareVideo GamesWard Transport & Logistics Corp.
Ward Transport and Logistics notified victims of March 2024 network breach
RansomwareTransportation and LogisticsAgence France-Presse
Agence France-Presse reported potential data breach after cyberattack
HackingMediaDutch National Police
Dutch national police breach exposes contact details of every officer
HackingGovernmentCasino Fandango
Casino Fandango disclosed June 2024 breach of its computer network
HackingHospitality and GamingCity of Arkansas City, Kansas
Arkansas City, Kansas water plant switches to manual after cyberattack
HackingGovernmentMoneyGram International
MoneyGram confirms cyberattack behind days-long global outage
HackingFinancial ServicesMC2 Data
MC2 Data left 2.2TB background check database exposed online
Human ErrorData BrokerageDell Technologies
Hacker claimed two Dell Technologies breaches within days in September 2024
HackingTechnologyTotal Tools
Total Tools data breach exposed about 38,000 customer accounts
HackingRetailCompass Group Australia
Compass Group Australia confirmed Medusa ransomware attack
RansomwareFood ServicesFireworks Software, Inc.
Fireworks Software breach exposed data tied to Rowan College at Burlington County
HackingSoftwareElitecare Emergency Hospital
Elitecare Emergency Hospital notifies 24,754 patients of data breach
HackingHealthcareDavid's Bridal
David's Bridal notified customers and staff of January 2024 data breach
HackingRetailKawasaki Motors Europe
Kawasaki Motors Europe restored servers after RansomHub attack
RansomwareAutomotiveFortinet
Fortinet confirmed customer data taken from third-party cloud file drive
Third-Party Data BreachTechnologyAccess Sports Medicine and Orthopaedics
Access Sports Medicine breach exposed data on about 88,000 patients
RansomwareHealthcareIndustrial and Commercial Bank of China (ICBC), London branch
Hunters International claimed 6.6TB theft from ICBC's London branch
RansomwareFinancial ServicesAramark
Aramark employees phished through fake myPay site in payroll diversion scheme
PhishingFood ServicesSlim CD, Inc.
Slim CD breach exposed card data for about 1.7 million people
HackingPayment ProcessingT. Rowe Price Retirement Plan Services
T. Rowe Price named in Infosys McCamish breach affecting 6 million people
Third-Party Data BreachFinancial ServicesAvis Rent A Car System
Avis breach of a business application exposed data on 299,006 customers
HackingTravel & TourismCharles Darwin School
Ransomware attack closed Charles Darwin School in Bromley for three days
RansomwareEducationKemperSports
KemperSports breach exposed Social Security numbers of over 62,000 people
HackingHospitalityNationwide Recovery Service
Nationwide Recovery Service reports breach of debt collection records
HackingDebt CollectionHighline Public Schools
Highline Public Schools closed for three days after a cyberattack
RansomwareEducationCenters for Medicare & Medicaid Services
CMS said a MOVEit hack at contractor WPS exposed 946,801 Medicare beneficiaries
Third-Party Data BreachHealthcareSt. Charles Parish Government
St. Charles Parish lost over $1.2 million to a vendor email compromise
Business Email CompromiseGovernmentPlanned Parenthood of Montana
RansomHub claimed a cyberattack on Planned Parenthood of Montana
RansomwareHealthcareTewkesbury Borough Council
Tewkesbury Borough Council shut down its systems after a suspected cyberattack
Human ErrorGovernmentTracelo
Tracelo phone tracking service breach exposed 1.4 million customers and targets
HackingLocation Tracking ServiceMt. Carmel Behavioral Healthcare
Mt. Carmel Behavioral Healthcare disclosed email breach exposing patient data
PhishingHealthcareJAS Worldwide
JAS Worldwide confirms ransomware attack behind freight operation disruptions
RansomwareLogisticsToronto District School Board
Toronto District School Board says student data stolen in June ransomware attack
RansomwareEducationDick's Sporting Goods
Dick's Sporting Goods discloses intrusion and locks employees out of email
HackingRetailFota Wildlife Park
Fota Wildlife Park told customers to cancel cards after a website breach
HackingTourism & AttractionsUSAA
USAA notified about 32,000 members after update error misdelivered documents
MisconfigurationInsuranceMeli
Qilin ransomware gang claims 215 GB theft from Australian charity Meli
RansomwareNonprofitYoung Consulting
Young Consulting breach exposed data on 954,177 people, including Blue Shield members
RansomwareSoftwarePort of Seattle (Seattle-Tacoma International Airport)
Rhysida ransomware attack disrupted Seattle-Tacoma International Airport systems
RansomwareAviationBloom Hearing Specialists
Bloom Hearing Specialists ransomware attack exposed patient and staff records
RansomwareHealthcareHalliburton Company
Halliburton took systems offline after August 2024 cyberattack
HackingEnergy ServicesCaja Los Andes
Unsecured database at Chile's Caja Los Andes exposed data on 10 million people
MisconfigurationFinancial ServicesMicrochip Technology Incorporated
Microchip Technology cut manufacturing output after August 2024 cyberattack
HackingSemiconductor ManufacturingOregon Zoo
Oregon Zoo warned 117,000 online ticket buyers of payment card theft
HackingZoos and AttractionsToyota
Toyota confirms customer data exposed after 240 GB leak blamed on third party
Third-Party Data BreachAutomotiveCannonDesign
CannonDesign notified 13,000 people of 2023 AvosLocker ransomware breach
RansomwareArchitecture and EngineeringVeriSource Services, Inc.
VeriSource Services disclosed February 2024 breach of employee benefits data
HackingEmployee Benefits AdministrationFlightAware
FlightAware configuration error exposed account data for over three years
MisconfigurationAviation TechnologySpecialty Networks, Inc.
Specialty Networks breach exposed data on more than 411,000 patients
HackingHealthcare TechnologyCity of Flint, Michigan
Ransomware attack knocked City of Flint payment and phone systems offline
RansomwareMunicipal GovernmentThe Washington Times
Rhysida ransomware group put Washington Times data up for auction
RansomwareMediaAutoCanada Inc.
AutoCanada disclosed cyberattack on its internal IT systems
HackingAutomotive RetailRodl Management, Inc.
Rodl Management breach exposed tax client data from Jamestown and JT Tax Services
HackingProfessional ServicesGrand Palais Reunion des musees nationaux
Ransomware attack hit Grand Palais and dozens of French museums during Paris Olympics
RansomwareMuseums and Cultural VenuesZB Financial Holdings
Mad Liberator leaked ZB Financial Holdings data after Zimbabwe group refused ransom
RansomwareFinancial ServicesSable International
BianLian emailed Sable International customers after immigration firm breach
HackingImmigration ServicesFresnillo plc
Fresnillo disclosed unauthorised access to IT systems and data
HackingMiningMcDowall Affleck
RansomHub claimed 470GB of data from engineering firm McDowall Affleck
RansomwareEngineeringJerico Pictures Inc. (National Public Data)
National Public Data faced suit over a claimed 2.9 billion record breach
HackingData BrokerageC-Edge Technologies
Ransomware at C-Edge Technologies knocked roughly 300 Indian banks offline
RansomwareFinancial ServicesOneBlood
Ransomware attack on OneBlood disrupted blood supply across the Southeast
RansomwareNonprofit Blood ServicesGemini
Gemini discloses breach at banking partner exposing customer account details
Third-Party Data BreachCryptocurrency ExchangeLite-On Technology Corporation
RansomEXX claimed a 142GB data theft from Taiwan's Lite-On Technology
RansomwareElectronics ManufacturingSquirrel
Squirrel breach exposed ID documents of up to 600 New Zealand investors
HackingFinancial ServicesLeidos Holdings
Leidos internal documents leaked online after third-party vendor breach
Third-Party Data BreachIT ServicesSplit Airport
Akira ransomware attack disrupts flights at Croatia's Split Airport
RansomwareAviationFirstNet (AT&T)
AT&T reversed course and said most FirstNet numbers were in the breached data
Third-Party Data BreachPublic Safety CommunicationsWattle Range Council
LockBit posts data stolen from South Australia's Wattle Range Council
RansomwareLocal GovernmentSuperior Court of Los Angeles County
Ransomware closed all 36 Los Angeles County Superior Court courthouses
RansomwareJudiciaryMichigan Medicine
Michigan Medicine notifies about 57,000 patients after email account breach
HackingHealthcareCity of Columbus, Ohio
Rhysida claimed 6.5TB of data from the City of Columbus ransomware attack
RansomwareMunicipal GovernmentPueblo County School District 70
Pueblo County School District 70 disclosed ransomware breach of student records
RansomwareEducationAtlassian (Trello)
Trello data on 15 million users leaked after an open API was scraped
HackingSoftwareRite Aid
Rite Aid says June cyberattack exposed data on 2.2 million people
RansomwareRetail PharmacyBassett Furniture Industries
Bassett Furniture halted manufacturing after ransomware encrypted data files
RansomwareFurniture ManufacturingThe Walt Disney Company
Disney investigates leak of 1.1 TB of internal Slack data
HackingEntertainmentAT&T
AT&T discloses theft of call and text records for nearly all wireless customers
Credential CompromiseTelecommunicationsGoshen Central School District
Goshen Central School District hit by ransomware attack
RansomwareEducationSibanye-Stillwater
Sibanye-Stillwater cyberattack hit the mining group's IT systems worldwide
HackingMiningAdvance Auto Parts
Advance Auto Parts notifies 2.3 million after Snowflake-linked breach
Credential CompromiseRetailThe Heritage Foundation
SiegedSec leaks Heritage Foundation data in protest over Project 2025
HackingThink TankRoblox
Roblox developer conference attendee data exposed in FNTech vendor breach
Third-Party Data BreachGamingFlorida Department of Health
Florida Department of Health data published after RansomHub attack
RansomwareGovernmentElite Fitness
Elite Fitness confirms DragonForce ransomware attack in New Zealand
RansomwareRetailAlabama State Department of Education
Alabama State Department of Education breached in a halted ransomware attack
HackingEducationFédération Internationale de l'Automobile (FIA)
FIA discloses data breach after phishing attacks on two email accounts
PhishingSports Governing BodyRoll20
Roll20 discloses breach of an administrative account exposing user records
HackingGamingHealthEquity, Inc.
HealthEquity breach traced to a compromised business partner account
Credential CompromiseHealth Benefits AdministrationPatelco Credit Union
Patelco Credit Union ransomware attack shuts down banking systems for weeks
RansomwareFinancial ServicesMass General Brigham
Mass General Brigham fired staff who let outsiders view patient records
Malicious InsiderHealthcareCambridge University Press & Assessment
Cambridge University Press & Assessment hit by INC Ransom attack
RansomwarePublishingFederated Co-operatives Limited
Federated Co-operatives cyberattack disrupted Co-op stores and fuel cardlocks
RansomwareRetail and WholesaleKadokawa Corporation
Kadokawa confirmed a ransomware attack on its data centre and Niconico
RansomwareMedia and EntertainmentUniversity Hospital Centre Zagreb (KBC Zagreb)
LockBit claims attack on Croatia's largest hospital, KBC Zagreb
RansomwareHealthcareTeamViewer
TeamViewer's corporate network was breached by APT29
Credential CompromiseSoftwareEvolve Bank & Trust
LockBit's claimed Federal Reserve hack was really Evolve Bank & Trust data
RansomwareBankingNeiman Marcus Group
Neiman Marcus confirmed a Snowflake-linked breach affecting 64,472 people
Credential CompromiseRetailGeisinger
Geisinger notified over a million patients after a vendor insider breach
Third-Party Data BreachHealthcarePusat Data Nasional (Indonesia National Data Center)
Indonesia's Pusat Data Nasional crippled by Brain Cipher ransomware
RansomwareGovernmentNational Health Laboratory Service (NHLS)
Ransomware halts test reporting at South Africa's National Health Laboratory Service
RansomwareHealthcareFinancial Business and Consumer Solutions
Debt collector FBCS breach grew from 1.9 million to more than 3 million people
HackingDebt CollectionJollibee Foods Corporation
Jollibee investigated a data breach affecting 11 million customers
HackingFood ServiceDisability Rights Wisconsin
Disability Rights Wisconsin email breach exposed 19,150 Medicaid members
HackingNonprofitAccenture
Accenture disputed a BreachForums claim of 32,000 leaked employee records
HackingProfessional ServicesCDK Global
CDK Global ransomware attack halted software at 15,000 car dealerships
RansomwareSoftwareVictoria Racing Club
Medusa ransomware gang demanded US$700,000 from Victoria Racing Club
RansomwareSports and RecreationNewberg-Dundee School District
Newberg-Dundee School District hit by ransomware in June 2024
RansomwareEducationTruist Bank
Truist Bank confirms October 2023 breach after employee data listed for sale
HackingBankingLife360 (Tile)
Life360 says hacker stole Tile customer data and tried to extort the company
Credential CompromiseConsumer TechnologyCity of Cleveland, Ohio
City of Cleveland confirms ransomware attack that closed City Hall for two weeks
RansomwareMunicipal GovernmentVietnam Post
Ransomware attack took Vietnam Post's delivery systems offline
RansomwarePostal ServicesHeineken
Heineken employee data offered for sale after 888 claimed a breach
HackingFood and BeverageSynnovis
Synnovis ransomware attack disrupts pathology services at London NHS hospitals
RansomwareHealthcareKing's College Hospital NHS Foundation Trust
Synnovis ransomware attack disrupted King's College Hospital and other London trusts
Third-Party Service DisruptionHealthcareVerny
Cyberattack forces Russian discount chain Verny to take cash only across 1,000 stores
HackingRetailChristian Democratic Union (CDU)
Germany's CDU took IT systems offline after a serious cyberattack
HackingPoliticsEasterseals Central Illinois
Rhysida ransomware gang demanded $1.3 million from Easterseals Central Illinois
RansomwareNon-profitGuardian Childcare
Guardian Childcare breach exposed scanned ID documents of Australian families
HackingChildcareLive Nation Entertainment (Ticketmaster)
Live Nation disclosed Ticketmaster data theft from a third-party cloud database
Third-Party Data BreachEntertainment and TicketingSnowflake
Snowflake says up to 165 customer accounts hit in credential theft campaign
Credential CompromiseCloud ComputingTicketek Australia
Ticketek Australia customer data exposed via third-party cloud platform
Third-Party Data BreachTicketingEverbridge
Everbridge told customers attackers reached corporate files after employee phishing
PhishingSoftwareBBC
BBC Pension Scheme breach exposed data on more than 25,000 members
HackingBroadcastingSmith & Caughey's
Smith & Caughey's crypto-locked by ransomware on the day it announced its closure
RansomwareRetailDecathlon
Decathlon confirmed Spanish employee email addresses leaked from third-party app
Third-Party Data BreachRetailSav-Rx (A&A Services)
Sav-Rx breach exposed data of 2.8 million prescription plan members
HackingPharmacy BenefitsThe Seattle Public Library
Ransomware attack knocked The Seattle Public Library's systems offline
RansomwarePublic LibraryCencora
Eleven drug companies disclose patient data loss from Cencora breach
HackingPharmaceutical ServicesAlbany County, New York
Albany County, New York investigates possible cybersecurity breach
HackingGovernmentTRC Staffing Services, Inc. (TRC Talent Solutions)
TRC Talent Solutions ransomware breach exposed 158,593 job seekers
RansomwareStaffingWelsh Rugby Union
Welsh Rugby Union investigated leak of supporters club member data
MisconfigurationSports Governing BodyMerrill Lynch, Pierce, Fenner & Smith Incorporated
Merrill email error exposed Social Security numbers of Walmart 401(k) savers
Human ErrorFinancial ServicesFirst Nations Health Authority
First Nations Health Authority reported a cyberattack on its corporate network
HackingHealthcareAmerican Radio Relay League (ARRL)
ARRL cyberattack takes Logbook of The World offline
RansomwareMembership AssociationGuam Seventh-Day Adventist Clinic
Guam Seventh-Day Adventist Clinic email breach exposed 56,635 people
HackingHealthcareMediSecure
MediSecure ransomware attack hits Australian e-prescription provider
RansomwareHealthcare TechnologyAffiliated Dermatologists & Dermatologic Surgeons, P.A.
Affiliated Dermatologists breach hit about 380,000 patients and staff
RansomwareHealthcareNissan North America
Nissan North America breach exposed Social Security numbers of 53,000 employees
RansomwareAutomotiveRockford Public Schools
Ransomware attack knocks out Rockford Public Schools network
RansomwareEducationBanco Santander
Santander says third-party database breach hit customers and staff
Third-Party Data BreachBankingKeytronic
Keytronic confirms data theft after Black Basta ransomware attack
RansomwareElectronics ManufacturingPalomar Health Medical Group
Palomar Health Medical Group cyberattack knocked outpatient systems offline for months
HackingHealthcareDocGo
DocGo discloses cyberattack that exposed patient health data
HackingHealthcareMedStar Health
MedStar Health email breach exposed data on about 183,000 patients
HackingHealthcareCity of Wichita, Kansas
Ransomware forces the City of Wichita to shut down its network
RansomwareMunicipal GovernmentMonash Health
Monash Health records exposed in ZircoDATA ransomware breach
Third-Party Data BreachHealthcareDropbox
Dropbox Sign production systems breached, user credentials exposed
HackingTechnologyFirstmac Limited
Firstmac confirms breach after EMBARGO ransomware attack
RansomwareFinancial ServicesJPMorgan Chase
Software flaw at J.P. Morgan exposed data on 451,000 retirement savers
MisconfigurationFinancial ServicesKaiser Foundation Health Plan (Kaiser Permanente)
Kaiser Permanente website trackers exposed data on 13.4 million members
MisconfigurationHealthcareLondon Drugs
London Drugs closed all 79 stores across Western Canada after a ransomware attack
RansomwareRetail PharmacyState Security Committee of the Republic of Belarus (KGB)
Cyber-Partisans claim breach of Belarus state security service
HackingGovernmentCoffee County, Georgia
Coffee County, Georgia cut its link to the state voter roll after a cyberattack
RansomwareLocal GovernmentLivaNova
LivaNova notified about 130,000 people after LockBit ransomware attack
RansomwareMedical DevicesSkanlog
Ransomware at Nordic distributor Skanlog empties Systembolaget shelves
RansomwareLogisticsCarpetright
Carpetright cyberattack halts UK store and online trading for a week
HackingRetailGrodno Azot
Cyber-Partisans encrypt systems at Belarusian fertilizer maker Grodno Azot
RansomwareChemical ManufacturingTipton Municipal Utilities
Russia-linked group claimed cyberattack on Tipton, Indiana wastewater plant
HackingWater UtilityThe MITRE Corporation
MITRE said nation-state hackers breached its NERVE network via Ivanti zero-days
HackingNonprofit ResearchPandemonium Rocks
Pandemonium Rocks refund form exposed ticketholders' bank details
MisconfigurationLive EventsDistrict of Columbia Department of Insurance, Securities and Banking (DISB)
LockBit claimed DC insurance regulator data taken via Tyler Technologies cloud
Third-Party Data BreachGovernmentFrontier Communications Parent, Inc.
Frontier Communications disclosed April 2024 breach of its IT environment
HackingTelecommunicationsSolano County Library
Ransomware took Solano County's SPLASH library network offline for weeks
RansomwarePublic LibrariesOctapharma Plasma
Ransomware shut Octapharma Plasma donation centers across 35 US states
RansomwareHealthcareCentre Hospitalier Simone Veil de Cannes (CHC-SV)
Cannes hospital CHC-SV reverted to paper after LockBit ransomware attack
RansomwareHealthcareUnited Nations Development Programme (UNDP)
UNDP confirmed data theft after ransomware attack on Copenhagen IT systems
RansomwareInternational DevelopmentThe Heritage Foundation
Heritage Foundation shut down its network after April 2024 cyberattack
HackingThink TankWells Fargo
Wells Fargo employee sent customer data to a personal account
Malicious InsiderBankingCity of Saint-Nazaire
Ransomware paralyzed Saint-Nazaire and four neighboring French communes
RansomwareMunicipal GovernmentSisense
CISA warned Sisense customers to reset credentials after vendor breach
HackingBusiness Analytics SoftwareCVS Group plc
CVS Group took systems offline after unauthorised access to UK IT servers
HackingVeterinary ServicesEBlock Corp.
EBlock notified nearly 2,000 people of breach of legacy ABS Auto Auctions systems
HackingAutomotive AuctionsU.S. Environmental Protection Agency (EPA)
EPA denies breach after hacker posts 8.5 million contact records
HackingGovernmentThe Home Depot
Home Depot confirmed a vendor exposed employee data leaked by IntelBroker
Third-Party Data BreachRetailNew Mexico Highlands University
New Mexico Highlands University canceled a week of classes after ransomware attack
RansomwareHigher EducationPanera Bread
Panera Bread ransomware attack caused week-long nationwide IT outage
RansomwareRestaurantsJackson County, Missouri
Jackson County, Missouri declared a state of emergency after ransomware attack
RansomwareLocal GovernmentOmni Hotels & Resorts
Daixin ransomware attack took Omni Hotels & Resorts systems offline for a week
RansomwareHospitalityIxMetro PowerHost
SEXi ransomware encrypted IxMetro PowerHost's ESXi servers and its backups
RansomwareHosting and Data CentersAT&T
AT&T confirmed data on 73 million current and former customers leaked online
HackingTelecommunicationsHot Topic, Inc.
Hot Topic notifies customers after November 2023 credential stuffing attacks
Credential CompromiseRetailActivision Blizzard
Activision warns players after infostealer malware harvested gaming logins
Credential CompromiseVideo GamesCarolina Foods Inc.
Black Basta claims ransomware attack on snack maker Carolina Foods
RansomwareFood ManufacturingThe Big Issue Group
Qilin ransomware gang leaked data stolen from The Big Issue Group
RansomwareMediaCommunications Workers Union (CWU)
UK Communications Workers Union confirms cyberattack on its IT systems
HackingTrade UnionGiant Tiger Stores Limited
Giant Tiger customer contact data exposed in third-party vendor breach
Third-Party Data BreachRetailAir Europa
Air Europa told customers passport and ID data was exposed in 2023 breach
HackingAirlineRadiant Logistics
Radiant Logistics isolated Canadian operations after March 2024 cyberattack
HackingLogisticsCrinetics Pharmaceuticals
LockBit claimed attack on Crinetics Pharmaceuticals and demanded $4 million
RansomwarePharmaceuticalsMediaWorks
MediaWorks said 403,000 New Zealanders' data was taken in competition hack
HackingMedia and BroadcastingOffice of the Colorado State Public Defender
Colorado public defender says ransomware attack exposed client data
RansomwareGovernmentFujitsu
Fujitsu confirms malware on work computers and possible data theft
HackingTechnologyInternational Monetary Fund (IMF)
IMF said 11 email accounts were compromised in a February 2024 breach
HackingInternational Financial InstitutionNHS Dumfries and Galloway
NHS Dumfries and Galloway hit by focused and ongoing cyberattack
RansomwareHealthcareScranton School District
Ransomware attack knocks out Scranton School District systems
RansomwareEducationNations Direct Mortgage
Nations Direct Mortgage notified 83,000 people of a December 2023 breach
HackingFinancial ServicesFrance Travail
France Travail breach exposes data on up to 43 million job seekers
Credential CompromiseGovernmentEquiLend
EquiLend tells employees data was stolen in January ransomware attack
RansomwareFinancial ServicesMarineMax
Rhysida claims ransomware attack on boat retailer MarineMax
RansomwareRetailCybersecurity and Infrastructure Security Agency (CISA)
CISA took two systems offline after Ivanti gateway flaws were exploited
HackingGovernmentRoku
Roku disclosed credential stuffing attack affecting 15,363 accounts
Credential CompromiseStreaming MediaJersey Financial Services Commission (JFSC)
Jersey Financial Services Commission registry flaw exposed 66,806 records
MisconfigurationFinancial RegulatorLeicester City Council
Leicester City Council shut down IT systems and phone lines after cyberattack
RansomwareMunicipal GovernmentDuvel Moortgat
Ransomware halted brewing at Duvel Moortgat's Belgian and US sites
RansomwareFood and BeverageSouth St. Paul Public Schools
South St. Paul Public Schools took systems offline after network intrusion
RansomwareEducationFinancial Transactions and Reports Analysis Centre of Canada (FINTRAC)
FINTRAC took corporate systems offline after a March 2024 cyber incident
HackingGovernmentAmerican Express
American Express warns cardholders of breach at third-party merchant processor
Third-Party Data BreachFinancial ServicesScottish Ambulance Service
Scottish Ambulance Service apologizes after first responder spreadsheet emailed in error
Human ErrorEmergency ServicesChunghwa Telecom
Chunghwa Telecom breach put 1.7TB of Taiwanese government data on the dark web
HackingTelecommunicationsFidelity Investments Life Insurance Company
Fidelity Investments Life Insurance notified 28,000 after Infosys McCamish breach
Third-Party Data BreachInsuranceYX International
YX International left SMS database of one-time passcodes exposed online
MisconfigurationTelecommunicationsCutout.Pro
Cutout.Pro records for about 20 million accounts leaked on hacking forum
HackingTechnologyU-Haul International, Inc.
U-Haul notified 67,000 customers after reservation system breach
Credential CompromiseVehicle RentalCity of Hamilton, Ontario
Ransomware disabled most of the City of Hamilton's network for weeks
RansomwareMunicipal GovernmentQuik Pawn Shop
Akira ransomware group claimed an attack on Alabama's Quik Pawn Shop
RansomwareConsumer LendingRoyal Canadian Mounted Police (RCMP)
Royal Canadian Mounted Police opened criminal probe into network cyberattack
HackingLaw EnforcementDas Team AG (dasteam ag)
Black Basta leaked 200GB stolen from Swiss staffing firm Das Team AG
RansomwareStaffing and RecruitmentChange Healthcare
Cyberattack on Change Healthcare disrupted US pharmacies and claims processing
RansomwareHealthcare TechnologyMalawi Department of Immigration and Citizenship Services
Malawi halts passport printing after immigration system hack and ransom demand
HackingGovernmentTangerine Telecom
Tangerine Telecom breach exposed data on 232,000 Australian customers
Credential CompromiseTelecommunicationsRobert Half International
IntelBroker and Sanggiero claimed a data breach at staffing firm Robert Half
HackingStaffing and RecruitmentStratford-on-Avon District Council
Stratford-on-Avon council insider took 79,000 resident email addresses
Malicious InsiderLocal GovernmentGolden Corral Corporation
Golden Corral breach exposed data on more than 183,000 employees
HackingRestaurantsINTEGRIS Health
INTEGRIS Health said a 2023 breach exposed data on 2.4 million patients
HackingHealthcarePSI Software SE
Ransomware attack forced German control systems vendor PSI Software offline
RansomwareIndustrial SoftwareWashington County, Pennsylvania
Washington County, Pennsylvania paid a $350,000 ransom after January cyberattack
RansomwareLocal GovernmentBank of America
Bank of America notified 57,028 customers after Infosys McCamish breach
Third-Party Data BreachFinancial ServicesTrans-Northern Pipelines
ALPHV claimed a data theft at Canada's Trans-Northern Pipelines
HackingEnergyVarta AG
Cyberattack halted production at German battery maker Varta AG
HackingManufacturingPrudential Financial
Prudential Financial disclosed breach of employee and contractor data
RansomwareFinancial ServicesSlobozia County Emergency Hospital
Slobozia hospital among Romanian hospitals hit by Hipocrate ransomware attack
RansomwareHealthcareHyundai Motor Europe
Black Basta claimed three terabytes of data from Hyundai Motor Europe
RansomwareAutomotiveWinStar World Casino and Resort
WinStar app customer data exposed by unsecured Dexiga database
MisconfigurationCasinos and GamingService Employees International Union (SEIU) Local 1000
LockBit ransomware attack disrupted SEIU Local 1000 in California
RansomwareLabor UnionMunicipality of Korneuburg, Austria
Ransomware attack on Austria's Korneuburg municipality postponed funerals
RansomwareMunicipal GovernmentMedical Management Resource Group, LLC (American Vision Partners)
Medical Management Resource Group breach hit 2.35 million eye care patients
HackingHealthcare ServicesAnyDesk
AnyDesk confirms attackers breached its production systems
HackingSoftwareFootball Australia
Football Australia exposed player passports and contracts through leaked AWS keys
Human ErrorSports Governing BodyCity of Jacksonville Beach, Florida
Jacksonville Beach said ransomware attack exposed data on about 49,000 people
RansomwareMunicipal GovernmentAnn & Robert H. Lurie Children's Hospital of Chicago
Ransomware attack took Lurie Children's Hospital systems offline for weeks
RansomwareHealthcareGlobal Affairs Canada
Global Affairs Canada breach exposed employee data through a compromised VPN
HackingGovernmentKeenan & Associates
Keenan & Associates breach exposed data of more than 1.5 million people
HackingInsuranceSchneider Electric
Cactus ransomware hit Schneider Electric's Sustainability Business division
RansomwareEnergy ManagementFulton County, Georgia
Cyberattack knocked out Fulton County, Georgia government systems
RansomwareLocal GovernmentFreehold Township School District
Freehold Township School District closes schools after cybersecurity incident
HackingEducationCaravan and Motorhome Club
Caravan and Motorhome Club outage in UK traced to a cyberattack
RansomwareMembership OrganizationHewlett Packard Enterprise
Russian group APT29 read Hewlett Packard Enterprise email for seven months
HackingTechnologyCity of Frederick, Maryland
City of Frederick lost $280,527 to a phishing driven wire fraud scheme
Business Email CompromiseMunicipal GovernmentDENHAM the Jeanmaker
DENHAM the Jeanmaker confirms cyberattack linked to Akira ransomware
RansomwareFashion RetailJason's Deli
Jason's Deli customer accounts breached in credential stuffing attack
Credential CompromiseRestaurantsSouthern Water
Black Basta claims ransomware attack on UK utility Southern Water
RansomwareWater UtilitiesBucks County, Pennsylvania
Bucks County, Pennsylvania loses emergency dispatch system in ransomware attack
RansomwareLocal GovernmentMicrobe & Lab (CoronaLab)
Dutch COVID testing lab CoronaLab exposed 1.3 million records in open database
MisconfigurationMedical LaboratoryGALA Hispanic Theatre
GALA Hispanic Theatre recovers $255,000 drained in bank fraud
Business Email CompromiseArts and CultureTrezor
Trezor support portal breach exposes contact data of 66,000 users
Third-Party Data BreachCryptocurrencyMicrosoft
Microsoft says Midnight Blizzard read senior leaders' corporate email
Credential CompromiseTechnologyVeolia North America
Veolia North America discloses ransomware attack on Municipal Water division
RansomwareWater UtilitiesTilbury District Family Health Team
Tilbury District Family Health Team patient data taken in TransForm ransomware attack
Third-Party Data BreachHealthcareFoxsemicon Integrated Technology
LockBit defaces Foxsemicon website and claims 5TB of stolen data
RansomwareSemiconductor ManufacturingKansas State University
Kansas State University cyberattack knocks out VPN, email and campus services
HackingHigher EducationHal Leonard Australia
Qilin leaks 37.6 GB of data from music publisher Hal Leonard Australia
RansomwareMusic PublishingWater for People
Medusa gang listed nonprofit Water for People with a $300,000 demand
RansomwareNonprofitClearview Resources Ltd.
Clearview Resources loses C$1.5 million to email account takeover
Business Email CompromiseEnergyLush
Lush confirms cyber incident later described as a ransomware attack
RansomwareRetailInspiring Vacations
Inspiring Vacations left 112,000 travel records in an open cloud bucket
MisconfigurationTravelHMG Healthcare
HMG Healthcare breach hit residents and staff at 40 nursing facilities
HackingHealthcareToronto Zoo
Toronto Zoo discloses ransomware incident, employee records taken
RansomwareZooCooper Aerobics
Cooper Aerobics notifies patients almost a year after network intrusion
HackingHealthcareMidwives of Windsor
Midwives of Windsor tells clients an email account was breached in April 2023
Credential CompromiseHealthcareHousing Authority of the County of San Bernardino
San Bernardino County housing authority breach exposed 18,689 people
HackingLocal GovernmentOrrick, Herrington & Sutcliffe
Orrick law firm breach exposed data on more than 637,000 people
HackingLegal ServicesGallery Systems
Gallery Systems ransomware attack took museum collection databases offline
RansomwareSoftwareHealthEC LLC
HealthEC breach exposed records of about 4.5 million patients
HackingHealthcare TechnologyCourt Services Victoria
Court Services Victoria breach exposed years of court hearing recordings
RansomwareGovernmentCommunaute de communes du Pays Fouesnantais
Cyberattack shut down IT services across France's Pays Fouesnantais
RansomwareLocal GovernmentMemorial University of Newfoundland
Memorial University delays Grenfell Campus classes after ransomware attack
RansomwareHigher EducationOrbit Chain
Orbit Chain lost about $81 million in New Year's Eve bridge exploit
HackingCryptocurrencyFallon Ambulance Service
Defunct Fallon Ambulance Service breach exposed data on 911,757 people
RansomwareEmergency Medical ServicesKatholische Hospitalvereinigung Ostwestfalen
LockBit ransomware hit three German hospitals run by KHO on Christmas Eve
RansomwareHealthcareNational Amusements
National Amusements disclosed a December 2022 breach affecting 82,128 people
HackingMedia and EntertainmentMint Mobile
Mint Mobile told customers a hacker obtained their account data
HackingTelecommunicationsAteam Inc.
Ateam Google Drive misconfiguration exposed data on 935,779 people
MisconfigurationTechnologyComcast Xfinity
Comcast Xfinity breach exposed data of 35.8 million customers via Citrix Bleed
HackingTelecommunicationsInsomniac Games
Rhysida leaks 1.67TB of Insomniac Games data after Sony studio refuses ransom
RansomwareVideo GamesVF Corporation
VF Corporation reported a ransomware attack in one of the first SEC cyber filings
RansomwareApparel and FootwearFred Hutchinson Cancer Center
Fred Hutchinson Cancer Center ransomware attack led to extortion of patients
RansomwareHealthcareAsper Biogene
Asper Biogene breach exposed genetic and health data of 10,000 in Estonia
HackingGenetic TestingDelta Dental of California
Delta Dental of California MOVEit breach affected nearly 7 million people
HackingDental InsuranceLedger
Ledger Connect Kit compromised after phishing attack on a former employee
PhishingCryptocurrency HardwareLondon Public Library
London Public Library in Ontario shut down services after a cyberattack
HackingPublic LibraryKyivstar
Kyivstar cyberattack knocked out mobile service for millions in Ukraine
HackingTelecommunicationsGreater Richmond Transit Company (GRTC)
Greater Richmond Transit Company hit by Play ransomware over Thanksgiving
RansomwarePublic TransportationCity of Huber Heights, Ohio
Huber Heights, Ohio spends months rebuilding after BlackSuit ransomware attack
RansomwareMunicipal GovernmentNorton Healthcare
Norton Healthcare ransomware breach exposed data on 2.5 million people
RansomwareHealthcareBinghamstown/Drum Group Water Scheme
Hacktivists cut water to Irish group scheme over Israeli-made pump controller
HackingWater UtilityAustal USA
Austal USA confirms data incident after Hunters International leak claim
HackingShipbuildingHTC Global Services
HTC Global Services confirms cyberattack after ALPHV leaks stolen files
RansomwareIT ServicesNissan Oceania
Nissan warns Australian and New Zealand customers after Akira ransomware breach
RansomwareAutomotiveStaples
Staples took systems offline after a Cyber Monday intrusion
HackingOffice Supply RetailWeMystic
WeMystic left 13.3 million user records exposed in an open database
MisconfigurationConsumer Web ServicesJapan Aerospace Exploration Agency (JAXA)
JAXA confirms intruders reached its internal network
HackingGovernmentNational Aerospace Laboratories
LockBit claims ransomware attack on India's National Aerospace Laboratories
RansomwareAerospace ResearchYanfeng Automotive Interiors
Qilin ransomware group claims attack on auto supplier Yanfeng
RansomwareAutomotive ManufacturingZeroedIn Technologies
ZeroedIn Technologies breach exposed data of about 2 million Dollar Tree workers
HackingHuman Resources TechnologyArdent Health Services
Ardent Health Services ransomware attack diverted ambulances at US hospitals
RansomwareHealthcareMunicipal Water Authority of Aliquippa
Cyber Av3ngers hijacked a controller at Aliquippa's water authority
HackingWater UtilityIndian Hotels Company Limited (Taj Hotels)
Taj Hotels investigates claimed leak of data on 1.5 million guests
HackingHospitalityFidelity National Financial (FNF)
Fidelity National Financial shut down systems after ALPHV ransomware attack
RansomwareTitle InsuranceBrookfield Global Relocation Services (BGRS)
BGRS and SIRVA Canada breach exposed decades of federal relocation files
RansomwareRelocation ServicesIdaho National Laboratory
Idaho National Laboratory confirmed HR system breach claimed by SiegedSec
HackingNuclear ResearchService public de l'assainissement francilien (SIAAP)
Paris-area wastewater agency SIAAP hit by cyberattack
HackingWater UtilityBlue Shield of California
Blue Shield of California members hit by MOVEit breach at vision benefits vendor
Third-Party Data BreachHealth InsuranceToyota Financial Services
Medusa ransomware hit Toyota Financial Services in Europe and Africa
RansomwareAutomotive FinanceCity of Long Beach, California
Long Beach declared a local emergency after a November 2023 network breach
HackingMunicipal GovernmentMeridianLink
MeridianLink confirmed a cyberattack after ALPHV reported it to the SEC
RansomwareFinancial SoftwareSamsung Electronics
Samsung UK store breach exposed contact details of 2019 and 2020 shoppers
HackingConsumer ElectronicsStanley Steemer
Stanley Steemer breach exposed data on about 67,000 customers
HackingConsumer ServicesDP World Australia
DP World Australia halts four container ports after network intrusion
HackingPorts and LogisticsWashington State Department of Transportation
Cyberattack disrupts Washington State Department of Transportation services
HackingGovernmentHenry County Schools
Henry County Schools network shut down by BlackSuit ransomware attack
RansomwareEducationIndustrial and Commercial Bank of China (ICBC)
ICBC's US broker-dealer hit by LockBit ransomware, disrupting Treasury trades
RansomwareFinancial ServicesState of Maine
State of Maine says MOVEit breach exposed data on 1.3 million people
HackingGovernmentElectric Ireland
Electric Ireland says contractor staff member accessed 8,000 customers' data
Malicious InsiderEnergyMarina Bay Sands
Marina Bay Sands breach exposed data on 665,000 loyalty members
HackingHospitalityCook County Health
Cook County Health notifies 1.2 million patients of breach at vendor PJ&A
Third-Party Data BreachHealthcareShimano
LockBit claims 4.5TB of data stolen from bicycle component maker Shimano
RansomwareManufacturingSutter Health
Sutter Health says MOVEit breach at vendor Welltok exposed 845,000 patients
Third-Party Data BreachHealthcareBoeing
Boeing confirms cyberattack on its parts and distribution business
RansomwareAerospaceQueretaro Intercontinental Airport
Queretaro Intercontinental Airport confirms cyberattack claimed by LockBit
RansomwareAviationThe British Library
Rhysida ransomware attack kept British Library services offline for weeks
RansomwareLibraries and ArchivesMr. Cooper Group
Mr. Cooper shuts down systems after cyberattack, blocking mortgage payments
HackingFinancial ServicesAllied Pilots Association
Ransomware hits Allied Pilots Association, the American Airlines pilots union
RansomwareLabor UnionSudwestfalen IT
Ransomware at Sudwestfalen IT disrupts more than 70 German municipalities
RansomwareIT ServicesTruepill (Postmeds Inc.)
Truepill breach exposed prescription records of about 2.3 million patients
HackingPharmacyAce Hardware
Ace Hardware cyberattack downs 1,202 devices and halts online orders
HackingRetailToronto Public Library
Toronto Public Library cyberattack takes down digital services at 100 branches
RansomwarePublic LibrariesStanford University
Akira claimed 430 GB from Stanford's public safety department
RansomwareHigher EducationClark County School District (CCSD)
Hackers emailed stolen student records to Clark County School District parents
HackingEducationAmerican Family Insurance
American Family Insurance confirmed a cyberattack behind week-long outages
HackingInsuranceSeiko Group Corporation
Seiko says ransomware attack exposed about 60,000 items of personal data
RansomwareManufacturingWelltok
Welltok MOVEit breach exposed data on 8.5 million US patients
HackingHealthcare SoftwareGrupo GTD
Rorschach ransomware disrupts Chilean telecom operator Grupo GTD
RansomwareTelecommunicationsOrange County District Attorney's Office
Orange County District Attorney shut down IT systems after a cyberattack
HackingGovernmentTransForm Shared Service Organization
Ransomware at TransForm knocked out systems at six Ontario health facilities
RansomwareHealthcare ITWestchester Medical Center Health Network (WMCHealth)
WMCHealth diverted ambulances after a cyberattack on Hudson Valley hospitals
HackingHealthcareKwik Trip
Kwik Trip confirmed a cyberattack caused its two-week systems outage
HackingRetailD-Link
D-Link confirmed a phishing attack exposed old registration records
PhishingNetworking HardwareAmpersand
Ampersand confirmed ransomware attack claimed by Black Basta
RansomwareAdvertisingArietis Health, LLC
Arietis Health reported a MOVEit breach affecting nearly 2 million patients
HackingHealthcare BillingHenry Schein
Henry Schein confirms a cybersecurity incident as ALPHV claims the attack
RansomwareHealthcareMorrison Community Hospital
BlackCat claimed 5TB data theft from Morrison Community Hospital
RansomwareHealthcareQuality Service Installation (QSI), Inc.
ALPHV claimed 5TB of data from ATM installer Quality Service Installation
RansomwareBanking TechnologyCDW
LockBit demanded $80 million from CDW after breaching Sirius Federal servers
RansomwareTechnology ServicesPerry Johnson & Associates (PJ&A)
PJ&A transcription breach exposed data of nearly 9 million patients
HackingMedical TranscriptionLDLC ASVEL Villeurbanne
LDLC ASVEL confirmed data theft after NoEscape ransomware listing
RansomwareSportsShadow
Shadow said hacker stole customer data after employee lured on Discord
Credential CompromiseCloud GamingSimpson Manufacturing
Simpson Manufacturing took systems offline after October 2023 cyberattack
HackingManufacturingVolex plc
Volex said attackers accessed IT systems and data at international sites
HackingElectronics ManufacturingDistrict of Columbia Board of Elections (DCBOE)
DC Board of Elections says voter roll was stolen from its hosting provider
Third-Party Data BreachGovernmentFlagstar Bank
Flagstar Bank told 837,000 customers their data was taken in Fiserv MOVEit breach
Third-Party Data BreachFinancial ServicesLyca Mobile
Lyca Mobile confirmed customer data theft after cyberattack
HackingTelecommunications23andMe
23andMe user profiles scraped after credential stuffing attack
Credential CompromiseConsumer GeneticsThe Royal Women's Hospital
Royal Women's Hospital notified 192 patients after staff email account hacked
Credential CompromiseHealthcareSony Interactive Entertainment
Sony Interactive Entertainment notified about 6,800 people of MOVEit breach
HackingVideo GamesEstes Express Lines
Estes Express Lines confirms cyberattack behind multi-day IT outage
RansomwareTransportation and LogisticsFirst Judicial Circuit Court of Florida
ALPHV claimed ransomware attack on Florida's First Judicial Circuit Court
RansomwareGovernmentMotel One
Motel One confirms data theft after ALPHV/BlackCat ransomware attack
RansomwareHospitalityBuilders Mutual Insurance Company
Builders Mutual Insurance notified 64,761 people of a 2022 network intrusion
HackingInsuranceMcLaren Health Care
McLaren Health Care confirms ransomware attack claimed by ALPHV/BlackCat
RansomwareHealthcareWorld Baseball Softball Confederation (WBSC)
World Baseball Softball Confederation exposed 4,600 passport scans in open AWS bucket
MisconfigurationSports Governing BodyEuropean Telecommunications Standards Institute (ETSI)
ETSI says attackers stole its online user database
HackingStandards BodyFlair Airlines
Flair Airlines left database and email credentials exposed on its website
MisconfigurationAirlineBORN Ontario (Better Outcomes Registry & Network)
BORN Ontario says MOVEit breach exposed health data on 3.4 million people
HackingHealthcareAuckland University of Technology
Auckland University of Technology hit by cyberattack claimed by Monti ransomware
RansomwareHigher EducationPizza Hut Australia
Pizza Hut Australia told 193,000 customers their data was accessed
HackingRestaurantsProgressive Leasing
Progressive Leasing discloses cyberattack that exposed Social Security numbers
RansomwareConsumer LeasingAir Canada
Air Canada says internal system breached, limited employee data accessed
HackingAirlineInternational Criminal Court
International Criminal Court detected intrusion into its information systems
HackingJudiciaryLakeland Community College
Lakeland Community College notified 285,948 people of a data breach
RansomwareHigher EducationCity of Pittsburg, Kansas
Cyberattack knocked out email, phones and payments in Pittsburg, Kansas
HackingLocal GovernmentVirginia Department of Medical Assistance Services
Virginia Medicaid agency reports breach affecting 1.2 million people
HackingGovernmentAuckland Transport
Auckland Transport ticketing systems disrupted by ransomware attack
RansomwarePublic TransportCaesars Entertainment
Caesars Entertainment disclosed loyalty database theft and paid a ransom
RansomwareHospitality and GamingGreater Manchester Police
Greater Manchester Police officer data exposed in supplier ransomware attack
Third-Party Data BreachLaw EnforcementORBCOMM
ORBCOMM ransomware attack knocked out trucking fleet management and ELDs
RansomwareTransportation TechnologyShell (BG Group Australia)
Shell says BG Group Australia employee data taken in MOVEit breach
HackingOil and GasAirbus
Airbus supplier data leaked after credentials stolen from airline employee
Credential CompromiseAerospaceCanadian Nurses Association
Canadian Nurses Association confirmed data theft after Snatch leaked 37GB
RansomwareProfessional AssociationMGM Resorts International
MGM Resorts shut down IT systems across its casinos after a cyberattack
RansomwareHospitality and GamingDymocks
Dymocks blamed an external data partner for a breach of 836,000 customers
Third-Party Data BreachRetailInternational Joint Commission
NoEscape claimed an 80GB theft from the US-Canada International Joint Commission
RansomwareGovernmentJohnson & Johnson
IBM breach exposed Johnson & Johnson's Janssen CarePath patient data
Third-Party Data BreachPharmaceuticalsSabre Corporation
Dunghill Leak claimed a 1.3TB data theft from travel technology firm Sabre
RansomwareTravel TechnologyNXP Semiconductors
NXP Semiconductors told portal account holders their contact data was exposed
HackingSemiconductorsFreecycle
Freecycle disclosed a breach affecting more than 7 million members
HackingNonprofitTissuPath
TissuPath patient records leaked after breach at a third-party IT supplier
Third-Party Data BreachHealthcareZaun
LockBit attack on UK fencing maker Zaun exposed military site documents
RansomwareManufacturingMom's Meals (PurFoods, LLC)
Mom's Meals discloses ransomware breach affecting more than 1.2 million people
RansomwareHealthcare ServicesMetropolitan Police Service
Metropolitan Police supplier breach exposed details of 47,000 officers and staff
Third-Party Data BreachLaw EnforcementOhio History Connection
Ohio History Connection ransomware attack exposed data on about 7,600 people
RansomwareNonprofitPareto Phone
Pareto Phone breach leaked Australian charity donor data to the dark web
RansomwareTelemarketingPôle emploi
Pole emploi says MOVEit breach at a contractor exposed data on 10 million people
Third-Party Data BreachGovernmentCloudNordic
CloudNordic and AzeroCloud lost nearly all customer data in ransomware attack
RansomwareCloud HostingGEICO
GEICO tells employees their data was exposed in MOVEit-linked vendor breach
Third-Party Data BreachInsuranceUniversity of Minnesota
University of Minnesota investigates claim that 7 million records were stolen
HackingHigher EducationauDA (.au Domain Administration)
auDA finds no evidence of breach after NoEscape claimed to hold its data
RansomwareInternet InfrastructureEnergy One
Energy One takes systems offline after cyberattack on Australian and UK operations
HackingEnergy SoftwareTesla, Inc.
Tesla blamed insider wrongdoing for breach affecting 75,000 employees
Malicious InsiderAutomotiveSwan Retail
Swan Retail cyberattack knocks around 300 UK independent retailers offline
HackingRetail SoftwareThe Clorox Company
Clorox took systems offline after unauthorized activity on its network
HackingConsumer Goods ManufacturingPrince George's County Public Schools
Cyberattack on Prince George's County Public Schools hit 4,500 accounts
HackingEducationColorado Department of Health Care Policy and Financing
Colorado health agency notified 4.1 million people after IBM MOVEit breach
Third-Party Data BreachGovernment Health AgencyCumbria Constabulary
Cumbria police accidentally published names and salaries of all staff
Human ErrorLaw EnforcementFreeport-McMoRan Inc.
Freeport-McMoRan disclosed a cybersecurity incident affecting its IT systems
HackingMiningIndiana Family and Social Services Administration
Indiana FSSA said Maximus MOVEit breach exposed 744,000 Medicaid members
Third-Party Data BreachGovernment Health AgencyAlberta Dental Service Corporation
Ransomware at Alberta Dental Service Corporation hit 1.47 million people
RansomwareHealth Benefits AdministrationRapattoni Corporation
Rapattoni cyberattack froze MLS property listings across the US
HackingReal Estate TechnologyPolice Service of Northern Ireland
PSNI accidentally published details of about 10,000 officers and staff
Human ErrorLaw EnforcementThe Electoral Commission (United Kingdom)
UK Electoral Commission revealed hack exposing 40 million voters' details
HackingGovernment AgencyColorado Department of Higher Education
Colorado Department of Higher Education breach exposed 16 years of records
RansomwareState GovernmentAristocrat Leisure Limited
Aristocrat Leisure confirmed employee data stolen through MOVEit flaw
HackingGaming TechnologyProspect Medical Holdings
Prospect Medical Holdings cyberattack shut hospital services in four states
RansomwareHealthcareOregon Health Plan
MOVEit breach at PH Tech exposed 1.7 million Oregon Health Plan members
Third-Party Data BreachHealth InsuranceHealth Employers Association of British Columbia
Cyberattack on B.C. health recruitment sites exposed up to 240,000 records
HackingHealthcareHot Topic
Hot Topic disclosed credential stuffing attacks on Rewards accounts
Credential CompromiseRetailThe Prudential Insurance Company of America
Prudential said MOVEit hack at vendor PBI exposed 320,840 people
Third-Party Data BreachInsuranceTempur Sealy International
Tempur Sealy shut down IT systems after July 2023 cyberattack
HackingManufacturingSouthern Association of Independent Schools (SAIS)
Unsecured SAIS database exposed 682,000 school records
MisconfigurationEducationAllegheny County, Pennsylvania
Allegheny County MOVEit breach exposed data on more than 950,000 people
HackingLocal GovernmentMaximus Inc.
Maximus says MOVEit hack exposed data on up to 11 million people
HackingGovernment ServicesNational Disability Insurance Agency
Australia's disability agency assessed exposure from the HWL Ebsworth hack
Third-Party Data BreachGovernment AgencyCardioComm Solutions
CardioComm Solutions took systems offline after cyberattack
HackingMedical TechnologyPacific Premier Bancorp
Pacific Premier Bancorp customer data stolen in vendor's MOVEit breach
Third-Party Data BreachFinancial ServicesRite Aid
Rite Aid says vendor software flaw exposed data on 24,400 customers
HackingRetail Pharmacy1st Source Corporation
1st Source Bank reports about 450,000 records exposed in MOVEit hack
HackingFinancial ServicesYamaha Canada Music
Yamaha Canada Music confirmed attack claimed by two ransomware gangs
RansomwareMusical InstrumentsGeorge County, Mississippi
Ransomware encrypts all three servers at George County, Mississippi
RansomwareLocal GovernmentTSG Interactive US Services Limited (PokerStars)
PokerStars US notifies 110,291 people of MOVEit related data theft
HackingOnline GamingTampa General Hospital
Tampa General Hospital says data on 1.2 million patients was stolen
RansomwareHealthcareThe Estee Lauder Companies
Estee Lauder confirmed data theft as Clop and BlackCat both claimed attacks
HackingConsumer GoodsCharter Oak Federal Credit Union
Charter Oak Federal Credit Union pulls online banking offline after attack
HackingFinancial ServicesTOMRA Systems ASA
TOMRA isolates systems after extensive cyberattack on Norwegian group
HackingIndustrial TechnologyHillsborough County, Florida
Hillsborough County notified more than 70,000 people after MOVEit breach
HackingLocal GovernmentSun Life Financial
Sun Life US members exposed in MOVEit breach at vendor PBI
Third-Party Data BreachInsuranceChoice Hotels International
Choice Hotels confirmed Radisson guest records taken in MOVEit attacks
Third-Party Data BreachHospitalityHCA Healthcare
HCA Healthcare breach exposed data on about 11 million patients
HackingHealthcareRazer
Razer investigated claims that Razer Gold data and source code were stolen
HackingConsumer ElectronicsVentia
Ventia took key systems offline after weekend cyberattack
HackingInfrastructure ServicesAutoZone
AutoZone notified 184,995 people of a MOVEit-related data breach
HackingAutomotive Parts RetailDeutsche Bank
Deutsche Bank customer data exposed in service provider's MOVEit breach
Third-Party Data BreachBankingUniversity of the West of Scotland
University of the West of Scotland data auctioned by Rhysida ransomware gang
RansomwareHigher EducationNational Institutes of Health Federal Credit Union (NIHFCU)
NIH Federal Credit Union notified 14,706 members after an email account breach
Credential CompromiseFinancial ServicesPort of Nagoya
Ransomware halted container operations at Japan's Port of Nagoya
RansomwarePorts and LogisticsZooTampa at Lowry Park
ZooTampa disclosed cyberattack claimed by BlackSuit ransomware group
RansomwareLeisure and Attractionsdaa (Dublin Airport Authority)
About 2,000 Dublin Airport staff had pay data taken in the Aon MOVEit breach
Third-Party Data BreachAviationBarts Health NHS Trust
BlackCat claimed a seven terabyte data theft from Barts Health NHS Trust
RansomwareHealthcareImagine360, LLC
Imagine360 notifies over 112,000 after two file transfer breaches
Third-Party Data BreachHealthcareAdvanced Medical Management, LLC
Advanced Medical Management breach exposed data on 319,485 people
HackingHealthcareDozor-Teleport CJSC
Russian satellite operator Dozor-Teleport knocked offline in June 2023 hack
HackingTelecommunicationsU.S. Department of Health and Human Services (HHS)
HHS told Congress a MOVEit breach at contractors affected more than 100,000 people
Third-Party Data BreachFederal GovernmentTaiwan Semiconductor Manufacturing Company (TSMC)
TSMC faced a $70 million LockBit ransom after supplier Kinmax was breached
Third-Party Data BreachSemiconductor ManufacturingU.S. Patent and Trademark Office (USPTO)
USPTO exposed about 61,000 trademark applicants' home addresses for three years
MisconfigurationFederal GovernmentLaw Foundation of Silicon Valley
Ransomware at the Law Foundation of Silicon Valley exposed data on 42,525 people
RansomwareLegal ServicesSuncor Energy
Suncor Energy cyberattack disrupted payments at Petro-Canada stations
HackingOil and GasPilot Credentials
Pilot Credentials breach exposed data on American and Southwest pilot applicants
HackingRecruitment TechnologyCalifornia Public Employees' Retirement System (CalPERS)
CalPERS said 769,000 retirees were exposed by a vendor's MOVEit breach
Third-Party Data BreachPublic Pension FundGen Digital
Gen Digital said employee data was exposed in the MOVEit breach
HackingConsumer SoftwareBlackCat threatened to leak 80GB of Reddit data taken in a February breach
PhishingSocial MediaSmartpay Holdings
Smartpay confirmed customer data was stolen in a ransomware attack
RansomwarePaymentsU.S. Department of Agriculture
USDA said fewer than 30 employees may have been hit by a vendor's MOVEit breach
Third-Party Data BreachFederal GovernmentLouisiana Office of Motor Vehicles
Louisiana warned all driver's license and ID holders were exposed in MOVEit breach
HackingState GovernmentDevelopment Bank of Southern Africa
Development Bank of Southern Africa disclosed an Akira ransomware attack
RansomwareBankingFIIG Securities
ALPHV claimed theft of 385GB from Australian bond broker FIIG Securities
RansomwareFinancial ServicesIntellihartx
Intellihartx told about 490,000 people data was taken in GoAnywhere hack
Third-Party Data BreachHealthcare ServicesComisión Nacional de Valores (CNV), Argentina
Medusa ransomware group attacked Argentina's National Securities Commission
RansomwareFinancial RegulatorOfcom
Ofcom said MOVEit hack took data on 412 staff and companies it regulates
HackingGovernment RegulatorJamaica Ministry of National Security
Jamaica's Ministry of National Security confirmed cyberattack on JamaicaEye website
HackingGovernmentInfotel JSC
Ukrainian hacktivists took Russian bank connectivity provider Infotel JSC offline
HackingTelecommunicationsMahony Horner Lawyers
Mahony Horner Lawyers warned clients of leak after IT provider was hacked
Third-Party Data BreachLegal ServicesUK National Health Service (NHS)
NHS research data on 1.1 million patients accessed in University of Manchester hack
Third-Party Data BreachHealthcareGovernment of Nova Scotia
Nova Scotia government detailed scope of MOVEit data theft affecting about 100,000
HackingRegional GovernmentPflegia
German healthcare recruiter Pflegia exposed job seeker files in open AWS bucket
MisconfigurationRecruitmentAscension Seton
Ascension Seton disclosed breach of two legacy websites run by vendor Vertex
Third-Party Data BreachHealthcareZellis
MOVEit zero-day at payroll provider Zellis exposed staff data at BA, BBC and Boots
Third-Party Data BreachPayroll ServicesHillsborough County Supervisor of Elections
Hillsborough County elections office breach exposed data on 58,000 Florida voters
HackingLocal GovernmentiSpace, Inc.
iSpace notified consumers of a breach exposing Social Security and health data
HackingBusiness ServicesCasepoint
BlackCat claimed a breach of legal platform Casepoint used by US agencies
RansomwareLegal TechnologyIdaho Falls Community Hospital
Cyberattack forced Idaho Falls Community Hospital to divert ambulances
HackingHealthcareSimpleTire
SimpleTire left 2.8 million customer records in an open database
MisconfigurationRetailEjercito de Chile (Chilean Army)
Rhysida ransomware group published documents stolen from the Chilean Army
RansomwareMilitaryMCNA Dental
MCNA Dental breach affected 8.9 million people after LockBit attack
RansomwareHealth InsuranceOnix Group
Onix Group ransomware attack exposed data on about 320,000 patients and employees
RansomwareReal Estate and Healthcare ServicesInsurance Information Bureau of India
Insurance Information Bureau of India hit by ransomware, refused $250,000 demand
RansomwareInsuranceXplain
Play ransomware attack on Swiss supplier Xplain reached federal government data
RansomwareIT ServicesApria Healthcare
Apria Healthcare disclosed 2019 and 2021 breaches affecting 1.87 million people
HackingHealthcareCity of Augusta, Georgia
BlackByte ransomware gang claimed attack on the City of Augusta, Georgia
RansomwareMunicipal GovernmentSuzuki Motorcycle India
Cyberattack halted production at Suzuki Motorcycle India for about a week
HackingManufacturingBank Syariah Indonesia
LockBit published 1.5TB of data stolen from Bank Syariah Indonesia
RansomwareBankingCollectivité Territoriale de Martinique
Rhysida claimed the ransomware attack on Martinique's territorial government
RansomwareRegional GovernmentFresh Del Monte Produce
Fresh Del Monte Produce notified employees after network intrusion
HackingAgricultureScanSource
ScanSource confirmed ransomware attack behind multi-day outages
RansomwareTechnology DistributionUintah Basin Healthcare
Uintah Basin Healthcare breach affected 103,974 patients in rural Utah
HackingHealthcareairBaltic
airBaltic sent booking details to the wrong passengers after email system error
Human ErrorAviationCredit Control Corporation
Credit Control Corporation disclosed March 2023 breach affecting hundreds of thousands
HackingDebt CollectionLacroix
Lacroix shut three electronics plants for a week after ransomware attack
RansomwareElectronics ManufacturingAmbulance Victoria
Ambulance Victoria exposed paramedic drug and alcohol test results on staff intranet
Human ErrorEmergency ServicesIllinois Department of Healthcare and Family Services
Illinois benefits portal breach exposed Medicaid, SNAP and TANF recipient data
Credential CompromiseGovernmentToyota Motor Corporation
Toyota cloud misconfiguration exposed vehicle data for 2.15 million customers
MisconfigurationAutomotiveU.S. Department of Transportation
US Department of Transportation breach exposed data on 237,000 federal employees
HackingGovernmentABB
Black Basta ransomware hits Swiss automation giant ABB
RansomwareIndustrial TechnologyMurfreesboro Medical Clinic & SurgiCenter
Murfreesboro Medical Clinic shut down for two weeks after a ransomware attack
RansomwareHealthcareTechnologyOne
TechnologyOne halts ASX trading after back-office systems breached
HackingSoftwareNational Gallery of Canada
National Gallery of Canada recovers from ransomware attack
RansomwareArts and CultureNextGen Healthcare
NextGen Healthcare breach exposed data on more than one million patients
Credential CompromiseHealth ITConstellation Software
ALPHV claims ransomware attack on Constellation Software
RansomwareSoftwareCrown Princess Mary Cancer Centre
Medusa ransomware group claims data from Sydney's Crown Princess Mary Cancer Centre
RansomwareHealthcareLa Malle Postale
La Malle Postale left data on about 90,000 hiking clients publicly exposed
MisconfigurationTransportationCity of Dallas, Texas
Royal ransomware disrupted City of Dallas police, court and dispatch systems
RansomwareMunicipal GovernmentAvidXchange
AvidXchange hit by RansomHouse in its second ransomware incident of 2023
RansomwareFinancial TechnologySysco Corporation
Sysco discloses breach affecting customer, supplier and employee data
HackingFood DistributionHWL Ebsworth
ALPHV ransomware group claims 4TB of data from Australian law firm HWL Ebsworth
RansomwareLegal ServicesAmericold Realty Trust
Americold network breach shut down cold storage operations
RansomwareCold Storage and LogisticsAmnesty International Australia
Amnesty International Australia disclosed a December 2022 hack four months later
HackingNon-ProfitDiocese of Las Vegas
Diocese of Las Vegas disclosed a data breach affecting parishioners and donors
HackingReligious OrganizationNational Small-bore Rifle Association
Cyber attack on the UK National Small-bore Rifle Association exposes member data
HackingSports and RecreationUnitedHealthcare
UnitedHealthcare notified members after credential stuffing attack on its mobile app
Credential CompromiseHealth InsuranceHardenhuish School
Hardenhuish School in Wiltshire disrupted by a ransomware attack
RansomwareEducationBitmarck
Bitmarck took systems offline across German health insurers after a cyberattack
HackingHealthcare ITEdisonLearning
Royal ransomware gang claimed 20GB of data stolen from EdisonLearning
RansomwareEducation ServicesCIC Group, Inc.
CIC Group notified 4,500 people after a breach exposed Social Security numbers
HackingEngineering and ConstructionYellow Pages Group
Yellow Pages Canada confirmed Black Basta attack after data leak
RansomwareDigital Media and DirectoriesAmerican Bar Association
American Bar Association breach exposed credentials of 1.4 million members
HackingProfessional AssociationFincantieri Marine Group
Ransomware attack halted work at Fincantieri Marine Group's Wisconsin shipyard
RansomwareShipbuildingConsumer Financial Protection Bureau
Former CFPB employee sent data on 256,000 consumers to a personal email
Malicious InsiderGovernment AgencyPoint32Health
Point32Health ransomware attack disrupted Harvard Pilgrim member services
RansomwareHealth InsuranceCommScope
Vice Society leaked CommScope employee data after March ransomware attack
RansomwareNetwork Infrastructure ManufacturingEvide
Ransomware at Derry data firm Evide hit charities serving abuse survivors
RansomwareInformation Technology ServicesGateway Casinos & Entertainment
Gateway Casinos ransomware attack closed 14 Ontario properties
RansomwareGaming and HospitalityColes Group
Coles customer credit card data caught up in Latitude Financial breach
Third-Party Data BreachRetailDimas Volvo
Brazilian Volvo dealer Dimas Volvo leaked database credentials for a year
MisconfigurationAutomotive RetailNCR Corporation
BlackCat ransomware knocked out NCR's Aloha point-of-sale platform
RansomwarePayment TechnologyNorthOne
Unsecured database exposed over a million NorthOne-branded invoices
MisconfigurationFinancial TechnologyRheinmetall
Rheinmetall cyberattack hit civilian division, defence business unaffected
RansomwareDefence and Automotive ManufacturingEnzo Biochem
Enzo Biochem said ransomware attack exposed test data on 2.47 million people
RansomwareBiotechnologyKodi
Kodi disclosed forum breach affecting about 400,000 users
Credential CompromiseSoftwareLürssen
Lürssen hit by ransomware attack over the Easter weekend
RansomwareShipbuildingSD Worx
SD Worx shut down UK and Ireland payroll systems after cyberattack
HackingPayroll and HR ServicesWebster Bank
Webster Bank customer data exposed in Guardian Analytics vendor breach
Third-Party Data BreachBankingGroupe Nordik
Groupe Nordik breach exposed gift certificate buyers' card data
HackingHospitalityMicro-Star International (MSI)
Money Message ransomware gang claimed 1.5TB theft from MSI
RansomwareComputer HardwarePacific Union College
Pacific Union College discloses ransomware breach affecting 56,041 people
RansomwareHigher EducationACRO Criminal Records Office
UK's ACRO Criminal Records Office pulled portal offline after cyber incident
HackingGovernmentCamden County Police Department
Camden County Police Department locked out of case files by ransomware
RansomwareLaw EnforcementMunicipality of Herselt
Cyberattack shut municipal services in Herselt, Belgium
Supply Chain AttackLocal GovernmentOCR Labs
OCR Labs exposed credentials tied to banking clients in misconfigured file
MisconfigurationIdentity VerificationProskauer Rose
Proskauer Rose left confidential client M&A files exposed on an unsecured cloud server
MisconfigurationLegal ServicesRoyal Dutch Football Association (KNVB)
Royal Dutch Football Association says hackers stole employee data
RansomwareSportsCapita plc
Capita cyberattack disrupted Microsoft 365 access and exposed client data
RansomwareBusiness ServicesWestern Digital
Western Digital network breach takes My Cloud services offline
HackingComputer HardwareTMX Finance
TMX Finance discloses breach affecting 4.8 million TitleMax and InstaLoan customers
HackingConsumer LendingMeriton
Meriton breach exposes staff financial records and guest incident reports
HackingHospitality and PropertyPharMerica
PharMerica breach exposed data of 5.8 million patients
RansomwareHealthcareCrown Resorts
Crown Resorts confirms Clop extortion attempt after GoAnywhere zero-day
HackingCasinos and EntertainmentLumen Technologies
Lumen Technologies discloses two separate cyberattacks in SEC filing
RansomwareTelecommunicationsTwitter source code leaked on GitHub, company subpoenas for leaker's identity
Malicious InsiderSocial MediaNCB Management Services
NCB Management breach grows past 1.5 million, starting with Bank of America customers
HackingDebt CollectionCity of Toronto
City of Toronto confirms data theft through GoAnywhere file transfer vendor
Third-Party Data BreachMunicipal GovernmentWalsall Healthcare NHS Trust
Walsall Healthcare NHS Trust contains cyberattack on its network
HackingHealthcareAlliance Healthcare Espana
Cyberattack on Alliance Healthcare Espana disrupts Spanish medicine distribution
HackingPharmaceutical DistributionCity of Oak Ridge, Tennessee
Malware attack disrupts services in the City of Oak Ridge, Tennessee
HackingMunicipal GovernmentUS Wellness Inc.
US Wellness vendor breach exposed Blue Cross Blue Shield of Arizona members
Third-Party Data BreachHealthcare ServicesQIMR Berghofer Medical Research Institute
QIMR Berghofer skin cancer study data exposed in Datatime breach
Third-Party Data BreachMedical ResearchPuerto Rico Aqueduct and Sewer Authority (PRASA)
Vice Society claims cyberattack on Puerto Rico water utility PRASA
RansomwareWater UtilityDocomo Pacific
Docomo Pacific cyberattack knocks out internet and phone services in Guam and the CNMI
HackingTelecommunicationsHitachi Energy
Hitachi Energy confirms employee data breach in Clop GoAnywhere campaign
Third-Party Data BreachEnergy TechnologyNational Basketball Association
NBA notifies fans after breach at third-party email provider
Third-Party Data BreachSportsLatitude Financial
Latitude Financial says stolen staff login led to theft of 328,000 records
Credential CompromiseFinancial ServicesGSC Game World
GSC Game World breached, hackers threaten to leak STALKER 2 material
HackingVideo Game DevelopmentLansing Community College
Lansing Community College breach exposed data on 757,832 people
HackingHigher EducationEssendant
LockBit claims ransomware attack behind Essendant's multi-week outage
RansomwareWholesale DistributionNorthStar Emergency Medical Services
NorthStar EMS notifies about 82,000 patients of 2022 network intrusion
HackingEmergency Medical ServicesCHU Saint-Pierre
Cyberattack diverts ambulances from Brussels hospital CHU Saint-Pierre
HackingHealthcarePostal Prescription Service (Healthy Options Inc., Kroger)
Kroger's Postal Prescription Service exposed 82,466 customers' details
Human ErrorPharmacyAT&T
AT&T notifies about 9 million customers after marketing vendor breach
Third-Party Data BreachTelecommunicationsBlack & McDonald
Ransomware hits Black & McDonald, contractor to Canada's military
RansomwareEngineering and ConstructionDC Health Link
DC Health Link breach exposes data on 56,000 people including members of Congress
MisconfigurationHealth InsuranceAcer
Acer confirms breach of repair technician document server
HackingTechnology ManufacturingSundaySky Inc.
SundaySky notifies 37,095 people after files copied from its cloud servers
HackingMarketing TechnologyCerebral
Cerebral tells 3.1 million people tracking pixels leaked their health data
Human ErrorTelehealthRoyal Dirkzwager
Play ransomware group hits Dutch maritime firm Royal Dirkzwager
RansomwareMaritime LogisticsHospital Clínic de Barcelona
RansomHouse attack forces Hospital Clínic de Barcelona to cancel surgeries
RansomwareHealthcareDenver Public Schools
Denver Public Schools breach exposed employee Social Security numbers
HackingEducationChick-fil-A
Chick-fil-A confirmed 71,473 accounts hit by credential stuffing
Credential CompromiseRestaurantsWH Smith PLC
WH Smith said attackers stole current and former employee data
HackingRetailGroup 1001 Insurance Holdings
Group 1001 insurance units restored operations after February ransomware attack
RansomwareInsuranceMinneapolis Public Schools
Medusa ransomware gang leaked Minneapolis Public Schools student records
RansomwareEducationDISH Network Corporation
DISH Network confirms ransomware attack behind multi-day outage
RansomwareTelecommunicationsSoutheastern Louisiana University
Southeastern Louisiana University took its network offline after cyberattack
HackingHigher EducationU.S. Marshals Service
U.S. Marshals Service ransomware attack hit a sensitive investigative system
RansomwareFederal GovernmentCornell University
Cornell ticket buyers hit by AudienceView Campus platform breach
Third-Party Data BreachHigher EducationReventics, LLC
Reventics breach exposed data on more than 250,000 patients
RansomwareHealthcare ServicesThe Good Guys
The Good Guys told 1.85 million loyalty members of a supplier breach
Third-Party Data BreachRetailDole plc
Dole shut down North American operations after ransomware attack
RansomwareAgribusinessU.S. Department of Defense
U.S. Department of Defense notified 20,600 people of 2023 email exposure
MisconfigurationFederal GovernmentLehigh Valley Health Network
Lehigh Valley Health Network refused ransom after BlackCat attack on physician practice
RansomwareHealthcareTusla, Ireland's Child and Family Agency
Tusla began notifying 20,000 people whose data was stolen in the 2021 HSE attack
Third-Party Data BreachGovernmentU.S. Federal Bureau of Investigation
FBI confirmed a cyber incident on its own network at the New York field office
HackingFederal GovernmentStanford University
Stanford University exposed files of 897 economics PhD applicants
MisconfigurationHigher EducationCity of Hilliard, Ohio
City of Hilliard, Ohio lost $219,000 to a vendor impersonation scam
Business Email CompromiseMunicipal GovernmentRailYatri
RailYatri data on more than 31 million users posted to a hacking forum
HackingTravel TechnologyBurton Snowboards
Burton Snowboards halted online orders after a February 2023 cyber incident
HackingSporting GoodsLiverpool University Hospitals NHS Foundation Trust
Liverpool University Hospitals NHS trust leaked payroll data of 14,000 staff
Human ErrorHealthcareCity of Oakland, California
Oakland declared a local emergency after ransomware took city systems offline
RansomwareLocal GovernmentPepsi Bottling Ventures LLC
Pepsi Bottling Ventures breach hit more than 28,000 employees and contractors
HackingFood and BeverageAguas e Energia do Porto
LockBit claimed a ransomware attack on Porto's municipal water utility
RansomwareUtilitiesIndigo Books & Music Inc.
Indigo Books & Music shut down its website after a cyberattack
RansomwareRetailWeee!
Weee! confirmed a breach after order data for 1.1 million customers leaked
HackingRetailMKS Instruments, Inc.
Ransomware at MKS Instruments halted production at some facilities
RansomwareManufacturingMunster Technological University
Munster Technological University closed Cork campuses after ransomware attack
RansomwareHigher EducationVesuvius plc
Vesuvius plc shut down systems after cyber incident at steel industry supplier
RansomwareManufacturingPeopleConnect, the parent company of TruthFinder and Instant Checkmate
TruthFinder and Instant Checkmate Suffer Data Breach: 20 Million Customers Affected
HackingBackground Checking Services988 Suicide and Crisis Lifeline
Cyberattack on vendor Intrado knocked out 988 Lifeline calls for nearly a day
Third-Party Service DisruptionPublic HealthSharp HealthCare
Sharp HealthCare notified about 63,000 patients after a web server breach
HackingHealthcareAtlantic General Hospital (Maryland)
Maryland’s Atlantic General Hospital hit by Ransomware: Patient Care Impacted
RansomwareHealthcareION Group
LockBit ransomware attack on ION Group disrupted global derivatives trading
RansomwareFinancial SoftwarePlanet Ice
Planet Ice breach exposed data on more than 240,000 UK skating customers
HackingLeisure and EntertainmentJD Sports Fashion plc
JD Sports data breach hit around 10 million UK customers
HackingRetailCharter Communications
Telecom Giant Charter Communications Discloses Vendor Security Breach: Customer Data Exposed
Third-Party Data BreachTelecommunicationsExco Technologies
Cyber Attack Cripples Exco Technologies: Three Production Facilities Still Recovering
HackingManufacturer of diecast auto parts and toolsRunning Room
Running Room Canada Data Breach - Customer Data Compromised
HackingSporting goods retailZacks Investment Research
Zacks Investment Research Confirms Data Breach Affecting 280,000 Customers
HackingInvestment Research and AnalysisSolar Industries India Limited
BlackCat claimed a 2TB theft from Indian defence manufacturer Solar Industries
RansomwareDefence ManufacturingGoTo (formerly LogMeIn)
GoTo (formerly LogMeIn) Suffers Data Breach
Credential CompromiseEnterprise softwareFive Guys Enterprises, LLC
Five Guys Data Breach: Job Applicant Information Compromised
RansomwareFood ServiceSAIF Corporation
SAIF Data Breach: Oregon's Leading Workers' Compensation Provider Experiences Security Incident
HackingOregon Workers' Compensation Insurance and BenefitsCott Systems
400 Local Governments Forced to Resort to Manual Processes as a Result of Cott Systems Cyber Attack
HackingGovernment Records ManagementToronto Hospital for Sick Children (SickKids Hospital)
Toronto’s SickKids Hospital Confirms Ransomware Attack
RansomwareHealthcareGale Healthcare Solutions
30K Healthcare Workers’ Info Found On Unprotected Database
MisconfigurationHealthcare, Staffing ServicesButler County Community College
Classes Cancelled As School Recovers From Ransomware Attack
RansomwareEducationDesjardins
Desjardins Class Action Lawsuit Over 2019 Breach Settles For $200M
Malicious InsiderFinancial ServicesDNA Diagnostics Center (DDC)
DNA Testing Centre Admits To Data Breach Affecting Over 2 Million People
Credential CompromiseHealthcare ServicesLake County Board of Commissioners
FBI Investigating Attempted Data Breach During Election Fraud
Malicious InsiderGovernment, Local ServicesAtalanta
Food Importer Admits Data Breach After Previous Ransomware Attack
RansomwareFood & Beverage, Distributor/ImporterCox Communications
Fraudster Impersonates Support Agent In Cox Vishing Attack
PhishingMedia, Digital Cable ProviderMonoX
Hackers Victimize MonoX Leaving Losses Up To $30M in Digital Tokens
HackingFintech, CryptocurrencySupernus Pharmaceuticals
Ransomware Gang Threatens to Leak 1.5TB of Data
RansomwarePharmaceuticalSuperior Plus
Superior Plus Discloses Ransomware Attack Over The Weekend
RansomwareDistribution, PropaneThe Virginia Division of Legislative Automated Systems (DLAS)
Virginia’s Government IT Agency Hit By Ransomware
RansomwareGovernment, Technology ServicesGovernor General of Canada
Governor General of Canada Detects Internal Network Breach
HackingFederal GovernmentSocial Enterprise for Canada (SEC)
Ontario Non-Profit Warning Clients After Ransomware Attack
RansomwareNon-Profit, Family ServicesKronos, Ultimate Group
Ransomware Attack Could Affect Customer Payroll Services For Weeks
RansomwareTechnology, Payroll ServicesPlanned Parenthood
400,000 Patients’ Information Compromised In Ransomware Attack
RansomwareHealthcare, Non-ProfitGoDaddy
Over 1 Million Users Affected In GoDaddy Data Breach
Credential CompromiseTechnology, Web HostingCoinMarketCap
3.1 Million Users’ Email Addresses Leaked In Data Breach
HackingTechnology, FinancialRobinhood
7 Million Users Affected In Robinhood Data Breach
PhishingFintechRonmor Holdings
Calgary Real Estate Developer Hit By Ransomware Attack
RansomwareReal EstateFerrara Candy Company
Candy Maker Hit By Ransomware During Halloween Rush
RansomwareFood and Beverage, ManufacturerWest Virginia Parkways Authority
Cyberattack on Government Agency Disrupts Computer Systems
RansomwareGovernment Agency, TransportationNewfoundland and Labrador Health
Experts Deem N.L. Cyberattack as Canada’s Worst Ever
RansomwareGovernment, HealthcareFederal Bureau of Investigation (FBI)
FBI Email System Compromised In Cyberattack
Business Email CompromiseFederal Government, AgencyIKEA
IKEA Hit By Ongoing, Highly Sophisticated Reply-Chain Attack
PhishingRetailDiamond Comic Distributors
Major Comic Book Distributor Hit By Ransomware
RansomwareDistributor, Publications & EntertainmentCalifornia Pizza Kitchen
Over 100,000 Employees Affected By California Pizza Kitchen Data Breach
HackingFood & Beverage, RestaurantPracticeMax
Patient Data Exposed In 3rd Party Healthcare Ransomware Attack
RansomwareHealthcare Services, TechnologySinclair Broadcast Group
Ransomware Knocks Programs Offline for Nationwide Broadcast Group
RansomwareMediaRideau Valley Health Centre
Ransomware Attack On Ottawa Clinic Disrupts Patient Care
RansomwareHealthcare, Medical ClinicSchreiber Foods
Ransomware Shuts Down Production Distribution For Schreiber Foods
RansomwareAgriculture, ManufacturerHewlett Packard Enterprise (HPE)
Stolen Access Key Used to Breach HPE’s Aruba Central
Credential CompromiseTechnology, ManufacturingNational Rifle Association (NRA)
Threat Actors Demand Ransom from NRA After Leaking Files On Dark Web
RansomwareAdvocacy GroupToronto Transit Commission (TTC)
Toronto Transit System Hit By Ransomware Attack
RansomwareGovernment Agency, TransportationElectronic Warfare Associates
US Defense Contractor Reveals Employee Phishing Attack
PhishingGovernment, Defense ContractorTurner Construction Co.
5,600 Construction Employees Potentially Impacted By Phishing Scam
PhishingConstructionDefence Construction Canada
Defence Construction Canada Recovering After Cyber Attack On IT Systems
HackingConstruction, Federal GovernmentClark Builders
Edmonton Construction Company Warns Industry After $11.8M Phishing Scam
PhishingConstructionProfessional Excavators and Construction
Over $100k In Ransomware Recovery Costs for Calgary Construction
RansomwareConstructionUniversity of Colorado
30,000 University Students Potentially Impacted By 3rd Party Data Breach
HackingEducationKemptville District Hospital
Ontario Hospital Resumes Emergency Services After ‘Cyber Incident’
HackingHealthcare, MedicalOlympus Corporation of the Americas
Global Medical Manufacturer’s IT Systems Down After 2nd Consecutive Ransomware Attack
RansomwareManufacturer, Medical TechnologyDurham Regional Government
Hackers Leak More Troubling Data for Local Ontario Government
Third-Party Data BreachGovernment, MunicipalSandhills Global
Systems And Operations Shut Down For Digital Publisher After Ransomware
RansomwareTechnology, Digital PublishingTwitch
Twitch Suffers Massive Source Code Data Breach
MisconfigurationTechnology, Streaming PlatformPremier Patient Healthcare
Terminated Executive Turns Insider Threat After 37,000 Patients’ Data Compromised
Malicious InsiderHealthcareOregon Eye Specialists
Independent Optometry Chain Hit By Employee Email Breach
Credential CompromiseHealthcare, OptometryUnity Health Toronto
Toronto Hospital Network Investigating After Malicious Insider Threatens Data Exposure
Third-Party Data BreachHealthcareNext Level Apparel
Several Employee Email Accounts Compromised in Phishing Attack
PhishingManufacturer, ClothingCoinbase
Hackers Steal Cryptocurrency from 6,000 Coinbase Users
HackingTechnology, Financial AppNeiman Marcus
4.9 Million Affected by Retail Giant Neiman Marcus Data Breach
HackingRetailNavistar
Employees Seek Class Action Lawsuit After Info Stolen In Data Breach
HackingManufacturing, AutomobileMoneyLion
Fintech Customer Accounts Locked After Credential Stuffing Attack
Credential CompromiseFinancial, FintechMarcus & Millichap
Ransomware Group Targets Commercial Real Estate Firm
RansomwareReal EstateMarketron
Thousands of Customers Impacted By Marketron Ransomware Attack
RansomwareTechnology, Marketing ServicesPortpass
Privacy Breach Could Affect 650K Canadians Using COVID-19 Passport App
MisconfigurationTechnology, Vaccine Passport PlatformEpik
Hacktivist Group Anonymous Leaks 180GB of Far-Right Data
HackingTechnology, Web HostingNew Cooperative And Crystal Valley Cooperative
Twin Ransomware Attacks Halt Business For Agriculture Industry
RansomwareManufacturing, AgricultureSimon Eye And US Vision
Hackers Victimize Healthcare Providers in Dual Hacking Breaches
HackingHealthcare, OptometryDotty’s
F&B Customer’s Data Exposed In Ransomware Attack
RansomwareFood and Beverage, GamingTTEC
TTEC Ransomware Attack Encrypts Data Disrupting Business Operations
RansomwareTechnology, Customer Service ProviderWalgreen’s
Millions Possible Affected By Walgreen’s Website Error
MisconfigurationRetail, PharmacyUnited Nations
Hackers Infiltrate United Nations IT Networks
HackingIntergovernmental OrganizationTexas Right To Life
Hundreds of Job Applicants’ Data Exposed on Misconfigured Website
MisconfigurationPolitical Rights OrganizationPacific City Bank
Ransomware Attack Hits Community Bank
RansomwareFinancialCareer Group Inc.
Company Warns 49,000 Customers After Ransom Paid In Cyber Attack
RansomwareStaffing AgencyDuPage Medical Group
600,000 Patients Warned After Medical Group Discovers Data Breach
HackingHealthcare, MedicalAustin Cancer Centers
Cyber Attack Exposes Over 36,000 Cancer Clinic Patients’ Data
RansomwareHealthcareCanpar Express
No Explanation on Ransomware Attack Leaves Customers Complaining
RansomwareLogisticsCanada Revenue Agency
Thousands Affected By CRA Data Breach
Credential CompromiseGovernmentMajor Bitcoin Scam Rocks Twitter
HackingSocial MediaMGM Resorts
Over 142 Million Affected in MGM Resorts Data Breach
Credential CompromiseTravel, HotelPEI Provincial Government
$900,000 In Costs For PEI Taxpayers After Ransomware Attack (Update)
RansomwareGovernmentOneClass
Over 1 Million Students’ Personal Info Exposed on Unsecured Database
MisconfigurationEducationChartered Professional Accountants of Canada (CPA)
329,000 Affected By CPA Canada Phishing Attack
PhishingFinancialNorthwest Territories Power Corporation (NTPC)
NTPC Customers Facing “Financial Hardships” After Ransomware Attack
RansomwareServices, Utilities ProviderGoDaddy
Approximately 28,000 GoDaddy Users Affected by Data Breach
HackingTechnology, Web HostingWorld Health Organization
450 Active WHO Email Credentials Leaked Online
Credential CompromiseNot-For-Profit, HealthcareThe Ottawa Hospital
Ottawa Police Warning New COVID-19 Hospital Phishing Scam
PhishingHealthcareQuebec Treasury Board
360,000 Quebec Teachers Affected By Data Breach
Credential CompromiseEducationPEI Government
PEI Government Investigating Ransomware Attack
RansomwareGovernmentSimon Fraser University
SFU Ransomware Attack Compromises Personal Info for Students, Faculty & Alumni
RansomwareEducationSouthern First Nations Network of Care
Non-Profit IT Systems Paralyzed for 6 Weeks In Ransomware Attack
RansomwareNon-ProfitPublic Service and Procurement Canada
Canadian Government's Internal Data Breach: 69,000 Federal Workers' Information Compromised
Human ErrorGovernmentConfederation College
Malware Disables Canadian College’s IT Systems
HackingEducationCanadian Government, Federal Departments
144,000 Canadians’ Personal Info Mishandled by Federal Departments
Human ErrorGovernmentRogers Communication
Rogers Communications Notified of Minor Data Leak
MisconfigurationTechnology, TelecommunicationsBird Construction
Ransomware Hits Canadian Federal Contractor Bird Construction
RansomwareConstructionCity of Corner Brook
City’s Privacy Breach Handed Over to Provincial Privacy Commissioner
MisconfigurationGovernment, MunicipalityeHealth
eHealth Sask Sees Downtime Costs Escalate After Ransomware Attack
RansomwareMedical ServicesPlanetDrugsDirect
Hackers Access Personal Health Info From Online Pharmacy
HackingOnline Retail, HealthcareCIBC, Scotiabank, RBC, TD Canada Trust
2 Year Phishing Campaign Targeting Major Canadian Banks Uncovered
PhishingFinancial ServicesPlenty of Fish
Plenty of Fish Private User Info Accidental Data Leaked
MisconfigurationTechnology, Dating Services AppAndrew Agencies
Financial Company Sees 245 Computers Encrypted with Ransomware
RansomwareFinancial ServicesCraftsman Collision
$100s of Thousands in Ransomware Remediation For Craftsman Collision
RansomwareService, Automobile RepairLife Labs
15 Million Canadians Potentially Affected By Life Labs’ Massive Data Breach
RansomwareMedical ServicesShaw
Shaw Warns Customers of Potential Data Leak 6 Months Later
Lost or Stolen DeviceTechnology & CommunicationsCity of Woodstock
Local Canadian Govt Accrues $667,000 in Costs After Ransomware
RansomwareLocal GovernmentAlectra Utilities
Utilities Company Urging Customers To Be Alert After Data Breach
MisconfigurationUtilities DistributorWaterloo Catholic District School Board
ON Catholic School Faces Rising Downtime Costs After Ransomware
RansomwareEducationWaterloo Brewing Company
$2.1 Million Lost In Phishing Attack for Waterloo Brewing
Business Email CompromiseFood and Beverage, ManufacturingNunavut Government Services Impacted By Ransomware
Nunavut Government Services Impacted By Ransomware
RansomwareGovernmentPipestone Kin-Ability Centre
Over $400K Siphoned In Not-For-Profit System Hack
HackingNot-for-Profit, Health ServicesOntario Science Centre
3rd Party Data Breach Affects Ontario Science Centre
Third-Party Data BreachEducational InstitutionTransUnion
37,000 Potentially Affected By TransUnion Data Breach
Credential CompromiseFinancialPAL Airlines
Hacked Email Provides Access To Airline’s Sensitive Data
Credential CompromiseTravel, AirlinesNational Basketball Association Canada (NBA Canada)
NBA Canada Suffers Massive Data Breach
MisconfigurationEntertainmentListowel Wingham Hospital Alliance
Ontario Hospital Network Faces Increasing Downtime Costs After Ransomware
RansomwareMedical, Health ServicesDoorDash
Nearly 5 Million DoorDash Users Impacted After Server Hack
HackingFood and BeverageScotiabank
Scotiabank's Major Security Breach: 25 Million Scotiabank Customers’ Data Left Exposed
MisconfigurationFinancialYves Rocher
Yves Rocher Data Leak Impacts 2.5 Million Canadians
MisconfigurationRetailEastern Ontario Municipality
$7-$10K Ransom Request Refused by Municipal Ontario Government
RansomwareGovernment, MunicipalBoyd Group Income Fund
Well Prepared Boyd Group Hit By Ransomware Attack
RansomwareService, Automobile RepairDesjardins
Former Credit Union Employee Creates Data Breach Affecting 2.9 Million Customers
Malicious InsiderFinancial ServicesCity of Burlington
BEC Phishing Scam Tricks City into Transferring $530K
Business Email CompromiseGovernmentNova Scotia Health Authority
2,841 Patients Impacted by Phishing Attack
PhishingGovernment, Health ServicesFreedom Mobile
Thousands Impacted By Freedom Mobile Server Leak
MisconfigurationTechnology, TelecommunicationsMitsubishi Aerospace
Ransomware Leaves Mitsubishi Aerospace Without Internet and Network Access
RansomwareTechnologyBC Pension Corporation
8,000 People Warned After BC Pension Plan Data Leak
Lost or Stolen DeviceGovernmentPrecise Parklink
Small Risk, High Costs After Ransomware hits CIRA Parking Garage
RansomwareService, Parking GarageNorsk Hydro ASA
Norsk Hydro ransomware attack forced aluminum plants onto manual operations
RansomwareManufacturingNatural Health Services Ltd.
Alberta Patients Warned After Data Breach Exposes Medical Info
HackingHealthcare, RetailContainer World
Richmond, BC Facility’s System Shutdown in Lieu of Ransom Payment
RansomwareLogisticsNWT Department of Health and Social Services
40K Canadians Potentially Impacted By Lost Gov’t Employee Laptop
Lost or Stolen DeviceGovernment, Healthcare500px
14.8 Million Accounts Exposed In 500px Data Breach
HackingTechnologyCarePartners
CarePartners Ransomware Attack: $60K Bitcoin Demand Threatens Data Exposure
RansomwareHealthcareCanada Revenue Agency (CRA)
Thousands of Canadians Affected As CRA Employees Caught Snooping
Malicious InsiderGovernment AgencyCoast Capital Savings
$100’s of Thousands Stolen as Coast Capital Members Targeted In Phishing Ring
PhishingFinancialNothing matches those filters.