Data Breaches

data breach news

At Cyber Management Alliance, we help organisations strengthen their defences and prepare for such attacks through our NCSC Assured Cyber Incident Planning and Response training, Cyber Tabletop Exercises, and Incident Response Playbook creation and review workshops. In a filing with Maine’s attorney general, DISA said the breach affected more than 3.3 million people who had undergone employee screening tests. DISA, a Texas-based provider of employee screening services, including drug and alcohol tests and background checks, confirmed in February a https://adeptiv.ai/ai-compliance-platform-guide/ massive data breach that happened almost a year earlier in April 2024. The easy-to-exploit bug also exposes the email addresses of the people who signed up for the stalkerware apps. A trio of stalkerware apps exposed the personal data of millions of people who unwittingly have them planted on their devices, a security researcher revealed to TechCrunch in February.

The hacking group USDoD claimed it had allegedly stolen personal records of 2.9 billion people from National Public Data, according to a class-action lawsuit filed in U.S. The more people dig into this data, the better we can all understand and hopefully prevent future breaches. Some of these ongoing incidents had massive scope, including Infosys McCamish Systems (originally from 2023) affecting over 6 million people and Ascension Health impacting 5.6 million people. While 561 incidents were newly reported, 97 represented continued notification activity from breaches originally discovered in earlier months or years. The healthcare sector also saw some of the largest individual breaches, including the Blue Shield of California’s incident we mentioned earlier, affecting 4.7 million people and Community Health Center’s breach impacting over 1 million people. Hacking incidents continued to dominate the breach landscape, accounting for 400 of the 658 total incidents (61%).

The company filed required authority reports, began investigation work, and warned readers about phishing abuse. Foxconn confirmed that affected North American factories were returning to normal production after the cyberattack. Foxconn acknowledged a cyberattack on its North American factories on 12 May, 2026, after the Nitrogen ransomware group claimed it stole 8 terabytes of sensitive data. ShinyHunters later released Spectrum-linked data that researchers said covered at least 13 million people and nearly 10 million customer-support records. The incident shows how one social engineering call can turn cloud identity access into mass customer exposure. Charter said no sensitive personal information or CPNI was exfiltrated, though later breach monitoring tied the exposed dataset to 4.9 million accounts.

data breach news

Hackers Allegedly Breach TikTok, Exposing Over 900,000 Usernames & Passwords

However, it seems that the servers that were breached did not store any customer payment details. The information included files from big restaurant clients, promo codes, payment reports, and API keys. According to recent reports, a bank of email addresses belonging to around 200 million Twitter users is being sold on the dark web right now for as little as $2.

Semiconductor Firm Analog Devices Confirms Data Breach After Internal Systems Intrusion

Dates of birth, Social Security numbers, and driver’s licenses could have also been accessed. Customers are still being served in Victoria’s Secret and PINK stores, however CEO Hillary Super has told employees that, “Recovery is going to take a while.” Many other companies customers were affected — About 462,000 current and former customers of Blue Cross Blue Shield of Montana saw their details exposed, for just one example.

data breach news

Capita, which provides outsourcing services for both public agencies and private companies, confirmed that hundreds of pension schemes it manages were affected. The Information Commissioner’s Office (ICO) said the firm’s weak security controls allowed hackers to access sensitive data belonging to around 6.6 million people. The safest wording is that sensitive contractor-held defence documents were reportedly exposed, while the MoD’s own core systems were not confirmed breached. The MoD said it is “actively investigating” and declined to release further details to protect sensitive operational information. The Mail on Sunday, which first reported the incident, stated that the leaked data includes information on bases such as RAF Lakenheath in Suffolk, home to the U.S.

Personal information belonging to 138,080 people is believed to have been compromised. Stolen information potentially includes names, social security numbers, and dates of birth. The company claims there is no evidence to suggest that personal information has been “misused.” Potentially affected data included names, dates of birth, Social Security numbers, and health insurance information. Reportedly, stolen information includes patient names, addresses, dates of birth, social security numbers, drivers’ license numbers, medical record numbers, health insurance information, and clinical information related to some patients’ care.

  • In January, solution provider giant Conduent—whose systems are used to enable government services such as child support payments and food assistance—confirmed that a major service outage was caused by a cyberattack.
  • According to a notice filed with the Maine Attorney General, data from 144,180 people was affected.
  • Attackers can use these email-password pairs to attempt account takeovers, exploit reused credentials, and access mail or business systems tied to those accounts.
  • Close to 13 million people in Australia — roughly half of the country’s population — had personal and health data stolen in a ransomware attack on prescriptions provider MediSecure in April.
  • From huge stores of customers’ personal information getting scraped, stolen, and posted online, to reams of medical data covering most people in the United States getting stolen, the worst data breaches of 2024 have surpassed 1 billion stolen records and are rising.

data breach news

This incident follows a 2024 Dell breach that exposed personal data from over 10,000 employees. Law firm Levi & Korsinsky, LLP is investigating potential compensation claims for those impacted. Moviynt disclosed a data breach involving unauthorized access to employee email accounts and files between February 27 and March 6, 2025.

According to the leaked files, comedian Ben Stiller was categorized as “Low Risk,” while rapper A Boogie wit da Hoodie was labeled “High Risk.” Teams and companies use this confidential information to make signing, partnership, and advertising decisions. However, there is no evidence that the data breach exposed confidential financial details or account information, such as passwords. The group recently claimed responsibility for breaching American fashion powerhouse Ralph Lauren Corporation and stealing 200GB of data, including personal information.

  • Social security numbers, birth dates, names, and health insurance information were all extracted from the Kentucky-based health provider’s systems.
  • Recent state regulatory reports show at least 15.4 million people affected in Texas alone (up from an initial estimate of 4 million), with earlier filings indicating 10.5 million impacted in Oregon and hundreds of thousands more across other states.
  • In a filing with Maine’s attorney general, DISA said the breach affected more than 3.3 million people who had undergone employee screening tests.
  • EY contained the access, hired an independent cybersecurity company, notified federal law enforcement, and began contacting affected people.

Suisan City, California, Responds to Cyber Incident Amid Wave of US Local Government Attacks

Volkswagen stated that its core IT systems remain unaffected, hinting that the breach may have originated through a supplier or subsidiary rather than direct network access. Attackers https://givewebhosting.com/what-is-wcpss-technology.html can use these email-password pairs to attempt account takeovers, exploit reused credentials, and access mail or business systems tied to those accounts. Around 16.4 million of the exposed accounts had not appeared in previous leaks. Google confirmed there was no Gmail-specific hack and called reports suggesting otherwise inaccurate. A massive dataset known as “Synthient Stealer Log Threat Data” was added to Have I Been Pwned, containing about 183 million unique email accounts with passwords stolen from infected devices. Exposed information may include medical details, insurance data, driver’s license numbers, service information, and other patient records.

Eight of the twenty largest breaches reported in 2025 occurred at service providers, together accounting for 231 million of the year’s 375 million affected individuals. The sector accounted for 66% of all affected individuals in 2025, driven by Change Healthcare but extending across hospital systems, radiology practices, dialysis providers, and dental groups. The year’s statistics were dominated by Change Healthcare, whose final notification arrived in October, twenty months after the February 2024 ransomware attack, confirming 192.7 million people were affected.

Leave a Reply

Your email address will not be published. Required fields are marked *