Skip to main content

Data Breaches

Brightly-lit tech headquarters with a hint of concern, daylight shining through a large window and blurred computer screens…

Salesforce Disables Klue App Over OAuth Token Abuse

Salesforce has taken swift action to protect its customers by disabling the Klue Battlecards app integration after detecting unusual activity that may have led to unauthorized access to some customer data. This move ensures the security of the Salesforce platform, which remains unaffected by a vulnerability.

Analyst 207
Blurred screens and interfaces surround a prominent computer server in a dimly lit data center, conveying vulnerability.

US Carrier Exposed Credit Card Data in Clear Text

A newly hired database admin stumbled upon a shocking discovery on her first day - a main production server containing sensitive customer data, including full 16-digit credit card numbers stored in plain text, Social Security numbers, and billing information. The exposed data was found on a server that didn't even require a secondary system lookup, making it alarmingly accessible.

Analyst 207
Office setting with a laptop on a plain desk, surrounded by neutral decor, under soft daylight.

Nintendo Data Breach Exposes Employee Survey Information

Nintendo of America recently experienced a data breach through a third-party survey service, exposing limited employee survey information, but fortunately, no customer or financial data was compromised. The company is working to resolve the issue and has confirmed that its own systems remain secure.

Analyst 207
Healthcare worker standing near medical equipment with blurred records in foreground.

UK Watchdog Cautions Healthcare Worker Over Royal's Medical Records Breach

When trust in healthcare settings is broken and personal info is mishandled, swift action is taken - as seen in the ICO's recent decision to issue a formal caution to a former healthcare professional for misusing sensitive patient data. The watchdog is clear: people's personal info must be safe from exploitation.

Analyst 207
Brightly-lit office with CRM workstation, laptop on desk, and city view through window, hinting at a breached business…

Klue OAuth Breach Enables Icarus Extortion Attacks on Salesforce Data

A recent OAuth breach at market intelligence platform Klue has enabled a new extortion group called Icarus to steal sensitive Salesforce CRM data from multiple organizations, sparking a wave of ransom demands. Salesforce has swiftly responded by disabling the connection between Klue's Battlecards app and its platform to protect customers.

Analyst 207
Dimly lit server room with rows of computer equipment and a blurred figure in the background.

Telco Exposes Customer Data in Cleartext, Ignoring Basic Security Protocols

A new hire was granted sudo-level access to a live production database on their first day, with management's casual instruction to "take a look" - and promptly uncovered customer records stored in easily accessible cleartext. This alarming lapse in security protocols left sensitive customer information, including full personal details and payment numbers, exposed and vulnerable.

Analyst 207
Interior of a Kodak facility with industrial and corporate elements, blurred computer equipment, and a neutral-toned server…

Kodak Breach Exposes 2.2M Records to ShinyHunters Threat Group

Kodak has confirmed a major data breach, with the ShinyHunters threat group claiming to have stolen 2.2 million records, including sensitive customer information. The company is working closely with law enforcement and cybersecurity experts to address the breach.

Analyst 207
Network equipment and servers in a server room with blinking lights and laptop screens in the foreground.

Fortinet Firewalls Compromised in Massive Password-Stealing Attack

A massive password-stealing attack has compromised around 75,000 Fortinet firewall devices, putting credentials of major corporations across 194 countries at risk and leaving a trail of full network compromises in its wake. The breach, dubbed FortiBleed, has created a verified database of working credentials for some of the world's largest enterprises, threatening nearly every sector of the global economy.

Analyst 207
Rows of equipment racks and networking gear in a brightly-lit server room.

FortiBleed Exposes 73,000 Fortinet VPN Credentials Worldwide

A massive security breach has exposed a whopping 73,000 Fortinet VPN credentials worldwide, putting tens of thousands of firewall endpoints at risk, including those of major companies like Chevron, Samsung, and Mercedes-Benz. The alarming leak, discovered by security researcher Bob Diachenko, contains sensitive information like usernames, email addresses, and plaintext passwords.

Analyst 207
Institutional building entrance with subtle tech elements, hinting at digital breach.

Kodak Breach Exposes Sensitive Data After ShinyHunters Hack

Kodak recently suffered a data breach at the hands of hackers known as ShinyHunters, who gained temporary access to sensitive company data. The company has launched a swift investigation with external cybersecurity experts and is working closely with law enforcement to mitigate the impact.

Analyst 207
Workers stand in a sugarcane field with industrial equipment in the foreground under a clear Australian sky.

Cyberattack Disrupts Australian Sugar Production

Mackay Sugar is making a sweet recovery after a cyberattack halted operations, with significant progress made over the weekend in restoring systems and a staged restart of crushing operations on the horizon. The company is getting back on track, with manual crushing already underway at its Farleigh Mill and harvesting expected to resume soon.

Analyst 207
Person holding letter with puzzled expression in hospital setting.

Breach Notice Error Fuels Patient Skepticism

A simple mistake on breach notices sent by third-party vendor Xsolis sparked skepticism among patients when the letters misnamed Rochester Regional Health as "Rochester Regional Medical Center", leading many to dismiss them as scams. This misstep undermined trust and raised questions about the effectiveness of the breach notification process.

Analyst 207
Cardiac monitor on hospital trolley in brightly lit corridor with slightly ajar door in background.

Cardiac Monitor Maker's Data Breach Exposes Security Gaps

A recent report has exposed a shocking security gap in a leading cardiac monitor manufacturer's system, leaving sensitive clinical monitoring data vulnerable to data thieves. This alarming breach highlights the urgent need for enhanced medical-device security and protection of patient information.

Analyst 207
Cardiac monitor on a hospital bedside table with a faint shadow of a hacker in the background.

iRhythm Breach Exposes Patient Data in Cardiac Monitoring Hack

A recent data breach at iRhythm exposed sensitive patient information, compromising personal and health data from over 12 million patients whose heartbeat data was analyzed through the company's cardiac monitoring service. The breach was discovered after a ransomware-style intrusion hit third-party business applications used by iRhythm.

Analyst 207
Government office interior with computer screen displaying abstract database representation.

ShinyHunters Breach Council of Europe in Oracle PeopleSoft Heist

The Council of Europe has fallen victim to a massive data breach, with hackers claiming to have stolen a whopping 297 GB of sensitive information, including HR records, payslips, and medical data, by exploiting a zero-day flaw in Oracle PeopleSoft. The ShinyHunters extortion group is behind the breach, boasting a haul of 429,000 files from the attack.

Analyst 207
Council of Europe headquarters building exterior with subtle security presence.

Council of Europe Probes ShinyHunters Data Breach Claims

The Council of Europe is actively investigating claims by the ShinyHunters extortion group that sensitive internal documents were stolen, and is working to assess the situation. The organization, which represents 46 European member states, has confirmed the probe but declined to provide further comment at this stage.

Analyst 207
Medical professional stands in a clinical setting with a blurred laptop screen in the background, conveying a sense of…

Novo Nordisk Data Breach Exposes Clinical Trial Information

A recent data breach at Novo Nordisk exposed sensitive clinical trial information, including pseudonymized patient records and healthcare provider contact details, highlighting the importance of robust data security measures. The breach serves as a cautionary tale, reminding us that even seemingly anonymized data can be vulnerable to cyber threats.

Analyst 207
Computer screen displays error message in office setting with blurred background.

Maine Data Breach Portal Disabled After Hoax Reports Flood System

The Maine Attorney General's office has temporarily disabled its data breach portal due to an influx of false reports, which were later confirmed to be hoaxes submitted by an unknown entity. The office is now reviewing its internal procedures to prevent similar abuse in the future.

Analyst 207
School office with computer workstation and papers, blurred cityscape in background.

ShinyHunters Breach Exposes 137,000 Infinite Campus Staff Accounts

A massive data breach at Infinite Campus has exposed the sensitive information of 137,000 staff members, including names, email addresses, phone numbers, and physical addresses, after the ShinyHunters extortion group hacked into the company's Salesforce instance. The stolen data has been published online, putting staff at risk of identity theft and phishing scams.

Analyst 207
Dimly lit government office room with scattered papers and a darkened computer screen.

Maine Disables Breach Database After Fake Reports Flood In

Maine's Attorney General's office has temporarily taken down its public database of data breach reports after being flooded with fake submissions, including hoax reports targeting VRChat and another company. The office is reviewing its procedures to prevent future abuse and plans to reinstate the database with enhanced safeguards.

Analyst 207
Government office setting with computer screen and partially visible foreground object.

Maine Disables Breach Portal After Hoax Submissions

Maine has temporarily shut down its public data breach reporting portal after being hit with a series of false reports, or hoaxes, submitted through the system. The state's Attorney General's Office is reviewing the situation and has removed the fraudulent filings from its database.

Analyst 207
Hospital corridor with people in background, medical device and laptop on table.

Novo Nordisk Discloses Cyberattack, Patient Data Stolen

Novo Nordisk revealed that a cyberattack has compromised patient data, specifically information related to clinical-trial participants, though assured that the data is not directly linked to patients by name or other identifiers. The company is working with outside experts to investigate and contain the breach.

Analyst 207
Laptop screen on cluttered desk shows blurred email inbox with one message.

Plymouth Council Breach Exposes 500 Home-Schooling Families' Email Addresses

A careless mistake by Plymouth City Council's Elective Home Education team has led to a data breach, exposing the email addresses of around 500 home-schooling families after a single email was sent with all recipient addresses visible. The council is now dealing with the fallout after compromising the personal email addresses of hundreds of families.

Analyst 207
Hospital corridor with healthcare professionals, laptop screen, and large windows, conveying a sense of unease.

Novo Nordisk Discloses Clinical Trials Data Breach

Novo Nordisk revealed a clinical trials data breach, confirming that hackers accessed and copied sensitive personal data, including patient information and healthcare professional records, from its internal IT systems without authorization. The stolen data includes patient IDs, trial details, and health information such as biomarkers, lifestyle factors, and more.

Analyst 207