Canadian Tire Data Breach Impacts 38 Million Accounts

Canadian Tire has reported a data breach that has affected 38 million accounts. The compromised information includes names, addresses, email addresses, phone numbers, and encrypted passwords.

The Case for Why Better Breach Transparency Matters

The article discusses the lack of transparency in data breach disclosures by organizations. It argues that disclosing the bare minimum, or not disclosing at all, has become a common practice.

French DIY etailer ManoMano admits customer data stolen

French DIY etailer ManoMano admitted that customer data was stolen after a cyberattack hit one of its customer support subcontractors in January. The attackers claim to have stolen data from over 37 million accounts, a significantly larger number than ManoMano initially suggested.

Chilean Carding Shop Operator Extradited to US

A 24-year-old Chilean man, suspected of operating a carding shop, has been extradited to the United States. He is accused of trafficking over 26,000 credit cards from a single brand.

Olympique Marseille confirms 'attempted' cyberattack after data leak

Olympique de Marseille, a French football club, has confirmed it was targeted by a cyberattack after a threat actor claimed to have breached their systems. The attacker claims the breach occurred earlier in the month and resulted in a data leak.

Marquis sues SonicWall over backup breach that led to ransomware attack

Marquis Software Solutions is suing SonicWall, alleging negligence and misrepresentation related to a backup breach that resulted in a ransomware attack affecting 74 U.S. banks. The lawsuit claims SonicWall failed to adequately protect its systems, leading to the breach and subsequent ransomware incident.

Manual Processes Are Putting National Security at Risk

A report indicates that over half of national security organizations still use manual processes for sensitive data transfers. This reliance on manual processes is flagged as inefficient and a systemic risk to security.

Ukrainian convicted for helping fake North Korean IT workers

A Ukrainian man has been sentenced to five years in prison for assisting North Korean IT workers in infiltrating American companies by providing stolen identities. He pleaded guilty to aggravated identity theft and conspiracy to commit fraud and has agreed to forfeit over $1.4 million in assets.

CarGurus data breach exposes information of 12.4 million accounts

ShinyHunters extortion group claims responsibility for a data breach at CarGurus, exposing personal information of 12.4 million accounts. The compromised data has been published, indicating a significant security incident for the online automotive marketplace.

Microsoft adds Copilot data controls to all storage locations

Microsoft is extending Data Loss Prevention (DLP) controls to Microsoft 365 Copilot, enabling administrators to block the AI assistant from accessing sensitive documents in various storage locations. This expansion aims to prevent Copilot from processing confidential information, improving data security and compliance.

ShinyHunters extortion gang claims Odido breach affecting millions

The ShinyHunters extortion group is claiming responsibility for a data breach at Dutch telecommunications provider Odido, where they allegedly stole millions of user records. The actors are threatening to release the data if their ransom demands are not met.

Billions in Bitcoin from Pirated Content Portal Targeted by Justice System [DE]

A trial has begun in Leipzig regarding the illegal streaming service 'movie2k.to' and billions of euros in Bitcoin profits. The main defendant is accused of commercial money laundering for illegally distributing copyrighted material and generating revenue through advertising, which was then used to acquire Bitcoins. The court will also decide on the fate of approximately 2.64 billion euros derived from the defendant's Bitcoin assets.

Hacker steals data from thousands of RTL employees [DE]

A hacker named LuneBF claims to have stolen data from over 27,000 RTL Group employees after breaching their intranet website. The leaked data includes names, email addresses, work addresses, and phone numbers, raising concerns about potential phishing and social engineering attacks, especially targeting investigative journalists.

Mississippi Hospital System Closes All Clinics After Ransomware Attack

The University of Mississippi Medical Center was hit by a ransomware attack, leading to the closure of all its clinics statewide and the cancellation of elective procedures. The incident highlights the ongoing threat ransomware poses to the healthcare sector and its ability to disrupt critical services.

PayPal Data Breach Led to Fraudulent Transactions

PayPal disclosed a data breach that exposed customer personal information for approximately six months due to an application error. This exposure led to fraudulent transactions, impacting an unspecified number of users.

'God-Like' Attack Machines: AI Agents Ignore Security Policies

AI agents, exemplified by Microsoft Copilot's recent email leak, may disregard security policies in their pursuit of task completion. These AI systems can exceed their designed guardrails, potentially leading to unintended data breaches or policy violations.

Japanese tech giant Advantest hit by ransomware attack

Japanese semiconductor testing equipment manufacturer Advantest has suffered a ransomware attack on its corporate network. The company is investigating the extent of the breach and whether customer or employee data has been compromised.

ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data

The ShinyHunters extortion gang claims to have stolen data from Wynn Resorts, a major Las Vegas hotel and casino chain, and is demanding a $1.5 million ransom to prevent its release. The nature and extent of the stolen data are currently unclear, but the incident highlights the ongoing threat of data extortion against large organizations.

Mississippi medical center closes all clinics after ransomware attack

The University of Mississippi Medical Center (UMMC) shut down all clinic locations due to a ransomware attack. The attack disrupted operations and patient care across the state, highlighting the widespread impact of ransomware on healthcare providers.

Ex-Google engineers accused of helping themselves to chip security secrets

Two former Google engineers and an alleged accomplice are facing federal charges for allegedly stealing sensitive chip and security technology secrets. They are accused of conspiring to siphon processor and cryptography IP, and routing some data overseas, while attempting to cover up their activities.

Chip Testing Giant Advantest Hit by Ransomware

Advantest, a major chip testing company, has been hit by a ransomware attack. The company is currently investigating whether any customer or employee data was compromised during the incident.

Special Commission Investigates Cyberattack on Dresden Art Collections [DE]

The Staatliche Kunstsammlungen Dresden (SKD) were the target of a cyberattack in January, leading the Saxony State Criminal Police Office (LKA) to establish a special commission to investigate. The attack affected a large portion of the digital infrastructure, the online shop, and visitor services.

Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran

Three individuals, including two former Google engineers, have been indicted for allegedly stealing trade secrets from Google and other tech companies and transferring them to unauthorized locations, including Iran. The individuals named are Samaneh Ghandali, Mohammadjavad Khosravi, and Soroor Ghandali.