McKesson, a major healthcare technology provider, has reported a cyberattack that exposed millions of patient records. The group ShinyHunters is reportedly demanding a $55.2 million ransom in connection with the breach.
Berlin's city administration has confirmed a data theft incident following a ransomware attack by the Rhysida gang. The cybercriminals are attempting to extort the city after listing it on their data leak site.
McKesson has confirmed a data breach, with the ShinyHunters extortion group claiming responsibility for the theft of 284 million records. An attacker deadline is reportedly looming.
Boston Scientific is still experiencing the aftermath of a cyberattack that caused significant global network disruptions. The medical device company has engaged cybersecurity firm CrowdStrike to assist in the ongoing investigation of the incident.
An extortion group named FulcrumSec claims to have exfiltrated over 80 GB of data from the Manchester Airports Group. The group has stated its intention to leak this stolen data online.
Two Nigerian men have been extradited to the United States and charged with involvement in sextortion schemes. These schemes are linked to the deaths of two teenagers in Mississippi and North Carolina.
The Rhysida ransomware group has claimed to have exfiltrated over 5TB of data, which includes personal information and credentials. Authorities in Berlin have stated they will not pay any ransom to the extortion group.
FulcrumSec claims to have stolen 86 GB of data from Manchester Airports Group (MAG). BleepingComputer validated a sample of the stolen data, which included detailed customer, booking, and travel information.
The toy and game company Hasbro has disclosed a data breach that resulted from a cyberattack earlier this year. The attack caused disruptions to the company's operations, and the breach has exposed personal information of employees.
Healthcare and pharmaceutical distribution company McKesson has disclosed a cybersecurity incident. The ShinyHunters extortion group claims to have stolen 284 million patient data records as a result of unauthorized access to third-party applications.
Berlin's state government has confirmed it is the target of an extortion attempt after its state administrative network was compromised in August. The government has stated it will not meet the hackers' demands, and forensic analysis revealed further data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment.
Several cybersecurity incidents are highlighted, including a cyberattack on Manchester Airports Group and a data breach at Carhartt where some leaked data was found to be fabricated. The article also mentions U.S. Bank addressing claims made by a ransomware gang.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a major cyber incident that is being investigated by the Department of Justice. This confirmation follows a claim by a ransomware group that they were responsible for the attack.
Hasbro, a major toy and game company, has reported a data breach that exposed the personal and financial information of its employees. The extent of the breach and the number of affected individuals remain undisclosed.
A website offering AI girlfriend services had its testing and staging environments exposed to the public for three weeks. This lack of protection allowed sensitive information to be accessible, highlighting the importance of securing all environments, not just production.
The Manchester Airports Group (MAG) has reported a data breach resulting from a cyberattack. Hackers successfully accessed MAG's systems and exfiltrated customer data, specifically information collected during Wi-Fi sign-ups across Manchester, Stansted, and East Midlands airports.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is responding to a significant cybersecurity incident. This follows claims by a ransomware gang that they were responsible for the breach. The US Justice Department is now investigating the incident.
Manchester Airports Group (MAG), the UK's largest airport operator, has suffered a data breach that may have affected up to 8.7 million customers. The nature and extent of the compromised data are still under investigation, but the incident is believed to involve cybercriminals.
The ShinyHunters extortion group has published sensitive data from approximately 13 million accounts stolen from the clothing retailer Carhartt. The data breach was first identified earlier this month and subsequently confirmed by data breach notification service Have I Been Pwned.
Boston Scientific is experiencing global operational disruptions due to a cyberattack. The incident has impacted the company's ability to process and ship customer orders.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" involving a system compromise, following claims by the Qilin ransomware gang that they breached the agency. The full scope and impact of the incident are still being investigated.
A report analyzes the state of ransomware attacks in the education sector, based on insights from 226 IT and cybersecurity leaders across 17 countries. The article focuses on organizations that experienced ransomware incidents in the past year.
Medical device manufacturer Boston Scientific has disclosed a "global disruption" affecting its IT systems due to an ongoing cyberattack. The company is currently investigating the incident and has not provided a timeline for restoring its IT services.
Medical technology company Boston Scientific experienced a global cyberattack that disrupted some of its IT systems and operations. The extent of the breach and the specific nature of the attack are still under investigation.
Carhartt has confirmed a data breach affecting 12.9 million customer records. This figure is half of the initial claims made by the threat actor ShinyHunters.
Nutex Health has reported a data breach to the SEC, confirming unauthorized access and exfiltration of sensitive information. The full extent and nature of the compromised data are still under investigation.
The Los Angeles County Museum of Art (LACMA) has disclosed a data breach that occurred last year. The breach resulted in the exposure of sensitive customer and employee information, including social security and medical data.
The article discusses the increasing costs associated with cybersecurity, including breach expenses and defense spending, which are creating an affordability crisis for small businesses. This exposure of smaller organizations poses a significant risk to overall supply chain security.
Nutex Health, a healthcare and services provider, is investigating a cyberattack where an unauthorized third party exfiltrated data from company servers. The extent of the data stolen and its potential impact are currently under investigation.
ReliaQuest has confirmed a security incident where a phishing attack on an employee led to unauthorized access to a dashboard. The company states that the impact of the breach, attributed to the ShinyHunters threat actor, was limited.
Cybersecurity company ReliaQuest has confirmed an attempted data-theft attack targeting one of its employees through social engineering. Hackers impersonated a member of ReliaQuest's security team in an attempt to gain unauthorized access.
A breach occurred at a South Korean government-backed startup platform, exposing encrypted personal data. The incident happened because an encryption key was inadvertently included in an API, highlighting critical failures in key management.
Apollo Global Management has experienced a data breach that exposed personal information. The firm was reportedly targeted as part of a larger campaign against major financial companies.
Over 9,300 Amazon Web Services (AWS) access keys were publicly exposed between August 2022 and August 2026, and many of them remain active and valid. This exposure grants full administrative control over affected corporate AWS accounts, allowing attackers to access, modify, or delete sensitive data and resources.
Toronto's Hospital for Sick Children (SickKids) experienced a data breach that exposed personal information of employees and job applicants. The incident originated from a vulnerability in third-party software, but critical clinical systems and patient records remained unaffected.
US Bank is investigating claims by the ransomware group LockBit that they have successfully exfiltrated sensitive data. LockBit has set a deadline for the bank to pay a ransom, threatening to leak the stolen data if their demands are not met.
France's tax authority, Direction Générale des Finances Publiques (DGFiP), has reported a security breach that exposed the data of approximately 600,000 individuals. The stolen information includes sensitive details such as contact information, household finances, and tax withholding rates.
Sakura Internet, a Japanese cloud and data center service provider, has reported a data breach where hackers accessed its sales management system. This system contained customer contract and membership information.
U.S. healthcare IT company CareCloud has disclosed that a data breach incident suffered earlier this year has impacted over 3.7 million individuals. The extent of the compromised data and the specific methods of intrusion are still under investigation, but the breach has significant implications for patient privacy and data security within the healthcare sector.
The U.S. has indicted 17 individuals from Iran, identified as members of the Mabna Institute, for their alleged involvement in a sophisticated intellectual property theft scheme. This operation, spanning several years, targeted numerous American organizations and resulted in the illicit acquisition of valuable data.
The Cl0p ransomware group has publicly named over 40 companies that were victims of its recent PTC Windchill campaign. Prominent companies such as Shell, Philips, and Fiserv are among those listed.
A data breach initially thought to affect 350,000 individuals has now been found to impact approximately 3.7 million people. The expanded scope of the breach was reported on the HHS breach tracker.
The Australian hotel chain Quest has experienced a data breach affecting the personal information of its guests. The breach occurred at a third-party database operator, leading to the exposure of guest data across 120 Quest properties.
A single attacker, operating under the moniker 'City Forum campaign,' has been scraping data from both Salesforce and ServiceNow customer portals across various industries for over a year. The campaign has been traced back to a single server hosted by a specific provider.
Hackers have accessed sensitive personal and financial information belonging to at least 1.2 million individuals through a breach on a third-party platform used by Heights Finance. The stolen data includes names, addresses, phone numbers, Social Security numbers, and financial details.
Hardware wallet maker SafePal has announced a data exposure incident affecting nearly 40,000 customers. An authorization flaw in an order-tracking plug-in inadvertently exposed customer names, email addresses, shipping addresses, phone numbers, and purchase details. The company has begun notifying affected individuals.
Communications made during the initial chaotic hours of a cyber incident can have significant legal and financial repercussions long after the attack. What is said and documented can become evidence in litigation and investigations, and simply copying legal counsel does not automatically grant attorney-client privilege.
A threat actor claims to have stolen millions of Azure account records from several Fortune 500 companies by exploiting compromised credentials. The stolen data, allegedly containing employee databases, is being offered for sale on a dark web forum.
The Pokémon Center has announced a data breach affecting customers in the UK and Germany. Hackers gained access to customer personal and order information through a third-party logistics provider, CEVA Logistics. This breach has also led to the cancellation of some customer orders.
Hackers have breached the French tax authority, impacting an estimated 680,000 individuals. The attackers gained access to the system using compromised credentials, leading to the exposure of enterprise and personal tax-related data.