Tag

Data Breach

All articles tagged with #data breach

Apollo exposes personal data in cloud breach tied to social engineering
business4 days ago

Apollo exposes personal data in cloud breach tied to social engineering

Apollo Global Management said hackers gained unauthorized access to information on its cloud platforms from July 6–10, exposing names, birth dates, home addresses and Social Security numbers; the breach is attributed to a social engineering incident, law enforcement was notified, and there is no evidence yet that personal data was publicly posted or used for fraud.

Azure Credential Breach Leaks Millions of Enterprise Directory Records
security9 days ago

Azure Credential Breach Leaks Millions of Enterprise Directory Records

A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}

AnMed Facebook Hack Floods Page with Ransom Messages, Claims Huge Patient Data Breach
technology14 days ago

AnMed Facebook Hack Floods Page with Ransom Messages, Claims Huge Patient Data Breach

AnMed Health’s Facebook page was taken down after hackers posted nearly 100 ransom messages, claiming to have exfiltrated six terabytes of sensitive patient data and threatening further harm unless paid. The incident appears to be part of a broader cyberattack that began July 26; AnMed has since set up a patient helpline and recovery site while authorities investigate.

Valve warns Steam hardware buyers' data compromised in CEVA logistics breach
technology15 days ago

Valve warns Steam hardware buyers' data compromised in CEVA logistics breach

Valve has informed European Steam hardware buyers that their personal data may have been exposed in a cyberattack on CEVA Logistics, which handles Steam Deck, Steam Machine, and Steam Controller deliveries. The breach occurred July 29–August 1 and was reported August 7; affected data include names, street addresses, postal codes, cities, countries, phone numbers, email addresses tied to Steam accounts, and the type and price of the ordered hardware, while payment data, passwords, and Steam Guard codes were not affected. CEVA said the intrusion affected part of its European operation and several warehouses, with Valve notifying data protection authorities. Customers are warned to expect phishing attempts referencing orders, and Steam Support will never request passwords. The exact number of affected customers has not been disclosed.

European Steam hardware orders exposed in CEVA breach, warning of scams
technology16 days ago

European Steam hardware orders exposed in CEVA breach, warning of scams

Valve says a data breach at its European shipping partner CEVA Logistics may have exposed the personal information of customers who ordered Steam hardware in Europe, including names, addresses, phone numbers, and email addresses, with the breach occurring July 29–August 1 and delivery-related data kept for up to 90 days. The company warns of fake messages claiming to be from Steam, Valve, or a courier; CEVA does not have payment data or passwords, and Valve will not contact users via email, Steam chat, or Discord—use help.steampowered.com for official assistance.

Metabase zero-day in the wild unlocks admin access with unauthenticated SQL injection
technology17 days ago

Metabase zero-day in the wild unlocks admin access with unauthenticated SQL injection

Metabase warns of a high-severity zero-day (CVSS 10) that has been exploited in the wild to gain unauthenticated admin access by injecting arbitrary SQL into the Metabase database. The flaw affects self-hosted Metabase versions from 1.58.x up to 1.63.x (fixed in 1.63.5); Metabase Cloud was updated. A temporary workaround is to block the /api/session/reset_password endpoint. After patching, admins should revoke all sessions, review and rotate API keys and credentials, verify administrator accounts, and inspect logs for unauthorized activity. IoCs include a POST /api/session/reset_password (400) followed by a GET /api/user/current (200). Affected customer Framework reported exposure of names, login IPs, addresses, phone numbers, and emails, though no payment data was compromised. Metabase did not detail the attacker activity but referenced a past vulnerability CVE-2023-38646.

Parliament finds MoD data breach of Afghan relocation scheme was foreseeable
defence27 days ago

Parliament finds MoD data breach of Afghan relocation scheme was foreseeable

A parliamentary Defence Committee report says the MoD's management of the Afghan Relocations and Assistance Policy (ARAP) was a 'foreseeable' systemic failure, driven by inappropriate tools (Excel), weak operating procedures, insufficient training and an overreliance on secrecy that undermined accountability. The breach exposed personal data of more than 18,500 ARAP applicants, stemming from a spreadsheet shared with a trusted third party, and has prompted reforms as ARAP closes in 2025, with ongoing scrutiny of UK Special Forces involvement and governance of the scheme.

Chick-fil-A reports limited loyalty data exposure in June security incident
business1 month ago

Chick-fil-A reports limited loyalty data exposure in June security incident

Chick-fil-A says a June security incident may have exposed limited personal data from Chick-fil-A One loyalty accounts, including names, email addresses, membership numbers, mobile payment numbers, the last four digits of cards and the amount of loyalty credit; attackers used third-party credentials to access the site and app June 17–19, prompting password resets, balance restoration, and customer notifications across several states, with an apology from the company.

Chick-fil-A breach hits loyalty accounts in 10 states and DC
technology1 month ago

Chick-fil-A breach hits loyalty accounts in 10 states and DC

Chick-fil-A says unauthorized parties accessed Chick-fil-A One accounts during a June 17–19 cyberattack, potentially exposing names, email addresses, loyalty numbers, the last four digits of card numbers, and Chick-fil-A credits for customers in 10 states and Washington, D.C. Texas later reported 2,182 affected residents. The company reset passwords, forced logouts, removed stored payment methods, and restored balances while urging customers to monitor credit reports and account activity for signs of identity theft.

Chick-fil-A breach exposes loyalty-program customer data
business1 month ago

Chick-fil-A breach exposes loyalty-program customer data

Chick-fil-A says a limited number of Chick-fil-A One loyalty accounts were accessed in an automated attack on June 17–19, potentially exposing names, email addresses, birthdays, phone numbers, addresses, and the last four digits of stored payment cards. The company forced logouts, removed saved payment methods, reset passwords, restored balances, and offered a reward to impacted customers. Massachusetts reported 39 affected residents and Texas 2,182; Georgia impact is unclear. The breach underscores varying state disclosure rules and the need for vigilance against identity theft, with the company providing guidance for affected residents.

Chick-fil-A hit by credential-stuffing data breach exposing customer info
cybersecurity1 month ago

Chick-fil-A hit by credential-stuffing data breach exposing customer info

Chick-fil-A disclosed a data breach after a June credential-stuffing attack on its Chick-fil-A One site/app that may have exposed customer data, including names, emails, membership numbers, mobile pay numbers, QR codes, Chick-fil-A credit, and the last four digits of card numbers, with possible birth dates, phone numbers, and addresses; affected accounts were logged out, payment methods removed, balances restored, and customers were urged to change passwords, with notices issued to residents in multiple states (including Texas and Massachusetts).

Autonomous AI Agent Breach Exposes Hugging Face Credentials
technology1 month ago

Autonomous AI Agent Breach Exposes Hugging Face Credentials

Hugging Face disclosed that attackers used an autonomous AI agent to breach its production infrastructure, stealing internal datasets and cloud credentials after exploiting a malicious dataset to trigger two code-execution vulnerabilities; the company evicted the attacker, rebuilt affected nodes, rotated credentials, and deployed enhanced detection while informing law enforcement and engaging external forensics. There is no current evidence of tampering with public models or Spaces, though the incident highlights evolving AI-driven attack risks. Users are advised to rotate access tokens and review account activity; Hugging Face also stresses having a vetted self-hosted model ready to use during incidents to avoid guardrail lockout and contain attacker data.

Your Period Tracker Isn’t the Only Privacy Wake-Up Call This Week
security1 month ago

Your Period Tracker Isn’t the Only Privacy Wake-Up Call This Week

Security roundup flags widening privacy and security concerns: Stardust period-tracker data sharing is exposed in a Mozilla audit (Euki is the privacy-friendly exception), Russia’s FSB is sanctioned for a near–blackout attack on Poland’s grid, a Russian hacker’s ties to Kaspersky surface in a Reuters report, DHS’s HSIN breach was initially treated as a false positive before confirmation, and Suno’s AI music training scraped millions of songs with customer data exposed—illustrating how AI, surveillance, and state-linked cyber operations intersect with everyday tech.