Articles tagged "Data Breach"

Found 729 articles

The Cl0p ransomware group has publicly named over 40 victims from its campaign targeting PTC Windchill, a software used for product lifecycle management. Notable companies on the list include Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. This incident raises concerns about the security of major corporations and their vulnerability to ransomware attacks. The attackers are leveraging weaknesses in the software to extract sensitive data, which emphasizes the need for companies to bolster their cybersecurity measures. As ransomware attacks continue to evolve, organizations must remain vigilant and proactive in protecting their systems and data.

Read Original
Actively Exploited

A recent investigation by Ransomnews has uncovered a significant leak of over 50,000 unique Stripe API keys, which were found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers. This leak poses serious risks, as these API keys can be exploited by attackers to commit fraud, access sensitive data, and abuse accounts within a matter of hours. Businesses utilizing Stripe for payment processing are particularly vulnerable, as the leaked keys could allow unauthorized transactions and data breaches. The incident highlights the ongoing challenge of securing sensitive information in public environments and serves as a reminder for companies to maintain strict controls over their API keys and sensitive credentials. Organizations should take immediate action to rotate any exposed keys and review their security practices to prevent similar incidents in the future.

Read Original
Actively Exploited

A hacker known as TheHatman has reportedly stolen sensitive employee records from McDonald's and is selling the data on a forum. The data dump, titled 'McDonalds 1.7M+ Azure Internal Employee Dump,' includes information related to over 1.7 million employees. This incident raises significant concerns about the security of sensitive employee information and the potential for identity theft or other malicious activities. Companies like McDonald's must ensure robust security measures to protect their internal data, especially when it involves a large workforce. The sale of such data on public forums highlights the ongoing risks organizations face regarding data breaches and the need for vigilance in cybersecurity practices.

Read Original

The article discusses significant risks associated with unmanaged cloud infrastructure, particularly focusing on gaps in control planes that make it difficult for organizations to detect potential security issues. These blind spots can lead to unauthorized access and data breaches, as companies may lack visibility into what is happening within their cloud environments. This situation affects a wide range of businesses that utilize cloud services but do not have adequate management practices in place. The lack of oversight can result in severe consequences, including data loss and regulatory non-compliance. It’s crucial for organizations to implement better monitoring and management solutions to mitigate these risks and protect sensitive information.

Read Original

Heights Finance has reported a data breach that compromised the personal and financial information of over 1.2 million customers. The breach occurred after hackers gained access to a third-party cloud platform used by the company. Heights Finance, which specializes in providing personal loans to individuals with limited access to traditional banking services, is now facing significant scrutiny regarding its data security measures. This incident not only affects the privacy of the impacted customers but also raises concerns about the security of third-party vendors and the potential for further exploitation of sensitive information. Customers should be vigilant about monitoring their financial accounts and personal data in the wake of this breach.

Read Original

A single attacker has been extracting records from Salesforce and ServiceNow customer portals for over a year, according to research from Reco, a security platform. This activity, identified as the City Forum campaign, is traced back to a specific server with the IP address 158.220.87.79. The attack affects organizations across various industries that use these platforms, raising concerns about the security of sensitive customer data. The ongoing nature of this campaign suggests that organizations using Salesforce and ServiceNow must take immediate action to protect their data. This incident underscores the need for heightened vigilance and improved security measures in customer portal management.

Read Original

SafePal, a manufacturer of hardware wallets, has revealed that an authorization flaw in one of its order-tracking plugins exposed sensitive information belonging to nearly 40,000 customers. This breach compromised names, email addresses, shipping addresses, phone numbers, and details of their purchases. The company took immediate action, notifying the affected customers via email on August 16, 2023. This incident raises significant concerns about the security of customer data in online transactions, as it highlights vulnerabilities that can lead to identity theft or phishing attacks. Users of SafePal products need to be cautious and monitor their accounts for any unusual activity following this breach.

Read Original

A hacker using the alias 'TheHatman' claims to have stolen millions of employee records from the Azure environments of various Fortune 500 companies, including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services (TCS). Over the past week, TheHatman has shared large internal directories on cybercrime forums, asserting these records were extracted directly from the companies' Azure tenants. This incident raises significant concerns about the security of cloud environments and the potential exposure of sensitive employee information. Organizations using Azure services need to assess their security measures to prevent unauthorized access and protect their data. The situation emphasizes the ongoing risks associated with cloud computing and the need for robust cybersecurity practices.

Read Original

SafePal has reported a data breach that has potentially affected nearly 40,000 customers. The breach occurred between March 2, 2025, and April 11, 2026, exposing sensitive information including customer names, email addresses, shipping addresses, and phone numbers. This incident raises concerns about the security of customer data in the cryptocurrency space, as it can lead to identity theft and other malicious activities. Customers of SafePal should be vigilant and may need to update their security settings and monitor their accounts for unusual activity. The company has not detailed how the breach occurred or what measures they are taking to prevent future incidents.

Read Original

Pokémon Center has informed customers in the UK and Germany about a data breach linked to its third-party logistics provider, CEVA Logistics. Hackers accessed sensitive personal and order information from customers, raising concerns about the security of their data. Some orders have been canceled as a precautionary measure. This incident emphasizes the risks associated with relying on third-party vendors for logistics and customer data management. Affected customers are advised to monitor their accounts for any unusual activity and to be cautious of potential phishing attempts that could arise from this breach.

Read Original

SafePal has reported a data breach that has impacted the personal information of 39,798 customers. The breach occurred due to a flaw in its order-tracking plugin, allowing hackers to access data related to orders placed between March 2, 2025, and April 11, 2026. Importantly, the breach did not compromise sensitive wallet credentials, private keys, seed phrases, or payment information, which may provide some reassurance to users. This incident raises concerns about the security of customer data in online services and highlights the need for companies to regularly update and monitor their plugins for vulnerabilities. Customers affected by this breach should remain vigilant and consider changing their account details as a precautionary measure.

Read Original

The LiteLLM supply-chain attack, linked to a malware known as 'SANDCLOCK,' has compromised credentials in over 2,000 code repositories, significantly impacting sectors such as technology, banking, healthcare, and retail. Researchers from Resecurity estimate that this breach has caused serious security concerns across these industries, as the backdoor allows attackers to manipulate or access sensitive data. The attack's implications are expected to linger, raising alarms about the security of software supply chains. Companies in the affected sectors are urged to assess their security measures and update their systems to prevent further exploitation. The depth of this breach underscores the vulnerabilities inherent in code repositories used by many organizations today.

Read Original

General Electric (GE) and Philips are currently investigating claims that their systems were breached by the Clop ransomware gang, which allegedly stole sensitive data. Both companies have confirmed they are looking into these claims, but specific details about the stolen data or the extent of the breach have not been disclosed. This incident raises concerns about the security of critical infrastructure, particularly given the significant roles both GE and Philips play in healthcare and technology sectors. If the allegations are confirmed, it could have serious implications for patient privacy and operational integrity. The situation is still developing as both companies work to determine the full impact of the breach.

Read Original

The French Ministry of the Economy and Finance has reported a significant data breach involving the General Directorate of Public Finances (DGFiP). An attacker managed to access their systems, compromising the personal data of approximately 678,000 individuals. The stolen information may include sensitive financial details, which could put those affected at risk for identity theft or fraud. This incident raises concerns about the security of government systems and the protection of citizens' data. Authorities are urging individuals to monitor their financial accounts and take precautions against potential misuse of their information.

Read Original
Actively Exploited

SafePal, a cryptocurrency wallet provider, has reported a data breach that has affected approximately 40,000 customers. Hackers took advantage of a vulnerability found in the order-tracking feature of a plugin, allowing them to access sensitive customer information. This breach raises significant concerns for users, as it may expose personal data and financial information. SafePal has not specified what particular data was compromised, but the incident highlights ongoing vulnerabilities within digital wallet services. Users are advised to monitor their accounts for any suspicious activity and take necessary precautions to protect their information.

Read Original
PreviousPage 3 of 49Next