ChipSoft Ransomware Attack - Dutch Hospital Patient Records Software
On April 7, 2026, ChipSoft — a Dutch healthcare IT company providing Electronic Patient Dossier (EPD/HiX) software to approximately 80% of all Dutch hospitals — was hit by a …
Every breach is a lesson. This is the record.
Attackers share tactics. Defenders should too. Browse 3893 documented incidents — attack vectors, malware families, CVEs, and what actually happened.
Total Incidents
Total Financial Loss
AI Incidents
Cloud Incidents
With Attack Vector
Supply Chain Claims
On April 7, 2026, ChipSoft — a Dutch healthcare IT company providing Electronic Patient Dossier (EPD/HiX) software to approximately 80% of all Dutch hospitals — was hit by a …
On approximately 7 April 2026, a Massachusetts healthcare system disclosed it was experiencing a cyberattack that forced the organisation to divert ambulance patients to other …
Bitcoin ATM operator Bitcoin Depot has disclosed a March 23 hack in which attackers stole 50.903 BTC (~$3.67 million) from company wallets. According to the company's disclosure …
In early April 2026, Cisco disclosed that attackers leveraged credentials stolen through the March 2026 Trivy supply chain compromise (attributed to TeamPCP / UNC6780) to penetrate …
The Solana-based Drift defi perpetual futures exchange was exploited for $285 million. The project alerted the community on social media, writing: "Drift Protocol is experiencing …
On April 1, 2026, UNC4736 (North Korean state-sponsored TraderTraitor group) executed a 12-minute, 31-transaction drain of $285 million from Drift Protocol, the largest Solana DeFi …
On March 31, 2026, Sapphire Sleet (a North Korean state-sponsored threat actor tracked by Microsoft) published two malicious versions of axios (1.14.1 and 0.30.4) to npm. Axios is …
On March 27, 2026 at 03:51 UTC, TeamPCP published two unauthorized malicious versions of the Telnyx Python SDK (4.87.1 and 4.87.2) to PyPI. Both versions were quarantined by 10:13 …
On March 27, 2026, TeamPCP (a threat group also linked to the European Commission cloud breach) compromised PyPI publishing credentials for LiteLLM, a widely used open-source …
On March 26, 2026, the Qilin ransomware group (described as Russian-speaking and both financially and politically motivated) attacked Die Linke, a left-wing democratic socialist …
New York City Health + Hospitals — the largest public health system in the US, serving approximately 1.4 million patients annually — notified patients of data exposure from two …
The LiteLLM PyPI supply chain attack by TeamPCP involved a cascading attack chain: TeamPCP first compromised the Trivy security scanner's GitHub Actions CI/CD pipeline (March 19, …
In late March / early April 2026, Hasbro Inc. — the US toy and entertainment conglomerate (maker of Monopoly, Transformers, My Little Pony, Magic: The Gathering, Dungeons & …
In late March 2026, Handala — an Iranian state-linked hacktivist group that has previously conducted operations attributed to Iran's IRGC — published photographs and alleged …
After a November 2025 exploit in which $110 million was drained from the Balancer defi protocol, the company behind the project has announced it will shut down. Besides the massive …
The Moonwell lending protocol faced a governance attack on its deprecated Moonriver instance that could have drained $1 million from the project. Because Moonwell's MFAM governance …
The Resolv USD stablecoin, also known as USR, lost its intended dollar peg and dropped to around $0.14 after an exploiter was able to mint and sell tens of millions of unbacked …
In March 2026, an attacker exploited a vulnerability in Resolv Protocol — an Ethereum-based decentralised finance (DeFi) stablecoin protocol — to mint approximately $24 million in …
On March 21, 2026, as the second step in its cascading supply chain campaign, TeamPCP used PATs stolen during the March 19 Trivy/Aqua Security GitHub Actions compromise to target …
On March 20, 2026, the WorldLeaks extortion gang breached a third-party digital system used by the Los Angeles City Attorney's Office to transfer legal discovery documents. The LA …
A multi-month cyberespionage campaign targeted a Libyan oil refinery in 2026, using commodity (commercially available) malware to maintain persistent covert access for intelligence …
On March 20, 2026, attackers used compromised credentials to access Bitcoin Depot's digital asset settlement accounts and transfer 50.903 BTC (valued at approximately $3.665 …
AppsFlyer — one of the world's largest mobile attribution platforms, with its SDK embedded in thousands of iOS and Android applications including crypto wallets and fintech apps — …
A Washington State-based employee benefits administrator notified approximately 2.7 million individuals of a data breach. The firm provides employee benefits enrollment, …
On March 19, 2026, ShinyHunters obtained an AWS API key belonging to the European Commission's cloud environment via a prior compromise of the open-source security tool Trivy. This …
On March 19, 2026, TeamPCP (tracked by Google GTIG as UNC6780) began the first stage of a cascading multi-tool supply chain campaign by exploiting a misconfigured GitHub Actions …
The Interlock ransomware group exploited a maximum-severity vulnerability in Cisco adaptive security appliances (ASA) or Firepower Threat Defense (FTD) firewalls, gaining …
In the weeks following Stryker's March 2026 Handala wiper attack (documented separately), multiple lawsuits were filed against Stryker as the Iranian-linked Handala group continued …
On March 17, 2026, identity protection firm Aura disclosed a data breach after ShinyHunters used targeted vishing to compromise a single employee's account. The attacker had access …
The BNB Chain's Venus Protocol lending protocol accumulated $2.15 million in bad debt after an exploiter manipulated the price of the Thena protocol's THE token. THE had very low …
On March 16, 2026, CareCloud (a Somerset, NJ-based healthcare IT company) detected unauthorized access to one of its six EHR environments. The threat actor had access for …
Approximately a month after halting deposits and withdrawals, citing liquidity issues and "recent market and financial conditions", the American crypto lender BlockFills has filed …
On March 12, 2026, a threat actor gained access to Crunchyroll's customer support ticketing system after compromising an Okta account belonging to an employee of Telus Digital, …
A trader using the Aave interface attempted to swap $50 million USDT for AAVE. However, due to the enormous size of the order, the purchase had dramatic impact on the aave price. …
On March 11, 2026, the Iran-linked hacktivist group Handala (a persona of Void Manticore, affiliated with Iran's Ministry of Intelligence and Security) wiped between 80,000 and …
Users of the Aave defi lending protocol who had borrowed from the wstETH/stETH pool suffered erroneous liquidations when a price oracle from Chaos Labs reported an inaccurately low …
A thief exploited a smart contract belonging to the Gondi NFT platform to steal 78 NFTs priced at $230,000. Perhaps the most shocking part of the theft is that the attacker managed …
The US Department of Health and Human Services Office for Civil Rights (HHS OCR) issued a $10,000 civil monetary penalty to a dental practice management software vendor responsible …
Trizetto Provider Solutions (a Cognizant subsidiary providing healthcare billing, revenue cycle management, and claims processing services to hospitals and physician practices) …
The Solv Protocol bitcoin defi lending and staking platform disclosed an exploit that they said affected fewer than ten users, but nevertheless netted the attacker 38 SolvBTC (a …
An August 2025 ransomware attack on the University of Hawaii Cancer Center's research study data systems was disclosed in early 2026 as affecting approximately 1.2 million …
After a thief drained a crypto wallet of 4 million PRTG (notionally priced at $4.9 million, but highly illiquid) after blundering Korean tax officials posted the wallet's seed …
On approximately 31 March 2026, a California-based maker of implantable orthopedic devices disclosed it had been the victim of a cybersecurity incident. DataBreachToday reported …
In early 2026, the Dutch Ministry of Finance (Ministerie van Financiën, also known as Rijksfinancien) disclosed a cybersecurity breach, details of which were reported in …
In early April 2026, a data leak affecting approximately 450,000 Lloyds Banking Group customers was reported, with details emerging in DataBreachToday's weekly breach roundup. …
In March 2026, UNC6426 demonstrated a sophisticated attack chain converting a stolen developer GitHub Personal Access Token (from the 2025 nx npm supply chain compromise) into full …
In April 2026, ShinyHunters disclosed that they had breached Anodot (an Israeli AI analytics company acquired by Glassbox in November 2025), maintaining access 'for some time.' By …
In early 2026, Bithumb — South Korea's largest cryptocurrency exchange with approximately $1 billion in daily trading volume and over 8 million registered users — suffered a …
In March 2026, US federal law enforcement seized four web domains associated with Handala's Iranian online leak infrastructure, days after Handala published materials it claimed to …
On February 26–27, 2026, the Qilin ransomware gang listed Malaysia Airlines on its dark web leak site. Unlike its typical practice, the group published no file samples, data cache …
When Korean authorities posted a photograph of seized cash and other items from a police raid, they included photos of cards containing crypto wallet seed phrases, which were …
UFP Technologies — a Massachusetts-based manufacturer of single-use medical device components, specialty packaging, and protective solutions for healthcare — disclosed a data theft …
PayPal disclosed a data breach and associated fraud incident caused by a coding error in its payment application. The error allowed unauthorized access to a subset of user account …
Step Finance announced that, following a $30 million theft in late January, the project would be shutting down. Along with it, they will shut down SolanaFloor — a Solana-focused …
A lending pool operated by YieldBlox on the Stellar blockchain was emptied of around $10.2 million in an oracle manipulation attack on the Reflector oracle supplying prices for the …
IoTeX, a platform to connect IoT devices to blockchain networks, lost around $2 million after a private key compromise enabled an attacker to drain funds from the project's token …
Federal authorities arrested Christopher Alexander Delgado, the CEO of Goliath Ventures (previously Gen-Z Ventures). According to the charging documents, what Delgado presented to …
On February 19, 2026, the University of Mississippi Medical Center (UMMC) detected a ransomware attack that forced the closure of all 35 of its clinic locations statewide. Hospital …
Staff members working for South Korean prosecutors, for some reason, decided to use a "wallet checking tool" during an August 2025 audit of seized crypto assets. The tool they …
Kettering Health (an Ohio-based health system operating multiple hospitals and care sites) was notifying current and former patients of data exposure resulting from an Interlock …
On February 17, 2026, the FBI began investigating abnormal activity in an unclassified system — DCS-3000 (known as Red Hook), part of its Digital Collection System Network (DCSNet) …
After an oracle misconfiguration, the Moonwell defi lending protocol accumulated $1.78 million in bad debt. When the protocol showed that cbETH was priced at just over a dollar, …
The Chicago-based institutional crypto lending firm BlockFills has halted deposits and withdrawals, citing "recent market and financial conditions" and a desire to "further the …
On the weekend of February 7–8, 2026, ShinyHunters breached Odido's (Netherlands' largest mobile network operator) customer contact system and downloaded records for approximately …
The South Korean cryptocurrency exchange Bithumb disclosed that it had accidentally given its customers more than 620,000 BTC (~$44 billion) in a promotional event gone wrong. …
On February 6, 2026 (starting at ~03:29 AM EST), a ransomware attack hit BridgePay Network Solutions, a payment gateway serving merchants, municipalities, and integrators. The …
In early 2026, the former Nuance Communications IT worker responsible for the Geisinger Health patient data breach (documented separately) faced additional federal charges. The …
Gemini, the cryptocurrency exchange founded and run by Cameron and Tyler Winklevoss, will lay off as many as 200 employees globally. The news came amid an announcement that the …
Harvard University and the University of Pennsylvania were named as victims and had data leaked by ShinyHunters, the prolific hack-and-leak group responsible for numerous …
Between February 4–7, 2026, threat actors used a compromised Okta SSO account to access Hims & Hers' Zendesk support instance and exfiltrate customer support tickets. The breach …
On February 3, 2026, security researcher Jeremiah Fowler discovered three unsecured publicly exposed databases during routine Shodan scans, containing 4.3 terabytes of data linked …
Capital Health — which operates capital health hospital and clinical facilities in New Jersey and Pennsylvania — agreed to pay $4.5 million to settle claims arising from a LockBit …
In February 2026, ShinyHunters breached CarGurus (a major US online automotive marketplace) via social engineering. After CarGurus declined to pay ransom, the data was published …
LexisNexis, the major legal research and information services platform used extensively by law firms, government agencies, and courts, confirmed a data breach in early 2026. …
Hackers exploited a bug in smart contracts deployed by the defi protocol CrossCurve to steal an estimated $3 million across multiple blockchains. The thief was able to spoof …
The Solana-based defi portfolio tracker Step Finance lost 261,854 SOL (~$28.7 million) when a thief gained access to treasury and fee wallets. It's not yet clear how the attacker …
Since January 31, 2026, researchers identified at least 72 malicious Open VSX extensions linked to the GlassWorm campaign. On January 30, 2026, four established Open VSX extensions …
An ambulance billing and medical collections firm agreed to pay $515,000 to Massachusetts and Indiana attorneys general following a hack that compromised patient data. The firm …
In 2025, a Maryland-based firm providing AI-powered services (identity or background verification) was hacked, with the breach disclosed in early 2026 affecting approximately 3.1 …
An attacker exploited a bug in an Aperture Finance smart contract to steal at least $3.4 million from users who had enabled "instant liquidity management" features. Aperture …
Some users of Matcha Meta, a decentralized exchange aggregator on the Base blockchain, suffered losses after a thief exploited a vulnerability in its SwapNet integration. SwapNet …
Two crypto thieves decided to settle an argument over who was wealthier by screensharing as they transferred crypto between wallets to prove ownership. In doing so, one of them — …
The Department of Government Efficiency (DOGE) — the advisory body established by the Trump administration — was reported to have transferred sensitive Social Security …
Electronic health records vendor Veradigm (formerly Allscripts Healthcare Solutions, rebranded 2022) agreed to pay $10.5 million to settle a class-action lawsuit arising from a …
The Saga project halted its blockchain after acknowledging that $7 million had been stolen. An attacker was evidently able to mint a large quantity of Saga Dollar tokens, though …
The Minnesota Department of Human Services notified approximately 304,000 people — primarily Medicaid and public benefits recipients — of a data breach involving a third-party …
Law enforcement agencies raided two suspected members of the Black Basta ransomware group and announced they are actively seeking the group's leader(s). Black Basta has been one of …
Between January 19 and February 11, 2026, attackers used phishing pages cloning the Starbucks Partner Central portal to steal employee credentials. Starbucks detected the …
Shortly after losing his campaign for re-election as mayor of New York City, Eric Adams announced he would be launching "NYC Token". He's pitched the project as a fundraising tool …
A crypto holder has lost $282 million in bitcoin and litecoin after a scammer impersonating a customer support employee for the Trezor hardware wallet manufacturer successfully …
In January 2026, ShinyHunters breached Crunchbase (a major business intelligence and startup data platform) via vishing — attackers impersonated internal employees to …
On January 9, 2026, Betterment (a major US robo-advisor and investment platform) suffered a data breach after ShinyHunters used vishing to compromise IT support at a third-party …
A bug in a smart contract belonging to the Ethereum-based Truebit project allowed an attacker to steal 8,535 ETH (~$26.4 million). The thief targeted one of the project's older …
On January 29, 2026, ShinyHunters posted data allegedly stolen from Bumble (dating app) and Match Group (parent of Tinder, Hinge, OkCupid) on a dark web leak site. ShinyHunters …
Figure Technology Solutions (fintech lending company) disclosed in February 2026 that ShinyHunters conducted a vishing (voice phishing) attack against an employee in January 2026, …
Telus Digital (Canadian BPO providing outsourced customer support, content moderation, and AI services) confirmed a multi-month breach on March 12, 2026. ShinyHunters claimed …
In early 2026, security researchers and government agencies disclosed a new cyberespionage campaign by hackers tied to Russia's GRU military intelligence agency (Fancy Bear / APT28 …
On New Year's Eve 2025/2026, the TridentLocker ransomware-as-a-service (RaaS) group claimed an attack on Sedgwick Government Solutions, a subsidiary of Sedgwick that provides …
Unleash Protocol, a project promising to allow creators to register their intellectual property on the blockchain, has been exploited for around $3.9 million. An attacker was able …
The Flow blockchain suffered an exploit in which an attacker was able to mint a large number of wrapped FLOW tokens, which they then swapped to tokens on other blockchains. …
On December 26, 2025, an unauthorized actor exfiltrated data from Eurail B.V.'s (European rail pass operator covering 33 national railways) AWS S3, Zendesk, and GitLab instances. …
The Trust Wallet Chrome extension was compromised in an apparent supply chain attack. People who used the non-custodial wallet extension after it updated to version 2.68 lost funds …
Navia Benefit Solutions, an employee benefits administration company, suffered a data breach due to a BOLA (Broken Object Level Authorization) API vulnerability. An unknown threat …
On December 20, 2025, a threat actor called 'Lovely' posted a 2.366 million-record database from WIRED.com on the Breach Stars forum, selling access for approximately $2.30. …
A crypto trader lost almost $50 million in the Tether stablecoin after falling victim to an address poisoning attack. Because blockchain wallet addresses are long, random …
Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH …
In December 2025, ShinyHunters breached SoundCloud via vishing — attackers convinced employees to provide access to an ancillary service dashboard. SoundCloud confirmed the breach …
Ribbon Finance, which has partially rebranded to Aevo, has lost $2.7 million after attackers exploited a vulnerability in the smart contract for legacy Ribbon vaults that enabled …
Binance has announced that the company has suspended an employee who used the platform's official Twitter accounts to promote a memecoin they had launched. The token, called "year …
Ethereum validators running the Prysm consensus client lost around 382 ETH ($1.18 million) after a bug resulted in delays that caused validators to miss blocks and attestations. …
On January 4, 2026, the Crimson Collective threat group publicly claimed via Telegram to have breached Brightspeed (a major US fiber broadband provider) and stolen records for over …
Ledger (hardware crypto wallet manufacturer) disclosed in January 2026 that an unnamed unauthorized party accessed a Global-e cloud system used to process international orders. …
Cegedim Santé (French healthcare software provider) confirmed on March 3, 2026, that attackers stole 15.8 million administrative patient records from its MonLogicielMedical …
In 2025, Customers of 74 banks and credit unions served by Marquis Software Solutions experienced a data security incident via a third-party vendor relationship. The compromised …
In 2025, Freedom Mobile experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, PornHub experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …
In 2025, Shuffles (Pinterest app) experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …
Yearn Finance, a defi yield protocol, has suffered another hack. The exploiter took advantage of bugs in the project's smart contract to drain assets from several of its pools by …
The Korean cryptocurrency exchange Upbit suffered a loss of around $30 million in various Solana-based assets due to a hack. Some entities have suggested that Lazarus, a North …
Hackers breached Mixpanel, a third-party analytics vendor used by OpenAI to track user behavior on its API platform, on November 26, 2025. The breach exposed data belonging to …
Attackers redirected users intending to visit the websites for the decentralized exchanges Aerodrome and Velodrome to their own fraudulent versions using DNS hijacking, after …
On November 21, the Cardano blockchain suffered a major chainsplit after someone created a transaction that exploited an old bug in Cardano node software, causing the chain to …
An attacker stole approximately $3.1 million from the BNB chain-based GANA Payment project. The thief laundered about $1 million of the stolen funds through Tornado Cash shortly …
Amid a month of falling crypto prices, the crypto tracking platform DappRadar has announced it will be shutting down after seven years of operation. "Running a platform of this …
A holder of around 14.4 million ADA (~$6.9 million), the token for the Cardano network, made an expensive error when attempting to swap the tokens for a stablecoin. Because the …
SitusAMC (a financial technology provider serving 1,500+ clients including major US banks, real estate firms, and insurers) became aware of a breach on November 12, 2025, and …
Cybernews researchers discovered on November 11, 2025, that IDMerit (a US identity verification and KYC/AML services provider) had left a MongoDB database publicly exposed without …
A former Coupang employee maintained unauthorized access to the company's systems and exfiltrated customer data, with the breach continuing until November 8, 2025. Coupang (South …
After the defi yield platform Stream Finance announced a $93 million loss, Elixir announced it would be discontinuing its deUSD synthetic stablecoin. Stream Finance owes $68 …
The Stream Finance defi yield project announced that "an external fund manager overseeing Stream funds disclosed the loss of approximately $93 million in Stream fund assets." …
The Moonwell lending protocol, built on the Base Ethereum L2, wound up with $3.7 million in bad debt after an attacker took advantage of an oracle malfunction that caused the price …
The defi protocol Balancer suffered a major exploit that drained over $110 million across several blockchains, including Ethereum, Polygon, Base, and Sonic. Attackers exploited …
In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted extortion, alleging theft of 343 GB of data. In January 2026, data for approximately …
Freedom Mobile, one of Canada's largest wireless carriers (owned by Shaw/Rogers), disclosed in December 2025 that a third-party vendor had been compromised, resulting in the …
Marquis Software Solutions, a provider of core banking and analytics software to community banks and credit unions across the United States, disclosed in December 2025 that a …
In 2025, Checkout.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, Iberia (International Airlines Group) experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party …
In 2025, Logitech experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, Terminalen A/S experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was DocuBizz. Source reporting: …
In 2025, The Washington Post experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Oracle E-Business Suite. Source …
In 2025, OpenAI experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …
In early November 2025, the US Congressional Budget Office (CBO) detected and confirmed a cyberattack by a suspected foreign actor. US officials briefed CNN that Chinese …
The Garden bitcoin bridge suffered a roughly $11 million loss after one of its solvers was compromised. These solvers essentially act as market makers for the protocol. Some …
On October 25, 2025, an unauthorized third party gained access to DoorDash's internal systems after successfully social engineering a company employee. The number of affected …
The Canadian cryptocurrency exchange Cryptomus has been fined CA$177 million (US$127 million) by the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) for …
Nevada's Financial Institutions Division has issued a cease and desist order against Fortress Trust, stating that the firm is "on the verge of insolvency". The company admits it …
Iberia, the Spanish national airline and subsidiary of IAG (International Airlines Group), disclosed in November 2025 that a third-party vendor breach had exposed loyalty programme …
In late 2025, Mixpanel, a widely-used product analytics SaaS platform, suffered a breach that exposed user behavioral data from dozens of customer companies. Confirmed affected …
Paxos, the issuer of PayPal's PYUSD stablecoin, accidentally minted 300 trillion of the supposedly dollar-pegged token. For context, this is approximately 2.5x the global GDP, and …
An attacker apparently obtained access to a victim's private key, enabling them to drain $21 million in various crypto assets. The attacker quickly bridged the stolen funds to ETH, …
In their third major hack in two years, the Abracadabra defi lending project lost $1.8 million of their Magic Internet Money stablecoin. An attacker took advantage of a bug in the …
In October 2025, Discord disclosed that an unnamed third-party customer service provider had been breached, exposing data for approximately 55 million Discord users. The exposed …
In October 2025, DocketWise (a cloud-based immigration case management platform for law firms) discovered that credentials to one of its third-party partner repositories had been …
The Washington Post disclosed in November 2025 that a breach of its Oracle E-Business Suite ERP system had exposed sensitive personal and financial data for approximately 10,000 …
In 2025, Discord experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, MANGO experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, Renault and Dacia UK experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source …
In November 2025, OpenAI disclosed that customer data had been exposed via Mixpanel, its third-party product analytics platform. OpenAI had shared user behavioral data with …
On October 1, 2025, the cybercrime group Crimson Collective disclosed a breach of Red Hat's consulting GitLab instance, claiming to have exfiltrated 570 GB of data from over 28,000 …
In 2023, there was no shortage of buzzy press coverage for Futureverse, which promised to build a metaverse and gaming-focused blockchain. They partnered with Ready Player One …
Exploiters drained $782,000 in crypto assets from two markets on the Hyperdrive lending protocol, which is built on the Hyperliquid layer-1 blockchain. The attacker apparently took …
Only days after the Hypervault yield farming platform announced on Twitter that they'd surpassed $5 million in total value locked, the platform suddenly shut down its website and …
Crypto sleuth zachxbt observed $21 million in "suspicious outflows" from SBI Crypto, a crypto mining subsidiary of the Japanese SBI Group. The money was quickly laundered through …
One day after Griffin AI launched its GAIN token on Binance Alpha, an attacker minted 5 billion fake GAIN tokens on the Ethereum blockchain, then exploited a cross-chain endpoint …
An attacker exploited bridges for SFUND, the token issued by the Seedify launchpad and incubator. It appears the exploiter has profited around $1.7 million from the theft. Seedify …
The "AI-powered web3 social platform" UXLINK was exploited by an attacker that gained control of the project's multisignature wallet, then minted billions of the project's UXLINK …
Between September 17 and September 23, 2025, an unauthorized actor exploited an unknown vulnerability in Insightin Health's GoAnywhere managed file transfer tool, gaining access to …
MANGO, the Spanish global fashion retailer, disclosed in October 2025 that a third-party marketing provider had been compromised, exposing customer data. Exposed information …
On September 14, 2025, the first malicious packages of the Shai-Hulud self-replicating worm appeared in the npm ecosystem. By September 16, over 180 packages were confirmed …
The YU bitcoin-backed stablecoin lost its intended dollar peg after what they described as "an attempted attack", later writing that there was an "unauthorized transfer of funds". …
A bridge for Shibarium, the layer-2 network for the Shiba Inu project, was exploited for approximately $2.4 million in funds. The attacker bought 4.6 million BONE tokens (the …
John-Paul Thorbjornsen, the founder of Thorchain and Vultisig, suffered a wallet drain, reportedly after experiencing a video meeting scam from an attacker who had exploited the …
Thieves stole 192,600 SOL (~$41.5 million) from a wallet belonging to the Swiss cryptocurrency exchange SwissBorg. The attack is being blamed on a vulnerability in the API of Kiln, …
After a JavaScript developer's NPM account was compromised in a phishing attack, attackers used it to upload malicious versions of heavily used JavaScript color and debugging …
On September 8, 2025, 18 widely used npm packages were compromised via an account takeover of maintainer 'qix'. Affected packages collectively receive 2.6+ billion downloads per …
The Nemo Protocol on the Sui blockchain suffered a $2.4 million exploit. The defi yield infrastructure protocol acknowledged the theft shortly after, explaining they had paused the …
The Bunni decentralized exchange was exploited for approximately $8.4 million across the Unichain Ethereum layer 2 network and the Ethereum mainnet. Bunni acknowledged the theft …
A user of the Venus Protocol borrowing and lending platform was successfully phished by an attacker who gained access to their account and drained $13.5 million in stablecoins and …
In September 2025, SwissBorg, a Swiss crypto asset management platform, lost approximately $41 million worth of Solana (SOL) after threat actors compromised Kiln, the third-party …
In September 2025, ShinyHunters exploited a vulnerability in Wynn Resorts' Oracle PeopleSoft platform to access employee records. The breach was discovered in February 2026. …
Renault and Dacia UK disclosed in October 2025 that a third-party vendor had been compromised, exposing data for UK customers. Exposed information included customer names, gender, …
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows. On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack …
Page not found – Agility PR Solutions. We use cookies to improve your experience. If that's okay, select "I Agree" to consent to all cookies. You can also customize your …
Salesforce / Drift Security Incident | BeyondTrust. BeyondTrustâs Privileged Access Management platform protects your organization from unwanted remote access, stolen …
Third-party company: Drift (Salesloft).
Update: Bugcrowd Response to Salesloft Drift Third-Party Security Event | @Bugcrowd. We want to share an update to our blog post regarding the recent unauthorized access to …
In 2025, Cato Networks experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Chess.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, ContentSquare experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, CyberArk Software Ltd. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source …
In 2025, Dynatrace LLC. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Employment and Social Development Canada (ESDC) experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was 2Keys …
In 2025, Ericom Software experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Esker experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, HackerOne experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Harrods experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, LiveRamp experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, London North Eastern Railway (LNER) experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. …
In 2025, Omada experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, OneSpan experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Palo Alto Networks experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Pantheon experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Proofpoint experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Qualys, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Sigma Computing experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Sophos Ltd. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Sprout Social, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, SpyCloud, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Stellantis experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Salesforce. Source reporting: …
In 2025, SwissBorg experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Kiln. Source reporting: …
In 2025, Tenable, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Wealthsimple experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …
In 2025, Workiva experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Cloudflare experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Elasticsearch B.V. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Fastly experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
In 2025, Workday experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …
On August 31, 2025, an unknown ransomware group attacked the University of Hawaii Cancer Center's Epidemiology Division, compromising research servers (clinical operations were not …
Beginning August 31, 2025, the 'Scattered Lapsus$ Hunters' alliance — a cybercrime consortium of Scattered Spider (initial access/social engineering), LAPSUS$ …
From August 28 to September 21, 2025, an individual affiliated with a licensed healthcare provider accessed the Minnesota Department of Human Services' MnCHOICES disability …
Three years after launching "Collectible Avatars", the NFT project they didn't want to call "NFTs" because they were already becoming kind of cringe, Reddit has decided to pull the …
The PulseChain-based defi project BetterBank was exploited by an attacker who took advantage of a vulnerability that allowed them to mint arbitrary tokens, some of which they then …
Unauthorized access to Insight Hospital and Medical Center's (Chicago) network occurred between August 22 and September 11, 2025. The hospital issued a substitute notice on January …
A bitcoin holder reportedly fell for a social engineering attack after receiving communications from scammers posing as customer support for a crypto exchange and hardware wallet …
London North Eastern Railway (LNER), the UK train operator serving the East Coast Main Line between London King's Cross, Edinburgh, and Aberdeen, disclosed in September 2025 that a …
Wealthsimple, a major Canadian online investment and financial services platform, disclosed in September 2025 that a third-party vendor had been compromised, resulting in the …
Marquis Software Solutions, a marketing and compliance services vendor to 700+ US financial institutions, was hit by Akira ransomware on August 14, 2025. Threat actors exploited a …
The Turkish cryptocurrency exchange BtcTurk has apparently been hacked again, as various blockchain security firms observed suspicious withdrawals estimated at around $49 million. …
Monero, a privacy-focused blockchain network, has been undergoing an attempted 51% attack — an existential threat to any blockchain. In the case of a successful 51% attack, where a …
Odin.fun, a bitcoin-based memecoin launchpad sort of like the popular pump.fun, was exploited for 58.2 BTC (~$7 million). The attacker had apparently manipulated the price of …
On August 9, 2025, the INC Ransom ransomware group attacked the Pennsylvania Office of the Attorney General, knocking its website, email, and phone lines offline for approximately …
The Cl0p ransomware group exploited CVE-2025-61882, a critical CVSS 9.8 zero-day unauthenticated remote code execution vulnerability in Oracle E-Business Suite (EBS), beginning as …
Between August 8–18, 2025, threat actors tracked as UNC6395 exploited compromised OAuth tokens from the Salesloft Drift integration to gain unauthorized access to connected …
Scammers using AI-generated YouTube videos to promote supposedly profitable crypto bot software have convinced crypto users to deploy what is, in reality, malicious code that …
A group of crypto enthusiasts promoting a memecoin have claimed responsibility for a string of incidents in which neon green sex toys were thrown onto professional women's …
On August 4, 2025, Bouygues Telecom — France's third-largest mobile phone carrier — detected a cyberattack. The company publicly disclosed the breach on August 6-7, 2025. …
The defi lending protocol Credix lost $4.5 million to an exploit after a hacker gained control of an admin wallet and used it to mint tokens and drain liquidity pools.Credix …
Beginning in August 2025, attackers exploited CVE-2025-61882 (a zero-day in Oracle E-Business Suite) to breach the University of Phoenix's network and steal sensitive data. The …
In September 2025, the Canadian government disclosed that 2Keys Corporation, a digital identity and authentication service provider contracted by multiple federal agencies, had …
Chess.com, the world's largest online chess platform with over 100 million registered users, disclosed in September 2025 that a third-party file transfer provider had been …
In September 2025, Harrods, the iconic London luxury department store, disclosed that a third-party vendor had been compromised, exposing contact details for online customers. …
Criminal background checker APCS faces data breach. Exclusive: The attack first affected an upstream provider of bespoke software. Exclusive A leading UK provider of criminal …
JFrog Help Center. JFrog documentation has moved to a new and improved site at docs.jfrog.com. The Help Center will continue to serve as your dedicated hub for Support and FAQ …
Salesloft Drift application incident response. Read Lucidâs response to a recent security incident that affected the Drift application, which involved CRM data across numerous …
Megaport Trust Center | Powered by SafeBase. See how Megaport manages their security program with SafeBase. Welcome to the Megaport Trust Center, where we demonstrate our …
Dermatology Clinics Affected by Practice Management Company Data Breach. Several dermatology practices have recently announced data breaches following an attack on their management …
Pi-hole discloses data breach triggered by WordPress plugin flaw. Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed …
Salesforce-Connected Third-Party Drift Application Supply Chain Incident Response. We use cookies to improve your experience, analyze traffic, and personalize content. Some are …
Hundreds of Swedish municipalities impacted by suspected ransomware attack on IT supplier. A suspected ransomware attack on a Swedish software provider is believed to have impacted …
Salesloft Drift Data Breach: What We Know and What We're Doing. Hackers breached Salesloft in a major data theft campaign, stealing OAuth and refresh tokens linked to the Drift AI …
Cyber-attack on MoD-linked contractor exposes data of Afghans in resettlement scheme. Breach at Inflite The Jet Centre is latest in series of leaks involving private information of …
Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s. Zscaler swiftly mitigates a security incident impacting Salesloft Drift, and ensuring robust protection against …
Air France and KLM disclose data breaches impacting customers. Air France and KLM announced on Wednesday that attackers had breached a customer service platform and stolen the data …
Fashion giant Chanel hit in wave of Salesforce data theft attacks. French fashion giant Chanel is the latest company to suffer a data breach in an ongoing wave of Salesforce data …
Cisco discloses data breach impacting Cisco.com user accounts. Cisco has disclosed that cybercriminals stole the basic profile information of users registered on Cisco.com …
Farmers Insurance data breach impacts 1.1M people after Salesforce attack. U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with …
Update: Salesloft’s Drift Integration Security Incident Impacting Some PagerDuty Salesforce Data. Per our August 29 post, we were notified in late August that PagerDuty (and our …
Pandora confirms data breach amid ongoing Salesforce data theft attacks. Danish jewelry giant Pandora has disclosed a data breach after its customer information was stolen in the …
TransUnion suffers data breach impacting over 4.4 million people. Consumer credit reporting giant TransUnion warns it suffered a data breach exposing the personal information of …
The Abra cryptocurrency lender sent an email to customers announcing that "Abra Earn international services are currently paused, effective immediately", attributing the decision …
TransUnion disclosed on August 28, 2025, that unauthorized actors accessed a third-party application serving its US consumer support operations between July 28–30, 2025. The attack …
A hacker stole RARE tokens priced at around $731,000 after exploiting a vulnerability in a staking contract for the SuperRare NFT platform. The attacker funded the exploiter wallet …
The City of St. Paul, Minnesota (state capital) suffered a ransomware attack beginning July 25, 2025. The city shut down all networks on August 11 after confirming it was …
Attackers who compromised devices belonging to a WOO X employee stole $14 million from users of the Taiwanese WOO X cryptocurrency exchange. The phishing attack on the employee …
The Indian cryptocurrency exchange CoinDCX was hacked, with attackers stealing around $44 million. The company announced the breach the following day, attributing it to a …
The BigONE cryptocurrency exchange was hacked for more than $27 million, which the hacker quickly swapped for various other tokens. The attacker compromised one of the exchange's …
On July 16, 2025, threat actors gained access to a third-party cloud CRM (Salesforce) used by Allianz Life Insurance of North America via social engineering/vishing. Attackers used …
The Arcadia Finance defi margin protocol was exploited for $3.5 million after an attacker found a vulnerability in a project smart contract. The attacker quickly swapped the stolen …
In a seizure request filed by the DC Attorney General, the Justice Department outlined how a Nigerian scammer used the classic "lowercase Ls look like uppercase Is" trick to steal …
The price of Kinto's $K token suddenly crashed 90%, sparking accusations of a rug pull. A tranche of investor tokens had just been unlocked recently, leading some to speculate that …
The decentralized perpetual exchange GMX has been exploited for $42 million. The exploit involved a vulnerability in one version of the exchange's price calculation smart contract. …
An attacker exploited the Solana-based lending protocol Texture, stealing $2.2 million in user funds from one of the project's vaults.Shortly after the attack, Texture sent a …
On July 9, security researchers at VennBuild and other firms disclosed a "critical backdoor" affecting thousands of smart contracts, which one of the researchers said left "over …
On July 2–3, 2025, the SafePay ransomware group exfiltrated files from Ingram Micro's internal repositories. Ingram Micro (a leading global IT distributor processing ~$15B in …
700Credit — the largest provider of credit reporting, identity verification, fraud and compliance services for US automotive dealerships — suffered a data breach between …
In July 2025, McDonald's disclosed a breach affecting approximately 64 million job applicants whose data was stored on systems operated by Paradox, Inc., McDonald's third-party …
A code update error in PayPal's Working Capital loan application exposed approximately 100 customers' personally identifiable information from July 1 to December 13, 2025 — …
Air France-KLM, the Franco-Dutch multinational airline group, disclosed in August 2025 that their Salesforce CRM environment had been compromised as part of the …
In August 2025, TransUnion confirmed it had been affected by the ShinyHunters/Scattered Spider Salesforce social engineering campaign, with limited personal information exposed for …
Massive data breach confirmed by Allianz Life. U.S. life insurance firm Allianz Life had most of its 1.4 million customers' data compromised following a data breach this month, …
Louis Vuitton says regional data breaches tied to same cyberattack. Luxury fashion giant Louis Vuitton confirmed that breaches impacting customers in the UK, South Korea, and …
'123456' password exposed chats for 64 million McDonald’s job chatbot applications. Cybersecurity researchers discovered a vulnerability in McHire, McDonald's chatbot job …
Qantas confirms data breach impacts 5.7 million customers. Australian airline Qantas has confirmed that 5.7 million people have been impacted by a recent data breach, in which …
Texas Centers for Infectious Disease Associates Announces 19K-Record Data Breach. Data breaches have recently been announced by Texas Centers for Infectious Disease Associates, …
Kelly Benefits says 2024 data breach impacts 550,000 customers. Kelly & Associates Insurance Group (dba Kelly Benefits) is informing more than half a million people of a data …
In July 2025, Qantas Airways (Australia's flag carrier) suffered a Salesforce data breach attributed to ShinyHunters/Scattered Lapsus$ Hunters via a vishing campaign. Approximately …
Cisco confirmed in August 2025 that it had been affected by the ShinyHunters Salesforce social engineering campaign. Exposed data included names, addresses, user IDs, email …
Pandora (Danish jewelry brand) and Chanel (French luxury fashion house) both disclosed in August 2025 that their Salesforce CRM environments had been compromised as part of the …
Stellantis, the multinational automotive manufacturer (maker of Jeep, Chrysler, Fiat, Peugeot, and other brands), disclosed in September 2025 that a breach via its Salesforce …
An attacker was able to exploit a vulnerability in a smart contract used by the Resupply stablecoin lender to extract about $9.3 million from the project. After depositing around …
Christian Nieves, a New York man who goes by the handles "daytwo" and "PawsOnHips", has reportedly stolen more than $4 million through a theft ring where he impersonates Coinbase …
On June 19, a company called Aza Ventures published allegations on Telegram that they had been scammed by someone promising to facilitate OTC sales of steeply discounted tokens for …
Web3 cybersecurity firm Hacken had a cybersecurity incident of their own when the private key belonging to a wallet with mint access for the project's $HAI token was leaked. …
The Iran-based Nobitex cryptocurrency exchange suffered a $90 million hack, and the attacker has also promised to imminently release data and source code from the platform. The …
An attacker exploited a vulnerability in the staking contract for Meta Pool, which is a liquid staking project. This allowed them to mint 9,700 mpETH, the project's liquid staking …
On June 12, 2025, Aflac insurance company's US network was compromised via social engineering. The attack is attributed to Scattered Spider, a financially motivated …
ALEX Lab lost $8.3 million in various currencies after an attacker exploited a flaw in the project's smart contracts that allowed them to create a malicious token. They drained a …
The Taiwanese cryptocurrency exchange BitoPro disclosed that they had suffered a theft from one of their hot wallets, which they said occurred during a system upgrade in which they …
Between June and August 2025, unauthorized actors accessed Prosper Marketplace's customer databases by exploiting compromised credentials. Prosper (a San Francisco-based …
In October 2025, Scattered Lapsus$ Hunters published 63.62 GB of data (23+ million records) from Vietnam Airlines' Salesforce CRM system. The initial intrusion occurred around June …
Coinbase breach tied to bribed TaskUs support agents in India. A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from …
Glasgow City Council impacted by ‘cyber incident’. The Glasgow City Council announced that it was affected by an incident “disrupting a number of online services and which may have …
MainStreet Bank reports vendor cyber incident that leaked customer info. In regulatory filings with the Securities and Exchange Commission, MainStreet Bank's holding company said a …
More than 5 million affected by data breach at healthcare tech firm Episource. California-based Episource disclosed in filings with the U.S. Department of Health and Human Services …
Switzerland says government data stolen in ransomware attack. The government in Switzerland is informing that sensitive information from various federal offices has been impacted …
On May 29, 2025, hackers breached a third-party vendor system used by Farmers Insurance Exchange and its subsidiaries. Farmers was alerted to the suspicious activity on May 30, …
Cork Protocol, a defi project aimed at "tokenizing the risk of depeg events for stablecoins and liquid (re)staking tokens", suffered a $12 million loss after an attacker exploited …
An attacker stole $223 million from the Sui-based Cetus Protocol. The project announced shortly after that $163 million of the funds had been frozen, leaving around $60 million …
Kettering Health, an Ohio health system running 14 medical centers and dozens of clinics primarily in the Dayton area, was hit by Interlock ransomware on May 20, 2025. …
Covenant Health (Catholic healthcare network serving Massachusetts, Maine, New Hampshire, Pennsylvania, Rhode Island, and Vermont) detected unauthorized activity on May 26, 2025, …
The website and Twitter accounts belonging to the Curve Finance defi projects were compromised in quick succession. On May 5, an attacker compromised the Twitter account belonging …
On May 4, 22-year-old Zerebro founder Jeffy Yu published a blog post introducing "legacoins" — a version of memecoins he said would be used to "define the legacy" of those who had …
UK Legal Aid Agency investigates cybersecurity incident. The Legal Aid Agency (LAA), an executive agency of the UK's Ministry of Justice that oversees billions in legal funding, …
Magento supply chain attack compromises hundreds of e-stores. A supply chain attack involving 21 backdoored Magento extensions has compromised between 500 and 1,000 e-commerce …
Adidas warns of data breach after customer service provider hack. German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and …
Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people. Hospitals tied to the two companies announced breaches over the last week …
Marks & Spencer confirms customer data stolen in cyberattack. M&S said that some customer data — but not payment card details or passwords — had been breached in a recent …
Chinese hackers breach US local governments using Cityworks zero-day. Chinese-speaking hackers have exploited a now-patched Trimble Cityworks zero-day to breach multiple local …
Nationwide Recovery Service Data Breach Victim List Grows: 560,000+ Individuals Affected. The list of victims from the data breach at the debt collection agency Nationwide Recovery …
Sharp HealthCare, a major integrated regional health system in San Diego, California, disclosed in June 2025 that a breach at Episource, its third-party healthcare risk adjustment …
The DragonForce ransomware cartel exploited three vulnerabilities in SimpleHelp RMM software (disclosed January 2025) to breach a managed service provider (MSP) and then pivot to …
3,250 BTC (~$330 million) were apparently stolen from a bitcoin holder and then quickly moved through multiple exchanges and swapped for the Monero privacycoin. Such a massive swap …
After trading — and prices — surged in Bitget's market for the thinly traded video game token VOXEL, the company has accused a "professional arbitrage" group of "improperly" …
A new Solana-based defi protocol called Loopscale, backed by Coinbase Ventures and Solana Labs, suffered a $5.8 million exploit only two weeks after its launch. The stolen funds …
The Ethereum-based lending project Term Finance lost $1.6 million when an oracle misconfiguration resulted in unintended liquidations. The team later announced that they had …
Beginning around April 22, 2025, Scattered Spider (also tracked as UNC3944 and Octo Tempest) attacked Marks & Spencer, the UK's largest clothing retailer, by socially engineering …
SK Telecom (South Korea's largest mobile carrier, ~27 million subscribers) officially confirmed a breach on April 19, 2025, after detecting malware on April 18 targeting its Home …
Between April 17–22, 2025, an unknown threat actor accessed files at an unnamed third-party service provider used by Ericsson Inc. (US operations). The investigation concluded in …
Victims, mostly in Nigeria and Kenya, have lost approximately $12 million to a Ponzi scheme called CBEX, which was named to mimic an association with the China Beijing Equity …
An attacker compromised an admin account belonging to the ZKsync Ethereum layer-2 project, which is built by Matter Labs. By doing so, they were able to steal approximately $5 …
KiloEx, a decentralized perpetual futures exchange, was exploited for $7.5 million. An attacker executed an oracle manipulation attack on KiloEx's pricing smart contracts to steal …
Mantra's $OM token price suddenly crashed by around 90%, with the project's supposed "market cap" shrinking by around $5 billion in the span of hours. Mantra is a layer-1 …
The stablecoin issued by First Digital, FDUSD, has lost its $1 peg and sunk as low as $0.76 before returning to around $0.97 — which, in stablecoin world, is still a substantial …
Scattered Spider (UNC3944) affiliates acting as DragonForce ransomware-as-a-service operators conducted a wave of attacks against UK retailers in April–May 2025. Co-op confirmed …
In May 2025, Adidas disclosed that a data breach had occurred via an unnamed third-party customer service provider. The breach exposed customer contact information including names, …
In May 2025, the UK Legal Aid Agency (part of the Ministry of Justice) disclosed a significant data breach affecting information on 2,000 legal service providers and their clients. …
Office of the Maine AG: Consumer Protection: Privacy, Identity Theft and Data Security Breaches. Home > Consumer Information > Privacy, Identity Theft and Data Security Breaches > …
Ascension discloses new data breach after third-party hacking incident. Ascension, one of the largest private healthcare systems in the United States, is notifying patients that …
In 2025, âRoyal Mail experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Spectos GmbH. Source reporting: …
In May 2025, Nationwide Recovery Services (NRS), a healthcare billing and accounts receivable management vendor, disclosed a data breach affecting over a dozen healthcare provider …
The zkLend lending platform was hoping they could secure the return of stolen funds from the attacker who stole 3,667 ETH (~$9.5 million at the time) from the platform in …
A project called "ICERAID" has emerged, promising to reward "intelligence gathering" on "suspicious activities" by photographing supposedly criminal behavior by undocumented …
In late March 2025, a threat actor claimed to have stolen approximately 144GB of data from Royal Mail by compromising Spectos GmbH, a data analytics vendor used by Royal Mail for …
A Coinbase customer reportedly lost 400 BTC (~$35 million) in a scam identified by blockchain sleuth zachxbt. While investigating the massive theft from the single customer, he …
While many crypto firms have escaped enforcement actions from federal regulators thanks to massive industry lobbying, state enforcers are still on the beat. Crypto investment firm …
HyperLiquid's Hyperliquidity Provider market making vault suffered a $13.5 million loss after an alleged market manipulation incident involving a memecoin called JELLYJELLY. A …
Bets on the Polymarket platform where the outcome is not clear are resolved using an oracle system called UMA, or Universal Market Access. Holders of the UMA token participate in a …
An attacker using a flash loan attack stole $13 million in the Magic Internet Money token from the Abracadabra project. The attack was enabled by a bug in the platform's smart …
DaVita Inc., one of the largest kidney dialysis providers in the US, disclosed a ransomware attack on April 12, 2025. Intrusion began March 24, 2025 and was eradicated April 12. …
Binance announced on Twitter that they had fired an employee after discovering that they had engaged in insider trading. The employee took a large position in a token that he knew …
RWA restaking platform Zoth suffered a $8.29 million hack after an attacker gained access to admin privileges that allowed them to modify the platform's smart contracts. The hacker …
After suffering an $183,000 loss to an attack in February, the BNB-based Four.Meme memecoin launchpad has been hacked again, this time for around $130,000. Four.Meme aims to be …
CVE-2025-22457 is a stack-based buffer overflow in Ivanti Connect Secure. Ivanti initially classified it as a low-risk DoS-only vulnerability and patched it 11 February 2025 in …
Yale New Haven Health System, a Connecticut-based health system affiliated with Yale School of Medicine, detected unauthorized network access on March 8, 2025. The health system …
Zoth, a restaking platform for "real world assets" (or RWAs), was hacked for around $285,000 when an exploiter discovered a bug in the platform's collateral calculations. This …
An attacker exploited a smart contract belonging to the 1inch DEX aggregator, stealing $5 million in the USDC stablecoin and wETH. According to the platform, the vulnerability …
Data breach at Japanese telecom giant NTT hits 18,000 companies. Japanese telecommunication services provider NTT Communications Corporation (NTT) is warning almost 18,000 …
Thousands of public school workers impacted by cyberattack on retirement plan administrator. A December 2024 cyberattack on a prominent administrator for retirement plans has …
StreamElements Confirms Third-Party Data Breach from an Infostealer Infection. Stay informed with the latest insights in our Infostealers weekly report. Explore key findings, …
Oracle Health breach compromises patient data at US hospitals. A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole …
Berkeley Research Group (BRG), a major consulting and financial advisory firm, suffered a ransomware attack discovered March 2, 2025. Unauthorized activity occurred February 28 – …
The Wemix Foundation, which runs the blockchain gaming platform WEMIX, suffered a $6.2 million hack of their blockchain bridge. Although the hack occurred on February 28, the …
A plaintiff named Mandar Mirashi has filed a lawsuit against an unknown defendant accused of stealing around $40 million in bitcoin through a sophisticated phishing attack and/or …
Suji Yan, the founder of the Mask Network, suffered the loss of more than $4 million in various cryptocurrency assets to an apparent wallet hack. According to Yan, the theft …
Around $49.5 million in the USDC stablecoin was stolen from the Infini crypto-focused "stablecoin neobank", a fintech company that promises "financial freedom" by "democratizing …
On February 21, 2025, Bybit (Dubai-based cryptocurrency exchange) suffered the largest cryptocurrency theft ever recorded: $1.46 billion in Ethereum stolen from a cold wallet. …
In what is looking like largest ever theft from a cryptocurrency exchange, attackers took control of a hot wallet belonging to the Bybit cryptocurrency exchange and moved a massive …
Around $400,000 in ETH was stolen from around 9,000 wallets on the Abstract layer-2 network, which is built by the same company that makes the Pudgy Penguins NFTs. It appears that …
Opexus, a Thoma Bravo-owned software company providing records management services to nearly every US federal agency, was compromised by twin brothers Muneeb and Suhaib Akhter who …
StreamElements, a platform for live streaming tools and creator merchandise, disclosed in March 2025 that a third-party vendor breach had exposed customer data. The breach …
Anne Arundel Dermatology (a Maryland-based multi-site dermatology practice) disclosed a data breach affecting approximately 1.9 million individuals. Attackers maintained …
A tweet from Argentina's president Javier Milei promoted a memecoin called Libra, which he described as a "private project [that] will [be] dedicated to encouraging the growth of …
The Starknet-based lending platform zkLend was exploited for around $9.5 million. zkLend paused the protocol after the attack was discovered, and began working with various crypto …
A BNB Chain memecoin platform, Four.Meme, announced on Twitter that they were "currently experiencing a malicious attack". The team briefly paused a portion of the service while …
A former FTX customer made an expensive mistake in October 2023 when he transferred 2,000 SOL (~$64,000 at the time, almost $400,000 today) to an old FTX account, about a year …
Crypto sleuth zachxbt has accused the popular American cryptocurrency exchange Coinbase of "fail[ing] to stop its users losing $300M+ per year to social engineering scams". He …
Scattered Spider (UNC3944) gained initial access to M&S systems as early as February 2025 via social engineering of the third-party IT service desk (vishing/impersonation). …
Accendo Insurance Company Affected by Business Associate Data Breach. Data breaches have recently been announced by Accendo Insurance Company, Menorah Life, Humboldt Independent …
Background check and drug testing provider DISA Global Solutions reports data breach. Houston-based employee screening company DISA Global Solutions says a 2024 data breach exposed …
GrubHub data breach impacts customers, drivers, and merchants. Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of …
Russian officials warn of potential compromise of major tech services provider. In an unusual public disclosure, the Russian government said that subsidiaries of LANIT, a major …
Over 1 Million Patients Affected by Community Health Center Data Breach. Community Health Center, a nonprofit healthcare provider in Middletown, Connecticut, has notified more than …
Cyberattack on River Region Cardiology Affects Up to 500,000 Individuals. Cyberattacks have been reported by River Region Cardiology in Alabama and Delta County Memorial Hospital …
The creator of the AlleyCat Solana-based cryptocurrency project has reportedly taken about 600 SOL (~$130,000) raised during the project's presale and transferred it to gambling …
In late January, the creator of the "dogwifhat" memecoin announced "Officially confirmed. Viva hat vegas." in a tweet accompanied by a photo overlaying the dog meme with the Las …
A suite of software tools called DogWifTools was popular among memecoin creators looking to rug pull unsuspecting traders. By helping token creators mask supply control and fake …
A Ethereum-based project promising to duplicate the bitcoin leveraged investment strategy used by MicroStrategy has announced that, prior to even launching, 165 ETH (~$535,850) was …
Ross Ulbricht, the founder of the Silk Road darknet market place, earned a presidential pardon on January 21 as an apparent thank you by President Trump to the Libertarian Party. …
A project called "Tsotchke" has convinced a lot of people to buy up its token based on claims that it uses "spin-based quantum computing" to "enable quantum-enhanced AI at room …
Unauthorised access to Western Sydney University's systems via the SSO service occurred between 28 January and 25 February 2025. Approximately 10,000 current and former students …
On January 27, 2025, Frederick Health Medical Group (a Maryland-based healthcare network with 25+ locations) announced a ransomware attack that compromised the protected health …
Episource LLC, a medical coding and risk adjustment company and Optum/UnitedHealth Group subsidiary, detected a ransomware intrusion on February 6, 2025, after unauthorized access …
The KuCoin cryptocurrency exchange has pleaded guilty to a charge filed against them in March that they were operating an unlicensed money transmitting business. Since at least …
The Singapore-based Phemex cryptocurrency exchange has acknowledged the compromise of some of the exchange's hot wallets, which saw outflows of at least $37 million across multiple …
The ThorChain project is in crisis amid news that the project is insolvent. In order to prevent what would effectively be a bank run and likely death spiral, the project has paused …
Richard Kim, the founder of the Zero Edge crypto casino, resigned on July 2, 2024 after blowing most of the project's seed funding. Kim was a former executive of Galaxy Digital, …
On or after January 22, 2025, a threat actor used stolen credentials to access legacy Cerner electronic health record (EHR) servers belonging to Oracle Health that had not yet been …
Between January 21 and February 5, 2025, the Medusa ransomware group exfiltrated data from SimonMed Imaging (a large US radiology/medical imaging provider). Medusa claimed more …
A Twitter account called @TrumpDailyPosts has more than 1.3 million followers on Twitter. While the account does automatically crosspost to Twitter any posts Donald Trump makes on …
Starting January 20, 2025, operatives associated with the Department of Government Efficiency (DOGE), led by Elon Musk, were granted unprecedented access to sensitive federal …
Reverand Lorenzo Sewell, a pastor and vocal Trump supporter who delivered the benediction at Donald Trump's inauguration, followed in his hero's footsteps by trying to shill a …
Before people had a chance to process the fact that the incoming president of the United States had just launched his own transparent crypto cash-grab, the soon-to-be First Lady …
Ryan Fournier, a co-founder of the Students for Trump organization, worked with a memecoin creator to create a $TIKTOK memecoin, which he said was intended to celebrate TikTok …
In what is likely a preview of the levels of grift about to come — levels previously not thought possible — Trump has launched a Solana memecoin two days before his inauguration. …
The Digital Currency Group has agreed to settle with the SEC for $38 million over charges that its Genesis subsidiary misled investors. When the hedge fund Three Arrows Capital …
Citing "ongoing market challenges and funding difficulties", the MakersPlace NFT platform announced it will be shutting down after six years of operations. The company had raised …
Although BitMEX had previously tried to argue that they should not face additional penalties after being fined $110 million in 2024 for Bank Secrecy Act violations, a judge has …
Only hours after Sony launched its "Soneium" layer-2 Ethereum blockchain, the company was accused of "rugging" people who had purchased various memecoins launched on Soneium when …
An attacker noticed a vulnerability in a smart contract for The Idols, an NFT project that also incorporates ETH staking functionality. They discovered that a function used to …
Holders of any of the several thousand "AO ArtBall" NFTs may be disappointed as the Australian Open appears to have abandoned the project aimed at tennis fans. The first NFTs …
The UniLend project, which advertises itself as a "unified platform for all things AI and defi", was exploited for almost $200,000. An attacker was able to take advantage of a bug …
The hosts of the Bankless crypto podcast have landed in hot water after selling off some of the substantial quantities of $AICC tokens they were allocated as investors in the …
New York Attorney General Letitia James announced a lawsuit against a group of scammers operating a scheme in which they promised fake job opportunities to victims, convincing them …
A self-described crypto banker from Hengelo, Netherlands was arrested in connection to an alleged crypto pyramid scheme he'd been running. He'd originally told police that he was …
The Moby Trade defi options protocol suffered a $1 million loss, narrowly avoiding the loss of another nearly $1.5 million. The project team stated that a hacker had "identified …
The Arbitrum-based liquidity management project Orange Finance suffered at least $840,000 in losses after hackers compromised the project's admin address, then used it to upgrade …
A man who received an inheritance in 2021 and decided to put it into crypto lost his entire $100,000 balance when he fell victim to a spoofing site in 2023. When he decided to …
Tata Technologies, a Tata Group subsidiary providing engineering and technology services in automotive, aerospace, and industrial sectors (12,500+ employees, operating in 27 …
Starting in approximately early 2025, cybercriminals recruited and bribed several customer support agents employed by TaskUs, Coinbase's outsourced support provider operating from …
PowerSchool hack exposes student, teacher data from K-12 districts. Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat …
294,000 Allegheny Health Network Patients Affected by Business Associate Cyberattack. Allegheny Health Network (AHN), a Pittsburgh-based 14-hospital academic medical system, has …
Texas utility firm investigating potential leak of customer data tied to 2023 MOVEit breach. A large Texas energy company confirmed it is investigating reports of stolen customer …
Billing Support Vendor Notifies 701K Patients About December 2023 Data Breach. Medusind, a Florida-based revenue cycle management vendor and practice management software provider, …
Russian telecom giant Rostelecom investigates suspected cyberattack on contractor. Russia's Rostelecom said that it was responding to a cyberattack on a contractor that helps to …
Frederick Health Recovering from Ransomware Attack. Frederick Health in Maryland is investigating a ransomware attack, Holdrege Memorial Homes in Nebraska has mailed notification …
380,000 Impacted by Data Breach at Cannabis Retailer Stiiizy. This website stores cookies on your computer. These cookies are used to improve your website experience and provide …
TalkTalk investigates breach after data for sale on hacking forum. UK telecommunications company TalkTalk is investigating a third-party supplier data breach after a threat actor …
In January 2025, TalkTalk, the UK telecommunications provider, disclosed that a data breach had occurred via CSG Ascendon, its third-party subscriber management and billing …
In May 2025, security researchers disclosed that three Magento extension vendors — Tigren, Meetanshi, and MGS (Mageplaza) — had their extension distribution servers compromised. …
Beginning in early 2025, threat actors exploited CVE-2025-0994, a critical deserialization vulnerability in Trimble Cityworks, to compromise GIS asset and work-order management …
Attackers bribed at least one overseas customer support agent contracted through third-party vendor TaskUs to access and steal Coinbase customer data from internal support systems. …
By 2025-2026, documented evidence shows AI is systematically accelerating cyberattack timelines and lowering barriers to entry for attackers, while defenders face structural …
By 2025-2026, AI-powered identity theft had emerged as a major and growing threat category, representing a structural shift in how identity fraud and credential theft are conducted …
In March 2025, a threat actor known as 'rose87168' advertised on BreachForums the sale of approximately 6 million records allegedly stolen from Oracle Cloud's federated SSO login …
Otelier data breach exposes info, hotel reservations of millions. Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage …
Grubhub detected unusual activity traced to a compromised third-party contractor account in early 2025. The contractor had access to internal systems used for customer care. Stolen …
After crypto sleuth zachxbt noticed an apparent theft from the NoOnes peer-to-peer crypto trading platform on January 1, CEO Ray Youssef was forced to acknowledge the theft. He …
By 2025-2026, documented case studies from Darktrace, CrowdStrike, Palo Alto Networks Unit 42, and Microsoft MSTIC demonstrate that the most advanced attackers are executing …
The "Feed Every Gorilla" project has once again been hacked, after suffering a pair of flash loan attacks in May 2022 amounting to $1.9 million in losses. The protocol also …
The SEC has levied a $123 million fine against Jump Crypto subsidiary Tai Mo Shan, which was part of a secret deal with Terraform Labs to help prop up the floundering Terra …
PowerSchool, the dominant K-12 student information system provider serving approximately 16,000 schools and 50 million students in North America, suffered a data breach beginning …
Attacker (later identified as Massachusetts college student Matthew D. Lane, 19) used compromised credentials to access PowerSchool's PowerSource support portal on 19 December …
Gabriel Hay and Gavin Mayo, two LA-based NFT creators, have been charged for defrauding investors of more than $22.4 million through a series of NFT rug pulls and other crypto …
CVE-2025-0282 is an unauthenticated stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways enabling remote code execution. Mandiant identified …
A crypto holder tweeted at the Ledger hardware wallet manufacturer to report that 10 BTC (~$1 million) and "~1.5m of NFTs" had been stolen from a Ledger wallet they were using. …
The US-based cryptocurrency exchange Kraken has been fined AU$8 million (US$5.1 million) for illegally offering margin trading to Australian customers. The firm had offered the …
The CFTC has filed suit against Francier Obando Pinillo, an American former pastor who targeted his former congregants and other unsophisticated investors with a crypto pyramid …
Clober, a DEX built on Coinbase's Base Ethereum layer-2, suffered an exploit only about a week after its launch. A re-entrancy bug in the project allowed an attacker to siphon …
Users of the Alpaca Finance lending protocol suffered losses when the protocol's sloppy oracle implementation finally resulted in consequences. Although many had warned the project …
Monroe University, a New York-based for-profit university, suffered a cyberattack between December 9 and December 23, 2024, in which threat actors exfiltrated data on 320,973 …
An 85-year-old painter from Brooklyn was convinced to send scammers $135,000 after they promised they would sell his artwork as NFTs on OpenSea. After agreeing to have a supposed …
Who could have guessed that buying up a token based around the long-past-its-expiration-date hawk tuah meme might turn out to be an unwise investment? Haliey Welch, the originator …
The popular Ultralytics YOLO AI/ML library (60M+ downloads, 30K+ GitHub stars) was backdoored on 4 December 2024. Versions 8.3.41, 8.3.42, 8.3.45, and 8.3.46 deployed XMRig to mine …
An attacker was able to compromise an account that had publish access for the official Solana web3.js library, which is widely used by dApps to read and write from the Solana …
Nike will be shutting down its RTFKT "virtual collectibles" project at the end of January 2025, according to an announcement made in early December. Nike had acquired RTFKT in 2021 …
Hertz Corporation disclosed in April 2025 that customer data had been stolen in attacks exploiting Cleo managed file transfer (MFT) software vulnerabilities in approximately …
Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss. A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach …
Gastroenterology, Cardiology, and Nursing Care Providers Suffer Cyberattacks. Cyberattacks have recently been announced by Connecticut GI and Gastroenterology Associates of …
Rhode Island confirms data breach after Brain Cipher ransomware attack. Rhode Island is warning that its RIBridges system, managed by Deloitte, suffered a data breach exposing …
Colonial Behavioral Health & Veterans Health Administration Patients Affected by Ransomware Attacks. Colonial Behavioral Health and a medical transcription service provider used by …
Californian Hospitals Continue to be Disrupted by Thanksgiving Ransomware Attacks. Over Thanksgiving weekend, Watsonville Community Hospital and PIH Health in California fell …
Ascension Health disclosed in April 2025 a second security incident, separate from the May 2024 Black Basta ransomware attack. This breach involved a former business partner that …
In early 2025, the HellCat-affiliated threat actor 'Rey' exfiltrated 6.5 GB of data (12,000 files) from Orange Romania's back-office systems, resulting in exposure of over 600,000 …
The Clipper decentralized exchange suffered a $450,000 exploit across two Ethereum layer-2 chains. Although some speculated that the issue may have been a private key leak, Clipper …
Krispy Kreme detected unauthorized IT activity 29 November 2024; disclosed via SEC 8-K 11 December 2024. Online ordering disrupted. Play ransomware gang claimed attack in December; …
On November 28, cryptocurrency exchange XT.com abruptly suspended withdrawals, citing a "wallet upgrade and maintenance". However, after a blockchain security firm identified $1.7 …
On November 20, 2024, an unauthorized party gained access to a single employee account and computer within the Southeast Series of Lockton Companies' network — one of the largest …
A 13-year-old known as the "Gen Z Quant kid," created a token called QUANT and executed a rug pull, making $30,000. In retaliation, various people in the cryptocurrency world …
DEXX, a platform that advertises itself as the "first memecoins trading terminal application", disclosed that it had been hacked when it posted a message on social media addressed …
The Fantom-based Polter Finance defi project was exploited for $7 million when an attacker was able to perform an oracle manipulation attack. By artificially increasing the price …
The Thala Labs Aptos-based defi project suffered a $25.5 million theft when an attacker exploited a vulnerability in one of their smart contracts. They paused related smart …
Clop ransomware group exploited CVE-2024-50623 in Cleo's MFT products starting November 2024, bypassing the initial patch. Huntress identified active exploitation 3 December 2024 …
The DeltaPrime defi protocol was hacked for the second time in two months, losing $4.8 million in Arbitrum and Avalanche tokens. The attacker appeared to have exploited a flaw in …
After apparently exhausting all his other options, a trader has put out a call to "all skilled hackers and white hats out there" to help him recover 7,912 Renzo staked ETH (ezETH) …
Legends International, a major entertainment venue management and premium services company, detected unauthorized activity on November 9, 2024. The company manages venue services …
Crypto-powered poker website CoinPoker was apparently exploited for around $2 million when an attacker was able to compromise a hot wallet controlled by the platform. The attacker …
INC Ransom breached Ahold Delhaize USA (parent of Stop & Shop, Food Lion, Giant Food, Hannaford, and The Giant Company) between 5-6 November 2024, stealing up to 6 TB of data. …
Hot wallets used by the MetaWin crypto casino were drained of around $4 million. According to the company's CEO, the attacker "t[ook] advantage of our frictionless withdrawal …
Italian Serie A football club Bologna FC was attacked by RansomHub in November 2024. RansomHub claimed to have stolen 200 GB of data including player contracts, passports, …
Hellcat ransomware group breached Schneider Electric's internal Atlassian Jira project tracking platform in November 2024, stealing over 40 GB of compressed data including 75,000 …
ARC Community Services, a Wisconsin-based nonprofit providing community living and support services for people with intellectual and developmental disabilities, announced a …
Data Breaches Reported by Hopscotch; Athenahealth; Central Resources. Hopscotch Health Management has learned that a bad actor accessed the physical records of almost 5,000 …
Young people’s data feared stolen in cyberattack on French government contractor. The French government said an incident directly impacted an unnamed service provider used by the …
Nokia investigates breach after hacker claims to steal source code. Nokia is investigating whether a third-party vendor was breached after a hacker claimed to be selling the …
Presbyterian Healthcare Services & ORM Fertility Patients Affected by Data Breaches. Oregon Reproductive Medicine, doing business as ORM Fertility, has announced a security breach …
Ransomware attack on software supplier disrupts operations for Starbucks and other retailers. A ransomware attack that hit a major software provider last week caused disruptions …
TriHealth Physician Partners Confirms Patient Data Exposed in Cyberattack. Cyberattacks have recently been announced by TriHealth Physician Partners in Ohio and Harmac Medical …
Schneider Electric confirms dev platform breach after hacker steals data. Schneider Electric has confirmed a developer platform was breached after a threat actor claimed to steal …
Finastra (London-based fintech serving 45 of the world's top 50 banks and 8,100+ financial institutions in 130 countries) had its SFTP platform accessed between 31 October and 8 …
Attackers were able to inject malicious code into the popular "LottieFiles" JavaScript animations library. Visitors to websites using the library saw a prompt to connect their …
The UAE-based M2 cryptocurrency exchange was hacked for $13.7 million in bitcoin, ether, and Solana tokens. The exploiter compromised several of the exchange's hot wallets to take …
A perpetuals trading platform called Sunray Finance was hacked on October 30 by an attacker who was able to upgrade a smart contract used by the protocol. They then were able to …
More than $20 million in stablecoins and Ethereum were transferred from a wallet identified as belonging to the US government, and holding funds connected to the 2016 hack of the …
A dog-themed memecoin project called Sharpei abruptly cashed out $3.4 million, tanking the token price by more than 96% in seconds. The project had been promoted by crypto …
Sometime in 2023, blockchain firm Forte acquired game studios Phoenix Labs and Rumble Games. However, it would be a year before this came to light, because according to a report …
From 22 October 2024, Midnight Blizzard targeted thousands of users across 100+ organizations in government, academia, defense, and NGOs in UK, Europe, Australia, and Japan. Emails …
Conduent, a company providing payment processing and document services to major health insurers and state government programs, was breached by the SafePay ransomware group. …
An unauthorized third party had access to Conduent Business Services' systems from October 21, 2024, to January 13, 2025, when operational disruption was triggered. Conduent …
The defi lending protocol Tapioca DAO was exploited after an attacker reportedly socially engineered the DAO's co-founder and gain access to their private key. The attacker then …
On 16 October 2024, attackers executed transferOwnership on Radiant Capital's Pool Provider contract using 3 collected malicious signatures, gaining control of all lending pool …
The cryptocurrency lending project Radiant Capital was hacked for the second time in under a year, this time for more than $50 million in the USDC stablecoin, wBNB, ETH, and other …
Cosmos creator Jae Kwon has raised concerns about a portion of the Cosmos protocol called the "Liquid Staking Module" after learning it was developed by North Korean agents. …
An attacker using the permit phishing technique stole $1.39 million in tokens from an unsuspecting holder. The victim unknowingly signed a "Permit2" signature — a function intended …
Datadog Security Labs identified a coordinated supply chain attack campaign (tracked as MUT-8694) active from at least October 10, 2024, targeting both the npm and PyPI package …
Casio, the Japanese electronics and watchmaking company, suffered a ransomware attack on October 5, 2024. The Underground ransomware group claimed responsibility on October 10, …
Around 1.67 million EIGEN tokens belonging to an investor in the popular Ethereum-based EigenLayer project were stolen after the investor was tricked into transferring the tokens …
American Water Works, the largest regulated water and wastewater utility in the United States (serving 14+ million people across 14 states), detected unauthorized activity in its …
Threat actor 'Satanic' posted on BreachForums on 21 October 2024 claiming 350 million Hot Topic user records (figure likely inflated); confirmed data set is ~730 GB covering Hot …
Stiiizy, a major California-based cannabis brand and retailer, disclosed in January 2025 that a breach via its unnamed third-party POS system provider in approximately October 2024 …
ADT discloses second breach in 2 months, hacked via stolen credentials. Home and small business security company ADT disclosed it suffered a breach after threat actors gained …
More Than 909,000 Individuals Affected by Cyberattack on New York IT Services Provider. ATSG Inc., an IT services company headquartered in New York, has recently reported a …
Comcast says customer data stolen in ransomware attack on debt collection agency | TechCrunch. The ransomware attack on a U.S. debt collection agency also affects customers of CF …
Rackspace monitoring data stolen in ScienceLogic zero-day attack. Cloud hosting provider Rackspace suffered a data breach exposing "limited" customer monitoring data after threat …
38,000 Individuals Affected by Center for Urban Community Services Cyberattack. Security breaches have been reported by the Center for Urban Community Services in New York, …
US Bitcoin ATM operator Byte Federal (which operates 1,200+ ATMs nationwide) was breached on 30 September 2024 via a GitLab vulnerability but did not detect the incident until 18 …
A victim lost 12,083 spWETH tokens (~$32.4 million) after signing a malicious transaction stemming from someone using wallet drainer software. These drainers are …
Beginning September 28, 2024, an attacker accessed Free's network through VPN credentials using insufficiently robust multi-factor authentication. The attacker connected to MOBO, …
Threat actor (SN_BlackMeta, linked to pro-Palestinian hacktivist movement) defaced archive.org with a JavaScript alert and simultaneously exfiltrated a 6.4 GB SQL file …
A staking platform called Bedrock lost around $2 million after exploiters discovered a bug that allowed them to swap 1 ETH for 1 BTC despite the more than $63,000 difference in …
The Truflation platform suffered a loss of around $5 million after what they described as "an attack using malware". The company acknowledged the attack and limited some of their …
The Onyx protocol was hacked for a second time by attackers taking advantage of known bugs in forks of the Compound Finance project. Projects regularly fail to patch these bugs, …
The Twitter account belonging to OpenAI's news account was compromised and used to "announce" a scam website purporting to announce the $OPENAI token. "All OpenAI users are …
Singaporean cryptocurrency exchange BingX suffered a $52 million loss across a broad range of cryptocurrencies. The thefts occurred across two attacks that were hours apart. The …
MoneyGram, a major international money transfer and payment services company, suffered a data breach September 20–22, 2024 via an IT helpdesk social engineering attack (attributed …
A crypto yield platform called Shezmu suffered a loss of around $4.9 million in $ShezUSD after an attacker exploited a flaw that allowed anyone to mint collateral, which they could …
Between September 19 and November 5, 2024, Serviceaide (an agentic AI-powered IT and workflow management platform based in Santa Clara, CA) left an Elasticsearch database …
Some people use a Telegram-based crypto trading bot called "Banana Gun" to "snipe" crypto trades, copytrade, and perform other activities. On September 19, at least 11 victims lost …
Two people have been arrested in relation to a phishing scam that successfully stole more than 4,000 BTC priced at around $243 million from a single individual. The victim was …
German authorities have seized 47 cryptocurrency exchanges alleged to have been used to launder stolen funds by ransomware groups. The exchanges did not require KYC, allowing …
The website for the Ethena protocol was compromised by attackers who gained control of the project's domain registration. The protocol issued warnings to their users to urge them …
The defi lending protocol Rari Capital, and its three co-founders, have settled charges from the SEC that it misled investors and engaged in unregistered broker activity. Rari …
Texas Tech University Health Sciences Center (TTUHSC) and its El Paso center suffered a ransomware attack in September 2024, claimed by the Interlock group. Combined, 1,465,000 …
The DeltaPrime defi protocol suffered a $6 million loss after a private key was leaked. Access to the private key allowed the attacker to mint 1.1×1069 DPUSDC, which are tokens …
A blockchain-based version of the 2014 hit game Flappy Bird has emerged, taking advantage of the recent "tap-to-earn" crypto craze. The @flappy_bird Twitter account posted "I AM …
A blockchain-based version of the 2014 hit game Flappy Bird has emerged, taking advantage of the recent "tap-to-earn" crypto craze. The @flappy_bird Twitter account posted "I AM …
CCP, the developer of the Eve Online space MMORPG, has angered their fanbase with a new announcement that their upcoming game will be built on the blockchain and incorporate …
The eToro stock and crypto trading platform settled with the U.S. Securities and Exchange Commission on charges that it was operating an unregistered broker and unregistered …
A rare CryptoPunk NFT recently sold for only 10 ETH (~$25,300), despite a market value that's likely around 600 ETH (~$1.5 million). The sale went through thanks to lingering smart …
In May 2022, WeWork founder and former CEO Adam Neumann announced he would be launching a company called Flowcarbon, which would issue "tokenized carbon credits" called "Goddess …
The Indonesian Indodax cryptocurrency exchange suffered an exploit that allowed attackers to steal tokens from several of its hot wallets. The firm did not directly acknowledge the …
An attacker exploited a bug in the smart contract for a BSC-based token called CUT, draining a PancakeSwap liquidity pool of almost $1.45 million in the BSC-USD stablecoin. Total …
Five states have settled with the European crypto firm GS Partners over several crypto investment pyramid schemes. These included one in which the firm sold crypto "vouchers", each …
AssangeDAO was a project created to fundraise for the legal defense of WikiLeaks founder Julian Assange, who has been fighting espionage and computer intrusion charges for over a …
The development team behind friend.tech has officially ditched the crypto-based social media project, which was (very) briefly hailed as a potential platform for influencers to …
Nick Drakon, formerly the CEO of the crypto research and venture capital firm Revelo, announced on Twitter that he was resigning from the company. In the post, he claimed that he …
Robinhood has paid $3.9 million to settle charges from the California Department of Justice that the platform was violating commodities laws. From 2018 to 2022, the popular trading …
Lacoste abruptly shutdown the website, Discord, and Twitter account belonging to "UNDW3", its NFT project. Lacoste launched its original collection of NFTs in June 2022, selling …
The defi protocol Penpie was exploited for 11,113.6 ETH (~$27.3 million) by an attacker who exploited a flaw allowing them to withdraw unearned "rewards". Although the protocol …
The Twitter accounts belonging to Lara and Tiffany Trump were compromised and used to announce a fake launch of the (unfortunately real) World Liberty Financial project that their …
Eighteen months after the crypto-focused algorithmic trading fund Galois Capital shut down, explaining that they had lost around $40 million in the FTX collapse, the SEC has filed …
CMS Notifies Individuals Potentially Impacted by Data Breach | CMS. The Centers for Medicare & Medicaid Services (CMS) and Wisconsin Physicians Service Insurance Corporation (WPS) …
Popular French retailers confirm hackers stole customer data. Targets of the cyberattacks include electronics and home appliances store Boulanger and the retailer Cultura. Several …
Data on nearly 1 million NHS patients leaked online following ransomware attack on London hospitals. The stolen data, which was published in June by the Qilin ransomware gang, …
T-Mobile’s VM logs allegedly leaked in 20 GB Capgemini data breach. The attacker claims to have stolen databases, source code, credentials, private keys, as well as log files …
The London subsidiary of the Industrial and Commercial Bank of China (ICBC), the world's largest bank by assets and a Chinese state-owned financial institution, was attacked by …
Scattered Spider attacked Transport for London on 31 August 2024, ultimately exposing data of approximately 10 million customers — one of the largest breaches in British history. …
The popular defi lending platform, Aave, suffered a smart contract exploit that allowed an attacker to steal around $56,000. A smart contract outside of the core Aave protocol, …
OpenSea has announced that they received a Wells notice from the U.S. Securities and Exchange Commission, warning them of a likely lawsuit from the agency. According to CEO Devin …
Brothers Jonathan and Tanner Adam were charged with violating the antifraud provisions of the federal securities laws with their GCZ Global and Triten Financial Group entities, …
The Texas-based Rhodium Enterprises bitcoin mining company has filed for bankruptcy, disclosing debts between $50 and $100 million and total assets between $100 and $500 million. …
The SEC charged the Abra cryptocurrency lending platform with failing to register the offers and sales of its retail crypto asset lending product, Abra Earn, and with operating as …
Some fans of the Polygon blockchain, or those looking for help with using it, suffered losses after hackers successfully compromised the project's Discord server. Discord hacks …
RansomHub (ransomware-as-a-service operation, launched February 2024) attacked Halliburton. Detected 21 August 2024; SEC 8-K filed 23 August 2024. Production planning and shipment …
McDonald's Instagram account, as well as the Twitter account of a McDonald's marketing director, began promoting a memecoin called $GRIMACE (named for the restaurant chain's blobby …
Someone holding almost $55.5 million in the DAI stablecoin was apparently phished, signing a transaction to reassign ownership of their DAI stash to a phishing address. The victim …
Shan Hanes, the former CEO of the Kansas Heartland Tri-State Bank, was sentenced to 293 months (24 years, 5 months) imprisonment after pleading guilty to embezzlement by a bank …
Roman Ziemian, a co-founder of the alleged crypto pyramid scheme FutureNet, was arrested in Montenegro, where he was living under a false identity. He had previously been arrested …
Between 17-19 August 2024, unauthorized third parties exploited two newly created Fidelity customer accounts to access personal data of 77,099 customers including Social Security …
After encountering issues trading his cryptocurrency holdings on Coinbase, a man in his 60s decided to contact Coinbase support for help. He Googled "Coinbase" and clicked on a …
In January 2023, Twitch streamer DNP3 issued a statement admitting that he had gambled away investor funds while chasing losses. "Eventually I lost everything. In addition to my …
Following a lawsuit from the New York Attorney General in June, the SEC has filed a lawsuit against the promoters of the NovaTech crypto pyramid scheme and affinity fraud. Cynthia …
AutoCanada, a publicly traded North American automotive dealership group operating 84 franchised dealerships, detected a ransomware attack on August 11, 2024. Hunters International …
FTX will pay $8.7 billion in restitution and another $4 billion in disgorgement to settle the lawsuit from the CFTC, which was filed shortly after FTX collapsed in November 2022. …
According to blockchain investigator zachxbt, North Korean developers using fake identities were able to steal $1.3 million from a cryptocurrency project after pushing malicious …
A judgment has been issued in the long-running case against Ripple by the SEC, and the company has been fined $125 million for violations of securities laws in its institutional …
The Ronin bridge, which bridges crypto assets to the Ronin Network used by Axie Infinity and other gaming projects, has once again suffered a breach — though a considerably smaller …
Surprising just about no one, a wallet holding around 20% of the supply of the $DJT Trump-themed memecoin suddenly dumped its holdings, crashing the token price by around 90%. The …
The CFTC has sent a subpoena to Hit Network, the crypto media company that was previously headed up by Ben "BitBoy" Armstrong until his rather public meltdown. According to The …
An attacker took advantage of a flaw in the code for the yield farming project ConvergenceFi, draining it of all the tokens that had been allocated for staking emissions. Because a …
Hacker wipes 13,000 devices after breaching classroom management platform. A hacker has breached Mobile Guardian, a digital classroom management platform used worldwide, and …
Ransomware Hackers Steal Medical Insurance Data of 1M People. Young Consulting, which develops software for the stop-loss insurance market, is notifying 1 million individuals that …
Cyberattack on Help at Home Affects 26,700 Current & Former Patients. Data breaches have been reported by Help at Home, Kinsler Family Dentistry, ParkTree Community Health Center, …
Ransomware attack on Indian payment system traced back to Jenkins bug. Researchers at Juniper Networks analyzed the recent breach of the National Payments Corporation of India …
Six Healthcare Providers Added to Ransomware Data Leak Sites. Recent reports by Rapid7 and Guidepoint Security indicate the number of active ransomware groups has increased in …
Toyota confirms third-party data breach impacting customers. Toyota confirmed that customer data was exposed in a third-party data breach after a threat actor leaked an archive of …
The team behind the Kujira project wound up with around $2 million in bad debt after taking some of their operational funds and using it to make leveraged bets on their own …
American sports gambling behemoth DraftKings announced the shutdown of its Reignmakers NFT game and NFT marketplace, effective immediately. Reignmakers was a fantasy sports game …
Nader Al-Naji, also known as "Diamondhands", was arrested on wire fraud charges relating to his BitCloud crypto social media platform. He was simultaneously charged by the SEC with …
The Starknet-based decentralized exchange ZKX abruptly shuttered operations on July 30, with an announcement from founder Eduard Tur explaining that they had "been unable to find …
A controversial proposal in front of the Compound Finance DAO has narrowly passed, granting 499,000 COMP (~$24 million, and amounting to 5% of the project's treasury) to an outside …
The MonoSwap DEX announced on July 24 that it had been compromised, and urged its users to withdraw their funds to avoid losses. According to the project team, one of their …
Crypto exchange dYdX has announced that the website for their v3 exchange was compromised, and is urging people not to use it. This announcement came almost simultaneously with a …
The operators of a project called ETHTrustFund on Coinbase's Base layer-2 Ethereum blockchain have apparently rug-pulled the project. The ETHTrustFund project was a fork of the …
An apparent misconfiguration by the RHO Markets lending protocol allowed operators of an MEV bot to take $7.6 million from the project's users across multiple chains.In a stroke of …
On 19 July 2024, CrowdStrike released a faulty content configuration update (Channel File 291) to Windows systems running the CrowdStrike Falcon endpoint detection and response …
$234.9 million in crypto assets stolen from Indian exchange WazirX on 18 July 2024. Attributed to North Korea's Lazarus Group by joint US/Japan/South Korea statement in January …
After a $230 million "suspicious transfer", Indian cryptocurrency exchange WazirX has paused withdrawals and acknowledged that one of their multisignature wallets was compromised. …
INC Ransom group (double extortion) gained access 17 July 2024; suspicious activity detected 5 August. All IT systems including EHR taken offline; hospitals reverted to paper …
Travel company Trip.com has some perturbed crypto holders on its hands, after shutting down the "Trekki" NFT project it launched in June 2023. The company's dolphin-themed NFTs had …
Users of the cross-chain swapping API LI.FI Protocol, and of projects that build on top of it, suffered wallet drains amounting to at least $10 million (and counting). An attacker …
Three people have been arrested in connection to a crypto pyramid scheme called Metamax. Those behind the scam promised that people who invested in the scam could then earn income …
An attacker stole $1.4 million from the defi lending project Minterest. Using a flash loan attack, they manipulated the exchange rate calculated by the project, allowing them to …
Defi platform Dough Finance was hacked for 608 ETH ($1.8 million) by a hacker using a flash loan attack funded through the Railgun privacy service.Dough Finance sent an on-chain …
Websites providing the frontends for some popular defi services, including Compound Finance, were compromised and replaced with wallet drainers: websites resembling the usual …
BitMEX has pleaded guilty to charges from 2020 that they violated the Bank Secrecy Act by failing to implement an appropriate anti-money laundering program. BitMex's founders, …
Turkish authorities arrested Andreas Szakacs, also known as Emre Avci, for his role in the OmegaPro cryptocurrency Ponzi scheme. Victims were invited to make small investments in …
The Twitter account belonging to rapper Doja Cat was compromised on July 8, tweeting to her 5.6 million followers that they should "buy $DOJA or else", and various other messages …
Some users of the Bittensor wallet software suffered wallet drains as thieves emptied their cryptocurrency wallets of the project’s TAO token. Around 32,000 TAO, notionally worth …
Small Indian banks hit by ransomware attack; NPCI suspends payment. Ransomware attack on C-Edge impacts banking services, but no financial loss reported; restoration work underway. …
Car dealership company AutoNation says CDK ransomware incident cut into quarterly earnings. AutoNation alerted investors that earnings per share would be down about a one-third …
Affirm says cardholders impacted by Evolve Bank data breach. Buy now, pay later loan company Affirm is warning that holders of its payment cards had their personal information …
SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks. SouthCoast Health and Privia Medical Group in Georgia have notified patients about a cyberattack and HIPAA …
Crypto exchange Gemini discloses third-party data breach. Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated …
Protected Health Information Stolen in HealthEquity SharePoint Breach. HealthEquity has confirmed a breach of its SharePoint data, which included protected health information. …
Email Breach Affects 22,000 Ambulatory Surgery Center of Westchester Patients. The Mount Kisco Surgery Center, doing business as the Ambulatory Surgery Center of Westchester in New …
Roblox vendor data breach exposes dev conference attendee info. Roblox announced late last week that it suffered a data breach impacting attendees of the 2022, 2023, and 2024 …
Email Breaches Reported by SkinCure Oncology & the Wisconsin Department of Health Services. SkinCure Oncology has notified 13,434 patients about an email attack that occurred in …
TriZetto, a healthcare technology subsidiary of Cognizant Technology Solutions, disclosed in late 2024 that a data breach had affected over 3 million individuals. TriZetto provides …
Massive AT&T data breach exposes call logs of 109 million customers. AT&T is warning of a massive data breach where threat actors stole the call logs for approximately 109 million …
Otelier, a cloud-based hotel management platform used by major hotel chains worldwide, was breached starting in approximately July 2024. Threat actors obtained employee credentials …
More than a year after the crypto-friendly Silvergate Bank collapsed, its parent company has agreed to pay $63 million in fines to the Federal Reserve and California Department of …
As expected, the SEC has filed a lawsuit against Consensys, the maker of the popular MetaMask cryptocurrency wallet. Although Consensys had recently gloated about the SEC …
Yield App, a crypto investment platform, has announced that it will be entering liquidation proceedings. Citing "significant financial challenges", the project announced that the …
A year and a half after threatening to sue YouTuber Coffeezilla for his series of videos exposing influencer Logan Paul's (alleged) role in (allegedly) scamming his large following …
In June 2024, security researchers at Sansec discovered that cdn.polyfill.io — a widely used JavaScript polyfill service loaded by approximately 380,000 websites — had been …
The Department of Justice busted a group of more than a dozen people, led by a 24-year-old man named Remy St. Felix, who perpetrated a string of break-ins and violent assaults in …
A victim lost $11 million in Aave Ethereum (aEthMK) and Pendle USDe tokens after signing several permit phishing signatures. Permit phishing is a technique in which scammers …
The token for the Farcana blockchain shooting game plummeted in value by around 60%. First, the project team announced that one of the project wallets had been compromised. …
The Turkish cryptocurrency exchange BtcTurk has acknowledged that they suffered a hack that impacted ten hot wallets containing multiple cryptocurrencies. The exchange halted …
CoinStats, an application promising to help people track their cryptocurrency holdings, has suffered a breach impacting more than 1,500 user wallets.The application asks its users …
50 Cent has claimed his Twitter account and website were hacked to promote a memecoin called $GUNIT. "I have no association with this crypto," the rapper wrote on Instagram.50 Cent …
It appears that the online crypto sports betting platform Sportsbet.io suffered a theft of around $3.5 million in USDT and Tron's TRX tokens. The theft was observed by crypto …
Acadian Ambulance Service, a Louisiana-based emergency medical services provider, was attacked by the Daixin Team ransomware gang between June 19-21, 2024. The group claimed to …
Prominent blockchain security firm CertiK has accused American cryptocurrency exchange Kraken of threatening them after they reported a bug. According to CertiK, they discovered a …
BlackSuit ransomware (linked to Royal/Conti lineage) attacked CDK Global June 18 2024, disrupting dealer management systems for ~15,000 US auto dealerships. CDK suffered second …
After Arkham Intelligence announced a $150,000 bounty for anyone who could prove the identity of the person behind a Donald Trump memecoin called $DJT, blockchain sleuth zachxbt …
Globe Life Inc. (insurance holding company, parent of American Income Life Insurance) detected suspicious activity on June 13, 2024. A threat actor obtained customer PII and …
The Holograph tokenization project was exploited on June 13 after they took advantage of a flaw in a smart contract that allowed them to mint 1 billion HLG tokens. Notionally worth …
After suffering a $20 million loss in a June 10 hack, the UwU Lend defi lending protocol has now seen another $3.7 million in suspicious outflows only days later. Although UwU Lend …
Attentive phishers noticed when Andreessen Horowitz partner Peter Lauten changed his Twitter username from @peter_lauten to @lauten, and snapped up the previous username. They then …
Terraform Labs and its former CEO Do Kwon have agreed to settle the SEC's civil action against them with a $4.5 billion payment of disgorgement, interest, and penalties. Kwon and …
The defi lending protocol UwU Lend was hacked for around $20 million. After various blockchain security firms observed suspicious outflows of funds, the protocol acknowledged there …
Although Loopring markets its wallet application as "Ethereum's most secure wallet", that's evidently a pretty low bar. They disclosed that they had suffered a breach in their …
On 8 June 2024, BlackSuit (rebrand of Royal ransomware / Conti successor) attacked Japanese media/gaming giant Kadokawa and its Niconico video platform. 254,241 individuals' data …
Rite Aid (third-largest US pharmacy chain) was breached on 6 June 2024 with 2.2 million customers' names, dates of birth, addresses, and driver's license/government ID numbers …
The New York Attorney General’s office has sued Cynthia and Eddy Petion over two allegedly fraudulent cryptocurrency pyramid schemes called AWS Mining and NovaTech. They …
A blockchain developer posted on Twitter that he had lost almost $50,000 after his cryptocurrency wallet was drained. He explained that he had been working on a software project on …
The UK-based Lykke crypto exchange suffered an exploit that saw more than $23.6 million stolen from the platform. The platform shut down trading two days later, and some customers …
Qilin ransomware group attacked Synnovis, a joint venture providing blood testing and pathology services to King's College Hospital NHS Foundation Trust and Guy's and St Thomas' …
Widong "Bill" Guan, Chief Financial Officer of the far-right Epoch Times media company, has been indicted on money laundering conspiracy and bank fraud charges for his alleged …
CBIZ Benefits & Insurance Services (subsidiary of business services giant CBIZ Inc.) disclosed a breach affecting 35,953 individuals who had retiree health information on file. …
The Velocore DEX, built on the Linea Ethereum layer-2 blockchain, was exploited for around $6.8 million in ETH. The hacker was able to take advantage of a bug in the project's …
An attacker gained access to Tile's customer support system using credentials belonging to a former employee, then scraped millions of customer records and attempted to extort …
More Than 70,000 Adventist Health Tulare Patients Affected by Business Associate Breach. A business associate of Adventist Health Tulare has identified unauthorized access to the …
Almost 20,000 Aptihealth Patients Affected by Business Associate Data Breach. Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil …
Former IT employee accessed data of over 1 million US patients. Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of …
Patient Data Exposed in Cyberattacks on PruittHealth & Easterseals Central Illinois. PruittHealth has notified patients about a November 2023 ransomware attack and has confirmed …
In 2024, King's College Hospital, Guy's Hospital, St Thomas' Hospital and more⦠experienced a data security incident via a third-party vendor relationship. The compromised …
In 2024, Lithia Motors, Sonic Automotive, Penske Automotive Group, Inc. and more⦠experienced a data security incident via a third-party vendor relationship. The compromised …
Email Breach Affects 10,000 University of Chicago Medical Center Patients. Hackers gained access to the email accounts of University of Chicago Medical Center employees and the …
T-Mobile denies it was hacked, links leaked data to vendor breach. T-Mobile has denied it was breached or that source code was stolen after a threat actor claimed to be selling …
North Korean TraderTraitor hackers stole 4,502.9 BTC (~$308 million) from Japanese crypto exchange DMM Bitcoin on 31 May 2024 — the third-largest crypto theft in history. FBI, DC3, …
A Japanese cryptocurrency exchange called DMM Bitcoin has announced that they suffered an "unauthorized leak" of 4,502.9 bitcoin (~$308 million) from a company wallet. They've …
Evolve Bank & Trust, an Arkansas-based fintech banking partner, was attacked by the LockBit ransomware gang in late May 2024. An employee clicked a malicious link, granting …
Ryan Salame was the CEO of FTX Digital Markets which was the Bahamian portion of the FTX business. In September 2023, just before Sam Bankman-Fried's trial began, Salame pleaded …
According to crypto sleuth zachxbt, the team behind the Solana-based $CAT memecoin hacked the Twitter account of "Gigantic-Cassocked-Rebirth" (@GCRClassic) crypto influencer.First, …
Olympic athlete-turned-Trumpworld media personality Caitlyn Jenner has confused many by apparently launching a memecoin on pump.fun and heavily promoting it on her Twitter account …
An attacker perpetrated a flash loan attack on the "Normie" memecoin on the Base layer-2 blockchain to drain millions of NORMIE tokens. The vulnerability was evidently discovered …
RansomHub had access to Patelco Credit Union's systems from approximately 23 May 2024 until detected 29 June 2024. Online banking, mobile app, and call centre were shut down for …
Someone was able to mint 5 billion $GALA tokens, the native token of the Gala Games blockchain gaming project. The tokens would be notionally worth around $200 million based on …
Two people were charged in California for laundering money obtained from cryptocurrency and fiat "pig butchering" scams. After receiving the money from the investment scammers, the …
Pump.fun is a Solana-based memecoin generator that soared to popularity recently amid a resurgence in memecoin trading. On May 16, the project suffered a $2 million exploit by an …
Aiden Pleterski, a 25-year-old who goes by "Crypto King", has finally been arrested and charged with fraud and money laundering. In 2022, he was sued by a group of investors who …
Two brothers, Anton and James Peraire-Bueno, were indicted for a theft involving MEV — maximal extractable value. MEV involves previewing upcoming transactions on a blockchain and …
An attacker tried to pull off what could have been a ~$12 million heist from ALEX Lab's XLink bridge after a private key was compromised. However, the sloppy work by the attacker …
The Sonne Finance lending protocol was exploited for at least $20 million as an attacker was able to exploit a vulnerability in some of their smart contracts. Sonne is a fork of …
Alexey Pertsev, one of the developers of the Tornado Cash mixing service, was found guilty of money laundering and sentenced to 64 months imprisonment in the Netherlands. …
Landmark Admin LLC, a Texas-based third-party administrator for multiple insurance companies, detected unauthorized access to its systems on May 13, 2024, and was breached again on …
Texas-based third-party insurance administrator Landmark Admin (serving American Monumental Life, Pellerin Life, Liberty Bankers Life, Capitol Life, and others) detected a …
After the founder of the Solana-based Cypher futures trading protocol publicly accused a core contributor of stealing funds, the contributor — publicly known only as "hoak" — has …
Black Basta ransomware group encrypted servers across a 12-hospital system. Initial access via a malicious file inadvertently downloaded by an employee. Attackers accessed only 7 …
Keytronic, a printed circuit board assembly (PCBA) manufacturer based in Spokane, WA, was hit by Black Basta ransomware on May 6, 2024. Operations in the US and Mexico were halted …
Robinhood has disclosed that they received a Wells notice from the US Securities and Exchange Commission in relation to their "Robinhood Crypto" product. This indicates that the …
An exploiter was able to create a fake version of the $GNUS token on the Fantom blockchain, then bridge the tokens to Ethereum and Polygon where they were then sold as though they …
An Ethereum wallet was apparently drained of 1,155 wrapped bitcoin (~$72.7 million) when they transferred it to a malicious address that had been operating an address poisoning …
The former CEO, CFO, and CCO of the cryptocurrency lending service Cred have been indicted on multiple charges involving wire fraud and money laundering. They were charged in …
Cencora & The Lash Group Settle Data Breach Litigation for $40 Million. Cencora, The Lash Group, and their affiliates have agreed to pay $40 million to settle class action data …
Third-party company: eClinical Solutions LLC.
In 2024, BYM Fashion, Lizay Kuyumculuk, Aker Magazacılık and more⦠experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor …
Continuum Health Alliance Data Breach Affects 377,000 Consensus Medical Group Patients. Marlton, NJ-based Continuum Health Alliance has recently confirmed that it has experienced a …
WebTPA Data Breach Affects 2.4 Million Health Insurance Policyholders. WebTPA, a Texas-based provider of administration services to health insurance and benefit plans has recently …
Alleged HSBC, Barclays data exposed by IntelBroker. Hackread reports that IntelBroker has exposed sensitive data allegedly stolen from major UK-based international financial …
MediSecure e-script firm hit by ‘large-scale’ ransomware data breach. Electronic prescription provider MediSecure in Australia has shut down its website and phone lines following a …
What Snowflake isn't saying about its customer data breaches | TechCrunch. As another Snowflake customer confirms a data breach, the cloud data company says its position "remains …
Snowflake account hacks linked to Santander, Ticketmaster breaches. A threat actor claiming recent Santander and Ticketmaster breaches says they stole data after hacking into an …
Pure Storage, a leading enterprise cloud storage provider, confirmed on June 11, 2024 that attackers breached its Snowflake workspace as part of the broader UNC5537/Sp1d3r campaign …
Bausch Health, a Canadian pharmaceutical company, was targeted as part of the 2024 UNC5537/Sp1d3rHunters Snowflake credential-theft campaign. The threat actor 'Sp1d3rHunters' …
Pike Finance, a cross-chain lending protocol, was exploited twice in four days as attackers discovered vulnerabilities in the project's smart contracts.The first attack, on April …
Roger Ver, an early bitcoin investor who later became an outspoken evangelist for the fork Bitcoin Cash, has been arrested on tax fraud charges. According to the Department of …
Former Binance CEO Changpeng "CZ" Zhao has been sentenced to four months in prison after pleading guilty to money laundering-related charges. The charges were filed in November, …
Bahrain-based cryptocurrency exchange Rain was exploited for around $16.13 million dollars on April 29. The exchange did not publicly disclose the hack until the suspicious …
In the wake of the $33 million ZKasino rug pull, Dutch police have arrested an as yet unnamed 26-year-old who is likely "Derivatives_Ape", the creator of the project. The police …
LockBit claimed the attack on London Drugs and demanded $25 million ransom (reportedly offered $8 million). All 79 Western Canada stores closed 28 April–7 May 2024. Corporate head …
Threat actor 'Menelik' registered as a Dell partner using fake company information (access granted within 24–48 hours), then used automated tooling to enumerate 49 million customer …
Jay Mazini, an influencer who often boasted of his wealth on Instagram by doing cash giveaways to random strangers, has been sentenced to seven years in prison after running …
On 24 April 2024, Dropbox discovered that a threat actor had accessed Dropbox Sign's (formerly HelloSign's) production environment. Dropbox Sign is an e-signature service used by …
Keonne Rodriguez and William Lonergan Hill, founders of the Samourai Wallet, were arrested and charged with conspiracy to commit money laundering and conspiracy to operate an …
A project promising to build a decentralized casino managed to raise $33 million, despite an anonymous team that had exhibited several instances of shady behavior throughout …
Hedgey Finance, a platform used to manage token claims, lockups, and vesting, was hit with a flash loan attack that drained $44.7 million of customer funds from the platform.The …
A jury found Avi Eisenberg guilty of fraud and market manipulation after he stole $110 million from the Mango Markets defi protocol in October 2022. Although he tried to argue that …
Police in Hong Kong have arrested 72 people and frozen HK$228 million (~US$29 million) in connection to the collapse of the JPEX cryptocurrency exchange in September 2023. The …
UNC5537 accessed a third-party Snowflake-hosted database used by Santander. Breach began April 17, discovered May 10, disclosed May 14. ShinyHunters listed data on BreachForums …
Amid tweets alleging corruption among jurors in his 2019 criminal case, far-right activist and Trumpworld figure Roger Stone has posted several tweets endorsing "MAGA Memecoin", …
Grand Base, a real world assets platform built on the Base layer-2 blockchain, has seen $2 million exit the platform in a hack or rug pull.The team behind the project claimed that …
Frontier Communications (a major US telecom serving 25 states) detected unauthorized access on 14 April 2024. RansomHub claimed responsibility and threatened to leak 5 GB of stolen …
UNC5537 accessed Advance Auto Parts' Snowflake environment between April 14 and May 24, 2024. Breach disclosed July 10 via Maine AGO notification affecting 2.3 million current and …
UNC5537 downloaded AT&T call and text metadata for nearly all ~110 million AT&T wireless customers, covering May–Oct 2022 and a small subset from Jan 2023. Data included call/text …
UNC5537 (ShinyHunters / Scattered Spider affiliates) used infostealer-harvested credentials to authenticate to Ticketmaster's Snowflake tenant which had no MFA configured. …
UNC5537 threat actor 'Sp1d3r' posted on BreachForums 1 June 2024 claiming 190 million individual records and 3 billion tracking pixel data records (2 TB compressed) stolen from …
Neiman Marcus (US luxury retailer) was breached as part of the UNC5537 mass-Snowflake campaign in May 2024. While the company notified Maine AG of 64,472 individuals, Troy Hunt …
Nearly 110 million AT&T wireless customers had call and text metadata stolen — which numbers were contacted, call duration, and for some users cell tower location data. Data …
The tea.xyz protocol first earned an entry on Web3 is Going Just Great in late February, when their plan to reward open source software contributors resulted in crypto enthusiasts …
Shakeeb Ahmed, the hacker who stole a combined $12 million from Crema Finance and Nirvana Finance in July 2022, has been sentenced to three years in prison. Ahmed had previously …
Pac Finance, a fork of the Aave lending protocol deployed on the Blast blockchain, surprised some of its users as an unannounced and unexpected code change lowered the liquidation …
NGS Crypto, which sold "crypto mining packages" to interested investors, has been put into receivership. The Australian firm encouraged customers to set up a self-managed super …
Liquidators have been appointed for three cryptocurrency companies owned by Ash Balanian. DCA Capital, Digital Commodity Assets, and the Digital Commodity Assets Fund have all …
Young Consulting (also known as Connexure), an Atlanta-based software solutions provider for medical stop-loss insurance organizations, suffered a BlackSuit ransomware attack …
The MarginFi decentralized lending project on Solana has been at the epicenter of some major drama recently, amid concerns around oracle problems, withdrawal failures, and …
The US Securities and Exchange Commission issued a warning to the Uniswap decentralized exchange in the form of a Wells notice. Wells notices are used to inform the recipient of an …
STFIL, a protocol that promises liquid staking and "leverage mining" to holders of Filecoin's FIL token, announced on Twitter that "We believe that the STFIL core technical team is …
A person or group have raised funds for various crypto projects only to abandon them, empty the project wallets, and launder the funds through Tornado Cash. The largest of the …
It's hard to believe that the hamburger joint themed around the owner's Bored Ape NFT failed to take off. Although there was novelty value in the themed restaurant, which for a …
After hearing arguments that Terraform Labs was "built on lies" during a two-week-long trial, the jury in the civil case against the company and its founder Do Kwon found that both …
The leadership team behind SushiSwap, a popular defi platform, submitted proposals for a DAO governance vote that would transfer control of around $40 million from the DAO to a …
A project describing itself as "The world's first memecoin pre-announced as a rugpull" was explicit in its marketing: "do not buy this coin, as it will go to zero."Despite that, …
MediSecure, an Australian electronic prescription delivery service provider, suffered a ransomware attack in April 2024. Approximately 6.5 TB of data was exfiltrated, impacting …
Background check company National Public Data (Jerico Pictures) breached via plaintext admin credentials found in Members.zip archive on sister site RecordsCheck.net. 2.9 billion …
In 2024, AMG Healthcare Management Services, Marshall Medical Center, South Coast ER Medical Group and more⦠experienced a data security incident via a third-party vendor …
Phishers Gain Access to 23 L.A. County Department of Health Services Email Accounts. Los Angeles County Department of Health Services' employees were targeted in a recent phishing …
Cisco Duo warns third-party data breach exposed SMS MFA logs. Cisco Duo's security team warns that hackers stole some customers' VoIP and SMS logs for multi-factor authentication …
DC city agency says LockBit claims tied to third-party attack. The Department of Insurance, Securities and Banking (DISB) said the ransomware gang stole data from a contractor, …
DOJ data on 341,000 people leaked in cyberattack on consulting firm. Medicare and other information belonging to 341,000 people was leaked after a consulting firm working with the …
German database company Genios confirms ransomware attack. The Munich-based company said that as a result of the incident, “unfortunately we have to assume an outage for several …
BianLian Threat Group Claims Responsibility for Cyberattack on Tennessee Eye Clinic Network. Politzer and Durocher, PLC, which does business as Optometric Physicians of Middle …
Medusa Ransomware Group Leaks Data Stolen from American Renal Associates. The Medusa ransomware group has leaked data stolen from American Renal Associates. Moffitt Cancer Center …
State Department investigating reports of data theft allegedly involving federal tech consulting firm. The U.S. State Department said it is investigating claims that a hacker stole …
UNC5537 / Scattered Spider / ShinyHunters used credentials stolen by infostealer malware (some dating back to Nov 2020) to access 160+ Snowflake customer environments lacking MFA. …
Cylance (a cybersecurity company owned by BlackBerry) confirmed in June 2024 that a data breach occurred involving a third-party cloud platform. The threat actor 'Sp1d3r' claimed …
UNC5537 compromised approximately 165 Snowflake customer tenants in a mass credential-stuffing campaign from April 2024. Known victims include AT&T (110M records), Ticketmaster …
UNC5537 accessed Neiman Marcus's Snowflake database between April and May 2024. Official notification to Maine AGO cited 64,472 individuals; however HIBP analysis identified 31 …
Ticketek Australia (operated by TEG, Ticket Entertainment Group) disclosed a data breach in May/June 2024 involving a third-party cloud platform. A ShinyHunters-linked actor posted …
Los Angeles Unified School District had student and teacher data stored in Snowflake accounts maintained by one or more third-party vendors. As part of the UNC5537 / ShinyHunters …
Ryan Mitchell Kramer (alias 'NullBulge'), a 25-year-old from Santa Clarita, California, distributed a malicious AI art generation tool on GitHub. When a Disney employee downloaded …
The FixedFloat cryptocurrency exchange was exploited again, this time for around $2.8 million. This follows shortly after a February 18 hack in which attackers made off with $26 …
The Solana ecosystem is grappling with a spate of drained wallets. A cause has yet to be definitively determined, but some of the thefts were linked to the use of trading bots like …
The defi protocol Prisma Finance was hacked for 3,257 ETH ($11.5 million). An attacker was able to take advantage of a flaw in the project's smart contracts, allowing them to …
Sixteen months after the collapse of his FTX cryptocurrency exchange, Sam Bankman-Fried has been sentenced to 25 years in prison. He has also been ordered to pay an $11 billion …
The LENX cross-chain bitcoin liquidity protocol has recently been accused of a $10 million rug pull after community members observed massive withdrawals of treasury funds which …
The "Munchables" crypto game explains: "Schnibbles grow on every realm across the Munchable's world. Each realm has their own unique and distinctive schniblet, and the Munchables …
The cryptocurrency exchange KuCoin and two of its founders, Chun Gan and Ke Tang, were indicted in the Southern District of New York on charges of conspiring to operate an …
CVSS 10.0. Threat actor UTA0218 exploited zero-day in PAN-OS GlobalProtect feature allowing unauthenticated OS command execution as root. Affected PAN-OS 10.2, 11.0, 11.1 with …
Curio, a crypto project that creates tokens based on "real-world assets" (RWAs) like cars, watches, wine, and other goods, has suffered an attack that saw around $16 million …
The astrology-based Lucky Star Currency project rug-pulled for $1.1 million in October 2023. You'd think that might be the end of it, but on March 22, 2024, ownership of the …
Solana memecoin trading has been booming lately, with people making money by speculating on tokens themed around various memes and jokes. Amid an explosion in trading …
Super Sushi Samurai, a new blockchain game on the Blast layer-2 blockchain was exploited for $4.6 million when an attacker discovered a vulnerability in its smart contract. A bug …
A developer brought on to run a presale for the $TICKER token stole $900,000 from the project. 15% of the token supply was sent to the developer to distribute via an airdrop, but …
An attacker used social engineering techniques to gain access to the AirDAO project's liquidity pool. They then were able to drain 126.5 ETH (~$551,540) and 41.6 million AMB …
The Dolomite DEX suffered a $1.8 million theft as an exploiter was able to take advantage of a vulnerability in a smart contract that had been deployed in 2019. Although most …
Fortune reported that the U.S. Securities and Exchange Commission has targeted the Swiss-based Ethereum Foundation for investigation, apparently in an effort to classify its ETH …
A "very small number of accounts" were able to crash the bitcoin price on the BitMEX exchange from its roughly $66,000 price to as low as $8,900. BitMEX attributed the incident to …
People have gotten really into memecoin trading on Solana recently. Like really into it. Someone decided they'd hop on the bandwagon with "Slerf", a sloth-themed memecoin they said …
Someone impersonating Ansem, an influential crypto trader, was able to scam people out of more than $2.6 million simply by replying to the real Ansem's tweets. Using an account …
"Charlotte Fang", the leader of the controversial Remilia project (known for its Milady NFTs), claimed he was hacked and drained of ETH and NFTs potentially worth several million …
Wilder World is a blockchain-based racing game that uses all the buzzwords: blockchains, artificial intelligence, and metaverse. On March 16, someone with access to the project …
A Binance-incubated platform called NFPrompt claims to be "the first Prompt Artist Platform in Web3" — with "prompt artist" referring to people who come up with prompts to feed …
The "AI-optimized" defi project Mozaic Fi was exploited by an attacker who drained around $2 million in funds from the project.According to MozaicFi, the theft had been perpetrated …
Someone accidentally threw away $1.36 million when they accidentally sent Tethers to the Tether contract address — making them permanently inaccessible in a process known as …
The decentralized lending protocol, MOBOX, was exploited on March 14, 2024 after an attacker was able to take advantage of a bug in its referral program and borrowing …
The U.S. Attorney's Office in the District of Massachusetts announced that they had filed a civil forfeiture action to seize cryptocurrency priced at around $2.3 million from two …
An Ethereum holder who had been staking their ETH through a liquid restaking protocol called Ether.fi suffered a 501 ETH (~$2.025 million) loss when they fell victim to a phishing …
Since March 5, those who used the Incognito Market darkweb narcotics marketplace have found themselves unable to withdraw the Bitcoin and Monero they had on the platform. It …
Web3: a technology so promising you can't even pay a company $100 million to use it.Crowdfunding website Kickstarter surprised and dismayed many of its users in December 2021 when …
Scam Sniffer's February 2024 report describes 57,000 victims who collectively lost almost $47 million thanks to various phishing schemes on the Twitter platform. Many of the losses …
The Wacks Law Group, a Whippany, New Jersey estate planning law firm with only six attorneys, was attacked by the Qilin ransomware group on March 9, 2024. Sensitive client data …
HealthEquity, a Utah-based administrator of health savings accounts (HSAs), health reimbursement arrangements (HRAs), and COBRA benefits serving millions of Americans, disclosed a …
A investment firm called Crypto4Winners announced in their Telegram channel that "Our investigations lead us to suspect an individual of committing fraudulent acts that may have …
The Unizen defi platform lost around $2.1 million in the Tether stablecoin in an attack that took advantage of a vulnerability an external call from the project smart contract.The …
IntelBroker breached federal IT contractor Acuity Inc. on 7 March 2024 and claimed to have stolen data from US State Department, DoD, NSA, ICE, USCIS, and other agencies. The …
An attacker was able to use a flash loan attack to manipulate an oracle on the WooFi DEX implementation on the Arbitrum network. By manipulating the price of $WOO, they were able …
On 4 March 2024, JetBrains and Rapid7 (the discoverer) simultaneously disclosed two authentication bypass vulnerabilities in JetBrains TeamCity — a popular CI/CD build server used …
American Express credit cards exposed in third-party data breach. American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant …
Grace Lutheran Communities Falls Victim of ALPHV/Blackcat Ransomware Attack. Grace Lutheran Communities in Wisconsin, a provider of rehabilitation services, assisted living, …
MFA Bypassed in Cyberattack on L.A. County Department of Mental Health. Cyberattacks and data breaches have been reported by the L.A. County Department of Mental Health, …
First BofA, Now Fidelity: Same Vendor Behind Third-Party Breaches. The private information of more than 28,000 people may have been accessed by unauthorized actors, thanks to a …
Benefytt, EMSA, Lindsay Municipal Hospital Affected by Cyberattacks. Health Plan Intermediaries Holdings (Benefytt) has been affected by a cyberattack on a vendor, Emergency …
Mintlify, an AI-powered code documentation platform used by software developers, suffered a breach on March 1, 2024. A vulnerability in Mintlify's systems allowed unauthorized …
Cogdell Memorial Hospital Cyberattack Affects 87,000 Patients. Cyberattacks and data breaches have recently been reported by Cogdell Memorial Hospital, Hospice of Huntington, Santa …
Switzerland: Play ransomware leaked 65,000 government documents. The National Cyber Security Centre (NCSC) of Switzerland has released a report on its analysis of a data breach …
Cyberattack on Vietnam securities broker disrupts stock markets. VNDirect, one of Vietnam's largest brokers, is still responding to an incident that started over the weekend and …
California and North Dakota Hospitals Report Cyberattacks. Cyberattacks have been reported by Pembina County Memorial Hospital, Pomona Valley Hospital Medical Center, and Rancho …
235,000 Individuals Affected by Yakima Valley Radiology Data Breach. Yakima Valley Radiology has suffered a data breach that has affected 235,249 individuals. Data breaches have …
Second Roku credential stuffing incident of 2024 (first: ~15,000 accounts in March). Attackers used username/password pairs from prior unrelated breaches to authenticate against …
Someone who held over 111.6 million ALI tokens from a project called The AI Protocol was phished by someone using a wallet drainer service using a permit phishing technique. The …
The Shido blockchain suffered an exploit of their staking smart contract, in which an attacker was able to transfer ownership of the contract to another address and then upgrade …
A bug in Seneca Protocol's smart contract has allowed attackers to steal funds from users who had approved the contract. So far, around $3 million has been stolen across the …
VeriSource Services (Texas-based employee benefits and HR administration provider) discovered unusual activity on 28 February 2024. The final breach count was approximately 4 …
There are evidently no lows to which crypto scammers will not sink.Some scammers were able to compromise the Twitter account belonging to the Friends star Matthew Perry, who passed …
Serenity Shield, a project aiming to solve "crypto inheritence", has been hacked. Although the project prominently claims to help "ensur[e] your financial and personal security", …
The user experience in crypto is apparently so bad that platforms can't even keep their own tokens straight. A web3 messaging project, Dechat, announced with some fanfare that the …
MicroStrategy, the company founded and chaired by Bitcoin maximalist Michael Saylor, suffered a Twitter account compromise on February 26. Although MicroStrategy ostensibly …
The Hong Kong-based BitForex cryptocurrency exchange has shut down access to its platform after a suspicious outflow of around $57 million on several blockchains. Users who have …
This crypto skeptic I've heard of once said "Show me the incentive and I will show you the outcome."A project called tea.xyz promised people they could "get rewards for [their] …
A community member of the Tornado Cash cryptocurrency tumbler project has reported that malicious code was added to the Tornado Cash project on January 1, which has put at risk …
A pig-butchering operation in Myanmar has scammed victims of more than $100 million in Tether in less than two years, according to a report from Chainalysis and the anti-human …
RiskOnBlast, a gambling and trading platform on the new ethereum layer-2 Blast blockchain, appears to have performed the blockchain's first major rug pull — before the blockchain …
Aleo, a blockchain project that advertises it's a place for "fully private applications" with "built-in privacy" has just emailed private identification documents — including …
CVSS 10.0. Suspected nation-state actor 'Jia Tan' (JiaT75) spent 2+ years cultivating trust in xz-utils project before becoming co-maintainer. Injected SSH authentication …
When businessman Kow Seng Chai transferred AU$99,500 (~US$65,000) to a cryptocurrency account on the Australian OTCPro cryptocurrency trading platform on January 25, he received an …
I might otherwise skip over news of a $170,000 hack, given how commonly thefts of that scale happen in the crypto world, but with a name like this... come on.One thing that keeps …
The Blueberry defi leverage project had a bug in their lending contract, where improper decimal handling allowed for an exploit. An attacker tried to exploit the vulnerability, but …
Jeff "Jihoz" Zirlin, a co-founder of the Axie Infinity blockchain game, lost around $9.5 million as two of his crypto wallets were compromised. The thief stole 3,248 ETH ($9.5 …
Cencora detected a cyberattack on 21 February 2024. Attackers exfiltrated patient data from its patient support program platform used by major pharmaceutical clients including …
The Hong Kong-based AAX cryptocurrency exchange suspended withdrawals in November 2022, only days after the FTX collapse and related chaos in the cryptocurrency world. They claimed …
A popular cryptocurrency influencer known as "Crypto Rover" has been accused by blockchain sleuth zachxbt of shady behavior, including accepting promotional payments from crypto …
On 19 February 2024, ConnectWise disclosed two critical vulnerabilities in ScreenConnect — an on-premises remote access tool used by managed service providers (MSPs) and IT teams …
After projects like Celestia and Starknet distributed airdrops of crypto tokens to people who had contributed to their open source Github repositories, airdrop hunters have begun …
The FixedFloat cryptocurrency exchange was exploited for around 409 BTC (~$21.17 million) and 1,728 ETH (~$4.85 million) for a total loss of just over $26 million. FixedFloat is a …
A trader known as kirilm.eth fell victim to a phishing attack, losing over 180 million BEAM tokens to a scammer. BEAM is a token belonging to the Beam blockchain gaming network, …
On February 16, the NFT giant Yuga Labs announced it would be acquiring the Moonbirds NFT project. This adds to list of blue-chip NFT collections controlled by Yuga Labs, which …
One of the promises made by proponents of crypto-focused decentralized social networks like Farcaster is that you can't be de-platformed by centralized companies, and you maintain …
Crypto sleuths Coffeezilla and zachxbt teamed up on an investigation into YouTuber and crypto promoter KSI, accusing him of pumping up interest into the XCAD project and then …
Financial Business and Consumer Solutions (FBCS), a Pennsylvania-based debt collection agency, suffered a ransomware attack between February 14-26, 2024. The breach ultimately …
Financial Business and Consumer Solutions (FBCS), a third-party debt collection agency used by Comcast, was hit by ransomware in February 2024. As a result, data on approximately …
Pablo Stanley, an artist who created the "Robotos" generative NFT collection, posted two final messages from the Robotos Twitter account. First, "it was a good run! thank u, all!", …
Pablo Stanley, an artist who created the "Robotos" generative NFT collection, posted two final messages from the Robotos Twitter account. First, "it was a good run! thank u, all!", …
The Duelbits crypto casino and sports betting website was drained of around $4.6 million on both the Ethereum and BNB Chain blockchains. The funds were quickly bridged or exchanged …
In April 2026, Iowa Attorney General Brenna Bird filed a lawsuit against UnitedHealth Group seeking financial damages, civil penalties, and improvements to the company's data …
Affiliate of ALPHV/BlackCat breached Change Healthcare (UnitedHealth subsidiary) on Feb 11 2024 via stolen credentials on a Citrix portal lacking MFA. Spent 9 days in network …
DISA Global Solutions (background check, drug testing, and employment screening provider to 55,000+ companies including 135 Fortune 500 firms) was breached for 100+ days before …
The South Korean blockchain gaming platform PlayDapp was hacked on February 9, and an attacker minted 200 million $PLA tokens. These were notionally priced at around $36.5 million, …
Some fans of Yuga Labs (the company behind Bored Apes and the much-anticipated Otherside metaverse gaming project) are questioning how much progress the company can really have …
They were doing so well! After suffering a slew of outages during 2022, Solana had seemed to get their act together in 2023 with only one major outage. Now, however, Solana has …
ALPHV/BlackCat ransomware group breached Prudential Financial (major US insurer) between 4-5 February 2024, initially believed to affect only 36,545 people. The true scope was …
ALPHV/BlackCat claimed responsibility for the breach, detected 5 February 2024 (breach date 4 February). Initial SEC disclosure in February cited ~36,000 potential victims; updated …
NTT Communications Corporation, the international subsidiary of Japan's NTT Group, disclosed in March 2025 that a breach had exposed data for 17,891 corporate customers. The …
Ransomware attack forces 100 Romanian hospitals to go offline. 100 hospitals across Romania have taken their systems offline after a ransomware attack hit their healthcare …
Data breach at French healthcare services firm puts millions at risk. French healthcare services firm Viamedis suffered a cyberattack that exposed the data of policyholders and …
Des Moines Orthopaedic Surgeons Notifies Patients About February 2023 Data Breach. Des Moines Orthopaedic Surgeons (DMOS) in Iowa has recently notified 307,864 current and former …
Egyptian Health Department Cyberattack Affects Up to 100,000 Individuals. Egyptian Health Department (EHD) in Eldorado, IL, has recently announced a data breach affecting up to …
462,000 Hawai'i Residents Affected by Data Breach at Navvis & Company. Approximately 462,000 individuals who enrolled in health plans through the Hawaii Medical Service Association …
February 14, 2024 Healthcare Data Breach Round-Up. Data breaches have recently been reported by the Hampton-Newport News Community Services Board, Marywood Nursing Care Center, …
Keenan & Associates Data Breach Affects More Than 1.5 Million Individuals. The Torrance, CA-based insurance broker Keenan & Associates has recently reported a cybersecurity …
February 2024 Healthcare Data Breach Report. There has been a fall in the number of reported healthcare data breaches for the second consecutive month, with 59 data breaches of 500 …
R1 RCM Data Breach Impacts 16,000 Patients. Data breaches have recently been reported by R1 RCM, St. Mary's Healthcare System for Children, Philips Respironics, and California …
Third-party company: CGI Federal.
Who can believe this. OPNX, the crypto derivatives exchange created by the people who ran and then blew up the Three Arrows Capital hedge fund, will be shutting down. The exchange …
Three people running a SIM swapping operation have been charged with fraud and identity theft. By gaining access to the personal information of their victims and then convincing …
Scam Sniffer's January 2024 report describes more than 40,000 victims who collectively lost more than $58 million thanks to various phishing schemes on the Twitter platform.The top …
Blockchain sleuth zachxbt noticed the strange movement of around 213 million XRP, the native token for the Ripple project. These tokens were priced at around $112.5 million at the …
Well that sure is a headline I just had to write.The Magic Internet Money ($MIM) stablecoin has lost its dollar peg again, dipping all the way below $0.77 in a flash crash before …
US Attorneys in Maryland and the US Securities and Exchange Commission filed criminal and civil lawsuits, respectively, against Sam Lee, the co-founder of the HyperVerse …
Goledo Finance, an Aave-based lending protocol, was exploited through a flash loan attack. The attacker stole assets estimated by CertiK at around $1.7 million.Goledo Finance …
Have you ever gone out to karaoke and thought "man, the only thing missing from this perfect night is a blockchain"? No? Weird.Anyway, the South Korean Somesing platform — which is …
Rhysida ransomware attacked Lurie Children's Hospital of Chicago (pediatric hospital) Jan 26-31 2024. Patient-facing systems offline for ~3.5 months. 791,784 individuals notified …
The US government is cementing its status as one of the largest BTC holders by adding another 8,100 BTC (priced at almost $350 million today) to its stash. The tokens were …
Hackers were able to exploit a vulnerability in the staking contract for WallStreetMemes ($WSM), a memecoin and online casino project targeted at the "meme warriors" who frequent …
After hackers gained access to various accounts on the MailerLite email marketing software via a social engineering attack on an employee, they were able to send malicious phishing …
An attacker was able to gain access to the Gamee (GMEE) token's source code repository, then exploit a vulnerability in the code to transfer 600 million GMEE tokens to their own …
The Concentric Finance yield aggregator project issued a statement that the protocol had been exploited after a social engineering attack on a team member that had access to the …
Terraform Labs, the company behind the Terra blockchain, has filed for bankruptcy. Its flagship product, the Terra stablecoin and associated LUNA token, failed spectacularly in May …
In January 2024, AnyDesk — the widely-used remote desktop software with over 170,000 customers including major enterprises and government agencies — discovered a breach of its …
NBA star Dwight Howard is clearly at least a year (probably two) late to the time when celebrities and star athletes could drop some low-effort NFTs and sell out the whole batch …
The CFTC has filed a complaint against Debiex, a shadowy cryptocurrency platform whose precise location and executives are unknown. The company's employees primarily targeted …
On January 19-20, 2024, TietoEVRY, a Finnish-Norwegian IT company and one of the largest IT service providers in the Nordics, suffered an Akira ransomware attack against its …
A Colorado-based pastor for an online ministry sold INDXcoin to his followers and others in the Christian faith. However, there was no way for buyers to cash out the tokens. …
In January 2024, Russian hackers affiliated with Sandworm (a GRU/Russian military intelligence cyber unit) infiltrated water treatment systems in Muleshoe, Texas, causing a water …
Apparently, former president of the Royal Spanish Football Federation Luis Rubiales has decided the way to rehabilitate his reputation after forcibly kissing a soccer player and …
The Socket cross-chain infrastructure protocol was hacked for around $3.3 million in an attack that exploited its Bungee bridge. The thieves were able to exploit a bug that allowed …
Threat actor 'emo' fed 500 million email addresses from prior breach corpora into Trello's publicly accessible REST API which returned public user profile data for each match, …
In July 2023, angry investors in the Hector Network project opted to "rage quit" — an option reserved by some defi projects that allows investors to vote to liquidate a project's …
TrueUSD, a stablecoin connected to Justin Sun, deviated from its intended $1 peg to around $0.983 as traders sold off more than $100 million of the token seeking safer options. The …
On December 7, the Harmony blockchain began encountering a bug that ultimately caused around 150 million of the project's $ONE token (priced at around $2.2 million) to be …
Just as the NFT marketplace was entering collapse in May 2022, GameStop decided it would be a great time to launch an NFT marketplace. The marketplace launched in July, and made …
After the New York Department of Financial Services accused the Genesis cryptocurrency platform of cybersecurity failures that made it vulnerable to criminal activity and hacking …
A trader looking to buy $9 million of a recently popular Solana memecoin, dogwifhat (WIF), lost $5.7 million of their funds to slippage as they placed a massive order in a pool …
As Euler Finance tried to recover from a massive hack in March 2023, and as founder co-founder Michael Bentley was dealing with matters in his personal life, he "made an error and …
Just about two years after launching a feature in which NFT owners could show off their NFTs with special, hexagonal profile pictures, Twitter has apparently removed support for …
As the crypto industry collectively turns blue holding its breath for a decision on a raft of bitcoin spot ETFs currently in front of the SEC, the SEC Twitter account was hacked. …
A crypto influencer known as "Bitcoin Rodney" was arrested by US authorities for his involvement in the HyperVerse crypto scam, which fleeced victims out of over $1 billion. In …
The creator of a Solana-based NFT project called Undead Apes Society has been charged with money laundering conspiracy and making false statements to investigators after …
A cryptocurrency project called Narwhal appears to have rug-pulled, claiming that they were hacked. In a post on their Twitter account, they claimed that a "hacker attack" caused …
A Solana yield farming project called MangoFarmSOL encouraged people to deposit Solana tokens into the protocol to earn airdrops by January 10. However, on January 6, the project …
The crypto payments platform CoinsPaid was hacked for the second time in six months. This time, around $7.5 million in various tokens was stolen.In July 2023, an attacker stole …
The xKingdom project promised users a way to "build your kingdom" on Twitter, earning tokens by interacting with tweets and doing "quests". Users had to borrow XKING tokens in …
The Twitter account of the blockchain security company CertiK was hacked, then used to post tweets ostensibly warning of a massive crypto vulnerability and urging users to click a …
California-based mortgage lender LoanDepot was attacked by the ALPHV/BlackCat ransomware gang between January 3-5, 2024. Approximately 16.9 million customers had their personal …
The Gamma Strategies defi protocol suffered an exploit when an attacker targeted their vaults on several projects across the Arbitrum layer-2 network. The attacker successfully …
Bill Lou, the co-founder of a cryptocurrency wallet that claims to "revolutionize wallet security", was scammed out of 52 stETH (~$125,000) when he clicked a link promising an …
Radiant Capital, a cross-chain lending protocol built on the Arbitrum layer-2 network, was hacked for 1,900 ETH (~$4.5 million). The exploit relied on a flaw in the underlying …
Kaiser Permanente disclosed that tracking technologies (pixels) embedded in its website and mobile apps transmitted member health information to third-party tech companies …
Outabox, an Australian hospitality IT provider offering facial recognition sign-in services for clubs, suffered a data breach exposing biometric and personal data of approximately …
HMG Healthcare Data Breach Affects 80,000 Individuals. HMG Healthcare, LLC, a Texas-based healthcare services provider, has recently confirmed that the protected health information …
Singing River Health System Confirms Ransomware Attack Affected 895,000 Patients. Singing River Health System has confirmed that 895,204 individuals were affected by an August 2023 …
Framework discloses data breach after accountant gets phished. Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers …
Third-party company: Perry Johnson & Associates, Inc., (PJ&A).
Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected. Finland-based Tietoevry said “one part of one of our Swedish datacenters” was attacked with …
Tietoevry ransomware attack causes outages for Swedish firms, cities. Finnish IT services and enterprise cloud hosting provider Tietoevry has suffered an Akira ransomware attack …
Data breach at healthcare tech firm impacts 4.5 million patients. HealthEC LLC, a provider of health management solutions, suffered a data breach that impacts close to 4.5 million …
Law Firm Orrick Reveals Extensive Data Breach, Over Half a Million Affected. This website stores cookies on your computer. These cookies are used to improve your website experience …
ConsensioHealth Ransomware Attack Affects 61,000 Patients. The Wisconsin-based medical billing service, ConsensioHealth, has recently notified 60,871 individuals about a July 2023 …
Tycoon2FA is a sophisticated phishing-as-a-service platform discovered in 2023 and analysed in depth by Sekoia.io in March 2024. The platform operates as a reverse proxy between …
CISA issued an urgent advisory on 11 April 2024 warning Sisense customers to immediately rotate all credentials used with the platform. Sisense (a business intelligence/analytics …
Volkswagen Group's software subsidiary CARIAD left data on approximately 800,000 EV owners unencrypted and publicly accessible in AWS cloud storage for months. Affected brands: …
By 2025-2026, healthcare vendor supply chain attacks had become the dominant breach vector in US healthcare, with HHS OIG and OCR reporting that third-party vendor incidents …
By 2025-2026, international law enforcement agencies had significantly shifted their approach to ransomware disruption — moving from reactive arrests after the fact to proactive …
The Orbit Bridge project, a cross-chain bridge for the Orbit Chain project, was exploited on December 31 for around $81 million. The attacker made off with around 26,742 ETH (~$64 …
Someone had a not so fun end to the year when they fell victim to a phishing attack and had around 275,700 LINK drained from their crypto wallet. Those tokens are priced at around …
The federal judge overseeing the SEC v. Terraform Labs case has determined that Terra's UST stablecoin, LUNA token, and related tokens were securities. "There is no genuine dispute …
New SEC filings have revealed that Digital Currency Group CEO Barry Silbert and president Mark Murphy have resigned from the board of Grayscale Investments, the organization behind …
An attacker successfully manipulated an oracle to drain around 10% of the liquidity pool for the Levana Protocol, an Osmosis-based perpetual futures project. This amounted to …
$TEL, the token associated with the Telcoin remittances project, plunged 40% as an exploiter was able to steal around $1.25 million from the project. The company later disclosed …
Anna Jaques Hospital in Newburyport, Massachusetts was attacked on Christmas Day 2023 by the Money Message ransomware group, which claimed 600 GB of data was stolen. 316,342 …
The Megabot project rug pulled, stealing $742,000 from those who bought in to the project's presale. The majority of the money — around $692,000 — was stolen on the Solana …
I wish I could give myself a billion dollars for Christmas, too.On December 25, Tether minted 1 billion of its USDT dollar-pegged stablecoin. CEO Paolo Ardoino announced on Twitter …
About six months after the SEC filed a complaint against the BarnBridge DAO, the group has agreed to disgorge almost $1.5 million in proceeds from their "SMART Yield bonds" — which …
The Canadian Catalyx cryptocurrency exchange has frozen trading and halted withdrawals after an emergency order by the Alberta Securities Commission on December 21. Catalyx …
A new wallet drainer tool has stolen $58.98 million in cryptocurrency assets from more than 63,000 victims in the past nine months. People using the drainer software have pulled in …
Despite raising $80 million in February 2022 in a Series A round that saw the company valued at $460 million, the Qredo crypto custody platform just had to secure debt financing to …
First American Financial Corp (one of the largest US title insurance providers) shut down its systems in late December 2023 after attackers accessed and encrypted non-production …
On 19 December 2023, St Vincent's Health Australia — the country's largest non-government healthcare and aged care provider, operating hospitals and aged care facilities across New …
The Aurory gaming platform uses a bridge called SyncSpace to move assets between the blockchain and the game's off-chain network. On December 17, the bridge was targeted on …
Attackers exploited old smart contracts from the NFT Trader peer-to-peer NFT trading application to steal pricey NFTs, including at least 37 Bored Apes, 13 Mutant Apes, and NFTs …
On 14 December 2023, an attacker compromised the npm account of a former Ledger employee (whose account retained access to the @ledgerhq/connect-kit package despite employment …
A supply chain attack on the Ledger connector application has rippled throughout the world of decentralized apps, which widely use the software to enable people to connect their …
The company behind the SafeMoon cryptocurrency scam has filed for Chapter 7 bankruptcy. Screenshots circulated on Twitter of a letter to employees citing "a number of operational …
Four individuals who helped launder money through shell companies and various bank accounts have been charged in connection to an $80 million "pig butchering" cryptocurrency scam. …
Many investors have reported losses thanks to a cryptocurrency investment scheme called HyperVerse, which operated in Australia from around 2018 to mid-2023. Several financial …
The Californian cryptocurrency exchange CoinList has settled a lawsuit from the Treasury Departments Office of Foreign Assets Control (OFAC) for $1.2 million. OFAC charged CoinList …
There was surprise in an Austrian courtroom when a defendant suddenly gave up any pretense of innocence, proclaiming, "I've run out of steam, I've finished driving... I plead …
OKX DEX is a service by OKX that aggregates decentralized exchanges (or DEXes) to help users access features and prices across multiple projects. On December 12, an attacker …
Two fraudsters capitalized on the hype around both cryptocurrency and artificial intelligence, advertising an "artificial intelligence automated trading bot" that they promised …
The collapse of the NFT bubble hasn't stopped Donald Trump from trying to cash out. Following in the footsteps of his wife, who timed things much better as far as interest in NFTs …
After raising $12 million from crypto-focused venture funds, the Immortal Game blockchain chess platform has announced that they would be nixing most of the blockchain part by …
The KuCoin cryptocurrency exchange has agreed to a settlement in which it will pay a $22 million fine and ban residents of New York state from its platform. The New York Attorney …
Periodically, Yearn Finance converts a small quantity of its treasury tokens into stablecoins to spend on operations. However, something went terribly wrong during this process …
Do Kwon, founder of the collapsed Terra/Luna project, will be extradited from Montenegro to the United States once he's completed his four-month-long jail sentence for document …
In April 2021, an attacker stole $50 million from the defi exchange Uranium Finance. Blockchain investigator zachxbt now says that he believes this attacker has been able to cash …
The Nostr Assets bitcoin platform has had to ask people to stop depositing into their platform because it's all clogged up. The project uses the bitcoin Lightning Network, which …
Binance says traders must have missed the memo on the AEUR stablecoin, which was intended to be pegged to the Euro. Shortly after it was listed on Binance, high demand caused the …
If you're named Rob Robb, do you have any choice but go into a life of thievery?Robb, also known as "pokerbrat2019", convinced at least 11 people to give him a total of $1.2 …
Projects using the suite of pre-built smart contracts from crypto development platform ThirdWeb have been racing to migrate to patched versions as ThirdWeb has disclosed a …
Users of the (not so) Safe Wallet have lost $2.05 million altogether in the past week as they've been targeted by an attacker using an address poisoning attack. The same attacker …
10,000 people's data stolen in genetic testing company Asper Biogene leak. Personal and health data belonging to approximately 10,000 people has been illegally downloaded from the …
60 credit unions facing outages due to ransomware attack on popular tech provider. The ransomware attack targeted the cloud services provider Ongoing Operations, a company owned by …
Healthcare software provider data breach impacts 2.7 million. ESO Solutions, a provider of software products for healthcare organizations and fire departments, disclosed that data …
Chinese nexus APT UNC5221 exploited chained zero-days in Ivanti Connect Secure VPN gateways starting Dec 2023, publicly disclosed Jan 10 2024 by Volexity. CVE-2023-46805 (auth …
In March 2022, Polygon boasted about how "The decision by DraftKings, a NASDAQ-listed company, to take an active role in day-to-day operations of a major network is an important …
An apparent address poisoning attack on the Florence Finance real-world asset lending protocol led to the loss of $1.45 million in the USDC stablecoin.As of December 4, Florence …
The crypto media website Forkast has stopped publishing and laid off most of its editorial staff. The last post on the site is from November 22.After raising $1.7 million in seed …
The crypto media website Forkast has stopped publishing and laid off most of its editorial staff. The last post on the site is from November 22.After raising $1.7 million in seed …
BitStable launched their BSSB token in a public sale only to watch as all tokens sold out in one block. Four entities acquired the majority of the BSSB tokens, an outcome that the …
After entering the crypto sector in 2019, the neobank SoFi is jettisoning the blockchain portion of its business by mid-December. Customers are being given the option to move their …
Attackers gained access to Integris Health's network on 28 November 2023. On 24 December 2023, Integris discovered that patients were being directly contacted by the cybercriminal …
Geisinger Health (major Pennsylvania health system) discovered on 29 November 2023 that former Nuance employee Andre Burk (age 46, California) had accessed patient records from 27 …
A scam Hong Kong cryptocurrency platform called Hounax swindled its customers out of HK$148 million (US$19 million). The group drew in customers by offering financial expertise on …
A Bitcoiner making a large transaction ended up spending 83.64 BTC (~$3 million) of the 139.42 BTC (~$5.1 million) transaction on transaction fees, effectively spending $3 million …
Justin Sun confirmed that HTX (formerly Huobi) and its related Heco Chain protocol were hacked for a combined $115 million. It's been a rough few weeks for Sun, whose Poloniex …
The KyberSwap decentralized exchange was hacked by an attacker who stole large sums of ETH, wETH, and the USDC stablecoin. Altogether, the assets are valued at around $54.7 …
Beginning 22 November 2023, CyberAv3ngers — a threat group affiliated with Iran's IRGC Cyber-Electronic Command — conducted attacks against Unitronics Vision Series PLCs at water …
Aragon is a prominent project that creates DAO infrastructure. Ironically, its own DAO-based governance has been fraught, with the group facing a governance crisis in May over …
Binance founder Changpeng "CZ" Zhao pleaded guilty to money laundering charges and agreed to step down as CEO of Binance, the largest global cryptocurrency exchange. He will pay a …
After paying a then-record $29 million fine for sanctions violations in October 2022, shutting down US operations in March 2023, filing for bankruptcy in May, and paying $24 …
At least according to the rather shady Tether stablecoin provider, the U.S. Department of Justice has been working on an investigation into a massive "pig butchering" romance scam …
According to Bloomberg, ongoing negotiations between the U.S. Department of Justice and Binance have involved penalties greater than $4 billion as part of ending an ongoing, …
Kraken is the latest cryptocurrency exchange to face a lawsuit from the U.S. Securities and Exchange Commission. According to the SEC, Kraken violated securities laws by listing …
The cryptocurrency trading firm Kronos Research announced on Twitter that they had stopped trading while they investigated "unauthorized access of some of our API keys". They …
Around 40% of the "insurance fund", intended to protect dYdX users from having to backstop other traders' losing trades, was drained in what dYdX CEO described as "pretty clearly a …
It's not that blockchain gaming was a flop, they were "just too early" (said CEO Sean Ryan). The Aqua gaming NFT marketplace announced their shutdown, attributing it to "challenges …
French blockchain firm The Blockchain Group announced that they had requested trading be halted on the company's shares and postponed a planned company meeting. The announcement …
On the evening of November 14 I logged on to Twitter to notice that #OpenSeaHackAlert and related hashtags were trending. But they were trending not because OpenSea had truly been …
Nation-state threat actor (attributed to Midnight Blizzard / Cozy Bear / APT29 in some reporting) used one access token and three service account credentials stolen during the Okta …
While trying to help a Bitcoin holder who lost their password, researchers at Unciphered discovered a major flaw in the way early Bitcoin wallets had been created. Thanks to a flaw …
An attacker apparently stole $27 million in the Tether stablecoin from a wallet that had just withdrawn the funds from their Binance account. The hacker quickly converted the funds …
A wallet drainer service has facilitated the theft of more than $60 million in various assets from almost 100,000 victims since May 2023. According to research group ScamSniffer, …
An attacker exploited the Raft defi project after finding a vulnerability that allowed them to mint 6.7 million of Raft's R stablecoin without any backing.The attacker then went to …
DP World Australia, which operates approximately 40% of Australia's container port throughput across terminals in Sydney, Melbourne, Brisbane, and Fremantle, suffered a cyberattack …
On 10 November 2023, DP World Australia — one of Australia's largest port operators, managing approximately 40% of Australian container port operations across Port Botany (Sydney), …
Fred Hutchinson Cancer Center (Fred Hutch), a major Seattle-based research hospital, suffered a ransomware attack between November 10–25, 2023. The Hunters International group …
Assets including Bitcoin, Ethereum, and Tron's TRX token, priced at more than $126 million, were stolen from Justin Sun's Poloniex cryptocurrency exchange. Researchers are still …
The treasury of the Samudai DAO was apparently drained as an attacker compromised the project's multisignature wallets and the wallet belonging to the project's founder, Kushagra …
The Australian cryptocurrency exchange CoinSpot appears to have been hacked for around 1,283 ETH (~$2.4 million). In two separate transactions, the ETH was transferred out of …
The US broker-dealer subsidiary of the Industrial and Commercial Bank of China (ICBC Financial Services) suffered a LockBit ransomware attack on November 8, 2023. The attack …
An MEV bot was exploited after an attacker discovered a vulnerability in its code that allowed anyone to call one of its functions that sold wBTC for wETH. Using a flash loan to …
"Public service announcement or 'how we are not really friends with Near Foundation and Aurora Labs going forward'", wrote Wintermute CEO Evgeny Gaevoy on Twitter. He launched into …
Indian police have arrested around eighteen people, including four police officers, in connection with a $300 million cryptocurrency scam that affected around 100,000 people in …
One might think that a social media lead might have a grasp on his own social media accounts, and might have scrubbed damning tweets made only shortly before they began their …
Bored Ape collectors attending an ApeFest party in Hong Kong have now been subjected to the kind of eye pain the rest of us have felt for years having to look at their hideous, …
On November 3, 2023, Sumo Logic, a cloud-native security analytics and log management platform, discovered that a compromised AWS access key had been used to gain unauthorized …
After less than five hours of deliberation, a jury convicted Sam Bankman-Fried of seven fraud and money laundering charges. The conviction followed a five-week-long trial which …
Welltok data breach exposes data of 8.5 million US patients. Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients …
Blue Shield of California Confirms MOVEit Data Breach at MESVision Compromised Consumers’ Confidential Information | JD Supra. On November 17, 2023, California Physicians' Service …
NY AG Issues Consumer Alert Regarding PJ&A Healthcare Data Breach | TechTarget. New York's Attorney General issued a consumer alert about the recent PJ&A healthcare …
Dollar Tree hit by third-party data breach impacting 2 million people. Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 people after …
Console & Associates, P.C.: PJ&A Reports Data Breach Exposing Social Security Numbers and PHI of an Unknown Number of Northwell Health Patients. /PRNewswire/ -- Millions of …
New Samsung data breach impacts UK store customers. Samsung Electronics is notifying some of its customers of a data breach that exposed their personal information to an …
Sutter Health Confirms 84K Individuals Affected by Cyberattack on Business Associate. Sutter Health, a healthcare provider serving Northern California, has recently confirmed that …
EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions progressing - Property Industry Eye. EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions …
Canadian government discloses data breach after contractor hacks. The Canadian government says two of its contractors have been hacked, exposing sensitive information belonging to …
Westat. Notice of data security incident affecting Renown Health patient information. Learn about the MOVEit vulnerability and credit monitoring. Third-party company: Nuance …
Midnight Blizzard (Russian SVR, also known as Nobelium/Cozy Bear/APT29) conducted a password spray attack against a legacy Microsoft test tenant account with no MFA enabled in …
Okta breach: 134 customers exposed in October support system hack. Okta says attackers who breached its customer support system last month gained access to files belonging to 134 …
Monero's Community Crowdfunding System (CCS) funds projects that aim to improve the ecosystem of Monero, a privacycoin. The CCS is funded by donations, and up until September 1, …
The Onyx Protocol was hacked for 1,164 ETH (~$2.1 million) after an exploiter took advantage of a known vulnerability affecting forks of Compound Finance. The bug allows attackers …
An indictment charging SafeMoon executives with defrauding investors via their SafeMoon token was unsealed in the Eastern District of New York. Three defendants were charged with …
LockBit ransomware group attacked Infosys McCamish Systems (IMS) between 29 October–2 November 2023, claiming to have encrypted 2,000+ corporate systems. IMS is a major BPO …
Truist Bank (6th-largest US bank) confirmed an October 2023 breach after threat actor 'Sp1d3r' listed the stolen data for sale on a dark web forum on 12 June 2024 for $1 million. …
A judge has ordered Ryder Ripps and his co-defendant Jeremy Cahen to pay almost $1.6 million in disgorgement and damages after they created a collection of identical NFTs to the …
A judge in the Cayman Islands has placed Aubit, the firm behind the Freeway crypto project, into liquidation. Freeway was a crypto lending project that promised annual returns as …
On October 19-20, 2023, unauthorized actors accessed the Sands LifeStyle loyalty programme database of Marina Bay Sands, Singapore's iconic integrated resort and casino. The breach …
The New York Attorney General filed suit against Gemini, Genesis, and Digital Currency Group (DCG), a group of companies that have been involved in a bitter feud amongst …
Superdao, a project aiming to assist communities in forming DAOs, has announced it will be closing its doors. It was blunt in its announcement: "it became clear that the crypto …
The U.S. Treasury Department introduced a proposal for new regulation that would require cryptocurrency mixers (also called tumblers) to up their recordkeeping and reporting …
A small defi protocol called Hope Lend was drained of nearly all its assets when attackers stole around 526 ETH (~$825,000). Hilariously, the project claims the hacker was frontrun …
The team behind the Everscale blockchain project disclosed that a "large number" of tokens had been stolen. In an attempt to thwart the attacker from cashing out, they announced …
An attack targeting the Fantom Foundation and its employees siphoned $7 million from wallets under their control. Of that, around $550,000 were funds belonging to the Fantom …
Reddit's attempt to blockchainify their signature Reddit karma has come to an end as the company has decided to pull the plug on the feature. The idea was that users could "own a …
Between October 16–19, 2023, attackers exploited the Citrix Bleed vulnerability (CVE-2023-4966) to gain unauthorized access to Comcast's Xfinity systems. Citrix had issued a patch …
A post falsely announcing that the SEC had approved a spot Bitcoin ETF caused $100 million in liquidations as the market briefly surged on the news. $81 million in short positions …
A lawmaker in South Korea has alleged that the Sui Foundation has engaged in market manipulation to enrich themselves. The South Korean Financial Supervisory Service reportedly …
A new, Euro-pegged stablecoin called $TEURO emerged on October 13, with an initial supply of around €70 million. However, TrueUSD subsequently tweeted that "we have zero …
An otherwise very "web2" hack has taken on a web3 twist as hackers have started to store malicious code on the blockchain. Attackers first compromise WordPress websites, then show …
At this point, they should probably just have a form email ready to go. Platypus Finance has suffered a cumulative $2.23 million in losses thanks to several attacks on the platform …
Simultaneous civil lawsuits from the Commodity Futures Trading Commission (CFTC) and Federal Trade Commission (FTC) against former CEO of the collapsed Voyager crypto lender accuse …
The real-estate-backed US dollar stablecoin "Real USD" (aka USDR) lost its peg, dropping from $1 to around $0.53. The website for the stablecoin was — even after the depeg — …
The Black Hole Token project suffered a $1.28 million apparent exploit, according to security firm PeckShield, though it's hard not to wonder if it might have been a rug pull.Black …
3Commas, a crypto trading bot provider, suffered another security breach in which some customer wallets were used to make unauthorized trades. They haven't disclosed how much in …
A metaverse gaming project called FinSoul promised users “sandbox worlds, multiplayer sports, leisure experiences, player socializing, MMORPG,” and other features. However, on …
The BNB Chain-based FSL token rug pulled within 24 hours of launching, with developers draining $1.68 million of liquidity they had amassed. Total loss estimated at $1,680,000.
Goldfinch is a decentralized lending platform aiming to provide undercollateralized loans, an unusual strategy in the crypto world where loans are typically overcollateralized due …
The American supermarket chain and cookie butter paradise, Trader Joe's, has filed a lawsuit against the popular Trader Joe decentralized exchange. According to the lawsuit, the …
Bitmain, the manufacturer of popular Bitcoin mining equipment (known as ASICs), is apparently in such dire financial straits that it can no longer pay employee salaries. Local …
Lucky Star Currency was an NFT-focused project released by a group claiming to be made up of astrologists. The group was heavily promoted on Chinese news and Q&A platforms. …
The United Kingdom's Financial Conduct Authority (FCA) has added another 146 entries to its "warning list" of unauthorized firms, including the crypto exchanges Huobi and KuCoin. …
Stars Arena, an Avalanche-based dupe of the popular Friend.Tech project, suffered a serious exploit in which an attacker drained tokens priced at around $3 million.Avalanche …
Even the best known NFT brand can't escape the effects of a collapsing industry. Yuga Labs, the company behind the blue-chip Bored Apes NFTs and related collections, and the …
The THORSwap decentralized exchange has put its web interface into "maintenance mode" in hopes of thwarting the thief who stole over $400 million from the FTX exchange as it was …
After agreeing to allocate $500,000 to "MMM" (merchandise, memes, and marketing — no, really), Gitcoin screwed up sending the money so badly that it's gone forever. Whoever was in …
The defi staking and lending project BigWhale announced that the private key to one of their crypto wallets had been leaked, and 7,200 BNB (~$1.5 million) had been stolen.In a long …
Crypto.com spent around two years operating in the Netherlands without bothering to register as required by the Dutch central bank — or pay the supervisory fees they were supposed …
LockBit 3.0 affiliates exploited Citrix Bleed (CVE-2023-4966) to breach Boeing Distribution Inc. (parts and distribution business). Session token extraction from Citrix NetScaler …
Truist Bank, a major US financial institution formed by the merger of SunTrust Banks and BB&T, confirmed in June 2024 that its systems had been breached in October 2023. The breach …
RCM Company Reports Data Breach Tied to MOVEit Software, 1.9M Impacted | TechTarget. The revenue cycle management company reported a data breach that impacted more than 1.9 million …
Cyberattack on health services provider impacts 5 Canadian hospitals. A cyberattack on shared service provider TransForm has impacted operations in five hospitals in Ontario, …
Cook County Health Patients Affected by Cyberattack at Medical Transcription Firm. Cook County Health, which operates John H. Stroger, Jr. Hospital and Provident Hospital in …
Third Flagstar Bank data breach since 2021 affects 800,000 customers. Flagstar Bank is warning that over 800,000 US customers had their personal information stolen by …
Cyberattacks Reported by Brooklyn Premier Orthopedics & Atlas Healthcare. Brooklyn Premier Orthopedics (BPO) in New York has confirmed the protected health information of 48,459 …
NorthStar Anesthesia patients may have been affected by breach - Becker’s ASC. Arietis Health, a medical billing company, recently filed a data breach notice. Medical billing …
SA patient health info deleted in third-party app breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …
Sony confirms data breach impacting thousands in the U.S.. Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a …
Super SA discloses third-party data breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …
Third-party company: Ipswitch, Inc..
September 2023 Healthcare Data Breach Report. September was a much better month for healthcare data privacy, with the lowest number of reported healthcare data breaches since …
In January 2024 (revealed for an exposure dating to September 2023), RedHunt Labs security researchers discovered that a GitHub API authentication token belonging to a …
The U.S. Securities and Exchange Commission filed a lawsuit against auditor Prager Metis, who they allege violated auditor independence rules and aided and abetted their clients' …
Co-founder of the collapsed Three Arrows Capital hedge fund, Su Zhu, was arrested in Singapore while allegedly trying to leave the country. He and his cofounder Kyle Davies have …
On 28 September 2023, an attacker used a stolen service account credential to gain access to Okta's customer support case management system. The attacker downloaded a report …
Threat actor accessed Okta customer support case management system Sept 28 - Oct 17 2023 using credentials stolen from an employee's personal Google account. 134 Okta customers …
Chase Bank’s UK branch has decided it will completely block debit card purchases and bank transfers that it identifies as being "related to crypto assets", a move they say is …
On 25 September 2023, Johnson Controls International — a global conglomerate manufacturing building automation systems, HVAC systems, fire safety systems, and physical security …
After the Hong Kong-based JPEX exchange limited withdrawals amidst what appeared to be an impending collapse of the platform, things are now looking a lot more like fraud.Police …
Upbit, a major South Korean cryptocurrency exchange, suddenly suspended deposits and withdrawals of the Aptos $APT token after some users were able to deposit and withdraw fake …
Justin Sun confirmed on September 25 that his crypto exchange Huobi (recently rebranded to "HTX") had been hacked for 5,000 ETH ($8 million) the prior day. He reassured customers …
The operators of the Mixin Network disclosed that hackers had stolen around $200 million in funds in the largest known hack of the year (to date). Mixin Network is a cross-chain …
Someone lost over $4.4 million of the Tether stablecoin after falling victim to a phishing scam that promised them fake mining rewards. A phisher lured in the victim, likely …
Balancer issued an urgent warning to stop using its web interface, as it was evidently compromised by malicious actors who redirected the funds to themselves. Within 30 minutes of …
"We believe that the platform will not collapse," wrote JPEX, amidst apparent collapse. JPEX is a Hong Kong crypto exchange that was advertising more than 20% APY on various …
Billionaire crypto evangelist Mark Cuban apparently fell victim to a hack when an attacker was able to siphon around $870,000 in multiple cryptocurrencies from a wallet belonging …
Ethereum prepared to launch a new test network, called "Holesky", which was supposed to be massive compared to the mainnet in order to work on scaling problems. The launch was …
Nouns DAO, one of the most prominent Ethereum DAOs, has split into two projects after holders of around 56% of the Nouns NFTs in circulation voted to "ragequit". This means that …
Crypto exchange Remitano suffered a hack in which $2.7 million in Tether (USDT), USDC, and Ankr was drained from the exchange's hot wallets across three blockchains. Luckily for …
Jacksonville Jaguars quarterback Trevor Lawrence has agreed to settle claims against him made in a class action lawsuit by FTX customers who say his endorsement of the fallen …
Maybe they'd sunk too much money into producing Killer Whales to back out, or maybe its creators actually think that a Shark Tank-style crypto reality TV series is what it will …
Maybe they'd sunk too much money into producing Killer Whales to back out, or maybe its creators actually think that a Shark Tank-style crypto reality TV series is what it will …
PolkaWorld, a major community within the Polkadot blockchain project, has announced that they will have to suspend operations as a funding proposal was overwhelmingly rejected. In …
After announcing on September 5 that Genesis would be closing their U.S. spot trading business in a "decision ... made voluntarily and for business reasons", Genesis has now …
In a rather amusing press release, the SEC announced they had charged "Stoner Cats 2 LLC" with conducting an unregistered securities offering when they raised $8.2 million selling …
Various blockchain watchers noticed suspicious transfers from a hot wallet known to belong to the CoinEx cryptocurrency exchange. CoinEx later confirmed a "security incident" …
Brian Shroder, the CEO of Binance's US entity, has left the crypto exchange as it faces an existential lawsuit from the U.S. SEC. Shroder is only the latest exec to leave Binance …
Karl Sebastian Greenwood, co-founder of the notorious OneCoin ponzi scheme, was sentenced to 20 years in prison after pleading guilty to fraud and money laundering charges. He will …
Fortress Trust is a crypto custody and blockchain infrastructure company, founded by Scott Purcell. Purcell is also known for founding Prime Trust, which later lost over $75 …
The team behind Banana Gun, a Telegram bot to help "snipe" token launches, launched a token associated with the project on September 11. Only hours later, they announced in a tweet …
A developer working on an NFT project spearheaded by Remilia, the DAO behind the Milady NFT project, stole around $1 million from the group by diverting fees generated by their new …
A wallet on the Bitcoin blockchain paid a 19.82 BTC ($499,171) fee to transfer 0.074 BTC ($1,865). Put another way, they spent 270x the transaction value to pay the fee. Bitcoin …
The Twitter account belonging to Vitalik Buterin, inventor and effective leader of the Ethereum project, was hacked to promote a crypto scam. A tweet posted to his compromised …
Scattered Spider (UNC3944) used LinkedIn to identify MGM employee, called IT helpdesk impersonating them to get Okta/Azure admin access. Waited 2 days then launched ransomware …
The NFT startup Glass was operating under the assumption that YouTubers and others who post video content for fans online might want to mint those videos as NFTs, which their fans …
As of writing, the April 2021 $2 billion Thodex exit scam is the second largest exit scam recorded in the Web3 is Going Great leaderboard. Thodex was one of the largest crypto …
The CFTC has announced charges and settlements against defi projects Opyn, ZeroEx, and Deidex for various commodities law violations. The projects will pay $250,000, $200,000, and …
Former CEO of FTX's Bahamian entity, Ryan Salame, has pleaded guilty to two criminal charges in the ongoing case against FTX and founder Sam Bankman-Fried. Salame (pronounced …
A crypto phisher hit it big today when they lured in a victim with a massive wallet balance. The victim wallet was drained of 4,851 rETH and 9,579 stETH, both wrapped versions of …
A group of high-profile streamers and social media influencers agreed to join eFuse's "Creator League", where they would lead community e-sports teams. The project was announced on …
Phishing scammers hoping to lure victims into visiting fake websites resembling that of the popular MetaMask crypto wallet have adopted a new approach: compromising government …
In November 2022, popular password management tool LastPass disclosed that hackers had stolen "password vaults" containing data belonging to more than 25 million users. Although …
The brand new Arbitrum-based defi casino GMBL.COMPUTER was exploited for around 471 ETH (~$770,000). The project, which promises to "generate yield from casino games", had …
Although Genesis Global Capital filed for bankruptcy in January 2023, portions of the larger business were not included in bankruptcy proceedings and continued to operate. One such …
Attackers managed to make transactions from hot wallets operated by the Stake betting platform, stealing approximately $15.7 million from their Ethereum wallet and around $25.6 …
"Even VCs are rugging now", remarked someone on Twitter as Nima Capital was observed selling 9 million $SYN (priced at ~$3.7 million before the sudden sale caused the token price …
National Student Clearinghouse data breach impacts 890 schools. U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using …
Airbus investigates data leak allegedly involving thousands of suppliers. The European aerospace giant Airbus said on Tuesday that it is investigating a cybersecurity incident …
Amerita Notifies Nearly 220K of PharMerica Data Breach | TechTarget. MedMinder Systems and PurFoods also reported healthcare data breaches recently. Amerita, a specialty infusion …
SickKids impacted by BORN Ontario data breach that hit 3.4 million. The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were …
Kroll data breach exposes info of FTX, BlockFi, Genesis creditors. Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted …
Several Colombian government ministries hampered by ransomware attack. A cyberattack on a technology provider caused a range of problems for government agencies in Colombia, …
PHI of Almost 75,000 Individuals Exposed in Email Incident at AmeriBen. IEC Group, Inc., doing business as AmeriBen, a medical benefits administration services provider, has …
University of Sydney data breach impacts recent applicants. The University of Sydney (USYD) has announced it has suffered a data breach through a third-party service provider, …
The two co-founders of blockchain gaming company Gala Games are suing each other. One lawsuit, filed by Gala Games CEO Eric Schiermeyer, alleges that Gala's director Wright …
"The wallets that did not upgrade in time will lose their assets," a StarkWare customer support representative said on Discord to an individual inquiring why they could no longer …
Brazilian blockchain gaming streamer Fraternidade Crypto says he lost his life savings after accidentally exposing his crypto wallet seed phrase during a livestream pertaining to …
Entertainment company Impact Theory has agreed to a $6.1 million payment to settle charges from the SEC that its sales of its "Founder's Keys" NFTs constituted an unregistered …
After warning users several days prior that a critical vulnerability had been discovered in their protocol, the Balancer defi project has been drained of around more than $2.1 …
A year after raising $4 million in a seed round joined by Multicoin Capital, Solana Ventures, and Asymmetric, Clockwork co-founder Nick Garfield announced that the Solana-based …
On August 27, 2023, a Retool employee received a convincing smishing (SMS phishing) message claiming to be from Retool IT support regarding a benefits enrollment issue requiring …
Magnate Finance, a lending protocol built on the new Base layer-2 blockchain, rug pulled within hours of a warning from crypto sleuth zachxbt. Zachxbt had discovered that a wallet …
The NFT collector SOL Big Brain lost around $1.5 million in ETH, stablecoins, and the Gearbox token after being targeted in a phishing scam. The attacker apparently compromised a …
Holders of the $PEPE memecoin sold en masse after the PEPE multisig wallet transferred more than 16 trillion $PEPE (~$16.9 million) to crypto exchanges. Although the multisig …
After seizing a little more than $500,000 in the Tether stablecoin from two accounts it believed were involved in illegal narcotics sales, the DEA mistakenly sent $50,000 of the …
John DeSalvo, a former New Jersey corrections officer, was charged by the SEC over a pump-and-dump scheme associated with his "Blazar" token, a project he targeted at fellow law …
A year after the Department of Treasury added Tornado Cash to the OFAC sanctions list, the DOJ has come in to charge the service's two founders with conspiracy charges involving …
Balancer, a popular Ethereum-based defi protocol, has warned users that they should withdraw funds from vulnerable pools on the project after receiving a report of a critical …
Google Ad phishing is the practice of taking out a Google advertisement to promote a malicious website impersonating a legitimate project. By taking out the ad, the result is …
Titan Global Capital Management, an investment advisory firm, has been charged by the SEC for violations of securities laws, including misrepresenting potential investment …
The "interchain stablecoin protocol" Harbor announced on August 19 that they had experienced an exploit that drained some of the funds in the project pools. They wrote on Twitter …
Scattered Spider targeted Caesars' outsourced IT support vendor Aug 18 2023 via voice phishing, convincing vendor to hand over Okta credentials. Within days accessed 6TB loyalty …
The Exactly Protocol, an attempt to "decentralize the credit market" built on the Optimism layer-2 network, was exploited. The protocol announced a pause to investigate a security …
Despite the catastrophic Terra/Luna collapse in May 2022, the Terra blockchain is still up and running. On August 19, the official Twitter account for the Terra project tweeted …
Bryan Lawrence, the leader of a crypto project called Glow Token, recently shared that he'd fallen victim to scammers impersonating employees of the Crypto.com exchange. Lawrence …
Farmington State Bank, also known as Moonstone Bank, is a tiny Washington state bank that drew scrutiny after the FTX collapse for receiving an outsized investment from the firm. …
In September 2021, the Recur NFT platform announced it had raised $50 million in a Series A funding round that saw the startup valued at $333 million.In December 2021, the company …
Payment gateway provider Slim CD disclosed that attackers had access to its systems from 17 August 2023, with credit card data specifically accessed 14-15 June 2024 before …
Blockchain Capital co-founder Bart Stephens has filed a lawsuit against as-yet-unknown individuals who he says stole $6.3 million in cryptocurrency from him. The attackers used a …
People were very excited when the Shiba Inu-focused "Shibarium" layer-2 Ethereum blockchain went live on August 16. The dog-themed network is part of a push to make Shiba Inu a …
Despite the fact that Coinbase's Base blockchain was only officially launched a week ago, and a relatively small amount of funds are locked on the chain, it's already racking up …
After the Nevada Financial Institutions Division issued a cease and desist describing Prime Trust as insolvent in June, then successfully requested the company be placed into …
Shenzhen Shikongyun Technology, a company focused on mining the Filecoin token, has been accused of running a pyramid scheme. Four of the company's executives were also charged. …
Exploiters stole around 471 ETH (~$857,000) from the RocketSwap project on the Base Ethereum layer-2 blockchain. According to RocketSwap, the project had stored private keys on a …
The Zunami Protocol stablecoin-focused yield farming aggregator was exploited for more than $2.1 million when an attacker was able to perform a price manipulation attack on the …
After pulling off a rug pull that only netted 14 ETH (~$25,900), Allen Lin (known as AzFlin) lost his day job for the company that maintains the Uniswap DEX. Hope it was worth …
On 11 August 2023, Clorox Company — one of the world's largest consumer goods manufacturers (Clorox, Hidden Valley, Burt's Bees, Kingsford charcoal) — detected a cyberattack and …
The Bittrex crypto exchange was charged in April by the SEC for operating an unregistered exchange, broker, and clearing agency. In May, Bittrex filed for bankruptcy. Now, Bittrex …
Ransomware hit Rapattoni Corp. (California-based MLS software provider serving ~100 MLSs and approximately 5% of US MLSs) on 9 August 2023. The attack froze MLS systems used by …
A team of researchers led by the Distrust security research firm have disclosed a vulnerability they've called "Milksad". The popular Libbitcoin project was used by multiple …
Hundred Finance is a lending protocol that was exploited in April 2023 for around $7 million, and in March for over $6 million. Since then, they've worked with law enforcement and …
SpiritSwap announced on its Discord that the project will be shutting down on September 1 unless they can find a new team to take over the project by that time. SpiritSwap lost …
Scammers are constantly coming up with creative new ways to pull off their scams, and the latest seems to be targeting web3-interested individuals via dedicated web3 jobs portals. …
Disney has shut off the last light in its metaverse division, parting ways with "metaverse chief" Michael White. In February 2022, Disney's then-CEO described the metaverse as "the …
Dollar Tree and its subsidiary Family Dollar disclosed in November 2023 that Zeroed-In Technologies, a third-party HR analytics vendor they used, suffered a data breach between …
The Solana-based Cypher protocol, a decentralized futures exchange, froze its smart contract after an attacker stole a little more than $1 million in Solana tokens and the USDC …
"NOTICE: Steadefi has been exploited and all funds are currently at risk," wrote Steadefi on Twitter after an attacker was able to change the contract owner to their own address — …
Jinwook Shin, CEO of the Bitsonic crypto exchange, was arrested in South Korea for allegedly stealing funds from users of his exchange. According to the prosecutors, he allegedly …
Hong Kong crypto news outlet Techub cited two insiders when reporting on August 5 that "at least three executives" at Huobi had been detained by Chinese police for investigation. …
After Kenya shut down Worldcoin's operations in the country over data privacy concerns, police have raided a warehouse in Nairobi. Authorities reportedly took "machines they …
After noticing someone set up a bot to copy his bids, NFT trader Hanwe Chang tricked the bot into purchasing multiple NFTs at hugely inflated prices. Chang purchased a large number …
Revolut, a British fintech firm, has announced it will no longer offer cryptocurrency services to its US-based customer. As is becoming typical, they blamed US regulations and …
Uwerx is a nascent project intending to build a blockchain-based freelancer marketplace, because what better concepts to combine than blockchains and the gig economy? Sadly for …
Nifty's was a web3 business backed by the likes of Mark Cuban, Joey Lubin, Coinbase, and Dapper Labs. In 2021, they raised a $10 million seed round, and launched as an NFT-focused …
Third-party company: Vodatech IT.
Third-party company: Vodatech IT.
In 2023, BeÅiktaÅ Sportive Products Industry and Trade AS experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was …
Records of 4 Million Coloradans Compromised in MOVEit Transfer Attack. The Colorado Department of Health Care Policy and Financing (HCPF), which oversees the state’s Medicaid …
Third-party company: Vodatech IT.
Third-party company: Vodatech IT.
In 2023, DoÄan Trend Automotive Trade Service and Technology Joint Stock Company experienced a data security incident via a third-party vendor relationship. The compromised …
Eversource reports data breach as companies across Connecticut struggle with cyber attacks.. Eversource joined M&T Bank and a number of other major U.S. companies to report. An …
Third-party company: Vodatech IT.
IBM Discloses Data Breach Impacting Janssen Healthcare Platform. This website stores cookies on your computer. These cookies are used to improve your website experience and provide …
Nuance Communications Notifies 1.2M Individuals of Data Breach | TechTarget. Another incident stemming from a vulnerability in Progress Software’s MOVEit Transfer software has been …
Third-party company: Vodatech IT.
August 2023 Healthcare Data Breach Report. There was a 21.4% month-over-month increase in healthcare data breaches in August. 68 data breaches of 500 or more records were reported …
Third-party company: Vodatech IT.
Third-party company: Vodatech IT.
Ransomware Hit Disrupts Real Estate Property Listings in US. Property listings nationwide are being disrupted due to an apparent ransomware attack against California-based …
A zero-transfer attack, also called an address poisoning attack, occurs when a phisher creates a blockchain address very similar to that of a target victim's wallet, and sends …
Although Coinbase's Base blockchain is at this stage intended for testing only, people have begun bridging substantial assets to the platform and using various services in …
A memecoin called $BALD, built on the Coinbase Base test network, appears to have rug pulled for at least $25.6 million. Although the Base network is meant to be used for developer …
The SEC filed charges against Richard Heart, the operator of Hex, PulseChain, and PulseX. Despite Heart's best attempts at evading securities laws — including by asking people to …
Some types of Curve factory pools, including one operated by AlchemixFi and one by JPEG'd, were exploited. The attack stemmed from an issue in the Vyper language, a smart contract …
The defi yield aggregator project Kannagi Finance rug pulled on July 29 as its creators drained the $2.13 million total value locked. Kannagi Finance deleted its website and social …
Traders hoping to get in on the next big memecoin eagerly snapped up a token called Pond0x, a Pepe the Frog-branded memecoin launched by Pauly0x. Pauly0x is Jeremy Cahen, a crypto …
A defi project called DeFiLabs was able to rug pull for $1.6 million thanks to a backdoor written into the smart contract. After traders bought into the project, its creator was …
The CoinsPaid crypto payment platform, which provides payment services to various online casinos, reportedly suspended withdrawals under mysterious circumstances. The company later …
The EraLend crypto lending platform was exploited for around $3.4 million after an attacker took advantage of a re-entrancy vulnerability to manipulate token prices and drain funds …
The crypto payment processor Alphapo suffered a hot wallet hack on July 22 in which at least $60 million in Ethereum, Tron, and Bitcoin was stolen. Alphapo processes payments for …
The IEGT token was created on Binance Smart Chain on July 13. However, its creators "covertly minted a large amount of tokens, primed for a rug pull", as blockchain security firm …
Hours after suffering a $3.2 million exploit on their ETH pools, Conic Finance was hacked for a second time. Although Conic had assured the public that the incident was limited to …
A re-entrancy vulnerability in the Conic Finance defi project enabled an attacker to steal 1,700 ETH (~$3.22 million) from the project's ETH pool.Conic Finance announced that they …
You almost have to hand it to the Party Parrot team, they really figured out how to take advantage of ostensibly "decentralized" governance to line their own pockets. After raising …
Melania Trump doesn't seem willing to let the flop of her first NFT project, which ended with her allegedly buying the NFT herself, slow her down. She's just announced a line of …
The GMETA project on BNB Chain saw its price plummet to near zero as the project creators drained the funds from the project. The contract creator was able to transfer large …
Documents unsealed on July 17 reveal that the U.S. Secret Service performed multiple asset seizures on U.S. bank accounts controlled by Deltec Bank, a Bahamian bank with close ties …
A Canadian named Dan, who goes by "Soup" online, made more than $1 million through various phishing scams targeting Discord projects including those belonging to the Pika Protocol …
Hector DAO, the governing body behind the Hector Network, voted to liquidate the project's $16 million treasury and distribute it to tokenholders, effectively putting an end to the …
After announcing a Neopets Metaverse project — complete with NFT collections and two different crypto tokens — in 2021, Neopets has announced they will be "transition[ing] away …
Five men are facing charges for allegedly kidnapping, confining, and beating Aiden Pleterski, the young, self-proclaimed "Crypto King" accused of losing $35 million in investor …
Defi lending project Geist Finance announced they would be shutting down after more than $200 million was drained from the Multichain project in two separate events in early July. …
After a months-long saga involving "stuck" transactions, Multichain announcing they couldn't get in contact with their CEO, rumors that the whole team was arrested, and several …
A multi-agency hammer came down on the bankrupt cryptocurrency lender and alleged Ponzi scheme that was Celsius. The co-founder and former CEO of the company, Alex Mashinsky, was …
Adam Todd, the CEO of the Digitex Futures exchange, has been ordered to pay $3.9 million in disgorgement and $11.7 million in penalties. The Commodity Futures Trading Commission …
OptyFi, a so-called "AI-powered defi" project, announced it would be shutting down for a variety of reasons. First, they blamed their recent failed token sale, in which they had …
Platypus Finance paused their pools after they were alerted to what they described as "suspicious activities". Security firm PeckShield was apparently the first to notice the …
An attacker manipulated a price oracle to drain 472 ETH (~$884,000) from Rodeo Finance, a new Arbitrum-based leveraged yield protocol. The thief then used Tornado Cash to tumble …
Arkham Intelligence, a blockchain intelligence company with the tagline "deanonymizing the blockchain", announced the launch of its "on-chain intelligence exchange", inviting …
Only five days after $130 million was emptied from the Multichain blockchain bridge, another $107 million in a wide range of assets has been taken. After the first theft, …
The U.S. Attorney's Office of the Southern District of New York announced the unsealing of charges against Soufiane Oulahyane, who they allege created a lookalike OpenSea website …
AlgoFi, a lending protocol built on the Algorand blockchain, announced that they will begin winding down the project. They were vague about the specific reasons, writing only that …
In a somewhat amusing complement to Arkham Intelligence's "on-chain intelligence exchange" announcement, a new product which seeks to allow people to buy and sell private …
Arcadia Finance is a defi margin trading protocol that launched on Ethereum and the Optimism Ethereum layer 2 protocol in March 2023. On July 9, an attacker used a flash loan to …
Dubai's Virtual Assets Regulatory Authority issued an alert that BitOasis was "under review for not meeting mandated conditions". In April, BitOasis received the first "MVP …
An attacker successfully compromised the Twitter account belonging to the popular Gutter Cat Gang NFT project, as well as the one belonging to the project co-founder, and used them …
Blockchain watchers observed $130 million in various assets flowing out of the Multichain blockchain bridge, questioning whether there had been an exploit. Multichain tweeted, "The …
A small and rather unknown project called BarnBridge aimed to build a variety of defi yield projects. BarnBridge claimed to be decentralized and governed by a DAO. On July 6, an …
A project called NFTPerp was, as the name suggests, a perpetual futures exchange for NFTs, allowing people to take long or short positions against NFTs. It relied on a vAMM — …
On 5 July 2023, a threat actor posted for sale on an online forum a database purporting to contain approximately 27.7 million records from HCA Healthcare — the largest US …
After paying nearly $40 million for a new set of Azuki NFTs, the Azuki community is pissed that they were "dilutive" near-copies of the original Azuki collection. To fight back …
Crypto personality LoveMake.eth wrote a Twitter thread about how they fell victim to a phishing scam in which an account appearing to belong to the cofounder of the popular Doodles …
The name Poly Network may ring a bell, because in August 2021 they were exploited for an (at the time) record-setting $611 million.Now, it's happened again, and some reports are …
A project called "Encryption AI" promised a Telegram bot that would provide a "secure and efficient way to launch tokens". People poured in around $2 million before the developer …
In September 2023, Dymocks Booksellers — Australia's largest book retailer operating approximately 65 stores — disclosed a data breach affecting approximately 836,000 customers. …
Third-party company: Mivento IT Services.
Third-Party Data Breaches Continue to Dominate Breach Notifications | TechTarget. The MOVEit hack and other third-party data breaches continue to impact healthcare entities across …
Third-party company: Mivento IT Services.
Third-party company: Mivento IT Services.
Activate Healthcare Reports Security Breach Affecting up to 93,761 Patients. The Illinois-based healthcare provider, Activate Healthcare, LLC, has recently confirmed that it …
US govt contractor Serco discloses data breach after MoveIT attacks. Serco Inc, the Americas division of multinational outsourcing company Serco Group, has disclosed a data breach …
Third-party company: Mivento IT Services.
Datenleck bei Postbank und Deutscher Bank / Kriminelle kopieren Bankdaten. Lahr (ots) - Hacker haben Daten von Kunden der Deutschen Bank bei einem Datenleck gestohlen. Auch die …
Third-party company: Mivento IT Services.
Third-party company: Mivento IT Services.
Third-party company: Mivento IT Services.
Third-party company: Mivento IT Services.
Bad news for wealthy crypto traders on Kraken, who previously might have hoped to evade paying taxes on their past crypto trades. A judge has ordered the exchange to turn over …
A little less than a year after raising $4.4 million in seed funding to build a Solana NFT protocol that allowed for NFT rentals and other such things, Cardinal Labs has announced …
After the Huobi crypto exchange (finally) fixed a massive vulnerability, researcher Aaron Phillips published a blog post explaining what he had found. According to Phillips, two …
Chibi Finance was a defi project built on the Arbitrum Ethereum layer 2 network. Its Twitter bio described the project as "ChibiVerse For Chads, by Chibis. Compound dem yields!" …
Themis Protocol is a lending platform that has had somewhat of an excruciating rollout, with users waiting ever longer for the platform to finally go live as they endured …
The blue-chip "Azuki" NFT brand opened sales on June 27 for its latest NFT collection, a 20,000-piece project called "Elementals". Eager to get in on the Azuki action, people …
Quick tip: if you're in jail and a fellow inmate who is serving twelve years for running a Ponzi scheme asks you to invest in a Bitcoin scheme, don't do it. Then again, on the list …
New Zealand-based We Are Bamboo may have been an ethical travel company, but they certainly weren't an ethical handler of customer funds. In late October 2022, the company abruptly …
Nevada's Financial Institutions Division and the Prime Trust crypto custodian requested that Prime Trust be placed into receivership, according to the NFID. A week earlier, the …
According to a report from NPR, a crypto investment scam called SpireBit drained the life savings of a 74-year-old man in California. The scheme followed a familiar pattern: an …
A phishing scam in which scammers airdropped fake NFTs impersonating real projects has landed the scammers around $1.25 million in the last two months. The scammers have created …
Belgium's Financial Services and Markets Authority alleged on June 2023 is violating prohibitions against "offering and providing exchange services in Belgium between virtual …
A company that promised an app that could identify dogs by their nose-prints — built on the blockchain, of course — has been alleged by South Korean police to be "a typical Ponzi …
What is it with former child stars and the siren song of crypto? Zachery Ty Bryan, who played Brad on the sitcom Home Improvement in the 90s, got rich when he used his earnings to …
The planned acquisition by BitGo of the Prime Trust crypto custodian fell through on June 22, as BitGo announced that they had "made the hard decision to terminate its acquisition" …
The Nevada Financial Institutions Division issued a cease and desist to the Prime Trust crypto custodian. Earlier in the month, the apparently embattled Prime Trust signed a …
Web3 influencer Elena announced she would be launching an NFT collection titled "Atomic Ordinals", which would be inscribed on the Bitcoin blockchain. She claimed that the 200 …
Binance's footprint is shrinking even further, as the company has canceled its registration with the United Kingdom's Financial Conduct Authority (FCA). This means that the company …
A report out of the Financial Times alleges that the Singapore-based Crypto.com exchange runs proprietary trading and market making teams. This is a controversial activity — though …
A report out of the Financial Times alleges that the Singapore-based Crypto.com exchange runs proprietary trading and market making teams. This is a controversial activity — though …
As they are wont to do, Binance set up shop in the Netherlands without getting permission from the country's regulators. However, after being warned and then fined €3.3 million …
Crypto personality and creator of C.R.E.A.M. Finance Jeffrey Huang, aka "Machi Big Brother", has filed a defamation lawsuit against crypto sleuth zachxbt. Huang alleges that …
The crypto payments platform Wyre finally announced they would be winding down "due to market conditions". This came after a January announcement from the CEO, where it was not …
The institutional cryptocurrency broker Floating Point Group (FPG) announced to customers on June 14 that they would be suspending all activity on their platform following a "cyber …
In an emergency cease-and-desist issued on June 15, the Texas State Securities Board alleged that the Abra crypto lending firm was "insolvent or nearly insolvent" as of interviews …
Although Binance's Cyprus arm was only registered in October 2022, the company is already looking to deregister in the country. According to Binance, they're pulling back in …
The US arm of Binance has cut around 50 positions, amounting to approximately 10% of its US employees. In a message to employees, Binance.US CEO Brian Shroder explained, "Because …
The Hong Kong-based cryptocurrency exchange CoinEx has agreed to pay $1.17 million in refunds to investors and $600,000 in penalties for failing to register as a securities and …
South Korean cryptocurrency lending platform Delio announced to its customers on June 14 that they would be suspending withdrawals. In a letter to customers, they wrote that the …
Banq, a subsidiary of the Prime Trust crypto custodian, has filed for bankruptcy. Banq is a "crypto-friendly" payment processor based in Nevada, though according to the bankruptcy …
The South Korean yield platform Haru Invest abruptly suspended withdrawals and deposits on June 13. They wrote in a blog post that they were experiencing "a certain issue" with an …
Although developers abandoned the Atlantis Loans defi lending project in early April due to "financial difficulties", as a self-executing defi protocol it has continued to chug …
After the massive BNB Chain bridge hack in October 2022, the hacker was able to take out a massive position with the Venus Protocol defi lending project. They borrowed $150 million …
The Sturdy Finance defi lending protocol was exploited, with hackers taking advantage of an oracle manipulation vulnerability to make off with 442 ETH (~$775,000). They …
On June 10, TrueUSD announced on Twitter: "TUSD mints via Prime Trust are paused for further notification." They offered no further explanation. TUSD is the fifth largest …
Robinhood announced that its crypto exchange will delist the tokens for Solana (SOL), Cardano (ADA), and Polygon (MATIC) after they were described as unregistered securities in …
Ooki DAO was sued in September of last year for allowing illegal trading of digital assets, engaging in activities only allowed by registered futures commission merchants, and not …
Singapore's Crypto.com has announced it will be imminently shutting down its institutional exchange service in the US, citing "limited demand from institutions in the U.S. in the …
Adding insult to injury in Binance's tough couple of days, someone has managed to hijack the Discord vanity URL used by BNB Chain, the blockchain project associated with Binance. …
The SEC has clearly been busy. The agency followed up its complaint against Binance by smacking Coinbase with charges the very next day. This isn't terribly unexpected: in late …
The SEC has filed a complaint against Binance, various related companies, and Binance CEO Changpeng "CZ" Zhao. They allege that the company has been acting with "blatant disregard" …
Multiple users of the Atomic Wallet software suffered wallet compromises totaling more than $100 million in a spate of hacks suggesting an issue with the wallet itself. Atomic …
Australian Government Says Its Data Was Stolen in Law Firm Ransomware Attack. This website stores cookies on your computer. These cookies are used to improve your website …
Genworth Financial Confirms 2.5 Million Customers Affected by MOVEit Data Breach | JD Supra. On June 22, 2023, Genworth Financial, Inc. filed documents with the Securities and …
UPMC contractor detects patient data breach. A contractor for UPMC said it discovered a data breach that could have impacted customer and patient information. Tennessee-based …
Extreme Networks emerges as victim of Clop MOVEit attack | Computer Weekly. Network equipment and services supplier Extreme Networks has revealed its instance of Progress …
Dublin Airport staff pay data hit by criminals. Attackers accessed it via third-party services provider, says management group. It's an awkward Monday for Dublin Airport after pay …
Capital One becomes latest bank affected by cyberattack on debt-buying giant. The initial response to the incident focused on former customers of Bank of America, but Capital One …
MOVEit attack on Aon exposed data of the staff at the Dublin Airport. [](https://www.facebook.com/sec.affairs/)[](https://twitter.com/securityaffairs). UAT-10362 linked to …
Millions of Oregon, Louisiana state IDs stolen in MOVEit breach. Louisiana and Oregon warn that millions of driver's licenses were exposed in a data breach after a ransomware gang …
MOVEIt breach impacts Genworth, CalPERS as data for 3.2 million exposed. PBI Research Services (PBI) has suffered a data breach with three clients disclosing that the data for 4.75 …
American Airlines, Southwest Airlines disclose data breaches affecting pilots. American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data …
Hackers steal data of 45,000 New York City students in MOVEit breach. The New York City Department of Education (NYC DOE) says hackers stole documents containing the sensitive …
media-center press-releases 2023 07 14 hillsborough-notifies-residents-vendors-of-global-data-breach. Skip to main content Enable accessibility for low vision Open the …
Missouri warns that health info was stolen in IBM MOVEit data breach. Missouri's Department of Social Services warns that protected Medicaid healthcare information was exposed in a …
After a developer leaked private keys to GitHub, someone used them to drain $375,000 from the unshETH defi project. The project emergency paused withdrawals of unshETH ether to …
In September 2024, the FBI and CISA announced the disruption of a botnet operated by Flax Typhoon, a Chinese state-sponsored threat actor (also tracked as RedJuliett/Ethereal …
Seeming to bow to regulatory pressures, Binance announced they would delist various privacycoins including Monero, ZCash, and MobileCoin for some regions. Privacycoins are tokens …
Crypto giant Binance has reportedly begun layoffs, according to independent crypto reporter Colin Wu, who cited several anonymous sources. The layoffs will amount to around 20% of …
A Chinese cryptocurrency publication has reported that the staff of Trust Reserve (formerly CNHC Group) were detained by police. A sign on the door of the company's office in …
A person claiming to be battling cancer created a "charity NFT project" ostensibly to help with her treatment. She convinced some crypto influencers to promote the project, …
The cryptocurrency exchange Bybit announced that they would be exiting Canada. The company cited "recent regulatory development" in the country for their decision to stop offering …
According to a report from The Information, MoonPay executives including CEO Ivan Soto-Wright pocketed $150 million from their $555 million Series A funding round completed in …
A report from The Athletic indicates that the National Football League Players Association, a labor union for NFL players, has been unable to collect nearly $42 million it is owed …
The new Arbitrum-based El Dorado Exchange (EDE) was exploited for around $580,000. In an interesting twist, the attacker claimed to be a whitehat who was exposing that the …
The BKEX crypto exchange announced on May 29 that they would be suspending withdrawals, claiming it was related to a police investigation. "Recently, the platform users' funds were …
Three days after the launch of its v2 protocol, the Arbitrum-based Jimbos Protocol was exploited for 4,090 ETH (~$7.5 million). The project had not properly controlled for …
Patricia, a retail cryptocurrency trading app in Nigeria, froze withdrawals after revealing that they had suffered a ₦2 billion hack. According to the outlet TechCabal, despite …
CL0P ransomware gang exploited a zero-day SQL injection in Progress Software's MOVEit Transfer MFT product starting May 27 2023. Installed LEMURLOOT web shell to steal data. Over …
Welltok, Inc. — a healthcare SaaS company providing patient health engagement and communication services to major US health plans — was among the largest individual victims of the …
Maximus Inc. (US government contractor managing Medicare, Medicaid, student loan programs) was the largest single victim of Cl0p's MOVEit campaign. SEC 8-K filed July 26 2023 …
Some traders hoping to snipe new tokens launched by Poo Finance (yes, really) decided to try to use a MEV bot to snag priority ordering compared to other pending blockchain …
A lawyer for a broker and the former director of the South Korean cryptocurrency exchange Coinone have told a court that their clients "admit the facts of the prosecution". The …
Digital Currency Group, the parent company of several companies in the crypto industry including Genesis, Grayscale Investments, and CoinDesk, announced that it will be shuttering …
The US-based crypto payments and custody platform Unbanked announced in a blog post that they will be shutting down services. The company was founded in 2018, and claimed they …
Twitter account compromises remain a lucrative way to scam crypto enthusiasts. Someone was able to compromise the Twitter account belonging to electronic musician and crypto …
The Multichain blockchain bridge, formerly known as Anyswap, encountered an apparent issue as users' funds were delayed for over 24 hours in getting to their destination. Some …
A Ponzi scheme called Morgan DF Fintoch lured consumers by claiming to be owned by the American banking giant Morgan Stanley. Morgan Stanley themselves warned of the scheme, …
An attacker exploited the brand new $CS token for almost $700,000 using a flash loan exploit. They then swapped the funds into around 383 ETH ($689,400) and laundered them through …
A proposal ostensibly to penalize cheating network participants in the Tornado Cash crypto tumbler project successfully passed by DAO vote. However, the proposer had added an extra …
Croatian company BitLucky told its customers that it would invest their money in cryptocurrencies, promising 5–25% monthly profits. However, its director Luka Burazer wrote an …
A scam-as-a-service company identified by ScamSniffer and dubbed "Inferno Drainer" has stolen assets nominally worth around $5.9 million since mid-February. The vendor sells …
Recently, the Aave protocol deployed a contract upgrade on the Polygon version of their v2 project that was not compatible with Polygon. The bug has resulted in around $110 million …
On May 19, an attacker successfully exploited the BNB Chain-based defi project WDZD Swap, making off with 609 Binance-Pegged ETH (~$1.1 million). The attack was apparently executed …
Cryptocurrency trading platform Coin Cafe will pay $4.3 million in restitution to customers who were charged high fees after signing up for a "free" crypto custody service. The …
A Grumpy Cat Coin memecoin emerged in May, with a website using illustrations of the late real-life Grumpy Cat to promote the coin. Crypto influencers, including the "SlumDoge …
Decentralized exchange Swaprum, a project on the Arbitrum layer-2 network, suddenly disappeared with around 1,628 ETH (~$2.96 million) in an apparent rug pull. The thieves then …
"Show me the incentive and I will show you the outcome."Sam Altman's Worldcoin project, a dystopian effort to use chrome orbs to scan the irises of people (often in developing …
Nevin Shetty, the former chief financial officer of the Fabric e-commerce platform, was federally indicted for wire fraud after allegedly misappropriating $35 million from Fabric …
Storm-0558, a Chinese state-sponsored threat actor (attributed to MSS), acquired a Microsoft MSA consumer token signing key (method of acquisition still unclear as of CSRB review) …
Blockchain security firm SlowMist has reported that a phishing website appearing to be the real cryptocurrency exchange HitBTC has stolen more than $15 million worth of Bitcoin, …
South Korean lawmaker Kim Nam-kuk has resigned over a cryptocurrency scandal. On May 8, 2023, The Korea Times reported that Kim cashed out around 800,000 Wemix tokens priced at …
A year ago, Andreessen Horowitz general partner Arianna Simpson wrote about the firm's investment into Irreverent Labs. Simpson had joined their first $5 million funding round, and …
A year ago, Andreessen Horowitz general partner Arianna Simpson wrote about the firm's investment into Irreverent Labs. Simpson had joined their first $5 million funding round, and …
Akira ransomware group breached Stanford University's Department of Public Safety (SUDPS) network between May 12 and September 27 2023. Stanford disclosed the incident on October …
If you've found yourself thinking "man, I wish I could buy a hundredth of an NFT", you now have one fewer options. Andy Chorlian, co-founder and CEO of fractional NFT platform …
The American corporation Bakkt recently acquired Apex Crypto, a Chicago-based crypto trading service. Bakkt shares a majority owner with the New York Stock Exchange. Shortly after …
Binance announced they would be exiting Canada, "proactively withdrawing" ahead of stablecoin regulation and crypto investment limits. As is becoming a trend in the industry, …
As the Aragon Association took steps to "progressively decentralize" their centralized project by assigning more control to the Aragon DAO, they encountered some challenges. …
A bit over a month after Bittrex announced it was closing US operations, and less than a month after the US SEC charged the company with operating an unregistered exchange, Bittrex …
Everledger was an Australian company that hoped to use blockchains to track provenance of diamonds, other precious gems, fine wines, and other luxury goods. Things apparently …
A recent surge in memecoin popularity has caused Ethereum transaction fees to skyrocket. One trader paid the price, eating a 64 ETH ($118,000) transaction fee just to perform a …
Deus Finance suffered yet another hack as around $7 million was taken from the protocol. This was not the first time the platform had been targeted, suffering a $3 million exploit …
Deus Finance suffered yet another hack as around $7 million was taken from the protocol. This was not the first time the platform had been targeted, suffering a $3 million exploit …
A project called Xirtam, built on the Arbitrum blockchain, raised 1,909 ETH (~$3.2 million) in several fundraising rounds in April 2023. Then, on May 4, the project rug pulled. …
WallStreetBets is a subreddit that became popular during the pandemic-fueled everyone-should-become-a-daytrader era, and is known for its memestocks and its users who often make …
Nate Chastain, the former Head of Product for the popular OpenSea NFT marketplace, was convicted by a jury of fraud and money laundering for illegally profiting from his insider …
As regulatory groups have started to pay more attention to crypto platforms, it hasn't been terribly unusual to see them tighten their identification requirements — particularly …
Coles confirms its customers impacted by Latitude Financial data breach. Supermarket giant Coles has confirmed it has been impacted by the Latitude Financial data breach, saying …
Cornerstone Home Lending Files Notice of Data Breach After Cybersecurity Incident at Third-Party Vendor | JD Supra. On April 3, 2023, Cornerstone Home Lending (“Cornerstone”), a …
Thousands impacted by Fermanagh and Omagh District Council programme data breach. OVER 2,000 people have been affected by a data-breach because of their participation in a scheme …
Intel investigating leak of Intel Boot Guard private keys after MSI breach. Intel is investigating the leak of alleged private keys used by the Intel BootGuard security feature, …
ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients. The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal …
Kibble Equipment Data Breach Investigation – Turke & Strauss LLP. Turke & Strauss LLP, a leading data breach law firm, is investigating Kibble Equipment, LLC and its vendors, Razor …
Mailing Error at CMS Vendor Affects 10,000 Medicare Beneficiaries. The Centers for Medicare & Medicaid Services (CMS) has started notifying certain Medicaid beneficiaries about an …
IL, KY, and TN Healthcare Orgs Recovering from Recent Cyberattacks. Morris Hospital & Healthcare Centers Investigating Royal Ransomware Attack Morris Hospital & Healthcare Centers …
PNI Atlantic News. Oh no! Mr Beaver lost this page when he went scavenging (or you need to check your spelling). Try searching below or check out our other top stories!. 1. ### …
Third-party company: Community Health Systems.
Third-party company: Brightline Health.
Debt Collection Agency Data Breach Affects 345,523 Individuals. R&B Corporation of Virginia, doing business as Credit Control Corporation (CCC), has recently reported a data breach …
Webster Bank Reports Third-Party Data Breach at Guardian Analytics, Inc. | JD Supra. On April 10, 2023, Webster Bank filed a notice of data breach with the Maine Attorney General …
Brightline: At Least 964,300 Individuals Affected by Fortra GoAnywhere Hack. Brightline, a provider of virtual behavioral and mental services to families, has confirmed it was …
Discord Informs Users of Data Breach Involving Customer Support Provider. This website stores cookies on your computer. These cookies are used to improve your website experience …
"Binance LaunchPool are meant as air drops for our retail users, not just for a few whales," tweeted Changpeng "CZ" Zhao, the CEO of Binance, after seeing an alert showing that …
The Level Finance decentralized perpetual exchange was exploited after an attacker discovered a vulnerability in one of the project's smart contracts. They were able to drain …
Storybook Brawl, a card based autobattler game that was beloved by Sam Bankman-Fried, took its servers offline on May 1. The game had no connection to the crypto industry until its …
A US entity that previously controlled the Poloniex crypto exchange has agreed to pay a $7.6 million fine to settle allegations that it violated US sanctions against Crimea, Cuba, …
Storybook Brawl, a card based autobattler game that was beloved by Sam Bankman-Fried, took its servers offline on May 1. The game had no connection to the crypto industry until its …
Between March and April 2023, the Scam Sniffer organization has identified at least $7.7 million stolen by so-called "permit phishers". These attackers convince their victims to …
Beginning April 29, 2023, a threat actor using the alias 'Golem' conducted credential stuffing against 23andMe's login portal over five months, gaining access to ~18,000 customer …
The 0VIX defi protocol on the Polygon blockchain was exploited for around $2 million. This was a substantial portion of the project's roughly $6.4 million TVL around the time of …
In late April 2023, ALPHV/BlackCat ransomware affiliates breached HWL Ebsworth — one of Australia's largest national law firms with offices in all Australian capital cities and …
A thief has identified nearly 1,000 Bitcoin addresses they believe to have been used in connection with Russian hacking activity. This is partly backed by analysis from the …
After finding that the South African businessman Cornelius Johannes Steynberg had run Mirror Trading International as a multi-level marketing scheme, in which he accepted 29,421 …
The only Belgian crypto platform, the Bit4You crypto lender, announced they would be suspending activities after the CoinLoan crypto exchange was ordered to suspend activities …
The FBI raided the home of Ryan Salame, the former co-CEO of FTX Digital Markets (FTX's Bahamian subsidiary). Salame was close with Sam Bankman-Fried, although it came out in …
TechCrunch reported that attackers were able to gain access to AT&T email accounts which they then used to gain access to customers' cryptocurrency accounts. Various customers …
TechCrunch reported that attackers were able to gain access to AT&T email accounts which they then used to gain access to customers' cryptocurrency accounts. Various customers …
The brand new Merlin DEX had only just launched on the zkSync Ethereum layer-2, with a public token sale beginning on April 25. The following day, they suddenly asked users to …
After surmounting various obstacles to acquire the assets of the bankrupt Voyager Digital crypto lending firm, Binance.US abruptly backed out of the $1.3 billion deal.Binance cited …
The Estonian crypto exchange CoinLoan announced they were immediately suspending all operations, including withdrawals. The action came after CoinLoan was declared insolvent by an …
Ordinals Finance was a short-lived project, emerging in late February with promises to help build out a defi ecosystem on the Bitcoin blockchain.On April 24, the project developer …
Over on the Bitcoin blockchain, people are abuzz over the launch of "BRC-20": a similar concept to the ERC-20 token on Ethereum that allows people to create their own tokens. The …
Around 770 people were convinced to spend a combined almost €1.5 million (~$1.66 million) on NFTs of teddy bears, which sold for around €1,250 each (~$1,380). Buyers were told they …
Around 770 people were convinced to spend a combined almost €1.5 million (~$1.66 million) on NFTs of teddy bears, which sold for around €1,250 each (~$1,380). Buyers were told they …
The Blur NFT marketplace appeared to become vulnerable to a bug in which old, canceled bids could still be accepted. This meant that people who had placed bids on NFTs when they …
Ukraine DAO is a project that emerged shortly after the Russian invasion of Ukraine, aiming to raise cryptocurrency funds to support Ukrainians. Despite the name, it is not a DAO …
Crypto researcher Tayvano posted a Twitter thread about a massive, mysterious wallet draining operation that has siphoned more than 5,000 ETH (~$9.88 million at today's prices) as …
WebTPA, a Texas-based third-party health insurance plan administrator, suffered a data breach discovered in April 2023 but not publicly disclosed until May 2024 — a 13-month delay. …
Krzysztof Gagacki and Edmond Truong are co-founders of Rebase.gg, some sort of augmented reality app where people go hunting for NFTs. They're best known for helping to create a …
Several weeks after Bittrex announced it would be winding down its US operations by the end of April, citing the US "regulatory and economic environment", the SEC filed charges …
An attacker was able to manipulate the exchange rate between tokens and their interest-bearing equivalents on the Hundred Finance system on the Optimism layer-2 network, ultimately …
The Singapore-based Bitrue crypto exchange suffered a hack on April 14 in which attackers siphoned tokens including Ethereum, Shiba Inu, and MATIC (the token for the Polygon …
A bug in a token issued by the Yearn Finance defi protocol resulted in a loss that has been estimated at around $11.6 million. An attacker was able to use a 10,000 USDT deposit to …
Franklin, aka franklinisbored, has come to be known as one of the most prolific collectors of Bored Apes. At times, he's held more than fifty of the NFTs, and he can often be …
New passive voice Hall of Fame contender just dropped: "There were mistakes made in a wallet that I controlled." You would think someone who got their start as a writer might know …
In February 2021, the Ren project announced that it had been acquired by Alameda Research so that Alameda could "[help] accelerate the decentralisation" of the project.Now, the Ren …
There has been an ongoing controversy in the NFT world over creator royalties. Although NFTs are often talked up as being good for artists because they enable royalties to be paid …
Hackers made off with 61 BTC, 350.5 ETH, 10 million WEMIX, and 220,000 USDT from a hot wallet belonging to the South Korean cryptocurrency exchange GDAC. Altogether, the assets are …
Niantic, the creator of the popular Ingress and Pokémon Go augmented reality games, announced it will be shutting down its "Trading Post" product for NFT trading cards that it had …
Terraport Finance is a defi project built on, believe it or not, the Terra blockchain. Yes, the same Terra blockchain on which the Terra/Luna projects were built. Despite the …
The former owner of Bored Ape #7810 presumably intended to agree to sell the ape to another buyer for 70 ETH (~$130,900). However, it's unlikely they intended for that buyer to …
0xSifu, also known as Michael Patryn, also known as Omar Dahani, is the once-pseudonymous chief developer of the Wonderland protocol. His identity was discovered by zachxbt in …
The latest ape escape has affected Dez Bryant, a former NFL player now turned "web3 innovator". Bryant was the proud owner of Bored Ape #2902, an ape with leopard print skin …
Bitcoin mining firm Sphere 3D has filed a biting lawsuit against its partner, Gryphon Digital Mining. According to Sphere 3D, Gryphon's CEO was fooled by multiple spoofing attacks …
dYdX announced that it would be shutting down its decentralized derivatives exchange in Canada. They gestured toward regulatory issues in the post, writing that, "We hope that the …
The Gemholic project raised 921 ETH (~$1.7 million) in a token sale only to discover there was no way for them to transfer those funds out of the smart contract. The project is …
OpenSea launched a collection of "Gemesis" NFTs to celebrate the launch of their Pro platform and their acquisition of Gem, a rival NFT platform. Anyone who bought NFTs from the …
Binance announced it would be closing its derivatives business in Australia "following recent engagement with ASIC", referring to the Australian Securities and Investments …
NCB Management Services, a debt purchasing and collections company that works with major banks, suffered a data breach on April 4, 2023. The breach exposed data of approximately …
Paxful, a peer-to-peer marketplace where people could trade Bitcoin, Tether (USDT), and USDC, suddenly announced on April 4 that they would be immediately suspending the …
The Sentiment liquidity protocol on the Arbitrum blockchain was attacked on April 4 for almost $1 million in various tokens, including wrapped Bitcoin and Ether, and several …
Crypto influencer Cobie made a wild guess on April 3 that an Interpol red notice might be issued for Changpeng "CZ" Zhao, the CEO of Binance. Binance has recently been hit with a …
It's a dog-eat dog-world in the crypto universe, where everyone's trying to steal money from everyone else.MEV bots are a phenomenon that became popular in recent times: bots that …
After a bumpy start to the airdrop that distributed governance tokens to Arbitrum users, the first use of those governance tokens arguably went even worse. Arbitrum submitted a …
HWL Ebsworth, one of Australia's largest law firms with over 2,500 staff and a significant federal and state government client base, was attacked by the ALPHV/BlackCat ransomware …
April 2023 Healthcare Data Breach Report. There was a 17.5% month-over-month fall in the number of reported healthcare data HIPAA compliance breaches with 52 breaches of 500 or …
The Allbridge cross-chain bridge project was exploited for around 283,000 BUSD and 291,000 USDT (~$574,000). The thief was able to manipulate a vulnerability in the project's smart …
Dynasty Loop is a Montreal-based video games studio launched in 2020 to create NFT games. In March, gaming news outlet Polygon reported that the studio allegedly owed more than $2 …
A token airdrop from the popular Arbitrum Ethereum L2 illustrated many of the challenges with airdrops: events where tokens are automatically distributed to a group of crypto …
Bittrex, one of the oldest and largest cryptocurrency exchanges serving US customers, announced that it would be shuttering its US platform. "It's just not economically viable for …
The U.S. Securities and Exchange Commission charged the Beaxy crypto exchange and its executives for failing to register as a national securities exchange, broker, and clearing …
If the pump-and-dump didn't get you, the liquidity pool compromise might have! Holders of the SafeMoon token were informed that the SafeMoon liquidity pool had been compromised, …
Perry Johnson & Associates (PJ&A), a Nevada-based medical transcription services company, was breached between March 27 and May 2, 2023. The breach went undetected for over a …
The US Commodity Futures Trading Commission (CFTC) filed charges against the crypto exchange Binance and its CEO Changpeng "CZ" Zhao for allegedly violating rules around trading …
The Kokomo Finance project on the Optimism Ethereum layer-2 network rug pulled for $4.5 million in assets. The project positioned itself as a non-custodial lending platform.After …
The new owner of a CryptoPunk, one of the most popular early NFT projects, accidentally burned the NFT they had only just purchased. After spending 77 ETH ($123,434) on the NFT, …
Despite Sotheby's estimates that the most popular piece in the "Oddly Satisfying" NFT collection would sell for €70,000–€100,000 ($75,500–$108,000), the "Eternity" NFT attained a …
Only hours after Do Kwon was arrested in Montenegro, federal prosecutors in New York filed eight criminal charges against him: conspiracy to defraud, conspiracy to defraud and …
The founder of Terra/Luna, the stablecoin that crashed dramatically in May 2022 and has subsequently been alleged to be a massive fraud, has been arrested in Montenegro.After the …
Capita, a major UK outsourcing company providing services across government, defence, and pension administration, was hit by Black Basta ransomware on March 31, 2023 (initial …
His (former?) Excellency Justin Sun has been charged by the US Securities and Exchange Commission for offering unregistered securities. His businesses, the Tron Foundation and two …
The SEC sent Coinbase a Wells notice, which is basically their way of saying "we're about to file a complaint against you, here's your chance to convince us not to."According to …
The Kraken cryptocurrency exchange announced to its users that it will be suspending ACH transfers on March 27, as a result of the collapse of its banking partner, Silvergate. …
Celebrities Lindsay Lohan, Jake Paul, Soulja Boy, Austin Mahone, Kendra Lust, Lil Yachty, Ne-Yo, and Akon were all charged by the SEC for violating anti-touting laws that would …
On March 20, 2023, OpenAI took ChatGPT offline after discovering a bug in its Redis client library (redis-py open-source library) that caused some users to see other users' …
Despite people periodically claiming that crypto is a panacea for the many issues that make it difficult for sex workers to get paid, the SpankPay crypto-based payments processor …
The largest manufacturer of Bitcoin ATMs, General Bytes, disclosed that attackers had stolen more than $1.6 million by exploiting a vulnerability in their software. The company …
According to a report by the BBC, a scam called iEarn Bot has impacted thousands of victims across multiple countries. In the scam, victims are convinced to sign up for an "AI …
File this one under "the audacity".On March 17, blockchain security company BlockSec observed an attacker trying to exploit a vulnerability in the NFT lending project Paraspace. …
Attacker stole employee credentials and used them to access Latitude Financial's data held by two service providers including DXC Technology. 14 million records affected across …
Lazarus Group (North Korea, subunit Labyrinth Chollima) trojanized 3CX DesktopApp versions 18.12.407 and 18.12.416 for Windows and Mac. Delivered SUDDENICON downloader which …
Law enforcement from the United States, Germany, and the European Union worked together to take down the ChipMixer cryptocurrency tumbler, which they allege had been used to …
When USDC deviated from its dollar peg on March 10, phishers were quick to devise a scheme to take advantage of holders' fears. A group launched a website appearing to be the blog …
Contagion from the massive exploit of the Euler project has spread to around a dozen defi projects, including Balancer, Angle Protocol, Yearn Finance, InverseFinance, and others. …
The decentralized lending platform Euler Finance suffered a flash loan attack in which an exploiter stole $197 million from the project. The attacker stole $8.7 million in the Dai …
In a Twitter thread, Meta (formerly Facebook) Head of Commerce and Fintech Stephane Kasriel announced that they would be "down digital collectibles (NFTs) for now to focus on other …
In March 2023, Money Message ransomware attacked PharMerica Corporation — one of the largest pharmacy benefit management companies in the US, providing pharmacy services to …
Two days after the collapse of Silicon Valley Bank and four days after the collapse of Silvergate Bank, the New York Department of Financial Services announced they had taken …
PeopleDAO is the successor to ConstitutionDAO, a group that made an ill-fated attempt to buy a copy of the US Constitution in November 2021. When the accounting lead for PeopleDAO …
Someone tried to swap around 2.03 million 3CRV tokens (priced at around $1.97 million) for stablecoins using the KyberSwap decentralized exchange protocol. However, due to an …
The major stablecoin USDC lost its peg to the US dollar on March 10. Earlier that day, the collapse of the Silicon Valley Bank sent shockwaves through the financial system, and …
BlockFi, which has been in bankruptcy since shortly after the November FTX collapse, appears to have exposure to the collapsed Silicon Valley Bank. According to a court filing, …
The collapse of the Silicon Valley Bank on March 10 led to concerns over the stability of the stablecoin USDC, after it was revealed that a portion (later specified at $3.3 …
Huobi Token, the token tied to the Huobi cryptocurrency exchange, experienced a flash crash in which the token price tumbled 90% from $4.60 to around $0.31 within about a …
Although it doesn't seem that it was exposure to the crypto industry that did in Silicon Valley Bank (unlike with fellow failed bank Silvergate), the crypto industry has been …
The Hedera network turned off access to the Hedera mainnet on March 9 after observing "smart contract irregularities". They subsequently confirmed that the Hedera smart contract …
After launching an asset management business less than a year ago, Blockchain.com has announced they will be shuttering it. They blamed the ongoing "crypto winter" as contributing …
New York Attorney General Letitia James announced a lawsuit against the Seychelles-based KuCoin crypto exchange, after finding that users could trade on the exchange despite it not …
In March 2023, data for approximately 56,415 individuals enrolled in DC Health Link — the health insurance marketplace for Washington D.C. residents including US House of …
Turkish electric vehicle startup Togg announced that interested customers would be able to buy obtain pre-order rights for the limited run of their "100 Year Special Series" cars …
Both CoinDesk and Reuters have reported that JPMorgan Chase & Co. will be ending its banking relationship with Winklevoss-led Gemini cryptocurrency exchange. Gemini responded …
California-based Silvergate bank had pivoted almost entirely to serving crypto clients, a move that proved fatal to them in the wake of the FTX collapse and ensuing contagion. On …
It doesn't take much to tank a token price, particularly lately as fear of SEC action in the Ethereum staking world has run high. Popular podcaster David Hoffman speculated on his …
A report from the Wall Street Journal made serious allegations against the stablecoin operator Tether, sister company Bitfinex, and the web of companies behind it. According to …
Silvergate is a US bank that shifted its business toward primarily serving crypto clients. Following the collapse of FTX, there have been concerns over Silvergate's exposure to the …
An investigation by crypto sleuth zachxbt uncovered that the Indian crypto exchange BitBNS had been hacked on February 1, 2022, but hid it from users. After experiencing a $7.5 …
In March 2023, Ferrari N.V. disclosed that it had received a ransom demand from a threat actor following unauthorized access to some of its IT systems. Ferrari detected the breach …
AT&T alerts 9 million customers of data breach after vendor hack. AT&T is notifying roughly 9 million customers that some of their information has been exposed after one of its …
Students' bank accounts hacked because of ticketing software breach - The Ithacan. After attending a concert at Cornell University featuring Beach Bunny on Jan. 28, several Ithaca …
NBA notifies fans of data breach at third-party newsletter provider - SiliconANGLE. …
Datalek Nederlandse bedrijven steeds groter: zeker 2 miljoen klanten getroffen. De oorzaak is een datalek bij een softwareleverancier van marktonderzoekers. Zij hebben grote …
Third-party company: Maximum Industries.
Uber suffers another data breach after law firm’s servers attacked. This is the third time in six months that Uber has been the victim of a data breach. Uber has found itself in …
If you're thinking about entering into a BNB Chain hackathon, you might want to think again. On March 1, Binance announced a new "Bitcasso" product: a tool for users to create NFTs …
San Francisco-based law firm Orrick, Herrington & Sutcliffe LLP — which ironically specializes in advising companies on cybersecurity incidents and data breaches — suffered a …
Nishad Singh, a co-founder of FTX and its former director of engineering, has agreed to plead guilty to six criminal charges and co-operate against his former boss, Sam …
Over a period of several days, around 25 accounts on the Algorand blockchain have been drained of funds. The attack appears to be targeted at high-value accounts, and over 13 …
Two BNB-based defi projects have been exploited for around $700,000 each in attacks that one of the projects has claimed were perpetrated by the same group. First, an attacker …
"I still don't quite understand what happened here", wrote hideyoapes.eth after their wallet was drained of around 30 NFTs. They had previously owned several pricey NFTs from the …
It's just like mid-2022 again! As transactions slowed to a crawl, developers embarked on a "coordinated restart" — a euphemism for the rather centralized way this supposedly …
In a world where "code is law", crypto users don't necessarily expect that the smart contracts might change out from under them — particularly given contracts are often assumed to …
On 23 February 2023, Dish Network and its parent EchoStar suffered a Black Basta ransomware attack that caused a several-day outage affecting Dish Network's websites, call centers, …
On February 23, 2023, Dish Network — a major US satellite TV provider — suffered a ransomware attack (attributed to Black Basta) that took down its internal systems, customer …
The Metroverse NFT-based game caught the end of the 2021–22 crypto bull market, minting the Genesis collection in January 2022. The project sold out quickly, netting the project …
The Guardian published a report on Phoenix Community Capital, a cryptocurrency investment project that solicited investments in part based on credibility it built by ingratiating …
Sam Bankman-Fried, the founder and former CEO of the now-bankrupt FTX exchange, was already facing eight criminal charges for offenses including wire fraud, securities fraud, money …
Indian cryptocurrency exchange WazirX abruptly closed their NFT marketplace on February 22, giving its users no warning. In an announcement on Twitter, they wrote that they had …
New guidance from the Canadian Securities Administrators requires any crypto asset trading platforms (CTPs) operating in Canada without formal registration to commit to …
After earning $5.3 million in their initial sale, creators of the Friendsies NFT project suddenly announced they would be "pausing" their project due to "market volatility". The …
One of the largest crypto-focused algorithmic trading funds, Galois Capital, announced that they would be closing up shop in the wake of the FTX collapse. The fund had half its …
Decentralized exchange aggregator Dexible disclosed that they had suffered an exploit of one of their smart contracts, which allowed an attacker to steal funds from customer …
In the second big-name slapdown from the SEC relating to the EthereumMax token, former Celtics player Paul Pierce has agreed to pay a $1.4 million fine to settle charges that he …
Crypto sleuth zachxbt has released research indicating that a cryptocurrency and NFT phishing scammer who goes by Loyalist/Lukas/Shibango has stolen more than $4 million of various …
Platypus USD, a stablecoin issued by the Platypus Finance defi protocol, was exploited only ten days after it first launched. The loss was estimated to be around $8.5 million, …
The U.S. Securities and Exchange Commission filed charges against Terraform Labs and its CEO, Do Kwon, relating to the May 2022 collapse of the Terra/Luna projects. The complaint …
You thought NFTs were dead? Think again. Perhaps longing for the halcyon days when you could mint an NFT on Ethereum and smile in satisfaction at the carbon emissions you just …
South Korean authorities have issued an arrest warrant for the former CEO of Tmon, a major Korean e-commerce platform. The allege that he was bribed with Luna tokens, which he …
The FDIC is continuing its recent crackdown on exchanges claiming they're protected by FDIC insurance, issuing a cease-and-desist to CEX.io. CEX.io, like several other crypto …
The U.S. Consumer Financial Protection Bureau (CFPB) disclosed in March 2023 that a former CFPB employee had sent 14 emails containing sensitive personal and financial information …
An attacker using flash loans to exploit a common re-entrancy vulnerability siphoned $3.65 million from the dForce defi project on both Arbitrum and Optimism, which are Ethereum …
New York-based crypto company Paxos was ordered by the New York Department of Financial Services to stop minting the Binance USD (BUSD) stablecoin over "several unresolved issues …
LocalBitcoins, a Finnish platform that allows individuals to trade Bitcoins with one another peer-to-peer, will be shutting down. The exchange is one of the longest running …
The Umami Finance defi protocol offered yield products intended for institutional customers. However, on January 31, they announced that they would be halting yields amidst claims …
U.S. cryptocurrency exchange Kraken has reportedly agreed to close up shop on its crypto staking operation and pay a $30 million fine to the U.S. Securities and Exchange …
CoinDesk reported that the New York Department of Financial Services is actively investigating Paxos, which issues both the Pax dollar (USDP) and the considerably larger Binance …
Yuga Labs released an endless runner game called "Dookey Dash" (really) where players compete to see how long they can keep their character navigating through a sewer pipe without …
A year ago, the Hermès luxury brand slapped Mason Rothschild, creator of "MetaBirkins" NFTs, with a trademark lawsuit. The suit centers on his NFT collection: a series of 100 …
The US-based company Coin Cloud, which operates crypto ATMs in the US and Brazil, filed for bankruptcy on February 7. They are the second largest crypto ATM operator in the world, …
The metaverse gaming company Webaverse disclosed on February 6 that they had suffered a $4 million theft several months earlier. They outlined what appeared to be a complex scam in …
Binance announced that they would be "temporarily suspending USD bank transfers" with two days notice.This comes in the wake of various crypto exchanges — Binance included — …
Attacker sent convincing phishing email mimicking Reddit IT, tricked employee into entering credentials and TOTP codes in real time on fake login page. Accessed internal documents, …
Logan Paul is now facing a class action lawsuit over his CryptoZoo project, a planned NFT game that Paul apparently lost interest in and abandoned — after profiting handsomely, of …
The decentralized exchange Orion Protocol suffered a loss of 1,757 ETH (about $2.9 million) from the company treasury funds thanks to a reentrancy attack.Orion Protocol CEO Alexey …
Rise Interactive Media & Analytics, LLC Reports Third-Party Data Breach Affecting Edgepark Medical Supplies Patients | JD Supra. On February 3, 2023, Rise Interactive Media & …
The Week in Ransomware - March 3rd 2023 - Wide impact attacks. This week was highlighted by a massive BlackBasta ransomware attack targeting DISH Network and taking down numerous …
Nearly 63K Impacted by Healthcare Data Breach from Exploited Web Server | TechTarget. Sharp HealthCare in San Diego suffered a healthcare data breach after an unauthorized …
Dish confirms ransomware attack allowed hackers to steal personal data | TechCrunch. Dish said a ransomware attack is to blame for an ongoing, multiday outage and warned that …
Atlassian data leak caused by stolen employee credentials. Atlassian has confirmed that a breach at a third-party vendor caused a recent leak of company data and that their network …
The Polygon-based defi borrowing protocol Bonq suffered an attack in which 112 million ALBT tokens and around 100 million BEUR tokens were stolen. A flaw in the protocol enabled …
Volt Typhoon (VOLTZITE per Dragos), a Chinese state-sponsored APT group, maintained persistent unauthorized access to the operational technology (OT) network of Littleton Electric …
A recent project called "Ordinals" has the Bitcoin community up in arms. The project is the latest attempt to introduce NFTs to the Bitcoin blockchain, a controversial subject …
Rally is an Ethereum sidechain built to support "social tokens" — typically, tokens intended for fans of various celebrities or groups.Fans of creators including Felicia Day …
Elon Musk's $1.5 billion Bitcoin bet at Tesla turned out to be a bad deal. He sunk the funds into Bitcoin in January 2021, when Bitcoin was trading between $30,000 and $40,000. …
It's no big secret that there's a lot less money actually floating around in crypto than bogus "market caps" and other numbers would have you believe, but it's being put into stark …
Hatch Bank, a fintech-focused bank-as-a-service provider headquartered in San Francisco, was an early confirmed victim of the Cl0p ransomware group's mass exploitation of …
The embattled Gemini crypto exchange, which is has $900 million of customer funds locked up in the Genesis bankruptcy and has been charged by the SEC for offering unregistered …
Community Health Systems (CHS), one of the largest for-profit hospital operators in the United States, was among the earliest publicly disclosed victims of Cl0p's mass-exploitation …
Hackers were able to compromise the Twitter account belonging to the popular Azuki NFT project, which they then used to promote a fake NFT drop to its 334,000 followers. Users who …
The Dutch central bank levied a €3.3 million ($3.6 million) fine against Coinbase, who began operating in the Netherlands without properly registering. The fine is reportedly …
Kevin Rose, perhaps best known as the founder of Digg, but also a prominent crypto investor and entrepreneur, lost a substantial number of pricey NFTs when he apparently signed a …
South Korean prosecutors filed charges against several executives of the Korean cryptocurrency exchange Bithumb. Those charged included its owner, Kang Jong-Hyun, and his sister …
A June 2022 hack saw cryptocurrency notionally worth $100 million stolen from Harmony's Horizon Bridge. At the time, blockchain research firm Ellipsis concluded that there were …
For some reason, Porsche decided they needed to release a set of Porsche 911 NFTs so that customers could buy "the opportunity to co-create Porsche's future in the Web3 universe" …
After the $320 million hack of the Wormhole blockchain bridge in February 2022, much of the funds remained dormant. Now, however, the hacker seems to have returned. On January 23, …
Gemini performed a 10% layoff, cutting roughly 100 positions. This move followed a 7% layoff in July 2022, and a 10% reduction just a month prior to that.Gemini has been having a …
Binance informed its users that they would no longer be able to perform transactions below $100,000 via the SWIFT financial network. According to Binance, this was because their …
The Genesis cryptocurrency lending platform filed for bankruptcy, following weeks of turmoil after the FTX collapse. Genesis halted withdrawals shortly after FTX's failure, and …
More bad news for Nexo, whose Bulgarian offices were raided a week prior amidst allegations of organized financial crime. Now, the United States SEC and state securities regulators …
Cl0p exploited zero-day RCE in Fortra GoAnywhere MFT admin portal. ~130 organizations breached over 10 days in January 2023. Cl0p named 100+ victims on leak site through March …
Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …
Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …
Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …
Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …
Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …
US authorities arrested and charged Anatoly Legkodymov, the founder of the Bitzlato cryptocurrency exchange. Although the exchange is relatively unknown, the justice department …
Western Sydney University (WSU) disclosed a data breach in May 2023 involving unauthorized access to its Microsoft 365 email environment and SharePoint files from approximately …
Kyle Davies and Su Zhu, the founders of the bankrupt Three Arrows Capital crypto hedge fund, have joined forces with Mark Lamb and Sudhu Arumugam, the founders of the CoinFLEX …
According to NFT GOD, his computer was infected with malware when he clicked a sponsored link in a Google search when he went to download the streaming software OBS. This is …
In a Twitter thread, LendHub published a message stating that "hackers stole about 6 million US dollars of assets from Lendhub". They wrote that they had "locked the hacker's …
As they tried to close an Alameda position on the Aave defi lending project, liquidators in charge of recovering customer funds lost $72,000 due to an error in their approach. The …
Bulgarian prosecutors raided more than 15 locations in Sofia, Bulgaria in relation to the Nexo cryptocurrency lender. A spokesperson for the prosecutors has said that the raids are …
The SEC filed charges against Genesis Global Capital and Gemini, two crypto firms that collaborated to create Gemini's embattled Earn lending program. According to the SEC, their …
LockBit ransomware hit Royal Mail's Heathrow Worldwide Distribution Centre Jan 10 2023, disrupting international mail for 6 weeks. LockBit initially demanded $80M ransom, lowered …
After laying off 1,100 people in an 18% staffing cut in June 2022, Coinbase CEO Brian Armstrong wrote that "in hindsight, we could have cut further at that time." The company …
Fast fashion retailer Forever 21 suffered a data breach where hackers had access to its systems from January 5 to March 21, 2023. The breach affected 539,207 current and former …
The major cryptocurrency exchange Huobi confirmed they planned to lay off 20% of employees, shortly after Huobi's advisor and somewhat its public face, Justin Sun, denied any …
The U.S. Attorney's Office of the Eastern District of New York announced fraud charges against Aurelien Michel, a 24-year-old French national living in Dubai. Michel, under the …
After a round of layoffs in August that impacted 20% of their employees, Genesis is laying off another 30% of their employees.Genesis is currently in a really bad spot, halting …
As Celsius bankruptcy proceedings continue on, the New York Attorney General has come out with a lawsuit against the company's founder and CEO, Alex Mashinsky. Attorney General …
Silvergate, a Californian bank that primarily serves the crypto industry, and which was FTX's primary banking partner, scrambled to cover $8.1 billion in withdrawals during the …
Crypto influencer CryptoNovo tweeted, "I just got hacked!!! Are you kidding me!?!" with a screenshot of valuable CryptoPunk NFTs being transferred from their account. An attacker …
Magic Eden, as with many NFT marketplaces, has a verification layer that shows popular projects as "verified" to reduce the chances of people being tricked by NFTs with the same …
Coinbase agreed to a $100 million settlement with the New York State Department of Financial Services over charges that the company violated anti-money laundering laws by …
"Over the past year, it has become clear that NFTs are unlikely to be sustainable or profitable as a standalone business," wrote CEO Michael Rubin in an internal email explaining …
Influencer-turned-(alleged)-crypto-grifter Logan Paul has threatened to sue scam researcher CoffeeZilla, who has exposed Paul's "CryptoZoo" blockchain game project as his latest …
Users of NFT marketplaces and explorer applications including Magic Eden, NFT Explorer, and Rand Gallery were briefly shown pornographic images and still frames from the Big Bang …
An apparent wallet compromise netted hackers 82,519 GMX tokens from a wallet belonging to a GMX whale. The hackers exchanged these tokens for 2,627 ETH ($3.18 million), then …
DNP3 is a streamer known for giving away large sums of money to other streamers. He is also a crypto founder behind projects including CluCoin, the Xenia play-to-earn game, the …
Crypto payments platform Wyre inked a deal to be acquired by Bolt in a $1.5 billion deal in April 2022, but the acquisition was canceled in September after the two firms "mutually …
An attacker drained the wallet of Nikhil Gopalani, the COO of the Nike-owned crypto organization RTFKT. Most of the stolen NFTs were RTFKT NFTs, and the priciest were the nineteen …
On November 16, Genesis halted withdrawals from its lending service shortly after the FTX collapse. Gemini, who partners with Genesis lending to power their Earn program, halted …
Air France and KLM notify customers of account hacks. Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their …
Nissan North America data breach caused by vendor-exposed database. Nissan North America has begun sending data breach notifications informing customers of a breach at a …
University of Colorado Hospital Authority Announces Third-Party Data Breach Following Incident at Diligent Corporation | JD Supra. On January 17, 2023, the University of Colorado …
In January 2023, Datadog disclosed that its RPM (Red Hat Package Manager) signing key used to sign Datadog age nt packages had been exposed in the CircleCI breach. CircleCI's …
In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …
In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …
One of the original Bitcoin core developers, Luke Dashjr, claimed on Twitter that attackers had managed to compromise multiple wallets — which he described as both hot and cold …
Salt Typhoon (China MSS) breached at least 9 US telecom carriers including AT&T, Verizon, T-Mobile, Lumen, Spectrum, Consolidated Communications, and Windstream. Active for 1-2 …
Chinese MSS-affiliated APT Salt Typhoon (FamousSparrow) breached at least 9 US telecoms including AT&T, Verizon, T-Mobile starting ~late 2022/early 2023. Accessed CALEA lawful …
Just before the holidays, employees of the Covario crypto broker based in Zug, Switzerland learned that their employer was no longer solvent. Attempts to secure a buyout had been …
If you bought an NFT for $1,000 and it's now worthless, you still have to find someone willing to buy it before you can claim it as a loss on your taxes. A project called …
In October, several people reported losing more than a million dollars each from accounts that were connected to the 3Commas trading platform. 3Commas vociferously denied that …
Wallets known to be controlled by Alameda Research, the crypto trading firm founded by Sam Bankman-Fried and currently in bankruptcy with the other FTX companies, suddenly began …
In October, an exploiter was able to manipulate collateral prices to extract tokens from the Mango Markets defi project, ultimately resulting in a $116 million loss for the …
Midas Investments announced suddenly that they would be shutting down their platform, which previously enabled users to deposit cryptocurrencies which would then be invested in …
BitKeep, a popular cryptocurrency wallet in Asia, suffered a hack in which at least $8 million in various cryptocurrencies were stolen from user accounts.BitKeep has claimed that …
In a press release, BIT Mining reported that their subsidiary BTC.com had experienced a "cyberattack" in which $700,000 of customer assets were stolen. They also reported that $2.3 …
The Rubic cross-chain exchange suffered an exploit in which attackers were able to siphon a total of around $1.4 million in user funds from their wallets. The exploit was enabled …
The Rubic cross-chain exchange suffered an exploit in which attackers were able to siphon a total of around $1.4 million in user funds from their wallets. The exploit was enabled …
Toyota confirmed a data breach in August 2024 after threat actor ZeroSevenGroup posted 240 GB of data on a hacking forum. Data included employee and customer PII, contracts, …
On 25 December 2022, an attacker uploaded a malicious package named 'torchtriton' to the public PyPI index. PyTorch nightly builds depended on a package with the same name …
Defrost Finance, a defi trading platform built on the Avalanche Network, apparently tried and failed to rug pull its users. The project claimed on December 23 that they were "sad …
The Hong Kong-headquartered AAX cryptocurrency exchange suddenly halted withdrawals on November 13, claiming they were performing temporary system maintenance. However, withdrawals …
Knock-off Pokémon crypto products — including NFTs and blockchain games — have been so prevalent in the past two years that they've earned their own collection on this blog.Now, it …
Core Scientific warned in October that it was teetering on the edge of bankruptcy, so it was no huge surprise when the company filed for bankruptcy protection on December 21. Core …
Peer-to-peer crypto marketplace Paxful announced that it will be delisting ether, citing "scams that have robbed people of billions".So close. You're almost there.Paxful CEO Ray …
"Convert home equity into Bitcoin", Swan Bitcoin advertises with their new home equity product. Relatively few details are available on the new loan product they're offering, but …
Two of Sam Bankman-Fried's inner circle, Caroline Ellison and Gary Wang, have pled guilty to federal criminal charges and are cooperating in the case against Sam Bankman-Fried. …
Crypto market maker Auros filed for bankruptcy protection in the British Virgin Islands, not long after a missed loan repayment to the Maple defi lender in late November signaled …
Apparently adopting Do Kwon's belief that the solution to a crashing algorithmic stablecoin project is creating another project, Waves founder Sasha Ivanov has announced, "I will …
A scammer spent a month setting up a con in which they stole fourteen Bored Ape NFTs belonging to one individual. Posing as a casting director at a real film production …
In December 2022 (disclosed 4 January 2023), CircleCI — a widely-used CI/CD platform with over 500,000 developer users — discovered that an attacker had stolen customer environment …
QuadrigaCX was a Canadian crypto exchange that shut down and filed for bankruptcy in early 2019, with hundreds of millions more in liabilities than in assets. It later became …
An exploit on the Solana-based Raydium decentralized exchange project resulted in a total loss to the platform of $4.4 to $5.5 million. The attacker's actual spoils were less — …
The accounting firm Mazars Group has ceased working with cryptocurrency clients, including Binance, KuCoin, and Crypto.com. A statement from the firm attributed their decision to …
It's finally happened. The siren song of NFT grifting proved too much for Donald Trump.Trump supporters got all excited when Trump posted on social media to tease a "major …
Binance, the largest cryptocurrency exchange in the world, processed at least $1.9 billion in withdrawals in a 24-hour period—considerably more than it processes in a typical day. …
When the company accidentally published draft bankruptcy documents to its website, Argo Blockchain was forced to reveal that it is in last-ditch negotiations to raise capital. The …
Reuters has reported that the U.S. Department of Justice is considering filing criminal charges against Binance executives, including CEO Changpeng Zhao ("CZ"). This comes as a …
Sam Bankman-Fried has been arrested by Bahamian authorities, who said in a press release that they took the action "follow[ing] receipt of formal notification from the United …
If the idea of dropping thousands of dollars to "own" a plot of "land" in the Decentraland metaverse doesn't do it for you, have I got news for you: Decentraland has just …
The Arbitrum-based crypto lending platform Lodestar Finance was attacked by an exploiter who was able to manipulate the price of the plvGLP token, allowing them to "borrow" the …
The Block is a cryptocurrency-focus media outlet that was originally founded in 2018 by Mike Dudas. In 2020, Michael McCaffrey became CEO of the company, and in 2021 he led a …
The Block is a cryptocurrency-focus media outlet that was originally founded in 2018 by Mike Dudas. In 2020, Michael McCaffrey became CEO of the company, and in 2021 he led a …
A class action lawsuit against the company behind Bored Apes and its executives, those on the board of "Ape DAO", a whole host of celebrity promoters and brands, and the MoonPay …
After a stint on Season 2 of Love Island Australia, Vanessa Sierra has made a career as a successful OnlyFans performer. In 2021, she also began offering crypto trading tips in a …
The Australian crypto broker Digital Surge entered voluntary administration several weeks after suspending withdrawals in the wake of the FTX collapse. In their announcement, …
After FTX declared bankruptcy, the entire FTX.us domain was redirected to a page providing information on the bankruptcy proceedings.However, NFTs that had been minted on the FTX …
UK-based crypto tax company Koinly announced they would be letting go of 14% of their team. This amounted to more than 100 employees, including the entire London- and Sydney-based …
The unsecured lending platform Maple Finance published a blog post announcing that they were severing ties with Orthogonal Trading, who had "misrepresented its financial position" …
Following a round of layoffs in August that cut 21% of their workforce, Australian cryptocurrency exchange Swyftx has just performed another round of layoffs less than four months …
On December 4, 2022, an attacker used SMS phishing (smishing) to social-engineer an Activision HR employee into providing their MFA authentication code. With access to Activision's …
After reducing their staff by 20–30% in June, Dubai-based cryptocurrency exchange Bybit is doing another round of layoffs. This time the cut is estimated at around 30%, which is …
On November 13, the AAX cryptocurrency exchange suspended withdrawals, claiming they were dealing with a botched system upgrade. Shortly before, they had reassured their customers …
After a domino effect in which Gemini suspended withdrawals from its "Earn" lending product due to Genesis suspending withdrawals due to FTX's collapse, it's been revealed by the …
On 2 December 2022, Play ransomware attacked Rackspace's Hosted Exchange email service, forcing Rackspace to permanently shut down the service. Rackspace had approximately 30,000 …
Inside the turmoil at Sobeys-owned stores after ransomware attack | CBC News. Employees of Empire Co., the parent company of Sobeys, have begun to speak out about the turmoil …
Third-party breach impacts St. Luke's Health. HealthITSecurity reports that Texas-based St. Luke's Health has disclosed experiencing a third-party data breach involving consulting …
In January 2023, a security researcher discovered that CommuteAir, a US regional airline, had a publicly exposed Jenkins build server with no authentication required. The Jenkins …
The BNB Chain-based Ankr defi protocol suffered an exploit of their aBNBc token. "We are currently working with exchanges to immediately halt trading," they wrote. However, the …
Attackers were able to take advantage of an exploit on the Ankr protocol to obtain around 183,000 aBNBc tokens for only 10 BNB (~$2,900). Before the Ankr exploit, which crashed the …
In November-December 2022, attackers who had previously breached LastPass in August 2022 (stealing source code and technical documentation) used that information to identify and …
Crypto trading firm Auros missed a payment on its 2,400 wETH (~$3 million) loan from the Maple defi lending project. According to M11 Credit, the operator of the credit pool from …
The US cryptocurrency exchange Kraken settled charges from the Office of Foreign Assets Control (OFAC) alleging that they had violated sanctions against Iran. In the agreement, …
The US cryptocurrency exchange Kraken announced that it had laid off 30% of its employees, or about 1,100 people. They blamed "macroeconomic and geopolitical factors" resulting in …
Tough news for folks who insist that blockchains' obvious use case is for supply chains: IBM and Maersk have discontinued their private blockchain-based TradeLens platform due to …
After cutting around 10% of their employees in May, the Latin American crypto exchange Bitso has performed another round of layoffs.The company didn't reveal how many employees …
TBD is a subsidiary of Block (formerly Square), a tech company co-founded by billionaire social media mogul and Twitter founder Jack Dorsey. In July, they unveiled the concept of …
Crypto lending firm BlockFi has filed for Chapter 11 bankruptcy in the wake of the FTX collapse. The company was in dire straits in the spring after Terra and Three Arrows Capital …
A shitcoin project desperate for the kind of pump that sometimes occurs when Elon Musk tweets about a cryptocurrency has gone to new lengths to get his attention. The group spent …
Attackers exploited an unprotected API endpoint starting Nov 25 2022, exfiltrating data over weeks undetected. 37 million customer records exposed including names, phone numbers, …
On November 14, CZ of Binance announced an "industry recovery fund", which he said would devote money to ending "further cascading negative effects of FTX [and] help projects who …
Beginning in mid-November, users of the CoinList exchange and ICO platform reported that they couldn't withdraw assets from the platform. On November 24, CoinList tweeted, "There …
The Argentinean cryptocurrency exchange Lemon Cash announced that they had laid off 38% of their employees, or around 100 people. The CEO blamed the international crypto …
After announcing earlier in the month that they were close to defaulting on a $100 million+ loan, Iris Energy has defaulted. Unable to pay the $7 million/month in debt obligations …
Governor Kathy Hochul signed legislation to ban for two years the issuance of permits to new crypto-mining operations at fossil fuel plants. This seeks to cut down on the enormous …
Genesis Global Trading has reportedly been telling investors that Genesis may need to file for bankruptcy if its attempts to raise at least $1 billion in new capital don't succeed. …
Grayscale Bitcoin Trust (GBTC), the largest publicly traded crypto fund, hit record lows in the wake of the FTX collapse. The fund was trading at nearly a 50% discount on the …
On June 19, the Hong Kong-based crypto exchange Hoo announced that they would be pausing withdrawals for "24–72 hours" while they transferred some assets to top up their hot …
The Australian Securities Exchange (ASX) has finally pulled the plug on their project that would have replaced the aging CHESS system that is used for transfer and settlement. The …
The French crypto broker Coinhouse announced that they would be suspending withdrawals from their crypto "savings account" product. Coinhouse partners with Genesis to offer the …
A class action lawsuit has been filed against Sam Bankman-Fried and a slew of celebrities who helped to promote FTX as a safe place to hold and trade crypto. Defendants include Tom …
The Gemini cryptocurrency platform announced that they would be pausing withdrawals on their lending platform. This is because they partner closely with Genesis' lending products, …
The crypto lending portion of Genesis Global Trading announced they would be halting withdrawals in the wake of the "extreme market dislocation and loss of industry confidence …
Nestcoin, a Nigerian startup that both builds and invests products they hope will "democratis[e] access to economic opportunity for everyday people in frontier markets", has …
Coachella partnered with FTX to sell a collection of NFTs in February, ultimately raking in around $1.5 million. The NFTs were paired with physical items — Coachella passes, art …
Cryptocurrency lending company BlockFi suspended withdrawals on November 10 after the FTX collapse, an expected move since they had stayed afloat after the previous crypto meltdown …
The Brisbane-based cryptocurrency exchange Digital Surge announced that they would be suspending deposits and withdrawals. "Due to the impact of FTX Australia's administration, we …
The crypto lending firm SALT announced that they would be halting withdrawals due to exposure to FTX. "I am sorry to report that the collapse of FTX has impacted our business," …
CZ of Binance announced on Twitter that Binance would be forming an "industry recovery fund", which he says is intended for projects that are "otherwise strong, but in a liquidity …
The founder and chief investment officer of the Californian crypto hedge fund Ikigai Asset Management wrote on Twitter, "Last week Ikigai was caught up in the FTX collapse. We had …
Exploits and rug pulls of random tokens on BNB Chain are fairly commonplace, but typically the amount of money lost is fairly minimal. In this case, exploiters or insiders were …
The Hong Kong-headquartered cryptocurrency exchange announced that they would suspend withdrawals, which they claimed was due to a system upgrade that went poorly. They've …
Huobi announced to shareholders that they had $18.1 million in crypto assets on the FTX exchange, where they can't be withdrawn. They reported that approximately $13.2 million of …
A Twitter user posted Etherscan screenshots showing a massive flow of crypto from the Crypto.com cryptocurrency exchange to another exchange, Gate.io. "Anyone know why Crypto.com …
"Our contract has been hacked and has caused a lot of losses," wrote DeFiAI simply in their announcement. That same day, the project had announced the launch of a new website for …
The Securities Commission of the Bahamas issued a statement saying that "The Commission wishes to advise that it has not directed, authorized or suggested to [FTX] the …
Tokensoft is a project that aims to help web3 projects launch fairly, without the launches being gamed. The group evidently thought they had come across 5,000 or so users who had …
Over $477 million was mysteriously withdrawn from FTX and FTX US late on November 11, despite the company freezing withdrawals.An FTX account administrator wrote on the FTX support …
On November 11-12, 2022, within hours of FTX's bankruptcy filing, approximately $400 million was drained from FTX exchange and FTX US wallets in a series of unauthorized …
Aaaand there it goes.FTX announced that it had filed for Chapter 11 bankruptcy in the United States. Sam Bankman-Fried resigned as CEO.SBF had spoken about trying to raise …
Bo Shen, a general partner at Fenbushi Capital and an early adopter of cryptocurrencies, tweeted on November 22 that two weeks prior, someone had stolen $42 million in …
An attacker was able to use a flash loan to exploit a vulnerability in the smart contract for DFX Finance, a decentralized forex trading platform. The platform suffered a loss …
BlockFi had a tough time this past June, floundering after substantial losses in the crypto downturn. They were bailed out by FTX, who extended them a $250 million loan, then …
The Securities Commission of the Bahamas (where FTX is headquartered) announced they had frozen the assets of FTX and "related parties" — presumably Alameda. They also disclosed …
Users panicked when FTX stopped processing withdrawals, particularly those with substantial amounts of funds locked in the exchange. When the exchange tweeted that they had "begun …
It's over as quickly as it started, and it started pretty dang quickly. Binance walked away from the non-binding letter of intent that Binance signed to acquire FTX, which doesn't …
Surprising just about everyone, FTX's Sam Bankman-Fried and Binance's Changpeng "CZ" Zhao announced suddenly that Binance had signed a "non-binding [letter of intent], intending to …
The U.S. Attorney's Office for the Southern District of New York announced that they had convicted James Zhong with wire fraud pertaining to his 2012 theft of around 50,000 Bitcoin …
On November 2, CoinDesk published a leaked balance sheet from Alameda Research (a trading firm also owned by FTX founder and CEO Sam Bankman-Fried). The sheet suggested that …
On November 2, CoinDesk published a leaked balance sheet from Alameda Research (a trading firm also owned by FTX founder and CEO Sam Bankman-Fried). The sheet suggested that …
LBRY is a blockchain-based social network and video sharing protocol that was described by a researcher at The International Centre for the Study of Radicalisation and Political …
The defi protocol Pando suffered a $20 million loss when it was exploited with an oracle manipulation attack. The protocol suspended several of its projects in response to the …
In August, the popular messaging app Telegram started repossessing some desirable usernames that were already being used. Shortly afterwards, Telegram founder Pavel Durov explained …
The "Monkey Drainer" NFT phishing scammer first identified by blockchain detective zachxbt has struck again. They successfully emptied 7 CryptoPunks and 20 Otherside NFTs, which …
There was some brief panic on November 3 as someone minted a huge number of $GALA tokens in what appeared to be an exploit. $GALA is the native token of Gala Games, a platform for …
An attacker was able to compromise the private key of an admin wallet for the Rubic crypto exchange, transferring around 34 million Rubic tokens. The attacker then sold the tokens …
Skyward Finance is a project based on the NEAR blockchain, aiming to help users with initial token distribution. The project's treasury was drained of 1.1 million NEAR (~$3.2 …
Iris Energy, an Australian "sustainable Bitcoin mining company", has announced that they are close to defaulting on loans used to purchase $103 million of Bitcoin mining rigs. …
An attacker was able to compromise the private key of an admin wallet for the Rubic crypto exchange, transferring around 34 million Rubic tokens. The attacker then sold the tokens …
Solend announced that an exploiter had manipulated the oracle price of an asset on their platform, allowing them to take out a loan that left the platform with $1.26 million in bad …
Major crypto exchange Deribit suffered a hot wallet compromise that resulted in a $28 million theft. The exchange halted withdrawals to perform security checks, but urged that …
TPG Telecom, Australia's second-largest telco (which acquired iiNet in 2015), disclosed on December 14 2022 that an unauthorised party had accessed its Hosted Exchange email …
Hodlnaut, a crypto lending platform that halted withdrawals on August 8, has been undergoing court proceedings while it's determined if the insolvent company has a path to …
Team Finance is a project that helps projects lock their tokens to be released after a certain period or on a schedule. A hacker exploited a vulnerability in a smart contract that …
One of the largest public crypto mining firms in the United States, Core Scientific, filed a notice with the SEC that they would miss upcoming debt payments due in October and …
friesDAO describes itself as a "a decentralized social experiment where a crypto community builds and governs a fast food franchise empire via wisdom of the crowd". Welcome to the …
A phishing scammer called "Monkey Drainer" stole around 700 ETH (~$940,000) in 24 hours on October 25, according to blockchain sleuth zachxbt. The scammer used malicious phishing …
An attacker was able to siphon nearly 50 million L2DAO tokens from a multi-sig wallet on the Optimism protocol. These tokens would nominally have been valued at around $400,000 at …
Adding to the recent string of oracle manipulation attacks is an attack on the miMATIC ($MAI) market on the QuickSwap decentralized exchange. An exploiter was able to manipulate …
Freeway, a financial scheme where users buy "Superchargers", which are crypto "simulations" that promise to pay out rewards of up to 43% annually, seems to have taken the off-ramp. …
Several users of the automated trading bot 3Commas reported losing over a million dollars each in a hack or phishing scam affecting users who had connected it to their FTX …
Insufficient validation on an OHM smart contract at Bond Protocol allowed an attacker to drain 30,437 OHM (~$300,000) from the Olympus DAO defi protocol.Olympus DAO wrote in an …
Warner Bros. has just announced their "The Lord of the Rings: The Fellowship of the Ring (Extended Version) Web3 Movie Experience". Catchy name.Now, you have of course already been …
Warner Bros. has just announced their "The Lord of the Rings: The Fellowship of the Ring (Extended Version) Web3 Movie Experience". Catchy name.Now, you have of course already been …
A security researcher published a frustrated Twitter thread reporting that "BitBTC's Optimism bridge is trivially vulnerable. Their team has ignored my messages, so I'm going to …
The Celo-based borrowing and lending platform, Moola Market, suffered a major exploit when an attacker manipulated collateral prices to steal a collection of assets notionally …
If you've ever wished you could put the same amount of thought into buying a $100,000+ home as you do ordering another bag of dog food from your online retailer of choice, you're …
Unstoppable Domains is in the business of selling "domains" — at least that's what they call them, but they're not the kind of domain that you can plug into your web browser. …
The Swap feature of the BitKeep crypto wallet suffered an exploit that landed a hacker more than $1 million worth of BNB. The project acknowledged the hack, and promised to …
Aptos, a much-anticipated layer 1 blockchain backed by FTX and a16z, and created by a team of former Meta employees, launched to much anticipation on October 17. The team had …
Joseph Jason Rotunda, Director of the Enforcement Division of the Texas State Securities Board, submitted a filing to the ongoing Voyager bankruptcy case. FTX is the highest bidder …
The web3 company Syntropy suffered the loss of 15 million of their $NOIA tokens when they attempted to transfer them to a venture capital firm, but instead they ended up with a …
Advocate Aurora Health — an integrated health system with 26 hospitals across Wisconsin and Illinois — disclosed in October 2022 that it had notified approximately 3 million …
The defi project Earning.Farm lost 748 ETH (~$971,000) to a hacker using a flash loan attack. The project contract was missing a check that a flash loan was initiated by the …
On October 14, Ethereum reached a milestone that alarms many who have pushed for blockchains as "censorship-proof" technology. More than 51% of blocks produced in the preceding 24 …
In August 2021, DAO Maker (not to be confused with MakerDAO) was hacked for $7.38 million. The stolen funds were taken from users, rather than a project treasury, and 5,521 people …
Blu3DAO is a DAO that describes itself as "focused on empowering women, non-binary people, and allies to learn, earn, and play in web3 towards financial freedom". The group was the …
On September 15, a blockchain security firm disclosed a vulnerability affecting Profanity, a tool that allowed people to generate "vanity" crypto wallet addresses: addresses …
In June 2021, CNN launched "Vault": a project to "make moments from history available for purchase". The project involved minting as NFTs various clips of CNN footage and …
A Black woman attending the major Devcon Ethereum community event in Bogotá posted to Twitter a photograph of a man at the conference, writing, "Day 1 of Devcon and a group of us …
Mango Markets, a Solana-based defi project offering borrowing, lending, and leverage trading, was exploited for $116 million. An attacker manipulated the supposed value of their …
On September 15, a blockchain security firm disclosed a vulnerability affecting Profanity, a tool that allowed people to generate "vanity" crypto wallet addresses: addresses …
Rabby Swap, a feature of the Rabby crypto wallet, was exploited a month after it was first rolled out. An attacker discovered an apparent vulnerability in the Rabby Swap smart …
A hacker discovered a vulnerability in the smart contract for the STAX project, which is built on the TempleDAO defi protocol. STAX is a liquidity provider for $TEMPLE/$FRAX.Poor …
According to a scoop in Bloomberg, the United States Securities and Exchange Commission has been probing whether NFTs from Yuga Labs should be considered securities regulations, …
The U.S. Treasury Department announced fines against Bittrex, a U.S.-based cryptocurrency exchange. The Office of Foreign Assets Control (OFAC) announced a $24 million penalty …
KILLNET is a Russian hacktivist collective (with suspected ties to Russian intelligence) that conducted a sustained wave of DDoS attacks against Western government and …
On 9 October 2022, MyDeal — an Australian online retail marketplace owned by Woolworths Group (acquired in 2022 for A$217 million) — was breached via compromised user credentials …
Blockwater Technologies, a crypto investment firm based in South Korea, missed a payment on their $3.4 million loan from TrueFi, a decentralized borrowing platform. According to …
In an incredible display of misfortune and perhaps ineptitude, an NFT collector was scammed out of a Bored Ape and then scammed out of six more Bored Apes when he tried to revoke …
According to CoinDesk, the metaverse platform Decentraland is entertaining roughly 38 users a day these days. This isn't much for its "valuation" of $1.3 billion — although …
Binance Smart Chain, the relatively popular blockchain that Binance is trying to rebrand as "BNB Chain", was halted when an attacker exploited "BSC Token Hub", the bridge between …
Celsius Network is undergoing bankruptcy proceedings after its impressive implosion earlier this year. The company's latest court filing is 14,532 pages long — because it contains …
South Korean prosecutors have reportedly frozen $39.6 million in crypto assets belonging to Do Kwon, the founder of Terraform Labs and creator of the failed Terra blockchain …
Zcash is a privacycoin which, unlike popular blockchains like Bitcoin and Ethereum, allows users to obscure who they are sending money to and how much. Since June or July, the …
Bitcoin-based defi protocol, Sovryn, lost $1 million to a price manipulation attack. An exploiter was able to use the project's legacy lend and borrow functionality to maliciously …
On 3 October 2022, CommonSpirit Health — the second-largest nonprofit hospital system in the United States with 140 hospitals and over 1,000 care sites across 21 states — was hit …
A Floridian who was in the business of buying and selling hacked account logins on the dark web was busted for attempted income tax evasion when he tried to hide more than $1 …
Kim Kardashian agreed to settle with the SEC over allegations that she had promoted a "crypto asset security" without disclosing how much she had been paid, or when. In June 2021, …
The largest crypto exchange in the U.S., Coinbase, suffered a six-hour-long outage in which they couldn't take payments or make withdrawals involving U.S. bank accounts. They …
Transit Swap is a multi-chain decentralized exchange aggregator. Users of the project were collectively exploited for approximately $21 million when an attacker took advantage of a …
Beginning in October 2022 (nearly eight months before disclosure), UNC4841 — a China-nexus espionage group assessed by Mandiant as acting in support of Chinese state interests — …
Somnia Pain Management of Kentucky Announces Data Breach Stemming from Incident at Unnamed Management Services Organization | JD Supra. On October 24, 2022, Somnia Pain Management …
In the latest illustration of our marvelous new decentralized, resilient blockchain future, one single Solana node apparently was able to take down the entire Solana network. …
"Most of us are too poor to be spending the [ether] we have left on huge sweeps, but we still want that sweet adrenaline rush of flipping JPEGs" said Brian Krogsgard, co-founder of …
Texts exposed in the discovery process during the Elon Musk v. Twitter lawsuit have exposed not just a number of high-profile people embarrassingly simping for Musk, but also …
MEV bots are a controversial category of bots who frontrun transactions in ways that are often detrimental to users. One such bot, known as 0xbadc0de, earned a windfall when a …
A businessman has published a video in which he burns a drawing that he claims is an original Frida Kahlo drawing worth more than $10 million — though its value and its …
The wave of crypto executives stepping down from their roles is continuing, after Genesis' CEO left the company and Michael Saylor gave up his CEO title (but stayed on as chairman) …
Crypto lending service Nexo was hit with a barrage of cease-and-desist lawsuits from eight states: California, Vermont, Oklahoma, Kentucky, Washington, South Carolina, New York, …
Sports manager turned crypto entrepreneur Jason Falovitch is now perhaps best known for his influence in the NFT space. He co-founded the Leverage Game Media company along with …
The U.S. Attorney's Office for the District of Utah announced seven felony charges against a man who is accused of several crypto-related scams.In one, he conned two victims for …
The Commodity Futures Trading Commission fined the bZeroX blockchain project and its founders $250,000 for allowing illegal trading of digital assets, engaging in activities only …
According to a report in the Wall Street Journal, US-based cryptocurrency exchange Coinbase tested a group to speculate on cryptocurrencies in hopes of earning funds for the …
Compute North has filed for Chapter 11 bankruptcy, in what may be a blow to the crypto mining industry. Compute North is a major datacenter provider, and have deals with crypto …
The IRS was granted authorization to issue a "John Doe summons", which will require M.Y. Safra Bank to provide them with information on U.S. customers who may have failed to report …
The algorithmic market maker Wintermute suffered a major hack, according to their CEO. He estimated the loss at around $160 million, also writing that the company is "solvent with …
"[I] was a 20-something-year-old kid" said Aiden Pleterski, when asked why he kept his "investment" scheme going when he knew he couldn't repay his existing customers. Although he …
Australian telco Optus exposed an unauthenticated internet-facing API due to coding error from 2018 not fully remediated. Attacker used simple trial-and-error over 3 days in Sept …
CryptoFX is a crypto-based scheme targeted specifically to Latines, promising to invest its victims' assets in cryptocurrencies and teach its customers how to trade crypto. It also …
The firm Sparkster and its CEO Sajjad Daya settled with the U.S. SEC after a cease-and-desist arguing that Sparkster sold securities worth at least $30 million without …
The United Kingdom's Financial Conduct Authority issued a warning that FTX is not authorized by them, but is targeting consumers in the UK. "Almost all firms and individuals …
The owner of Mutant Ape #21080 was approached with an offer to trade their ape for another Mutant Ape (#55) and an extra 0.5 ETH ($675) to sweeten the deal. The trader agreed, and …
On 17-18 September 2022 — just two days after the Uber breach — the same 18-year-old Scattered Spider attacker (Arion Kurtaj) breached Rockstar Games' internal systems and leaked …
GMX is a decentralized cryptocurrency exchange that boasts zero price impact trades. On most exchanges, users have to contend with slippage: a difference between the price of a …
Helium has two different tokens: HNT, which is paid out to people who run Helium hotspots, and MOBILE, which is paid to those maintaining the new Helium 5G network. However, …
18-year-old Lapsus$-affiliated attacker purchased stolen contractor VPN credentials from dark web. Bypassed Duo MFA by bombing target with push notifications for >1 hour then …
In the early hours of September 15, Ethereum completed "The Merge — the long-awaited transition from its original proof-of-work consensus mechanism to proof-of-stake.Later that …
The 1inch Network disclosed a vulnerability that some of their contributors had found in Profanity, a tool used to create "vanity" wallet addresses by Ethereum users. Although most …
A South Korean court has issued a warrant for the arrest of Do Kwon, the founder of the Terra ecosystem, as well as five other people. According to Bloomberg the allegations …
If it seems like you've been seeing a lot of Ethereum co-founder and figurehead Vitalik Buterin around Twitter lately, it may be due to the influx of hacked verified Twitter …
When the "politics" were widespread civil unrest in the summer of 2020 triggered by the police murder of George Floyd, and pressure on the company to release a statement in support …
When Starbucks CEO Howard Schultz first announced at an employee town hall in April that the company was looking to get into NFTs, I assumed he was just hoping for a headline to …
On 11 September 2022, an attacker used a sophisticated social engineering technique to gain access to Revolut's customer support system through a Revolut employee. The attacker …
On September 11, 2022, Revolut — a UK/EU-based neobank and fintech company with over 20 million customers — suffered a brief but significant data breach via a social engineering …
Remember when Ubisoft decided it was going to shoehorn NFTs into their Tom Clancy's Ghost Recon Breakpoint game, to the nearly universal disappointment of their fans? Remember when …
The Algorand Foundation is a group responsible for managing Algorand, a proof-of-stake blockchain. On September 9 they disclosed that they had put $35 million of the project's …
A flash loan attack against the New Free DAO project resulted in a $1.25 million loss. The project's token also crashed 99% in the wake of the theft. The hacker quickly sent 1,500 …
After what USA Strong Head of Sales & Partnerships described as "months and months" of work, apparently the company had decided they had sunk too much effort into the …
In the wake of OFAC adding Tornado Cash to the U.S. sanctions list in early August, Coinbase has announced they will fund a lawsuit against the Treasury Department to challenge the …
The news of Queen Elizabeth II's death resulted in the creation of at least 40 memecoins, multiple Queen Elizabeth-themed NFT collections, and special edition NFTs in various …
If Amazon would like to buy the rights to the slogan "Web3, powered by AWS™️", feel free to reach out, because I'm registering it.On September 8, a security researcher published a …
The Philadelphia Inquirer published a report on VBit Technologies, later Advanced Mining Group, a company that promised investors to buy and operate Bitcoin miners on their behalf …
An attacker using the Avalanche blockchain successfully executed a flash loan attack impacting one contract and several other liquidity providers. The attacker made around $370,000 …
The latest entry in "group launches NFTs, fans hate it" comes from the David Bowie estate, who decided that "Bowie on the Blockchain" would be a cool idea to raise money for …
Binance users who hold USDC (USD Coin), USDP (Pax Dollar), or TUSD (True USD) will find their holdings "converted" into Binance's stablecoin, BUSD, on September 29. The three …
PoolinWallet is a crypto wallet service provided by Poolin, which runs the fourth-largest Bitcoin mining pool and third-largest Ethereum mining pool in the world. In the …
Mark Hopkins, also known as "Doctor Bitcoin" or "Rizzn", announced on social media that he would be spending between 6 and 15 months in federal prison "for the crime of selling …
In the apparent "first known nonfungible token created and disseminated by a terrorist sympathizer", a supporter of the Islamic State has minted an NFT with a message praising an …
The Los Angeles Unified School District (LAUSD), the second-largest school district in the United States (serving approximately 600,000 students and 74,000 employees), suffered a …
The group Rug Pull Finder aims to combat fraud, scams, and hacks in the NFT space, often investigating crypto rug pulls and offering audits for projects and smart contracts. They …
Some Coinbase customers in Georgia (the country, not the state) took advantage of an hours-long price bug where a misplaced decimal point altered the exchange rate of the Georgian …
Anthem MaineHealth Reports Third Party Data Breach Related to Incident at Choice Health | JD Supra. On September 30, 2022, Anthem MaineHealth (“AMH Health”) filed an official …
Humana Announces Reports Third-Party Data Breach Involving Data Security Incident at Choice Health | JD Supra. On September 21, 2022, Humana confirmed that the company experienced …
Hackers breach software vendor for Magento supply-chain attacks. Hackers have injected malware in multiple extensions from FishPig, a vendor of Magento-WordPress integrations that …
Bill Murray auctioned off an NFT representing the right to drink a beer with him, during which a painter will paint a picture of the scene that the buyer can keep. The auction …
An attacker was able to insert malicious code into the frontend of the decentralized exchange KyberSwap and steal $265,000 of user funds. The project used Google Tag Manager to …
An attacker discovered that anyone could call the burn function on the liquidity pool contract for the ShadowFi project. They were able to exploit this vulnerability by calling the …
2TM, the holding company for the Brazilian crypto exchange Mercado, announced they would be laying off 15% of their workforce — about 100 people. The company had previously laid …
The decentralized crypto exchange dYdX announced on August 31 that they would give users $25 if they completed a "liveness check", which is accomplished by taking webcam facial …
In April, an attacker exploited vulnerabilities in the defi lending project Rari Capital to steal $80 million. The asset management project Babylon Finance was a major lending pool …
Helium is a network of wireless hotspots that decided to bolt on a cryptocurrency layer a few years after it was created. Through this, they hoped to convince people to spend …
DC-based Bitcoin evangelist and former CEO (now chairman) of MicroStrategy has been accused by the DC Attorney General of avoiding years of taxes by pretending to live in Florida, …
Kyle Roche, a founding partner and namesake of the Roche Freedman law firm, has withdrawn from class-action lawsuits filed by the company against projects including Tether and …
Snap Program Manager Jake Sheinman tweeted that "As a result of the company restructure, decisions were made to sunset our web3 team. The same team that I co-founded last year with …
A hacktivist group calling themselves the Belarusian Cyber Partisans managed to gain access to the entire passport records of Belarus last year. On August 30, they began selling …
The Securities and Exchange Commission in Thailand took action against Samret Wajanasathian, the chief technology officer of the Thai crypto exchange Bitkub. The SEC fined him 8.5 …
Compound Finance released an update to change the price feed used by the Compound v2 protocol. Despite being audited by three firms, no one caught a bug that caused all …
Crypto.com somehow managed to not only send a woman AUD$10.5 million (US$7.2 million) in May 2021, but not notice it for months afterwards. The woman had requested a $100 refund, …
Faruk Fatih Özer, the CEO of the Thodex cryptocurrency exchange, swore that when they halted trading and shut off customers' access to accounts in April 2021, it was just to …
OptiFi, a derivatives defi project, accidentally and permanently shut down the project smart contract, irretrievably locking up $661,000 — the project's entire fund. A developer …
An anonymous whistleblower website called "CryptoLeaks" has alleged that Ava Labs, the company behind the Avalanche blockchain, paid lawyers to sue competitors and obtain …
Ragnarok is a metaverse role-playing game that launched its character NFTs in April 2022. The project received $1.75 million in seed funding, plus another $17.5 million from NFT …
Russian cybercriminal (Aleksandr Ermakov, sanctioned by Australia Jan 2024) accessed Medibank's network Aug 25 - Oct 13 2022 via stolen privileged VPN credentials without MFA. …
Some people might be familiar with ENS, the "Ethereum Name Service", which seeks to be a web3 equivalent of DNS. If you've seen people with usernames ending in .eth, that's an ENS …
Financial crime agents from India's Directorate of Enforcement searched the offices of CoinSwitch and the residences of some of its executives. CoinSwitch is the largest crypto …
In 2020, a Canadian teenager used SIM swapping to steal US$37 million in Bitcoin and Bitcoin Cash from a single person. Canadian police announced his arrest in November 2021 after …
It's not much compared to at least three separate crypto Pokémon ripoffs since February that have each taken millions, but apparently the love of Pokémon still drew people in to …
On 23 August 2022, Plex — a media management and streaming platform with approximately 30 million registered users — discovered that an attacker had accessed a subset of their …
The virtual server provider Hetzner posted a clarification that using its service to mine Ethereum — either in its current form or in the promised proof-of-stake version — violates …
Six hours after its launch, the team behind the new SudoRare NFT exchange took the money and ran, deleting the project website and social media. People had already warned about …
The U.S. Attorney's Office of the Southern District of New York announced charges against three men responsible for a scheme in which they stole millions from cryptocurrency …
Honestly, who can blame BendDAO for failing to consider that the hype bubble around Bored Apes and other NFT projects might not last forever! "We underestimated how illiquid NFTs …
In what might be a new record, someone bought a Bored Ape NFT for 70.69 ETH (~$116,000) and had it stolen from them less than two hours later. The scammer quickly flipped the NFT …
The same issue that led to OpenSea paying out $1.8 million to users who lost their NFTs is apparently still alive and well (despite OpenSea's introduction of an "Inactive listings" …
When people started sinking hundreds of thousands of dollars into Bored Ape NFTs, it wasn't long before people came up with the genius idea of using those NFTs as collateral for …
When Terra was collapsing in May, concerned users of the Hodlnaut lending platform asked whether the firm was exposed. CEO JT wrote on Twitter, "Hodlnaut as a firm did not take any …
The Federal Deposit Insurance Corporation (FDIC) sent cease and desist notices to the FTX US crypto exchange and four websites that they allege are falsely claiming their products …
The Australian crypto exchange Swyftx laid off 21% of its workforce, affecting 74 employees. One such employee was on her honeymoon in Hawaii when she learned she was suddenly out …
An experienced crypto trader lost $470,000 to a hack when they signed a malicious message that permitted an attacker to drain all of their USDC stablecoins from their crypto hot …
DegenTown, a collection of brightly-colored cel shaded humanoid figures, launched with much promotion from Magic Eden on their Launchpad minting service. Magic Eden aims to provide …
The Bribe Protocol promised a DAO infrastructure tool where "token holders get paid to govern", and raised $5.5 million in funding in January to work on their extensive roadmap. …
In mid-June, Crypto.com announced they would be laying off 260 people, or around 5% of their employees. However, The Verge has reported that "hundreds more" employees were quietly …
A letter-writer seeking advice from the Financial Times wrote, "I got divorced last year and as part of the financial agreement, my ex-wife and I agreed that I would keep my …
The South Korean Financial Services Commission (FSC) reported to investigators sixteen unregistered crypto exchanges that were serving Korean users and hosting events marketing to …
The Celer Network's cBridge project was targeted with a BGP hijacking attack. Users who tried to access the bridge's frontend were instead shown a site that prompted them to …
Binance's chief communications officer, Patrick Hillman, has come out with a blog post claiming that "Scammers created an AI hologram of me to scam unsuspecting projects". …
HUSD, a stablecoin linked to the Huobi crypto exchange, lost its peg and dropped to around $0.85. HUSD is a cash-backed stablecoin intended to be pegged to the US dollar, but the …
In a just world, people would probably not be able to fail upwards quite to the extent of Adam Neumann, who engaged in all sorts of self-dealing and lost billions of dollars, among …
Canadian caisse de dépôt et placement du Québec (CDPQ), Canada's second-largest pension fund manager, sunk $150 million into Celsius during a WestCap-led funding round announced in …
Crypto broker Genesis is laying off 20% of their employees and reshuffling their leadership in the wake of a several-hundred-million dollar loss related to the Three Arrows Capital …
The U.S. Securities and Exchange Commission filed a complaint against an individual and his companies in relation to their sale of Dragon tokens in 2017. The ICO raised $16.5 …
After halting withdrawals on August 8, Singaporean crypto lender Hodlnaut has applied for protection against creditors: a process similar to the U.S. Chapter 11 bankruptcy.They …
In a motion to dismiss a trademark lawsuit filed by Yuga Labs (the company behind the Bored Ape Yacht Club NFT project) against Ryder Ripps and various others, the defendants …
In May 2021, investment management firm Galaxy Digital announced their plans to acquire crypto custodian BitGo for $1.2 billion in what would be the first $1 billion dollar deal …
The Nasdaq-listed firm Eqonex has announced they will close their "underperforming" crypto exchange, hoping to change their money allocation to "reflect the current market …
A misconfiguration in a newly-deployed liquidity pool allowed an attacker to mint 1.2 billion aUSD, a stablecoin built on the Polkadot network. The exploit caused aUSD to lose its …
The Brazilian crypto lending platform BlueBenx suddenly shut its doors after announcing they had suffered an "extremely aggressive" hack of 160 million BRL (US$32 million). …
An NFT collector who goes by ASEC_APE lost four Bored Ape Yacht Club NFTs to a phishing attack. The attacker quickly flipped three of the four NFTs for a total of around 200 ETH …
A scammer created a fake ApeCoin contract on the NFT Trader service, with tokens that appeared identical to the true ApeCoins but were actually worthless. After "chatt[ing] for a …
On August 4, the team behind the Velodrome exchange and liquidity marketplace noticed that $350,000 had been taken from a team-operated wallet that was normally used for …
"BitBoy Crypto" (Ben Armstrong) has sued "Atozy" (Erling Mengshoel Jr.) over a video in which Mengshoel accuses Armstrong of "lacking integrity as a cryptocurrency commentator" and …
It's no secret that insider trading has happened at Coinbase, with the U.S. Attorney's Office of the Southern District of New York filing charges in July against three individuals, …
India's Enforcement Directorate froze $46.5 million of assets belonging to FlipVolt, the Indian branch of the Vauld cryptocurrency exchange. Vauld had previously filed for …
I've almost got to give it to him. When I wrote up Druglike, Martin "Pharma Bro" Shkreli's new "web3" project for drug discovery, and asked him some questions in the project …
A suspected developer of the Tornado Cash cryptocurrency tumbler was arrested in the Netherlands, according to the country's Fiscal Information and Investigation Service (FIOD). …
The Ethermine mining pool is responsible for over a quarter of all Ethereum mining, making them the largest miner for that blockchain. On August 11, three days after OFAC added the …
Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …
The email marketing company Mailchimp reportedly suspended accounts belonging to several prominent companies and individuals in the crypto sphere, including crypto analytics tool …
Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …
The yield aggregator Blur Finance rug pulled, taking more than $600,000 in assets from the BNB Chain and Polygon-based projects before deleting their website and social media …
A wallet identified as belonging to Celsius CEO Alex Mashinsky sold off 17,475 CEL (the native token of the Celsius lending platform) for around $28,000. Celsius is undergoing …
Mother Jones has reported that the Coinbase crypto exchange stopped sending the email notifications that it had previously sent some users when the price of a cryptocurrency …
The Hotbit cryptocurrency exchange abruptly announced they would be suspending services because they were under criminal investigation, and law enforcement had frozen some of their …
The dominant NFT platform, OpenSea, has changed its policy around NFTs that are reported as stolen. OpenSea now requires those who have reported an NFT as stolen to produce a …
Two days after OFAC sanctioned crypto tumbler Tornado Cash, the blockchain analytics firm Elliptic pointed to cryptocurrency bridges as a likely future target for sanctions if the …
Curve Finance's frontend at curve.fi was compromised, prompting users to give token approval to a malicious smart contract. Stolen funds were then transferred out to the FixedFloat …
The cryptocurrency exchange CoinFLEX announced they had filed for restructuring, a move that probably didn't surprise too many people after they stopped customer withdrawals in …
The German cryptocurrency exchange Nuri, formerly known as Bitwala, filed for insolvency. Interestingly, they did not stop customer withdrawals — as have many exchanges who later …
I've largely stopped covering crypto Discord compromises because they occur so frequently it would drown out everything else. OKHotshot has been keeping count, though, and …
Two-stage breach in 2022. Aug 8-11: attacker compromised software developer's laptop, stole 14 source code repositories. Aug 12: senior DevOps engineer's personal computer …
Crypto sleuth zachxbt has uncovered a French scam duo, Mathys and Camille, who he believes were behind the March "turn your BAYC animated" phishing scam in which they stole a …
The Bitcoin mining firm Riot Blockchain produced 318 BTC in July, valued at around $6.88 million, from its mining operations located in central Texas. The firm also received $9.5 …
Crypto lending firm Hodlnaut announced they would be suspending withdrawals "due to recent market conditions". They also announced they would be withdrawing their license …
The U.S. Office of Foreign Assets Control (OFAC) added Tornado Cash to its SDN list: a list of "Specially Designated Nationals And Blocked Persons" with whom U.S. individuals and …
Non-profit advertising watchdog organization Truth in Advertising (TINA) sent letters to seventeen celebrities, urging them to follow FTC requirements on clearly disclosing when …
After India froze the assets of the WazirX cryptocurrency exchange due to suspicions they were enabling money laundering, suddenly no one wants to admit to operating it.Despite a …
The Polygon-based Dragoma app promised to be a new move-to-earn game, the term for a category of web3 apps that promise to reward people in tokens when they exercise. This …
Who could have predicted that the shitcoin named after one of Elon Musk's 16-year-old sons could turn out to be a scam? Well, besides the people who fell for previous rug pulls of …
The Xinjiang Victims Database is a database that aims to collect records on ethnic minority citizens in China's Xinjiang Uyghur Autonomous Region who have been imprisoned in …
The algorithmic stablecoin project Beanstalk Farms suffered a devastating hack in April 2022, suffering $182 million in losses from a governance attack and flash loan exploit on …
A hacker compromised the wallet belonging to Steven Galanis, the CEO of Cameo, an app that allows people to pay various celebrities to record short messages for them. The hacker …
Researchers from The Hebrew University have identified an attack on the consensus mechanism used by Ethereum which they describe as risk-free and which can used to "obtain …
India's Enforcement Directorate froze $8.16 million of assets belonging to WazirX, a Binance-owned cryptocurrency exchange that is one of the largest exchanges in India. According …
On August 4, 2022, Twilio — a cloud communications platform used by thousands of businesses — confirmed that attackers had breached its internal systems by sending SMS phishing …
CoinDesk revealed that eleven developers behind Solana projects including Sunny Aggregator and Cashio were all actually personas created by Ian Macalinao. Macalinao created the …
The self-described "world's most secure digital asset exchange", ZB, suffered an exploit in which attackers stole a large number of different cryptocurrencies, estimated by various …
After the August 1 Nomad bridge exploit, Nomad created an address where people who took money out of the bridge could return it.However, that was not the address that CoinGape …
Bitcoin maximalist Michael Saylor announced he would be stepping down as CEO of MicroStrategy, which is ostensibly a software company but in recent years appears to be mostly a …
Nearly 8,000 Solana wallets were drained for at least $6 million worth of assets, including native SOL tokens and SPL tokens like USDC. The attack went on for nearly a day before …
In their Q2 earnings report, European cryptocurrency investment firm CoinShares reported that they'd only made $120,000 in net income in the most recent quarter, down from more …
The New York Department of Financial Services levied a $30 million fine against Robinhood, an app used for stock trading that has also branched into crypto. According to the DFS, …
Stock and crypto trading app Robinhood announced they would be laying off 23% of their staff: 780 people. The layoffs followed a prior round of layoffs in April, which saw 9% of …
After an attacker began exploiting a vulnerability in the Nomad bridge, many people rushed to replicate the attack and steal some of the roughly $190 million of various …
Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …
Kiplepay informs users on potential indirect data breach through third-party payment gateway provider. KUALA LUMPUR: E-wallet service provider Kiplepay Sdn Bhd had informed its …
Lee County Emergency Medical Services notifies past customers of third-party security breach. Lee County Emergency Medical Services reports that on Aug. 4 staff received …
Human Verification. Before proceeding to your request, you need to solve a puzzle, and the puzzle requires Google Translate to be disabled. Please disable Google Translate and …
NHS IT supplier held to ransom by hackers. Its IT provider says it may take three or four weeks to fully recover from the cyber-attack. A cyber-attack on a major IT provider of the …
Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …
Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …
Practice Resources, LLC Announces Data Breach Impacting the Information of 924,138 Patients | JD Supra. On August 4, 2022, Practice Resources, LLC confirmed that the company …
In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …
On August 25, 2022, DoorDash disclosed a data breach caused by a phishing attack against an employee of an unnamed third-party vendor with access to DoorDash's internal systems. …
Twilio hack exposed Signal phone numbers of 1,900 users. Phone numbers of close to 1,900 Signal users were exposed in the data breach Twilio cloud communications company suffered …
The SEC charged eleven people who helped to create and promote the crypto pyramid and Ponzi scheme Forsage. The scam operated from January 2020 into 2021, despite multiple cease …
Yield farming project Reaper Farm suffered an exploit that resulted in a $1.7 million loss. The attackers discovered a vulnerability that allowed them to withdraw anyone else's …
Two men who ran an "investment management service" called Dropil were sentenced to 2½ and 3 years in prison after stealing around $1.9 million from more than 2,000 people. …
Half of the money in a large deal between the crypto platform Voyager Digital and the National Women's Soccer League was supposed to be distributed to players in cryptocurrency …
On August 1, 2022, the Nomad cross-chain bridge was drained of approximately $190 million in a chaotic 'free-for-all' exploit. A recent routine upgrade had inadvertently set the …
Babel Finance, a crypto lender that suspended withdrawals in mid June, sustained "massive losses" thanks to its proprietary trading desk, which was trading with customer funds. …
CoinFLEX, a yield farming platform that stopped withdrawals in late June, announced they had made major staff cuts to reduce their cost base by 50–60%. "The intention is to remain …
Helium, a network of wireless hotspots for low-power devices whose operators are incentivized by a crypto token, has been lying about its relationship with scooter rideshare …
The Solana-based yield farming project, Nirvana Finance, was exploited by an attacker who used flash loans to drain the project of just under $3.5 million. The attacker took out a …
One of the ways Voyager Digital drew in customers was by promising that their funds in USD were protected from a collapse of the company by FDIC deposit insurance, which normally …
"DAO delusion was at its peak when the community went into this journey together", wrote SpiceDAO founder Soban "Soby" Saqib. SpiceDAO (named for the Dune drug) won an auction to …
Those in the crypto ecosystem have long claimed to embrace the principles of censorship resistance and freedom of speech, but apparently some of them draw the line at speech that's …
The New York Times reported on July 26 that the Treasury Department's Office of Foreign Assets Control (OFAC) has been investigating major US-based crypto exchange Kraken for …
CEO Michael Stollery of Titanium Blockchain Infrastructure Services (TBIS) pled guilty to securities fraud in connection to a $21 million cryptocurrency scam. The company promoted …
The Australian crypto company Immutable fired 17% of staff from its gaming division. Immutable has said this amounted to 18 workers, though the Games Workers Australia union …
Nemus is an NFT project already described in W3IGG for its plans to become "Guardians" of the Amazon rainforest and saviors of its Indigenous populations by selling Ethereum NFTs …
The Teddy Doge defi project saw its token price plummet over 99% as 30 billion TEDDY were transferred from the project's deployer and distributed to various wallets, which then …
Martin Shkreli, sometimes known as "Pharma Bro", earned notoriety after obtaining the patent for an anti-parasitic drug and hiking the price from $13.50 a pill to $750. An FTC …
An attacker was able to create and pass a governance proposal to transfer out 18.5 million AUDIO tokens from the community treasury. They then successfully swapped these for 705 …
GameStop's brand new NFT platform, which launched on July 12, is off to a less than promising start. Unlike some other NFT platforms like OpenSea, Gamestop does not allow just …
Celsius customers have begun to send letters to the judge presiding over Celsius Network's bankruptcy case in the Southern District of New York. More than fifty letters have been …
The cryptocurrency exchange Blockchain.com announced they would be cutting 25% of their employees, or around 150 people. They attributed the decision to the crypto market …
Ishan Wahi, a former product manager for Coinbase, was indicted on two charges of wire fraud and two charges of wire fraud conspiracy for allegedly tipping off his brother and …
Randall Crater, founder of the cryptocurrency company My Big Coin, was convicted of multiple charges including wire fraud for a crypto scheme in which he stole more than $6 million …
Prosecutors working on the fraud case around the May Terra/Luna collapse raided seven cryptocurrency exchanges in South Korea including Bithumb, Upbit, and Coinone. They also …
Bored Ape aficionado franklinisbored has apparently found a new source of entertainment by placing high bids on his own ENS domains with amusing names, causing a Twitter bot that …
Tesla announced in their Q2 financial report that they had sold about 75% of the Bitcoin they had been holding. The company first bought $1.5 billion of Bitcoin in January 2021, at …
Five villages were evacuated and a rail line was closed as a wildfire has burned 14,000 hectares (~35,000 acres) near Ateca in northwestern Spain. The fire was reportedly sparked …
Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …
Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …
Singapore-based crypto exchange Zipmex is the latest in a long string of crypto platforms to suspend customer withdrawals. "Due to a combination of circumstances beyond our control …
20.8 million BUSD, a dollar-pegged stablecoin on BNB Chain, was transferred from Raccoon Network and the Freedom Protocol on July 19. Security firm PeckShield identified the …
Salesforce Park, a suspended park area underneath the Salesforce Tower, has been described as intentionally unwelcoming to the many unhoused San Franciscans it looms atop. Parts of …
The FBI's Cyber Division issued a notification about fraudulent cryptocurrency investment apps that are successfully being used to defraud American investors. The scammers …
The cryptocurrency exchange Bexplus announced that "due to force majeure, Bexplus will stop service from now on". Users were told to close their open positions and withdraw any …
Binance, the world's largest crypto exchange, was fined €3.3 million ($3.35 million) by De Nederlandsche Bank (DNB) for operating in the Netherlands without the required …
The cryptocurrency lender BlockFi is reportedly offering employees buyouts — sorry, a "voluntary separation program" — in an effort to reduce their headcount even further. Those …
After laying off 10% of its workforce in the first week of June, Gemini has performed a second round of layoffs. The layoffs have not been announced externally, nor were they …
SkyBridge Capital, an investment firm founded by Anthony Scaramucci, reportedly suspended redemptions from its "Legion Strategies" fund. Around 18% of the $230 million fund is …
PREMINT is an NFT service intended to help project creators build access lists for new NFT projects based on various qualifications. The project was compromised on July 17, and …
The AEX crypto exchange paused all withdrawals on June 16, estimating a 36-hour outage "to avoid unnecessary panic withdrawal". Then, instead of re-enabling all withdrawals, they …
On July 16, hackers compromised the Twitter account belonging to the well-known NFT artist DeeKay, who sold an NFT for 310 ETH (then $1 million) to Snoop Dogg in April. The 180,000 …
A leaked email revealed that Coinbase is planning to temporarily end its affiliate-marketing program, which pays influencers to convince their followers to sign up. Some …
Crypto sleuth zachxbt has accused the NFT project "Boneheads" of rug pulling only weeks after the project minted in August 2021. Although they promised physical collectibles, more …
The studio behind Betty Boop decided there was no better time to launch a Betty Boop NFT collection than during a period of record low interest in NFTs (or, more likely, they …
OpenSea, the largest NFT marketplace, announced that they would be laying off around 20% of their employees, or around 60 people. CEO Devin Finzer blamed "crypto winter" for …
One month after pausing customer withdrawals, crypto lending firm Celsius Network filed for Chapter 11 bankruptcy. Celsius had recently hired a new group of restructuring lawyers …
In October 2020, the SEC filed charges against anti-virus software magnate, two-time Libertarian presidential candidate, and all-around shady character John McAfee, as well as his …
Citizen Finance, a multichain platform that has something to do with NFTs and blockchain gaming, claimed to have suffered an attack by an outside party who obtained access to a …
In a successful, broadly-targeted phishing campaign, more than 70,000 addresses connected to Uniswap were airdropped tokens that baited users into approving transactions that …
Crypto lending firm Vauld, which suspended withdrawals and announced they were considering restructuring on July 4, have disclosed to their creditors a shortfall of around $70 …
The latest Reuters investigation into Binance has alleged that the company processed transactions for Iranian users, despite U.S. sanctions and the company's claim to be compliant …
Bifrost is a platform that allows developers to create dApps across multiple blockchains. They run the service BiFi, which is a defi platform built atop Bifrost. On July 10, they …
Hackers used a flash loan attack to steal around 1,300 ETH ($1.43 million) from the NFT lending platform Omni. Omni allows users to borrow cryptocurrency against their NFTs.Hackers …
When CoinFLEX suspended withdrawals on June 23, they blamed "continued uncertainty involving a counterparty".Although they initially dodged naming the counterparty, CEO Mark Lamb …
Ivan Ravlich, founder of the nebulous crypto firm called Hypernet Labs, announced on Twitter that "Hypernet's road has reached an end". "Hypernet was impacted by the same market …
Crypto exchange Blockchain.com announced in a letter to shareholders that they could lose the $270 million in cryptocurrency and USD they loaned to Three Arrows Capital, a …
On 8 July 2022, Rogers Communications — Canada's largest telecommunications company serving approximately 12 million wireless customers — suffered a massive network outage that …
Kyle Davies and Zhu Su, the founders of Three Arrows Capital, have apparently disappeared after the firm entered bankruptcy proceedings. Although lawyers for the duo have said they …
Cryptocurrency exchange Vauld, who suspended withdrawals on July 4, filed for a moratorium against creditors in Singapore, a process that's conceptually similar to Chapter 11 …
Reddit announced that they will be selling "Collectible Avatars", artist variations on the Reddit "Snoo" figure that users can then customize. Amusingly, Reddit's announcement …
The Spanish cryptocurrency platform 2gether suddenly announced that they were "forced to close service for private accounts" due to "lack of resources and crypto winter". Users …
Jason Stone, founder of the KeyFi company who formerly managed assets for Celsius, filed a complaint against Celsius Network in a New York court, alleging the company was operating …
According to Seoul Economic Daily, the Korean cryptocurrency investment fund Uprise lost 99% of its customer funds when they tried to short Luna during its collapse in May. …
The cryptocurrency exchange Bitstamp announced its plans to charge a €10 (~$10.17) monthly fee to inactive users outside of the US who had account balances below €200 ($203.38). …
A user tried twice to swap $5 of the USN stablecoin for Tether on the Decentral Bank platform. Both times, the transaction failed due to a bug that prevented users who didn't …
Genesis, a crypto broker and lender, suffered "a few hundred million dollars" in losses during the recent crypto downturn. This were largely due to the firm's exposure to the …
Voyager Digital, a crypto broker that suspended withdrawals a week prior, announced that it had filed for bankruptcy. They attributed their decision to "prolonged volatility and …
Vaporware is hardly a new phenomenon in the web3 space, but the Polium project is bringing it to new heights. They announced their product — a "multi-chain console for Web 3 …
The U.S. Office of Government Ethics issued a legal advisory stating that government employees who hold cryptocurrency may not work on policy or regulation that could potentially …
Claiming that they had no exposure to the various high profile collapses in the crypto industry lately, CoinLoan announced that they nevertheless would be reducing account …
Vauld, a major cryptocurrency lender backed by the likes of Coinbase and Peter Thiel, announced they have suspended withdrawals, trading, and deposits due to the crypto market …
The 362,000-follower verified Twitter account and 178,000-follower YouTube account for the British Army were simultaneously compromised, and used to shill two different crypto …
Solana liquidity protocol Crema Finance was exploited for around 69,500 SOL (~$2.3 million) and around $6.5 million worth of stablecoins for a total loss of around $8.8 million. …
Ransomware attack one of year's biggest health data breaches. A cyberattack on a little-known debt collection firm affects over 650 healthcare facilities across the U.S. A …
First Choice Community Healthcare Data Breach Affects 101,000 Patients. First Choice Community Healthcare in Albuquerque, NM, has started notifying certain patients that an …
Boeing Employees’ Credit Union Announces Third-Party Data Breach Following Incident at Printing Vendor | JD Supra. On July 25, 2022, Boeing Employees’ Credit Union (“BECU”) filed …
Blockworks. $72.1K $72,120.00 $2.2K $2,214.14 $602.5 $602.46 $84 $83.95 $41.4 $41.37. 24hr Spot DEX Volume $6.03B -0.75%24hr App Revenue $11.81M -0.01%24hr Blockchain REV $229.96M …
Student Loan Breach Exposes 2.5M Records. 2.5 million people were affected, in a breach that could spell more trouble down the line. EdFinancial and the Oklahoma Student Loan …
Anesthesia, Eye Care, and Telehealth Providers Announce Third-Party Data Breaches. Several more providers of anesthesia services have confirmed they have been affected by a data …
Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …
Page not found - Toronto Symphony Orchestra. It looks like you may be using a web browser version that we don't support. Make sure you're using the most recent version of your …
The Ankr public RPC gateways (basically an API for dApps and other services to communicate with the blockchain) for Polygon and Fantom were impacted when attackers compromised the …
Quixotic, an NFT marketplace on the Optimism network, was attacked after a hacker was able to exploit a recently updated smart contract. The attacker made off with at least …
Voyager Digital announced that they had suspended trading, deposits, withdrawals, and loyalty rewards. This came after it was revealed that Voyager had issued a notice of default …
Diem, formerly known as Libra, was a stablecoin-based payments system proposed by Meta, formerly known as Facebook. Novi, formerly Calibra (are you keeping up?), was a crypto …
The U.S. Department of Justice announced charges against Le Anh Tuan, who was one of the individuals behind the "Baller Ape" NFT rug pull in October 2021. According to the DoJ, …
If it wasn't already nauseating to watch a huge corporation like Coca-Cola use LGBTQ Pride Month to market their products and pay lip service to supporting LGBTQ rights while …
Mirror Trading International was a South African Bitcoin pool operator that advertised to investors that it would generate 10% returns a month, with bonuses for referring friends …
According to CNBC, the cryptocurrency exchange FTX is hammering out the details on an agreement to acquire crypto lending platform BlockFi. Earlier in June, it was reported that …
The U.S. Department of Justice announced fraud charges against David Saffron, the owner of the Circle Society cryptocurrency investment platform (with no relation to Circle). …
The U.S. Department of Justice announced they had filed charges against Emerson Pires, Flavio Goncalves and Joshua David Nicholas, the two founders and the "head trader" of the …
The U.S. Department of Justice charged Michael Alan Stollery with securities fraud over his role as founder and CEO of Titanium Blockchain Infrastructure Services (TBIS). TBIS was …
The U.S. Securities and Exchange Commission rejected a proposal from Grayscale Investing that would turn their Bitcoin trust into an exchange-traded fund (ETF). If accepted, this …
A Freedom of Information Act request has revealed an August 2021 contract between U.S. crypto company Coinbase and U.S. Immigrations and Customs Enforcement (ICE). The contract …
A court in the British Virgin Islands ordered the liquidation of Three Arrows Capital, a crypto hedge fund. This follows initial rumors in mid-June that the firm was insolvent, …
A somewhat blundering group of developers decided to create "w3itch.io", an online marketplace for game creators. The marketplace said it was intended to be friendly to games …
The CEO and CFO of Compass Mining, a Bitcoin mining hosting and brokerage services firm, both resigned suddenly on June 28. The sudden departures followed accusations the previous …
XCarnival is a project describing itself as a "metaverse asset bank". The project drew in users by promising high rewards, with one marketing campaign promising 41% APY.A hacker …
Chevrolet decided to create their first ever NFT, an illustration of a bright green 2023 Corvette Z06. The 1 of 1 edition NFT, titled "Own the Color", also would come with a "free" …
The LA Times reported that the Bored Ape-themed "Bored & Hungry" restaurant in Long Beach, California had stopped accepting crypto payments. Despite excitedly announcing the first …
The Austrian cryptocurrency exchange Bitpanda joined the recent litany of crypto companies laying off employees. In an announcement to staff, later shared publicly, the company …
The LA Times reported that the Bored Ape-themed "Bored & Hungry" restaurant in Long Beach, California had stopped accepting crypto payments. Despite excitedly announcing the …
The Horizon Bridge is a blockchain bridge allowing assets to be used across Ethereum, BNB, and Harmony blockchains. The bridge is run by the Harmony blockchain project.On June 23, …
Yield farming platform CoinFLEX is the latest crypto platform to stop allowing customers to withdraw their money. Customers had raised concerns about withdrawals not processing, …
After announcing their crypto-friendly proposed legislation earlier in June, Senators Lummis and Gillibrand have uploaded it to Github to solicit feedback, as was apparently widely …
The Ontario Securities Commission (OSC) accused crypto trading platforms Bybit and Kucoin of operating unregistered platforms and offering unregistered securities to Ontarian …
In a decision that makes you wonder if there was one single queer person in the room during the branding meetings, Hostess has announced $TWINKcoin snack cakes. The limited-edition …
Invictus Capital, the group operating several cryptos in the Cayman Islands and the British Virgin Islands, announced to investors that it would be suspending redemptions. The …
Voyager Digital disclosed that they had loaned $350 million in stablecoins and 15,250 Bitcoin (around $310 million) to Three Arrows Capital, a crypto hedge fund that could not meet …
Crypto exchange FTX loaned $250 million to BlockFi, a crypto lending platform that recently announced 20% layoffs as they struggled to weather the crypto downturn. BlockFi also had …
The Peter Thiel- and Coinbase-backed Vauld cryptocurrency exchange laid off 30% of its 100–200 employees, reportedly due to falling prices, low trading volumes, and tax concerns. …
Research firm Logically published an investigation into two QAnon influencers who successfully convinced their follower to put more than $2 million into crypto scams. Telling their …
A former employee of Terraform Labs, the company behind the Terra project that collapsed in May, found that he was banned from leaving the country. According to the former …
Bybit, a Dubai-based cryptocurrency exchange, is reportedly joining the group of crypto companies laying off employees amidst plummeting cryptocurrency markets. Journalist Colin Wu …
So, apparently polo shirts have NFTs now. Fashion brand Lacoste's NFT project is titled "Undw3", which is apparently supposed to be pronounced "underwater" — I guess if you say the …
Solend DAO, the DAO behind the Solend lending protocol on Solana, just passed its first ever governance proposal. A whale used their platform to take out an enormous margin …
The defi insurance protocol Bancor announced on June 19 that they would be suspending their impermanent loss protection due to "hostile market conditions". The feature sought to …
The Hong Kong-based cryptocurrency exchange Hoo announced that they would be pausing withdrawals, after so many customers tried to withdraw their crypto that they began to run out …
A stablecoin called Magic Internet Money (yes, really) is one of the latest to have trouble maintaining its peg. The stablecoin is issued by the Abracadabra lending platform, which …
Babel Finance is the latest crypto finance platform to suddenly limit customer withdrawals. Citing "unusual liquidity pressures" and "conductive risk events" to crypto …
MakerDAO voted to disable the Aave—DAI direct deposit module, which previously allowed users to mint DAI (MakerDAO's stablecoin) and deposit it into the Aave lending protocol. …
The Wall Street Journal reported that Three Arrows Capital, a crypto hedge fund that was rumored to be insolvent several days earlier, was indeed pursuing last-ditch options to …
A hacker was able to perform an oracle manipulation attack enabled by flash loans to siphon crypto worth around $1.26 million from Inverse Finance. The loss to the protocol was …
A hacker was able to perform an oracle manipulation attack enabled by flash loans to siphon crypto worth around $1.26 million from Inverse Finance. The loss to the protocol was …
The AEX crypto exchange is among a growing number of exchanges to limit customer withdrawals amidst a crypto downturn. In an announcement, AEX wrote that "we honestly admit that …
Anna Sorokin, the scammer who convinced people and companies to give her hundreds of thousands of dollars by pretending to be a German heiress, has decided to get into NFTs. After …
Finblox is a crypto yield farming company that describes themselves as a "savings platform" and promises "up to 90% APY on your crypto!". They announced they would be preventing …
8 Blocks Capital is a Hong Kong-based trading firm. In a Twitter thread, Danny Yuan explained that 8BC had been using 3AC's trading accounts to reduce their trading fees. He wrote, …
The U.S.-based crypto exchange Kraken has announced that, despite the layoffs and hiring freezes among its competitors in the ongoing "crypto winter", they intend to keep hiring …
The Discord server for Known Origin, a fairly major NFT platform, was compromised. The scammer used their access to advertise a fake free NFT mint, which actually would steal NFTs …
After playing up how Axie Infinity had "created hundreds of thousands of jobs in the Philippines" and other locations where salaries are low, Axie Infinity has crumbled. Some …
The Iowa Insurance Division announced that they had levied a $943,000 fine against BlockFi for failing to register securities they offered on their platform. The regulator also …
Coinbase announced that they would be cutting 18% of their employees, amounting to 1,100 people. This announcement came only two weeks after they rescinded already-accepted job …
Members of the Merit DAO, a DAO operating in the play-to-earn space, voted on proposals renege on a deal signed with an early investor to the DAO, Yield Guild Games (YGG). The …
According to FOX Business, the SEC has sent an inquiry to at least one "major crypto exchange", in what their source said they believed was an investigation spanning several …
Blockchain data showed that Three Arrows Capital (3AC), a crypto-focused hedge fund based in Singapore, appeared to be dumping stETH as quickly as possible. stETH is Lido-staked …
Binance paused Bitcoin withdrawals for three hours on June 13, explaining that some network maintenance resulted in transactions becoming "stuck and not able to be processed …
A group of people who put money into Terra (UST), the stablecoin that collapsed in May, have filed a class action lawsuit against Binance.US. Binance.US is a crypto exchange that …
In October 2021, an NFT collector dropped 300 ETH (then $1.05 million) on CrypToadz #2155, a pixel art image of a blue toad skeleton on a blue background. On June 13, they sold the …
USDD, the algorithmic stablecoin belonging to the Tron network, dipped as low as $0.91 from its $1 peg on June 13 amidst a day of turmoil elsewhere in the crypto ecosystem. …
On June 10, Crypto.com announced they would be "making targeted reductions" of 260 people, amounting to around 5% of their workforce. On June 13, BlockFi announced that they were …
The Confiant security research group has discovered a group that is backdooring and distributing versions of legitimate crypto wallets including Coinbase Wallet, MetaMask, …
Lido-staked ETH, a project that offers to allow users to stake ETH for the purposes of securing it after the Ethereum "merge" — that is, the ever-delayed move to proof-of-stake. …
The Celsius platform announced that they would be pausing all withdrawals, swaps, and transfers due to "extreme market conditions".There has been a lot of concern lately about …
Scammers successfully compromised the Twitter account for El Universal, a Venezuelan newspaper. The account is verified, and has five million followers. The scammers used the …
Scammers successfully compromised the Twitter account for El Universal, a Venezuelan newspaper. The account is verified, and has five million followers. The scammers used the …
Some crypto advocates have long promoted crypto as a proper digital equivalent to cash. Physical dollars have a lot of benefits, including that you don't need a bank account to use …
The ApolloX exchange suffered an exploit where an attacker was able to withdraw around 40 million $APX, which they were able to swap for around $1.5 million. This also caused the …
The Baby Elon project on BNBChain rug pulled on June 8, with the token price plummeting 98% as the team withdrew 623 BNB (~$179,000) from the project. They quickly moved the funds …
Attackers stole around $2.1 million from the GYM Network defi project after exploiting a bug in a recently-deployed contract that failed to check the identity of the caller. The …
Representative Madison Cawthorn (R-NC) is facing an ethics investigation pertaining to his involvement with the Let's Go Brandon coin, which includes allegations of insider trading …
As the Ethereum scaling project Optimism worked to create the $OP token, a token they launched in a move towards decentralizing the project's governance, they decided to obtain a …
The Osmosis chain was halted on June 8 after users discovered a bug where people could deposit money into Osmosis pools and receive 3x the amount when they withdrew. The bug was …
Crypto-sleuth zachxbt reported on June 8 that Players Only, and NFT project created by a group of NBA players including Michael Carter-Williams and Jerami Grant, appears to be a …
Senators Lummis (R-WY) and Gillibrand (D-NY) introduced the "Responsible Financial Innovation Act", the first major proposal for cryptocurrency regulation in the US. A press …
The June 4 compromise of the Bored Apes Discord was only one of several Discord hacks in a several-day period. All the attacks appeared to involve user accounts of individual …
You might think that, since Epic Games has decided to distinguish itself from its major competitor Steam by welcoming blockchain games to its platform, they might try to make a …
You might think that, since Epic Games has decided to distinguish itself from its major competitor Steam by welcoming blockchain games to its platform, they might try to make a …
A Reuters investigation alleged that Binance "served as a conduit for the laundering of at least $2.35 billion in illicit funds" between 2017 and 2021. Binance is the largest …
The same day that Reuters released an investigation implicating Binance in helping to launder billions of dollars of illicit funds, Bloomberg reported that the U.S. Securities and …
Hackers were able to discover and exploit a bug in the decentralized exchange Maiar, stealing assets notionally worth $113 million. Maiar developers took the exchange offline soon …
Scammers were able to compromise the Discord account of a Bored Apes community manager, then use it to post an announcement of an "exclusive giveaway" to anyone who held a Bored …
An NFT collector hoping to claim NFTs from the Goblintown collection was phished, resulting in ten of their NFTs being stolen from them. The scammers took two Mutant Ape NFTs and …
The New York state Senate passed a bill putting a two-year halt on issuing new or renewing existing permits for crypto mining at fossil fuel plants — a practice that has been …
The Canadian firm Timechain claimed that they lost around $4 million to the Terra collapse, a loss they said destroyed the company. Timechain claimed that a stop-loss mechanism …
The U.S. Federal Trade Commission (FTC) reported that "Although it's yet to become a mainstream payment method, reports to the FTC show [crypto is] an alarmingly common method for …
Animoon is yet another Pokémon rip-off NFT project, with artwork that was ripped directly from Pokémon artwork and recolored. They claim to have a "signed NDA" with Pokémon …
Hoping to riff off the popularity of the recent and weird Goblintown NFT project, some NFT enthusiasts decided to make their own "Goblin Asses" project, which is exactly what it …
A Reddit poster asking for legal advice reported that when they moved out of their apartment, they received only $1600 of the $3000 they provided to their landlord as an initial …
The same day that Gemini announced they would be laying off 10% of their staff, Coinbase announced they would be extending a hiring freeze they'd put in place two weeks earlier, …
The TIGER project was supposed to be a DAO aiming to "support global technical teams" and protect wild animals and the environment. The project was broad-ranging, and had NFT, …
The Winklevoss twins, founders of the Gemini crypto exchange, announced to employees and in a public blog post on June 2 that they would be laying off 10% of their workforce. They …
Gemini is a major cryptocurrency exchange and market for Bitcoin futures. The Commodity Futures Trading Commission (CFTC) filed a lawsuit against Gemini for making false or …
Not Found. Best in Class Identity Protection Services | ID Theft Protection | IDX. Best identity protection services to keep you safe from cyber crime with credit and identity …
BCBS of Massachusetts Reports Third-Party Vendor Data Breach | TechTarget. BCBS of Massachusetts reported a third-party vendor data breach involving its pension plan payment …
Texas Tech University Health Science Center Reports Third-Party Data Breach Affecting 1.3 Million Patients | JD Supra. Recently, Texas Tech University Health Science Center …
Colorado Springs Utilities experiences data breach, customer data compromised. COLORADO SPRINGS, Colo. (KRDO) -- Colorado Springs Utilities is warning customers about a data breach …
OpenSea users' email addresses leaked in data breach. If you’ve shared your email address with the NFT marketplace, you should assume to be impacted. The company is working with …
120K Priority Health Members Impacted By Third-Party Data Breach | TechTarget. Michigan-based health plan Priority Health notified 120,000 individuals of a third-party data breach …
In June 2022, Marriott International suffered its third significant data breach in four years (after the 2018 Starwood breach affecting 383M guests and the 2020 employee credential …
Twilio employees received smishing SMS impersonating IT dept claiming password expiry. Employees entered credentials on fake Twilio login page with real-time MFA relay bypassing …
NFT collector onekiller purchased Bored Ape #7256 for 188 ETH a month ago — at the time worth about $513,000. On June 1, they sold the ape for 0.088 ETH, or $161.It's not quite …
Solana is one of the more popular proof-of-stake blockchains, and is often trotted out as an alternative to Ethereum when people bring up Ethereum's environmental impact, slowness, …
Alex Hern, a technology editor at the Guardian, was surprised to receive an onslaught of messages asking about "Tsuka", a new crypto token. It turned out someone had been using …
Alex Hern, a technology editor at the Guardian, was surprised to receive an onslaught of messages asking about "Tsuka", a new crypto token. It turned out someone had been using …
A group of 26 technologists (disclosure: myself included) have signed an open letter to U.S. lawmakers urging them to "take a critical, skeptical approach toward industry claims …
Nate Chastain was asked to resign from his position as Head of Product at OpenSea in September 2021 following allegations of NFT insider trading. Online sleuths had discovered that …
An NFT collector trying to list their Bored Ape NFT for sale on OpenSea made a typo, and accidentally listed it for sale for 10 ETH (around $19,000) instead of 105 ETH (around …
Someone has been able to drain more than $2 million from the Mirror Protocol in the Terra ecosystem. It appears they are exploiting an issue with the price oracle for "Luna …
The Superlative Apes NFTs are a collection of Bored Apes derivative NFTs that feature colorful pastels. The project amassed a large following (including, apparently, the rapper …
The Toronto Comic Arts Festival angered artists and fans alike when they invited Saba Moeel, the artist behind the Pink Cat NFT collection, to attend as a featured guest. This was …
All holders of Luna, who saw their holdings crash to nothing in the Terra collapse, received an airdrop of the new Luna tokens with the release of Terra 2.0 (electric boogaloo). …
A somewhat robotic-sounding deepfake Elon Musk speaks to a deepfaked interviewer, who asks "what can you tell us about your project and how can it help people get rich right now?" …
The token associated with yet another crypto Pokémon rip-off, PokeMoney, suddenly crashed in price when around 11,800 BNB ($3.5 million) worth of it was pulled out of the project. …
A crypto researcher who goes by "FatMan" discovered that the Mirror Protocol in the Terra ecosystem contained a serious vulnerability, that was quietly patched with no announcement …
The Solana blockchain clock drifted about 30 minutes behind real-world time on May 26, as a result of slower-than-usual slot times. Solana's status page read that "this has no …
The Latin American crypto exchange Bitso laid off 80 employees, around 10% of their staff which had previously amounted to around 700 people. The exchange told CoinDesk that they …
Following the dramatic collapse of Terra earlier this month, the Terra ecosystem voted to pass a proposal by Do Kwon to create "Terra 2.0". The project intends to "effectively …
On 24 May 2022, a Yanluowang ransomware affiliate (linked to UNC2447/Lapsus$ connections) compromised Cisco Systems through a combination of credential theft from a personal Google …
Adam and Rebekah Neumann, the duo behind the WeWork coworking space company that imploded spectacularly in 2019, have re-emerged to start a company called Flowcarbon. The company …
The creators of the Decentraworld project, and its associated $DEWO token, rug pulled for 3127 BNB, valued at just over $1 million. The project promised an "ecosystem of dapps with …
A scammer was able to trick a prolific NFT collector into signing a transaction on a fake trading website, which then allowed them to maliciously transfer 29 pricey Moonbirds NFTs …
The U.S. House of Representatives Committee on Ethics announced on May 23 that they had unanimously voted to investigate whether Representative Madison Cawthorn (R-NC) "improperly …
Attackers gained control of the Twitter account belonging to Beeple, an artist known for "selling" an NFT for $69 million in March 2021 and for his recent horror-inducing NFT …
Crypto speculator Jonny Reid wrote on May 22 that his crypto wallet had been hacked and drained of approximately $203,000. He wrote that he had never owned a hardware wallet before …
The founder of the Remilia Collective and its popular "Milady Maker" NFT project, "Charlotte Fang", was discovered to have been a key player in a white supremacist cult known as …
bDollar was the first algorithmic stablecoin on the BSC blockchain. An attacker was able to manipulate the price of underlying assets to pull 2,381 wBNB out of the protocol, worth …
A litigation firm filed a class action lawsuit against HUMBL, a financial services company that touts its web3 and defi products. The lawsuit alleges that HUMBL and its executives …
The serial rug-puller who was behind the Balloonsville rug pull in February and Doodled Dragons rug pull in January has popped up once again, this time with a Solana NFT project …
A class action law firm sent a letter to the yield generation project Stablegains, demanding records on customer accounts, marketing and advertising strategies, and communications …
The $QANX token for the QAN project suddenly plummeted in value as an attacker stole more than 4 million QANX from the project. The attacker subsequently swapped the tokens for …
The $QANX token for the QAN project suddenly plummeted in value as an attacker stole more than 4 million QANX from the project. The attacker subsequently swapped the tokens for …
The "Feminist Metaverse" ($FM) token suddenly plunged in value by 99.7% after an attacker stole 1,838 BNB ($533,000). The hacker quickly transferred the stolen funds to the Tornado …
Following the collapse of the Terra ecosystem and its tokens TerraUSD and Luna, affected Korean investors have filed both criminal and civil lawsuits against the project's creator, …
Members of several large NFT Discord servers began seeing suspicious-looking messages announcing supposed NFT mints that turned out to be fakes. Affected communities appeared to …
Actor Seth Green tweeted that he had been targeted with a phishing attack that resulted in the theft of four pricey NFTs: a Bored Ape, two Mutant Apes, and a Doodle. The thief …
In what seems like a bad sign for Terraform Labs, the developer of the Terra blockchain and the TerraUSD (UST) and Luna cryptocurrencies, the three members of the company's legal …
On May 15, Binance CEO Changpeng Zhao (widely known as CZ) created a tweet thread in which he attempted to speak nonchalantly about questions that had "just occurred to [him]" …
An unidentified US citizen transferred more than $10 million in Bitcoin to a cryptocurrency exchange in a "comprehensively sanctioned" country where they were running a payments …
Many were eagerly awaiting a report from Luna Foundation Guard (LFG) on what happened to the several billion dollars' worth of Bitcoin reserves they once held, which they …
The defi lending protocol Scream may have taken the "stable" in "stablecoin" a bit too literally when they hardcoded the prices of the Fantom USD (fUSD) and DEI stablecoins. In the …
Another stablecoin lost its peg as dominoes continued to fall in the declining crypto market. DEI, an algorithmic stablecoin created by Deus Finance on the Fantom network, …
A flash loan attack on the "Feed Every Gorilla" (FEG) token swap contracts pulled $1.3 million from the project, also tanking the token price by 80%. The project operates on both …
Now that the dust is settling somewhat from the dramatic collapse of Terra, people are beginning to wonder when they'll hear more about what exactly happened to the 80,394 Bitcoin …
Popular cryptocurrency websites including Etherscan, CoinGecko, and DeFi Pulse were showing users a pop-up prompting them to connect their MetaMask wallets. CoinGecko founder Bobby …
One of the features of crypto that its proponents sometimes highlight is that transactions can't be reversed. This, of course, is not true when making trades on exchanges like …
InsurAce is a defi insurance provider (oh yes, they exist) that allows people to buy insurance against events including smart contract vulnerabilities and stablecoin depegs. …
In what is beginning to become a pattern, SpiritSwap was the latest project where attackers gained control of their domain and were able to modify the frontend to divert funds to a …
After $LUNA dropped below $0.01, Terra announced that they halted the Terra blockchain. "Terra validators have decided to halt the Terra chain to prevent governance attacks …
Earlier today, Terra halted their blockchain after a devastating few days. Subsequently, Chainlink's oracle paused the price feed, causing it to fall out of sync with the apparent …
Eddy Alexandre, CEO of the cryptocurrency and forex trading platform EminiFX, was charged by the FBI with fraud for his role in what he described to investors as a crypto …
Tether, the largest stablecoin, had a major wobble. Pegged to the U.S. dollar and widely used throughout the cryptocurrency ecosystem, even a fractional cent deviation from its peg …
In a scoop published shortly after the catastrophes began with TerraUSD and Luna, CoinDesk reported that Terraform Labs CEO Do Kwan had also previously led a different failed …
Terraform Labs develops two cryptocurrencies: TerraUSD ($UST), an algorithmic stablecoin meant to be pegged to the U.S. dollar, and $LUNA, a crypto asset used both for speculation …
The New Zealand cryptocurrency exchange BitPrime paused trading operations, issuing a notice to their customers: "A perfect storm has occurred, where liquidity has reduced, the …
Ruja Ignatova, also known as the "Cryptoqueen", is a serial fraudster who has been on the run since 2017. In 2019, she was charged in absentia by U.S. authorities due to her …
Coinbase added new language to its latest 10-Q, a quarterly report submitted by public companies to the SEC. In the section outlining risks to the business, Coinbase wrote: …
In a blog post titled "A Builder's Journey", the founder of the popular Azuki NFT project admitted that he had also been behind the NFT projects CryptoPhunks (note the "h"), …
The G.O.A.T. ("Greatest of all Tokens") project claimed to be "the new standard in cryptocurrency", with vague claims that it would "add value by addressing scalability and risk …
It's been a rough few days for TerraUSD, one of several popular stablecoins pegged to the US dollar. Unlike many stablecoins like Tether or USDC, Terra is an algorithmic …
In what almost guarantees some fun lawsuits down the line, former footballer Michael Owen tried to hit back at "the critics" by announcing that "[his] NFTs will be the first ever …
Cashera was a project claiming to provide a "banking revolution" with its CSR crypto token. The project did many things to try to appear legitimate, including linking to government …
An attacker was able to steal 1,048 ETH (~$2.65 million) and 400,000 DAI from the Fortress Protocol borrowing and lending platform in what appears to have been an oracle …
Under the pretense of a contract upgrade, the Hunter defi project team drained the liquidity from the project, swapping the tokens for assets worth around $1.2 million. The team …
The Fury of the Fur NFT project was a collection of 3D models that sort of resembled bears. The project advertised that the models were "metaverse and game-ready", and the roadmap …
Coinbase is a big name in the crypto exchange world, enjoying the highest trading volume in the United States. The company decided to enter the NFT trading space, first releasing …
The token associated with the Day of Defeat project, which describes itself as a "radical social experiment token mathematically designed to give holders 10,000,000X PRICE …
Someone was able to gain control of a ferrari.com subdomain to create a scam NFT mint. Most scam NFT projects rely on eager NFT collectors not noticing a URL that isn't quite right …
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) announced that they had sanctioned the North Korean cryptocurrency tumbler Blender.io. This was the …
The OpenSea Discord server was compromised, allowing a scammer to post a seemingly-official announcement that OpenSea was partnering with YouTube on a line of NFTs. They urged …
Crypto scammers on YouTube rehosted a "live" panel discussion — actually from "The ₿ Word" conference in July 2021 — in which Elon Musk, Jack Dorsey, and Cathie Wood …
The Pragma defi project on the Fantom blockchain announced that their treasury and project wallets had been drained for around $1.5 million in $FTM.The rug pull appeared to have …
The Department of Justice unsealed an indictment on May 5, showing that Mining Capital Coin's CEO and founder Luiz Capuci Jr. was charged with orchestrating a $62 million …
A protracted discussion and two different votes ended with the Juno project deciding to confiscate all but 50,000 of the 3 million $JUNO accumulated by one individual. When the …
MM.Finance, a group of crypto projects based on the Cronos blockchain, suffered an attack that allowed a hacker to redirect more than $2 million worth of crypto assets that were …
a lotta yall still dont get itape holders can use multiple slurp juices on a single apeso if you have 1 astro ape and 3 slurp juices you can create 3 new apesTonight's slurp juice …
The Wall Street Journal reported that "the NFT market is collapsing", citing data from NonFungible that showed daily average sales of NFTs had dropped 92% from their September …
Video game company Square Enix, the creators of titles including Deus Ex and Tomb Raider, agreed to sell off the intellectual property rights to those games, as well as other games …
A press release from metaverse developer Sensorium announced a "VR and NFT gallery" that would host art and content for the Vatican. The project will allow VR, PC, and mobile …
Illinois Gastroenterology Group Data Breach Impacts 228K | TechTarget. Optima Dermatology, EvergreenHealth, and SAC Health also faced healthcare data breaches recently. Illinois …
Local Class Action Lawsuit Targets Partnership HealthPlan Over 'Massive Data Breach' of Personal Info. « While Conducting Aforementioned Drug Bust in Rio Dell, Drug Task Force …
Illuminate Education Mega-Breach Affects K-12 Students. New York state officials are investigating a data breach at Illuminate Education, maker of a widely used software platform …
Mangatoon data breach exposes data from 23 million accounts. Manga comic reading app Mangatoon has suffered a data breach that exposed the account information of 23 million users …
St. Luke's says customers hit with data breach that may have exposed personal, financial, medical information. St. Luke’s Health System issued a news release Wednesday saying an …
The Juno community has officially voted to confiscate over 2.95 million $JUNO owned by one whale who they believe gamed the airdrop to obtain more than his fair share. This follows …
The Wikimedia Foundation, the non-profit organization that owns and operates Wikipedia and related projects, announced that they would no longer accept donations in cryptocurrency. …
A hacker attacked multiple Rari liquidity pools relating to the Fei Protocol, exploiting a known re-entrancy vulnerability that exists on forks of the Compound protocol. The …
The much-awaited Bored Ape Yacht Club "Otherside" metaverse land sale began, and its popularity just about wrecked Ethereum for everyone else. Gas fees, which increase based on …
In what should surprise nobody, some of the historically phishing-prone fans of the pricey Bored Apes project fell for scams that pretended to be the Bored Apes' new land project, …
An exploiter used a flash loan attack to pull 3,933 ETH (~$11 million) from the "decentralized automated market maker" Saddle Finance. Shortly after the attack, the hacker began …
On April 30, NFT minting bots began flooding the Solana network with 4 million transactions per second, causing the network to lose consensus. The project tweeted that "Engineers …
A project to create Teenage Mutant Ninja Turtles NFTs stirred up a lot of excitement, garnering more than 100,000 Twitter followers on a verified Twitter account that described …
The defi project Deus Finance was hit with a flash loan attack that netted the hacker $13.4 million. The loss to the protocol was likely larger than what the hacker was able to …
The defi project Deus Finance was hit with a flash loan attack that netted the hacker $13.4 million. The loss to the protocol was likely larger than what the hacker was able to …
The SEC charged four individuals with fraud violations in relation to their actions with NASGO, a company that created various tokens that the SEC has since described as …
The Central African Republic became the second country to adopt Bitcoin as legal tender, after El Salvador did the same in September 2021. It's a strange move, in a country where …
Scammers created a project on OpenSea with Louis Vuitton branding, which invited individuals to visit an external site to mint exclusive NFTs. They placed a blue checkmark on the …
Financial services company Fidelity announced its intentions to allow people to put some of their retirement savings into Bitcoin in the near future, despite the Department of …
North Carolina Representative Madison Cawthorn was one of several influential people who helped to promote the "Let's Go Brandon" memecoin, which has since become the subject of a …
On 25 April 2022, Yuma Regional Medical Center (YRMC) — the primary regional hospital for southwestern Arizona serving Yuma, Arizona and surrounding areas — discovered a ransomware …
The Bored Ape Yacht Club's Instagram account was compromised and used to advertised a fake airdrop for metaverse land. This was particularly believable, as the much-anticipated …
Buy the $570 NFT and you'll get access to "celebrity doctors" who have amassed followings on apps like TikTok. Promising to "provide access quality doctors without all the usual …
Reggie Fowler, a businessman and former pro football player who worked for the Panama-based Crypto Capital Corp., pled guilty to various charges involving bank fraud, wire fraud, …
Sam Bankman-Fried, one of the most well-known crypto execs and the founder of the popular FTX crypto exchange, appeared for an interview on Bloomberg's Odd Lots podcast alongside …
Micah Johnson, an artist and former professional baseball player, launched an astronaut-themed NFT project called AkuDreams. The auction was based around a Dutch auction, with the …
Binance, the largest cryptocurrency exchange, shared customer data with the Russian government according to a Reuters special report. Reuters detailed how Binance provided the …
Bob Byrne and Tim Collins, two prolific contributors to the far-right Epoch Times, have expanded their grift to crypto. A twenty-page-long "newspaper" titled Wall Street Today …
Bob Byrne and Tim Collins, two prolific contributors to the far-right Epoch Times, have expanded their grift to crypto. A twenty-page-long "newspaper" titled Wall Street Today …
An attacker targeted the ZEED defi projects, successfully using a flash loan attack to pull just over $1 million from the project. With the funds transferred to the attack …
Binance, the world's largest crypto exchange, used Twitter's branded hashtag feature to add a custom emoji to Twitter when people use the hashtags #Binance or #BNB. The hashtag …
The Rogue Society NFT project launched in September, with an ambitious roadmap that included a theme song, comic book series, 3D figurines, an augmented reality app, and an …
Scammers ran Google ads for popular search queries relating to the Terra ecosystem. When users searched for things like "Anchor protocol" or "Astroport", the first result was …
The price of the $CHEDDA token suddenly plummeted 50% when a developer removed $1.17 million from the project. The withdrawal was accomplished with a function only available to …
NFT influencer 0x_fxnction reported that his wallet had been compromised, and 2349 SOL (~$240,000) had been stolen. The money had primarily been profit from the DeGods project, he …
Crypto sleuth zachxbt researched the Rich Bulls Club, an NFT project that launched in December with NFTs priced at 0.3 ETH (~$1,350) a pop. The project included a clause where …
Redemption provides the liquidity pools for 2omb, a Fantom-based algorithmic stablecoin project with big promises: "What if you could invest in a golden goose? Something you can …
A press release from Atari announced that the company would be cutting ties with ICICB Group. In addition to Atari granting ICICB hotel and casino licenses, the original deal had …
Some MetaMask users using iOS were shocked to discover that their MetaMask credentials were automatically being stored to iCloud today, after MetaMask acknowledged this was the …
Security researchers at Palisade publicly disclosed a wormable cross-site scripting (XSS) vulnerability and WAF bypass they had discovered and responsibly disclosed to Rarible …
Andre Cronje has graced the pages of W3IGG before, when he and his development partner Anton Nell unexpectedly announced they would be abandoning their 20+ defi projects, without …
All my magic beans gone. An attacker successfully used a flash loan attack to exploit a flaw in Beanstalk Farms' stablecoin protocol, which allowed them to make off with 24,830 ETH …
A pseudonymous co-founder of the NFT startup Gem, who was previously known only as "Neso", has been revealed to be Josh Thompson. Using the handles "Joshpriest" and "MethodJosh", …
The NFT project "Moonbirds" generated so much hype that they implemented a raffle system for the many people who hoped to get on the project's allowlist, hoping to make it more …
Rikkei Finance, which describes itself as a metaverse defi project, was apparently exploited. 2,571 BNB, priced at around $1.07 million, was transferred out of the protocol and …
Archie Comics announced they would be launching an NFT project called "Archieverse", which centers around their spooky "Madam Satan" character and invites people to "unlock the …
Monero is a privacycoin that attempts to address some of the privacy issues with more popular currencies (like Bitcoin or Ethereum) — namely, that anyone can see that wallet A sent …
Influencer, conservationist, and exotic animal whisperer "The Real Tarzann" (a.k.a. Mike Holston) announced in October 2021 his plans for an NFT project called "Tribes of Ogun". …
Unicorn Nodes claimed to be a "defi-as-a-service" project. It launched its $RNBW token on April 14, despite warnings from "TheBreadmaker", who rates various protocols. Only hours …
According to the FBI, the infamous cybercrime group Lazarus has been implicated in the March Axie Infinity exploit that saw $625 million taken from the game's blockchain bridge. …
The police in Richmond, British Columbia say they've received 22 reports of crypto fraud, which have included fake investment schemes, romance scams, or scammers impersonating …
For years now, Ethereum has been talking about a transition from its energy-intensive, expensive proof-of-work consensus model to a proof-of-stake consensus model, which sports a …
A scammer recreated the Twitter account for SkyVerse, a much-anticipated NFT land project due to launch in "mid-April". More than 250 NFT collectors eager to get in on a mint that …
After Jack Dorsey made an NFT out of his first-ever tweet, then-cryptocurrency executive Sina Estavi won the auction in March 2021 with a 1,630 ETH bid (then around $2.9 million). …
Securities Commissioner Travis J. Iles issued an emergency cease and desist order to stop "Sand Vegas Casino Club", a project that writes on its website "THE HOUSE ALWAYS WINS. And …
A group of shareholders have filed a class-action lawsuit against Coinbase, alleging that the registration and prospectus statements provided for the company's IPO were false and …
A person was able to use a flash loan attack to drain the Elephant Money project, crashing the token price to 0 while cashing out 27,416 BNB ($11 million). Losses to the project …
Celsius announced that, in order to comply with United States regulations, they would no longer allow non-accredited investors from the U.S. to "earn rewards on" (that is, lend) …
On April 11, Coinbase announced 50 new cryptocurrencies they were considering listing on their exchange. These announcements tend to increase the price of the tokens under …
"Don't make your dystopian books our reality, Pierce," a fan replied to sci-fi author Pierce Brown's announcement of an NFT project. Brown, the author of the bestselling Red Rising …
Wikipedia editors and other members of the Wikimedia communities completed a three-month-long discussion about whether the Wikimedia Foundation (WMF) should continue to accept …
NFT collector "Casper" discovered their wallet had been compromised, and an attacker had stolen around 114 NFTs worth around $600,000. The collector took to Twitter to urge people …
An attacker stole about $1.9 million after exploiting a bug in the smart contract for the Creat Future token. The contract's transfer function was defined as public, with no …
Ichi, a defi project that allows other projects to create their own stablecoins suffered cascading liquidations in its Rari pool, leading to a token price crash. Rari is a protocol …
A restaurateur opened "Bored & Hungry", a Bored Ape-themed restaurant in Long Beach, California that offers a simple menu of hamburgers or plant-based burgers (with or without …
A restaurateur opened "Bored & Hungry", a Bored Ape-themed restaurant in Long Beach, California that offers a simple menu of hamburgers or plant-based burgers (with or without …
Because, really, what is even the point of playing Dungeons & Dragons if you're not buying a premade character from a limited set of options, playing premade adventures with …
On April 8, 2022 — during Russia's full-scale military invasion of Ukraine — Sandworm (GRU Unit 74455) attempted to deploy an upgraded version of Industroyer malware (dubbed …
In April 2022, GitHub detected that an attacker had used stolen OAuth user tokens issued to third-party integrations — specifically Heroku Dashboard (OAuth app ID 145909) and …
Starstream, a defi project built on the Andromeda layer 2 Ethereum protocol, had its treasury drained. Blockchain security company CertiK reported that the treasury appeared to …
Attorney Kevin Homiak tweeted that his firm would be representing several individuals who contributed money to a developer, Tyler Gaye, who promised to be working on an NFT …
WonderHero is a mobile play-to-earn turn-based strategy game. Attackers were able to mint 80 million $WND after successfully exploiting the bridge linking the WonderHero …
It's not exactly straightforward to revoke wallet permissions once they've been granted, and so many users use a site called revoke.cash to remove permissions in the case of …
Star Trek announced the creation of "Star Trek Continuum", a part of Paramount's new NFT platform. They state that the project is "accessible to everyone [with $250 to throw …
Star Trek announced the creation of "Star Trek Continuum", a part of Paramount's new NFT platform. They state that the project is "accessible to everyone [with $250 to throw …
A third "stolen ape" lawsuit was filed against OpenSea, alleging that Opensea's "security vulnerability allowed an outside party to illegally enter through OpenSea's code and …
Ubisoft announced in December that they would be incorporating NFTs in to their Tom Clancy's Ghost Recon Breakpoint title, much to the chagrin of its players and some employees as …
AJ Vaynerchuk, brother of prominent NFT personality Gary Vaynerchuk (aka Gary Vee), launched his VaynerSports NFT collection. The popularity of the project resulted in surging gas …
New reporting from BuzzFeed News and MIT Technology Review described some of the issues that Worldcoin has been encountering on its mission to scan the eyeballs of the world …
Ubisoft announced in December that they would be incorporating NFTs in to their Tom Clancy's Ghost Recon Breakpoint title, much to the chagrin of its players and some employees as …
A Floridian suspected of selling hacked account information for services including HBO, Netflix, and Uber had $34 million in Bitcoin seized by federal authorities. Prosecutors …
A trader who owned a Bored Ape and two Mutant Ape NFTs apparently reached a deal to trade them for three different Bored Ape NFTs. Because OpenSea doesn't support swapping NFTs …
Reddit reopened its chaotic collaborative art project, r/place, for several days. Users could place colored pixels onto a shared canvas at limited intervals, collaborating to …
Robert W. Malone, a COVID-19 conspiracy theorist, gave a speech to a group of anti-vax truckers in which he announced plans to dox over 4,000 "[World Economic Forum] trainees" by …
The stablecoin belonging to the Waves protocol, "Neutrino dollar" (aka USDN), crashed nearly 20%, despite intending to maintain its 1:1 ratio to the US dollar. The volatility …
A Bitcoin holder using a Trezor hardware wallet fell victim to a phishing scam after attackers stole email lists from a third-party vendor use by Trezor. The user wrote on Reddit …
An attacker targeting the defi project Inverse Finance was able to manipulate the price oracle of INV/ETH, artificially inflating the apparent price of INV and allowing the …
An attacker targeting the defi project Inverse Finance was able to manipulate the price oracle of INV/ETH, artificially inflating the apparent price of INV and allowing the …
Local Marketing Automation & Brand Harmony | OneTouchPoint. Empower local teams with OneTouchPoint. Our OTP One platform ensures brand compliance while accelerating speed-to-market …
Dis-Chem says it won't share more info on data breach that hit 3.6m clients | News24. In April an “unauthorised person” accessed 3.6 million customers’ first names, surnames, email …
Cyber-Attackers Hit Sunwing Airlines. Thousands of passengers of Canadian low-cost airline face delays after third-party system was hacked. Thousands of passengers of Canadian …
An apparent scammer was able to create transactions that appeared as though they were coming from the smart contract belonging to the Bored Ape Yacht Club. OpenSea's UI doesn't …
Taiwanese singer Jay Chou fell victim to an apparent phishing scam, in which a malicious actor transferred his pricey Bored Ape NFT to their own wallet. The scammer then flipped …
A class-action lawsuit filed by Missouri investor Eric De Ford claims that the people behind the pro-Trump "Let's Go Brandon" (LGB) memecoin misled investors about a NASCAR …
Another day, another Discord compromise — or in this case, many Discord compromises. Bored Apes wrote on their Twitter account in the early hours of the morning, "STAY SAFE. Do not …
An up-and-coming defi lending project called Vires Finance, which was based on the Waves protocol, offered high returns of 30–70% APY on stablecoins placed in the project. As with …
The former head moderator of the Cosmic Cowgirls NFT project Discord, Esh, wrote on Twitter that that the project team had fired all moderators and scrapped all of their roadmaps. …
Nate Chastain resigned from OpenSea at their request in September 2021 after it was discovered that he had allegedly been buying NFTs based on insider knowledge that they would be …
Ola Finance is a lending protocol that allows others to create their own lending networks. It promises to allow users to create their own loan platforms where "assets can be listed …
One of the most popular play-to-earn games, Axie Infinity, suffered an enormous hack to the Ronin network on which it runs. The project announced that a majority of Ronin validator …
Many had written off the Bored Bunny NFT project (and its subsequent spin-off NFT collections) as a rug pull. After releasing several new NFT collections that appeared to be little …
In February, perennial political candidate Andrew Yang announced he had created "Lobby3", a DAO which he says will push for crypto-friendly regulation and "eradicate poverty". The …
NFT trader Calvin Chan recently made some unusual NFT trades. He sold his Bored Ape, which he had bought in August 2021 for 16 ETH (then about $50,000), for 115 DAI ($115 — DAI is …
NFT collector Cameron Moulène was excited to see a link promising a merch drop in the bio of an account with the same branding as Bored Ape Yacht Club, but with the handle …
MkLeo, who is widely considered to be the best Smash Ultimate player in the world, had his 217,000-follower Twitter account hacked and repurposed for NFT shilling. The scammers …
Collectors were excited for a chance to obtain NFTs from the artist Pak's upcoming collection, "Ash Chapter II: Metamorphosis". Pak is an extremely popular digital artist, and his …
The Revest protocol was targeted with an attack that stole $BLOCKS, $ECO, and $RENA tokens from their vault. The protocol wrote that the attacker used a "highly sophisticated …
A trader known by taylorRichie.eth agreed to swap their Morie NFT for a Doodle, in a trade they'd coordinated with a user on Discord. Because OpenSea doesn't support trading one …
Coinbase began sending out notices to its customers who reside in Canada, Singapore, and Japan, to tell them that in early April, they will need to begin inputting information …
In March 2022, MCG Health — a Hearst Health subsidiary providing evidence-based patient care guidelines and clinical decision support software to health plans and hospitals — …
New York Times reporter Ron Lieber began fact-checking a story in March about a deal between crypto tax software firm ZenLedger and the Internal Revenue Service. Lieber ran into …
According to Bloomberg, Exxon Mobil has begun a pilot program to set up Bitcoin miners at an oil well in North Dakota. The project reportedly runs off 18 million ft³ of …
On January 9, an ice cream-themed NFT project called "Frosties" made off with $1.1 million in a rug pull only an hour after the NFTs were launched. Less than three months later, …
The security firm PeckShield reported that the Pye ecosystem had been targeted with a flash loan attack, which drained around $2.6 million from the protocol. Pye is a group of defi …
After three roller derby stars announced an NFT project called "'Bout Time", the roller derby community was fairly united in its displeasure with the idea. Though the project …
Some scammers obtained hacked verified Twitter accounts, then rebranded them to claim to be founders of the Bored Ape Yacht Club. They then tweeted about how their team's ApeCoin …
In the latest installment of "large television program launders the reputations of NFTs", an "NFT band" performed on Ellen... Well, some animated characters danced on a screen …
Two lawsuits were filed nearly simultaneously, each alleging misconduct by the other party with respect to the "Caked Apes" NFT project — a project full of illustrations that were …
A hacker was able to exploit an infinite mint glitch in the protocol of Cashio, a Solana stablecoin project. They were able to pull around $50 million out of the platform, while …
On March 23, 2022, the Lazarus Group (North Korea, DPRK Bureau 121) stole 173,600 ETH and 25.5 million USDC ($625 million at the time) from the Ronin Network — the Ethereum …
The VeVe marketplace has developed a bit of a reputation as the partner of choice for some big names who have dipped their toes into "licensed digital collectible" NFTs, including …
G2 Esports announced a partnership with NFT provider Bondly in June 2021, through which they planned to release profile picture NFTs that would also provide access to membership …
A hacker was able to use a flash loan attack to exploit an issue with OneRing Finance. By manipulating the price of tokens in the project's liquidity pool, the hacker was able to …
Arthur_0x, a crypto investor and NFT whale, had two of their hot wallets compromised. The attacker stole ETH and transferred some big-ticket NFTs out of the wallets, including at …
An NFT collector fell for a scam website promising to "turn your BAYC animated". After connecting their wallet, the attacker transferred their three pricey Bored Ape NFTs to their …
NeoNexus was a metaverse NFT project that raised about 25,000 SOL (worth around $2.2 million today; previously worth $3.5 to $4.5 million). The project had sold various "property …
On March 20, 2022, LAPSUS$ posted a screenshot on Telegram showing they had access to Microsoft's internal Azure DevOps environment, including source code repositories for Bing, …
The Twitter account belonging to Nikki Fried, the current Florida Agriculture Commissioner and a Democratic candidate for the 2022 Florida gubernatorial race, was compromised and …
The Australian Competition & Consumer Commission (ACCC) announced that they had begun federal court proceedings against Facebook, alleging that the company "engaged in false, …
An NFT project's value is often discussed in terms of its floor price — that is, the lowest price at which any given NFT in a collection is listed for sale. The new NFT project …
The Bored Ape Yacht Club recently created a token called ApeCoin, some of which they announced would be distributed to people who owned various Bored Ape NFTs and NFTs from their …
Asa Saint Clair created an organization called the World Sports Alliance, which he falsely described to prospective investors as being closely affiliated with the United Nations …
After hackers successfully compromised the account of one of the Rare Bears Discord moderators, they posted an announcement that new NFTs were being minted. Those who tried to …
A week after LimeWire emerged from cryostasis to announce it would become an NFT platform, Winamp decided to jump in as well. Winamp was a Windows media player that first launched …
Bored Ape Yacht Club decided to release "ApeCoin", a new cryptocurrency token. The token distribution heavily favors current BAYC owners, truly underscoring the fantasy about a …
In June 2021, Binance announced they would stop operating in Ontario after the province introduced new prospectus and registration requirements for crypto exchanges. However, in …
Hackers were able to use a flash loan attack to manipulate a price oracle, pulling 200,000 DAI and 1101.8 ETH (totaling almost $3.1 million) out of the Deus Finance defi platform. …
An attacker using a flash loan attack targeted two projects on the Gnosis blockchain: Hundred Finance and Agave Finance. Each project paused their smart contracts, but not before …
Hackers were able to use a flash loan attack to manipulate a price oracle, pulling 200,000 DAI and 1101.8 ETH (totaling almost $3.1 million) out of the Deus Finance defi platform. …
A project called NFTBOOKS has cropped up, promising to "transform the world of book-readings" by creating an NFT economy of authors, book-lenders, readers, translators, and, of …
F1 Delta Time, a crypto car racing game that was officially licensed with F1 racing, shut down in mid-March. The game had previously generated a lot of hype — one of its car NFTs …
After an extended Polygon outage on March 10, Binance temporarily paused deposits and withdrawals via Polygon on March 15. Although Binance reported it was "due to the network wide …
Bitcoin wallet addresses look something like bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq, and so it's not always obvious at a glance if one string of random characters might have …
The Sol Invictus project was an Olympus DAO-like project on the Solana blockchain, much like the Wonderland project that went up in flames recently. Promising absolutely massive …
Wizard Pass is an NFT trading community and package of various software tools that can be joined for a price: a collection of 3,000 NFTs gates access to the community. The NFTs had …
A trader set very low limit order on Ripple's XRP token, and was delighted to see it executed with XRP very briefly plummeted in value in what's known as a flash crash. The price …
Matt Furie is the original creator of the Pepe the Frog cartoon that was later co-opted as an alt-right hate symbol, and which has also been popular among crypto enthusiasts and …
A Facebook profile impersonating an economist named David Rosenberg was discovered by Snopes to have drawn in around 3.4 Bitcoin in deposits, ostensibly from victims who were …
Believe me, I was as shocked as you were to discover that the MeUndies underwear brand has a "community". But that community apparently objected to the brand's purchase of a Bored …
All 81 functional Bitcoin ATMs in the United Kingdom are operating illegally, says the UK's Financial Conduct Authority (FCA). None of the companies operating them have a license …
Nothing really says "decentralized" like one company controlling the priciest and most popular NFT collections! Yuga Labs, the company behind the popular Bored Apes Yacht Club …
The large hedge fund Fir Tree Capital Management has decided that the doubts around the stablecoin Tether are serious enough to take out a substantial short position against the …
Off the Pitch reported on March 11 that Socios, the sports fan platform, had withheld payments owed to staff, advisors, and others who had signed agreements to endorse the …
ESPN MLB reporter Jeff Passan was having a great day, as he had been the one to break the news of an agreement between the MLB and the MLB Players Association, who had been …
The owner of EtherRock #44 tried to list their NFT for sale for 444 ETH (almost $1.2 million), but erroneously listed it for 444 wei — the fractional unit of ETH typically used for …
A blockchain protocol called Juno launched in October 2021, airdropping their $JUNO tokens to members of the Cosmos ecosystem in proportion to how many $ATOM tokens they held. The …
After a network upgrade, Polygon went offline for eleven hours while developers scrambled to diagnose and patch an issue preventing its validators from achieving the 2/3 consensus …
Yuga Labs, the company behind the Bored Ape Yacht Club (BAYC) project, announced a new project in partnership with blockchain gaming group Animoca Brands. The signup required KYC — …
John Terry, an English football coach and former player, launched an NFT project called "Ape Kids Football Club" on February 2. Several players, including Tammy Abraham, Ashley …
Something apparently went terribly wrong on the trading platform that Twitter user rifftrader was using (though they didn't say which) when 10 BTC (~$385,000) was erroneously …
An exploiter was able to use a bug in the Fantasm Mint contract to drain more than 1,000 ETH ($2,640,000) from Fantasm Finance. Fantasm urged their users to redeem their tokens …
The Pirate X Pirate blockchain gaming platform was exploited, with an attacker selling of more than 9.6 million $PXP. They were able to dump the tokens into the market for a profit …
LimeWire, the filesharing service that was enormously popular in the early 2000s for piracy, has been resuscitated — or at least the brand has. Needless to say they are probably …
Four individuals who owned and operated EmpowerCoin, ECoinPlus, and Jet-Coin were indicted on wire fraud, money laundering, and obstruction of justice charges. They allegedly …
John Barksdale, part of the sibling duo behind Ormeus Coin, was charged with conspiracy, securities fraud, and wire fraud for his role in selling the Ormeus Coin token. He …
Crypto.com sent out an unexpected email to some users, apparently primarily in the EU, announcing that "Lending is no longer supported in your jurisdiction... [and] we are required …
An NFT project called the August Sander 10K Collection launched on February 11, offering NFTs of all 10,700 photographs by German portrait and documentary photographer August …
Jake Paul, who is already in hot water after being named in the class-action lawsuit against SafeMoon, has now been implicated by YouTube detective CoffeeZilla in $2.2 million …
Andre Cronje and Anton Nell, the prolific developers of around 25 defi projects including yearn.fi and the new Solidly exchange, suddenly announced on Twitter that they would be …
Bacon Protocol, a defi project seeking to provide NFT mortgage liens (yes, really) was hacked. A reentrancy bug in their smart contract enabled attackers to get more lending …
The NFT project BattleCatsArena appears to have rug pulled on March 5, about three weeks after its launch. The project had been announced late last year, with a post from its …
Lapsus$ hacking group leaked 190GB of alleged Samsung source code and proprietary data in March 2022. Stolen data included: TrustZone trusted applet source code, biometric unlock …
NeosVR, a virtual reality project originally released in 2018, introduced "Neos Credits" (NCR) in 2018 with the idea that it could enable in-game transactions. The crypto component …
The entrepreneur and motivational speaker Tai Lopez, of "here in my garage, just bought this new Lamborghini" fame, announced a new NFT project. The NFTs feature staggering list …
Users based in Venezuela suddenly found themselves unable to use the enormously popular crypto wallet, MetaMask, on March 3. MetaMask relies on Infura, a popular API platform for …
A project called Nemus Earth has emerged, offering to sell you an Ethereum NFT to become a "Guardian" of the Brazilian Amazon rainforest. The project has lofty plans to create a …
After embracing cryptocurrency donations to help fund its resistance to Russian invasion, the Ukrainian government decided to try to solicit even more donations by announcing they …
Ukraine canceled its promised cryptocurrency token airdrop on the day it was expected to happen. Government officials had previously announced that anyone who donated by March 3 …
Iranian users were surprised to find that their OpenSea accounts had been deactivated with no warning. One Iranian user wrote, "NOT A gm AT ALL. Woke up to my opensea trading …
Conspiracy theorists Brian Rose and David Icke are together known for their April 7, 2020 interview where Icke attempted to draw unsubstantiated links between the rollout of 5G …
The Treasure NFT marketplace on Arbitrum (a layer 2 network built atop Ethereum) apparently experienced a bug that allowed someone to "buy" NFTs in transactions where they sent 0 …
Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …
Data breach at health care organization may affect 2 million people, including in Maine. Massachusetts-based Shields Health Care Group Inc. provides imaging and ambulatory surgical …
Data Breach Alert: DataHEALTH, Inc. | JD Supra. Recently, DataHEALTH, Inc. confirmed that certain consumer data was compromised as a result of the company being the target of a …
Highmark issues statement on ‘data security incident’ with vendor. [](https://circulation.timesleader.com/product/times-leader-e-edition/). Times Leader Wilkes-Barre, PA News, …
Report shows pandemic increased risk to Telco employee data. Third-party breach exposes data of Oklahoma's Department of Human Services clients. Third-party company: Liberty of …
Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …
Samsung data breach: Hackers steal data from microchip giant Nvidia. Samsung has confirmed that a hacking group which stole data from microchip giant Nvidia last week has also …
MCG Health Data Breach Impacts 8 Organizations, 793K Individuals | TechTarget. About 793,283 individuals and at least 8 organizations were impacted by a third-party data breach …
Third-party company: Sykes Enterprises.
In late February, the Lapsus$ ransomware group claimed to have breached Nvidia's corporate network and stolen more than a terabyte of data, which they say includes schematics and …
A developer offering his services on the freelancer marketplace Fiverr was hired by 32 different NFT projects, for which he wrote and deployed the smart contracts. The first …
You might think if Parler was going to create an NFT celebrating their hero, they wouldn't include along with their promotional material the example most reminiscent of Milo …
A group of 35 former employees of the startup incubator ConsenSys filed a request for an audit of a transfer of the company's "crown jewel" assets to a new company, which they say …
Elexir Finance promised a platform where users could build passive income via "yield bearing NFTs". They drew in more than $1.3 million in investments since the project's launch on …
Ukrainian Vice President Mykhailo Fedorov publicly requested major cryptocurrency exchanges to freeze addresses of all Russian and Belarusian users, to increase economic pressure …
GenomesDAO has created a platform which they promise will allow people who wish to sell their genetic data to have more control over it. They write that genetic data is "data that …
Robert Armijo is the former owner of three valuable NFTs — one Bored Ape and two Mutant Apes — which he bought for a total of around $300,000 between November 2021 and January …
Apparently hoping to create the "rallying cry for the women of web3", Randi Zuckerberg released her second crypto-themed song "WAGMI", a parody of Twisted Sister's "We're Not Gonna …
On February 26, the Ukrainian government tweeted Bitcoin and Ethereum addresses, allowing cryptocurrency donations directly to the government to support their resistance to the …
The enormously popular "Doodles" NFT project announced on February 26 that their Discord server had been "penetrated by a hacked bot", and that all messages should be ignored. They …
A heavily-hyped NFT project called "Howlerz" released its project via "secret mint" with no allowlist, and it went very, very poorly. Would-be buyers who were excitedly waiting for …
The Starcatchers NFT project sold NFTs which did not immediately show the image associated with them, but would instead be revealed at a later date. An observant collector noticed …
Cryptocurrency scammers have turned to the crisis in Ukraine to provide fodder for their scams. Some have taken the tactic of pretending to be a person trying to escape the country …
After the fiasco the previous day in which some group of people at the Associated Press apparently decided turning an image of human suffering into an NFT was a brilliant idea, …
BitConnect founder, Satish Kumbhani, founded the Bitconnect "investment program" in 2016, which attracted investors with its impossibly high payouts. From then until its dramatic …
The Guardian reported that five watercolor paintings created by former South African president Nelson Mandela depicting scenes from his years of incarceration will be sold as NFTs …
The Pixelmon project promised an ambitious roadmap including a Pokémon-like game where the pixelized Pokémon could be caught and traded, a land project, and rewards to buyers of …
The Associated Press announced they would be dropping a new NFT on the platform they launched in January, which notably doesn't allow users to sell their NFTs off-platform or …
Arther Hayes and Benjamin Delo, the founders of the BitMEX cryptocurrency exchange, pled guilty to violations of the Bank Secrecy Act, which they violated by ignoring requirements …
The 2022-2026 period fundamentally documented the integration of cyberattacks into modern armed conflicts as a standard component of military operations. Key documented cyber …
The popular Tom's Hardware and PC Gamer websites both ran articles about a utility called "Nvidia RTX LHR v2 Unlocker", which claimed to increase the artificially-limited …
On approximately 23 February 2022, the Lapsus$ extortion group compromised Nvidia's internal network and exfiltrated approximately 1 terabyte of data, including proprietary GPU …
On February 23, 2022, LAPSUS$ — a cybercriminal extortion group — gained access to NVIDIA's internal systems and exfiltrated approximately 1TB of data. NVIDIA was alerted to the …
Sacramento Kings player De'Aaron Fox announced his "SwipaTheFox" NFT project in mid-December, and the "high utility NFT collection" went live on January 15. The project roadmap …
Two weeks prior, collector 0x650d announced that they would be partnering with the Sotheby's auction house to auction a single lot of 104 CryptoPunks. CryptoPunks are some of the …
Space Crypto, a play-to-earn game that launched on February 15, announced on February 23 that users wouldn't be able to withdraw all their reward tokens, as expected. Without …
"The DAO", one of the first DAOs, was famously hacked in 2016, requiring a hard fork of the Ethereum blockchain to "undo" the breach. (So immutable!) Had Ethereum not forked, …
Ocean Protocol is a web3 project promising to help people "publish, discover, and consume data in a secure, privacy-preserving fashion". Recently, they've been promoting the ALGA …
Coinbase CEO Brian Armstrong embarked on a 12-tweet-long thread congratulating Coinbase employees for coming up with the bouncing QR code Super Bowl ad. He wrote, "I guess if there …
Atom Protocol, a project built on the Avalanche blockchain (and not to be confused with the Atom/Cosmos project on Binance), rug pulled within a day of launching. The developers …
Composable Finance is a company that makes infrastructure tools for defi. Until recently, their head of product has been known only as 0xbrainjar, and has operated pseudonymously. …
Indian authorities arrested at least eleven people accused of running a cryptocurrency scam that drew ₹40 crore (around $5.3 million) from investors. The alleged ringleader, Nishid …
Panic erupted on February 19 as a few users saw their wallets emptied of valuable NFTs without knowing why, and many others feared the same could happen to them. Early explanations …
Authorities performed nine separate raids targeting Generación Zoe, a holding company raising money from thousands of Argentines. The company promised 7.5% monthly returns at the …
An appeals court found that a legal claim could continue to be pursued against some of the major voices that promoted Bitconnect online. Bitconnect was a Ponzi scheme that …
Polly, a member of the popular Crypto.Chicks NFT team, apologized for "drawing inspiration from" artists and "inadvertently cop[ying]" their work, after it is discovered that she …
Kickstarter announced back in December that they planned to completely rebuild their product on a blockchain. It was quickly met with resistance from the community, including some …
Businessman Timothy McKimmy is the former owner of Bored Ape #3475, an NFT he purchased in December for 55 ETH (then about $232,000). In a lawsuit against OpenSea, McKimmy alleged …
Perennial political candidate Andrew Yang, perhaps in a desperate bid to stay relevant, announced his plans to create "Lobby3". Lobby3 is a DAO which he says will push for …
A class action suit was filed against SafeMoon, various executives, and a handful of influencers and celebrities who promoted the token. The plaintiffs allege that promotions …
The person known on Twitter by the name SHL0MS bought a used Lamborghini Huracan, drove it to the desert, and recorded the enormous fireball as they blew up the car. The explosion, …
Binance announced they had stopped "marketing to Israelis and all activities focused on Israel until we examine the issue of licensing." The "issue" in question seems to be that …
Chaosium, a maker of tabletop roleplaying games (TTRPGs; think games like Dungeons & Dragons) including the popular Call of Cthulu game, launched an NFT project in July 2021. …
An artist creating and selling trading cards of various streamers without asking their permission claims he was "just trying to do something cool for the community". He originally …
"Robness", an NFT artist who is somewhat known for selling a photograph of a trashcan for more than $250,000, apparently took issue with BuzzFeed News journalist Katie Notopoulos, …
Gary Vaynerchuk, an entrepreneur and now crypto/NFT personality, took to Twitter to express his frustration with some projects that airdrop their NFTs to big-name collectors and …
BNB42 was a "100% decentralized investment platform" that promised investors a 20% daily return on their investments. Unsurprisingly, that turned out to be too good to be true when …
More shadiness emerges around the Jacked Ape Club as it's discovered that the popular NFT influencer account Morgan (aka @helloimmorgan and morgan.eth) failed to disclose being …
In a Valentine's Day-themed stunt, the otherwise reputable Belvedere Museum in Austria decided to sell Gustav Klimt's The Kiss as NFTs. But making one NFT was apparently not enough …
A person managed to submit a proposal to the DAO that governs BuildFinance, a "decentralized venture builder", that would allow them to take over the project contract. The attacker …
The leaders of the Canadian anti-vaccine trucker protest communicated their plan to distribute the 21 Bitcoin (worth almost $1 million) to the truckers blockading the border. …
Left in place for posterity's sake, but the inimitible Katie Notopoulos has determined that this "app" was all a well-executed prank in the post-ironic world that is web3.The …
The team behind Jacked Ape Club, another NFT project featuring computer-generated apes, briefly erupted in chaos, shaking the confidence of many in the project. Several days prior, …
Much of the mining of the Monero privacycoin is done by a single mining pool named MineXMR. The total computing power being used to mine and process Monero transactions (also …
British tax authorities seized three NFTs in what they said was an attempt to dodge £1.4 million ($1.9M) in taxes. Officials stated that the seizure was a "warning to anyone who …
People were apparently tempted by Coinbase's Super Bowl ad — which was just a QR code bouncing around the screen like the DVD screensaver — so much so that it took the Coinbase …
thomasg.eth is the founder of Arrow, a DAO that is working to create "open-source VTOL [vertical take-off and landing] aircraft and air taxi protocol". In a long Twitter thread, he …
The Jacked Ape Club launched their public sale on February 10, offering 8,888 NFTs of illustrated apes much like the Bored Apes, but muscular. The following day they tweeted that, …
Lana Rhoades put her celebrity status behind the "CryptoSis" NFT project, which launched on January 22 and raised about $1.8 million. The project featured a detailed roadmap, …
Bloomberg reported that BlockFi is preparing to pay $100 million to settle allegations from the Securities and Exchange Commission (SEC) and state regulators that it provided a …
The "Runescape-like" MMO game known as TitanReach has had a bumpy history so far, first failing to reach its Kickstarter goal in a crowdfunding project launched in 2020, but …
Remember MoviePass, the completely unsustainable and shady business that allowed people to go see unlimited movies in theaters (until it didn't)? Well, it's back. This time they …
The "Runescape-like" MMO game known as TitanReach has had a bumpy history so far, first failing to reach its Kickstarter goal in a crowdfunding project launched in 2020, but …
The fledgling mtgDAO promised to deliver a "crypto NFT card economy" based around the Magic: The Gathering card game published by Wizards of the Coast. Needless to say, WotC sent …
A project called Squiggles generated an enormous amount of hype before its launch, with hundreds of thousands of members in its Discord and followers on Twitter. Just before the …
Atomic Wallet is a cryptocurrency wallet that claims to have more than 3 million downloads and advertises that "we provide users with the exceptional safety of their funds". …
The Baby Musk Coin memecoin launched in January, promising to "revolutionize the meme industry". The coin enjoyed a $2 million ICO the previous month, despite warnings from …
A protest in Canada against COVID-19 vaccine requirements for truckers re-entering the country, known as the "Freedom Convoy" has tried to crowdfund in several ways. A GoFundMe …
Hackers drained more than $10 million from the project Dego Finance. This also plunged the value of the project's $DEGO token by about 78%. Dego claims that the hackers compromised …
A mostly-dormant coal power plant near Seneca Lake in New York was converted to natural gas in 2017 and began devoting much of its power generation to mining Bitcoin in 2019. The …
Samsung launches a "sustainability-themed quest" on their "Samsung 837X" Decentraland metaverse project, where they invite characters to hunt for "recyclable product boxes", plant …
The BBC featured an article on their homepage about Hanad Hassan, "a 20-year-old who made millions trading cryptocurrency [who] is set to open a food bank to give back to his …
Brandon Smietana, the creator of the Skycoin cryptocurrency, filed a civil racketeering lawsuit on February 9 against a slew of people. He claims that the people hired to market …
The U.S. Department of Justice announced that they had arrested a New York couple and seized more than $3.6 billion in Bitcoin that they were allegedly trying to launder. The …
IRA Financial, a platform for managing retirement investments, boasts of being "the first self-directed IRA company to allow their clients to invest in cryptocurrencies, such as …
A vulnerability in the Superfluid crypto streaming protocol allowed an attacker to drain $8.7 million, affecting projects including Mai Finance, Stacker Ventures, Stake DAO, and …
The British Journal of Photography is a magazine and institution within the fine art and documentary photography world dating to 1854. In June 2021, they asked for investments, but …
In early February, Coinbase listed the Aventus token ($AVT) on its exchange and added support for Pawtocol ($UPI). Shortly before these announcements, someone created a new crypto …
EarnHub, a DeFi platform with its own rap song, suddenly saw 660 wBNB (around $284,000) disappear from their project. EarnHub wrote on Twitter that "A hacker was able to exploit …
The team behind LooksRare, an NFT platform known for its enormous proportion of wash trading, cashed out around 10,500 wETH worth around $30 million. They had earned the wETH by …
Following close on the heels of the disaster of an idea that was HitPiece, a new project called "NFT Music Stream" cropped up. Like HitPiece, the project appeared to be scraping …
The same week as bigoted tweets from an ENS director Brantly Millegan surfaced, so too did racist tweets by Ashni Christenson, then-community manager for the NFT platform …
On January 9, the team behind an NFT project called Doodled Dragons made off with $30,000 and wrote that the charity to which they'd promised to donate "will instead now be... my …
Cent, the NFT marketplace which sold Jack Dorsey's NFT of his first tweet for $2.9 million, stopped transactions on February 6. The founder explained that people selling NFTs of …
Mexican VTuber Zilverk created an NFT project called Ratz Club, built on the Solana blockchain. On February 6, the project announced that a developer they had contracted drained …
Players are not the only ones questioning Ubisoft's decisions to incorporate NFTs into their games (such as their newest Tom Clancy game), though Ubisoft has done little more than …
A report by the United Nations identified cyberattacks as an "important revenue source". At least three cryptocurrency exchanges were targeted by North Korean hackers, and a …
A bug in the Meter Passport smart contract allowed an attacker to pull 1400 ETH (~$4.2 million) and 2 wrapped Bitcoin (~$83,000) from the Meter Passport blockchain bridge. This was …
Brantly Millegan is the director of operations for the Ethereum Name Service, which is basically a blockchain version of DNS, and is also how some people get their wallet to show …
A prospective house-buyer wanted to pad their bank account to try to convince their bank to approve them for a mortgage. Their bank didn't consider Bitcoin holdings when evaluating …
A person using the TraderJoe DeFi platform to yield farm encountered issues when trying to "harvest" their rewards. They tweeted at the platform (@traderjoe_xyz) to get …
Brian Box Brown, an artist who had previously worked for the digital self-publishing platform Gumroad, tweeted that he was ramping up his original art sales because "my former …
Some sophisticated hackers managed a BGP hijack on the servers powering KakaoTalk, a marketing and customer service application used by the South Korean KLAYswap cryptocurrency …
Nike filed a lawsuit in New York federal court against StockX, an online reseller that decided to get in on NFTs in January. StockX started selling "NFTs tied to physical …
Miami mayor Francis Suarez eagerly hyped "MiamiCoin" ($MIA), a cryptocurrency created by a private company and not actually controlled by Miami. Suarez appeared on CoinDesk TV to …
The Wormhole Network is a blockchain bridge between Solana and various other blockchains, allowing assets to be traded across the different and not otherwise interoperable chains. …
On February 2, 2022, the Wormhole cross-chain bridge — which facilitates token transfers between Solana, Ethereum, and other blockchains — suffered a smart contract exploit …
In approximately February 2022, Australian Clinical Labs' Medlab Pathology subsidiary suffered a ransomware attack that exfiltrated approximately 223,000 patients' sensitive …
[](http://www.business-standard.com/article/international/hackers-hit-fortune-500-service-provider-data-of-over-500k-people-leaked-122020600340_1.html#). Home / World News / …
Recently, the Internet Society, a non-profit organization dedicated to keeping the internet open and secure, experienced an extensive third party The post 80,000+ ISOC Members …
Information for over 6,000 Memorial Hermann patients accessed in security breach. A contracted vendor with Memorial Hermann is looking into the security breach. Hackers could …
2 Vendor Hacking Incidents Affect Over 600,000 Individuals. Two recent hacking breaches affecting hundreds of thousands of individuals - one reported by a firm that provides …
OKC Police rape kit info exposed in data breach of DNA contractor. The DNA and personal information of past sexual assault victims were a part of a data breach by a contractor of …
Artist bayneko created and airdropped NFTs of microscope pictures of SARS-COV-2 (the virus that causes COVID-19) to all 96,186 users of Hic et Nunc (HEN) who hold at least one NFT. …
The industrial band Choke Chain tweeted, "Yo a bunch of industrial scene acts (including me) have NFTs for sale on the site hitpiece.com I did not put it online and I assume you …
Team17, the studio behind the many Worms games, announced their plans for "MetaWorms": NFTs based on the characters from the games. The announcement on January 31 apparently …
Paul Denino, also known as "Ice Poseidon", is a livestreamer, Internet personality, and cryptocurrency enthusiast. In July 2021 he launched Cxcoin, a forked project he said was …
NFT collecter "iloveponzi", aka Larry Lawliet, apparently authorized what he thought was a legitimate application to access his NFT wallet. Unfortunately for him, he had actually …
On January 31, a cryptocurrency project called Realux launched after fanfare from viral tweets and influencer YouTube videos. The project promised to make "real estate open to …
Voice actor Troy Baker faced some backlash in mid-January when he announced that he would be partnering with "voice NFT" project Voiceverse. His antagonistic tweet, that "You can …
The UK branch of the World Wildlife Fund (WWF) announced their upcoming "Tokens For Nature" NFT project, which is meant to support endangered species. The WWF was quick to tout …
Crypto trading and crypto casinos have presented a new challenge to those battling gambling addiction. There are options for problem gamblers who are struggling to stop gambling in …
With so many newcomers to cryptocurrencies this year, and the often complex tax situations cryptocurrency trading can create (assuming it's reported at all), some traders are …
As the NFT gold rush continues and people attempt to slap price tags on everything in sight, Omar Farooq detailed his plans to sell colors on the blockchain. He said he will then …
After a bug in their code allowed an attacker to make off with $80 million, Qubit immediately began trying to contact the exploiter and convince them to return the money. First …
The Wonderland protocol had a rough week, first experiencing massive losses in "cascading liquidations" and then the unmasking of the previously pseudonymous lead developer as …
After Paris Hilton and Jimmy Fallon engaged in a frankly bizarre discussion of their beloved Bored Apes on The Tonight Show, a fake projects imitating the Bored Ape Yacht Club …
The media went a bit nuts when Justin Bieber reportedly bought a Bored Ape (for several times what it was "worth", for some reason). This served to generate hype for several NFT …
A trader learned that, in order to exchange Ethereum tokens (ETH) for Wrapped Ethereum (WETH), they should send their ETH to the WETH token contract and receive the WETH in return. …
Khan Academy, an otherwise excellent non-profit offering online educational tools, announced they would be participating in an NFT charity auction on January 19. The auction …
Lazy Lion Ape Club, an NFT project in somewhat resembling the mega-popular Bored Apes, listed their NFTs on OpenSea on January 26. In addition to the NFTs, the project promised to …
LooksRare, a new NFT marketplace that launched on January 10, has boasted enormous trading volume since day one. It's no secret that wash trading — that is, a user "selling" an NFT …
OpenSea began reimbursing users who lost money earlier this month through what some have described as a bug with the platform, but which others argue is just a misunderstanding on …
On January 27, OpenSea announced a limit of five collections and 50 items per collection, after discovering that "over 80% of the items created with [their free minting tool] tool …
An attacker exploited a bug in Qubit Finance, a decentralized lending platform. The bug allowed them to call the "deposit" function without actually depositing any funds. This …
MetaMask acknowledged a week ago that they'd failed to address an IP leakage "issue has been widely known for a long time". The issue is present in many NFT marketplaces and …
Padawan DAO is a project that aims to provide funding to students under 25 to attend blockchain-related events. In early January, the DAO decided to essentially gamble with project …
Sifu, the pseudonymous chief developer of the Wonderland protocol, was revealed to be Michael Patryn, previously known as Omar Dahani. Patryn was a co-founder of the Canadian …
New Zealand auction house Webb's is selling the original glass plate negatives of two photographs taken of artist Charles Goldie sometime between 1910 and 1920. The sale also …
Melania Trump launched a new NFT in January, following her December unveiling of the series. The January NFT involved a white hat that Ms. Trump wore during a state visit, as well …
Mercenary was a short-lived play-to-earn game that promised "innovative tokenomics, to ensure the stability and longevity of the game's economy". The project had invested heavily …
WeGro, a project to allow "everyone to safely participate in the hemp and cannabis industry through the supply chain", saw its token tank in price as the deployer drained 1,000 BNB …
"Fan engagement blockchain platform" IQONIQ went into liquidation late January 2022, taking down its token sale platform and crashing the value of the fan-owned coin by over 90%. …
The "Let's Go Brandon" $LGB coin tied to NASCAR driver Brandon Brown, and created as an apparent way to support "the American dream" and stick it to Joe Biden (somehow), suddenly …
Blockverse, a project that promised to build a play-to-earn game on top of Minecraft, rug pulled two days after launch. The initial NFT collection sold out in only eight minutes, …
Julian Lennon maintains a private collection of Beatles memorabilia, including clothing worn by his late father John Lennon, and other items from other members of the band. He …
A project called "Meta Slave" launched, offering NFTs made from photographs of Black people (all apparently algorithmically-generated). Backlash was swift and intense, and the …
The broader decline in cryptocurrency prices triggered "cascading liquidations" in the Wonderland defi project, which is a fork of the "it might be a ponzi" OlympusDAO project. …
El Salvadoran president Nayib Bukele gives us Americans a painful reminder of having a president who truly cannot be trusted with the reins of a country, much less a Twitter …
A horrified (former) owner of a Bored Ape tweeted that his NFT had just unexpectedly sold for a measly 0.77 ETH (about $1,700) and that "I cant financially afford that loss". The …
The enormously popular Cryptopunks project, created by the LarvaLabs group, is actually on its second version. A bug in the original smart contract allowed users to retrieve their …
The Solana-based asset management protocol Solfire attracted users with its promises of over 500% APY. Partnerships and mentions from other prominent Solana projects helped the …
French surgeon Emmanuel Masmejean minted an NFT of an x-ray image of a bullet embedded in the fractured forearm of a person who was shot in the November 2015 Paris Bataclan …
Conservationist and wildlife photographer George Benjamin tweeted about his new project, "The NFT Conservation Fund". "Over the last decade I've seen first-hand the devastation …
An NFT group announced that they'd be releasing NFTs created from photographs of a 1991 Nirvana show they performed shortly before Nevermind rose to popularity. The NFTs go on sale …
Ozzy Osbourne's NFT project, CryptoBatz, changed to a slightly different Discord URL ("cryptobatz" rather than "cryptobatznft") some time after the new year. However, they forgot …
Solana was so overloaded with bot transactions that users couldn't transact. As the cryptocurrency market in general continued to tank, users rushed to top up the collateral they …
Popular NFT marketplace OpenSea suffered an outage that had ripple effects throughout several major services using their APIs, including the browser extension crypto wallet …
Shortly after rolling out their hexagonal NFT profile pictures, @twitter posted "gm, looking for an nft pfp". The next day, McDonald's German language communications account, …
Security researchers publicly disclosed a critical privacy vulnerability with the popular cryptocurrency wallet Metamask, where a malicious attacker can easily create an NFT and …
Although NFTs-as-profile-pictures on Twitter is nothing new, Twitter launched a new feature in which users can connect their crypto wallets to verify that an NFT belongs to them. …
Multichain publicly announced a vulnerability that was affecting their tokens, without first notifying users to ask them to remove vulnerable funds. Several hackers quickly …
Kingfund Finance suddenly drained more than 300 WBNB (about $141,000) from their project. This happened a few days after users began to report being blocked by the project's …
On 18 January 2022, the International Committee of the Red Cross (ICRC) discovered a cyberattack on servers hosted by a contractor in Switzerland that stored data for its Restoring …
The BNB Heroes play-to-earn game apparently rug pulled after a period of inactivity from the development team. The developer drained almost $200,000 from the token pool, plummeting …
Apparently the real issue with crypto grifts all along has been that it's just too dang hard to put your money into them. Mastercard has shown up to fix that, announcing a new …
Popular cryptocurrency wallet provider and trading platform Crypto.com briefly suspended trading after acknowledging there had been "unauthorized activity" in user accounts. The …
Mason Rothschild, the creator of "MetaBirkins" NFTs, was the target of a trademark lawsuit by Birkin bag-maker Hermès. The lawsuit came after he ignored a cease and desist from the …
Lapsus$ accessed Okta's network via compromised Sitel/Sykes contractor support workstation starting Jan 16 2022. Attacker used RDP lateral movement, accessed …
The value of the $BURG token associated with the CryptoBurgers game suddenly plummeted after being hacked shortly after launching earlier that day. The game allowed users to earn …
Enthusiasts rushed to buy NFTs from a project called NotASecretNFT after seeing NFT mega-whale Pranksy buy in, even though the OpenSea description was simply, "1000 secrets, …
Somehow, SpiceDAO managed to raise €2.66 million (about $3 million) to buy the storyboard for Alejandro Jodorowsky's never-made Dune adaptation. In a celebratory tweet the group …
Shortly after it was discovered that the images used for the NFT project "InvertedCulture" were nothing more than unauthorized flipped copies from a different NFT project, DNA …
Eight people were arrested in China after being connected to a rug pull. One investor lost ¥590,000 ($90,000) he had poured into the token in June, when project owners took the …
Lack of liquidity in the Uniswap V3 FLOAT/USDC oracle allowed an attacker to manipulate the prices within the pool, then deposit it at a much higher rate. The hacker pulled about …
Troy Baker, the voice actor behind video game characters in The Last of Us, Far Cry, and various Batman games, announced he would be partnering with "voice NFT" company Voiceverse. …
fees.wtf, a platform allowing people to see how much money a given cryptocurrency wallet has spent in gas fees, decided it was time to release their own token, and promised to …
Global Game Jam, an annual event where people collaborate to make video games, proudly plugged The Sandbox as their "primary headline sponsor" on Twitter. The Sandbox is a platform …
The creators of "Big Daddy Ape Club" rug pulled shortly after mint, deleting their social media and website and making off with around $1.2 million. The project's creators were …
I can safely describe most NFT marketplaces as bizarre, but the AP is really trying to top the bunch. The marketplace will provide a place for trading the NFTs they plan to create …
Crypto investors who bought 40 acres of land in Wyoming in hopes of "building a city on the Ethereum blockchain" lost more than $92,000 to a Discord hack. Some clever social …
Animoca Brands' subsidiary Lympo, an NFT platform specifically for sports, experienced a breach of several hot wallets. This allowed an attacker to pull 165.2 LMT tokens from the …
A SolSea-verified NFT project on the Solana blockchain, Doodled Dragons, touted that they would distribute all profits "straight to charities protecting animals on the brink of …
An hour after releasing their ice cream-themed NFTs, developers of the Frosties NFT project closed their social media accounts and disappeared with $1.1 million, plunging the token …
The Rich Dwarves Tribe was an NFT project announced in December 2021, which minted in January 2022. The project had been heavily promoted by musicians including NeYo, Jason Derulo, …
The Liechtenstein-based cryptocurrency exchange LCX suffered a $6.8 million loss when one of its hot wallets was compromised. Assets including ETH, USDC, EURe, and LCX were moved …
Gary Vaynerchuk announced plans for his New York City "NFT restaurant", Flyfish Club. The cheapest NFT, giving access to only parts of the restaurant, was listed at 2.5 ETH (at the …
Users reported not being able to withdraw currency from their accounts with Coinsuper, a Hong Kong-based crypto exchange. Although trading has remained active on the platform to …
An investor filed a class action lawsuit against Kim Kardashian, Floyd Mayweather, and Paul Pierce, all of whom promoted the EthereumMax currency (not to be confused with the …
The SEC alleged that Craig Sproule, founder of companies CrowdMachine and Metavine, ran a fraudulent and unregistered ICO when he launched "Crowd Machine Compute Tokens" (CMCTs). …
Someone on the Mozilla Foundation's social team inexplicably thought that tweeting "Dabble in @dogecoin? HODLing some #Bitcoin & #Ethereum? We're using @BitPay to …
Fuel shortages and spiking electricity costs in Kazakhstan have contributed to protests and a governmental crisis in the country. The electricity issue is partially thanks to …
Pudgy Penguins, a popular NFT project that somehow warranted a full-length New York Times article by Kevin Roose, apparently is trying something pretty shady. This was revealed by …
Artist Aja Trier was shocked to discover that her artwork depicting dogs painted in the style of Van Gogh's Starry Night has been stolen and turned into an NFT collection with …
Stephanie Matto, who starred on season 6 of the reality show 90 Day Fiancé, has turned to some weird moneymaking schemes following her TV career. For a time, she claims she was …
NFT collector and influencer Franklin posted a tweet thread about how he had hyped a project that later rugpulled. He was paid about 18 ETH (about $63,000) to promote the …
Energy shortages and rolling blackouts plagued Kosovo towards the end of 2021, leading the Kosovan government to issue a 60-day state of emergency to address the crisis. The …
Yield farming platform ArbixFinance was drained of at least $10 million, with some reporting amounts up to $32 million. Some optimistic users hoped it was a glitch, but the fact …
Although Polymarket was nominally "decentralized", it wasn't so decentralized that the CFTC couldn't fine its New York-based parent company for operating an unregistered market and …
Sunflower Farm, a play-to-earn farming game on the Polygon network, contributed to massive slowdowns and a spike in gas fees on the Polygon blockchain. Heavy bot usage and a game …
If trying to type in the name of a movie on Netflix with a TV remote isn't painful enough for them, now people will be able to try using their TV to do due diligence into whether …
"Fortune favors the brave", said Matt Damon as he walked past images of mountain climbers, the Wright brothers, and astronauts. "History is filled with 'almosts'. With those who …
Tinyman, a defi platform that bills itself as "decentralized, secure trading", had all liquidity drained from its goBTC and goETH pools after an attacker found a bug in their smart …
A vulnerability in Twitter's account authentication system, introduced in a June 2021 code change, allowed any caller of Twitter's `id.twitter.com` API to submit a phone number or …
In November 2022, a threat actor using the alias 'Ryushi' posted a dataset of 487 million WhatsApp user phone numbers for sale on the Breached hacking forum, claiming it was …
In January-February 2022, Avamere Health Services — a Wilsonville, Oregon-based managed services provider for senior living, skilled nursing, and rehabilitation facilities — …
In January 2022, Ciox Health — a major provider of health information management (HIM) services including medi cal record retrieval, release-of-information (ROI), and coding …
Family Medicine Practice Notifies Patients of Data Breach 1 Year Later | TechTarget. Netgain discovered the data breach in late 2020, but a Minnesota family medicine practice …
Page not found - Infinity Rehab. [](https://www.facebook.com/InfinityRehabCommunity "Facebook")[](https://twitter.com/infinityrehab "X")[](https://www.instagram.com/infinityrehab/ …
South Australian gov issues breach notice to hacked payroll provider. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us …
In early 2022, SafetyDetectives researchers discovered a publicly accessible Amazon S3 bucket belonging to Pegasus Airlines — a major Turkish airline with approximately 74 million …
Football Australia, the governing body for association football (soccer) in Australia, suffered a data breach when AWS IAM credentials were exposed in a misconfigured Amazon S3 …
A Vietnamese play-to-earn game called CryptoBike became popular shortly after its December 25 launch, soaring to around $41.6 million in daily trading volume. However, on January …
Digiconomist released numbers for 2021, showing that during 2021, Bitcoin consumed 134 TWh in total — comparable to the energy consumption of Argentina. The report also claims that …
Carson Turner accused ACYCapital of "exploiting @BoredApeYC through a glitch in @rarible" after they bought his Bored Ape NFT that he had listed for sale (and which he has …
In the announcement, Square Enix CEO Yosuke Matsuda apparently wrote with a straight face: "I realize that some people who 'play to have fun' and who currently form the majority of …
Shortly after midnight on January 1, Tether added another $1 billion to its total supply. Although Tether claims that all of its supply is fully backed by actual currency, many …
A token called $YEAR invited people to connect their crypto wallets and see a "year in review"-style summary of their 2021 crypto and NFT transactions, with an airdropped token …
Todd Kramer, an NFT collector who had acquired Bored Ape and other pricey NFTs, clicked on a phishing contract that appeared to be a legitimate NFT trader link. Sixteen NFTs from …
A clone of Solana's popular "Baby Ape Social Club" project popped up on OpenSea, using the Polygon blockchain. The project enjoyed 14.3 ETH in trading volume (about $52,000) before …
Scammers took advantage of rumors that MetaMask, a popular Ethereum wallet, would be airdropping governance tokens. The scammers created a fake MetaMask token, $MASK, and managed …
Waka Flocka Flame posted to Twitter: "@opensea One of me wallets was hacked wtf man". In a video, he showed NFTs in his OpenSea wallet, saying "This is fake, this is fake, this is …
Board chairman of Energo-Pro Georgia, an energy company serving the Svaneti region of Georgia, wrote, "This can no longer continue. No network can withstand the electricity …
Founders say they aim to help the LGBTQ+ community with a Spanish cryptocurrency project, "Maricoin". The team plans for the currency to be used for payment in a network of …
A project that promised to be "the DAO of DAOs" managed to accumulate and then make off with 800 ETH, which was worth around $3.2 million at the time of the scam. The project …
1,100 BNB, or around $600,000, were transferred out of the MetaSwap token MGAS, dropping the price of the token nearly 50%. The funds went to a Tornado Cash account, a popular …
The "Cipher Punks" NFT project tried to sell NFTs with illustrations of various cypherpunks, or at least the ones that were listed on Wikipedia. The project said that it intended …
bergpay.eth checked his MetaMask wallet on the day after Christmas only to discover that all his NFTs had been stolen, including five from the popular "Jungle Freaks" collection …
A group called "BlockbusterDAO" emerged, with the stated goal of "liberat[ing] Blockbuster and form[ing] a DAO to collectively govern the brand as we turn Blockbuster into the …
On Christmas, Elon Musk tweeted a very cute photograph of his pet dog, Floki, wearing a Santa suit with the caption "Floki Santa". Creators of a memecoin called "Santa Floki" …
A scammer created a public poll on Mirror's official website, proposing to "Freeze the community pool in case of scam". However, if the poll passed, it would send 25 MIR to the …
An NFT collector lost his Bored Ape NFT to a scammer impersonating the well-known NFT collector Jeffrey Huang, aka "Machi Big Brother". The real Huang did eventually buy the NFT …
Around the holidays, Steve Bannon started touting a "Fuck Joe Biden" ($FJB) coin (formerly known as the "Let's Go Brandon" coin, and not to be confused with the other Let's Go …
Some prominent open source advocates and contributors were surprised to find that their likenesses were turned into NFTs by an artist who photographed them in 2018. Kris Nóva …
Because apparently the vinyl figurines known as Funko Pops aren't a sufficiently useless collectible, Funko decided to get in on the NFT craze by releasing a Bob Ross "Digital …
Another Discord scam netted its perpetrators around 800 SOL, or about $150,000, from 373 individuals. The scammer posted a fake minting link in the official Discord of Fractal, the …
An NFT trader hoping to get in on the "Monkey Kingdom" NFT collection was duped by a scam link in the project's official Discord channel, and sent 650 SOL (about $116,000) to a …
A reentrancy exploit in the Ethereum-based Visor Finance DeFi protocol allowed hackers to pull 8.8 million VISR tokens out of the network, equivalent to about $8.2 million. The …
Bent Finance informed its users of a "possible exploit", but soon after issued a statement that the exploit had originated from the Bent Finance project's own deployer. Because of …
A Twitter thread showed dozens of people reporting amounts from hundreds to tens of thousands of dollars disappearing from their Chivo Wallets, the Bitcoin wallet backed by El …
Grim Finance, the "compounding yield optimizer" DeFi platform, was hacked. According to them, attackers exploited a bug in the platform to perform a reentrancy attack that netted …
Anticipating that buyers would try to hoard items from a big-name NFT drop, Adidas decided to try to limit their NFT drop to two per buyer. They apparently didn't realize that …
Artists going through the greuling process of reporting individual NFTs created without permission from their work reported tickets being automatically rejected. Artists were also …
Comics artist Liam Sharp wrote on Twitter that he would likely need to close his DeviantArt gallery, which he has maintained for fourteen years, because his artwork keeps being …
The apparent owner of Bored Ape #5262, of which this site header is a derivative work, contacted me on Twitter to say "I believe you are using my ape on your website without my …
Lest it be mistaken for a grift, the press release was quick to say that Mrs. Trump had promised to donate a portion of the proceeds to children leaving foster care. The NFT …
Pushback from fans led S.T.A.L.K.E.R. 2 creators to quickly reverse their decision to add NFTs to the game. The studio announced their NFT plans on December 15, which involved …
Pushback from fans led S.T.A.L.K.E.R. 2 creators to quickly reverse their decision to add NFTs to the game. The studio announced their NFT plans on December 15, which involved …
Crypto miner Jaxson Davidson posted a video showing one of four buildings in his crypto mining farm, showing racks of thousands of GPUs — GPUs that gamers and other consumer buyers …
A misplaced decimal point caused an NFT trader to sell their "beloved" Doodle NFT for 0.37 ETH (about $1,500) instead of their intended 3.7 ETH (about $15,000). The trader tried …
A hacker gained access to someone's Amazon Web Services account and used it to spin up servers to run Monero miners, ultimately netting 6 Monero (XMR) worth a total of about $800 …
Laurent Correia, a French influencer and the creator of "Billionaire Tips" sports betting app, launched an NFT project called "Billionaire Dogs" in December. Promising perks …
Stan Lee fans were outraged when the Twitter account belonging to Lee, who died in 2018, posted a message to promote an upcoming NFT based on one of his characters. Fans fairly …
Some people were briefly elated or devastated when they looked at Coinbase or CoinMarketCap, both major cryptocurrency trackers. A glitch caused some cryptocurrency investments to …
Stolen private keys from the blockchain gaming platform Vulcan Forged enabled attackers to siphon funds out of just shy of 100 user wallets. Rather than users managing their own …
An NFT trader made a typing error when entering a listing price, accidentally listing his Bored Ape NFT for 0.75 ETH (about $3,000) instead of 75 ETH (about $300,000). The NFT was …
Someone released a collection of poorly-made pixel art NFTs depicting the late George Floyd, whose murder by a police officer in May 2020 set off protests around the world. There …
Digital artist Loish discovered more than one hundred instances where people had created NFTs from her art without her permission, and had to spend hours reporting each individual …
The Seattle Kraken announced that they would be releasing a set of NFTs. Although several sports groups have released NFTs, people were particularly surprised to see it coming from …
Ransomware struck UKG's (Ultimate Kronos Group) Kronos Private Cloud on December 11 2021, taking down workforce management and payroll processing systems used by thousands of large …
On 11 December 2021, UKG (Ultimate Kronos Group) — one of the world's largest workforce management software providers serving over 40 million people across 57,000 organisations …
Ascendex lost $77 million in a hack targeting hot wallets. The platform said it would reimburse customers for all of their lost funds. Total loss estimated at $77,000,000.
McDonalds tried to make a splash with a McRib-themed NFT project, but that was quickly outshined by the discovery that an early transaction to the Ethereum address associated with …
Peter Molyneux announced a new game, Legacy, a business management simulator (fun!) where you join by buying an NFT called "Land", and compete to increase your "LegacyCoin" bank …
In December 2021, a former employee of Cash App Investing — a subsidiary of Block, Inc. (formerly Square) — downloaded CSV reports containing brokerage account data for 8.2 million …
During a widespread AWS outage, supposedly-decentralized DeFi platform dYdX went down. dYdX is an Ethereum exchange that touts itself as the "world's leading decentralized …
Kickstarter announced they have decided to create a decentralized version of their platform, and to create it on the Celo blockchain. This was not entirely well-received, and some …
Ubisoft announced that it would be adding NFTs to its Tom Clancy's Ghost Recon Breakpoint title, allowing players to buy "Digits": artificially scarce in-game weapons, vehicles, …
Ubisoft announced that it would be adding NFTs to its Tom Clancy's Ghost Recon Breakpoint title, allowing players to buy "Digits": artificially scarce in-game weapons, vehicles, …
A compromised private key allowed an attacker to remove all funds from 8ight Finance's treasury, amounting to about $1.75 million. The team admitted to sending the key through …
WildWorks, a game company with a reputation for eco-friendliness, angered many of its fans when it announced it would be reusing the technology and assets from its …
Thurman began an article by writing, "Yes, it's a Ponzi scheme. But who cares? So are the dollars in your pocket." He was writing about OlympusDAO, a "decentralized finance (DeFi) …
Thurman began an article by writing, "Yes, it's a Ponzi scheme. But who cares? So are the dollars in your pocket." He was writing about OlympusDAO, a "decentralized finance (DeFi) …
On 4 December 2021, Eye Care Leaders — a provider of EHR and practice management software specifically designed for ophthalmology practices — suffered a ransomware attack that …
BitMart, "the most trusted cryptocurrency trading platform", experienced a major breach in which attackers stole approximately $200 million of various cryptocurrencies. The CEO …
Polygon lost a bit over $2 million after a hacker exploited a bug involving a lack of balance/allowance check in their MRC20 contract. Polygon had been in the process of releasing …
On December 4, 2021, security firm PeckShield identified large unauthorized outflows from BitMart's hot wallets totaling approximately $196 million — approximately $100 million …
Tether minted more than $3 billion in a two week span. This brings the total amount of USDT (which is pegged to the U.S. dollar) to 76 billion, and much of it was minted this year. …
Wales announced he would be auctioning an NFT of a website representing the first edit to Wikipedia. This was not taken well by some in the Wikimedia communities — some felt he was …
A platform called "CODEX" announced that they intend to "upgrade the digital book market industry to Web3". This, apparently, involves artificially limiting the number of copies of …
The SEC charged Latvian citizen Ivars Auzins with investment schemes he created using fake names and businesses. He allegedly created a fraudulent ICO for a coin that would back …
Lincoln College, a historically Black liberal arts college in Lincoln, Illinois, founded in 1865 (the same year Abraham Lincoln was assassinated), announced in May 2022 that it …
A hacker was able to use a compromised Cloudflare API key to inject malicious code into the BadgerDAO platform via Cloudflare Workers. They then siphoned currency of various kinds, …
In December 2021, a threat actor exploited a Twitter API vulnerability that allowed them to query any phone number or email address and receive the corresponding Twitter account …
Critical CVSS 10.0 RCE vulnerability in Apache Log4j 2 logging library. Publicly disclosed Dec 9 2021; patch released same day (2.15.0). Nation-state actors from China, Iran, North …
Although friesframe had transferred some of his valuable NFTs to cold storage (a crypto wallet not connected to the Internet), he had been waiting for gas fees to come down before …
A hacker stole $31 million from the liquidity pool provider MonoX by exploiting a bug in their smart contract software that allowed them to exchange a token for itself and …
Developers launched a memecoin called "Unvaxxed Sperm", hoping to make a buck while also recruiting for their anti-vaccine group. The name is based on the belief that in the …
SnowdogDAO creators say they didn't rugpull, but that the coin plummeting over 90% was a "game-theory experiment" that went wrong. The project was intended to only last for eight …
Dedric Reid has repeatedly stolen art and promotional material, passing off other projects' work as his own, to promote his "MetaWorld" project — a concept he's been promising (and …
The SEC filed charges against Ryan Ginster related to two online platforms that he ran, MyMicroProfits.com and Social Profitmatic. He promised investors what the SEC described as …
The U.S. Senate Committee on Banking, Housing, and Urban sent letters to various stablecoin operators including Tether, Coinbase, and Binance, asking for more details on how the …
An art curator created NFTs from photographs of Stormtrooper helmet artwork, but failed to actually ask permission from the artists. The NFTs sold for a collective $7.5 million …
Because Wolf Game put their entire source code into the blockchain, they were unable to patch an exploit once it was discovered. They had to completely recreate the game, reissuing …
Because Wolf Game put their entire source code into the blockchain, they were unable to patch an exploit once it was discovered. They had to completely recreate the game, reissuing …
ConstitutionDAO emerged out of a Twitter joke, but ultimately raised more than $40 million to bid on an auction for a rare first printing of the U.S. Constitution. After being …
In an apparent "fuck you" to members of the furry community who have been critical of NFTs, and to those who have pointed out that you can right-click and save files that people …
BadgerDAO, a DeFi protocol allowing users to earn yield on Bitcoin via Ethereum-based vaults, suffered a frontend supply chain attack beginning approximately November 10, 2021, …
On 19 January 2022, the International Committee of the Red Cross (ICRC) disclosed a sophisticated cyberattack that compromised personal data on more than 515,000 highly vulnerable …
Signs unfortunately point to this being an actual, real project rather than satire, but the video purporting to advertise it dunks on cryptobros harder than most satirists have …
Chinese police arrested 31 people for allegedly running a Ponzi scheme, in connection to sales of mining equipment for the filestorage crypto project Filecoin. The individuals were …
An attacker fooled a developer of the bZx decentralized finance platform into opening a Word document with a malicious macro, which ran a script that gave the attackers access to …
PR Newswire republished a fake press release which claimed that the Kroger supermarket chain would begin accepting "Bitcoin Cash" (not to be confused with Bitcoin) at its outlets. …
On November 3, 2021, an attacker called Robinhood's customer support line and socially engineered a customer support employee into granting them unauthorized access to the customer …
Blockchain Global, the parent company of a cryptocurrency exchange called ACX.io, entered voluntary administration after its protracted collapse. Customers had been unable to …
By manipulating the price of a low-liquidity, beta-stage stablecoin, an attacker was able to borrow all tokens in a Rari Fuse pool using the initial token as (inflated) collateral. …
The decentralized exchange BXH was exploited for $139 million. BXH CEO Neo Wang attributed the exploit to a compromised administrator key, which he said suggested either a staff …
320K Impacted in EHR Vendor Breach, Ransomware Hits Health Systems | TechTarget. Unauthorized email access and ransomware disrupted the operations of other health systems, while nn …
In early 2022, Uber disclosed that data for approximately 820,000 Uber Eats delivery driver accounts had been exposed through a third-party vendor that provided marketing services …
Creators of a Squid Game-themed token (not affiliated with, or authorized by, those behind the Netflix series) created a token which quickly skyrocketed in value and earned news …
Creators of a Squid Game-themed token (not affiliated with, or authorized by, those behind the Netflix series) created a token which quickly skyrocketed in value and earned news …
NFT collector Calvin Becerra fell for some social engineering on Discord: "Guys posing as buyers in Discord were helping me troubleshoot a problem we thought was happening... They …
In a twist absolutely no one could have predicted, the developer of a coin called "Monkey Jizz" ran off with around $270,000. The project promised to share a portion of …
A project called AnubisDAO launched a coin called ANKH, and were quickly flooded with cash from investors hoping to find another dog-themed memecoin success like Dogecoin or Shiba …
Miss Universe and its models, the @nft Instagram, and Steve Harvey all got in on the advertisements for the Miss Universe NFT project, which Miss Universe presenter Paula Shugart …
Bug bounty hunters helped OpenSea patch a cross-site scripting (XSS) vulnerability in their platform that previously allowed attackers to create an NFT from an SVG image, which …
$100,000 to charity, governance power over the project funds, a boxing game, and weekly competitions and raffles were all promised as a part of the Tekashi 6ix9ine-backed Trollz …
Crypto lending service C.R.E.A.M. Finance lost $130 million in a flash loan attack. It was the third hack of the platform this year, following a $37.5 million hack in February and …
Crypto lending service C.R.E.A.M. Finance lost $130 million in a flash loan attack. It was the third hack of the platform this year, following a $37.5 million hack in February and …
On October 27, 2021, Cream Finance suffered its third exploit of the year (previous hacks in February 2021 for $37.5M and August 2021 for $18.8M). This third attack was the …
Tech startup "Ryval", which is formally launching in 2022, announced its plans to allow "everyday Americans" to bet on the outcomes of civil lawsuits, potentially raising funds for …
On 22 October 2021, the npm account of Faisal Salman, maintainer of the popular ua-parser-js package, was compromised. The attacker published malicious versions 0.7.29, 0.8.0, and …
Six popular young-adult fiction writers attempted to launch an NFT project where they created a base universe, and participants would contribute their own stories (which they would …
A 17-year-old hacker was able to use a phishing webhook to make himself an admin in the CreatureToadz Discord server. Users who minted NFTs unknowingly sent cash to him, netting …
A hacker drained $16 million from Indexed Finance, a defi protocol built on the Ethereum blockchain. The stolen funds represented nearly half of the total value locked on the …
On October 11, 2021, Cox Communications discovered that a hacker had impersonated a Cox support agent to gain access to internal systems, then accessed a small number of customer …
On 6 October 2021, an anonymous actor posted a 125 GB torrent on 4chan containing Twitch's entire source code, internal security tools, mobile and desktop clients, proprietary …
Developers behind Solana Towers, an NFT project allowing investors to buy rooms in a metaverse virtual condo as NFTs, disappeared with around $280,000 a day after the project's …
A week after the launch of the "Evolved Apes" NFT project, which consisted of 10,000 NFTs and a promised fighting game, the anonymous developer behind the project disappeared after …
On October 6, 2021, an anonymous user posted a 125GB torrent to 4chan claiming it was a complete Twitch data dump intended to 'foster more disruption and competition in the online …
Third-Party Vendor Ransomware Attack Impacts Humana, Anthem Members | TechTarget. PracticeMax, a billing and IT solutions provider, experienced a ransomware attack that impacted …
Hackers leak police takedown video, medical records in Durham Region breach: CTV News Toronto investigation. A CTV News Toronto investigation has discovered that a data breach at …
Third-party data breach in Singapore hits healthcare provider. Fullerton Health says its third-party vendor, which platform facilitates appointment booking, had suffered a security …
A blatant clone of the extremely popular Bored Ape Yacht Club project, called "Baller Ape Club" and on the Solana blockchain, went live after much anticipation. Shortly afterwards, …
NFT collectors eagerly bought thousands of presales of an NFT project called "Iconics" after viewing sample artwork from a supposedly 17-year-old 3D artist. When they viewed their …
Robert Leshner, the founder of Compound Labs, took an unusual approach when trying to recoup funds that were mistakenly distributed through a $160 million bug in the protocol. He …
Shortly before the federal election, the German government launched the app "ID Wallet". It was supposed to store driver's licenses and other identification documents, and allow …
The Vee Finance decentralized finance platform was hacked for $35 million worth of Ethereum and Bitcoin. The platform suspended trading after the hack was discovered, and also …
A hacker stole $12 million from the DeFi platform pNetwork after exploiting a bug in the codebase. The network offered a $1.5 million bounty to the attacker to return the funds. …
SushiSwap's token platform, Miso, was hit with a supply chain attack that landed the attacker more than $3 million worth of Ethereum. Malicious code was injected into the …
A Twitter sleuth discovers that OpenSea's Head of Product, Nate Chastain, had apparently been engaging in a form of insider trading by buying NFTs that he knew would later be …
A press release distributed via GlobeNewswire claimed Walmart was announcing a partnership with Litecoin to begin accepting the cryptocurrency as a payment method. The value of …
The SEC filed charges against GTV Media Group and related entities, alleging they engaged in an unregistered ICO when they offered investors the opportunity to buy "G-Coins" (also …
The SEC charged Rivetz Corp. and related entities with running an illegal ICO when they launched their "RvT tokens". They raised $18 million through the ICO, which they never …
In September 2021, Ambulance Victoria — the state ambulance service providing emergency medical services across Victoria, Australia — inadvertently uploaded a file containing staff …
Nayib Bukele unexpectedly announced that El Salvador would be adopting Bitcoin as legal tender, and the policy went into effect on September 7, 2021. With the benefit of hindsight, …
On 6 September 2021, an unauthorized actor used a compromised password to access GoDaddy's Managed WordPress hosting provisioning system. GoDaddy is the world's largest domain …
On September 6, 2021, an attacker used a compromised password to access GoDaddy's Managed WordPress hosting provisioning system, where they maintained access for over two months …
A vulnerability in C.R.E.A.M. Finance allowed a re-entrancy attack to steal somewhere between $25 and $30 million from C.R.E.A.M. finance in its second multimillion dollar hack of …
A vulnerability in C.R.E.A.M. Finance allowed a re-entrancy attack to steal somewhere between $25 and $30 million from C.R.E.A.M. finance in its second multimillion dollar hack of …
A vulnerability in xToken's xSNX product allowed hackers to use flash loans to empty $4.5 million from xToken. This hack followed an even larger hack in May, where the platform was …
A vulnerability in xToken's xSNX product allowed hackers to use flash loans to empty $4.5 million from xToken. This hack followed an even larger hack in May, where the platform was …
The day after Nicholas lost almost $500,000 to NFT scammers, another collector was targeted for an even larger sum. "I've never felt more dumb, helpless, embarrassed or just plain …
After asking for help in the OpenSea Discord channel, Nicholas was successfully scammed by individuals posing as customer support. After convincing the investor to share his …
Apria Healthcare, a major US home healthcare equipment provider (durable medical equipment, infusion therapy, oxygen therapy), disclosed in May 2022 that it had experienced two …
Japanese cryptocurrency exchange Liquid Global suffered a hack that saw $90 million in various assets stolen. The exchange stated that the attack had targeted the company's MPC …
ProxyShell is a chain of three Microsoft Exchange Server vulnerabilities — CVE-2021-34473 (SSRF/ACL bypass), CVE-2021-34523 (privilege escalation), and CVE-2021-31207 (arbitrary …
The DAO Maker project (not to be confused with the well-known MakerDAO) is a launchpad that claims to be "building the future of venture capital". Its website boasts that users who …
Hackers stole approximately $611 million from the decentralized finance platform Poly Network in the largest cryptocurrency theft against a single platform to date. In a bizarre …
The "Fame Lady Squad" NFT project touted itself as a woman-designed and -developed project that would give back to women in the space, drawing support from high-profile individuals …
On August 10, 2021, an attacker exploited a critical vulnerability in Poly Network's cross-chain interoperability protocol to steal approximately $611 million across three …
On 9 August 2021, Wiz.io security researchers discovered a critical vulnerability chain in Microsoft Azure Cosmos DB — Microsoft's flagship globally distributed database service …
Poloniex, a cryptocurrency exchange, agreed to pay more than $10.3 million in a settlement with the SEC. The SEC had alleged that Poloniex had flouted securities laws from 2017 …
DeviantArt releases software to automatically scan the NFT platform OpenSea for NFTs that use stolen artwork from DeviantArt. While it's awesome that DeviantArt created this tool …
The SEC charged two individuals with selling more than $30 million in unregistered securities in what they described as a defi project that bought "real world" assets like car …
On 4 August 2021, Eskenazi Health — Indianapolis's primary safety-net hospital serving the city's most vulnerable and uninsured populations, and the only Level I adult trauma …
The company Uulala, which aimed to provide underbanked individuals with opportunities to build credit, settled with the SEC over charges that they ran an unregistered ICO that …
Popsicle Finance, a DeFi platform, lost $25 million to a bug exploited with flash loans. The organization later reimbursed users who lost money to the exploit. Total loss …
On approximately 1 August 2021, Roper St. Francis Healthcare — a nonprofit hospital system based in Charleston, South Carolina operating multiple hospitals and medical facilities — …
In August 2021, John Binns — a 21-year-old US citizen living in Turkey — exploited an improperly secured T-Mobile testing environment that had been exposed to the internet, gaining …
T-Mobile agreed to pay a $31.5 million FCC settlement in September 2024 covering four separate data breaches between 2021 and 2023. The 2021 breach (discovered August 2021) …
Catholic Health Impacted by CaptureRx Data Breach, Patients’ PHI Exposed | TechTarget. The CaptureRx data breach is impacting 17K Catholic Health patients in New York. Catholic …
First Horizon Bank Customers Have Account Funds Drained. Attackers stole under $1 million after breaching internal security. A leading US bank has revealed a data breach in which …
Microsoft Data Breach Exposes 38M Records Containing PII | TechTarget. A Microsoft Power Apps data breach exposed 38M records containing PII and impacted 47 organizations, …
Finiko, a Russian operation that turned out to be a Ponzi scheme, collapsed in July 2021 after defrauding approximately $95 million from people. Investors, facing difficult …
An attacker giving out free UniH tokens was able to exploit a bug in a non-standard token contract and steal RUNE tokens from unsuspecting victims. By baiting people into selling …
Norton, the makers of the popular Norton Antivirus software, started installing "Norton Crypto" on customers' machines when they install the popular Norton 360 antivirus and …
Coinbase's USD Coin claimed that there was $1 "in a bank account" to back it, meaning that if everyone hypothetically tried to redeem their USDC at once at any given time, it would …
REvil ransomware gang exploited zero-day SQL injection and auth bypass (CVE-2021-30116) in Kaseya VSA endpoint management software on July 4th weekend 2021. Delivered malicious …
ClearBalance Data Incident Impacts Over 200,000 US Patients' PII | TechTarget. A new cyberattack is impacting over 200,000 patients across the country. ClearBalance, a …
Supply Chain Ransomware Breach Affects 1.2 Million. A supply chain ransomware attack affecting more than 1.2 million individuals is among the largest health data breaches reported …
Third-party company: Elekta.
Third-party company: Guidehouse.
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
DarkSide behind Guess breach. Print-on-demand vendor data compromises. Patient data phished from lender. Gambling venue operator breached.. Experts guess DarkSide behind Guess …
See comprehensive record: data/supply-chain/2021-07_kaseya-vsa-revil.yaml. Kaseya VSA is used by MSPs (Managed Service Providers) to remotely manage client endpoints — a single …
StableMagnet creators rugpulled about $27 million from users by swapping out linked library code. Users who had StableMagnet linked to their cryptocurrency wallets saw their …
UNC2903 is a financially-motivated threat actor tracked by Mandiant/Google Cloud that systematically exploited IMDSv1 vulnerabilities in AWS deployments. Beginning in mid-2021, …
The cryptocurrency "titan" dropped from $65 to $0.000000024 within a few hours, despite being a stablecoin that is supposed to be much less volatile than most cryptocurrencies. As …
In early June 2021, a group (later attributed to early Lapsus$ affiliates) breached Electronic Arts' internal network using purchased Slack cookies worth approximately $10 …
In mid-2021, Latitude Financial Services suffered an earlier, smaller data security incident — separate from the major March 2023 breach (which affected 14 million customers via a …
Twitter API change in June 2021 introduced vulnerability allowing anyone to look up Twitter accounts via email/phone. Threat actors scraped at scale before patch in Jan 2022. …
Largest US propane distributor discloses '8-second' data breach. America's largest propane provider, AmeriGas, has disclosed a data breach that lasted ephemerally but impacted 123 …
Third-party company: Logicgate.
Third-party company: Elekta.
CVS Health Faces Data Breach,1B Search Records Exposed | TechTarget. A CVS Health data breach led to over 1 billion search records being accidentally posted online, as reported by …
Data breach with Harbor Regional Health vendor; potentially affected patients contacted. [](http://www.kxro.com/#facebook)[](http://www.kxro.com/#twitter)Share. Harbor Regional …
Ohio Medicaid Providers’ Personal Information Exposed by Vendor | JD Supra. Maximus, a contractor of the State of Ohio’s Medicaid program reported this week that it experienced a …
New Ransomware Targets US Congress Members: Did It Complete Breach iConstituent?. New ransomware targeted the vendor iConstituent. Security experts confirmed 60 U.S. Congress …
In July 2021, a threat actor using the name "ZeroX" began advertising 1 terabyte of data stolen from Saudi Arabian Oil Company (Saudi Aramco) on a darknet forum, demanding $50 …
Chinese state-sponsored group Volt Typhoon (Bronze Silhouette) active since mid-2021, targeting US critical infrastructure sectors: communications, energy, transportation, …
REvil (Russian) ransomware attack on JBS S.A., world's largest meat processor, May 30 2021. Disrupted beef and pork slaughter facilities in US, Canada, Australia. JBS paid $11M USD …
On 30 May 2021, JBS S.A. — the world's largest meat processing company, processing approximately one-fifth of all US beef — was hit by a REvil ransomware attack that forced the …
Belt Finance fell victim to a flash loan attack which netted an attacker $6.3 million. This was yet another exploit targeting a protocol built on the Binance Smart Chain protocol, …
A missing line of code made it "trivally" easy for an attacker to use a flash loan attack to pull $7.2 million from the DeFi platform BurgerSwap. BurgerSwap said it would "strive …
The SEC filed an action against five individuals that they alleged promoted unregistered securities in a $2 billion investment scheme, which they described as a "lending program". …
Attackers exploited a flaw in the smart contract of Bogged Finance's BOG token to drain half the liquidity pool, equivalent about $3 million. This resulted in the BOG token tanking …
DeFi100, a Binance-based DeFi protocol, suddenly replaced its website with a statement: "We scammed you guys and you can't do shit about it". One crypto analyst estimated a scam …
A hacker used flash loans to manipulate the price of other token pools, to then exploit a bug in PancakeBunny logic that calculates how many tokens should be minted. They were able …
A decentralized finance project called FinNexus was reportedly hacked for $7.6 million, in what was widely speculated to actually be a rug pull by the project's developers.The …
An attacker pulled $10.85 million in funds out of one of bEarn Fi's vaults by exploiting a bug that allowed them to withdraw more funds than they deposited. bEarn promised to …
On May 14, 2021, Conti ransomware operators attacked Ireland's Health Service Executive (HSE) — the country's entire national public health system — encrypting approximately 80,000 …
A flash loan attack allowed hackers to exploit two vulnerabilities in the xToken DeFi platform and steal $24.5 million. This was the first of two large-scale hacks of the platform …
A flash loan attack allowed hackers to exploit two vulnerabilities in the xToken DeFi platform and steal $24.5 million. This was the first of two large-scale hacks of the platform …
An attacker exploited a Rari Capital ETH pool, stealing ETH worth around $15 million. The theft caused the price of Rari's governance token to plummet by around 50%. Total loss …
DarkSide ransomware affiliate (Russian-based) compromised Colonial Pipeline via leaked VPN credentials on a legacy account lacking MFA. 100 GB of data exfiltrated day before …
After a $10 million hack just two days prior, Value DeFi had another $11 million stolen after attackers found and exploited a different bug in their smart contract. Total loss …
After a $10 million hack just two days prior, Value DeFi had another $11 million stolen after attackers found and exploited a different bug in their smart contract. Total loss …
Attackers exploited a bug in Value DeFi's smart contract to drain $10 million out of the platform, in a second attack in six months. In November 2020, the platform had lost $7 …
Attackers exploited a bug in Value DeFi's smart contract to drain $10 million out of the platform, in a second attack in six months. In November 2020, the platform had lost $7 …
In June 2021, data for approximately 700 million LinkedIn users — representing 93% of LinkedIn's total user base at the time — was posted for sale on RaidForums by a user calling …
Ransomware Hits Scripps Health, Disrupting Critical Care, Online Portal | TechTarget. This week's breach roundup is led by a ransomware attack on Scripps Health. The …
Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …
Canada Post hit by data breach after supplier ransomware attack. Canada Post has informed 44 of its large commercial customers that a ransomware attack on a third-party service …
Reported ransomware attack leads to weeks of Aprima EHR outages. Some customers describe being unable to access their clinic schedules, chart notes, refill requests or incoming …
In May 2021, multiple Japanese government agencies disclosed that sensitive data had been exfiltrated via Fujitsu's ProjectWEB platform, an enterprise project information-sharing …
US Physics Laboratory Exposed Documents, Credentials. The Fermilab physics laboratory in the U.S. has tidied up its systems after security researchers found weaknesses exposing …
US defense contractor BlueForce apparently hit by ransomware | TechTarget. A Virginia-based U.S. defense contractor has apparently been hit by ransomware, according to a ransomware …
Herff Jones data breach leaves students' bank information compromised - The Cougar. A data breach at UH graduation cap and gown vendor, Herff Jones, has students' bank information …
A UK recruitment firm exposed sensitive applicants data for months. FastTrack Reflex Recruitment firm recently joined the ranks of other companies that have been affected by data …
Security researchers at Upguard and Wiz.io discovered in mid-2021 that Microsoft Power Apps portals had a default configuration that left internal data tables publicly accessible …
A flawed calculation pertaining to the liquidity pool of Spartan Protocol allowed an attacker to drain $30 million from the project. Total loss estimated at $30,000,000.
DarkSide ransomware attacked Brenntag, one of the world's largest chemical distribution companies (Germany-headquartered, North America division targeted), on approximately April …
Frank Schilling, founder of the Uni Naming & Registry (UNR) held an auction for 23 TLDs (the bit at the end of the domain, like .com or .org). These included .link, .help, .game, …
A bug in Uranium Finance, a DeFi exchange based on Binance Smart Chain, allowed an attacker to drain the liquidity pools for multiple token pairs. Uranium had just commissioned an …
On 28 April 2021, an attacker exploited a critical vulnerability in Uranium Finance — a decentralised exchange (DEX) and automated market maker (AMM) protocol built on Binance …
On May 1, 2021, Scripps Health — San Diego's second-largest healthcare provider operating five hospitals and 19 outpatient facilities — suffered a Conti ransomware attack that took …
An employee of the ZKM Centre for Art and Media in Karlsruhe accidentally sent two of their four Cryptopunk NFTs back to its smart contract address. This is referred to as …
Turkish Bitcoin exchange Thodex halted trading and limited customers' access to their investments, claiming it was to investigate suspicious activity and swearing it was not an …
Click Studios, the Australian developer of the enterprise password manager Passwordstate, suffered a supply chain compromise between April 20–22, 2021 (a 28-hour window). Attackers …
Hackers compromised a computer belonging to EasyFi founder Ankitt Gaur, accessing his private keys which allowed them to transfer $6 million in stablecoins and $120 million worth …
The two founders of a South Africa-based crypto investment firm called Africrypt claimed they had been hacked, and all assets had been stolen. The duo disappeared as legal action …
On 7 April 2021, Reproductive Biology Associates (RBA) — an Atlanta, Georgia fertility clinic — and its affiliate My Egg Bank North America suffered a DoppelPaymer ransomware …
At some point in April 2021, a trader on the FTX cryptocurrency exchange successfully exploited the firm for around $800 million. They were able to take positions in relatively …
The Illinois Department of Human Services (IDHS) exposed sensitive personal data of more than 700,000 state residents for approximately four years, from April 2021 to September …
Blue Shield of California disclosed on April 9, 2025, that a misconfigured Google Analytics integration had been sharing member protected health information (PHI) with Google Ads …
Digital supply chain giant Bizongo suffers massive data breach, sensitive customer info exposed: Report - The Tech Portal. Digital supply-chain platform Bizongo reportedly became …
Third-party company: Quanta.
MN: Apple Valley Clinic notifies 157,939 patients about Netgain Technology breach - DataBreaches.Net. In November, 2020, cloud IT services provider Netgain Technology LLC …
BlackKite timeline indicates a third-party/vendor-related breach; detailed reporting was not accessible automatically.
US Telemarketing Biz Exposes 114,000 in Cloud Config Error. Call recordings of clients and customers on unsecured bucket. A US telemarketing company has leaked the personal details …
Celsius Suffers Third-Party Data Breach, Customers Report Phishing Texts, Emails. The crypto lender's data leak comes almost a year to the date after a similar data leak hit …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident | TechTarget. Data breach notifications and a report reveal a former MedData employee uploaded troves of …
Third-party company: Medifie.
Third-party security breach compromises data of Singapore job-matching service. Job-matching institute e2i says the personal details of 30,000 individuals may have been illegally …
Hacking campaign targets FileZen file-sharing network appliances. Threat actors are using two vulnerabilities in a popular file-sharing server to breach corporate and government …
ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users. Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app …
Malware attack on Radixx Res disrupts 20 airlines' ticket reservation systems - DataBreaches.Net. Radixx , a subsidiary of Sabre Corporation, provides an air passenger ticket …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Third-party company: Personal Touch Holding Corp..
Data Leak: Route Mobile investigating claims; data of Tata Communications, Bharti Airtel and DBS Bank allegedly leaked. Hackers have allegedly compromised servers of enterprise …
Upstox alerts its users of data breach; funds, securities safe. On receipt of e-mails claiming unauthorized access into Upstox database, the company has appointed a cyber-security …
Wieden+Kennedy Employees Exposed to a Data Breach. This is a preview. This ad will run at the top of the page as expected when running (or previewing) on your website. …
US investigators probing breach at code testing vendor. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …
On 28 March 2021, Nine Entertainment — Australia's largest media and entertainment company, operating the Nine Network (free-to-air TV), The Sydney Morning Herald, The Age, The …
CNA Financial Corporation, one of the largest commercial insurance companies in the United States, suffered a ransomware attack on March 21, 2021 that disrupted its operations for …
On 21 March 2021, CNA Financial — one of the largest commercial insurance companies in the United States — suffered a ransomware attack using a new malware strain called Phoenix …
24 hours after pre-sale, the team behind Turtledex drained $2.5 million from the liquidity pool and disappeared. Turtledex's smart contract had been audited shortly before the …
In March 2021, an unauthorized actor gained access to a Luxottica partner appointment scheduling application that contained patient data for customers of Luxottica's vision care …
Secure Administrative Solutions LLC (SAS), a third-party vendor providing benefits administration services to Renaissance Life & Health Insurance Company of America and other …
On March 14, 2021, REvil ransomware operators attacked Acer, the Taiwanese PC manufacturer, using the freshly-disclosed ProxyLogon Exchange vulnerability (CVE-2021-26855, disclosed …
Private keys for hot wallets on the Roll network were compromised, allowing the theft of around $5.7 million from various "social tokens". "Friends With Benefits", an a16z-backed …
Vignesh Sundaresan's $69 million purchase of an NFT by artist Beeple made headlines. However, Amy Castor outlined a few days later that Sundaresan is a business partner of …
DeFi project DODO was relieved of $3.8 million after hackers exploited a bug in their v2 Crowdpools smart contracts. The exchange later recovered $1.89 million of these funds. …
Jason Rohrer, developer of the 2014 indie game The Castle Doctrine announced his plan to auction 155 of the digital paintings that he had commissioned for the game as NFTs on the …
NFT artist "neitherconfirm" created a collection of 26 NFTs of stained glass-style computer-generated art. After release, they changed the art for each NFT to a picture of a rug, …
In March 2021, a collective including Swiss hacker Tillie Kottmann ('deletescape') gained access to Verkada's global security camera management platform by discovering Verkada …
A contract exploit allowed a hacker to mint almost 60 million PAID tokens (priced at around $160 million based on the value before the attack) on the PAID Network. The hacker then …
The team behind the Meerkat DeFi protocol claimed they had been victims of a hack, but subsequently disappeared from the web after the equivalent of $31 million in Binance Coin …
Third-party risks hit universities, associations. Financial services data breaches. State employee successfully phished.. US Geospatial Intelligence Foundation and AFCEA are …
Austin ISD warns of possible data breach. Those who have been affected are being offered free identity monitoring. AUSTIN, Texas — Austin ISD notified parents last week after it …
Local health plan manager announces data breach. [](http://thebusinessjournal.com/local-health-plan-manager-announces-data-breach/#menu-location-primary). …
European Banking Authority hit by Microsoft Exchange hack. The EU body is one of the first major organisations to admit falling victim to the global email hack. The European …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Personal details of all Israeli voters again leaked online, day before election. Anonymous hackers publish databases with 6.5 million names and ID numbers, including where people …
Third-party company: Netgain.
Data breach reported at Piedmont Health Services. We have used your information to see if you have a subscription with us, but did not find one. Please use the button below to …
Data breach involving former Polk County Schools vendor could impact thousands. This issue involves a company hired by Polk Schools to collect information about students using the …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Third-party company: Verkada.
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Third-party company: Healthgrades.
On 26 February 2021, SITA — the world's leading IT provider to the air transport industry, serving approximately 90% of international airlines — disclosed that its Passenger …
Singapore Airlines disclosed on 5 March 2021 that its KrisFlyer frequent flyer programme member data had been compromised through the SITA Passenger Service System breach disclosed …
On February 24, 2021, SITA — one of the world's largest aviation IT companies, serving approximately 90% of global airlines through its Passenger Service System (PSS) — detected …
DarkSide ransomware attacked fashion retailer Guess (NYSE: GES) in February 2021, exfiltrating data before encryption. DarkSide published a sample of stolen files on their leak …
A hacker was able to code a smart contract that tricked C.R.E.A.M. into believing it was from a trusted source. They were then able to make off with $37.5 million worth of Ethereum …
A hacker was able to code a smart contract that tricked C.R.E.A.M. into believing it was from a trusted source. They were then able to make off with $37.5 million worth of Ethereum …
NEC Networks LLC, doing business as CaptureRx, a San Antonio, Texas-based provider of 340B drug pricing program administrative services to healthcare organizations, suffered a …
On February 5, 2021, an unknown attacker gained remote access via TeamViewer to the HMI (Human Machine Interface) workstation of the City of Oldsmar, Florida's water treatment …
An exploit in Yearn Finance's yDAI vault resulted in an $11 million loss to the platform, though "only" $2.8 million of this went to the hacker. Total loss estimated at …
The stablecoin Tether swears up and down that it's fully backed by actual currency, but the New York Attorney General doesn't agree. Tether paid $18.5 million in penalties, was …
Hackers Exploit IT Monitoring Tool Centreon to Target Several French Entities. Russia-linked state-sponsored hackers Sandworm targeted IT monitoring software company Centreon in a …
Actor Exploits Beaumont Health’s COVID-19 Vaccine Scheduling Tool | TechTarget. This week's breach roundup is led by a Beaumont Health security incident. An actor exploited a …
US cities disclose data breaches after vendor's ransomware attack. A ransomware attack against the widely used payment processor ATFS has sparked data breach notifications from …
City of Monroe’s utility billing vendor hit with data breach - HeraldNet.com. A third of the city’s residential and commercial customers might have had have banking information …
Wind River Systems Investigating Possible Data Breach. Embedded software vendor Wind River Systems is investigating a security incident within its internal network, according to a …
Ransomware hits largest US fertility network, patient data stolen. US Fertility, the largest network of fertility centers in the U.S., says that some of its systems were encrypted …
Government Contractor Stormshield Suffers Double Breach. French security company warns of customer data and source code theft. A French cybersecurity company with government …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Jamaica's immigration website exposed thousands of travelers' data | TechCrunch. Exclusive: Months of immigration documents and COVID-19 lab results were left on an unprotected …
Mimecast Certificate Hacked in Microsoft Email Supply-Chain Attack. A sophisticated threat actor has hijacked email security connections to spy on targets. A Mimecast-issued …
Netgain ransomware incident impacts local governments. The ransomware incident that Netgain, a provider of managed IT services, had late last year rippled onto its customers. Now, …
Hacker leaks data of millions of Teespring users. A hacker has leaked the details of millions of users registered on Teespring, a web portal that lets users create and sell …
Ubiquiti discloses a data breach ................................. American technology company Ubiquiti Networks is disclosed a data breach and is notifying its customers via …
See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …
Between 31 January and 1 April 2021, attackers silently modified Codecov's popular bash uploader script, which thousands of CI/CD pipelines used to upload code coverage reports. …
Between 31 January and 1 April 2021, attackers modified Codecov's popular bash uploader script — used by thousands of CI/CD pipelines to upload code coverage reports — to …
Codecov, a widely used code coverage reporting service, suffered a sophisticated supply chain compromise that began January 31, 2021, and was not discovered until April 1, 2021 — …
PopcornSwap launched on BNB Chain and then immediately drained its liquidity pool, making off with tokens priced at around $2 million.Binance stated that they had been able to …
WestRock Company, one of the largest corrugated packaging and paperboard manufacturers in the world, disclosed on January 25, 2021 that it had suffered a ransomware attack on …
In late January 2021, SonicWall disclosed that its own internal systems and Secure Mobile Access (SMA) 100 series VPN appliances were targeted by sophisticated threat actors …
The Saddle Finance defi project, a fork of the Curve Finance project, launched on January 20. It promised it would "eliminate slippage".The project was exploited only hours later, …
Nevada Restaurant Services (NRS), the parent company of slot machine parlor chain Dotty's, disclosed a data breach in September 2021 after identifying the presence of malware on …
In January 2021, the Australian Securities and Investments Commission (ASIC) — Australia's corporate, markets, and financial services regulator — disclosed that its Accellion File …
On 11 January 2021, 20/20 Eye Care Network — a managed vision care benefits company providing administration services to health plans — discovered that an unauthorized actor had …
On January 8, 2021, Amazon Web Services notified Parler — a social media platform popular with right-wing users — that it would terminate Parler's hosting services on January 10 …
Chinese state-sponsored group HAFNIUM exploited four zero-days in on-premises Microsoft Exchange starting Jan 3 2021. CVE-2021-26855 (SSRF auth bypass) chained with CVE-2021-27065 …
On 20 July 2022, a threat actor posted on BreachForums offering to sell 69 million Neopets user records and — uniquely — live access to Neopets' database (with read and write …
Security researcher Jan Masters (working with Pen Test Partners) discovered in January 2021 that Peloton's API endpoints did not enforce authentication or authorization checks, …
Data breach at Bonobos hits up to 7 million: What to do [updated]. When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. Here at …
Defence tech service provider firm's data hacked, company claims Rs 50-cr loss. The executive claimed that majority of the hacked emails were of "extremely sensitive" nature and …
North Korean software supply chain attack targets stock investors. North Korean hacking group Thallium has been targeting a private stock investment messenger service in a supply …
Ransomware Attack Hits Short Line Rail Operator OmniTRAX. Colorado-based short line rail operator and logistics provider OmniTRAX was hit by a recent ransomware attack and data …
Saskatchewan privacy commissioner investigates potential breach of hunting licensing system | Globalnews.ca. Saskatchewan's privacy commissioner is currently investigating a …
After refusing to pay ransom, US-based auto parts distributor has sensitive data leaked by cybercriminals. NameSouth is the latest victim of NetWalker, a ransomware gang that …
Truckers' Medical Records Leaked. Ransomware attack on Virginia healthcare provider may have exposed medical records of transport workers. Medical records belonging to truck …
Chinese start-up leaked 400GB of scraped data exposing 200+ million Facebook, Instagram and LinkedIn users. High-flying and rapidly growing Chinese social media management company …
In January 2021, security researchers at vpnMentor discovered a publicly accessible Elasticsearch database belonging to Socialarks — a Chinese social media management company that …
In April 2021, Mandiant (FireEye) and CISA disclosed that at least two Chinese APT groups (tracked as UNC2630 and UNC2717, attributed to APT5 / MANGANESE) had been exploiting …
FIN11 / UNC2546 (linked to Cl0p/TA505) exploited four zero-days in legacy 20-year-old Accellion FTA product starting Dec 25 2020. Used DEWMODE webshell to exfiltrate data. ~100 of …
The Accellion FTA (File Transfer Appliance) breach was one of the most consequential supply-chain attacks of early 2021, affecting dozens of major organisations worldwide through a …
In December 2020, Nickolas Sharp, a senior cloud engineer at Ubiquiti Networks (maker of UniFi networking equipment), used his legitimate access to Ubiquiti's AWS infrastructure …
When a top cybersecurity firm gets hacked, what is the takeaway for the average netizen?. Cybersecurity firm FireEye said this week it had been breached by hackers for a foreign …
Russian hackers compromised Microsoft cloud customers through third party, putting emails and other data at risk. Outside Microsoft’s French headquarters in Issy-Les-Moulineaux, …
Chinese APT suspected of supply chain attack on Mongolian government agencies. Chinese hackers have compromised the update mechanism of a chat app used by hundreds of Mongolian …
Data breach hits 30,000 signed up to workplace pensions provider. Fraud worries as UK company Now:Pensions says ‘third-party contractor’ posted personal details of clients to …
Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia. ESET researchers have uncovered a supply-chain attack on the website of a government …
See comprehensive record: data/supply-chain/2020-12_solarwinds-sunburst.yaml. The SolarWinds Orion supply chain attack is the defining supply chain cyber incident of the decade — …
Belden Inc., a U.S.-based global manufacturer of network connectivity and industrial networking equipment (including routers, firewalls, switches, cabling, and connectors), …
American Bank Systems hit by ransomware attack, full 53 GB data dump leaked - Security Report. American Bank Systems (ABS), a service provider to US banks and financial …
Great Hearts Academies students and parents were victims of data breach. An unknown number of students at Great Hearts Academies and their parents had their names and contact …
Third-party company: Vertafore.
Animal Jam Hacked, 46M Records Roam the Dark Web. Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen …
Lazada, the Alibaba-owned Southeast Asian e-commerce platform, disclosed a data breach affecting approximately 1.1 million customers of its Singapore-based grocery delivery service …
DoppelPaymer ransomware crippled the University of Vermont Health Network on October 28 2020, affecting all six of its hospitals and hundreds of medical staff. The attack knocked …
On 28 October 2020, the University of Vermont Medical Center (UVMMC) and its University of Vermont Health Network — encompassing six hospitals and approximately 1,000 providers …
On October 26, 2020, Harvest Finance — a DeFi yield aggregator managing over $1 billion in assets — suffered a flash loan economic attack resulting in approximately $34 million in …
In October 2020, Nitro Software — the company behind Nitro PDF, a widely used PDF productivity and e-signature service — suffered a data breach that exposed data for approximately …
In October 2020, security researcher Carlo di Dato published details of a dataset containing 167 million Gravatar user records obtained by systematically scraping Gravatar's public …
Nitro PDF Suffered A Data Breach Impacting Google, Apple, Amazon, And More. Popular PDF service provider Nitro PDF has recently suffered a massive data breach. While, they …
Third-party company: Click2Gov.
Isentia Reeling After Suspected Ransomware Attack. Media monitoring giant Isentia has revealed that it is currently dealing with a major security incident disrupting some online …
Precious Metal Trader JM Bullion Acknowledges Breach. In a notification letter filed to the Montana Department of Justice, precious metal trader JM Bullion has revealed that an …
Shopify Data Breach - Arnold Law Firm. The Shopify data breach has affected thousands of merchants. Our lawyers can help you understand your legal rights and options for …
1M Inova Health Individuals Added to Blackbaud Breach Victim Tally | TechTarget. This week's breach roundup is led by the Blackbuad ransomware attack, which added more than 2 …
FireEye (now Mandiant) was one of the first and most notable victims of the SUNBURST supply chain attack via SolarWinds Orion. Unlike most SUNBURST victims, FireEye was …
Broadvoice, a VoIP (Voice over IP) service provider serving small and medium-sized businesses across the United States, inadvertently exposed a massive Elasticsearch cluster …
On September 27, 2020, Universal Health Services (UHS) — one of the largest US hospital chains with 400 facilities across the US and UK — was struck by Ryuk ransomware, causing one …
On September 25, 2020, KuCoin detected large unauthorized outflows from its hot wallets across multiple blockchains including Bitcoin, Ethereum, Litecoin, XRP, Stellar, TRON, and …
Fragomen, Del Rey, Bernsen & Loewy LLP — one of the largest immigration law firms in the United States, with over 582 attorneys across 47 global offices — disclosed a data breach …
Cisco disclosed in February 2021 that unauthorized actors had compromised AWS IAM credentials associated with the Cisco WebEx Teams video conferencing service. The attackers …
Dental Care Alliance (DCA), a Florida-based dental support organization (DSO) providing administrative and operational support to more than 320 affiliated dental practices across …
On 9 September 2020, ransomware (assessed as DoppelPaymer) crippled the IT systems of University Hospital Düsseldorf (Universitätsklinikum Düsseldorf) — one of Germany's largest …
Page Not Found. For optimal browsing, we recommend Chrome, Firefox or Safari browsers. By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to …
Payment Card Skimming Hits 2,000 E-Commerce Sites. From Friday through Monday, malicious JavaScript skimming code was injected into nearly 2,000 e-commerce sites that were running …
Some Pell City utility customers may have suffered data breach (free content). City Manager Brian Muenger said the municipality has been informed by Valley Bank that some of the …
Phipps Conservancy says members safe despite data breach that disclosed some info. Phipps Conservatory and Botanical Gardens in Pittsburgh’s Oakland section contacted its …
In November 2020, security researchers at vpnMentor discovered an unsecured Elasticsearch database containing approximately 380 million records including usernames, passwords, and …
Online marketing company exposes 38+ million US citizen records. The user record files contained full names, addresses, zip codes, emails, and phone numbers of people based in the …
Luxottica, the Italian eyewear conglomerate and parent company of EyeMed Vision Care, LensCrafters, Target Optical, and Pearle Vision, suffered two separate but related security …
Subscriber Access To OODA Content. When you join with subscriber level to OODA Loop, you’re not just reading intelligence, you are adding fuel to your OODA Loop. Subscriber Access …
Jack Daniel’s-Maker Suffers REvil Ransomware Breach. Attackers claim to have 1TB of stolen data in their possession. US wine and spirits giant Brown-Forman has become the latest …
Data Breach May Have Affected Some Rochester YMCA Accounts. Donors of the Rochester YMCA have been notified of a data breach that may have affected their personal information. …
In August 2020, security researcher Volodymyr Diachenko discovered a publicly accessible Elasticsearch cluster belonging to Razer — the US gaming hardware company known for gaming …
On July 23, 2020, Evil Corp (a Russian cybercrime organization led by Maksim Yakubets, sanctioned by OFAC) deployed WastedLocker ransomware against Garmin, encrypting the company's …
On July 20, 2020, Microsoft's AI research team published open-source AI training data to GitHub and inadvertently included an overpermissioned Azure SAS token in the repository. …
On 19-20 July 2020, GEDmatch — a popular free genealogy DNA comparison service with approximately 1.45 million registered users — suffered a cyberattack that changed the privacy …
On July 15, 2020, attackers hijacked approximately 130 high-profile Twitter accounts including Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple, Uber, Jeff Bezos, Kanye West, …
In August 2020, Freepik — one of the world's largest stock photography and design resources websites (along with its vector icon subsidiary Flaticon) — disclosed a data breach …
Third-party company: M.J. Brunner.
Citrix data exposed in third-party breach | TechTarget. Citrix Tuesday published a blog confirming that a third-party organization is investigating a possible data breach after a …
Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …
In July 2020, Microsoft's AI research division accidentally published an Azure Shared Access Signature (SAS) token with overly permissive access when sharing an open-source …
In June 2020, MEDNAX — a national health solutions company providing physician services management, including neonatology and pediatric subspecialty care, to approximately 120,000 …
In June 2020, Drizly (an online alcohol delivery service) suffered a data breach when an attacker discovered AWS credentials stored in a plaintext format in an internal GitHub …
In July 2020, the personal data of approximately 7.5 million users of Dave — a US-based neobank and personal finance app — was compromised and subsequently leaked on a public …
In June 2020, Wattpad — the online creative writing platform with over 90 million users — suffered a data breach exposing approximately 268 million user records. The data was …
Keepnet Labs confirms contractor exposed 'data breach database' of 5 billion records. Keepnet Labs has confirmed that a contractor temporarily exposed a database containing five …
MU Health reports data breach. University of Missouri Health Care said Thursday that it has notified patients affected by a September data breach. The organization said in a news …
‘BlueLeaks’ Exposes Files from Hundreds of Police Departments. Hundreds of thousands of potentially sensitive files from police departments across the United States were leaked …
San Francisco benefits program breach exposes PII on 74,000. A breach of the San Francisco Employees’ Retirement System (SFERS) may have exposed the information of 74,000 members, …
In approximately June 2020, ShinyHunters — a prolific cybercrime group responsible for multiple major 2020 breaches (Tokopedia, Dave.com, Microsoft GitHub repos) — breached Wattpad …
Joomla team discloses data breach. Joomla says a team member left an unencrypted backup of the JRD portal on a private AWS S3 bucket. The team behind the Joomla open source content …
In August 2020, Experian South Africa disclosed that a suspected fraudster had obtained personal data of approximately 24 million South African individuals and 793,749 businesses …
Bank of America Responds to Breach. Bank of America blames a suspected breach of credit card data on an unidentified third party. What happened, and what can other institutions do …
Data breach exposes Social Security info of some Floridians seeking unemployment benefits. The Florida Department of Economic Opportunity said they had to deal with a data security …
Management and Network Services Notifies 30,132 Patients About PHI Breach. Management and Network Services has discovered multiple email accounts have been compromised. The PHI of …
TrueCaller Data of 4.75 Cr Indians for Sale On Dark Web: Report. Online intelligence firm Cyble flagged that a cybercriminal was selling Truecaller records of 4.75 crore Indians on …
Maze ransomware group attacked Cognizant, a Fortune 500 IT managed services provider with ~300,000 employees, on April 18 2020. The attack disrupted services for clients across …
Magellan Health, one of the largest managed care companies in the United States (specializing in behavioral health and pharmacy benefits), disclosed in May 2020 that it suffered a …
On 11 April 2020, Magellan Health — a Fortune 500 managed care company specialising in behavioral health, pharmacy benefits, and radiology benefits management — suffered a …
In April 2020, 47 Service NSW employee email accounts were compromised through a phishing attack, allowing unauthorized access to customer data processed through those email …
IT services giant Cognizant suffers Maze Ransomware cyber attack. Information technologies services giant Cognizant suffered a cyber attack Friday night allegedly by the operators …
BlackKite timeline indicates a third-party/vendor-related breach; detailed reporting was not accessible automatically.
MSU says data breach of third party vendor impacts hundreds. Michigan State University said it has been informed by E-commerce vendor Volusion, which provides online payment …
Largest And Global Sovereign Wealth Fund Institute | SWFI. SWFI is an investor research platform offering family offices, private equity firms, banks, and institutional investors …
Two Usenet providers blame data breaches on partner company. Editor's note: This article was updated on July 8, 2025, to reflect new information discovered by an external …
In April 2020, Nintendo disclosed that approximately 160,000 Nintendo accounts had been accessed without authorisation using a credential stuffing attack against the Nintendo …
In April 2020, at the height of the COVID-19 pandemic when Zoom usage had surged from approximately 10 million to 300 million daily meeting participants in three months, …
Russian SVR (APT29/Cozy Bear) compromised SolarWinds build environment and injected SUNBURST backdoor into Orion software updates distributed March-June 2020. ~18,000 customers …
On March 16, 2020, researchers at Safety Detectives discovered a production Elasticsearch logging database belonging to CAM4 (an adult live-streaming platform operated by Granity …
CLOP ransomware group attacked ExecuPharm, a US clinical research organisation (CRO) and pharmaceutical services company, on March 13 2020. After the company declined to pay, CLOP …
In March 2020, First Republic Bank (a US private bank and wealth management company) disclosed that an insider threat incident had occurred. A bank employee with legitimate access …
Norwegian Cruise Line Holdings (NCLH), parent company of Norwegian Cruise Line, Regent Seven Seas Cruises, and Oceania Cruises, disclosed in July 2020 that it had suffered a data …
8 million UK shopping records exposed on the web, customers' personal info leaked - Comparitech. A 3rd-party app used by EU merchants on Amazon, Ebay, and other marketplaces …
Cyber insurer Chubb had data stolen in Maze ransomware attack. Chubb, a major cybersecurity insurance provider for businesses hit by data breaches, has itself become a target of a …
Third-party data breach exposes GE employees' personal information. Past and present employees of GE are learning that their sensitive information has been exposed by a data breach …
Radio.com users affected in data breach. Entercom, the second-largest radio company in the United States, has announced that it suffered a cybersecurity incident that affected …
A parts manufacturer for SpaceX and Tesla says it was hacked. Exclusive: The ransomware group have published some of the files stolen in the breach. A precision parts maker for …
T-Mobile warns customers about a recent data breach. T-Mobile this week notified customers about a data breach. According to the alert, a malicious third-party gained access to …
In April 2020, Nintendo disclosed that approximately 160,000 Nintendo Network IDs (NNIDs) — a legacy login system from the Nintendo 3DS and Wii U era — had been compromised via …
In April 2020, cybersecurity firm Cyble reported discovering approximately 530,000 Zoom account credentials being sold on dark web forums for as little as a fraction of a cent …
T-Mobile disclosed a breach on March 5 2020 affecting approximately 200,000 customers. Attackers had accessed some T-Mobile employee email accounts containing customer proprietary …
In February 2020, attackers breached Blackbaud — the world's largest provider of nonprofit and education CRM/fundraising software — and spent approximately five months in the …
Blackbaud, the world's largest provider of cloud software for nonprofits, universities, healthcare organizations, and foundations, disclosed in July 2020 that it had suffered a …
In May 2020, Blackbaud — one of the world's largest providers of cloud-based CRM and fundraising software for universities, hospitals, and nonprofits — suffered a ransomware attack …
In February 2020, Clearview AI — a controversial facial recognition company that scraped billions of photos from social media to build its facial recognition database, primarily …
Data breach potentially impacts hundreds of Brunswick County Schools employees - WWAYTV3. The company that administers the Flexible Spending Account plans for Brunswick County …
Hackers compromise financial information for Carson City residents who pay water bill online - Carson Now. According to a letter sent out to a group of residents who pay their …
Accounting Firm Ransomware Hack Affects Community Care Patient Data | TechTarget. This week's breach roundup is led by a ransomware attack on the accounting firm BST, which …
idahostatejournal.com | empowering the community. This website uses certain cookies, pixels and similar tracking technologies in order enhance site navigation, analyze site usage, …
Nedbank says 1.7 million customers impacted by breach at third-party provider. Hacker(s) believed to have exploited a vulnerability to breach Nedbank's marketing contractor. …
Rutters store chain reveals malware attacked its POS system. Convenience store company warns that malware collected payment card details as they were being processed. Convenience …
SURGA88 - Definisi Baru Gaming Premium Dengan Berbagai Kemudahan Untuk Semua Kalangan. SURGA88 : Tinggalkan pengalaman lama dan beralihlah ke standar baru dalam bermain game …
In January 2020, Amazon discovered that one or more employees had shared customer email addresses and phone numbers with an unauthorized third party in violation of company policy. …
EasyJet disclosed on 19 May 2020 that it had suffered a cyberattack that exposed the personal data of approximately 9 million customers. The attack was first detected in late …
In May 2020, easyJet (the UK-based low-cost airline) disclosed that it had suffered a cyberattack in which approximately 9 million customers had their email addresses and travel …
National General (later acquired by Allstate) suffered two sequential data breaches via its online auto insurance quoting portals. First breach (2020): exposed driver's licence …
Third-party company: Social Captain.
Third-party company: THSuite.
Leaky Server Exposes 12 Million Healthcare Records to Meow Attacker. Extortion and fraud risks persist for tens of thousands of patients. A healthcare technology company leaked 12 …
WeWork rival Regus in massive employee data breach. This feature is available for registered users. Please register or log in to continue. …
Aussie P&N bank suffers data breach. The Australian P&N Bank reported a data breach that exposed detailed and sensitive financial information on an unspecified number of …
In March 2020, Marriott International disclosed a second data breach (separate from the 2018 Starwood breach affecting 383 million guests) in which an attacker used the login …
In February 2020, security researcher Jeremiah Fowler discovered a publicly accessible Elasticsearch database belonging to Estée Lauder — one of the world's largest cosmetics and …
Data Leak Exposes 750K Birth Certificate Applications. AWS misconfiguration leaves storage bucket wide open. Over 750,000 applications for US birth certificates have been found …
On New Year's Eve 2019, REvil ransomware operators exploited CVE-2019-11510 in Travelex's unpatched Pulse Secure VPN to gain initial access to Travelex's corporate network. …
Marietta utility customer data found on dark web after third-party security breach. MARIETTA — About 8,800 Marietta utility customers may have had their credit card information …
Data security breach impacts City of Sioux City customers. SIOUX CITY -- A data security breach has potentially impacted more than 3,500 City of Sioux City customer utility and …
NYPD Fingerprint Database Infected With Ransomware by Third Party Contractor - CPO Magazine. Attempted ransomware attack on NYPD fingerprint database was the result of a “bumbling” …
2 vendors for Mindef, SAF hit by malware; personal data of 2,400 staff could have been leaked. The data included the full names and NRIC numbers, and a combination of contact …
IoT vendor Wyze confirms server leak. Details for 2.4 million users were exposed online for 22 days. Wyze, a company that sells smart devices like security cameras, smart plugs, …
GE, Dunkin', Forever 21 Caught Up in Broad Internal Document Leak. A PR and marketing provider exposed sensitive data for a raft of big-name companies. A marketing firm exposed …
On 22 November 2019, T-Mobile detected and stopped a cyberattack that gained access to information for approximately 1 million T-Mobile prepaid customers. T-Mobile disclosed the …
San Angelo explains what it's doing to prevent 3rd hack of payment system. Water customers in San Angelo are hacked off after the city's online payment system was hacked for the …
Facebook & Twitter suffer data breach via third-party developers. On Monday, both Facebook and Twitter announced that the data of hundreds of users had been compromised due to a …
Data breach put thousands of Florida Blue members' personal information at risk. A data breach at Magellan Health Inc. has put the personal information of Florida Blue members at …
Macy’s suffers online Magecart card-skimming attack, data breach. The department store detected malicious code in its online payment portal. Macy's has announced a data breach …
Third-Party Vendor Exposes Data of Palo Alto Employees. Cybersecurity firm’s employees affected by third-party data breach. American cybersecurity firm Palo Alto Networks has …
Water Bill Payment Breach Reported In Pompano Beach. A security alert for people in Pompano Beach. The city says a third-party software vendor used for online water bill payments …
Third-party company: Magellan Health System.
Potential data breach found on Charlottesville tax collections. Charlottesville is investigating the possibility of a data breach related to its tax collections. CHARLOTTESVILLE, …
In November 2019, a laptop computer was stolen in a burglary at the offices of GridWorks IC, a medical transportation coordination vendor contracted by Health Share of Oregon — the …
In November 2019, T-Mobile's cybersecurity team identified and shut down unauthorized access to systems containing prepaid customer account information. Approximately 1.26 million …
Cerebral, a US telehealth startup specializing in mental health treatment (therapy, psychiatry, and medication management), disclosed in March 2023 that it had transmitted …
Cerebral, a telehealth company specializing in mental health services (particularly ADHD and anxiety/depression treatment), disclosed in March 2023 that it had shared sensitive …
CenturyLink customers may have had data exposed in 'security incident'. The company says the incident involving a third party vendor may have exposed contact information. GOLDEN …
Third-party company: Magellan National Imaging Associates.
Officials admit to Chegg data breach affecting thousands of GW users’ account passwords. Officials notified students last week of a data leak revealing about 5,000 GW community …
CCSD says students, staff affected by third party data breach. The Clark County School District says a vendor it uses has experienced a data security incident. The school district, …
Our pick of the top fintech news stories this week includes Revolut, Coinbase, Bolt, FundApps, and more. Copyright © 2026 Informa PLC. Informa PLC is registered in England and …
Between October 1 and November 13, 2019, unknown attackers gained unauthorized access to Blue Bear, Active Network's web-based school accounting and online store management …
Home - Business Record. [](https://www.businessrecord.com/survey-on-gender-equity-in-iowa-caregiving-workplace-bias-and-financial-resources-identified-as-top-issues/). Casey’s …
Possible data breach of City of Broken Arrow online payment system. The City of Broken Arrow released a statement Thursday after the city's online payment system became …
BlackKite timeline indicates a third-party/vendor-related breach; detailed reporting was not accessible automatically.
SC Media UK. An error occurred trying to play the stream. Please reload the page and try again. Registering with SC Media is 100% free. Join tens of thousands of cybersecurity …
Malinda Air locks down publicly exposed servers. Indonesian budget airline Malindo Air reported on September 19 it had locked down the formerly publicly exposed servers that had …
Cosmetics Giant Yves Rocher Caught in Data Leak Impacting Millions of Customers. International cosmetics brand Yves Rocher found itself caught in a third-party data exposure …
On August 19, 2019, data belonging to approximately 90,000 members of Mastercard's Priceless Specials loyalty program was posted publicly on the internet, triggering Mastercard to …
Between August 14 and October 16, 2019, RCM Enterprise Services — a revenue cycle management (billing) vendor for Mercy Health Lorain Hospital in Ohio — inadvertently included …
Wood Ranch Medical Clinic, a small family medical practice in Simi Valley, California, announced in August 2019 that it would permanently close on December 17, 2019 following a …
Daily Chronicle. News • Sports • eNewspaper • Obituaries • Election • The Scene • 175 Years. …
Third-party company: Pearson Clinical Assessment (AIMSweb).
Volkswagen Group of America and Audi of America disclosed in June 2021 that approximately 3.3 million customers and prospective buyers had their personal data exposed due to an …
In August 2019, vpnMentor security researchers Noam Rotem and Ran Locar discovered a publicly accessible Elasticsearch database belonging to Suprema — a South Korean security …
On approximately July 2, 2019, security researcher Bob Diachenko (working with Comparitech) discovered a publicly accessible, unauthenticated MongoDB database containing …
On July 1, 2019, the day the 7pay mobile payment app launched in Japan, criminals immediately began exploiting a critical vulnerability in the app's password reset mechanism. The …
Dickey's Barbecue Pit, a Dallas-based smoked-meat restaurant chain with approximately 469 locations across the United States, suffered a prolonged point-of-sale (POS) malware …
In July 2019, an attacker accessed a cloud server at MGM Resorts International and extracted personal data for approximately 10.6 million hotel guests. The breach went undetected …
On June 28, 2019, threat actors — widely attributed to the Chinese state-sponsored APT group known as Tick (also tracked as Bronze Butler and associated with APT40) — breached …
In July 2019, the Bulgarian National Revenue Agency (Национална агенция за приходите, NAP) suffered the largest data breach in Bulgarian history. A hacker sent a link to the stolen …
In June/July 2019, Sprint discovered that hackers had exploited a vulnerability on Samsung's 'Add a Line' promotional webpage — a co-branded retail portal used to add new Sprint …
Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek. A serious vulnerability has been discovered in a cryptocurrency wallet app, putting millions of dollars’ …
On 24 May 2019, the graphic design platform Canva was breached by the GnosticiPlayers hacker collective. Approximately 137 million user records were stolen, containing usernames, …
On May 24, 2019, Canva — the Australian graphic design SaaS platform — suffered a data breach in which threat actor GnosticPlayers exfiltrated approximately 137 million user …
In May 2019, security researcher Anurag Sen discovered a large, unsecured database containing scraped Instagram profile data for approximately 49 million users, which he traced to …
On May 7, 2019, Binance CEO Changpeng Zhao (CZ) announced that hackers had stolen 7,000 BTC (worth approximately $40 million) from the exchange's hot wallet in a single large …
In May 2019, an attacker obtained user data from StockX — the Detroit-based sneaker and streetwear authentication and resale marketplace valued at over $1 billion. The breach went …
Hackers are collecting payment details, user passwords from thousands of sites. Servers of at least seven companies compromised to deliver malicious code to thousands of sites. …
Credit card holder? Beware, your personal data might be at risk. The revelation was made after STF Noida busted a gang of credit card scam artists and arrested four fraudsters from …
Forbes Becomes Latest Victim of Magecart Payment Card Skimmer. The web skimming script was recently found stealing payment data on the websites of Forbes Magazine as well as seven …
Truecaller Users’ Phone Numbers & Email IDs For Sale on Dark Web. Truecaller Number Search App: The caller ID company with more than millions of users in India caters to mobile …
In May–June 2019, U.S. Customs and Border Protection (CBP) experienced a major privacy and cybersecurity incident involving the unauthorized exposure of traveler facial recognition …
Cyber-attack affects over 460,000 online store accounts. The compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase …
German IT Firm CITYCOMP Data Breach Directly Affected Major Companies. Threat actors disclosed lots of financial data belonging to big firms online. The hacker gathered this data …
ASUS WebStorage abused to spy on users at the router level. Vulnerable software is potentially facilitating surveillance and data theft. The ASUS WebStorage system is being …
In May 2019, Cable ONE (now Sparklight), a US cable television and internet provider headquartered in Phoenix, Arizona, discovered that an unauthorized individual had gained access …
On 25 April 2019, Docker discovered unauthorized access to a Docker Hub database containing data for approximately 190,000 accounts (less than 5% of Hub users). Docker Hub is the …
PrismRBS is a subsidiary of Nebraska Book Company that operates PrismWeb, a white-label e-commerce platform specifically designed for college and university campus bookstores. In …
In June 2019, Westpac Bank disclosed that attackers had exploited its PayID lookup service to harvest the names and phone numbers of approximately 98,000 Australian banking …
In April–May 2019, security researchers Noam Rotem and Ran Locar discovered an unsecured Elasticsearch database belonging to Apptium Technologies, a third-party vendor that managed …
On March 22-23, 2019, Paige Thompson (alias 'erratic'), a former AWS software engineer, exploited a misconfigured AWS Web Application Firewall (WAF) running on Capital One's EC2 …
LockerGoga ransomware struck Norsk Hydro, one of the world's largest aluminium producers, on March 19 2019. The attack spread across 22,000 computers in 40 countries, encrypting …
On March 14, 2019, unauthorized parties used credential stuffing techniques — using phone numbers as usernames combined with account PINs — to access an unknown number of Boost …
Rush data breach exposes 45,000 patients. Patient names, addresses, Social Security numbers, birth dates and health insurance information were compromised, the health system says. …
Error: 404. …
Hacking, gone off the rails: Holiday travelers react to data breach · TechNode. We went to Beijing’s busiest train stations to ask travelers about the recent ticket-platform …
In early 2019, Medibank Private experienced an earlier, smaller breach via a third-party vendor that accessed customer data without authorisation. This breach predated the much …
In March 2019, security researchers Bob Diachenko and Vinny Troia discovered a massive publicly accessible Elasticsearch database belonging to Verifications.io — an email …
In late May 2020, researchers at vpnMentor discovered that CSC e-Governance Services Ltd — the government-mandated third party operating the merchant onboarding portal for India's …
In January 2019, security researcher Noam Rotem discovered a critical vulnerability in the Amadeus Global Distribution System (GDS) that exposed passenger reservation data for …
In June 2022, Canada's Office of the Privacy Commissioner (OPC), together with privacy commissioners from Alberta, British Columbia, and Quebec, published findings of a joint …
In early 2019, attackers exploited a feature in Facebook's contact import tool that allowed them to upload large lists of phone numbers and identify which were linked to Facebook …
In March 2024, AT&T confirmed that a dataset containing personal information on approximately 73 million people (7.6 million current and 65.4 million former AT&T customers) had …
Millions of bank loan and mortgage documents have leaked online | TechCrunch. A trove of more than 24 million financial and banking documents, representing tens of thousands of …
Third-party company: Click2Gov.
Magecart Delivered Via Advertising Supply Chain. We detected a significant increase in activity from one of the web skimmer groups we’ve been tracking.We found their malicious …
Custom404 • Hanover County, VA • CivicEngage. This website is AudioEye enabled and is being optimized for accessibility. To open the AudioEye Toolbar, press "shift + =". Some …
Humana has notified customers of a third-party security incident that might have exposed some of their personal information. According to a breach notification letter obtained by …
LocalBitcoins blames security breach on forum 'third-party software'. Hackers appears to have stolen $28,200 from users' accounts after phishing login credentials and 2FA one-time …
Between June 2018 and November 2018 (disclosed March 2019), attackers compromised ASUS's software build and signing infrastructure to inject a backdoor into the ASUS Live Update …
In January 2019, the PHP PEAR (PHP Extension and Application Repository) team announced that the official pear.php.net web server had been compromised by an unknown attacker who …
Georgia Institute of Technology disclosed on April 2 2019 that an unknown external actor had exploited a vulnerability in a web application to access a central data warehouse …
On 3 December 2018, Quora — the popular question-and-answer platform with approximately 300 million monthly unique visitors — disclosed that an unknown attacker had accessed data …
Page not found - Baylor Scott & White Medical Center – Frisco. Baylor Scott & White Medical Center – Frisco is a hospital in which physicians have an ownership or investment …
As many as 6,000 people may be affected by data breach in Saint John parking ticket system. The third-party software product Click2Gov, run by CentralSquare Technologies, was …
Microsoft Word - Redwood-AG Notification - California 4848-2006-9506 v.1. > ARIZONA •CALIFORNIA •COLORADO •CONNECTICUT •FLORIDA •GEORGIA •ILLINOIS •INDIANA •KANSAS •KENTUCKY …
In late November and early December 2018, a sophisticated supply chain attack targeting Chinese internet users emerged, exploiting Easy Programming Language (EPL, also known as …
On November 3, 2018, attackers compromised the StatCounter web analytics platform — used by hundreds of thousands of websites worldwide — and modified the StatCounter JavaScript …
Sophos News - The Sophos Blog. .svg?width=185&quality=80&format=auto&cache=true&immutable=true&cache-control=max-age%3D31536000). Sophos Insights LLM AI Exploit vulnerability …
City of Bakersfield announces data breach from hacked Click2Gov system. The city of Bakersfield has reported that a “cyber-security incident” may have compromised the personal and …
Listen on DAB+ radio, smart speaker, app and the YorkMix website - news, things to do and music worth sharing across York & North Yorkshire. York man jailed for attempted murder …
ECRMC warns job applicants of data breach. **Get unlimited access with our Fair Special - Digital Access Subscription.** Read our E-Edition, the digital replica of the print …
Bitdefender Cybersecurity Blogs: News, Views and Insights. [](http://hotforsecurity.bitdefender.com/ "Bitdefender")For HomeFor BusinessFor Partners. Third-party company: …
Shortly after the Ontario Cannabis Store (OCS) launched online sales following the legalization of recreational cannabis in Canada on October 17, 2018, a data breach was disclosed …
Australia's Defence department was badly exposed to China's hackers. The hackers are understood to have used procurement interfaces and email contact between contractors and …
Image-I-Nation Technologies, Inc. is a technology and hosting company that provides background screening software and data services to consumer reporting agencies (CRAs). In late …
In late October 2018, Dunkin Donuts — one of the world's largest coffee and baked goods chains — suffered a credential stuffing attack against its DD Perks loyalty rewards program. …
In October 2018, Nordstrom discovered that a contract worker had improperly handled employee personal data, resulting in the potential exposure of sensitive HR and payroll …
Microsoft Defender Threat Intelligence | Microsoft Security. Protect your organization today from modern cyberthreats and exposure with Microsoft Defender Threat Intelligence, a …
The Software Side of China’s Supply Chain Attack. Bloomberg the Company & Its Products The Company & its ProductsBloomberg Terminal Demo RequestBloomberg Anywhere Remote Login …
Another Click2Gov data breach hits Indio, California | StateScoop. The online bill payment software used by hundreds of local governments continues to be a frequent source of …
Vesta control panel servers infected with DDoS malware after supply chain attack. An open-source hosting panel software provider, Vesta Control Panel (VestaCP), has admitted that …
On September 30, 2018, during the UK Conservative Party's annual conference in Birmingham, a serious security vulnerability in the official conference mobile application was …
On the afternoon of September 25, 2018, Facebook's engineering team discovered an active attack exploiting a critical vulnerability in the platform's "View As" feature — a privacy …
Atrium Health, a major Charlotte, North Carolina hospital network, suffered a significant data breach affecting 2,650,000 patients through its billing services vendor AccuDoc …
In September 2018, an unknown attacker using the account 'right9ctrl' approached the original maintainer of the popular Node.js npm package 'event-stream' (dominictarr) and …
BlackKite timeline indicates a third-party/vendor-related breach; detailed reporting was not accessible automatically.
Feedify cloud service architecture compromised by MageCart crime gang. MageCart cyber gang compromised the cloud service firm Feedify and stole payment card data from customers of …
Foosackly's reports payment-card data breach. Mobile-based chicken-finger chain Foosackly's is warning customers of a data breach in its payment system. According to information …
In September 2018, The Perth Mint — the government-owned precious metals enterprise operated by the Government of Western Australia — disclosed a data breach affecting customers of …
WCSD addresses concerns over data breach. The Washoe County School District Board of Trustees has a message for parents: personal student information has not been compromised. …
Third-party company: Health Fitness Corp.
Third-party company: Invermar.
Wolverine Solutions Group (WSG) is a Detroit, Michigan-based company that provides mailing, printing, and administrative services to hospitals and healthcare organisations — …
On August 24, 2018, cybersecurity researchers at UpGuard discovered a publicly accessible, misconfigured Amazon Web Services S3 storage bucket belonging to MedCall Healthcare …
Between August 22 and 24, 2018, Air Canada detected unusual login behaviour on its smartphone mobile application and moved quickly to lock all 1.7 million app user accounts as a …
Between 21 August and 5 September 2018, a Magecart Group 6 skimmer silently exfiltrated payment card details from approximately 500,000 British Airways customers who purchased …
The British Airways Magecart breach of 2018 is one of the most technically documented payment card skimming attacks on record and led to a landmark GDPR enforcement action. The …
On 20 August 2018, T-Mobile detected and shut down an attack that exploited a vulnerability in T-Mobile's API, exposing account data for approximately 2 million customers. T-Mobile …
On August 11 and 13, 2018, Cosmos Co-operative Bank Ltd. of Pune, India — one of India's oldest cooperative banks — suffered a sophisticated two-weekend ATM cashout operation …
BevMo, a California-based alcohol retail chain, disclosed in late 2018 that its e-commerce website had been compromised by a payment card skimming attack affecting 14,579 …
Between August 1, 2018 and March 30, 2019, the web payment portal of American Medical Collection Agency (AMCA) — a third-party medical debt collections company — was compromised by …
Telemedicine vendor breaches the data of 2.4 million patients in Mexico. A configuration error left a database filled with healthcare data exposed on the internet, and the data …
In August 2018, KrebsOnSecurity reported a significant security flaw in Fiserv's web banking platform that exposed personal and financial details of customers at hundreds of …
Media monitoring app Mention suffers third-party data breach. Web and social media monitoring app Mention has revealed that a third-party provider has been hit by a data breach. …
Operation Red Signature Targets South Korean Companies. We uncovered Operation Red Signature, an information theft-driven supply chain attack targeting organizations in South …
American Medical Collection Agency (AMCA), a major third-party billing and collections vendor for US healthcare laboratories, suffered a long-running breach of its web payment …
OPKO Health's clinical laboratory subsidiary BioReference Laboratories was among the first wave of healthcare companies to disclose patient data exposure resulting from the …
The American Medical Collection Agency (AMCA) breach is the largest healthcare data breach reported in the United States in 2019, ultimately exposing the personal, financial, and …
As the American Medical Collection Agency (AMCA) breach continued to unfold through July 2019, a second wave of laboratory companies came forward to disclose patient data exposure. …
Clinical Pathology Laboratories (CPL), an Austin, Texas-based clinical testing company, disclosed on July 17, 2019 that approximately 2.2 million of its patients had personal and …
Managed Health Services of Indiana (MHS), which administers Indiana's Hoosier Healthwise and Hoosier Care Connect Medicaid managed care programs, disclosed in December 2018 that …
On 14 July 2018, LabCorp — one of the world's largest clinical laboratory networks, processing approximately 2.5 million patient specimens per week — suffered a SamSam ransomware …
On 4 July 2018 (US Independence Day), an attacker used a compromised cloud environment credential — which lacked multi-factor authentication — to access Timehop's production cloud …
On October 12, 2018, the US Department of Defense disclosed that a data breach at an unnamed commercial contractor had exposed travel records — including personal information and …
On June 28, 2018, the Central Bank of the Bahamas was made aware of unauthorized access to its external-facing public website. The bank's investigation confirmed that the breach …
Between 27 June and 4 July 2018, attackers exfiltrated personal data of 1.495 million patients from SingHealth's Sunrise Clinical Manager outpatient database — approximately 25% of …
On June 19, 2018, researchers from UpGuard's Cyber Risk Team discovered a publicly accessible Amazon S3 bucket named "abbottgodaddy" that contained sensitive configuration and …
On August 1, 2018, Reddit disclosed a security incident in which an attacker compromised several Reddit employee accounts at the company's cloud and source code hosting providers …
Between June 14 and June 18, 2018, an attacker compromised several Reddit employee accounts at the company's cloud hosting and source code hosting providers by intercepting …
Flipboard — the popular social news aggregation app — disclosed on 28 May 2019 that it had suffered two separate periods of unauthorized access to its databases. The first period …
BenefitMall (operating as Centerstone Insurance and Financial Services) is a national provider of payroll, employee benefits administration, and HR services whose clients include …
Security researcher Vinnie Troia discovered in June 2018 that Exactis, a Florida-based data broker and marketing aggregation company, had left a 2-terabyte Elasticsearch database …
On May 30, 2018, security researcher Bob Diachenko of Kromtech Security Center discovered an Apache Airflow server belonging to Agilisium, a cloud data contractor for Universal …
On May 24, 2018, Banco de Chile — Chile's largest bank — suffered a sophisticated coordinated attack combining a destructive cyber operation with financial fraud. Attackers …
In June 2018, Whitbread plc -- the parent company of Costa Coffee, Premier Inn, Brewers Fayre, Beefeater, and other UK hospitality chains -- disclosed that personal data of job …
Houzz is a leading home design and renovation platform with tens of millions of registered users worldwide. In early 2019, the company disclosed that it had suffered a significant …
In May 2018, PageUp People — a Melbourne-based HR and recruitment software company with clients across Australia, UK, US, Canada, and other countries — discovered unusual activity …
On June 1, 2018, PageUp — an Australian HR software company whose recruitment platform is used by over 100 Australian and international enterprises — disclosed that it had detected …
Corporation Service Company (CSC), a major provider of domain registration, corporate compliance, and agent-for-service-of-process services to Fortune 500 companies and other …
In April 2018, Chegg, an American education technology company, suffered a data breach when a contract worker used Chegg's AWS root account credentials — which had been shared …
UnityPoint Health, a major Iowa-based health system operating 32 hospitals and 280+ clinics across Iowa, Illinois, and Wisconsin, suffered two phishing-related breaches in 2018. …
In March and May 2018, UnityPoint Health — a major Iowa-based health system operating approximately 32 hospitals and 280 clinics in Iowa, Illinois, and Wisconsin — suffered two …
In March 2018, an attacker accessed Cathay Pacific's IT systems and obtained data for approximately 9.4 million passengers — one of the largest aviation data breaches ever. Cathay …
Brinker International, the parent company operating over 1,600 Chili's Grill and Bar restaurants worldwide, disclosed a payment card data breach on May 12, 2018, one day after …
In October 2019, NordVPN disclosed that one of its rented servers at a datacenter in Finland had been accessed without authorization. The actual breach occurred in March 2018 — …
In February 2018, the LA Times' Homicide Report website was discovered to be running Coinhive cryptocurrency mining code injected by attackers who had exploited a publicly writable …
In February 2018, an unauthorized party obtained data from approximately 150 million MyFitnessPal user accounts. Under Armour, which had acquired MyFitnessPal in 2015 for $475 …
From approximately February to June 2018, Magecart Group 5 skimmed payment card data from Ticketmaster UK customers by compromising Inbenta Technologies — a third-party customer …
On January 18, 2018, Allscripts Healthcare Solutions — one of the largest electronic health record (EHR) vendors in the United States, serving more than 45,000 physician practices …
On 18 January 2018, SamSam ransomware attackers encrypted systems at Allscripts Healthcare Solutions data centers, taking offline cloud-hosted electronic health record (EHR) and …
In April 2026, German Federal Criminal Police (BKA — Bundeskriminalamt) announced that it had, in conjunction with international law enforcement partners, identified and publicly …
HealthEngine, Australia's largest health appointment booking platform with over 17 million users across approximately 60,000 healthcare practices, was found by Australian …
Western Union disclosed in early 2018 that customer information had been accessed without authorization through a computer intrusion targeting an external vendor system formerly …
On January 17, 2019, Troy Hunt (creator of HaveIBeenPwned) disclosed 'Collection #1' — an 87GB aggregated credential dump that had appeared on MEGA cloud storage and hacking …
Klook, a Hong Kong-based travel activities and services booking platform, disclosed on June 29, 2018 that it had suffered a data breach through a compromised third-party web …
On December 6, 2017, NiceHash — a platform where users sell their computing power for cryptocurrency mining — halted operations after discovering that its internal payment system …
Orlando Orthopaedic Center reported a breach of 19,101 patient records caused by an error made by its third-party transcription service provider during a software upgrade in …
RMH Franchise Holdings, one of the largest Applebee's franchise operators in the United States, discovered malware on point-of-sale systems at its restaurants on February 13, 2018, …
On June 28, 2018, UC San Diego Health disclosed that 619 of its patients were affected by a data breach at Nuance Communications, a third-party medical transcription service …
In October 2017, Domino's Australia customers began receiving targeted spam and phishing emails that addressed them by first name and referenced their local suburb, suggesting the …
Between late 2017 and late 2018, at least 46 US cities were compromised through vulnerabilities in Click2Gov, a self-service bill payment portal used by municipalities for utility …
Imperva, a cybersecurity company providing cloud-based web application firewall (WAF) and DDoS protection services, disclosed in August 2019 that a data breach had exposed customer …
Between September 27 and October 12, 2017, an unauthorized third party gained access to [24]7.ai's online customer service chat platform and injected malicious code designed to …
Between mid-August and 12 September 2017, Piriform (a subsidiary of Avast Security) distributed a backdoored version of CCleaner 5.33 — a widely used Windows PC cleaning utility — …
In June 2018, Ticketmaster disclosed that malicious code had been found within a customer support chatbot function on its websites, hosted by third-party AI company Inbenta …
In August 2017, security researcher Dylan Houlihan discovered that Panera Bread's website had an unauthenticated API endpoint at panerabread.com that returned customer records in …
Huddle House is a family-style restaurant chain headquartered in Atlanta, Georgia, with approximately 400 corporate and franchisee locations primarily across the southeastern …
In late July/early August 2017, a hacker exfiltrated approximately 1.5 terabytes of data from HBO's internal systems including unreleased episodes of Game of Thrones (the most …
In late July 2017, Aetna mailed letters to approximately 11,887 members nationwide regarding a court-ordered change to HIV prescription coverage policy (members were being notified …
In July 2017, Kaspersky Lab researchers discovered that NetSarang Computer's server management software suite — used by hundreds of large enterprises globally for SSH, telnet, and …
On June 27, 2017, the NotPetya cyberattack struck, becoming one of the most destructive and costly cyberattacks in history with estimated global damages exceeding $10 billion. The …
On June 27, 2017, Russian military intelligence (GRU Unit 74455 / Sandworm) deployed NotPetya — a destructive wiper disguised as ransomware — by trojanizing the automatic update …
On June 23–24, 2017, an unknown attacker conducted a sustained brute-force attack against the UK Parliament's Outlook Web Access (OWA) email portal at Westminster. Parliament's IT …
On June 8, 2017, UpGuard cyber risk analyst Chris Vickery discovered a publicly accessible Amazon S3 storage bucket owned and operated by NICE Systems, an Israeli telephonic …
In June 2017, UpGuard cybersecurity researcher Chris Vickery discovered an Amazon S3 bucket belonging to Deep Root Analytics — a data analytics firm that had been contracted by the …
On June 12, 2017, UpGuard cyber risk analyst Chris Vickery discovered a publicly accessible Amazon S3 cloud storage bucket containing approximately 1.1 terabytes of data on 198 …
In July 2017, UpGuard security researchers discovered that NICE Systems — an enterprise software company contracted by Verizon to manage call center quality assurance — had left an …
TRITON (also known as TRISIS and HatMan) is the world's first known malware specifically designed to attack industrial Safety Instrumented Systems (SIS) — the last line of …
On 31 May 2017, OneLogin — an enterprise single sign-on and identity management provider serving approximately 2,000 enterprise customers — suffered a breach in which an attacker …
On 17-18 May 2017, Zomato — India's largest food delivery and restaurant discovery platform, operating in 24 countries with approximately 120 million monthly visitors — disclosed …
Between May 13 and July 30, 2017, attackers exploited a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) to breach Equifax, one of the three major US …
On May 12, 2017, WannaCry — a self-propagating ransomware worm — began spreading globally, infecting approximately 230,000 systems in 150+ countries within 24 hours. WannaCry …
On 12 May 2017, WannaCry ransomware caused the most significant cyberattack on the UK National Health Service in history. Of the 236 NHS Trusts in England, 80 were affected — about …
An unnamed hacker breached Bell Canada in May 2017 and exfiltrated data on approximately 1.9 million active and former customer accounts, including names, email addresses, phone …
Between May 2017 and March 2018, the FIN7 cybercriminal group (operating the JokerStash carding shop) compromised point-of-sale systems at all Saks Fifth Avenue and Lord & Taylor …
Between 2-6 May 2017, attackers compromised one of HandBrake's macOS download mirror servers and replaced the legitimate HandBrake installer with a trojanized version containing …
Between approximately May 2017 and March 2018 (approximately 10 months), the FIN7 cybercriminal organization's Joker's Stash carding marketplace operators deployed POS malware …
Between April 3 and November 18, 2017, point-of-sale malware infected payment systems at an undisclosed number of Forever 21 retail stores across the United States. The breach …
Between approximately April 3 and November 18, 2017 (~7 months), POS malware infected Forever 21 retail store locations in the United States. Forever 21 issued an initial public …
In April 2017, Wonga Finance — the UK's largest payday loan company at its peak, with approximately 1 million UK customers — suffered a data breach affecting approximately 270,000 …
Between 24 March and 18 April 2017, attackers installed malware on point-of-sale systems at most Chipotle Mexican Grill restaurant locations in the United States. The malware …
Between March 24 and April 18, 2017, POS malware infected the majority of approximately 2,250 Chipotle Mexican Grill restaurant locations across 47 U.S. states and Washington D.C., …
Between March 18 and July 2, 2017, point-of-sale malware infected front desk payment systems at 41 Hyatt Hotels properties across 11 countries. The malware was capable of capturing …
Apache disclosed CVE-2017-5638 March 7 2017 and patched same day. Equifax security scans failed to identify the vulnerable system. Attackers exploited Apache Struts flaw in …
First American Financial Corporation, one of the largest title insurance and real estate settlement services providers in the United States, had an IDOR (Insecure Direct Object …
India's Aadhaar national biometric identity system — which stores fingerprint and iris scan data for approximately 1.2 billion Indian citizens and links to bank accounts, mobile …
A Desjardins Group employee with legitimate access to member data exfiltrated personal information of members over approximately 26 months (from early 2017 to March 2019) and …
Desjardins Group, Canada's largest federation of credit unions with over 7 million members, disclosed in June 2019 that a malicious insider (a now-former employee) had been …
GoodRx, the US prescription drug discount platform with approximately 55 million users, disclosed its use of third-party advertising trackers in 2023 when the FTC took enforcement …
GoodRx, a health technology company offering prescription drug discount coupons and telehealth services, shared sensitive user health data with Facebook/Meta, Google, Criteo, …
In September 2017, security journalist Brian Krebs reported that a large batch of approximately 5 million stolen payment cards linked to Sonic Drive-In locations had appeared on …
In the final hours before France's legally mandated media blackout ahead of the May 7, 2017 presidential election runoff, approximately 9GB of documents and emails allegedly stolen …
On December 22, 2016, an unauthorized individual gained access to electronic files stored on computer systems maintained by a third-party vendor that provided patient management …
On December 17, 2016, exactly one year after the first Ukraine power grid attack (BlackEnergy 2015), Russian military intelligence (GRU Sandworm team) deployed Industroyer against …
In November 2016, Three Mobile UK — one of the UK's major mobile network operators — disclosed a breach of its customer upgrade system. Fraudsters used compromised employee login …
In October 2019, Zendesk — a major customer service software platform used by over 145,000 organizations — disclosed a security breach that affected customer accounts created …
In October 2016, a contractor responsible for building Australian Red Cross Blood Service's donor portal accidentally included a 1.74 GB SQL database backup file in a publicly …
On 25 October 2016, a file named 'donorquestionnaire.bak' containing registration data for 550,000 blood donors was inadvertently left in a publicly accessible directory on the …
Between approximately October 25, 2016 and January 19, 2017, POS malware infected corporate-owned Arby's restaurant locations across the United States. Franchise locations were not …
On December 6, 2016, data breach tracking service LeakedSource reported that a dataset containing 85.2 million Dailymotion user records had been offered for sale and contained data …
In October 2016, two hackers used credential stuffing to access Uber engineers' private GitHub repositories, leveraging passwords exposed in previous data breaches. Uber did not …
FriendFinder Networks, the operator of adult dating websites, suffered a breach that exposed approximately 412 million accounts across six properties including …
An attacker compromised a single Deloitte administrator account that lacked multi-factor authentication, granting access to Deloitte's global email server hosted on Microsoft …
Attackers found Uber AWS credentials in GitHub and downloaded data affecting 57M users and drivers (names, emails, phone numbers; 600K US driver license numbers). Uber CSO Joe …
In October-November 2016, two attackers discovered that Uber's private GitHub code repository contained hardcoded AWS credentials. Using those credentials, they accessed an AWS S3 …
LifeBridge Health, a Maryland-based health system operating Sinai Hospital, Northwest Hospital, Levindale Hebrew Geriatric Center, and other facilities, disclosed in May 2018 that …
On 22 September 2016, Cloudflare deployed a change to its HTML parsing pipeline that introduced a buffer overread bug (named 'Cloudbleed' by researcher Tavis Ormandy, in reference …
Between August 28, 2016, and January 14, 2017, the Diamond Institute for Infertility and Menopause, a fertility clinic based in Millburn, New Jersey, suffered repeated unauthorized …
Between August 2016 and April 2017, a group known as 'The Shadow Brokers' released staged leaks of what they claimed were NSA cyberweapon repositories stolen from the NSA's elite …
Between 10 August 2016 and 9 March 2017, an unauthorized actor gained access to Sabre Corporation's SynXis Central Reservations (CR) hospitality technology system — a hotel …
Between August 10, 2016, and March 9, 2017, an unauthorized party gained access to Sabre Corporation's SynXis central-reservations system, a widely used platform that processes …
Between approximately August 10, 2016 and March 9, 2017, an attacker used a compromised administrator account in Sabre Corporation's SynXis Hospitality Solutions central …
On August 2, 2016, Bitfinex — at the time the world's largest USD-denominated Bitcoin exchange — announced that 119,756 BTC had been stolen from customer accounts, worth …
Between approximately August 1 and December 29, 2016, POS malware was deployed at IHG franchise hotel properties across the United States and Puerto Rico. IHG (InterContinental …
On July 7-8, 2016, DataDog, a cloud monitoring and analytics platform, detected unauthorized access to its internal systems and discovered that AWS access keys had been exposed. …
Beginning in mid-2016, a cybercriminal group calling themselves 'The Dark Overlord' (TDO) conducted a sustained campaign of healthcare data theft and extortion against multiple US …
In mid-2016, the Carbanak/Anunak cybercriminal gang — responsible for stealing over $1 billion from banks globally through sophisticated malware campaigns — breached Oracle's …
Between 23 June and 7 July 2016, attackers first compromised Banner Health's point-of-sale (POS) systems at food and beverage outlets within Banner Health facilities, using …
Banner Health, a Phoenix, Arizona-based nonprofit hospital system operating 28 hospitals and numerous clinics across seven western states, disclosed on August 3, 2016 that it had …
Newkirk Products, Inc., a New York-based company that printed and mailed health plan identification cards on behalf of multiple Blue Cross Blue Shield (BCBS) plans, disclosed a …
On 11 May 2016, an unauthorized party gained access to a server maintained by Newkirk Products, Inc. — a company that prints and mails health insurance identification cards for …
On 27 March 2016, hacktivist group LulzSec Pilipinas defaced and dumped the Philippines Commission on Elections (COMELEC) entire voter database — weeks before the 9 May 2016 …
Beginning in March 2016, Russian military intelligence operatives from GRU Unit 26165 (Fancy Bear/APT28) and Unit 74455 (Sandworm) conducted a comprehensive hacking campaign …
In 2016, two separate Russian GRU units conducted coordinated cyber intrusions against the Democratic Party and Clinton presidential campaign. APT29 (GRU Unit 29155 / Cozy Bear) …
On 26 February 2016, a Snapchat payroll department employee received an email purportedly from CEO Evan Spiegel requesting payroll information for employees. The employee complied …
On the night of February 4–5, 2016, Lazarus Group (North Korean state-sponsored hackers) submitted 35 fraudulent SWIFT transfer instructions from Bangladesh Bank's account at the …
In February 2016, North Korea's Lazarus Group executed the most audacious central bank heist in history by compromising Bangladesh Bank's SWIFT messaging system and fraudulently …
In February 2016, Weebly — a popular drag-and-drop website builder platform serving approximately 40 million users and 625,000 paying customers — suffered a data breach. The breach …
On January 7, 2016, Centene Corporation — one of the largest Medicaid-focused managed care organizations in the United States, operating health plans in over 25 states — discovered …
In early 2016, Lifeboat — one of the most popular Minecraft Pocket Edition server networks with over 3 million registered accounts — was breached. The breach affected approximately …
In early 2016, Verizon Enterprise Solutions — the business division of Verizon that provides managed network services to Fortune 500 companies and government agencies — suffered a …
Vitagene, a consumer DNA and ancestry testing company, left Amazon S3 buckets containing raw genetic data files, health reports, and personal information for customers publicly …
FASTCash was a multi-year North Korean state-sponsored campaign (2016–ongoing) targeting bank payment switch servers — the AIX-based systems that approve or decline ATM …
On December 23, 2015, coordinated cyberattacks against three Ukrainian electricity distribution companies — Prykarpattyaoblenergo, Chernivtsioblenergo, and Kyivoblenergo — caused …
On 14 November 2015, a hacker breached VTech's Learning Lodge — the app store and content platform for the company's range of children's electronic learning tablets and toys. VTech …
On 21 October 2015, TalkTalk — one of the UK's largest broadband and telecoms providers serving approximately 4 million customers — was attacked by a group of teenagers who …
In October 2015, an unknown attacker compromised the patient database of 21st Century Oncology Holdings — the largest radiation oncology treatment chain in the United States, …
21st Century Oncology, the largest integrated cancer care provider in the United States at the time (operating 180+ locations in 17 states plus international), suffered a database …
Between October 2015 and mid-2016, a sophisticated POS malware attack — attributed to the Carbanak/Anunak criminal group — affected point-of-sale systems at 1,025 Wendy's franchise …
Between approximately fall 2015 and spring 2016, POS malware was deployed at Wendy's franchise restaurant locations in the United States. Wendy's first disclosed the breach in May …
In September 2015, Experian — a major US credit bureau — suffered a breach of a server it operated on behalf of T-Mobile for processing mobile phone service credit applications. …
On October 1, 2015, Experian disclosed that hackers had gained unauthorized access to a server containing personal information of approximately 15 million people who had applied …
Between approximately August 13 and December 8, 2015, POS malware infected payment processing systems at 250 Hyatt-managed hotels across 50 countries, including 100 hotels in 26 …
On July 12, 2015, a hacking group calling themselves 'Impact Team' notified Ashley Madison (a dating website for married people seeking affairs, operated by Avid Life Media) that …
On 5 July 2015, Hacking Team — an Italian cybersecurity company that sold offensive surveillance software (Remote Control System, branded 'Galileo') to governments and law …
On 12 June 2015, LastPass — one of the world's most widely used password managers with tens of millions of users — discovered that its network had been compromised and that user …
In June and July 2015, attackers compromised servers operated by PNI Digital Media, a Canadian company (subsidiary of Staples) that provided online photo printing and processing …
Between 7 and 26 May 2015, an attacker accessed Medical Informatics Engineering's (MIE) WebChart EHR cloud server using compromised credentials. MIE is a health information …
Between approximately April and May 2015, Russian military intelligence (GRU) APT28 (Fancy Bear) conducted a sophisticated intrusion into the German Federal Parliament (Bundestag) …
In May 2015, Sally Beauty Holdings disclosed its second payment card breach in approximately one year. The beauty supply retailer discovered unauthorized access to payment card …
On January 12, 2015, individuals calling themselves 'CyberCaliphate' and claiming affiliation with the Islamic State (ISIS) hijacked the official Twitter and YouTube accounts of …
Between January and May 2015, sophisticated cybercriminals exploited the IRS 'Get Transcript' web application to access prior-year tax return transcripts for over 100,000 …
Between January and May 2015, a sophisticated crime ring accessed the IRS's 'Get Transcript' online application — which allowed taxpayers to retrieve prior-year tax returns — and …
On April 9, 2015, TV5Monde — France's international television network broadcasting to 200 million people in 160 countries — had all 11 of its TV channels knocked off the air …
Anthem (now Elevance Health), the second-largest US health insurer, disclosed in February 2015 that attackers had gained access to its enterprise data warehouse and exfiltrated …
In late 2014, Morgan Stanley financial advisor Galen Marsh used his authorized access to the firm's internal systems to download account information for approximately 350,000 …
On November 24, 2014, attackers identifying themselves as 'Guardians of Peace' (GOP) deployed the Destover destructive wiper malware across Sony Pictures' corporate network, wiping …
In November 2014, BrowserStack, a cloud-based browser and device testing platform, suffered a breach when an attacker discovered a forgotten, active AWS access key that had been …
In late 2014, Russian state-sponsored hackers breached the U.S. State Department's unclassified email system (SBU — Sensitive But Unclassified network), gaining persistent access …
In September 2014, a sophisticated cyberattacker accessed portions of the UCLA Health network containing protected health information. UCLA Health — one of California's largest …
UCLA Health, one of the leading academic medical centers in the United States, disclosed in July 2015 that attackers had accessed parts of its network containing personal and …
On October 10, 2014, Sears Holdings announced that Kmart stores had been the victim of a data breach involving malware installed on point-of-sale systems. The company stated that …
Hacker collective NullCrew claimed responsibility for a breach of Bell Canada, Canada's largest telecom, disclosed August 28 2014. Approximately 1.9 million email addresses and …
The Marriott/Starwood breach is one of the largest data breaches in history and a landmark case study in the risks of inheriting a compromised IT environment through corporate …
K Box Entertainment Group — a Singapore-based karaoke chain with approximately 25 outlets — suffered a breach of its customer membership database in 2014, exposing data for …
The 2015 OPM breach is widely regarded as the most damaging government data breach in U.S. history. Chinese state-sponsored hackers (APT10/Deep Panda) used credentials stolen from …
In a letter to both current and former employees, Lowe’s says that personal information might have been compromised after a third-party vendor exposed it to the public. In a letter …
Code Spaces was a code hosting and project management platform (similar to GitHub) that operated entirely on AWS. On June 17, 2014, an attacker gained access to Code Spaces' AWS …
In June 2014, hacker group Rex Mundi announced they had stolen approximately 592,000 customer records from Domino's Pizza's online ordering systems in Belgium and France. Rex Mundi …
In June 2014, a sophisticated cyberattacker — assessed by Mandiant as the same China-linked group responsible for the Anthem (February 2015) and Premera Blue Cross (March 2015) …
In June 2014, Rex Mundi — a cybercriminal extortion group known for targeting European companies — compromised Domino's Pizza France and Belgium's online ordering systems and …
Between June and August 2014, a sophisticated attack attributed to a Russian cybercriminal group compromised JPMorgan Chase's internal network, gaining access to data for 76 …
In June 2014, a sophisticated hacking group breached JPMorgan Chase's network and maintained access until it was discovered approximately in August 2014. The attackers accessed …
CareFirst BlueCross BlueShield, the dominant health insurer for the Washington D.C./Maryland/Virginia region, disclosed on May 20, 2015 that approximately 1.1 million members had …
In June 2014, attackers compromised a JPMorgan Chase employee's personal computer and obtained login credentials, which they used to gain initial access to the bank's corporate …
In May 2014, a third party accessed an Uber software engineer's private GitHub repository that contained AWS credentials stored in code. Using these credentials, the attacker …
On 5 May 2014, attackers believed to be a Chinese APT group (assessed as Winnti/APT41) gained access to Premera Blue Cross's network via a spear-phishing attack. The attackers …
Premera Blue Cross, one of the largest health insurance carriers in the Pacific Northwest, disclosed in March 2015 that attackers had gained access to its IT systems beginning May …
CVE-2014-0160 (Heartbleed) was a critical vulnerability in OpenSSL's TLS/DTLS heartbeat extension, introduced in OpenSSL 1.0.1 (released March 2012) and present in all versions …
Between April and June 2014, a China-linked APT group (assessed as APT18/Wekby by Mandiant, who CHS hired to investigate) compromised Community Health Systems (CHS) — at the time …
Between April and September 2014, POS malware infected point-of-sale systems at 115 Staples store locations across the United States. The breach resulted in approximately 1.16 …
Between approximately April and June 2014, APT18 (also known as Dynamite Panda, Threat Group-0416, or Wekby), a Chinese state-linked advanced persistent threat group attributed by …
Between April and September 2014, attackers used stolen credentials belonging to a third-party Home Depot vendor to gain initial access to the retailer's network. They exploited an …
Between approximately April and September 2014, attackers deployed POS malware at Staples retail stores across the eastern United States. Staples first acknowledged an …
Boston Medical Center said it has fired a transcription service after a health care provider reported that the medical records of about 15,000 patients at the hospital were posted …
The OPM breach disclosed in June 2015 actually comprised two distinct intrusions. This earlier intrusion — dating to approximately March 2014 or possibly as early as late 2013 — …
On February 18, 2014, the University of Maryland suffered a data breach in which attackers accessed a database containing records for 309,079 faculty, staff, and students who had …
On February 12, 2014, Kickstarter was notified by law enforcement that its database had been accessed by unauthorized attackers via a SQL injection vulnerability. Kickstarter …
In early 2014, the Federal Aviation Administration (FAA) suffered an unauthorized intrusion into an agency computer system that contained personally identifiable information for …
In approximately February-March 2014, attackers compromised the credentials of a small number of eBay corporate employees and used those credentials to access the company's …
In early 2014, Andrew Skelton — a senior IT auditor at Morrisons, one of the UK's largest supermarket chains — deliberately leaked the personal data of 99,998 Morrisons employees …
Indiana University discovered in May 2014 that files containing Social Security numbers and other personal data for approximately 146,000 current and former students had been …
In November 2014, the U.S. Postal Service disclosed that Chinese government hackers had breached its corporate networks and accessed personnel data for approximately 800,000 …
Chinese state-sponsored hackers (linked to PLA) compromised Starwood Hotels reservation system as early as 2014, 2 years before Marriott acquired Starwood (2016). Breach persisted …
On May 3, 2017, security researcher Bob Diachenko of the Kromtech Security Research Center discovered a massive trove of patient records from Bronx-Lebanon Hospital Center in New …
Mercedes-Benz USA (MBUSA) disclosed on June 11, 2021, that a vendor had inadvertently left sensitive customer and prospective buyer data accessible on a cloud storage platform. The …
In December 2013, a sophisticated cyberattack — widely attributed to a China-linked nation-state APT group believed to be the same threat actor responsible for the Anthem and …
Excellus BlueCross BlueShield, a Rochester, New York-based health insurer covering approximately 3.5 million members in upstate New York, disclosed on September 10, 2015 that …
Attackers phished Fazio Mechanical (HVAC vendor) to steal Target network credentials in Nov 2013. Moved laterally from vendor-accessible HVAC network segment to POS environment due …
Toyota disclosed in May 2023 that vehicle data for 2.15 million Toyota and Lexus customers in Japan had been publicly accessible via a misconfigured cloud environment for …
Toyota Motor Corporation disclosed on May 12, 2023 that vehicle location data and other connected vehicle information for approximately 2.15 million customers in Japan had been …
In November 2013, Cupid Media — an Australian company operating approximately 35 niche online dating websites including ChristianCafe, CatholicMingle, MilfDate, AsianDating, and …
Between approximately November 2013 and April 2014, employees at AT&T's outsourced call centers in Colombia, Mexico, and the Philippines improperly accessed records of …
Last week, Target told reporters at The Wall Street Journal and Reuters that the initial intrusion into its systems was traced back to network credentials that were stolen from a …
Florida Healthy Kids Corporation (FHKC) administers the Florida KidCare health insurance program, providing subsidized health and dental coverage to children across Florida. FHKC …
In October 2015, Scottrade announced that it had been notified by federal law enforcement that its systems had been breached between approximately late 2013 and early 2014. The …
P.F. Chang's China Bistro, a US casual dining restaurant chain, confirmed in June 2014 that its payment systems had been compromised by POS malware for approximately 9 months …
P.F. Chang's China Bistro, a national casual dining restaurant chain, confirmed in June 2014 that it had suffered a payment card breach after KrebsOnSecurity reported that a large …
In October 2013, Adobe disclosed two simultaneous major security incidents: (1) Source code theft: attackers exfiltrated source code for Adobe Acrobat, Adobe Reader, Adobe …
On July 22, 2013, R.T. Jones Capital Equities Management, a St. Louis-based registered investment adviser, discovered that its third-party-hosted web server had been compromised by …
Between approximately July 16, 2013 and October 30, 2013, attackers installed RAM-scraping malware on Neiman Marcus point-of-sale (POS) systems at the luxury retailer's stores. The …
On July 15, 2013, four unencrypted desktop computers were stolen from Advocate Medical Group's administrative offices in Park Ridge, Illinois. The computers contained personal and …
On 15 July 2013, four unencrypted laptops were stolen from an administrative office of Advocate Medical Group — the largest physician practice group in Illinois, associated with …
Yahoo suffered two separate mega-breaches that collectively represent the largest credential theft in internet history. (1) August 2013 breach (disclosed December 2016, revised to …
Between 2013-2015, Aleksandr Kogan (Cambridge University researcher) built a personality quiz app ('This Is Your Digital Life') and used Facebook's Open Graph API to harvest …
Between 8 May 2013 and 27 January 2014, POS malware infected approximately 7.2% of Michaels stores' point-of-sale terminals nationwide, capturing payment card data for …
Michaels Stores, the US arts and crafts retail chain, confirmed in April 2014 that a data breach between May 8, 2013 and January 27, 2014 (approximately 9 months) had compromised …
Michaels Stores, the large arts and crafts retail chain, disclosed in January 2014 that it was investigating a potential data security breach involving payment cards used at its …
In May 2016, a dataset containing 65.5 million Tumblr user email addresses and hashed passwords appeared for sale on dark web markets, offered by the same seller ('peace_of_mind') …
On 26 April 2013, LivingSocial — a daily deals website owned by Amazon — disclosed that attackers had accessed its database containing up to 50 million customer records. Exposed …
In late April 2013, LivingSocial (an online deals and local offers marketplace, then majority-owned by Amazon) suffered a cyberattack in which hackers accessed a database …
In late February 2013, Evernote — the popular note-taking application with approximately 50 million registered users — detected and blocked suspicious activity on its network. The …
Beginning in February 2013, a third-party point-of-sale service provider to Goodwill Industries — C&K Systems, a payment processing vendor — had its systems compromised with …
In November 2017, security researcher Troy Hunt (operator of Have I Been Pwned) notified Imgur that a dataset containing 1.7 million Imgur user email addresses and passwords had …
Prestige Software, a Spain-based hotel channel management platform used by major online travel agencies including Hotels.com, Booking.com, and Expedia, left a misconfigured Amazon …
Schnucks, a regional Midwestern grocery chain headquartered in St. Louis, Missouri, with approximately 100 store locations, disclosed in March 2013 that it had suffered a payment …
Howard University Hospital in Washington, D.C. disclosed in January 2013 that an unencrypted laptop containing information on approximately 34,503 patients had been stolen. The …
In May 2015, Pennsylvania State University disclosed that its College of Engineering computer network had been compromised by two separate sophisticated cyberattacks. One was …
A foreign hacker (attributed to Eastern Europe, never charged) penetrated the South Carolina Department of Revenue via a spear-phishing email that compromised an employee's …
On 4 August 2012, Blizzard Entertainment — maker of World of Warcraft, Diablo, and StarCraft — discovered that an unauthorized party had illegally accessed their internal network …
Barnes & Noble, the US bookseller, disclosed in October 2012 that PIN pad payment terminals at 63 retail stores across 9 states had been physically tampered with — skimming devices …
Disqus — the widely-used blog comment hosting service embedded across millions of websites — disclosed in October 2017 that a database snapshot from July 2012 containing data for …
On October 5, 2017, Disqus disclosed that it had been notified by security researcher Troy Hunt that a dataset containing user data from a 2012 breach had been provided to him by …
The Dropbox breach of approximately July 2012 originated from employee password reuse. A Dropbox employee had reused their LinkedIn account password for their corporate Dropbox …
In August 2012, the South Carolina Department of Health and Human Services disclosed that a former agency employee, Christopher Lykes Jr., had accessed the state's Medicaid …
Barnes & Noble disclosed in October 2012 that criminals had tampered with at least one PIN pad terminal at each of 63 of its retail bookstore locations across nine states …
In June 2012, LinkedIn disclosed that a subset of member passwords had been compromised after approximately 6.5 million unsalted SHA-1 password hashes appeared on a Russian …
On June 6, 2012, eHarmony confirmed that a subset of its member passwords had been compromised and posted to an online password cracking forum. Approximately 1.5 million password …
eHarmony, the US online dating service, disclosed on June 6, 2012 that a subset of its member passwords had been compromised and posted online. Approximately 1.5 million unsalted …
Last.fm, the music discovery and social listening service (owned by CBS Interactive from 2007), suffered a breach of its user database that occurred around 2012 but was not …
On approximately January 15-16, 2012, Zappos (the online shoe and clothing retailer owned by Amazon) suffered a breach in which attackers accessed a customer database server. …
In March 2019, security journalist Brian Krebs reported that Facebook had been storing hundreds of millions of user passwords in plaintext in internal log files since as early as …
Global Payments, a major Atlanta-based credit card processing company, disclosed in March 2012 that it had suffered a data breach affecting approximately 1.5 million credit and …
On October 15, 2011, an unencrypted desktop computer was stolen from a Sutter Medical Foundation administrative office in Sacramento, California. The computer contained an …
On October 14, 2011, a desktop computer was stolen from a Sutter Physicians Services administrative office in Sacramento, California. The computer contained an unencrypted …
On September 14, 2011, backup tapes containing personal and protected health information for approximately 4.9 million TRICARE (US military healthcare) beneficiaries were stolen …
On September 14, 2011, backup tapes containing TRICARE (the U.S. military health insurance program) data were stolen from a car belonging to an employee of Science Applications …
Mt. Gox was once the world's largest Bitcoin exchange, handling over 70% of global BTC transactions at its peak. On February 7, 2014, Mt. Gox suspended all Bitcoin withdrawals …
Between April 17-19, 2011, attackers exploited a known Apache vulnerability to breach Sony's PlayStation Network (PSN) and Sony Online Entertainment (SOE) — the online gaming and …
In May 2011 (discovered internally, disclosed June 2011), hackers breached Citigroup's online banking portal by exploiting a straightforward insecure direct object reference (IDOR) …
In late March 2011, Epsilon Data Management — the world's largest permission-based email marketing company at the time (subsidiary of Alliance Data Systems) — suffered a data …
In March 2011, RSA Security (division of EMC) suffered a breach when a spear-phishing email titled '2011 Recruitment Plan' was opened by an employee. The Excel attachment exploited …
A Romanian cybercrime group compromised point-of-sale systems at approximately 150 Subway franchise restaurants across the United States, stealing over 80,000 payment card numbers …
In September 2010, NewYork-Presbyterian Hospital (NYP) and Columbia University Medical Center (CUMC) disclosed that approximately 6,800 patient records had been exposed on the …
New York-Presbyterian Hospital (NYP) and Columbia University Medical Center (CU) operated a shared data network that included electronic health records. In September 2010, a …
RockYou was a social media widget company (popular Facebook/MySpace apps) that stored all 32 million user passwords in plaintext — with no hashing whatsoever. A SQL injection …
In late 2008 through early 2009 (with disclosure occurring in late 2009 and broader reporting in 2010), RBS WorldPay (a payment processing subsidiary of the Royal Bank of Scotland …
Operation Aurora was a sophisticated, coordinated nation-state cyber espionage campaign originating in China and targeting at least 30 major corporations, with Google being the …
Stuxnet is the first publicly known cyberweapon designed to cause physical destruction of industrial equipment. Jointly developed by the United States (NSA, CIA — under 'Operation …
In January 2009, a hacker gained access to Twitter's administrative control panel by guessing the password of a Twitter admin account using automated brute force — Twitter had …
RBS WorldPay, the US payment processing division of the Royal Bank of Scotland (distinct from the later Worldpay/FIS entity), suffered a coordinated cyberattack in early November …
Between April 2008 and late 2010, Wyndham Hotel & Resorts suffered three separate network intrusions that collectively compromised approximately 619,000 consumer payment card …
MySpace, once the world's largest social network, suffered a breach (believed to have occurred around 2008) that was not publicly revealed until May 2016 when approximately 360 …
Hannaford Brothers, a supermarket chain operating in the northeastern United States, disclosed in March 2008 that its point-of-sale systems had been compromised by malware that …
Heartland Payment Systems, one of the largest payment processors in the United States, disclosed in January 2009 that it had been breached by Albert Gonzalez and two Russian …
On August 4, 2006, AOL's research team released a dataset of approximately 20 million search queries from 657,000 users to a public research website for academic purposes. Users …
On May 3, 2006, a laptop computer and external hard drive belonging to a U.S. Department of Veterans Affairs (VA) data analyst were stolen from his home in Aspen Hill, Maryland in …
On October 4, 2005, security researcher Samy Kamkar launched the Samy worm — the first self-replicating cross-site scripting (XSS) worm in history. The worm exploited an XSS …
On October 4, 2005, Samy Kamkar released a self-propagating JavaScript worm on MySpace, the then-dominant social network. The worm exploited a stored XSS vulnerability in MySpace …
The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 security patch for a critical Plug and Play buffer overflow vulnerability in …
The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 patch for a critical Plug and Play buffer overflow vulnerability in Windows 2000. …
The TJX breach was the largest retail breach in history at the time of disclosure. Beginning around July 2005, Albert Gonzalez's crew drove through TJX store parking lots with …
In February 2005, the contents of Paris Hilton's T-Mobile Sidekick device were stolen and posted on the internet — including her celebrity contact list, personal photos, and SMS …
DSW (Designer Shoe Warehouse) Inc. disclosed in March 2005 that a data breach had compromised payment card information from 108 of its 175 retail stores across the United States. …
DSW Inc. (Designer Shoe Warehouse), operating approximately 175 shoe retail stores across the United States, disclosed in March 2005 that attackers had accessed its computer …
MyDoom, discovered on January 26, 2004, remains the fastest-spreading email worm in recorded history — a record unbroken as of 2026. Within the first 36 hours, MyDoom was …
ChoicePoint, one of the largest US data brokers, disclosed in February 2005 that fraudsters had created approximately 50 fake business subscriber accounts using stolen identities …
CardSystems Solutions, a payment card processor based in Tucson, Arizona, was breached via SQL injection between approximately January 2004 and May 2005. The attackers accessed …
SQL Slammer, also known as Sapphire, is the fastest-spreading computer worm in recorded history. Launched at 05:30 UTC on January 25, 2003, the 376-byte worm doubled the number of …
BJ's Wholesale Club, a membership warehouse retailer operating in the eastern United States, suffered a payment card breach that was publicly disclosed in March 2004. Attackers …
BJ's Wholesale Club, a members-only retail warehouse chain on the US East Coast, suffered payment card data breaches beginning as early as 2003 due to systemic security failures, …
ShadowCrew was an underground carding forum operating from August 2002 until its takedown on October 26, 2004 in Operation Firewall — a joint US Secret Service operation involving …
Nimda (released exactly one week after the September 11 attacks) became the most widespread internet virus in history within 22 minutes of release, surpassing Code Red. Its five …
Code Red exploited a buffer overflow in the IDQ.DLL component of Microsoft IIS web server software (documented in MS01-033). The worm required no user interaction — it scanned …
Between March 2001 and March 2002, Gary McKinnon — a 36-year-old IT administrator from London, UK, operating under the alias 'Solo' — conducted what the US government called 'the …
On May 4-5, 2000, the ILOVEYOU worm began spreading from the Philippines, where computer science student Onel de Guzman had released it via a stolen internet access account. The …
In December 1999, an attacker known only as 'Maxus' (believed to be a ~19-year-old Eastern European) exploited a vulnerability in the payment processing systems of CD Universe, an …
Between August and October 1999, Jonathan James — a 15-year-old from Pinecrest, Florida using the handle 'c0mrade' — conducted a series of intrusions against US government systems …
On March 26, 1999, David Lee Smith of Aberdeen, New Jersey posted the Melissa macro virus to the alt.sex Usenet newsgroup using a stolen AOL account. The virus was embedded in a …
In February 1998, during the height of the Iraq crisis (US was preparing military action against Iraq over UN weapons inspections), unknown actors began systematically attacking US …
Moonlight Maze is one of the first documented nation-state cyber espionage campaigns against the United States. Beginning as early as October 1996 and continuing through at least …
This dataset is open source. Help keep it accurate and up to date by submitting new incidents via GitHub.
Each breach lives in one of eight folders: ransomware/, data-leak/, supply-chain/, credential-theft/, ai/, cloud/, cryptocurrency/, or other/.
Name it YYYY-MM_slug.yaml and fill in the required fields below. Use an existing record as a reference.
Submit your file on GitHub. A maintainer will review and merge it, and the site rebuilds automatically.
# ── Core fields (always present) ───────────────────────────────────────────────
source_name: "Publication or organization reporting the breach"
source_url: "https://example.com/direct-link-to-report"
date_of_breach: "YYYY-MM-DD" # also accepts YYYY-MM or YYYY
date_of_disclosure: "YYYY-MM-DD" # empty string "" if unknown
category: "ransomware | data-leak | supply-chain | credential-theft | ai | cloud | cryptocurrency | other"
notes: "Narrative summary of the incident including timeline, scope, threat actor attribution, and any known impact."
# ── Traditional breach fields ───────────────────────────────────────────────────
date_of_customer_notification: "" # YYYY-MM-DD or "" if unknown
initial_attack_vector: "CWE-NNN: Short description, or free-text description of the attack method"
cve: [] # list of CVE/GHSA IDs, e.g. ["CVE-2024-3094"], empty if none
vendor_product: "Vendor Product Name" # affected vendor or product
software_package: "" # package name for software supply chain incidents, "" otherwise
malware: "" # malware family name if identified, "" otherwise
supply_chain_claimed: false # true if a third-party vendor relationship was the attack vector
# ── Crypto / Web3 fields ───────────────────────────────────────────────────────
blockchain: "ethereum" # blockchain(s) involved, e.g. "ethereum, solana"; omit if not applicable
financial_loss_usd: 0 # numeric USD value of funds lost; omit if not applicable
financial_recovered_usd: 0 # numeric USD value recovered after the incident; omit if not applicable
affected_count: 0 # number of affected wallets, users, or individuals; omit if not applicable
# ── AI fields ─────────────────────────────────────────────────────────────────
ai_model_name: "" # AI model involved, e.g. "ChatGPT", "Claude", "Gemini"; omit if not applicable
ai_model_provider: "" # organization behind the model, e.g. "OpenAI", "Anthropic"; omit if not applicable
ai_attack_vector: "" # AI-specific attack method, e.g. "prompt injection", "deepfake"; omit if not applicable
# ── Cloud / SaaS fields ──────────────────────────────────────────────────────
cloud_provider: "" # cloud provider, e.g. "AWS", "Azure", "GCP", "Snowflake"; omit if not applicable
cloud_shared_responsibility: "" # "vendor" | "customer" | "shared" | "unknown"
cloud_resource_crit: "" # CRIT identifier, e.g. "arn:aws:s3:::{bucket}"; omit if not applicable