Every breach is a lesson. This is the record.

Attackers share tactics. Defenders should too. Browse 3893 documented incidents — attack vectors, malware families, CVEs, and what actually happened.

3425

Total Incidents

$81B+

Total Financial Loss

45

AI Incidents

183

Cloud Incidents

2795

With Attack Vector

821

Supply Chain Claims

Breaches

Sort:
Ransomware [SC]

ChipSoft Ransomware Attack - Dutch Hospital Patient Records Software

2026-04-07 [vendor] ChipSoft HiX (Electronic Patient Dossier / EPD healthcare platform)
Vector: Ransomware attack on ChipSoft's cloud infrastructure (SaaS Patient Portal and GP software tenant); threat actor group not yet publicly identified as of disclosure

On April 7, 2026, ChipSoft — a Dutch healthcare IT company providing Electronic Patient Dossier (EPD/HiX) software to approximately 80% of all Dutch hospitals — was hit by a …

Ransomware

Massachusetts Healthcare System Ransomware — Ambulance Diversion, Downtime Procedures

2026-04-07 [vendor] Massachusetts healthcare system IT infrastructure (identity not disclosed at time of reporting)
Vector: Ransomware or destructive cyberattack on the Massachusetts healthcare system's IT infrastructure; the attack forced the organisation to take clinical systems offline and revert to paper-based downtime procedures; emergency services were diverted to protect patient safety

On approximately 7 April 2026, a Massachusetts healthcare system disclosed it was experiencing a cyberattack that forced the organisation to divert ambulance patients to other …

Cryptocurrency

SEC Form 8-K

2026-04-06 [vendor] Bitcoin Depot [loss] $4M [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin ATM operator Bitcoin Depot has disclosed a March 23 hack in which attackers stole 50.903 BTC (~$3.67 million) from company wallets. According to the company's disclosure …

Cloud [SC]

Cisco Source Code Stolen via Trivy Supply Chain Attack (TeamPCP)

2026-04-03 [vendor] Trivy (open-source vulnerability scanner); GitHub Actions [malware] TeamPCP Cloud Stealer
Vector: TeamPCP (UNC6780) leveraged credentials stolen via the March 2026 Trivy vulnerability scanner supply chain compromise to breach Cisco's internal development and build environment via a malicious GitHub Action plugin

In early April 2026, Cisco disclosed that attackers leveraged credentials stolen through the March 2026 Trivy supply chain compromise (attributed to TeamPCP / UNC6780) to penetrate …

Other

Drift Protocol $285M DPRK Social Engineering Exploit

2026-04-01 [vendor] Drift Protocol (Solana DeFi perpetual futures DEX)
Vector: Six-month DPRK social engineering operation (UNC4736/TraderTraitor) targeted Drift Security Council members; attackers built relationships with team members and used Solana's 'durable nonces' feature to trick council members into pre-signing malicious transactions that transferred admin control

On April 1, 2026, UNC4736 (North Korean state-sponsored TraderTraitor group) executed a 12-minute, 31-transaction drain of $285 million from Drift Protocol, the largest Solana DeFi …

Supply chain [SC]

Axios npm Supply Chain Compromise - Sapphire Sleet (DPRK) RAT Delivery

2026-03-31 [vendor] axios (npm HTTP client library) [malware] Sapphire Sleet RAT
Vector: Sapphire Sleet (North Korean state actor) compromised the npm publishing credentials for axios, one of the most popular JavaScript HTTP client libraries (~70 million weekly downloads), and published malicious versions 1.14.1 and 0.30.4 containing a backdoored dependency connecting to attacker C2

On March 31, 2026, Sapphire Sleet (a North Korean state-sponsored threat actor tracked by Microsoft) published two malicious versions of axios (1.14.1 and 0.30.4) to npm. Axios is …

Supply chain [SC]

TeamPCP Telnyx Python SDK PyPI Supply Chain Compromise

2026-03-27 [vendor] Telnyx Python SDK; PyPI [malware] TeamPCP Cloud Stealer
Vector: TeamPCP compromised Telnyx's PyPI publishing credentials (part of their cascading GitHub Actions credential theft campaign) and published two malicious versions of the Telnyx Python SDK to PyPI containing a three-stage RAT payload hidden inside WAV audio file frames

On March 27, 2026 at 03:51 UTC, TeamPCP published two unauthorized malicious versions of the Telnyx Python SDK (4.87.1 and 4.87.2) to PyPI. Both versions were quarantined by 10:13 …

Ai [SC]

LiteLLM PyPI Supply Chain Attack - Mercor AI Breach (TeamPCP / Lapsus$)

2026-03-27 [vendor] LiteLLM (open-source AI/LLM API library); PyPI (Python package registry)
Vector: TeamPCP (linked to Lapsus$) compromised the PyPI publishing credentials for the LiteLLM open-source AI API library, injecting malicious code into two versions on March 27, 2026; downstream victim Mercor was compromised via the backdoored package

On March 27, 2026, TeamPCP (a threat group also linked to the European Commission cloud breach) compromised PyPI publishing credentials for LiteLLM, a widely used open-source …

Ransomware

Die Linke German Political Party Qilin Ransomware Attack

2026-03-26 [malware] Qilin
Vector: Qilin ransomware compromised Die Linke's network IT infrastructure; specific initial access vector not publicly disclosed

On March 26, 2026, the Qilin ransomware group (described as Russian-speaking and both financially and politically motivated) attacked Die Linke, a left-wing democratic socialist …

Data leak

Hasbro Inc. Data Breach — IT Systems Compromised, Data Stolen, Operations Disrupted

2026-03-25 [vendor] Hasbro Inc. corporate IT infrastructure
Vector: Unknown threat actor gained unauthorized access to Hasbro's corporate IT network and exfiltrated data before being detected; Hasbro took systems offline to contain the spread, disrupting some business operations; specific initial access vector was not publicly disclosed at time of reporting

In late March / early April 2026, Hasbro Inc. — the US toy and entertainment conglomerate (maker of Monopoly, Transformers, My Little Pony, Magic: The Gathering, Dungeons & …

Credential theft

Handala Hacks FBI Director Kash Patel Personal Email — Iranian Intelligence Operation

2026-03-25 [vendor] FBI Director Kash Patel personal email account
Vector: Handala — an Iranian state-linked hacktivist group operating as a persona for Iran's IRGC (Islamic Revolutionary Guard Corps) — obtained access to FBI Director Kash Patel's personal email account and/or cloud storage through unknown means, likely credential theft, SIM swapping, or exploitation of a third-party service

In late March 2026, Handala — an Iranian state-linked hacktivist group that has previously conducted operations attributed to Iran's IRGC — published photographs and alleged …

Other

Attack proposal

2026-03-24 [vendor] Moonwell governance attack
Vector: Governance attack / malicious on-chain proposal

The Moonwell lending protocol faced a governance attack on its deprecated Moonriver instance that could have drained $1 million from the project. Because Moonwell's MFAM governance …

Other

Resolv Protocol DeFi Exploit — $24 Million Minted via Smart Contract Vulnerability

2026-03-22 [vendor] Resolv Protocol (Ethereum DeFi stablecoin protocol)
Vector: Attacker exploited a vulnerability in Resolv Protocol's smart contracts on Ethereum, allowing unauthorized minting of tokens worth approximately $24 million; the specific technical exploit involved manipulating the protocol's collateralization or price oracle mechanisms

In March 2026, an attacker exploited a vulnerability in Resolv Protocol — an Ethereum-based decentralised finance (DeFi) stablecoin protocol — to mint approximately $24 million in …

Supply chain [SC]

TeamPCP Checkmarx KICS GitHub Actions Supply Chain Compromise

2026-03-21 [vendor] Checkmarx KICS (Keep Infrastructure as Code Secure); GitHub Actions [malware] TeamPCP Cloud Stealer
Vector: TeamPCP used GitHub Personal Access Tokens (PATs) stolen during the Trivy compromise to force-push malicious commits to all 35 version tags of the checkmarx/kics-github-action repository and poison version 2.3.28 of checkmarx/ast-github-action

On March 21, 2026, as the second step in its cascading supply chain campaign, TeamPCP used PATs stolen during the March 19 Trivy/Aqua Security GitHub Actions compromise to target …

Data leak

Los Angeles City Attorney / LAPD Police Records Breach - WorldLeaks (7.7TB)

2026-03-20
Vector: WorldLeaks extortion gang breached a third-party discovery transfer system used by the Los Angeles City Attorney's Office to transfer legal discovery documents; LAPD's own systems and networks were not directly compromised

On March 20, 2026, the WorldLeaks extortion gang breached a third-party digital system used by the Los Angeles City Attorney's Office to transfer legal discovery documents. The LA …

Other

Libyan Oil Refinery Multi-Month Cyberespionage Campaign

2026-03-20
Vector: A suspected cyberespionage campaign targeted a Libyan oil refinery using commodity malware, maintaining persistent access over multiple months for industrial intelligence collection

A multi-month cyberespionage campaign targeted a Libyan oil refinery in 2026, using commodity (commercially available) malware to maintain persistent covert access for intelligence …

Other

Bitcoin Depot Crypto ATM Breach - $3.66M BTC Stolen

2026-03-20
Vector: Attackers obtained credentials linked to Bitcoin Depot's digital asset settlement accounts, enabling unauthorized transfer of Bitcoin from company-controlled corporate wallets

On March 20, 2026, attackers used compromised credentials to access Bitcoin Depot's digital asset settlement accounts and transfer 50.903 BTC (valued at approximately $3.665 …

Supply chain [SC]

AppsFlyer Mobile SDK Supply Chain Breach — Enabled Downstream Crypto Theft

2026-03-19
Vector: AppsFlyer's mobile attribution SDK — embedded in thousands of iOS and Android applications — was compromised; attackers used malicious SDK code to intercept cryptocurrency wallet addresses in apps that used AppsFlyer for mobile marketing attribution

AppsFlyer — one of the world's largest mobile attribution platforms, with its SDK embedded in thousands of iOS and Android applications including crypto wallets and fintech apps — …

Cloud [SC]

European Commission ShinyHunters Cloud Breach via Trivy Supply Chain

2026-03-19 [vendor] Amazon Web Services; Trivy (open-source container scanner)
Vector: Attackers compromised the open-source security tool Trivy in a supply chain attack; a secret AWS API key associated with the European Commission's account was embedded in Trivy data and extracted by ShinyHunters, enabling access to the EC's AWS cloud environment

On March 19, 2026, ShinyHunters obtained an AWS API key belonging to the European Commission's cloud environment via a prior compromise of the open-source security tool Trivy. This …

Cloud [SC]

TeamPCP Trivy/Aqua Security GitHub Actions Supply Chain Compromise (CVE-2026-33634)

2026-03-19 [vendor] Trivy (open-source vulnerability scanner by Aqua Security); GitHub Actions [malware] TeamPCP Cloud Stealer [cve] CVE-2026-33634
Vector: TeamPCP (UNC6780) exploited a misconfigured GitHub Actions workflow in Aqua Security's Trivy vulnerability scanner repository, compromising the aqua-bot service account to execute an imposter commit attack that force-pushed malicious code to 76 of 77 version tags across aquasecurity/trivy-action and aquasecurity/setup-trivy

On March 19, 2026, TeamPCP (tracked by Google GTIG as UNC6780) began the first stage of a cascading multi-tool supply chain campaign by exploiting a misconfigured GitHub Actions …

Other

Stryker Wiper Attack Aftermath — Lawsuits Filed as Hackers Boast

2026-03-18
Vector: Handala (Iran-linked hacktivist group) deployed a wiper attack against Stryker's Microsoft Intune MDM infrastructure; subsequent lawsuits and ongoing recovery documented

In the weeks following Stryker's March 2026 Handala wiper attack (documented separately), multiple lawsuits were filed against Stryker as the Iranian-linked Handala group continued …

Data leak

Aura Identity Protection Data Breach - ShinyHunters Vishing (900K Records)

2026-03-17
Vector: ShinyHunters used targeted vishing (voice phishing) against a single Aura employee to obtain credentials, gaining approximately one hour of unauthorized access before being detected and removed

On March 17, 2026, identity protection firm Aura disclosed a data breach after ShinyHunters used targeted vishing to compromise a single employee's account. The attacker had access …

Data leak [SC]

CareCloud EHR Environment Data Breach

2026-03-16 [vendor] CareCloud talkEHR (electronic health record platform)
Vector: Unauthorized actor gained access to one of CareCloud's six electronic health record (EHR) environments; initial access vector not publicly disclosed

On March 16, 2026, CareCloud (a Somerset, NJ-based healthcare IT company) detected unauthorized access to one of its six EHR environments. The threat actor had access for …

Other

Chapter 11 Voluntary Petition

2026-03-15 [vendor] BlockFills goes bankrupt
Vector: Protocol collapse / insolvency

Approximately a month after halting deposits and withdrawals, citing liquidity issues and "recent market and financial conditions", the American crypto lender BlockFills has filed …

Cloud [SC]

Crunchyroll Data Breach via BPO Okta Compromise

2026-03-12 [vendor] Okta (identity/SSO); Telus (BPO/outsourcing) [malware] infostealer (unspecified)
Vector: Threat actor compromised an Okta SSO account belonging to a support agent at Telus (Crunchyroll's BPO partner); malware on the employee's device harvested credentials used to access Crunchyroll's support ticket system

On March 12, 2026, a threat actor gained access to Crunchyroll's customer support ticketing system after compromising an Okta account belonging to an employee of Telus Digital, …

Other

Tweet by Stani Kulechov

2026-03-12 [vendor] Aave swap loss [loss] $50M

A trader using the Aave interface attempted to swap $50 million USDT for AAVE. However, due to the enormous size of the order, the purchase had dramatic impact on the aave price. …

Other

Stryker Handala Iran-Linked MDM Wiper Attack

2026-03-11 [vendor] Microsoft Intune (mobile device management)
Vector: Handala (Void Manticore, MOIS-affiliated Iran) compromised a Microsoft Intune admin account at Stryker, then used the MDM platform to issue remote wipe commands against the entire enrolled device fleet across 79 countries

On March 11, 2026, the Iran-linked hacktivist group Handala (a persona of Void Manticore, affiliated with Iran's Ministry of Intelligence and Security) wiped between 80,000 and …

Cryptocurrency

Tweet by Solv Protocol

2026-03-05 [vendor] Solv Protocol [loss] $3M [chain] bitcoin
Vector: Smart contract exploit / hack

The Solv Protocol bitcoin defi lending and staking platform disclosed an exploit that they said affected fewer than ten users, but nevertheless netted the attacker 38 SolvBTC (a …

Data leak

California Orthopedic Device Maker (OrthoLogic/Implantable Device Company) Cyberattack

2026-03-01 [vendor] California-based implantable orthopedic device manufacturer (specific company name not confirmed at time of reporting)
Vector: Unknown attacker gained unauthorized access to the California-based implantable orthopedic device manufacturer's systems; the company reported the hacking incident to relevant authorities and is among several medical device makers to disclose cybersecurity incidents in early 2026

On approximately 31 March 2026, a California-based maker of implantable orthopedic devices disclosed it had been the victim of a cybersecurity incident. DataBreachToday reported …

Data leak

Dutch Ministry of Finance (Rijksfinancien) Data Breach

2026-03-01 [vendor] Dutch Ministry of Finance / Rijksfinancien IT systems
Vector: Unknown attacker gained unauthorized access to Dutch Ministry of Finance (Rijksfinancien) systems; the specific attack vector — whether phishing, exploitation of an internet-facing vulnerability, or supply chain — was not confirmed at time of initial reporting

In early 2026, the Dutch Ministry of Finance (Ministerie van Financiën, also known as Rijksfinancien) disclosed a cybersecurity breach, details of which were reported in …

Data leak

Lloyds Banking Group Data Leak — 450,000 Customer Records Exposed

2026-03-01 [vendor] Lloyds Banking Group customer data systems
Vector: Customer data belonging to Lloyds Banking Group was exposed or leaked; the specific mechanism — whether a direct breach of Lloyds systems, a third-party vendor incident, or an insider leak — was not confirmed at time of initial reporting; approximately 450,000 customer records were involved

In early April 2026, a data leak affecting approximately 450,000 Lloyds Banking Group customers was reported, with details emerging in DataBreachToday's weekly breach roundup. …

Cloud [SC]

UNC6426 nx npm Supply Chain → AWS Admin Takeover (72 Hours)

2026-03-01 [vendor] nx (npm build tool); AWS; GitHub Actions OIDC
Vector: UNC6426 leveraged credentials (GitHub Personal Access Token) stolen during the 2025 nx npm package supply chain compromise to abuse GitHub-to-AWS OpenID Connect (OIDC) trust, escalating from a developer PAT to full AWS AdministratorAccess within 72 hours

In March 2026, UNC6426 demonstrated a sophisticated attack chain converting a stolen developer GitHub Personal Access Token (from the 2025 nx npm supply chain compromise) into full …

Cloud [SC]

Anodot SaaS Integrator Breach - ShinyHunters Snowflake Token Theft

2026-03-01 [vendor] Anodot (AI analytics/SaaS integration platform); Snowflake (cloud data warehouse)
Vector: ShinyHunters maintained persistent access to Anodot's (an AI analytics SaaS integrator) infrastructure and stole authentication tokens used to connect Anodot to downstream customer Snowflake environments

In April 2026, ShinyHunters disclosed that they had breached Anodot (an Israeli AI analytics company acquired by Glassbox in November 2025), maintaining access 'for some time.' By …

Other

Bithumb Cryptocurrency Exchange Hack — South Korea, Recovery Plan 2026

2026-03-01 [vendor] Bithumb cryptocurrency exchange (South Korea)
Vector: Bithumb suffered an unauthorised access incident affecting its cryptocurrency exchange platform; specific technical attack vector not publicly disclosed at time of reporting; the exchange was working on a recovery plan to compensate affected users and restore operations

In early 2026, Bithumb — South Korea's largest cryptocurrency exchange with approximately $1 billion in daily trading volume and over 8 million registered users — suffered a …

Other

FBI Seizes Handala Iranian Leak Domains After Stryker Hack

2026-03-01 [vendor] Handala leak site infrastructure (Iranian IRGC-linked)
Vector: US federal law enforcement (FBI/DOJ) executed court-ordered domain seizures targeting four web domains used by Handala, an Iran-linked hacktivist group, for publishing stolen data and coordinating cyberattack claims

In March 2026, US federal law enforcement seized four web domains associated with Handala's Iranian online leak infrastructure, days after Handala published materials it claimed to …

Ransomware

Malaysia Airlines Qilin Ransomware Claim

2026-02-26 [malware] Qilin
Vector: Not disclosed; Qilin listed Malaysia Airlines on its dark web victim site with no file samples or proof of data theft published

On February 26–27, 2026, the Qilin ransomware gang listed Malaysia Airlines on its dark web leak site. Unlike its typical practice, the group published no file samples, data cache …

Data leak

PayPal App Coding Error Data Breach and Fraud

2026-02-23
Vector: A coding error in PayPal's application enabled unauthorized data access and facilitated fraud against a subset of PayPal users; the error was in the app's data handling logic rather than a direct attack by external threat actors

PayPal disclosed a data breach and associated fraud incident caused by a coding error in its payment application. The error allowed unauthorized access to a subset of user account …

Cryptocurrency

Tweet by Step Finance

2026-02-23 [vendor] Step Finance [chain] solana
Vector: Protocol collapse / insolvency

Step Finance announced that, following a $30 million theft in late January, the project would be shutting down. Along with it, they will shut down SolanaFloor — a Solana-focused …

Data leak

Tweet by Script3

2026-02-21 [vendor] YieldBlox theft [loss] $10M
Vector: Oracle price manipulation

A lending pool operated by YieldBlox on the Stellar blockchain was emptied of around $10.2 million in an oracle manipulation attack on the Reflector oracle supplying prices for the …

Other [SC]

FBI DCS-3000 Surveillance Network Breach - China-Linked 'Major Incident'

2026-02-17 [vendor] FBI Digital Collection System Network DCS-3000 (Red Hook) - pen register and tap-and-trace surveillance infrastructure
Vector: Threat actors leveraged a commercial Internet Service Provider's vendor infrastructure to access FBI systems; FBI systems in the Virgin Islands were compromised

On February 17, 2026, the FBI began investigating abnormal activity in an unclassified system — DCS-3000 (known as Red Hook), part of its Digital Collection System Network (DCSNet) …

Data leak

Odido (Netherlands) ShinyHunters Telecom Data Breach - 6.2M Customers

2026-02-07 [vendor] Odido customer contact/CRM system
Vector: ShinyHunters used phishing and social engineering to gain access to Odido's customer contact/CRM system used by customer service representatives

On the weekend of February 7–8, 2026, ShinyHunters breached Odido's (Netherlands' largest mobile network operator) customer contact system and downloaded records for approximately …

Ransomware

BridgePay Network Solutions Ransomware Attack

2026-02-06 [vendor] BridgePay Network Solutions (payment gateway platform)
Vector: Unknown; ransomware deployed against BridgePay's payment processing infrastructure

On February 6, 2026 (starting at ~03:29 AM EST), a ransomware attack hit BridgePay Network Solutions, a payment gateway serving merchants, municipalities, and integrators. The …

Cloud [SC]

Hims & Hers Zendesk Support Breach via ShinyHunters Okta Campaign

2026-02-04 [vendor] Zendesk (customer support platform); Okta (identity/SSO)
Vector: ShinyHunters compromised an Okta SSO account to access Hims & Hers' Zendesk customer support instance

Between February 4–7, 2026, threat actors used a compromised Okta SSO account to access Hims & Hers' Zendesk support instance and exfiltrate customer support tickets. The breach …

Data leak

Sears Home Services AI Chatbot Data Exposure - 3.7M Records, 4.3TB

2026-02-03
Vector: Misconfiguration: Transformco (Sears Home Services parent) left three cloud storage buckets containing AI chatbot logs, audio recordings, and scheduling data publicly accessible without authentication

On February 3, 2026, security researcher Jeremiah Fowler discovered three unsecured publicly exposed databases during routine Shodan scans, containing 4.3 terabytes of data linked …

Data leak

CarGurus ShinyHunters Data Breach - 12.4M Accounts

2026-02-01
Vector: ShinyHunters used social engineering (pretexting/vishing — impersonating employees calling the help desk for password resets) to gain unauthorized access to CarGurus systems

In February 2026, ShinyHunters breached CarGurus (a major US online automotive marketplace) via social engineering. After CarGurus declined to pay ransom, the data was published …

Cryptocurrency

Tweet by CertiK

2026-01-31 [vendor] Step Finance theft [loss] $29M [chain] solana
Vector: Smart contract exploit / hack

The Solana-based defi portfolio tracker Step Finance lost 261,854 SOL (~$28.7 million) when a thief gained access to treasury and fee wallets. It's not yet clear how the attacker …

Supply chain [SC]

GlassWorm Supply-Chain Attack - 72 Malicious Open VSX Extensions

2026-01-30 [vendor] Open VSX Registry (VS Code extension marketplace) [malware] GlassWorm
Vector: GlassWorm threat actor compromised a legitimate developer's Open VSX publishing credentials (leaked token or unauthorized access) to publish malicious extension versions; also abused extensionPack/extensionDependencies transitive dependency chains to turn benign extensions into GlassWorm delivery vehicles after trust was established

Since January 31, 2026, researchers identified at least 72 malicious Open VSX extensions linked to the GlassWorm campaign. On January 30, 2026, four established Open VSX extensions …

Cryptocurrency

Tweet thread by Aperture Finance

2026-01-25 [vendor] Aperture Finance [loss] $3M [chain] ethereum, polygon, bsc, avalanche
Vector: Smart contract exploit / hack

An attacker exploited a bug in an Aperture Finance smart contract to steal at least $3.4 million from users who had enabled "instant liquidity management" features. Aperture …

Cryptocurrency

"SwapNet Incident Post Mortem"

2026-01-25 [vendor] Matcha Meta [loss] $13M [chain] ethereum
Vector: Smart contract exploit / hack

Some users of Matcha Meta, a decentralized exchange aggregator on the Base blockchain, suffered losses after a thief exploited a vulnerability in its SwapNet integration. SwapNet …

Other

Tweet thread by zachxbt

2026-01-23 [vendor] Lick theft
Vector: On-chain theft (attributed by zachxbt)

Two crypto thieves decided to settle an argument over who was wealthier by screensharing as they transferred crypto between wallets to prove ownership. In doing so, one of them — …

Supply chain [SC]

EHR Vendor Veradigm $10.5M Data Breach Lawsuit Settlement

2026-01-21
Vector: Veradigm (formerly Allscripts Healthcare Solutions) suffered a data breach affecting physician practice clients; the breach resulted in class-action litigation that settled for $10.5 million

Electronic health records vendor Veradigm (formerly Allscripts Healthcare Solutions, rebranded 2022) agreed to pay $10.5 million to settle a class-action lawsuit arising from a …

Cryptocurrency

Tweet by Saga

2026-01-21 [vendor] Saga [loss] $7M [chain] ethereum
Vector: Private key compromise

The Saga project halted its blockchain after acknowledging that $7 million had been stolen. An attacker was evidently able to mint a large quantity of Saga Dollar tokens, though …

Credential theft

Starbucks Partner Central Phishing Breach - 889 Employees

2026-01-19 [vendor] Starbucks Partner Central (employee HR/payroll portal)
Vector: Attackers used phishing — fake websites mimicking the Starbucks Partner Central employee portal — to steal employee login credentials, then used those credentials to access the portal and exfiltrate employee PII

Between January 19 and February 11, 2026, attackers used phishing pages cloning the Starbucks Partner Central portal to steal employee credentials. Starbucks detected the …

Cryptocurrency

Tweet by RuneCrypto_

2026-01-12 [vendor] NYC Token crash [loss] $1M [chain] solana
Vector: Exit scam / rug pull

Shortly after losing his campaign for re-election as mayor of New York City, Eric Adams announced he would be launching "NYC Token". He's pitched the project as a fundraising tool …

Cryptocurrency

Tweet by zachxbt

2026-01-10 [vendor] Trezor support [loss] $281M [chain] bitcoin, monero, litecoin
Vector: On-chain theft (attributed by zachxbt)

A crypto holder has lost $282 million in bitcoin and litecoin after a scammer impersonating a customer support employee for the Trezor hardware wallet manufacturer successfully …

Data leak

Crunchbase Data Breach - ShinyHunters Vishing (2M Records)

2026-01-09 [vendor] Okta SSO
Vector: ShinyHunters used vishing (voice phishing) to impersonate employees calling IT/help desk and obtain Okta SSO credentials, gaining unauthorized access to Crunchbase systems

In January 2026, ShinyHunters breached Crunchbase (a major business intelligence and startup data platform) via vishing — attackers impersonated internal employees to …

Cloud

Betterment Data Breach - ShinyHunters Vishing (1.4M Customers)

2026-01-09 [vendor] Salesforce (third-party marketing/CRM platform)
Vector: ShinyHunters used vishing (voice phishing) to compromise IT support at a third-party vendor (believed to be Salesforce) used by Betterment for marketing and customer communications, gaining access to third-party software platforms

On January 9, 2026, Betterment (a major US robo-advisor and investment platform) suffered a data breach after ShinyHunters used vishing to compromise IT support at a third-party …

Cryptocurrency

Tweet by Truebit

2026-01-08 [vendor] Truebit [loss] $27M [chain] ethereum
Vector: Smart contract exploit / hack

A bug in a smart contract belonging to the Ethereum-based Truebit project allowed an attacker to steal 8,535 ETH (~$26.4 million). The thief targeted one of the project's older …

Data leak [SC]

Bumble and Match Group ShinyHunters Vishing Breach

2026-01-01 [vendor] Slack; Google Drive; Bumble internal contractor access
Vector: Vishing (voice phishing) attack compromised a contractor's account at Bumble, granting limited access to internal Slack and Google Drive systems; a related attack targeted Match Group

On January 29, 2026, ShinyHunters posted data allegedly stolen from Bumble (dating app) and Match Group (parent of Tinder, Hinge, OkCupid) on a dark web leak site. ShinyHunters …

Data leak

Figure Technology Solutions ShinyHunters Vishing Breach

2026-01-01
Vector: Voice phishing (vishing) social engineering attack tricked an employee into surrendering credentials and MFA codes, allowing unauthorized access to internal systems

Figure Technology Solutions (fintech lending company) disclosed in February 2026 that ShinyHunters conducted a vishing (voice phishing) attack against an employee in January 2026, …

Cloud [SC]

Telus Digital ShinyHunters Breach - ~1 Petabyte

2026-01-01 [vendor] Google Cloud Platform (BigQuery); Salesforce; Drift
Vector: ShinyHunters discovered Google Cloud Platform credentials for Telus Digital embedded in a Drift data export; used those credentials to access BigQuery, then pivoted using additional secrets found with trufflehog to access further systems

Telus Digital (Canadian BPO providing outsourced customer support, content moderation, and AI services) confirmed a multi-month breach on March 12, 2026. ShinyHunters claimed …

Other

GRU APT28 SOHO Router DNS Hijacking Campaign — Cloud Activity Espionage

2026-01-01 [vendor] SOHO routers (multiple vendors including TP-Link, ASUS, Netgear, D-Link) used by target organisations [malware] MooBot (Mirai variant), custom DNS hijacking tools
Vector: GRU-linked APT28 (Fancy Bear) threat actors compromised SOHO (Small Office/Home Office) routers by exploiting default credentials, unpatched firmware vulnerabilities, or known CVEs in popular router models; once compromised, attackers modified the routers' DNS resolver settings to redirect DNS queries through attacker-controlled infrastructure, enabling passive interception of cloud service authentication traffic for high-value targets

In early 2026, security researchers and government agencies disclosed a new cyberespionage campaign by hackers tied to Russia's GRU military intelligence agency (Fancy Bear / APT28 …

Ransomware

Sedgwick Government Solutions TridentLocker Ransomware Attack

2025-12-31 [malware] TridentLocker
Vector: TridentLocker ransomware group breached Sedgwick Government Solutions via an isolated file transfer system; initial access vector not publicly disclosed

On New Year's Eve 2025/2026, the TridentLocker ransomware-as-a-service (RaaS) group claimed an attack on Sedgwick Government Solutions, a subsidiary of Sedgwick that provides …

Cloud

Eurail B.V. AWS S3/Zendesk/GitLab Breach - 308K Travelers

2025-12-26 [vendor] Amazon Web Services S3; Zendesk; GitLab
Vector: Unauthorized actor transferred files from Eurail's AWS S3 buckets, Zendesk instance, and GitLab repositories on December 26, 2025; initial access vector not disclosed

On December 26, 2025, an unauthorized actor exfiltrated data from Eurail B.V.'s (European rail pass operator covering 33 national railways) AWS S3, Zendesk, and GitLab instances. …

Supply chain [SC]

Tweet thread by TrustWallet

2025-12-25 [vendor] Trust Wallet [loss] $7M
Vector: Software supply chain attack

The Trust Wallet Chrome extension was compromised in an apparent supply chain attack. People who used the non-custodial wallet extension after it updated to version 2.68 lost funds …

Data leak [SC]

Navia Benefit Solutions BOLA Vulnerability Data Breach

2025-12-22 [vendor] Navia Benefit Solutions (employee benefits administration platform)
Vector: Broken Object Level Authorization (BOLA) vulnerability in Navia's systems allowed unauthorized access to benefit plan data

Navia Benefit Solutions, an employee benefits administration company, suffered a data breach due to a BOLA (Broken Object Level Authorization) API vulnerability. An unknown threat …

Data leak

Condé Nast / WIRED Subscriber Database Breach - IDOR Vulnerability

2025-12-20 [vendor] Condé Nast (centralized identity platform)
Vector: Insecure Direct Object Reference (IDOR) vulnerabilities and broken access controls in Condé Nast's centralized identity/account platform allowed unauthenticated enumeration of user profiles by iterating user ID values

On December 20, 2025, a threat actor called 'Lovely' posted a 2.366 million-record database from WIRED.com on the Breach Stars forum, selling access for approximately $2.30. …

Data leak

Thief wallet

2025-12-19 [vendor] 0xcB8078 address poisoning
Vector: Address poisoning attack

A crypto trader lost almost $50 million in the Tether stablecoin after falling victim to an address poisoning attack. Because blockchain wallet addresses are long, random …

Cryptocurrency

Tweet by PeckShield

2025-12-16 [vendor] Yearn Finance [loss] $304,400 [chain] ethereum
Vector: Flash loan attack on smart contract

Only weeks after losing $6.6 million to an infinite mint exploit, a Yearn Finance smart contract has again been exploited, allowing an attacker to make off with around 103 ETH …

Cloud

SoundCloud Data Breach - ShinyHunters Vishing (29.8M Accounts)

2025-12-15
Vector: ShinyHunters used vishing (voice phishing) to trick SoundCloud employees into providing access credentials to an ancillary service dashboard rather than the company's core production systems

In December 2025, ShinyHunters breached SoundCloud via vishing — attackers convinced employees to provide access to an ancillary service dashboard. SoundCloud confirmed the breach …

Cryptocurrency

Tweet by Aevo (fka Ribbon Finance)

2025-12-12 [vendor] Ribbon Finance [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

Ribbon Finance, which has partially rebranded to Aevo, has lost $2.7 million after attackers exploited a vulnerability in the smart contract for legacy Ribbon vaults that enabled …

Cryptocurrency

"Fusaka Mainnet Prysm Incident"

2025-12-04 [vendor] Prysm consensus client bug [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

Ethereum validators running the Prysm consensus client lost around 382 ETH ($1.18 million) after a bug resulted in delays that caused validators to miss blocks and attestations. …

Data leak

Brightspeed Broadband Crimson Collective Data Breach Claim - 1M Customers

2025-12-01
Vector: Unknown; Crimson Collective threat actor claimed access to Brightspeed's systems and exfiltration of over 1 million customer records; Brightspeed confirmed an investigation into a potential cybersecurity event

On January 4, 2026, the Crimson Collective threat group publicly claimed via Telegram to have breached Brightspeed (a major US fiber broadband provider) and stolen records for over …

Data leak [SC]

Ledger Customer Data Breach via Global-e Third-Party Ecommerce Platform

2025-12-01 [vendor] Global-e (international ecommerce and payments platform)
Vector: Unauthorized access to Global-e's cloud system storing order data for multiple brands including Ledger; initial access vector not publicly disclosed

Ledger (hardware crypto wallet manufacturer) disclosed in January 2026 that an unnamed unauthorized party accessed a Global-e cloud system used to process international orders. …

Data leak [SC]

Cegedim Santé MonLogicielMedical Breach - 15.8M French Patient Records

2025-12-01 [vendor] Cegedim Santé MonLogicielMedical (cloud EHR/practice management platform)
Vector: Unauthorized access via abnormal API/application requests on doctor accounts in Cegedim Santé's MonLogicielMedical (MLM) cloud healthcare platform; initial access vector not publicly disclosed

Cegedim Santé (French healthcare software provider) confirmed on March 3, 2026, that attackers stole 15.8 million administrative patient records from its MonLogicielMedical …

Supply chain [SC]

Freedom Mobile Third-Party Breach (December 2025)

2025-12-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Freedom Mobile experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

PornHub Third-Party Breach (December 2025)

2025-12-01 [vendor] Mixpanel
Vector: Compromise of third-party service provider / vendor relationship

In 2025, PornHub experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …

Ai [SC]

TechCrunch

2025-11-26 [vendor] Mixpanel analytics platform (used by OpenAI)
Vector: CWE-284: Improper Access Control (third-party analytics vendor breach)

Hackers breached Mixpanel, a third-party analytics vendor used by OpenAI to track user behavior on its API platform, on November 26, 2025. The breach exposed data belonging to …

Cryptocurrency

Tweet thread by Homer J

2025-11-21 [vendor] Cardano [chain] cardano
Vector: AI-assisted attack or AI-generated exploit

On November 21, the Cardano blockchain suffered a major chainsplit after someone created a transaction that exploited an old bug in Cardano node software, causing the chain to …

Cryptocurrency

Telegram post by zachxbt

2025-11-20 [vendor] GANA Payment [loss] $3M [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

An attacker stole approximately $3.1 million from the BNB chain-based GANA Payment project. The thief laundered about $1 million of the stolen funds through Tornado Cash shortly …

Other

Tweet by DappRadar

2025-11-17 [vendor] DappRadar
Vector: Protocol collapse / insolvency

Amid a month of falling crypto prices, the crypto tracking platform DappRadar has announced it will be shutting down after seven years of operation. "Running a platform of this …

Data leak [SC]

SitusAMC Real Estate Finance Tech Breach - JPMorgan/Citi/Morgan Stanley Affected

2025-11-12 [vendor] SitusAMC (real estate debt/equity origination, transaction, and management platform)
Vector: Unknown; no encrypting malware was involved; SitusAMC described it as a contained data exfiltration incident

SitusAMC (a financial technology provider serving 1,500+ clients including major US banks, real estate firms, and insurers) became aware of a breach on November 12, 2025, and …

Cloud

IDMerit MongoDB KYC Data Exposure - 1 Billion Records

2025-11-11 [vendor] MongoDB (cloud database)
Vector: Misconfiguration: IDMerit left a MongoDB database containing KYC identity verification records publicly accessible on the internet without authentication

Cybernews researchers discovered on November 11, 2025, that IDMerit (a US identity verification and KYC/AML services provider) had left a MongoDB database publicly exposed without …

Data leak

Coupang Insider Data Breach - 33.7M South Korean Customer Accounts

2025-11-08
Vector: Insider threat: a former Coupang employee retained unauthorized access to internal systems and exfiltrated customer data; breach persisted until November 8, 2025, per South Korean government investigation

A former Coupang employee maintained unauthorized access to the company's systems and exfiltrated customer data, with the breach continuing until November 8, 2025. Coupang (South …

Cryptocurrency

Tweet thread by Elixir

2025-11-06 [vendor] Elixir [chain] ethereum
Vector: Protocol collapse / insolvency

After the defi yield platform Stream Finance announced a $93 million loss, Elixir announced it would be discontinuing its deUSD synthetic stablecoin. Stream Finance owes $68 …

Data leak

Tweet by Stream Finance

2025-11-04 [vendor] Stream Finance loss [loss] $93M
Vector: Withdrawal halt / insolvency

The Stream Finance defi yield project announced that "an external fund manager overseeing Stream funds disclosed the loss of approximately $93 million in Stream fund assets." …

Cryptocurrency

wrsETH Oracle Malfunction 11/4/25

2025-11-04 [vendor] Moonwell oracle malfunction [loss] $4M [chain] ethereum
Vector: Oracle price manipulation

The Moonwell lending protocol, built on the Base Ethereum L2, wound up with $3.7 million in bad debt after an attacker took advantage of an oracle malfunction that caused the price …

Ransomware

Under Armour Everest Ransomware Breach - 72M Records

2025-11-01 [malware] Everest
Vector: Everest ransomware group claimed unauthorized access to Under Armour systems, alleging exfiltration of 343 GB of data; initial access vector not publicly disclosed

In November 2025, the Everest ransomware group claimed Under Armour as a victim and attempted extortion, alleging theft of 343 GB of data. In January 2026, data for approximately …

Data leak

Freedom Mobile Third-Party Vendor Breach

2025-11-01
Vector: An unnamed third-party vendor used by Freedom Mobile was compromised, exposing customer account data stored in the vendor's systems

Freedom Mobile, one of Canada's largest wireless carriers (owned by Shaw/Rogers), disclosed in December 2025 that a third-party vendor had been compromised, resulting in the …

Supply chain [SC]

Marquis Software Solutions Breach (74 Banks and Credit Unions)

2025-11-01 [vendor] Marquis Software Solutions (core banking software)
Vector: Marquis Software Solutions, a vendor providing core banking software to community banks and credit unions, was compromised, exposing customer financial data for clients of 74 affected financial institutions

Marquis Software Solutions, a provider of core banking and analytics software to community banks and credit unions across the United States, disclosed in December 2025 that a …

Supply chain [SC]

Checkout.com Third-Party Breach (November 2025)

2025-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Checkout.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Logitech Third-Party Breach (November 2025)

2025-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Logitech experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Ai [SC]

OpenAI Third-Party Breach (November 2025)

2025-11-01 [vendor] Mixpanel
Vector: Compromise of third-party service provider / vendor relationship

In 2025, OpenAI experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Mixpanel. Source reporting: …

Other

US Congressional Budget Office China-Suspected Cyberattack

2025-11-01 [vendor] Cisco ASA (firewall)
Vector: Suspected exploitation of an outdated Cisco ASA firewall (last patched 2024) — vulnerable to newly discovered bugs actively exploited by suspected Chinese state-sponsored hackers; suspected PRC/China state-backed actor

In early November 2025, the US Congressional Budget Office (CBO) detected and confirmed a cyberattack by a suspected foreign actor. US officials briefed CNN that Chinese …

Data leak

DoorDash Data Breach via Employee Social Engineering

2025-10-25
Vector: Social engineering attack targeting a DoorDash employee; threat actors manipulated the employee to gain access to internal systems

On October 25, 2025, an unauthorized third party gained access to DoorDash's internal systems after successfully social engineering a company employee. The number of affected …

Cloud [SC]

Mixpanel Product Analytics Platform Breach (Multiple Companies)

2025-10-15 [vendor] Mixpanel (product analytics SaaS)
Vector: Threat actors compromised Mixpanel's product analytics platform infrastructure, gaining access to customer behavioral and analytics data that dozens of companies had shared with Mixpanel for product improvement and user analytics purposes

In late 2025, Mixpanel, a widely-used product analytics SaaS platform, suffered a breach that exposed user behavioral data from dozens of customer companies. Confirmed affected …

Cryptocurrency

Tweet by Whale Alert

2025-10-15 [vendor] Paxos accidental mint [chain] ethereum
Vector: Software bug / unintentional loss

Paxos, the issuer of PayPal's PYUSD stablecoin, accidentally minted 300 trillion of the supposedly dollar-pegged token. For context, this is approximately 2.5x the global GDP, and …

Data leak

Discord Third-Party Customer Service Provider Breach (55M Users)

2025-10-01
Vector: Threat actor compromised an unnamed third-party customer service provider used by Discord, gaining access to customer support data including user account information

In October 2025, Discord disclosed that an unnamed third-party customer service provider had been breached, exposing data for approximately 55 million Discord users. The exposed …

Data leak

DocketWise Immigration Platform Data Breach - 116K Clients

2025-10-01
Vector: Attackers used valid credentials to access and clone third-party partner repositories used in DocketWise's data migration pipeline, which contained unstructured client data belonging to immigration law firms

In October 2025, DocketWise (a cloud-based immigration case management platform for law firms) discovered that credentials to one of its third-party partner repositories had been …

Data leak

The Washington Post Oracle E-Business Suite ERP Breach

2025-10-01 [vendor] Oracle E-Business Suite (EBS) [cve] CVE-2025-61882
Vector: Attackers exploited a vulnerability in Oracle E-Business Suite (ERP system) used by The Washington Post for HR and payroll management, exfiltrating employee and contractor personal and financial data

The Washington Post disclosed in November 2025 that a breach of its Oracle E-Business Suite ERP system had exposed sensitive personal and financial data for approximately 10,000 …

Supply chain [SC]

Discord Third-Party Breach (October 2025)

2025-10-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Discord experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

MANGO Third-Party Breach (October 2025)

2025-10-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, MANGO experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Ai

OpenAI Mixpanel Product Analytics Data Exposure

2025-10-01 [vendor] Mixpanel (product analytics SaaS)
Vector: OpenAI's product analytics vendor Mixpanel was compromised, exposing behavioral and account data that OpenAI had shared with Mixpanel for product analytics purposes

In November 2025, OpenAI disclosed that customer data had been exposed via Mixpanel, its third-party product analytics platform. OpenAI had shared user behavioral data with …

Cloud [SC]

Red Hat Consulting GitLab Breach - Crimson Collective (570GB, 800+ Enterprises)

2025-10-01 [vendor] GitLab (self-hosted instance)
Vector: Crimson Collective gained unauthorized access to Red Hat's internal consulting GitLab instance used for customer engagement collaboration, exfiltrating approximately 570GB of compressed data from over 28,000 repositories

On October 1, 2025, the cybercrime group Crimson Collective disclosed a breach of Red Hat's consulting GitLab instance, claiming to have exfiltrated 570 GB of data from over 28,000 …

Data leak

Telegram message by zachxbt

2025-09-24 [vendor] SBI Crypto theft [loss] $21M
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Crypto sleuth zachxbt observed $21 million in "suspicious outflows" from SBI Crypto, a crypto mining subsidiary of the Japanese SBI Group. The money was quickly laundered through …

Ai

Tweet by Oli Feldmeier

2025-09-24 [vendor] Griffin AI [loss] $3M [chain] bsc, ethereum
Vector: AI-assisted attack or AI-generated exploit

One day after Griffin AI launched its GAIN token on Binance Alpha, an attacker minted 5 billion fake GAIN tokens on the Ethereum blockchain, then exploited a cross-chain endpoint …

Cryptocurrency

Tweet by Meta Alchemist

2025-09-23 [vendor] Seedify bridge [loss] $2M [chain] bsc, polygon, ethereum
Vector: Smart contract exploit / hack

An attacker exploited bridges for SFUND, the token issued by the Seedify launchpad and incubator. It appears the exploiter has profited around $1.7 million from the theft. Seedify …

Ransomware

Insightin Health GoAnywhere Breach - Medusa Ransomware Claim (142K)

2025-09-17 [vendor] GoAnywhere (managed file transfer) [malware] Medusa
Vector: Unauthorized actor exploited a previously unknown vulnerability in GoAnywhere (a managed file transfer tool) used by Insightin Health, gaining access to servers for approximately 6 days

Between September 17 and September 23, 2025, an unauthorized actor exploited an unknown vulnerability in Insightin Health's GoAnywhere managed file transfer tool, gaining access to …

Data leak

MANGO Third-Party Marketing Provider Breach

2025-09-15
Vector: MANGO's third-party marketing service provider was compromised, exposing customer contact and demographic data used for marketing campaigns

MANGO, the Spanish global fashion retailer, disclosed in October 2025 that a third-party marketing provider had been compromised, exposing customer data. Exposed information …

Supply chain [SC]

Shai-Hulud Self-Replicating npm Supply Chain Worm (v1 + v2)

2025-09-14 [vendor] npm (Node Package Manager registry) [malware] Shai-Hulud
Vector: Novel self-replicating worm injected malicious post-install scripts into npm packages by compromising developer maintainer accounts; spread autonomously by stealing npm tokens and publishing backdoored versions of other packages maintained by the same developers

On September 14, 2025, the first malicious packages of the Shai-Hulud self-replicating worm appeared in the npm ecosystem. By September 16, over 180 packages were confirmed …

Cryptocurrency

Tweet by Yala

2025-09-14 [vendor] Yala stablecoin depegs [loss] $8M [chain] bitcoin

The YU bitcoin-backed stablecoin lost its intended dollar peg after what they described as "an attempted attack", later writing that there was an "unauthorized transfer of funds". …

Supply chain

npm Supply Chain Attack: chalk, debug, and 16 Other Packages Compromised

2025-09-08 [vendor] npm registry [malware] Browser crypto wallet stealer (hooking window.ethereum, Solana APIs, fetch/XHR)
Vector: Phishing / adversary-in-the-middle attack against package maintainer 'qix' (Josh Junon): fake npm 2FA reset email (npmjs.help domain) captured username, password, and live TOTP code

On September 8, 2025, 18 widely used npm packages were compromised via an account takeover of maintainer 'qix'. Affected packages collectively receive 2.6+ billion downloads per …

Other

SwissBorg Kiln Staking Infrastructure Breach ($41M SOL)

2025-09-01 [vendor] Kiln (crypto staking infrastructure)
Vector: Threat actors compromised Kiln, a professional crypto staking infrastructure provider, and used their access to drain Solana (SOL) funds belonging to SwissBorg customers from the Kiln-managed Solana Earn product

In September 2025, SwissBorg, a Swiss crypto asset management platform, lost approximately $41 million worth of Solana (SOL) after threat actors compromised Kiln, the third-party …

Data leak

Renault / Dacia UK Third-Party Vendor Breach

2025-09-01
Vector: A third-party vendor used by Renault and Dacia UK was compromised, exposing customer personal data including vehicle identification information

Renault and Dacia UK disclosed in October 2025 that a third-party vendor had been compromised, exposing data for UK customers. Exposed information included customer names, gender, …

Supply chain [SC]

BeyondTrust Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesforce / Drift Security Incident | BeyondTrust. BeyondTrust’s Privileged Access Management platform protects your organization from unwanted remote access, stolen …

Supply chain [SC]

BugCrowd Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Update: Bugcrowd Response to Salesloft Drift Third-Party Security Event | @Bugcrowd. We want to share an update to our blog post regarding the recent unauthorized access to …

Supply chain [SC]

Cato Networks Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Cato Networks experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Chess.com Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Chess.com experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

ContentSquare Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, ContentSquare experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Dynatrace LLC. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Dynatrace LLC. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Esker Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Esker experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

HackerOne Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, HackerOne experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Harrods Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Harrods experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

LiveRamp Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, LiveRamp experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Omada Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Omada experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

OneSpan Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, OneSpan experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Pantheon Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Pantheon experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Proofpoint Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Proofpoint experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Qualys, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Qualys, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Sophos Ltd. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Sophos Ltd. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

SpyCloud, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, SpyCloud, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Stellantis Third-Party Breach (September 2025)

2025-09-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Stellantis experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Salesforce. Source reporting: …

Supply chain [SC]

Tenable, Inc. Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Tenable, Inc. experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Supply chain [SC]

Wealthsimple Third-Party Breach (September 2025)

2025-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Wealthsimple experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Third-party vendor. Source reporting: …

Supply chain [SC]

Workiva Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Workiva experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Cloud [SC]

Cloudflare Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Cloudflare experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Cloud [SC]

Fastly Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Fastly experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Cloud [SC]

Workday Third-Party Breach (September 2025)

2025-09-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

In 2025, Workday experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Drift (Salesloft). Source reporting: …

Ransomware

Jaguar Land Rover Scattered Lapsus$ Hunters Cyberattack

2025-08-31
Vector: Vishing (voice phishing) campaign weeks before the attack tricked employees into disclosing credentials; attackers posing as internal IT staff. Subsequent credential abuse and lateral movement into production and manufacturing systems.

Beginning August 31, 2025, the 'Scattered Lapsus$ Hunters' alliance — a cybercrime consortium of Scattered Spider (initial access/social engineering), LAPSUS$ …

Data leak

Minnesota DHS MnCHOICES Data Breach via FEI Systems - 304K Individuals

2025-08-28 [vendor] FEI Systems MnCHOICES (disability waiver case management)
Vector: A user affiliated with a licensed healthcare provider accessed the MnCHOICES disability services system without authorization; unauthorized access occurred through a third-party vendor (FEI Systems) managing the platform

From August 28 to September 21, 2025, an individual affiliated with a licensed healthcare provider accessed the Minnesota Department of Human Services' MnCHOICES disability …

Cryptocurrency

"Closing up (the) Shop"

2025-08-28 [vendor] Reddit [chain] polygon

Three years after launching "Collectible Avatars", the NFT project they didn't want to call "NFTs" because they were already becoming kind of cringe, Reddit has decided to pull the …

Other

Tweet by Chaofan Shou

2025-08-27 [vendor] BetterBank [loss] $1M

The PulseChain-based defi project BetterBank was exploited by an attacker who took advantage of a vulnerability that allowed them to mint arbitrary tokens, some of which they then …

Cryptocurrency

Tweet by zachxbt

2025-08-19 [vendor] Bitcoiner socially engineered out of $91 million [loss] $91M [chain] bitcoin
Vector: Social engineering attack

A bitcoin holder reportedly fell for a social engineering attack after receiving communications from scammers posing as customer support for a crypto exchange and hardware wallet …

Data leak

London North Eastern Railway (LNER) Third-Party Vendor Breach

2025-08-15
Vector: An unnamed third-party vendor used by LNER was compromised, exposing customer contact details and journey information stored in the vendor's systems

London North Eastern Railway (LNER), the UK train operator serving the East Coast Main Line between London King's Cross, Edinburgh, and Aberdeen, disclosed in September 2025 that a …

Data leak

Wealthsimple Third-Party Vendor Data Breach

2025-08-15
Vector: A third-party vendor used by Wealthsimple was compromised, exposing sensitive personal and financial identity documents for affected customers

Wealthsimple, a major Canadian online investment and financial services platform, disclosed in September 2025 that a third-party vendor had been compromised, resulting in the …

Ransomware [SC]

Marquis Software Solutions Akira Ransomware Attack

2025-08-14 [vendor] SonicWall (VPN/firewall) [malware] Akira [cve] CVE-2024-40766
Vector: Akira ransomware exploited CVE-2024-40766 (SonicWall VPN improper access control) to breach Marquis Software's network; attackers also bypassed MFA

Marquis Software Solutions, a marketing and compliance services vendor to 700+ US financial institutions, was hit by Akira ransomware on August 14, 2025. Threat actors exploited a …

Cryptocurrency

Tweet by BobBodily

2025-08-12 [vendor] Odin.fun [loss] $7M [chain] bitcoin
Vector: Smart contract exploit / hack

Odin.fun, a bitcoin-based memecoin launchpad sort of like the popular pump.fun, was exploited for 58.2 BTC (~$7 million). The attacker had apparently manipulated the price of …

Ransomware

Pennsylvania Office of Attorney General INC Ransom Attack

2025-08-09 [vendor] Citrix NetScaler (VPN/ADC) [malware] INC Ransom [cve] CVE-2025-5777
Vector: INC Ransom exploited CVE-2025-5777 (Citrix Bleed 2, critical) in public-facing Citrix NetScaler appliances at the Pennsylvania Attorney General's Office

On August 9, 2025, the INC Ransom ransomware group attacked the Pennsylvania Office of the Attorney General, knocking its website, email, and phone lines offline for approximately …

Supply chain [SC]

HIPAA Journal

2025-08-09 [vendor] Oracle E-Business Suite (Oracle Concurrent Processing) [cve] CVE-2025-61882 +1
Vector: CWE-306: Missing Authentication for Critical Function (CVE-2025-61882 Oracle EBS unauthenticated RCE, CVSS 9.8)

The Cl0p ransomware group exploited CVE-2025-61882, a critical CVSS 9.8 zero-day unauthenticated remote code execution vulnerability in Oracle E-Business Suite (EBS), beginning as …

Cloud [SC]

Salesloft Drift OAuth Token Supply Chain Attack

2025-08-08 [vendor] Salesloft Drift (AI chat/sales engagement platform); Salesforce; Google Workspace; Slack
Vector: UNC6395 compromised Salesloft's Drift AI chatbot integration and stole OAuth authentication tokens used to connect Drift with downstream customer Salesforce, Google Workspace, and Slack environments

Between August 8–18, 2025, threat actors tracked as UNC6395 exploited compromised OAuth tokens from the Salesloft Drift integration to gain unauthorized access to connected …

Data leak

University of Phoenix Data Breach - Oracle EBS Zero-Day CVE-2025-61882 (3.5M)

2025-08-01 [vendor] Oracle E-Business Suite (EBS) [cve] CVE-2025-61882
Vector: Attackers exploited CVE-2025-61882, a zero-day vulnerability in Oracle E-Business Suite (EBS), to access the university's network and exfiltrate sensitive data; attack tactics consistent with Clop ransomware gang

Beginning in August 2025, attackers exploited CVE-2025-61882 (a zero-day in Oracle E-Business Suite) to breach the University of Phoenix's network and steal sensitive data. The …

Supply chain [SC]

Canada Government 2Keys Corporation Identity Services Breach (ESDC, CBSA, CRA)

2025-08-01 [vendor] 2Keys Corporation (digital identity/authentication services)
Vector: Threat actors compromised 2Keys Corporation, a third-party digital identity service provider contracted by the Canadian federal government, gaining access to authentication data for government service accounts

In September 2025, the Canadian government disclosed that 2Keys Corporation, a digital identity and authentication service provider contracted by multiple federal agencies, had …

Data leak

Chess.com Third-Party File Transfer Provider Breach

2025-08-01
Vector: Chess.com's unnamed third-party file transfer provider was compromised, resulting in the exfiltration of customer data stored in that system

Chess.com, the world's largest online chess platform with over 100 million registered users, disclosed in September 2025 that a third-party file transfer provider had been …

Data leak

Harrods Third-Party Vendor Breach

2025-08-01
Vector: A third-party vendor used by Harrods for customer relationship management was compromised, exposing online customer contact details

In September 2025, Harrods, the iconic London luxury department store, disclosed that a third-party vendor had been compromised, exposing contact details for online customers. …

Supply chain [SC]

JFrog Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

JFrog Help Center. JFrog documentation has moved to a new and improved site at docs.jfrog.com. The Help Center will continue to serve as your dedicated hub for Support and FAQ …

Supply chain [SC]

Megaport Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Megaport Trust Center | Powered by SafeBase. See how Megaport manages their security program with SafeBase. Welcome to the Megaport Trust Center, where we demonstrate our …

Supply chain [SC]

Pi-hole Third-Party Breach (August 2025)

2025-08-01 [vendor] GiveWP WordPress
Vector: Compromise of third-party service provider / vendor relationship

Pi-hole discloses data breach triggered by WordPress plugin flaw. Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed …

Supply chain [SC]

Rubrik Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesforce-Connected Third-Party Drift Application Supply Chain Incident Response. We use cookies to improve your experience, analyze traffic, and personalize content. Some are …

Supply chain [SC]

Tanium Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesloft Drift Data Breach: What We Know and What We're Doing. Hackers breached Salesloft in a major data theft campaign, stealing OAuth and refresh tokens linked to the Drift AI …

Supply chain [SC]

Zscaler Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s. Zscaler swiftly mitigates a security incident impacting Salesloft Drift, and ensuring robust protection against …

Cloud [SC]

Chanel Third-Party Breach (August 2025)

2025-08-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

Fashion giant Chanel hit in wave of Salesforce data theft attacks. French fashion giant Chanel is the latest company to suffer a data breach in an ongoing wave of Salesforce data …

Cloud [SC]

Cisco Third-Party Breach (August 2025)

2025-08-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

Cisco discloses data breach impacting Cisco.com user accounts. Cisco has disclosed that cybercriminals stole the basic profile information of users registered on Cisco.com …

Cloud [SC]

PagerDuty Third-Party Breach (August 2025)

2025-08-01 [vendor] Drift (Salesloft)
Vector: Compromise of third-party service provider / vendor relationship

Update: Salesloft’s Drift Integration Security Incident Impacting Some PagerDuty Salesforce Data. Per our August 29 post, we were notified in late August that PagerDuty (and our …

Cloud [SC]

Pandora Third-Party Breach (August 2025)

2025-08-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

Pandora confirms data breach amid ongoing Salesforce data theft attacks. Danish jewelry giant Pandora has disclosed a data breach after its customer information was stolen in the …

Cloud [SC]

TransUnion Third-Party Breach (August 2025)

2025-08-01 [vendor] Salesforce
Vector: Compromise of third-party service provider / vendor relationship

TransUnion suffers data breach impacting over 4.4 million people. Consumer credit reporting giant TransUnion warns it suffered a data breach exposing the personal information of …

Data leak [SC]

TransUnion Third-Party Salesforce App Breach - 4.4M Consumers

2025-07-28 [vendor] Salesforce; third-party support application
Vector: Attackers (attributed to ShinyHunters/UNC6395) gained access to a third-party Salesforce-based application used by TransUnion for US consumer support operations, likely via the SalesLoft Drift OAuth token supply chain attack

TransUnion disclosed on August 28, 2025, that unauthorized actors accessed a third-party application serving its US consumer support operations between July 28–30, 2025. The attack …

Cryptocurrency

Tweet by CyversAlerts

2025-07-28 [vendor] SuperRare [loss] $731,000 [chain] ethereum
Vector: Smart contract exploit / hack

A hacker stole RARE tokens priced at around $731,000 after exploiting a vulnerability in a staking contract for the SuperRare NFT platform. The attacker funded the exploiter wallet …

Ransomware

City of St. Paul, Minnesota Interlock Ransomware Attack

2025-07-25 [malware] Interlock ransomware
Vector: Unknown; attack described as sophisticated; Interlock typically uses drive-by downloads and ClickFix social engineering

The City of St. Paul, Minnesota (state capital) suffered a ransomware attack beginning July 25, 2025. The city shut down all networks on August 11 after confirming it was …

Data leak

Tweet thread by WOO X

2025-07-24 [vendor] WOO X [loss] $14M
Vector: Phishing attack

Attackers who compromised devices belonging to a WOO X employee stole $14 million from users of the Taiwanese WOO X cryptocurrency exchange. The phishing attack on the employee …

Data leak

Tweet by SlowMist

2025-07-16 [vendor] BigONE [loss] $27M
Vector: Smart contract exploit / hack

The BigONE cryptocurrency exchange was hacked for more than $27 million, which the hacker quickly swapped for various other tokens. The attacker compromised one of the exchange's …

Cloud

Allianz Life Insurance Data Breach (ShinyHunters/Scattered Spider)

2025-07-16 [vendor] Salesforce CRM
Vector: Vishing / social engineering: attackers impersonated IT helpdesk to trick an employee or vendor into granting access to a cloud-based Salesforce CRM system; Salesforce Data Loader used to bulk-exfiltrate data

On July 16, 2025, threat actors gained access to a third-party cloud CRM (Salesforce) used by Allianz Life Insurance of North America via social engineering/vishing. Attackers used …

Cryptocurrency

Tweet thread by CertiK

2025-07-15 [vendor] Arcadia Finance [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

The Arcadia Finance defi margin protocol was exploited for $3.5 million after an attacker found a vulnerability in a project smart contract. The attacker quickly swapped the stolen …

Cryptocurrency

Tweet by Ramon | Kinto

2025-07-10 [vendor] Kinto token crashes [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The price of Kinto's $K token suddenly crashed 90%, sparking accusations of a rug pull. A tranche of investor tokens had just been unlocked recently, leading some to speculate that …

Cryptocurrency

Tweet by PeckShield

2025-07-09 [vendor] GMX [loss] $42M [chain] ethereum
Vector: Smart contract exploit / hack

The decentralized perpetual exchange GMX has been exploited for $42 million. The exploit involved a vulnerability in one version of the exchange's price calculation smart contract. …

Cryptocurrency

Tweet by Texture

2025-07-09 [vendor] Texture [loss] $2M [chain] solana
Vector: Smart contract exploit / hack

An attacker exploited the Solana-based lending protocol Texture, stealing $2.2 million in user funds from one of the project's vaults.Shortly after the attack, Texture sent a …

Cryptocurrency

Tweet thread by deeberiroz

2025-07-09 [vendor] VennBuild discloses bug [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

On July 9, security researchers at VennBuild and other firms disclosed a "critical backdoor" affecting thousands of smart contracts, which one of the researchers said left "over …

Ransomware

Ingram Micro SafePay Ransomware Attack

2025-07-02 [vendor] Palo Alto GlobalProtect (VPN) [malware] SafePay
Vector: SafePay ransomware gained initial access via Ingram Micro's GlobalProtect VPN platform, likely through leaked credentials or password-spraying

On July 2–3, 2025, the SafePay ransomware group exfiltrated files from Ingram Micro's internal repositories. Ingram Micro (a leading global IT distributor processing ~$15B in …

Data leak

700Credit Automotive Credit Verification Data Breach - 5.8M Vehicle Dealer Customers

2025-07-01
Vector: Attackers compromised a partner's system in July 2025 and gained unauthorized access to a third-party API linked to 700Credit's web application, likely via web application vulnerability or misconfiguration

700Credit — the largest provider of credit reporting, identity verification, fraud and compliance services for US automotive dealerships — suffered a data breach between …

Data leak

McDonald's Paradox AI Chatbot Breach (64M Job Applicants)

2025-07-01 [vendor] Paradox, Inc. AI chatbot / hiring platform
Vector: Third-party AI chatbot provider Paradox, Inc. used by McDonald's for automated job application processing was compromised, exposing applicant data collected through the hiring platform

In July 2025, McDonald's disclosed a breach affecting approximately 64 million job applicants whose data was stored on systems operated by Paradox, Inc., McDonald's third-party …

Data leak

PayPal Working Capital Loan Application Data Exposure - Code Error

2025-07-01 [vendor] PayPal Working Capital (PPWC loan application)
Vector: Routine code update to the PayPal Working Capital (PPWC) loan application contained a programming error that left customer PII accessible without authorization for approximately six months

A code update error in PayPal's Working Capital loan application exposed approximately 100 customers' personally identifiable information from July 1 to December 13, 2025 — …

Data leak

Air France-KLM Salesforce ShinyHunters Breach

2025-07-01 [vendor] Salesforce
Vector: ShinyHunters compromised Air France-KLM's Salesforce CRM environment through social engineering / vishing of a Salesforce-privileged employee, part of the broader 2025 ShinyHunters Salesforce campaign

Air France-KLM, the Franco-Dutch multinational airline group, disclosed in August 2025 that their Salesforce CRM environment had been compromised as part of the …

Data leak

TransUnion Salesforce Platform Breach (44M+ Records)

2025-07-01 [vendor] Salesforce
Vector: ShinyHunters compromised TransUnion's Salesforce environment through social engineering / vishing of a Salesforce-privileged user, part of the broader 2025 Scattered Spider/ShinyHunters Salesforce campaign targeting major enterprises

In August 2025, TransUnion confirmed it had been affected by the ShinyHunters/Scattered Spider Salesforce social engineering campaign, with limited personal information exposed for …

Supply chain [SC]

Allianz Life Third-Party Breach (July 2025)

2025-07-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Massive data breach confirmed by Allianz Life. U.S. life insurance firm Allianz Life had most of its 1.4 million customers' data compromised following a data breach this month, …

Supply chain [SC]

Louis Vuitton Third-Party Breach (July 2025)

2025-07-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Louis Vuitton says regional data breaches tied to same cyberattack. Luxury fashion giant Louis Vuitton confirmed that breaches impacting customers in the UK, South Korea, and …

Supply chain [SC]

McDonald's Third-Party Breach (July 2025)

2025-07-01 [vendor] Paradox, Inc.
Vector: Compromise of third-party service provider / vendor relationship

'123456' password exposed chats for 64 million McDonald’s job chatbot applications. Cybersecurity researchers discovered a vulnerability in McHire, McDonald's chatbot job …

Cloud

Qantas Salesforce Breach via ShinyHunters Vishing - 5.7M Customers

2025-07-01 [vendor] Salesforce CRM; Salesforce Data Loader (malicious OAuth app abuse)
Vector: ShinyHunters (Scattered Lapsus$ Hunters) used vishing (voice phishing) to impersonate IT support staff, tricking employees into visiting Salesforce's connected app setup page and entering a 'connection code' that linked a malicious OAuth app (malicious Salesforce Data Loader) to the employee's Salesforce environment

In July 2025, Qantas Airways (Australia's flag carrier) suffered a Salesforce data breach attributed to ShinyHunters/Scattered Lapsus$ Hunters via a vishing campaign. Approximately …

Cloud

Cisco Salesforce ShinyHunters Breach

2025-07-01 [vendor] Salesforce
Vector: ShinyHunters compromised Cisco's Salesforce CRM environment through social engineering / vishing of a Salesforce-privileged employee, part of the broader 2025 ShinyHunters Salesforce campaign

Cisco confirmed in August 2025 that it had been affected by the ShinyHunters Salesforce social engineering campaign. Exposed data included names, addresses, user IDs, email …

Cloud

Pandora and Chanel Salesforce ShinyHunters Breach

2025-07-01 [vendor] Salesforce
Vector: ShinyHunters compromised Pandora and Chanel's Salesforce CRM environments through social engineering / vishing, part of the broader 2025 ShinyHunters Salesforce campaign targeting major brand CRM instances

Pandora (Danish jewelry brand) and Chanel (French luxury fashion house) both disclosed in August 2025 that their Salesforce CRM environments had been compromised as part of the …

Cloud

Stellantis Salesforce ShinyHunters Vishing Breach

2025-07-01 [vendor] Salesforce
Vector: ShinyHunters compromised Stellantis's Salesforce environment through vishing/social engineering of a Salesforce-privileged user, part of the broader 2025 ShinyHunters Salesforce campaign

Stellantis, the multinational automotive manufacturer (maker of Jeep, Chrysler, Fiat, Peugeot, and other brands), disclosed in September 2025 that a breach via its Salesforce …

Data leak

Tweet thread

2025-06-23 [vendor] daytwo-thefts [loss] $4M
Vector: Smart contract exploit / hack

Christian Nieves, a New York man who goes by the handles "daytwo" and "PawsOnHips", has reportedly stolen more than $4 million through a theft ring where he impersonates Coinbase …

Data leak

Tweet thread

2025-06-21 [vendor] Hacken token crash [loss] $250,000
Vector: Smart contract exploit / hack

Web3 cybersecurity firm Hacken had a cybersecurity incident of their own when the private key belonging to a wallet with mint access for the project's $HAI token was leaked. …

Data leak

Aflac Insurance Data Breach (Scattered Spider)

2025-06-12
Vector: Social engineering / vishing (voice phishing): attackers impersonated employees to deceive IT help desk into granting account access

On June 12, 2025, Aflac insurance company's US network was compromised via social engineering. The attack is attributed to Scattered Spider, a financially motivated …

Data leak

Telegram post

2025-06-02 [vendor] BitoPro [loss] $12M
Vector: On-chain theft (attributed by zachxbt)

The Taiwanese cryptocurrency exchange BitoPro disclosed that they had suffered a theft from one of their hot wallets, which they said occurred during a system upgrade in which they …

Data leak

Prosper Marketplace Data Breach - 17.6M Peer-to-Peer Lending Customers

2025-06-01
Vector: Attackers used compromised credentials (likely a service account or employee login) to access Prosper's internal databases and issue unauthorized queries to extract customer data over approximately 3 months

Between June and August 2025, unauthorized actors accessed Prosper Marketplace's customer databases by exploiting compromised credentials. Prosper (a San Francisco-based …

Data leak

Vietnam Airlines Salesforce Breach via Scattered Lapsus$ Hunters - 23M Records

2025-06-01 [vendor] Salesforce CRM
Vector: Scattered Lapsus$ Hunters (ShinyHunters) breached Vietnam Airlines' Salesforce CRM instance as part of a campaign targeting 39+ companies via malicious OAuth app linked through vishing of employees

In October 2025, Scattered Lapsus$ Hunters published 63.62 GB of data (23+ million records) from Vietnam Airlines' Salesforce CRM system. The initial intrusion occurred around June …

Supply chain [SC]

Coinbase Third-Party Breach (June 2025)

2025-06-01 [vendor] TaskUs
Vector: Compromise of third-party service provider / vendor relationship

Coinbase breach tied to bribed TaskUs support agents in India. A recently disclosed data breach at Coinbase has been linked to India-based customer support representatives from …

Supply chain [SC]

Glasgow City Council Third-Party Breach (June 2025)

2025-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Glasgow City Council impacted by ‘cyber incident’. The Glasgow City Council announced that it was affected by an incident “disrupting a number of online services and which may have …

Supply chain [SC]

MainStreet Bank Third-Party Breach (June 2025)

2025-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

MainStreet Bank reports vendor cyber incident that leaked customer info. In regulatory filings with the Securities and Exchange Commission, MainStreet Bank's holding company said a …

Supply chain [SC]

Sharp Healthcare Third-Party Breach (June 2025)

2025-06-01 [vendor] Episource
Vector: Compromise of third-party service provider / vendor relationship

More than 5 million affected by data breach at healthcare tech firm Episource. California-based Episource disclosed in filings with the U.S. Department of Health and Human Services …

Supply chain [SC]

Switzerland Government Third-Party Breach (June 2025)

2025-06-01 [vendor] Radix (Zurich based and non-profit organization)
Vector: Compromise of third-party service provider / vendor relationship

Switzerland says government data stolen in ransomware attack. The government in Switzerland is informing that sensitive information from various federal offices has been impacted …

Cloud

Farmers Insurance Data Breach via ShinyHunters / Salesforce Third-Party (1.07M)

2025-05-29 [vendor] Salesforce (third-party vendor)
Vector: ShinyHunters and Scattered Spider breached a third-party vendor (believed to be Salesforce) used by Farmers Insurance, gaining unauthorized access to a database containing customer information

On May 29, 2025, hackers breached a third-party vendor system used by Farmers Insurance Exchange and its subsidiaries. Farmers was alerted to the suspicious activity on May 30, …

Cryptocurrency

Tweet by Cetus

2025-05-22 [vendor] Cetus [loss] $60M [chain] sui
Vector: Smart contract exploit / hack

An attacker stole $223 million from the Sui-based Cetus Protocol. The project announced shortly after that $163 million of the funds had been frozen, leaving around $60 million …

Ransomware

Kettering Health Interlock Ransomware Attack

2025-05-20 [malware] Interlock ransomware
Vector: Drive-by download from compromised legitimate website; ClickFix technique (fake CAPTCHA prompting users to run malicious code via Windows Run dialog)

Kettering Health, an Ohio health system running 14 medical centers and dozens of clinics primarily in the Dayton area, was hit by Interlock ransomware on May 20, 2025. …

Ransomware

Covenant Health Qilin Ransomware Attack

2025-05-18 [malware] Qilin
Vector: Qilin ransomware group gained unauthorized access to Covenant Health's IT environment; initial vector not publicly disclosed

Covenant Health (Catholic healthcare network serving Massachusetts, Maine, New Hampshire, Pennsylvania, Rhode Island, and Vermont) detected unauthorized activity on May 26, 2025, …

Data leak

Tweet by Curve Finance

2025-05-12 [vendor] Curve Finance website and Twitter account
Vector: DNS hijacking / domain takeover (front-end compromise)

The website and Twitter accounts belonging to the Curve Finance defi projects were compromised in quick succession. On May 5, an attacker compromised the Twitter account belonging …

Supply chain [SC]

Adidas Third-Party Breach (May 2025)

2025-05-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Adidas warns of data breach after customer service provider hack. German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and …

Supply chain [SC]

Catholic Health Third-Party Breach (May 2025)

2025-05-01 [vendor] Serviceaide
Vector: Compromise of third-party service provider / vendor relationship

Breaches at Serviceaide, Nationwide Recovery Services expose medical info of more than 500,000 people. Hospitals tied to the two companies announced breaches over the last week …

Supply chain [SC]

Marks & Spencer Third-Party Breach (May 2025)

2025-05-01 [vendor] Tata Consultancy Services (TCS)
Vector: Compromise of third-party service provider / vendor relationship

Marks & Spencer confirms customer data stolen in cyberattack. M&S said that some customer data — but not payment card details or passwords — had been breached in a recent …

Supply chain [SC]

TRG Medical Imaging Third-Party Breach (May 2025)

2025-05-01 [vendor] Nationwide Recovery Services (NRS)
Vector: Compromise of third-party service provider / vendor relationship

Nationwide Recovery Service Data Breach Victim List Grows: 560,000+ Individuals Affected. The list of victims from the data breach at the debt collection agency Nationwide Recovery …

Supply chain [SC]

Sharp HealthCare Episource Third-Party Breach

2025-05-01 [vendor] Episource (healthcare risk adjustment analytics)
Vector: Episource, a healthcare risk adjustment and analytics vendor, was breached, exposing patient records for Sharp HealthCare clients that had been shared with Episource for clinical documentation and risk adjustment analytics services

Sharp HealthCare, a major integrated regional health system in San Diego, California, disclosed in June 2025 that a breach at Episource, its third-party healthcare risk adjustment …

Cloud [SC]

BleepingComputer

2025-05-01 [vendor] SimpleHelp RMM (Remote Monitoring and Management) [malware] DragonForce ransomware [cve] CVE-2024-57726 +2
Vector: CWE-22: Path Traversal (CVE-2024-57727) and CWE-269: Improper Privilege Management (CVE-2024-57726)

The DragonForce ransomware cartel exploited three vulnerabilities in SimpleHelp RMM software (disclosed January 2025) to breach a managed service provider (MSP) and then pivot to …

Cryptocurrency

Tweet by zachxbt

2025-04-27 [vendor] $330 million in Bitcoin apparently stolen; laundering spikes Monero [loss] $331M [chain] monero, bitcoin
Vector: On-chain theft (attributed by zachxbt)

3,250 BTC (~$330 million) were apparently stolen from a bitcoin holder and then quickly moved through multiple exchanges and swapped for the Monero privacycoin. Such a massive swap …

Cryptocurrency

Tweet by Term Labs

2025-04-26 [vendor] Term Finance misconfiguration [loss] $600,000 [chain] ethereum
Vector: Software bug / unintentional loss

The Ethereum-based lending project Term Finance lost $1.6 million when an oracle misconfiguration resulted in unintended liquidations. The team later announced that they had …

Data leak [SC]

Marks & Spencer Tata Consultancy Services Breach

2025-04-22 [vendor] Tata Consultancy Services (IT outsourcing vendor) [malware] DragonForce ransomware
Vector: Scattered Spider (UNC3944) conducted a social engineering / vishing attack targeting Tata Consultancy Services (TCS) employees who had privileged access to M&S systems, gaining access to M&S Active Directory via NTLM hash relay and deploying DragonForce ransomware

Beginning around April 22, 2025, Scattered Spider (also tracked as UNC3944 and Octo Tempest) attacked Marks & Spencer, the UK's largest clothing retailer, by socially engineering …

Other

SK Telecom BPFDoor Malware Breach - 27 Million SIM Records

2025-04-18 [malware] BPFDoor; Tiny Shell
Vector: Multiple strains of malware (including 27 variants of BPFDoor backdoor, Tiny Shell, and other tools) installed on SK Telecom's internal servers; went undetected for approximately 3 years (2022–2025)

SK Telecom (South Korea's largest mobile carrier, ~27 million subscribers) officially confirmed a breach on April 19, 2025, after detecting malware on April 18 targeting its Home …

Data leak [SC]

Ericsson US Third-Party Service Provider Data Breach

2025-04-17 [vendor] Unnamed third-party service provider
Vector: Unauthorized access to an unnamed third-party service provider's systems that stored Ericsson employee and customer data

Between April 17–22, 2025, an unknown threat actor accessed files at an unnamed third-party service provider used by Ericsson Inc. (US operations). The investigation concluded in …

Cryptocurrency

Tweet by KiloEx

2025-04-14 [vendor] KiloEx [loss] $750,000 [chain] ethereum, bsc
Vector: Oracle price manipulation

KiloEx, a decentralized perpetual futures exchange, was exploited for $7.5 million. An attacker executed an oracle manipulation attack on KiloEx's pricing smart contracts to steal …

Ransomware

Co-op and Harrods ransomware attacks (DragonForce / Scattered Spider) 2025

2025-04-01 [vendor] Co-op Group (UK retailer/food/funeral); Harrods (UK luxury retailer) [malware] DragonForce ransomware
Vector: CWE-306: Missing Authentication for Critical Function / social engineering (Scattered Spider affiliates used vishing and employee impersonation to bypass MFA and conduct service-desk password resets)

Scattered Spider (UNC3944) affiliates acting as DragonForce ransomware-as-a-service operators conducted a wave of attacks against UK retailers in April–May 2025. Co-op confirmed …

Data leak

Adidas Third-Party Customer Service Provider Breach

2025-04-01
Vector: An unauthorized actor gained access to an unnamed third-party customer service provider used by Adidas, obtaining customer contact data stored in that system

In May 2025, Adidas disclosed that a data breach had occurred via an unnamed third-party customer service provider. The breach exposed customer contact information including names, …

Data leak

UK Legal Aid Agency Breach (2,000 Legal Service Providers)

2025-04-01
Vector: Attackers exploited an unpatched vulnerability in the Legal Aid Agency's online portal to gain unauthorized access to its database

In May 2025, the UK Legal Aid Agency (part of the Ministry of Justice) disclosed a significant data breach affecting information on 2,000 legal service providers and their clients. …

Supply chain [SC]

Ascension Third-Party Breach (April 2025)

2025-04-01 [vendor] Former business partner
Vector: Compromise of third-party service provider / vendor relationship

Ascension discloses new data breach after third-party hacking incident. ​Ascension, one of the largest private healthcare systems in the United States, is notifying patients that …

Supply chain [SC]

âRoyal Mail Third-Party Breach (April 2025)

2025-04-01 [vendor] Spectos GmbH
Vector: Compromise of third-party service provider / vendor relationship

In 2025, âRoyal Mail experienced a data security incident via a third-party vendor relationship. The compromised third-party vendor was Spectos GmbH. Source reporting: …

Supply chain [SC]

Nationwide Recovery Services Healthcare Billing Vendor Breach (Multiple Hospitals)

2025-04-01 [vendor] Nationwide Recovery Services (medical billing/RCM)
Vector: Nationwide Recovery Services (NRS), a medical billing and revenue cycle management vendor, suffered a breach of its systems, exposing patient data from more than a dozen healthcare provider clients

In May 2025, Nationwide Recovery Services (NRS), a healthcare billing and accounts receivable management vendor, disclosed a data breach affecting over a dozen healthcare provider …

Cryptocurrency

On-chain messages

2025-03-31 [vendor] zkLend [chain] ethereum
Vector: Phishing attack

The zkLend lending platform was hoping they could secure the return of stolen funds from the attacker who stole 3,667 ETH (~$9.5 million at the time) from the platform in …

Data leak

Royal Mail Spectos GmbH Third-Party Breach

2025-03-29 [vendor] Spectos GmbH (data analytics/service monitoring)
Vector: Threat actor compromised Spectos GmbH, a German data analytics and service monitoring firm used by Royal Mail to track delivery performance metrics, gaining access to Royal Mail customer and operational data stored on Spectos systems

In late March 2025, a threat actor claimed to have stolen approximately 144GB of data from Royal Mail by compromising Spectos GmbH, a data analytics vendor used by Royal Mail for …

Cryptocurrency

Telegram post

2025-03-28 [vendor] bc1qvl theft [loss] $46M [chain] bitcoin
Vector: On-chain theft (attributed by zachxbt)

A Coinbase customer reportedly lost 400 BTC (~$35 million) in a scam identified by blockchain sleuth zachxbt. While investigating the massive theft from the single customer, he …

Ransomware

DaVita Inc. Interlock Ransomware Attack

2025-03-24 [malware] Interlock ransomware
Vector: Spear phishing emails targeting employees, followed by exploitation of vulnerabilities on a third-party internet-facing file transfer platform

DaVita Inc., one of the largest kidney dialysis providers in the US, disclosed a ransomware attack on April 12, 2025. Intrusion began March 24, 2025 and was eradicated April 12. …

Other

Tweet by BinanceWallet

2025-03-24 [vendor] Binance insider trading

Binance announced on Twitter that they had fired an employee after discovering that they had engaged in insider trading. The employee took a large position in a token that he knew …

Cloud

Ivanti Connect Secure zero-day exploitation CVE-2025-22457 (UNC5221 / China-nexus)

2025-03-15 [vendor] Ivanti Connect Secure VPN (versions 22.7R2.5 and earlier; ICS 9.x end-of-life) [malware] TRAILBLAZE (in-memory dropper), BRUSHFIRE (passive backdoor), SPAWN ecosystem [cve] CVE-2025-22457
Vector: CWE-121: Stack-based Buffer Overflow (CVE-2025-22457 — stack buffer overflow in Ivanti Connect Secure enabling remote code execution)

CVE-2025-22457 is a stack-based buffer overflow in Ivanti Connect Secure. Ivanti initially classified it as a low-risk DoS-only vulnerability and patched it 11 February 2025 in …

Ransomware

BleepingComputer

2025-03-08 [vendor] Yale New Haven Health System IT network
Vector: CWE-284: Improper Access Control

Yale New Haven Health System, a Connecticut-based health system affiliated with Yale School of Medicine, detected unauthorized network access on March 8, 2025. The health system …

Data leak

"Zoth Hack Analysis"

2025-03-06 [vendor] Zoth [loss] $285,000
Vector: Smart contract exploit / hack

Zoth, a restaking platform for "real world assets" (or RWAs), was hacked for around $285,000 when an exploiter discovered a bug in the platform's collateral calculations. This …

Cryptocurrency

Tweet by 1inch

2025-03-05 [vendor] 1inch [loss] $5M [chain] ethereum
Vector: Smart contract exploit / hack

An attacker exploited a smart contract belonging to the 1inch DEX aggregator, stealing $5 million in the USDC stablecoin and wETH. According to the platform, the vulnerability …

Supply chain [SC]

StreamElements Third-Party Breach (March 2025)

2025-03-01 [vendor] Gooten
Vector: Compromise of third-party service provider / vendor relationship

StreamElements Confirms Third-Party Data Breach from an Infostealer Infection. Stay informed with the latest insights in our Infostealers weekly report. Explore key findings, …

Ransomware

Berkeley Research Group (BRG) Ransomware Attack

2025-02-28 [vendor] Microsoft Teams [malware] Chaos ransomware
Vector: Social engineering via Microsoft Teams: attacker impersonated an internal IT worker to gain access to an employee's laptop

Berkeley Research Group (BRG), a major consulting and financial advisory firm, suffered a ransomware attack discovered March 2, 2025. Unauthorized activity occurred February 28 – …

Cryptocurrency

Complaint

2025-02-27 [vendor] Mirashi [loss] $40M [chain] bitcoin
Vector: Phishing attack

A plaintiff named Mandar Mirashi has filed a lawsuit against an unknown defendant accused of stealing around $40 million in bitcoin through a sophisticated phishing attack and/or …

Cryptocurrency

Tweet by Suji Yan

2025-02-27 [vendor] Suji Yan wallet [loss] $4M [chain] ethereum
Vector: Private key compromise

Suji Yan, the founder of the Mask Network, suffered the loss of more than $4 million in various cryptocurrency assets to an apparent wallet hack. According to Yan, the theft …

Cryptocurrency

"0xInfini Incident Analysis"

2025-02-24 [vendor] Almost $50 million stolen from Infini "stablecoin neobank" [loss] $50M [chain] ethereum
Vector: Smart contract exploit / hack

Around $49.5 million in the USDC stablecoin was stolen from the Infini crypto-focused "stablecoin neobank", a fintech company that promises "financial freedom" by "democratizing …

Supply chain [SC]

Bybit Cryptocurrency Exchange Hack via Safe{Wallet} Supply Chain

2025-02-21 [vendor] Safe{Wallet} (multi-sig wallet UI)
Vector: Social engineering against a Safe{Wallet} developer; AWS session token theft to compromise Safe{Wallet} infrastructure; malicious JavaScript injected into transaction signing UI

On February 21, 2025, Bybit (Dubai-based cryptocurrency exchange) suffered the largest cryptocurrency theft ever recorded: $1.46 billion in Ethereum stolen from a cold wallet. …

Cryptocurrency

Tweet by Ben Zhou

2025-02-21 [vendor] Bybit [loss] $1.5B [chain] ethereum
Vector: Phishing attack

In what is looking like largest ever theft from a cryptocurrency exchange, attackers took control of a hot wallet belonging to the Bybit cryptocurrency exchange and moved a massive …

Cryptocurrency

Tweet by 0xCygaar

2025-02-18 [vendor] Abstract Cardex [loss] $400,000 [chain] ethereum
Vector: Smart contract exploit / hack

Around $400,000 in ETH was stolen from around 9,000 wallets on the Abstract layer-2 network, which is built by the same company that makes the Pudgy Penguins NFTs. It appears that …

Other

Opexus Federal Contractor Insider Breach

2025-02-18
Vector: Insider threat: two employees (twin brothers) with prior hacking convictions retained privileged access; exfiltrated files via USB drive and deleted government databases during and after termination meeting

Opexus, a Thoma Bravo-owned software company providing records management services to nearly every US federal agency, was compromised by twin brothers Muneeb and Suhaib Akhter who …

Supply chain [SC]

StreamElements Gooten Merchandise Operations Vendor Breach

2025-02-15 [vendor] Gooten (merchandise/print-on-demand fulfillment)
Vector: Gooten, a merchandise fulfillment and print-on-demand vendor used by StreamElements for its creator merchandise programs, was compromised, exposing StreamElements content creator customer data

StreamElements, a platform for live streaming tools and creator merchandise, disclosed in March 2025 that a third-party vendor breach had exposed customer data. The breach …

Cryptocurrency

Tweet by Lookonchain

2025-02-14 [vendor] Milei memecoin promotion [loss] $107M [chain] solana

A tweet from Argentina's president Javier Milei promoted a memecoin called Libra, which he described as a "private project [that] will [be] dedicated to encouraging the growth of …

Data leak

Tweet by CyversAlerts

2025-02-12 [vendor] zkLend [loss] $10M
Vector: Smart contract exploit / hack

The Starknet-based lending platform zkLend was exploited for around $9.5 million. zkLend paused the protocol after the attack was discovered, and began working with various crypto …

Cryptocurrency

Tweet by Four.Meme

2025-02-11 [vendor] Four.Meme [loss] $183,000 [chain] bsc
Vector: Smart contract exploit / hack

A BNB Chain memecoin platform, Four.Meme, announced on Twitter that they were "currently experiencing a malicious attack". The team briefly paused a portion of the service while …

Data leak

Tweet thread by zachxbt

2025-02-03 [vendor] Coinbase accused of failing to prevent phishing [loss] $300M
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has accused the popular American cryptocurrency exchange Coinbase of "fail[ing] to stop its users losing $300M+ per year to social engineering scams". He …

Ransomware

Marks & Spencer ransomware attack (Scattered Spider / DragonForce)

2025-02-01 [vendor] Marks & Spencer (UK retailer) — VMware ESXi virtual machines; service desk identity management [malware] DragonForce ransomware
Vector: CWE-306: Missing Authentication for Critical Function / social engineering (attackers impersonated an M&S employee and called the third-party service desk to perform a password reset; obtained NTDS.dit to crack hashes offline)

Scattered Spider (UNC3944) gained initial access to M&S systems as early as February 2025 via social engineering of the third-party IT service desk (vishing/impersonation). …

Supply chain [SC]

GrubHub Third-Party Breach (February 2025)

2025-02-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

GrubHub data breach impacts customers, drivers, and merchants. ​Food delivery company GrubHub disclosed a data breach impacting the personal information of an undisclosed number of …

Cryptocurrency

"AlleyCat - The Gambling Deployer!"

2025-02-01 [vendor] AlleyCat project developer takes presale money to fund gambling habit [loss] $130,000 [chain] solana
Vector: Exit scam / rug pull

The creator of the AlleyCat Solana-based cryptocurrency project has reportedly taken about 600 SOL (~$130,000) raised during the project's presale and transferred it to gambling …

Cryptocurrency

"Poetic Justice"

2025-01-31 [vendor] Rugpuller tool [loss] $10M [chain] solana
Vector: Exit scam / rug pull

A suite of software tools called DogWifTools was popular among memecoin creators looking to rug pull unsuspecting traders. By helping token creators mask supply control and fake …

Cryptocurrency

Tweet by Ether Strategy

2025-01-30 [vendor] Ether Strategy destroys over $500,000 of ETH [loss] $535,850 [chain] ethereum

A Ethereum-based project promising to duplicate the bitcoin leveraged investment strategy used by MicroStrategy has announced that, prior to even launching, 165 ETH (~$535,850) was …

Cryptocurrency

Tweet thread by Arkham

2025-01-30 [vendor] Ross Ulbricht memecoin mistake [chain] solana
Vector: MEV / sandwich attack

Ross Ulbricht, the founder of the Silk Road darknet market place, earned a presidential pardon on January 21 as an apparent thank you by President Trump to the Libertarian Party. …

Cloud

Western Sydney University data breach (2025) — 10,000 students

2025-01-28 [vendor] Western Sydney University SSO / identity management systems
Vector: CWE-287: Improper Authentication (single sign-on (SSO) service compromised; insider/former student gained unauthorised access)

Unauthorised access to Western Sydney University's systems via the SSO service occurred between 28 January and 25 February 2025. Approximately 10,000 current and former students …

Ransomware

Frederick Health Medical Group Ransomware Attack

2025-01-27
Vector: Ransomware attack targeting a shared network drive; attackers gained unauthorized access to a shared drive containing sensitive patient information (separate from the EMR system)

On January 27, 2025, Frederick Health Medical Group (a Maryland-based healthcare network with 25+ locations) announced a ransomware attack that compromised the protected health …

Ransomware

HIPAA Journal

2025-01-27 [vendor] Episource medical coding and risk adjustment platform
Vector: CWE-284: Improper Access Control

Episource LLC, a medical coding and risk adjustment company and Optum/UnitedHealth Group subsidiary, detected a ransomware intrusion on February 6, 2025, after unauthorized access …

Data leak

Tweet by Frederico0x

2025-01-23 [vendor] Phemex [loss] $70M
Vector: Smart contract exploit / hack

The Singapore-based Phemex cryptocurrency exchange has acknowledged the compromise of some of the exchange's hot wallets, which saw outflows of at least $37 million across multiple …

Other

Tweet thread

2025-01-23 [vendor] Thorchain
Vector: Protocol collapse / insolvency

The ThorChain project is in crisis amid news that the project is insolvent. In order to prevent what would effectively be a bank run and likely death spiral, the project has paused …

Cloud [SC]

Oracle Health (Cerner) Legacy Server Breach - 80 Hospitals Patient Data

2025-01-22 [vendor] Oracle Health (formerly Cerner) EHR [cve] CVE-2025-30154
Vector: Attacker used stolen credentials to access legacy Cerner EHR servers that had not yet been migrated to Oracle Cloud; CVE-2025-30154 exploited in related Oracle infrastructure

On or after January 22, 2025, a threat actor used stolen credentials to access legacy Cerner electronic health record (EHR) servers belonging to Oracle Health that had not yet been …

Ransomware

SimonMed Imaging Medusa Ransomware Attack - 1.27M Patients

2025-01-21 [malware] Medusa
Vector: SimonMed was alerted on January 27 by a vendor experiencing a security issue; suspicious activity was detected on SimonMed's own systems the following day, suggesting possible supply chain or third-party initial access

Between January 21 and February 5, 2025, the Medusa ransomware group exfiltrated data from SimonMed Imaging (a large US radiology/medical imaging provider). Medusa claimed more …

Cryptocurrency

Tweet by SlowMist

2025-01-21 [vendor] Fake Trump Twitter account memecoins [loss] $1M [chain] solana
Vector: Smart contract exploit / hack

A Twitter account called @TrumpDailyPosts has more than 1.3 million followers on Twitter. While the account does automatically crosspost to Twitter any posts Donald Trump makes on …

Other

DOGE Access to Federal Government Data Systems

2025-01-20
Vector: Authorised but controversial access granted to DOGE operatives to federal systems including OPM, Treasury payment systems (handling $6T in payments), USAJOBS, and other agencies

Starting January 20, 2025, operatives associated with the Department of Government Efficiency (DOGE), led by Elon Musk, were granted unprecedented access to sensitive federal …

Cryptocurrency

Tweet by Melania Trump

2025-01-19 [vendor] Melania Trump's tweet announcing the memecoin [chain] solana

Before people had a chance to process the fact that the incoming president of the United States had just launched his own transparent crypto cash-grab, the soon-to-be First Lady …

Cryptocurrency

Tweet by Donald Trump

2025-01-17 [vendor] Trump memecoin promo image [chain] solana

In what is likely a preview of the levels of grift about to come — levels previously not thought possible — Trump has launched a Solana memecoin two days before his inauguration. …

Other

Order

2025-01-17 [vendor] Genesis
Vector: Regulatory / legal action

The Digital Currency Group has agreed to settle with the SEC for $38 million over charges that its Genesis subsidiary misled investors. When the hedge fund Three Arrows Capital …

Other

"MakersPlace Announces Market Exit"

2025-01-16 [vendor] MakersPlace NFT marketplace
Vector: Protocol collapse / insolvency

Citing "ongoing market challenges and funding difficulties", the MakersPlace NFT platform announced it will be shutting down after six years of operations. The company had raised …

Cryptocurrency

"The Idols NFT"

2025-01-14 [vendor] The Idols NFT [loss] $324,000 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker noticed a vulnerability in a smart contract for The Idols, an NFT project that also incorporates ETH staking functionality. They discovered that a function used to …

Cryptocurrency

Tweet by SlowMist

2025-01-12 [vendor] UniLend [loss] $197,600 [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

The UniLend project, which advertises itself as a "unified platform for all things AI and defi", was exploited for almost $200,000. An attacker was able to take advantage of a bug …

Other

Tweet by David Hoffman

2025-01-11 [vendor] Bankless hosts slammed for dumping tokens

The hosts of the Bankless crypto podcast have landed in hot water after selling off some of the substantial quantities of $AICC tokens they were allocated as investors in the …

Cryptocurrency

"Moby Post-Mortem Report / Growth Plan"

2025-01-08 [vendor] Moby Trade theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

The Moby Trade defi options protocol suffered a $1 million loss, narrowly avoiding the loss of another nearly $1.5 million. The project team stated that a hacker had "identified …

Cryptocurrency

Tweet by Orange Finance

2025-01-08 [vendor] Orange Finance [loss] $840,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Arbitrum-based liquidity management project Orange Finance suffered at least $840,000 in losses after hackers compromised the project's admin address, then used it to upgrade …

Ransomware

Tata Technologies Hunters International Ransomware Attack

2025-01-01 [malware] Hunters International ransomware
Vector: Unknown; Hunters International typically uses phishing and exploits internet-facing systems

Tata Technologies, a Tata Group subsidiary providing engineering and technology services in automotive, aerospace, and industrial sectors (12,500+ employees, operating in 27 …

Data leak

Coinbase TaskUs Outsourced Customer Support Bribery Breach

2025-01-01 [vendor] TaskUs (outsourced customer support)
Vector: Threat actors bribed and recruited rogue agents working at TaskUs, Coinbase's outsourced customer support contractor in India, to steal customer data from Coinbase's internal support tools

Starting in approximately early 2025, cybercriminals recruited and bribed several customer support agents employed by TaskUs, Coinbase's outsourced support provider operating from …

Supply chain [SC]

94 K-12 Schools Third-Party Breach (January 2025)

2025-01-01 [vendor] PowerSchool
Vector: Compromise of third-party service provider / vendor relationship

PowerSchool hack exposes student, teacher data from K-12 districts. Education software giant PowerSchool has confirmed it suffered a cybersecurity incident that allowed a threat …

Supply chain [SC]

Khalil Foundation Third-Party Breach (January 2025)

2025-01-01 [vendor] Transform Studios
Vector: Compromise of third-party service provider / vendor relationship

Billing Support Vendor Notifies 701K Patients About December 2023 Data Breach. Medusind, a Florida-based revenue cycle management vendor and practice management software provider, …

Supply chain [SC]

Rostelecom Third-Party Breach (January 2025)

2025-01-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Russian telecom giant Rostelecom investigates suspected cyberattack on contractor. Russia's Rostelecom said that it was responding to a cyberattack on a contractor that helps to …

Supply chain [SC]

Stiiizy Third-Party Breach (January 2025)

2025-01-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

380,000 Impacted by Data Breach at Cannabis Retailer Stiiizy. This website stores cookies on your computer. These cookies are used to improve your website experience and provide …

Supply chain [SC]

TalkTalk Third-Party Breach (January 2025)

2025-01-01 [vendor] CSG Ascendon
Vector: Compromise of third-party service provider / vendor relationship

TalkTalk investigates breach after data for sale on hacking forum. UK telecommunications company TalkTalk is investigating a third-party supplier data breach after a threat actor …

Supply chain [SC]

TalkTalk CSG Ascendon Telecom Platform Breach

2025-01-01 [vendor] CSG Ascendon (telecom billing/subscriber management SaaS)
Vector: Threat actors compromised CSG Ascendon, a third-party telecom billing and subscriber management platform used by TalkTalk, gaining access to subscriber account records

In January 2025, TalkTalk, the UK telecommunications provider, disclosed that a data breach had occurred via CSG Ascendon, its third-party subscriber management and billing …

Supply chain [SC]

Magento Extension Supply Chain Attack (Tigren, Meetanshi, MGS — 500-1000 E-Commerce Stores)

2025-01-01 [vendor] Tigren; Meetanshi; MGS (Magento extensions)
Vector: Attackers compromised the servers of three Magento extension vendors (Tigren, Meetanshi, and MGS/Mageplaza) and trojanized their extension packages to include a backdoor that exfiltrated customer payment card data and credentials from the e-commerce stores that installed them

In May 2025, security researchers disclosed that three Magento extension vendors — Tigren, Meetanshi, and MGS (Mageplaza) — had their extension distribution servers compromised. …

Supply chain [SC]

Trimble Cityworks Vulnerability Exploited Against US Local Governments

2025-01-01 [vendor] Trimble Cityworks (GIS asset/work-order management) [cve] CVE-2025-0994
Vector: Attackers exploited a deserialization vulnerability in Trimble Cityworks, a GIS-based work order and asset management system used by local governments, to gain unauthorized access to municipal infrastructure systems

Beginning in early 2025, threat actors exploited CVE-2025-0994, a critical deserialization vulnerability in Trimble Cityworks, to compromise GIS asset and work-order management …

Credential theft

Coinbase Insider Bribery Data Breach

2025-01-01
Vector: Insider threat: cybercriminals bribed overseas customer support contractors (via TaskUs vendor) to exfiltrate customer data from internal support tools

Attackers bribed at least one overseas customer support agent contracted through third-party vendor TaskUs to access and steal Coinbase customer data from internal support systems. …

Ai

AI-Enabled Cyberattack Acceleration — Reduced Breakout Times, Autonomous Attack Chains

2025-01-01 [vendor] Multiple sectors — financial services, healthcare, critical infrastructure, technology companies globally
Vector: Threat actors use AI to automate reconnaissance, accelerate vulnerability exploitation, reduce time-to-breach, generate convincing phishing content at scale, and create adaptive malware that evades static detection; defenders face structural disadvantage as AI reduces skill barriers for attackers while defenders face integration and compliance costs

By 2025-2026, documented evidence shows AI is systematically accelerating cyberattack timelines and lowering barriers to entry for attackers, while defenders face structural …

Ai

AI-Powered Identity Theft Wave — Synthetic Identity Fraud, Deepfake KYC Bypass 2025-2026

2025-01-01 [vendor] Financial institutions, cryptocurrency exchanges, and identity verification platforms globally
Vector: Threat actors use generative AI tools to create synthetic identities combining real and fabricated personal data; deepfake video and voice generation is used to bypass live KYC (Know Your Customer) verification at banks and cryptocurrency exchanges; AI-driven phishing and vishing attacks increase success rates and reduce costs for attackers

By 2025-2026, AI-powered identity theft had emerged as a major and growing threat category, representing a structural shift in how identity fraud and credential theft are conducted …

Cloud

Oracle Cloud (OCI) Infrastructure Breach — 6 Million Records, Login Credentials

2025-01-01 [vendor] Oracle Cloud Infrastructure (OCI) / Oracle Identity Manager / Oracle Access Manager [cve] CVE-2021-35587
Vector: A threat actor known as 'rose87168' claimed to have exploited a vulnerability in Oracle Cloud's login infrastructure (login.oracle.com / Oracle Identity Manager) to access Oracle's SSO and LDAP systems, exfiltrating approximately 6 million records including encrypted SSO passwords, LDAP password hashes, and JKS files

In March 2025, a threat actor known as 'rose87168' advertised on BreachForums the sale of approximately 6 million records allegedly stolen from Oracle Cloud's federated SSO login …

Cloud [SC]

Wyndham Third-Party Breach (January 2025)

2025-01-01 [vendor] Otelier
Vector: Compromise of third-party service provider / vendor relationship

Otelier data breach exposes info, hotel reservations of millions. Hotel management platform Otelier suffered a data breach after threat actors breached its Amazon S3 cloud storage …

Cloud

Grubhub Data Breach via Third-Party Contractor

2025-01-01
Vector: Compromised credentials of a third-party service provider / contractor with access to Grubhub's internal systems

Grubhub detected unusual activity traced to a compromised third-party contractor account in early 2025. The contractor had access to internal systems used for customer care. Stolen …

Cryptocurrency

Telegram post

2025-01-01 [vendor] NoOnes [loss] $8M [chain] solana
Vector: On-chain theft (attributed by zachxbt)

After crypto sleuth zachxbt noticed an apparent theft from the NoOnes peer-to-peer crypto trading platform on January 1, CEO Ray Youssef was forced to acknowledge the theft. He …

Other

Machine-Speed Cyberattacks — AI-Automated Attack Chains Outpace Human Defence

2025-01-01 [vendor] Enterprise networks globally across all sectors
Vector: AI and automation enable attackers to execute complete attack chains — from initial access through lateral movement, privilege escalation, data exfiltration, and ransomware deployment — faster than human security operations teams can detect and respond; AI-driven tools exploit vulnerabilities and pivot across networks without requiring human attacker intervention at each step

By 2025-2026, documented case studies from Darktrace, CrowdStrike, Palo Alto Networks Unit 42, and Microsoft MSTIC demonstrate that the most advanced attackers are executing …

Data leak [SC]

K-12 Dive

2024-12-19 [vendor] PowerSchool Student Information System (SIS)
Vector: CWE-308: Use of Single-factor Authentication (compromised employee password, no MFA on PowerSource portal)

PowerSchool, the dominant K-12 student information system provider serving approximately 16,000 schools and 50 million students in North America, suffered a data breach beginning …

Supply chain [SC]

PowerSchool SIS data breach — 62 million students and 9.5 million educators

2024-12-19 [vendor] PowerSchool Student Information System (SIS) / PowerSource customer portal
Vector: CWE-287: Improper Authentication (stolen/compromised credentials for PowerSource customer support portal; no mandatory MFA)

Attacker (later identified as Massachusetts college student Matthew D. Lane, 19) used compromised credentials to access PowerSchool's PowerSource support portal on 19 December …

Cryptocurrency

Indictment

2024-12-18 [vendor] Hay and Mayo [loss] $22M [chain] ethereum, solana
Vector: Exit scam / rug pull

Gabriel Hay and Gavin Mayo, two LA-based NFT creators, have been charged for defrauding investors of more than $22.4 million through a series of NFT rug pulls and other crypto …

Cloud

Ivanti Connect Secure zero-day CVE-2025-0282 exploited by UNC5221 (China-nexus)

2024-12-15 [vendor] Ivanti Connect Secure VPN / Ivanti Policy Secure / Ivanti ZTA Gateways [malware] SPAWN ecosystem (SPAWNANT installer, SPAWNMOLE tunneller, SPAWNSNAIL SSH backdoor, SPAWNSLOTH log tamper tool) [cve] CVE-2025-0282 +1
Vector: CWE-121: Stack-based Buffer Overflow (CVE-2025-0282 — unauthenticated stack-based buffer overflow enabling RCE)

CVE-2025-0282 is an unauthenticated stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways enabling remote code execution. Mandiant identified …

Cryptocurrency

Tweet by Anchor Drops

2024-12-12 [vendor] Crypto holder [loss] $2M [chain] ethereum, bitcoin
Vector: Seed phrase / wallet compromise

A crypto holder tweeted at the Ledger hardware wallet manufacturer to report that 10 BTC (~$1 million) and "~1.5m of NFTs" had been stolen from a Ledger wallet they were using. …

Cryptocurrency

"Clober Dex Incident Analysis"

2024-12-11 [vendor] Clober DEX [loss] $501,000 [chain] ethereum
Vector: Smart contract exploit / hack

Clober, a DEX built on Coinbase's Base Ethereum layer-2, suffered an exploit only about a week after its launch. A re-entrancy bug in the project allowed an attacker to siphon …

Cryptocurrency

"False prophet"

2024-12-10 [vendor] Alpaca Finance oracle issue [loss] $3M [chain] bsc
Vector: Software bug / unintentional loss

Users of the Alpaca Finance lending protocol suffered losses when the protocol's sloppy oracle implementation finally resulted in consequences. Although many had warned the project …

Data leak

BleepingComputer

2024-12-09 [vendor] Monroe University IT systems
Vector: CWE-284: Improper Access Control

Monroe University, a New York-based for-profit university, suffered a cyberattack between December 9 and December 23, 2024, in which threat actors exfiltrated data on 320,973 …

Supply chain [SC]

Ultralytics YOLO PyPI Package Supply Chain Attack

2024-12-04 [vendor] GitHub Actions; PyPI [malware] XMRig (Monero cryptominer)
Vector: Attacker abused GitHub Actions by crafting malicious git branch names in pull requests to exfiltrate PyPI publish tokens from the CI/CD runner environment; then published backdoored package versions to PyPI

The popular Ultralytics YOLO AI/ML library (60M+ downloads, 30K+ GitHub stars) was backdoored on 4 December 2024. Versions 8.3.41, 8.3.42, 8.3.45, and 8.3.46 deployed XMRig to mine …

Other

Tweet by RTFKT

2024-12-02 [vendor] Nike to

Nike will be shutting down its RTFKT "virtual collectibles" project at the end of January 2025, according to an announcement made in early December. Nike had acquired RTFKT in 2021 …

Data leak

Hertz Cleo MFT Clop Breach (100K+ Customers including Thrifty and Dollar)

2024-12-01 [vendor] Cleo Harmony; Cleo VLTrader; Cleo LexiCom [cve] CVE-2024-50623 +1
Vector: Clop ransomware group exploited zero-day vulnerabilities in Cleo Harmony, VLTrader, and LexiCom managed file transfer software (CVE-2024-50623, CVE-2024-55956) to access Hertz's file transfer infrastructure

Hertz Corporation disclosed in April 2025 that customer data had been stolen in attacks exploiting Cleo managed file transfer (MFT) software vulnerabilities in approximately …

Supply chain [SC]

Monument Health Third-Party Breach (December 2024)

2024-12-01 [vendor] Change Healthcare
Vector: Compromise of third-party service provider / vendor relationship

Nebraska AG’s Lawsuit Against Change Healthcare Survives Motion to Dismiss. A lawsuit filed by Nebraska Attorney General Mike Hilgers over the 2024 Change Healthcare data breach …

Supply chain [SC]

Ascension Health Former Business Partner EHR Data Breach

2024-12-01
Vector: A former business partner of Ascension Health mistakenly included Ascension patient data in a data file sent to a software vendor for testing purposes; that vendor's systems were then compromised by an attacker who accessed the data

Ascension Health disclosed in April 2025 a second security incident, separate from the May 2024 Black Basta ransomware attack. This breach involved a former business partner that …

Cloud

Orange Romania HellCat/Rey Data Breach - 600K Records

2024-12-01 [vendor] Atlassian Jira (project management platform)
Vector: Compromised credentials and vulnerabilities in Orange Romania's Jira software and internal portals; attacker had access for over one month

In early 2025, the HellCat-affiliated threat actor 'Rey' exfiltrated 6.5 GB of data (12,000 files) from Orange Romania's back-office systems, resulting in exposure of over 600,000 …

Cryptocurrency

Tweet by Clipper DEX

2024-12-01 [vendor] Clipper DEX [loss] $450,000 [chain] ethereum
Vector: Private key compromise

The Clipper decentralized exchange suffered a $450,000 exploit across two Ethereum layer-2 chains. Although some speculated that the issue may have been a private key leak, Clipper …

Ransomware

Krispy Kreme cyberattack (Play ransomware)

2024-11-29 [vendor] Krispy Kreme (food/restaurant chain) [malware] Play ransomware
Vector: unknown

Krispy Kreme detected unauthorized IT activity 29 November 2024; disclosed via SEC 8-K 11 December 2024. Online ordering disrupted. Play ransomware gang claimed attack in December; …

Data leak

Southeast Series of Lockton Companies Data Breach - 1.1M Individuals

2024-11-20
Vector: Unauthorized party accessed a single individual employee account and associated computer within Lockton's network, then accessed files containing protected health and personal information

On November 20, 2024, an unauthorized party gained access to a single employee account and computer within the Southeast Series of Lockton Companies' network — one of the largest …

Data leak

Tweet by DEXX

2024-11-16 [vendor] DEXX losses [loss] $21M
Vector: Smart contract exploit / hack

DEXX, a platform that advertises itself as the "first memecoins trading terminal application", disclosed that it had been hacked when it posted a message on social media addressed …

Supply chain [SC]

Cleo MFT zero-day exploitation by Clop ransomware (CVE-2024-50623 / CVE-2024-55956)

2024-11-15 [vendor] Cleo Harmony, VLTrader, and LexiCom managed file transfer software (versions before 5.8.0.21 / 5.8.0.24) [malware] Clop (Cl0p) ransomware [cve] CVE-2024-50623 +1
Vector: CWE-434: Unrestricted Upload of File with Dangerous Type (CVE-2024-50623 / CVE-2024-55956 — unauthenticated file write vulnerability in Cleo Harmony, VLTrader, and LexiCom MFT software enabling RCE)

Clop ransomware group exploited CVE-2024-50623 in Cleo's MFT products starting November 2024, bypassing the initial patch. Huntress identified active exploitation 3 December 2024 …

Cryptocurrency

Tweet by DeltaPrime

2024-11-11 [vendor] DeltaPrime [loss] $5M [chain] avalanche, ethereum
Vector: Smart contract exploit / hack

The DeltaPrime defi protocol was hacked for the second time in two months, losing $4.8 million in Arbitrum and Avalanche tokens. The attacker appeared to have exploited a flaw in …

Cryptocurrency

Tweet by CyversAlerts

2024-11-08 [vendor] CoinPoker [chain] bsc, ethereum, polygon
Vector: Smart contract exploit / hack

Crypto-powered poker website CoinPoker was apparently exploited for around $2 million when an attacker was able to compromise a hot wallet controlled by the platform. The attacker …

Ransomware

Ahold Delhaize USA INC Ransom Attack

2024-11-05 [malware] INC Ransom
Vector: INC Ransom ransomware-as-a-service operation; initial access vector not publicly confirmed; INC Ransom commonly exploits Citrix NetScaler vulnerabilities and phishing

INC Ransom breached Ahold Delhaize USA (parent of Stop & Shop, Food Lion, Giant Food, Hannaford, and The Giant Company) between 5-6 November 2024, stealing up to 6 TB of data. …

Ransomware

Bologna FC RansomHub Ransomware Attack

2024-11-01 [malware] RansomHub ransomware
Vector: Unknown; RansomHub noted lack of security controls on the club's network

Italian Serie A football club Bologna FC was attacked by RansomHub in November 2024. RansomHub claimed to have stolen 200 GB of data including player contracts, passports, …

Ransomware

Schneider Electric Hellcat Ransomware Attack

2024-11-01 [vendor] Atlassian Jira [malware] Hellcat
Vector: Hellcat ransomware group accessed Schneider Electric's Atlassian Jira instance using the MiniOrange REST API to extract data

Hellcat ransomware group breached Schneider Electric's internal Atlassian Jira project tracking platform in November 2024, stealing over 40 GB of compressed data including 75,000 …

Ransomware

HIPAA Journal

2024-11-01 [vendor] ARC Community Services administrative systems
Vector: CWE-284: Improper Access Control

ARC Community Services, a Wisconsin-based nonprofit providing community living and support services for people with intellectual and developmental disabilities, announced a …

Supply chain [SC]

Nokia Third-Party Breach (November 2024)

2024-11-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Nokia investigates breach after hacker claims to steal source code. Nokia is investigating whether a third-party vendor was breached after a hacker claimed to be selling the …

Supply chain [SC]

Sainsbury's Third-Party Breach (November 2024)

2024-11-01 [vendor] Blue Yonder
Vector: Compromise of third-party service provider / vendor relationship

Ransomware attack on software supplier disrupts operations for Starbucks and other retailers. A ransomware attack that hit a major software provider last week caused disruptions …

Data leak

Finastra SFTP Banking Software Data Breach

2024-10-31 [vendor] IBM Aspera (SFTP/managed file transfer)
Vector: Threat actor used compromised credentials to access Finastra's Secure File Transfer Platform (IBM Aspera SFTP); no malware deployed — data-only theft via stolen credentials

Finastra (London-based fintech serving 45 of the world's top 50 banks and 8,100+ financial institutions in 130 countries) had its SFTP platform accessed between 31 October and 8 …

Cryptocurrency

"Security Update"

2024-10-31 [vendor] M2 [loss] $14M [chain] ethereum, bitcoin, solana
Vector: Smart contract exploit / hack

The UAE-based M2 cryptocurrency exchange was hacked for $13.7 million in bitcoin, ether, and Solana tokens. The exploiter compromised several of the exchange's hot wallets to take …

Other

Midnight Blizzard Large-Scale RDP Spear-Phishing Campaign

2024-10-22
Vector: Russian SVR-linked Midnight Blizzard (APT29/NOBELIUM) sent signed malicious RDP configuration files via spear-phishing email; RDP files connected targets' machines to attacker-controlled servers, mapping local resources for data theft and malware staging

From 22 October 2024, Midnight Blizzard targeted thousands of users across 100+ organizations in government, academia, defense, and NGOs in UK, Europe, Australia, and Japan. Emails …

Ransomware

Conduent Business Services SafePay Ransomware Attack

2024-10-21 [malware] SafePay ransomware
Vector: Unknown initial access; attackers had persistent access from October 21, 2024 to January 13, 2025

Conduent, a company providing payment processing and document services to major health insurers and state government programs, was breached by the SafePay ransomware group. …

Ransomware

Conduent Business Services SafePay Ransomware - 25M+ State Benefits Recipients

2024-10-21 [malware] SafePay
Vector: SafePay ransomware gang gained unauthorized access to Conduent's systems and maintained persistence for approximately three months before triggering an operational disruption

An unauthorized third party had access to Conduent Business Services' systems from October 21, 2024, to January 13, 2025, when operational disruption was triggered. Conduent …

Cryptocurrency

Tweet by Tapioca DAO

2024-10-18 [vendor] Tapioca DAO [loss] $4M [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The defi lending protocol Tapioca DAO was exploited after an attacker reportedly socially engineered the DAO's co-founder and gain access to their private key. The attacker then …

Credential theft

Radiant Capital DeFi Hack

2024-10-16 [vendor] Safe Wallet (multi-sig infrastructure) [malware] InletDrift
Vector: North Korean UNC4736 (Citrine Sleet/Lazarus sub-group) delivered InletDrift malware via malicious PDF on Telegram, posing as a trusted ex-contractor; malware compromised at least 3 developer hardware wallets by replacing Safe Wallet front-end display while submitting malicious transactions for signing

On 16 October 2024, attackers executed transferOwnership on Radiant Capital's Pool Provider contract using 3 collected malicious signatures, gaining control of all lending pool …

Cryptocurrency

"On the LSM Module"

2024-10-15 [vendor] Cosmos LSM [chain] cosmos
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Cosmos creator Jae Kwon has raised concerns about a portion of the Cosmos protocol called the "Liquid Staking Module" after learning it was developed by North Korean agents. …

Cryptocurrency

Tweet by Scam Sniffer

2024-10-13 [vendor] PEPE token permit phishing [loss] $1M [chain] ethereum
Vector: Phishing attack

An attacker using the permit phishing technique stole $1.39 million in tokens from an unsuspecting holder. The victim unknowingly signed a "Permit2" signature — a function intended …

Supply chain

MUT-8694 npm and PyPI Malicious Package Campaign

2024-10-10 [vendor] npm registry; PyPI [malware] Blank Grabber infostealer; Skuld Stealer
Vector: Typosquatting: malicious packages uploaded to npm and PyPI mimicking legitimate library names to trick developers into installing them

Datadog Security Labs identified a coordinated supply chain attack campaign (tracked as MUT-8694) active from at least October 10, 2024, targeting both the npm and PyPI package …

Ransomware

Casio Ransomware Attack (Underground Group)

2024-10-05 [malware] Underground ransomware
Vector: Unauthorized remote access; specific initial access vector not publicly disclosed

Casio, the Japanese electronics and watchmaking company, suffered a ransomware attack on October 5, 2024. The Underground ransomware group claimed responsibility on October 10, …

Other

BleepingComputer

2024-10-03 [vendor] American Water Works customer IT systems
Vector: CWE-284: Improper Access Control

American Water Works, the largest regulated water and wastewater utility in the United States (serving 14+ million people across 14 states), detected unauthorized activity in its …

Data leak [SC]

Hot Topic data breach via infostealer (Robling third party)

2024-10-01 [vendor] Hot Topic / Box Lunch / Torrid retail brands [malware] Infostealer malware (targeting Robling, third-party analytics vendor)
Vector: CWE-522: Insufficiently Protected Credentials (infostealer malware infected a third-party retail analytics provider, Robling, leaking credentials used to access Hot Topic's systems)

Threat actor 'Satanic' posted on BreachForums on 21 October 2024 claiming 350 million Hot Topic user records (figure likely inflated); confirmed data set is ~730 GB covering Hot …

Data leak

Stiiizy Cannabis Retailer POS Provider Breach (380K Customers)

2024-10-01
Vector: Threat actors compromised Stiiizy's third-party point-of-sale (POS) system provider, gaining access to customer purchasing records that include highly sensitive government-issued identity documents

Stiiizy, a major California-based cannabis brand and retailer, disclosed in January 2025 that a breach via its unnamed third-party POS system provider in approximately October 2024 …

Supply chain [SC]

ADT Third-Party Breach (October 2024)

2024-10-01 [vendor] Third-party business partner
Vector: Compromise of third-party service provider / vendor relationship

ADT discloses second breach in 2 months, hacked via stolen credentials. Home and small business security company ADT disclosed it suffered a breach after threat actors gained …

Supply chain [SC]

CF Medical Third-Party Breach (October 2024)

2024-10-01 [vendor] Financial Business and Consumer Solutions (FBCS)
Vector: Compromise of third-party service provider / vendor relationship

Comcast says customer data stolen in ransomware attack on debt collection agency | TechCrunch. The ransomware attack on a U.S. debt collection agency also affects customers of CF …

Supply chain [SC]

Rackspace Third-Party Breach (October 2024)

2024-10-01 [vendor] ScienceLogic
Vector: Compromise of third-party service provider / vendor relationship

Rackspace monitoring data stolen in ScienceLogic zero-day attack. Cloud hosting provider Rackspace suffered a data breach exposing "limited" customer monitoring data after threat …

Data leak

Byte Federal Bitcoin ATM - GitLab Vulnerability Breach

2024-09-30 [vendor] GitLab
Vector: Attacker exploited an unpatched GitLab vulnerability to gain access to a Byte Federal server hosting customer data

US Bitcoin ATM operator Byte Federal (which operates 1,200+ ATMs nationwide) was breached on 30 September 2024 via a GitLab vulnerability but did not detect the incident until 18 …

Data leak

Free Mobile / Free France Data Breach - VPN Credential Attack (24M Subscribers, €42M CNIL Fine)

2024-09-28
Vector: Attackers gained access to Free's network via insufficiently protected VPN authentication, then connected to Free Mobile's subscriber management tool (MOBO) to exfiltrate customer records starting October 6, 2024

Beginning September 28, 2024, an attacker accessed Free's network through VPN credentials using insufficiently robust multi-factor authentication. The attacker connected to MOBO, …

Data leak

Internet Archive (Wayback Machine) data breach

2024-09-28 [vendor] Internet Archive / archive.org
Vector: CWE-312: Cleartext Storage of Sensitive Information (authentication database exfiltrated; separately DDoS and defacement via JavaScript injection)

Threat actor (SN_BlackMeta, linked to pro-Palestinian hacktivist movement) defaced archive.org with a JavaScript alert and simultaneously exfiltrated a 6.4 GB SQL file …

Data leak

Web3 Is Going Great

2024-09-23 [vendor] OpenAI Twitter account
Vector: Smart contract exploit / hack

The Twitter account belonging to OpenAI's news account was compromised and used to "announce" a scam website purporting to announce the $OPENAI token. "All OpenAI users are …

Data leak

MoneyGram Data Breach via IT Helpdesk Social Engineering

2024-09-20
Vector: Social engineering / vishing targeting MoneyGram's IT helpdesk; attackers impersonated employees to obtain internal system access

MoneyGram, a major international money transfer and payment services company, suffered a data breach September 20–22, 2024 via an IT helpdesk social engineering attack (attributed …

Cloud

Serviceaide Unsecured Elasticsearch Database - 483K Catholic Health Patients

2024-09-19 [vendor] Elasticsearch (cloud database)
Vector: Misconfiguration: Serviceaide left an Elasticsearch database containing Catholic Health patient PHI publicly accessible on the internet without authentication for approximately six weeks

Between September 19 and November 5, 2024, Serviceaide (an agentic AI-powered IT and workflow management platform based in Santa Clara, CA) left an Elasticsearch database …

Other

Tweet thread by Samperson

2024-09-15 [vendor] Flappy Bird creator disavows crypto spin-off

A blockchain-based version of the 2014 hit game Flappy Bird has emerged, taking advantage of the recent "tap-to-earn" crypto craze. The @flappy_bird Twitter account posted "I AM …

Other

Eve Frontier FAQ

2024-09-13 [vendor] Eve Online announcement

CCP, the developer of the Eve Online space MMORPG, has angered their fanbase with a new announcement that their upcoming game will be built on the blockchain and incorporate …

Cryptocurrency

Tweet thread by CertiK

2024-09-10 [vendor] CUT token [loss] $1M [chain] bsc
Vector: Flash loan attack on smart contract

An attacker exploited a bug in the smart contract for a BSC-based token called CUT, draining a PancakeSwap liquidity pool of almost $1.45 million in the BSC-USD stablecoin. Total …

Data leak

Tweet by Nick Drakon

2024-09-05 [vendor] Revelo Ventures CEO resigns after robbery
Vector: Smart contract exploit / hack

Nick Drakon, formerly the CEO of the crypto research and venture capital firm Revelo, announced on Twitter that he was resigning from the company. In the post, he claimed that he …

Cryptocurrency

"Penpie Post-Mortem Report"

2024-09-03 [vendor] Penpie [loss] $27M [chain] ethereum
Vector: Smart contract vulnerability exploit

The defi protocol Penpie was exploited for 11,113.6 ETH (~$27.3 million) by an attacker who exploited a flaw allowing them to withdraw unearned "rewards". Although the protocol …

Supply chain [SC]

Cultura Third-Party Breach (September 2024)

2024-09-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Popular French retailers confirm hackers stole customer data. Targets of the cyberattacks include electronics and home appliances store Boulanger and the retailer Cultura. Several …

Supply chain [SC]

NHS England Third-Party Breach (September 2024)

2024-09-01 [vendor] Synnovis
Vector: Compromise of third-party service provider / vendor relationship

Data on nearly 1 million NHS patients leaked online following ransomware attack on London hospitals. The stolen data, which was published in June by the Qilin ransomware gang, …

Supply chain [SC]

T-Mobile Third-Party Breach (September 2024)

2024-09-01 [vendor] Capgemini
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile’s VM logs allegedly leaked in 20 GB Capgemini data breach. The attacker claims to have stolen databases, source code, credentials, private keys, as well as log files …

Credential theft

Transport for London (TfL) Scattered Spider Attack

2024-08-31
Vector: Social engineering / MFA bypass by Scattered Spider members; attacker gained internal access via compromised employee credentials

Scattered Spider attacked Transport for London on 31 August 2024, ultimately exposing data of approximately 10 million customers — one of the largest breaches in British history. …

Other

Tweet by Devin Finzer

2024-08-28 [vendor] OpenSea Wells notice
Vector: Regulatory / legal action

OpenSea has announced that they received a Wells notice from the U.S. Securities and Exchange Commission, warning them of a likely lawsuit from the agency. According to CEO Devin …

Cryptocurrency

Tweet by ValidatorK

2024-08-24 [vendor] Users [loss] $140,000 [chain] polygon
Vector: Smart contract exploit / hack

Some fans of the Polygon blockchain, or those looking for help with using it, suffered losses after hackers successfully compromised the project's Discord server. Discord hacks …

Ransomware

Halliburton cyberattack (RansomHub)

2024-08-21 [vendor] Halliburton (oilfield services) [malware] RansomHub ransomware
Vector: CWE-798: Use of Hard-coded Credentials / phishing (phishing emails delivering malicious links; subsequent credential theft and lateral movement)

RansomHub (ransomware-as-a-service operation, launched February 2024) attacked Halliburton. Detected 21 August 2024; SEC 8-K filed 23 August 2024. Production planning and shipment …

Cryptocurrency

Tweet by Lookonchain

2024-08-20 [vendor] Crypto holder [loss] $55M [chain] ethereum
Vector: Phishing attack

Someone holding almost $55.5 million in the DAI stablecoin was apparently phished, signing a transaction to reassign ownership of their DAI stash to a phishing address. The victim …

Data leak

Fidelity Investments Data Breach

2024-08-17
Vector: Attackers created two new fraudulent customer accounts and used them to access other customers' personal information via an internal document management system; no MFA gap on account creation process

Between 17-19 August 2024, unauthorized third parties exploited two newly created Fidelity customer accounts to access personal data of 77,099 customers including Social Security …

Ransomware

AutoCanada Hunters International Ransomware Attack

2024-08-11 [malware] Hunters International ransomware
Vector: Unknown; Hunters International typically uses phishing and exploits vulnerable internet-facing systems

AutoCanada, a publicly traded North American automotive dealership group operating 84 franchised dealerships, detected a ransomware attack on August 11, 2024. Hunters International …

Data leak

Tweet thread by zachxbt

2024-08-07 [vendor] 7ANPW theft [loss] $1M
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

According to blockchain investigator zachxbt, North Korean developers using fake identities were able to steal $1.3 million from a cryptocurrency project after pushing malicious …

Data leak

"Post-mortem | 08/01/2024"

2024-08-01 [vendor] ConvergenceFi [loss] $210,000
Vector: Smart contract exploit / hack

An attacker took advantage of a flaw in the code for the yield farming project ConvergenceFi, draining it of all the tokens that had been allocated for staking emissions. Because a …

Supply chain [SC]

Toyota Third-Party Breach (August 2024)

2024-08-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

Toyota confirms third-party data breach impacting customers. Toyota confirmed that customer data was exposed in a third-party data breach after a threat actor leaked an archive of …

Cryptocurrency

"Community Update on the Future of Reignmakers"

2024-07-30 [vendor] DraftKings Reignmakers shutdown [chain] ethereum, polygon
Vector: Regulatory / legal action

American sports gambling behemoth DraftKings announced the shutdown of its Reignmakers NFT game and NFT marketplace, effective immediately. Reignmakers was a fantasy sports game …

Data leak

Tweet by PeckShieldAlert

2024-07-24 [vendor] MonoSwap [loss] $1M
Vector: Smart contract exploit / hack

The MonoSwap DEX announced on July 24 that it had been compromised, and urged its users to withdraw their funds to avoid losses. According to the project team, one of their …

Cryptocurrency

ETHTrustFund

2024-07-20 [vendor] ETHTrustFund [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

The operators of a project called ETHTrustFund on Coinbase's Base layer-2 Ethereum blockchain have apparently rug-pulled the project. The ETHTrustFund project was a fork of the …

Cryptocurrency

Tweet by zachxbt

2024-07-19 [vendor] Rho loss [chain] ethereum
Vector: MEV / sandwich attack

An apparent misconfiguration by the RHO Markets lending protocol allowed operators of an MEV bot to take $7.6 million from the project's users across multiple chains.In a stroke of …

Other [SC]

CrowdStrike Falcon Sensor Update — Global Windows BSOD Outage (8.5 Million Devices)

2024-07-19 [vendor] CrowdStrike Falcon sensor (Windows) — Channel File 291
Vector: A faulty content configuration update (Channel File 291) for the CrowdStrike Falcon sensor on Windows hosts caused a logic error in the sensor's Content Interpreter, triggering an out-of-bounds memory read that led to an exception handling failure and Windows BSOD (Blue Screen of Death)

On 19 July 2024, CrowdStrike released a faulty content configuration update (Channel File 291) to Windows systems running the CrowdStrike Falcon endpoint detection and response …

Credential theft

WazirX Cryptocurrency Exchange Hack

2024-07-18 [vendor] Liminal Custody (multi-sig wallet infrastructure) [malware] Safe Wallet front-end manipulation / transaction substitution
Vector: Lazarus Group (North Korea) compromised WazirX multi-signature wallet by social engineering developers and manipulating Safe Wallet front-end; malware replaced legitimate transaction displays to collect hardware wallet signatures

$234.9 million in crypto assets stolen from Indian exchange WazirX on 18 July 2024. Attributed to North Korea's Lazarus Group by joint US/Japan/South Korea statement in January …

Ransomware

McLaren Health Care ransomware attack (INC Ransom)

2024-07-17 [vendor] McLaren Health Care (12-hospital Michigan system) [malware] INC Ransom ransomware
Vector: unknown

INC Ransom group (double extortion) gained access 17 July 2024; suspicious activity detected 5 August. All IT systems including EHR taken offline; hospitals reverted to paper …

Cryptocurrency

Tweet by Trekki

2024-07-17 [vendor] Trekki NFT shutdown [chain] ethereum

Travel company Trip.com has some perturbed crypto holders on its hands, after shutting down the "Trekki" NFT project it launched in June 2023. The company's dolphin-themed NFTs had …

Cryptocurrency

Tweet by LI.FI

2024-07-16 [vendor] LI.FI [loss] $10M [chain] ethereum, solana
Vector: Smart contract exploit / hack

Users of the cross-chain swapping API LI.FI Protocol, and of projects that build on top of it, suffered wallet drains amounting to at least $10 million (and counting). An attacker …

Cryptocurrency

Tweet by Chaofan Shou

2024-07-14 [vendor] Minterest [loss] $1M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker stole $1.4 million from the defi lending project Minterest. Using a flash loan attack, they manipulated the exchange rate calculated by the project, allowing them to …

Cryptocurrency

"Dough Finance loses $1.8M in flash loan attack"

2024-07-12 [vendor] Dough Finance [loss] $2M [chain] ethereum
Vector: Flash loan attack on smart contract

Defi platform Dough Finance was hacked for 608 ETH ($1.8 million) by a hacker using a flash loan attack funded through the Railgun privacy service.Dough Finance sent an on-chain …

Data leak

"Bittensor Community Update — July 3, 2024"

2024-07-02 [vendor] Bittensor wallet drain [loss] $8M
Vector: AI-assisted attack or AI-generated exploit

Some users of the Bittensor wallet software suffered wallet drains as thieves emptied their cryptocurrency wallets of the project’s TAO token. Around 32,000 TAO, notionally worth …

Supply chain [SC]

300 small Indian banks Third-Party Breach (July 2024)

2024-07-01 [vendor] C-Edge Technologies Ltd
Vector: Compromise of third-party service provider / vendor relationship

Small Indian banks hit by ransomware attack; NPCI suspends payment. Ransomware attack on C-Edge impacts banking services, but no financial loss reported; restoration work underway. …

Supply chain [SC]

AutoNation Third-Party Breach (July 2024)

2024-07-01 [vendor] CDK Global
Vector: Compromise of third-party service provider / vendor relationship

Car dealership company AutoNation says CDK ransomware incident cut into quarterly earnings. AutoNation alerted investors that earnings per share would be down about a one-third …

Supply chain [SC]

Bilt Third-Party Breach (July 2024)

2024-07-01 [vendor] Evolve Bank & Trust
Vector: Compromise of third-party service provider / vendor relationship

Affirm says cardholders impacted by Evolve Bank data breach. Buy now, pay later loan company Affirm is warning that holders of its payment cards had their personal information …

Supply chain [SC]

Clear Spring Health Third-Party Breach (July 2024)

2024-07-01 [vendor] Change Healthcare
Vector: Compromise of third-party service provider / vendor relationship

SouthCoast Health; Call 4 Health Notify Patients About Cyberattacks. SouthCoast Health and Privia Medical Group in Georgia have notified patients about a cyberattack and HIPAA …

Supply chain [SC]

Gemini Third-Party Breach (July 2024)

2024-07-01 [vendor] Not disclosed Automated Clearing House (ACH) service provider
Vector: Compromise of third-party service provider / vendor relationship

Crypto exchange Gemini discloses third-party data breach. Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated …

Supply chain [SC]

Roblox Third-Party Breach (July 2024)

2024-07-01 [vendor] FNTech
Vector: Compromise of third-party service provider / vendor relationship

Roblox vendor data breach exposes dev conference attendee info. Roblox announced late last week that it suffered a data breach impacting attendees of the 2022, 2023, and 2024 …

Supply chain [SC]

TriZetto (Cognizant) Healthcare Technology Breach (3M+ Individuals)

2024-07-01 [vendor] TriZetto (Cognizant subsidiary) — healthcare benefits/RCM software
Vector: Attackers breached TriZetto's healthcare data platform systems, exfiltrating data for health insurance customers that had been processed through TriZetto's revenue cycle management and benefits administration software

TriZetto, a healthcare technology subsidiary of Cognizant Technology Solutions, disclosed in late 2024 that a data breach had affected over 3 million individuals. TriZetto provides …

Cloud [SC]

AT&T Third-Party Breach (July 2024)

2024-07-01 [vendor] Snowflake
Vector: Compromise of third-party service provider / vendor relationship

Massive AT&T data breach exposes call logs of 109 million customers. AT&T is warning of a massive data breach where threat actors stole the call logs for approximately 109 million …

Cloud [SC]

Otelier Hotel Management Platform Breach (Marriott, Hilton, Hyatt, Wyndham)

2024-07-01 [vendor] Otelier (formerly Hotel Effectiveness)
Vector: Threat actors compromised Otelier's hotel management SaaS platform by stealing credentials through an infostealer malware infection, then used those credentials to access Otelier's Atlassian systems and AWS S3 buckets containing hotel customer reservation data

Otelier, a cloud-based hotel management platform used by major hotel chains worldwide, was breached starting in approximately July 2024. Threat actors obtained employee credentials …

Other

<i>Logan Paul v. Stephen Findeisen</i>

2024-06-27 [vendor] Logan Paul lawsuit against Coffeezilla
Vector: Regulatory / legal action

A year and a half after threatening to sue YouTuber Coffeezilla for his series of videos exposing influencer Logan Paul's (alleged) role in (allegedly) scamming his large following …

Cloud [SC]

Polyfill.io JavaScript Supply Chain Attack — 380,000 Websites Compromised

2024-06-25 [vendor] cdn.polyfill.io (JavaScript polyfill CDN service)
Vector: Chinese company Funnull CDN acquired the polyfill.io domain and associated GitHub repository from its original maintainer in early 2024; subsequently modified the polyfill.js script served by cdn.polyfill.io to inject malicious code that redirected mobile users to scam and malicious sites, with obfuscation to avoid detection

In June 2024, security researchers at Sansec discovered that cdn.polyfill.io — a widely used JavaScript polyfill service loaded by approximately 380,000 websites — had been …

Cryptocurrency

Tweet thread by Scam Sniffer

2024-06-23 [vendor] 0xfb94d theft [loss] $11M [chain] ethereum
Vector: Phishing attack

A victim lost $11 million in Aave Ethereum (aEthMK) and Pendle USDe tokens after signing several permit phishing signatures. Permit phishing is a technique in which scammers …

Cryptocurrency

Tweet by CertiKAlert

2024-06-23 [vendor] Farcana token plunge [loss] $164,000 [chain] polygon
Vector: Smart contract vulnerability exploit

The token for the Farcana blockchain shooting game plummeted in value by around 60%. First, the project team announced that one of the project wallets had been compromised. …

Data leak

BtcTurk status page

2024-06-22 [vendor] BtcTurk [loss] $85M
Vector: Smart contract exploit / hack

The Turkish cryptocurrency exchange BtcTurk has acknowledged that they suffered a hack that impacted ten hot wallets containing multiple cryptocurrencies. The exchange halted …

Cryptocurrency

Instagram post by 50 Cent

2024-06-22 [vendor] 50 Cent account compromise [loss] $1M [chain] solana
Vector: Smart contract exploit / hack

50 Cent has claimed his Twitter account and website were hacked to promote a memecoin called $GUNIT. "I have no association with this crypto," the rapper wrote on Instagram.50 Cent …

Cryptocurrency

Telegram message

2024-06-22 [vendor] Sportsbet.io [loss] $4M [chain] tron
Vector: Smart contract exploit / hack

It appears that the online crypto sports betting platform Sportsbet.io suffered a theft of around $3.5 million in USDT and Tron's TRX tokens. The theft was observed by crypto …

Ransomware

HIPAA Journal

2024-06-19 [vendor] Acadian Ambulance EMS systems [malware] Daixin Team ransomware
Vector: CWE-284: Improper Access Control

Acadian Ambulance Service, a Louisiana-based emergency medical services provider, was attacked by the Daixin Team ransomware gang between June 19-21, 2024. The group claimed to …

Cryptocurrency

Twitter thread by CertiK

2024-06-19 [vendor] CertiK and Kraken bug dispute [loss] $3M [chain] polygon
Vector: Smart contract exploit / hack

Prominent blockchain security firm CertiK has accused American cryptocurrency exchange Kraken of threatening them after they reported a bug. According to CertiK, they discovered a …

Ransomware

CNN Business / BlackFog / TechTarget / CyberScoop

2024-06-18 [vendor] CDK Global Dealer Management System [malware] BlackSuit
Vector: CWE-1391: Use of Weak Credentials (social engineering; exact initial vector not fully disclosed)

BlackSuit ransomware (linked to Royal/Conti lineage) attacked CDK Global June 18 2024, disrupting dealer management systems for ~15,000 US auto dealerships. CDK suffered second …

Cryptocurrency

"Pharma Bro's Trump Card"

2024-06-18 [vendor] Martin Shkreli claims to have been behind a Donald Trump memecoin [chain] solana
Vector: On-chain theft (attributed by zachxbt)

After Arkham Intelligence announced a $150,000 bounty for anyone who could prove the identity of the person behind a Donald Trump memecoin called $DJT, blockchain sleuth zachxbt …

Cryptocurrency

Tweet by Cyvers

2024-06-13 [vendor] UwU Lend [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

After suffering a $20 million loss in a June 10 hack, the UwU Lend defi lending protocol has now seen another $3.7 million in suspicious outflows only days later. Although UwU Lend …

Data leak

Tweet thread by zachxbt

2024-06-12 [vendor] Andreessen Horowitz phishing [loss] $245,000
Vector: On-chain theft (attributed by zachxbt)

Attentive phishers noticed when Andreessen Horowitz partner Peter Lauten changed his Twitter username from @peter_lauten to @lauten, and snapped up the previous username. They then …

Cryptocurrency

Tweet by UwU Lend

2024-06-10 [vendor] UwU Lend [loss] $20M [chain] ethereum
Vector: Flash loan attack on smart contract

The defi lending protocol UwU Lend was hacked for around $20 million. After various blockchain security firms observed suspicious outflows of funds, the protocol acknowledged there …

Ransomware

Kadokawa / Niconico BlackSuit Ransomware Attack

2024-06-08 [malware] BlackSuit
Vector: Phishing email compromised an employee account, leading to BlackSuit ransomware deployment across Kadokawa corporate infrastructure and Niconico video-sharing platform

On 8 June 2024, BlackSuit (rebrand of Royal ransomware / Conti successor) attacked Japanese media/gaming giant Kadokawa and its Niconico video platform. 254,241 individuals' data …

Ransomware

Rite Aid RansomHub Data Breach

2024-06-06 [malware] RansomHub
Vector: RansomHub threat actor impersonated a Rite Aid employee to obtain business credentials; gained access to certain business systems; incident detected within 12 hours

Rite Aid (third-largest US pharmacy chain) was breached on 6 June 2024 with 2.2 million customers' names, dates of birth, addresses, and driver's license/government ID numbers …

Cryptocurrency

Tweet by br1an.eth

2024-06-05 [vendor] br1an.eth private key compromise [loss] $48,630 [chain] cosmos
Vector: Smart contract exploit / hack

A blockchain developer posted on Twitter that he had lost almost $50,000 after his cryptocurrency wallet was drained. He explained that he had been working on a software project on …

Data leak

Tweet thread by SomaXBT

2024-06-04 [vendor] Lykke [loss] $2M
Vector: Smart contract exploit / hack

The UK-based Lykke crypto exchange suffered an exploit that saw more than $23.6 million stolen from the platform. The platform shut down trading two days later, and some customers …

Ransomware

Synnovis NHS pathology ransomware attack (Qilin)

2024-06-03 [vendor] Synnovis (NHS pathology services provider) [malware] Qilin ransomware
Vector: unknown

Qilin ransomware group attacked Synnovis, a joint venture providing blood testing and pathology services to King's College Hospital NHS Foundation Trust and Guy's and St Thomas' …

Data leak

CBIZ Benefits & Insurance Services Data Breach

2024-06-02
Vector: Unauthorized party exploited a vulnerability in a CBIZ web page to access and exfiltrate data from certain databases between June 2-21, 2024

CBIZ Benefits & Insurance Services (subsidiary of business services giant CBIZ Inc.) disclosed a breach affecting 35,953 individuals who had retiree health information on file. …

Cryptocurrency

"Velocore Incident Post-Mortem"

2024-06-02 [vendor] Velocore [loss] $7M [chain] ethereum
Vector: Flash loan attack on smart contract

The Velocore DEX, built on the Linea Ethereum layer-2 blockchain, was exploited for around $6.8 million in ETH. The hacker was able to take advantage of a bug in the project's …

Data leak

Tile / Life360 Data Breach and Extortion

2024-06-01 [vendor] Tile customer support platform
Vector: Threat actor used stolen credentials of a former Tile/Life360 employee to access the customer support platform; inactive credentials not revoked after employee departure

An attacker gained access to Tile's customer support system using credentials belonging to a former employee, then scraped millions of customer records and attempted to extort …

Supply chain [SC]

Aptihealth Third-Party Breach (June 2024)

2024-06-01 [vendor] Sisense
Vector: Compromise of third-party service provider / vendor relationship

Almost 20,000 Aptihealth Patients Affected by Business Associate Data Breach. Data breaches have been announced by the behavioral health engagement company Aptihealth and the civil …

Supply chain [SC]

Geisinger Third-Party Breach (June 2024)

2024-06-01 [vendor] Nuance Communications
Vector: Compromise of third-party service provider / vendor relationship

Former IT employee accessed data of over 1 million US patients. Geisinger, a prominent healthcare system in Pennsylvania, has announced a data breach involving a former employee of …

Supply chain [SC]

IACT Health Third-Party Breach (June 2024)

2024-06-01 [vendor] Advarra
Vector: Compromise of third-party service provider / vendor relationship

Patient Data Exposed in Cyberattacks on PruittHealth & Easterseals Central Illinois. PruittHealth has notified patients about a November 2023 ransomware attack and has confirmed …

Supply chain [SC]

Newton Centre Dental Third-Party Breach (June 2024)

2024-06-01 [vendor] Affinity Dental Management
Vector: Compromise of third-party service provider / vendor relationship

Email Breach Affects 10,000 University of Chicago Medical Center Patients. Hackers gained access to the email accounts of University of Chicago Medical Center employees and the …

Supply chain [SC]

T-Mobile Third-Party Breach (June 2024)

2024-06-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile denies it was hacked, links leaked data to vendor breach. T-Mobile has denied it was breached or that source code was stolen after a threat actor claimed to be selling …

Credential theft [SC]

DMM Bitcoin Hack - TraderTraitor (North Korea)

2024-05-31 [vendor] Ginco (crypto wallet provider)
Vector: TraderTraitor (North Korean) social engineering of an employee at crypto wallet company Ginco; attackers gained access to Ginco communications systems and intercepted a legitimate DMM Bitcoin transaction

North Korean TraderTraitor hackers stole 4,502.9 BTC (~$308 million) from Japanese crypto exchange DMM Bitcoin on 31 May 2024 — the third-largest crypto theft in history. FBI, DC3, …

Ransomware

BleepingComputer

2024-05-29 [vendor] Evolve Bank & Trust banking platform [malware] LockBit ransomware
Vector: CWE-601: URL Redirection to Untrusted Site (phishing link clicked by employee)

Evolve Bank & Trust, an Arkansas-based fintech banking partner, was attacked by the LockBit ransomware gang in late May 2024. An employee clicked a malicious link, granting …

Cryptocurrency

Tweet thread by zachxbt

2024-05-27 [vendor] CAT memecoin team [loss] $30,500 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

According to crypto sleuth zachxbt, the team behind the Solana-based $CAT memecoin hacked the Twitter account of "Gigantic-Cassocked-Rebirth" (@GCRClassic) crypto influencer.First, …

Cryptocurrency

"Normie Incident Analysis"

2024-05-26 [vendor] NORMIE [loss] $882,000 [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker perpetrated a flash loan attack on the "Normie" memecoin on the Base layer-2 blockchain to drain millions of NORMIE tokens. The vulnerability was evidently discovered …

Cryptocurrency

Thief wallet

2024-05-20 [vendor] Gala Games [loss] $21M [chain] ethereum
Vector: Smart contract exploit / hack

Someone was able to mint 5 billion $GALA tokens, the native token of the Gala Games blockchain gaming project. The tokens would be notionally worth around $200 million based on …

Cryptocurrency

"Alex Bridge Incident Anlaysis"

2024-05-14 [vendor] ALEX XLink bridge theft [loss] $6M [chain] bitcoin, bsc, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

An attacker tried to pull off what could have been a ~$12 million heist from ALEX Lab's XLink bridge after a private key was compromised. However, the sloppy work by the attacker …

Cryptocurrency

Tweet by CyversAlert

2024-05-14 [vendor] Sonne Finance [loss] $20M [chain] ethereum
Vector: Smart contract exploit / hack

The Sonne Finance lending protocol was exploited for at least $20 million as an attacker was able to exploit a vulnerability in some of their smart contracts. Sonne is a fork of …

Ransomware

BleepingComputer

2024-05-13 [vendor] Landmark Admin insurance administration platform
Vector: CWE-522: Insufficiently Protected Credentials (stolen VPN credentials)

Landmark Admin LLC, a Texas-based third-party administrator for multiple insurance companies, detected unauthorized access to its systems on May 13, 2024, and was breached again on …

Cryptocurrency

"Public statement"

2024-05-13 [vendor] Cypher contributor theft [loss] $316,294 [chain] solana
Vector: Smart contract exploit / hack

After the founder of the Solana-based Cypher futures trading protocol publicly accused a core contributor of stealing funds, the contributor — publicly known only as "hoak" — has …

Ransomware

Ascension Health ransomware attack (Black Basta)

2024-05-08 [vendor] Ascension Health EHR / MyChart [malware] Black Basta ransomware
Vector: CWE-494: Download of Code Without Integrity Check (employee downloaded malicious file believing it legitimate)

Black Basta ransomware group encrypted servers across a 12-hospital system. Initial access via a malicious file inadvertently downloaded by an employee. Attackers accessed only 7 …

Ransomware

Keytronic (Key Tronic) Black Basta Ransomware Attack

2024-05-06 [malware] Black Basta ransomware
Vector: Unknown; Black Basta typically uses phishing emails and exploited vulnerabilities for initial access

Keytronic, a printed circuit board assembly (PCBA) manufacturer based in Spokane, WA, was hit by Black Basta ransomware on May 6, 2024. Operations in the US and Mexico were halted …

Cryptocurrency

Tweet by Cyvers Alerts

2024-05-05 [vendor] GNUS.ai exploi [loss] $1M [chain] ethereum, fantom, polygon
Vector: AI-assisted attack or AI-generated exploit

An exploiter was able to create a fake version of the $GNUS token on the Fantom blockchain, then bridge the tokens to Ethereum and Polygon where they were then sold as though they …

Cryptocurrency

Tweet by Cyvers Alerts

2024-05-03 [vendor] 0x1E227 address poisoning [loss] $7M [chain] bitcoin, ethereum
Vector: Address poisoning attack

An Ethereum wallet was apparently drained of 1,155 wrapped bitcoin (~$72.7 million) when they transferred it to a malicious address that had been operating an address poisoning …

Supply chain [SC]

HSBC Third-Party Breach (May 2024)

2024-05-01 [vendor] Baton Systems
Vector: Compromise of third-party service provider / vendor relationship

Alleged HSBC, Barclays data exposed by IntelBroker. Hackread reports that IntelBroker has exposed sensitive data allegedly stolen from major UK-based international financial …

Supply chain [SC]

MediSecure Third-Party Breach (May 2024)

2024-05-01 [vendor] Third-party vendor
Vector: Compromise of third-party service provider / vendor relationship

MediSecure e-script firm hit by ‘large-scale’ ransomware data breach. Electronic prescription provider MediSecure in Australia has shut down its website and phone lines following a …

Cloud [SC]

Ticketmaster Third-Party Breach (May 2024)

2024-05-01 [vendor] Snowflake
Vector: Compromise of third-party service provider / vendor relationship

Snowflake account hacks linked to Santander, Ticketmaster breaches. A threat actor claiming recent Santander and Ticketmaster breaches says they stole data after hacking into an …

Cloud

BleepingComputer

2024-05-01 [vendor] Pure Storage Snowflake workspace (telemetry/support)
Vector: CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake)

Pure Storage, a leading enterprise cloud storage provider, confirmed on June 11, 2024 that attackers breached its Snowflake workspace as part of the broader UNC5537/Sp1d3r campaign …

Cloud

404 Media

2024-05-01 [vendor] Bausch Health Snowflake data warehouse
Vector: CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake)

Bausch Health, a Canadian pharmaceutical company, was targeted as part of the 2024 UNC5537/Sp1d3rHunters Snowflake credential-theft campaign. The threat actor 'Sp1d3rHunters' …

Cryptocurrency

"Early Bitcoin Investor Charged with Tax Fraud"

2024-04-30 [vendor] Roger Ver arrested for $50 million tax fraud [chain] bitcoin
Vector: Regulatory / legal action

Roger Ver, an early bitcoin investor who later became an outspoken evangelist for the fork Bitcoin Cash, has been arrested on tax fraud charges. According to the Department of …

Other

Web3 Is Going Great

2024-04-30 [vendor] Changpeng Zhao
Vector: Regulatory / legal action

Former Binance CEO Changpeng "CZ" Zhao has been sentenced to four months in prison after pleading guilty to money laundering-related charges. The charges were filed in November, …

Cryptocurrency

Telegram post by zachxbt

2024-04-29 [vendor] Rain [loss] $15M [chain] bitcoin, ethereum, ripple, solana
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Bahrain-based cryptocurrency exchange Rain was exploited for around $16.13 million dollars on April 29. The exchange did not publicly disclose the hack until the suspicious …

Ransomware

London Drugs ransomware attack (LockBit)

2024-04-28 [vendor] London Drugs (Canadian pharmacy/retail chain) [malware] LockBit ransomware
Vector: unknown

LockBit claimed the attack on London Drugs and demanded $25 million ransom (reportedly offered $8 million). All 79 Western Canada stores closed 28 April–7 May 2024. Corporate head …

Data leak

Dell customer data breach via partner portal API scraping

2024-04-28 [vendor] Dell partner portal API
Vector: CWE-284: Improper Access Control (unauthenticated/weakly authenticated partner portal API allowing automated enumeration of service tags)

Threat actor 'Menelik' registered as a Dell partner using fake company information (access granted within 24–48 hours), then used automated tooling to enumerate 49 million customer …

Cloud

Dropbox Sign (HelloSign) Breach — Customer Data, API Keys, MFA, OAuth Tokens

2024-04-24 [vendor] Dropbox Sign (formerly HelloSign) e-signature platform
Vector: Attacker gained access to a Dropbox Sign automated system configuration tool, using it to execute code in the context of the Sign application; this provided access to the customer database and to application-related secrets including API keys, OAuth tokens, and MFA keys/seeds

On 24 April 2024, Dropbox discovered that a threat actor had accessed Dropbox Sign's (formerly HelloSign's) production environment. Dropbox Sign is an e-signature service used by …

Cryptocurrency

Tweet by Hedgey Finance

2024-04-19 [vendor] Hedgey Finance [loss] $45M [chain] ethereum
Vector: Flash loan attack on smart contract

Hedgey Finance, a platform used to manage token claims, lockups, and vesting, was hit with a flash loan attack that drained $44.7 million of customer funds from the platform.The …

Cloud

Santander Bank data breach via Snowflake (UNC5537 / ShinyHunters)

2024-04-17 [vendor] Snowflake cloud data platform / Santander third-party database
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials reused against Snowflake tenant with no MFA)

UNC5537 accessed a third-party Snowflake-hosted database used by Santander. Breach began April 17, discovered May 10, disclosed May 14. ShinyHunters listed data on BreachForums …

Other

Tweet by Roger Stone

2024-04-17 [vendor] Roger Stone endorses $TRUMP memecoin

Amid tweets alleging corruption among jurors in his 2019 criminal case, far-right activist and Trumpworld figure Roger Stone has posted several tweets endorsing "MAGA Memecoin", …

Cryptocurrency

Tweet thread by CertikAlert

2024-04-15 [vendor] Grand Base theft [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

Grand Base, a real world assets platform built on the Base layer-2 blockchain, has seen $2 million exit the platform in a hack or rug pull.The team behind the project claimed that …

Ransomware

Frontier Communications RansomHub Attack

2024-04-14 [malware] RansomHub
Vector: RansomHub ransomware operation gained initial access to Frontier Communications systems; RansomHub typically focuses on data-theft extortion without file encryption

Frontier Communications (a major US telecom serving 25 states) detected unauthorized access on 14 April 2024. RansomHub claimed responsibility and threatened to leak 5 GB of stolen …

Cloud

Advance Auto Parts data breach via Snowflake (UNC5537)

2024-04-14 [vendor] Snowflake cloud data platform / Advance Auto Parts
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials reused against Snowflake tenant with no MFA)

UNC5537 accessed Advance Auto Parts' Snowflake environment between April 14 and May 24, 2024. Breach disclosed July 10 via Maine AGO notification affecting 2.3 million current and …

Cloud

AT&T call records breach via Snowflake (UNC5537)

2024-04-14 [vendor] Snowflake cloud data platform / AT&T
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials reused against Snowflake tenant with no MFA)

UNC5537 downloaded AT&T call and text metadata for nearly all ~110 million AT&T wireless customers, covering May–Oct 2022 and a small subset from Jan 2023. Data included call/text …

Cloud

Ticketmaster / Live Nation data breach via Snowflake (UNC5537 / ShinyHunters)

2024-04-14 [vendor] Snowflake cloud data platform [malware] VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA, METASTEALER (infostealers used to harvest credentials)
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials from infostealer malware reused against Snowflake tenant with no MFA)

UNC5537 (ShinyHunters / Scattered Spider affiliates) used infostealer-harvested credentials to authenticate to Ticketmaster's Snowflake tenant which had no MFA configured. …

Cloud

LendingTree / QuoteWizard data breach via Snowflake (UNC5537 / Sp1d3r)

2024-04-14 [vendor] Snowflake cloud data platform / LendingTree QuoteWizard subsidiary
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials reused against Snowflake tenant with no MFA)

UNC5537 threat actor 'Sp1d3r' posted on BreachForums 1 June 2024 claiming 190 million individual records and 3 billion tracking pixel data records (2 TB compressed) stolen from …

Cloud

Neiman Marcus Snowflake Breach - 31M Email Addresses

2024-04-14 [vendor] Snowflake (cloud data warehouse) [malware] VIDAR/RISEPRO/REDLINE infostealers (used to harvest Snowflake credentials)
Vector: UNC5537 used infostealer-harvested credentials to access Neiman Marcus's Snowflake cloud environment without MFA

Neiman Marcus (US luxury retailer) was breached as part of the UNC5537 mass-Snowflake campaign in May 2024. While the company notified Maine AG of 64,472 individuals, Troy Hunt …

Cloud

AT&T Snowflake Breach - 110 Million Customer Call Records

2024-04-14 [vendor] Snowflake (cloud data platform) [malware] Lumma/Vidar/RedLine infostealers (used to harvest credentials)
Vector: UNC5537 (Scattered Spider) used infostealer-harvested credentials to access AT&T's Snowflake cloud environment without MFA; attackers exfiltrated call and SMS metadata records between 14-25 April 2024

Nearly 110 million AT&T wireless customers had call and text metadata stolen — which numbers were contacted, call duration, and for some users cell tower location data. Data …

Ransomware [SC]

HIPAA Journal

2024-04-10 [vendor] Young Consulting (Connexure) medical stop-loss insurance software [malware] BlackSuit ransomware
Vector: CWE-284: Improper Access Control

Young Consulting (also known as Connexure), an Atlanta-based software solutions provider for medical stop-loss insurance organizations, suffered a BlackSuit ransomware attack …

Other

"Fighting for DeFi"

2024-04-10 [vendor] Uniswap Wells notice
Vector: Regulatory / legal action

The US Securities and Exchange Commission issued a warning to the Uniswap decentralized exchange in the form of a Wells notice. Wells notices are used to inform the recipient of an …

Cryptocurrency

Tweet by Long Beach County

2024-04-07 [vendor] Bored & Hungry [chain] ethereum
Vector: Protocol collapse / insolvency

It's hard to believe that the hamburger joint themed around the owner's Bored Ape NFT failed to take off. Although there was novelty value in the themed restaurant, which for a …

Cryptocurrency

Web3 Is Going Great

2024-04-03 [vendor] Rug pull token [loss] $28,878 [chain] ethereum
Vector: Exit scam / rug pull

A project describing itself as "The world's first memecoin pre-announced as a rugpull" was explicit in its marketing: "do not buy this coin, as it will go to zero."Despite that, …

Ransomware

HIPAA Journal

2024-04-01 [vendor] MediSecure eScripts prescription delivery platform
Vector: CWE-284: Improper Access Control

MediSecure, an Australian electronic prescription delivery service provider, suffered a ransomware attack in April 2024. Approximately 6.5 TB of data was exfiltrated, impacting …

Data leak

IBM Think / Wikipedia / KrebsOnSecurity

2024-04-01 [vendor] National Public Data / Jerico Pictures
Vector: CWE-312: Cleartext Storage of Sensitive Information (plaintext admin credentials in publicly accessible Members.zip on sister site RecordsCheck.net)

Background check company National Public Data (Jerico Pictures) breached via plaintext admin credentials found in Members.zip archive on sister site RecordsCheck.net. 2.9 billion …

Supply chain [SC]

Cisco Duo Third-Party Breach (April 2024)

2024-04-01 [vendor] Unknown Telephony Provider
Vector: Compromise of third-party service provider / vendor relationship

Cisco Duo warns third-party data breach exposed SMS MFA logs. Cisco Duo's security team warns that hackers stole some customers' VoIP and SMS logs for multi-factor authentication …

Supply chain [SC]

Department of Justice Third-Party Breach (April 2024)

2024-04-01 [vendor] Greylock McKinnon Associates
Vector: Compromise of third-party service provider / vendor relationship

DOJ data on 341,000 people leaked in cyberattack on consulting firm. Medicare and other information belonging to 341,000 people was leaked after a consulting firm working with the …

Supply chain [SC]

Moffitt Cancer Center Third-Party Breach (April 2024)

2024-04-01 [vendor] Gunster Yoakley and Stewart PA
Vector: Compromise of third-party service provider / vendor relationship

Medusa Ransomware Group Leaks Data Stolen from American Renal Associates. The Medusa ransomware group has leaked data stolen from American Renal Associates. Moffitt Cancer Center …

Cloud

Mandiant / Wikipedia / CNBC / BleepingComputer

2024-04-01 [vendor] Snowflake cloud data platform [malware] Redline Stealer / Lumma Stealer / Vidar / Raccoon Stealer / Risepro
Vector: CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials used against Snowflake instances lacking MFA)

UNC5537 / Scattered Spider / ShinyHunters used credentials stolen by infostealer malware (some dating back to Nov 2020) to access 160+ Snowflake customer environments lacking MFA. …

Cloud

BleepingComputer

2024-04-01 [vendor] Cylance/BlackBerry data warehouse (Snowflake)
Vector: CWE-522: Insufficiently Protected Credentials (infostealer-harvested credentials, no MFA on Snowflake account)

Cylance (a cybersecurity company owned by BlackBerry) confirmed in June 2024 that a data breach occurred involving a third-party cloud platform. The threat actor 'Sp1d3r' claimed …

Cloud

Snowflake UNC5537 Mass Customer Breach Campaign

2024-04-01 [vendor] Snowflake (cloud data warehouse) [malware] Lumma; Vidar; RedLine; RisePro; Raccoon (infostealers used to harvest credentials)
Vector: UNC5537 (Scattered Spider / ShinyHunters) used credentials harvested by infostealer malware (Lumma, Vidar, RedLine, RisePro, Raccoon) to log into Snowflake customer accounts that lacked MFA; no breach of Snowflake's own platform

UNC5537 compromised approximately 165 Snowflake customer tenants in a mass credential-stuffing campaign from April 2024. Known victims include AT&T (110M records), Ticketmaster …

Cloud

Neiman Marcus data breach via Snowflake (UNC5537)

2024-04-01 [vendor] Snowflake cloud data platform / Neiman Marcus
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (stolen credentials reused against Snowflake tenant with no MFA)

UNC5537 accessed Neiman Marcus's Snowflake database between April and May 2024. Official notification to Maine AGO cited 64,472 individuals; however HIBP analysis identified 31 …

Cloud

Ticketek Australia / TEG Cloud Data Breach

2024-04-01 [vendor] Snowflake (suspected third-party cloud platform)
Vector: Third-party cloud platform compromise; likely Snowflake credential theft via infostealer malware (not officially confirmed by TEG); ShinyHunters linked

Ticketek Australia (operated by TEG, Ticket Entertainment Group) disclosed a data breach in May/June 2024 involving a third-party cloud platform. A ShinyHunters-linked actor posted …

Cloud

Los Angeles Unified School District (LAUSD) Snowflake Credential Breach

2024-04-01 [vendor] Snowflake (cloud data platform)
Vector: Stolen credentials (via infostealer malware) used to access LAUSD vendor Snowflake account with no MFA configured; part of the broader UNC5537 Snowflake credential campaign

Los Angeles Unified School District had student and teacher data stored in Snowflake accounts maintained by one or more third-party vendors. As part of the UNC5537 / ShinyHunters …

Cloud

Walt Disney Company Internal Slack Data Breach (NullBulge)

2024-04-01 [vendor] Slack
Vector: Malicious file (trojanised AI art program) distributed via GitHub; credential theft from victim's 1Password password manager

Ryan Mitchell Kramer (alias 'NullBulge'), a 25-year-old from Santa Clarita, California, distributed a malicious AI art generation tool on GitHub. When a Disney employee downloaded …

Cryptocurrency

Tweet by FixedFloat

2024-04-01 [vendor] FixedFloat [chain] ethereum
Vector: Smart contract exploit / hack

The FixedFloat cryptocurrency exchange was exploited again, this time for around $2.8 million. This follows shortly after a February 18 hack in which attackers made off with $26 …

Cryptocurrency

Tweet by Solareum Project

2024-03-30 [vendor] Solana drain attacks [loss] $500,000 [chain] solana
Vector: Smart contract exploit / hack

The Solana ecosystem is grappling with a spate of drained wallets. A cause has yet to be definitively determined, but some of the thefts were linked to the use of trading bots like …

Cryptocurrency

On-chain messages

2024-03-28 [vendor] Prisma Finance [loss] $12M [chain] ethereum
Vector: Smart contract exploit / hack

The defi protocol Prisma Finance was hacked for 3,257 ETH ($11.5 million). An attacker was able to take advantage of a flaw in the project's smart contracts, allowing them to …

Other

Minute Entry

2024-03-28 [vendor] Sam Bankman-Fried
Vector: Regulatory / legal action

Sixteen months after the collapse of his FTX cryptocurrency exchange, Sam Bankman-Fried has been sentenced to 25 years in prison. He has also been ordered to pay an $11 billion …

Other

Volexity / Palo Alto Networks PSIRT / CISA / Tenable

2024-03-26 [vendor] Palo Alto Networks PAN-OS GlobalProtect [malware] UPSTYLE Python backdoor [cve] CVE-2024-3400
Vector: CWE-77: Command Injection via arbitrary file creation in GlobalProtect feature

CVSS 10.0. Threat actor UTA0218 exploited zero-day in PAN-OS GlobalProtect feature allowing unauthenticated OS command execution as root. Affected PAN-OS 10.2, 11.0, 11.1 with …

Cryptocurrency

Tweet by CertiK

2024-03-22 [vendor] Lucky Star Currency [loss] $297,000 [chain] bsc
Vector: Exit scam / rug pull

The astrology-based Lucky Star Currency project rug-pulled for $1.1 million in October 2023. You'd think that might be the end of it, but on March 22, 2024, ownership of the …

Cryptocurrency

Web3 Is Going Great

2024-03-22 [vendor] Solana racist memecoins [chain] solana

Solana memecoin trading has been booming lately, with people making money by speculating on tokens themed around various memes and jokes. Amid an explosion in trading …

Cryptocurrency

On-chain message

2024-03-21 [vendor] Super Sushi Samurai [loss] $345,000 [chain] ethereum
Vector: Smart contract vulnerability exploit

Super Sushi Samurai, a new blockchain game on the Blast layer-2 blockchain was exploited for $4.6 million when an attacker discovered a vulnerability in its smart contract. A bug …

Cryptocurrency

Tweet thread by zachxbt

2024-03-21 [vendor] TICKER [loss] $900,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A developer brought on to run a presale for the $TICKER token stole $900,000 from the project. 15% of the token supply was sent to the developer to distribute via an airdrop, but …

Data leak

Tweet by AirDAO

2024-03-20 [vendor] AirDAO [loss] $551,540
Vector: Social engineering attack

An attacker used social engineering techniques to gain access to the AirDAO project's liquidity pool. They then were able to drain 126.5 ETH (~$551,540) and 41.6 million AMB …

Cryptocurrency

Tweet thread by Slerf

2024-03-18 [vendor] Slerf memecoin meltdown only adds to mania [loss] $10M [chain] solana

People have gotten really into memecoin trading on Solana recently. Like really into it. Someone decided they'd hop on the bandwagon with "Slerf", a sloth-themed memecoin they said …

Cryptocurrency

Tweet by zachxbt

2024-03-16 [vendor] Ansem Twitter impersonator [loss] $3M [chain] solana
Vector: On-chain theft (attributed by zachxbt)

Someone impersonating Ansem, an influential crypto trader, was able to scam people out of more than $2.6 million simply by replying to the real Ansem's tweets. Using an account …

Cryptocurrency

Tweet by Dumpster DAO

2024-03-16 [vendor] Remilia Collective reports multi-million dollar [loss] $6M [chain] ethereum
Vector: Smart contract exploit / hack

"Charlotte Fang", the leader of the controversial Remilia project (known for its Milady NFTs), claimed he was hacked and drained of ETH and NFTs potentially worth several million …

Cryptocurrency

"March' Major Private Key Compromises"

2024-03-16 [vendor] Wilder World theft [loss] $2M [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

Wilder World is a blockchain-based racing game that uses all the buzzwords: blockchains, artificial intelligence, and metaverse. On March 16, someone with access to the project …

Ai

Tweet by NFPrompt

2024-03-15 [vendor] NFPrompt discloses [chain] bsc
Vector: AI-assisted attack or AI-generated exploit

A Binance-incubated platform called NFPrompt claims to be "the first Prompt Artist Platform in Web3" — with "prompt artist" referring to people who come up with prompts to feed …

Cryptocurrency

Tweet by CertiK Alert

2024-03-15 [vendor] Mozaic [loss] $200,000 [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

The "AI-optimized" defi project Mozaic Fi was exploited by an attacker who drained around $2 million in funds from the project.According to MozaicFi, the theft had been perpetrated …

Other

Tweet thread by Charles Wang

2024-03-15 [vendor] Tether user's accidental burn

Someone accidentally threw away $1.36 million when they accidentally sent Tethers to the Tether contract address — making them permanently inaccessible in a process known as …

Cryptocurrency

Tweet thread by ScamSniffer

2024-03-13 [vendor] ether.fi phishing [loss] $2M [chain] ethereum
Vector: Phishing attack

An Ethereum holder who had been staking their ETH through a liquid restaking protocol called Ether.fi suffered a 501 ETH (~$2.025 million) loss when they fell victim to a phishing …

Data leak

February 2024 Scam Sniffer Phishing Report

2024-03-10 [vendor] February 2024 Twitter phishing [loss] $42M
Vector: Phishing attack

Scam Sniffer's February 2024 report describes 57,000 victims who collectively lost almost $47 million thanks to various phishing schemes on the Twitter platform. Many of the losses …

Ransomware

New Jersey Law Journal

2024-03-09 [vendor] Wacks Law Group client file systems [malware] Qilin ransomware
Vector: CWE-284: Improper Access Control

The Wacks Law Group, a Whippany, New Jersey estate planning law firm with only six attorneys, was attacked by the Qilin ransomware group on March 9, 2024. Sensitive client data …

Data leak [SC]

HIPAA Journal

2024-03-09 [vendor] HealthEquity HSA/benefits platform (SharePoint storage via vendor)
Vector: CWE-522: Insufficiently Protected Credentials (compromised third-party vendor user accounts)

HealthEquity, a Utah-based administrator of health savings accounts (HSAs), health reimbursement arrangements (HRAs), and COBRA benefits serving millions of Americans, disclosed a …

Cryptocurrency

Crypto4Winners Telegram announcement

2024-03-09 [vendor] Crypto4Winners theft [chain] bitcoin, ethereum
Vector: Smart contract exploit / hack

A investment firm called Crypto4Winners announced in their Telegram channel that "Our investigations lead us to suspect an individual of committing fraudulent acts that may have …

Cryptocurrency

Tweet by SlowMist

2024-03-08 [vendor] Unizen [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Unizen defi platform lost around $2.1 million in the Tether stablecoin in an attack that took advantage of a vulnerability an external call from the project smart contract.The …

Data leak

Acuity Federal Contractor GitHub Repository Breach

2024-03-07 [vendor] Tekton CI/CD; GitHub
Vector: Threat actor IntelBroker exploited a vulnerability in Acuity's Tekton CI/CD server to steal GitHub credentials, then accessed government-related repositories

IntelBroker breached federal IT contractor Acuity Inc. on 7 March 2024 and claimed to have stolen data from US State Department, DoD, NSA, ICE, USCIS, and other agencies. The …

Cryptocurrency

Woofi

2024-03-05 [vendor] WOOFi [loss] $9M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to use a flash loan attack to manipulate an oracle on the WooFi DEX implementation on the Arbitrum network. By manipulating the price of $WOO, they were able …

Supply chain [SC]

JetBrains TeamCity CVE-2024-27198 Authentication Bypass — Mass Exploitation

2024-03-04 [vendor] JetBrains TeamCity (CI/CD server and build management platform) [malware] Various backdoors and remote access tools deployed by exploiting actors [cve] CVE-2024-27198 +1
Vector: Authentication bypass vulnerability (CVE-2024-27198, CVSS 9.8) in JetBrains TeamCity CI/CD server allowed unauthenticated remote attackers to gain administrative access to TeamCity build servers; a second vulnerability (CVE-2024-27199, CVSS 7.3) allowed path traversal; multiple threat actors exploited these within hours of Rapid7's public disclosure, abusing admin access to plant backdoors in CI/CD pipelines and steal source code, credentials, and build artifacts

On 4 March 2024, JetBrains and Rapid7 (the discoverer) simultaneously disclosed two authentication bypass vulnerabilities in JetBrains TeamCity — a popular CI/CD build server used …

Supply chain [SC]

American Express Third-Party Breach (March 2024)

2024-03-01 [vendor] A Merchant Processor
Vector: Compromise of third-party service provider / vendor relationship

American Express credit cards exposed in third-party data breach. American Express is warning customers that credit cards were exposed in a third-party data breach after a merchant …

Supply chain [SC]

Bay Area Anesthesia Third-Party Breach (March 2024)

2024-03-01 [vendor] Bowden Barlow Law, P.A.
Vector: Compromise of third-party service provider / vendor relationship

Grace Lutheran Communities Falls Victim of ALPHV/Blackcat Ransomware Attack. Grace Lutheran Communities in Wisconsin, a provider of rehabilitation services, assisted living, …

Supply chain [SC]

Fidelity Third-Party Breach (March 2024)

2024-03-01 [vendor] Infosys McCamish Systems (IMS)
Vector: Compromise of third-party service provider / vendor relationship

First BofA, Now Fidelity: Same Vendor Behind Third-Party Breaches. The private information of more than 28,000 people may have been accessed by unauthorized actors, thanks to a …

Supply chain [SC]

TechCrunch

2024-03-01 [vendor] Mintlify documentation platform
Vector: CWE-312: Cleartext Storage of Sensitive Information (OAuth tokens stored in database)

Mintlify, an AI-powered code documentation platform used by software developers, suffered a breach on March 1, 2024. A vulnerability in Mintlify's systems allowed unauthorized …

Supply chain [SC]

Swiss Goverment Third-Party Breach (March 2024)

2024-03-01 [vendor] Xplain
Vector: Compromise of third-party service provider / vendor relationship

Switzerland: Play ransomware leaked 65,000 government documents. The National Cyber Security Centre (NCSC) of Switzerland has released a report on its analysis of a data breach …

Credential theft

Roku credential stuffing attack (576,000 accounts)

2024-03-01 [vendor] Roku streaming platform
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (credential stuffing using credentials stolen from third-party breaches)

Second Roku credential stuffing incident of 2024 (first: ~15,000 accounts in March). Attackers used username/password pairs from prior unrelated breaches to authenticate against …

Cryptocurrency

Tweet by zachxbt

2024-03-01 [vendor] AI Protocol theft and burn [loss] $4M [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

Someone who held over 111.6 million ALI tokens from a project called The AI Protocol was phished by someone using a wallet drainer service using a permit phishing technique. The …

Cryptocurrency

Tweet by Spreekaway

2024-02-28 [vendor] Seneca Protocol bug [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A bug in Seneca Protocol's smart contract has allowed attackers to steal funds from users who had approved the contract. So far, around $3 million has been stolen across the …

Data leak

VeriSource Services HR Benefits Data Breach

2024-02-27
Vector: Unauthorized party gained access to VeriSource Services systems on approximately 27 February 2024 and exfiltrated employee benefits data; initial vector not publicly disclosed

VeriSource Services (Texas-based employee benefits and HR administration provider) discovered unusual activity on 28 February 2024. The final breach count was approximately 4 …

Cryptocurrency

Tweet

2024-02-27 [vendor] Serenity Shield [loss] $586,000 [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

Serenity Shield, a project aiming to solve "crypto inheritence", has been hacked. Although the project prominently claims to help "ensur[e] your financial and personal security", …

Cryptocurrency

Tweet by zachxbt

2024-02-26 [vendor] Dechat token launch error [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

The user experience in crypto is apparently so bad that platforms can't even keep their own tokens straight. A web3 messaging project, Dechat, announced with some fanfare that the …

Other

Tweet by zachxbt

2024-02-26 [vendor] BitForex withdrawals [loss] $57M
Vector: On-chain theft (attributed by zachxbt)

The Hong Kong-based BitForex cryptocurrency exchange has shut down access to its platform after a suspicious outflow of around $57 million on several blockchains. Users who have …

Other

"The disappointing tea.xyz"

2024-02-26 [vendor] tea.xyz spam

This crypto skeptic I've heard of once said "Show me the incentive and I will show you the outcome."A project called tea.xyz promised people they could "get rewards for [their] …

Supply chain [SC]

Akamai / CrowdStrike / Wikipedia / Datadog Security Labs

2024-02-24 [cve] CVE-2024-3094
Vector: CWE-506: Embedded Malicious Code (multi-year social engineering to gain maintainer status, then injected SSH backdoor into xz-utils)

CVSS 10.0. Suspected nation-state actor 'Jia Tan' (JiaT75) spent 2+ years cultivating trust in xz-utils project before becoming co-maintainer. Injected SSH authentication …

Data leak

Tweet by CertiK

2024-02-22 [vendor] DeezNutz_404 [loss] $170,000
Vector: Smart contract exploit / hack

I might otherwise skip over news of a $170,000 hack, given how commonly thefts of that scale happen in the crypto world, but with a name like this... come on.One thing that keeps …

Cryptocurrency

Tweet by CertiK

2024-02-22 [vendor] Blueberry Protocol narrowly avoids $1.3 million [loss] $265,000 [chain] ethereum
Vector: MEV / sandwich attack

The Blueberry defi leverage project had a bug in their lending contract, where improper decimal handling allowed for an exploit. An attacker tried to exploit the vulnerability, but …

Cryptocurrency

Tweet by Jihoz

2024-02-22 [vendor] Jihoz Zirlin wallet [loss] $10M [chain] ethereum
Vector: Smart contract exploit / hack

Jeff "Jihoz" Zirlin, a co-founder of the Axie Infinity blockchain game, lost around $9.5 million as two of his crypto wallets were compromised. The thief stole 3,248 ETH ($9.5 …

Other

Tweet by Cyvers Alerts

2024-02-20 [vendor] AAX money movement [loss] $56M

The Hong Kong-based AAX cryptocurrency exchange suspended withdrawals in November 2022, only days after the FTX collapse and related chaos in the cryptocurrency world. They claimed …

Other

Tweet thread by zachxbt

2024-02-20 [vendor] Influencer "Crypto Rover" accused of pump-and-dump and other shady behavior
Vector: On-chain theft (attributed by zachxbt)

A popular cryptocurrency influencer known as "Crypto Rover" has been accused by blockchain sleuth zachxbt of shady behavior, including accepting promotional payments from crypto …

Cloud [SC]

ConnectWise ScreenConnect CVE-2024-1709 Auth Bypass — Mass Exploitation by Multiple Threat Actors

2024-02-19 [vendor] ConnectWise ScreenConnect (remote access / remote desktop tool for MSPs) [malware] LockBit ransomware, Bl00dy ransomware, various RATs and backdoors deployed by multiple threat actors [cve] CVE-2024-1709 +1
Vector: Authentication bypass vulnerability (CVE-2024-1709, CVSS 10.0) in ConnectWise ScreenConnect — a widely-used remote desktop and access tool used by managed service providers (MSPs) — allowed unauthenticated remote attackers to bypass authentication and create new administrator accounts, leading to complete system compromise; a second path traversal vulnerability (CVE-2024-1708) also existed; multiple ransomware groups and nation-state actors exploited the vulnerabilities within hours of disclosure

On 19 February 2024, ConnectWise disclosed two critical vulnerabilities in ScreenConnect — an on-premises remote access tool used by managed service providers (MSPs) and IT teams …

Data leak

Tweet by Lookonchain

2024-02-16 [vendor] kirilm.eth phishing [loss] $4M
Vector: Phishing attack

A trader known as kirilm.eth fell victim to a phishing attack, losing over 180 million BEAM tokens to a scammer. BEAM is a token belonging to the Beam blockchain gaming network, …

Cryptocurrency

"Farcaster"

2024-02-15 [vendor] Farcaster name controversy [chain] ethereum

One of the promises made by proponents of crypto-focused decentralized social networks like Farcaster is that you can't be de-platformed by centralized companies, and you maintain …

Other

"KSI Accidentally Exposes His Crypto Scams"

2024-02-15 [vendor] YouTuber KSI accused of pump-and-dump [loss] $850,000
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuths Coffeezilla and zachxbt teamed up on an investigation into YouTuber and crypto promoter KSI, accusing him of pumping up interest into the XCAD project and then …

Data leak [SC]

BleepingComputer

2024-02-14 [vendor] Financial Business and Consumer Solutions (FBCS) debt collection platform
Vector: CWE-284: Improper Access Control

Financial Business and Consumer Solutions (FBCS), a Pennsylvania-based debt collection agency, suffered a ransomware attack between February 14-26, 2024. The breach ultimately …

Data leak

Comcast/Xfinity Customer Data Breach via FBCS Third-Party (FCC Fine)

2024-02-14
Vector: Third-party vendor breach: Financial Business and Consumer Solutions (FBCS), a debt collection agency handling Comcast customer accounts, was compromised in a ransomware attack February 14–26, 2024

Financial Business and Consumer Solutions (FBCS), a third-party debt collection agency used by Comcast, was hit by ransomware in February 2024. As a result, data on approximately …

Cryptocurrency

Tweet thread by HashBastardsNFT

2024-02-14 [vendor] Creator of "Robotos" NFT project, once collaborating on a TV series with TIME studios, accused of [chain] ethereum

Pablo Stanley, an artist who created the "Robotos" generative NFT collection, posted two final messages from the Robotos Twitter account. First, "it was a good run! thank u, all!", …

Cryptocurrency

Tweet by CertiK Alert

2024-02-13 [vendor] Duelbits [loss] $5M [chain] ethereum, bsc
Vector: Private key compromise

The Duelbits crypto casino and sports betting website was drained of around $4.6 million on both the Ethereum and BNB Chain blockchains. The funds were quickly bridged or exchanged …

Ransomware

Iowa AG Sues UnitedHealth / Change Healthcare over 2024 Ransomware Breach — State Enforcement Action

2024-02-12 [vendor] UnitedHealth Group / Change Healthcare (regulatory enforcement record) [malware] ALPHV/BlackCat ransomware (original incident)
Vector: See original Change Healthcare ALPHV/BlackCat ransomware breach record (2024-02-12): MFA-less Citrix remote access portal exploited by ALPHV affiliates using stolen credentials

In April 2026, Iowa Attorney General Brenna Bird filed a lawsuit against UnitedHealth Group seeking financial damages, civil penalties, and improvements to the company's data …

Ransomware

ThreatIntelReport / UnitedHealth Group congressional testimony

2024-02-11 [vendor] Citrix remote access / Change Healthcare claims processing platform [malware] ALPHV/BlackCat
Vector: CWE-308: Use of Single-Factor Authentication (compromised Citrix remote access lacking MFA)

Affiliate of ALPHV/BlackCat breached Change Healthcare (UnitedHealth subsidiary) on Feb 11 2024 via stolen credentials on a Citrix portal lacking MFA. Spent 9 days in network …

Data leak

DISA Global Solutions Employment Screening Data Breach

2024-02-09
Vector: Unauthorized third party gained access to DISA Global Solutions systems between 9 February and 22 April 2024; initial access vector not publicly disclosed

DISA Global Solutions (background check, drug testing, and employment screening provider to 55,000+ companies including 135 Fortune 500 firms) was breached for 100+ days before …

Ransomware

Prudential Financial ALPHV/BlackCat Breach

2024-02-04 [malware] ALPHV/BlackCat
Vector: ALPHV/BlackCat ransomware gained unauthorized access to Prudential Financial administrative and user data; initial access vector not publicly disclosed

ALPHV/BlackCat ransomware group breached Prudential Financial (major US insurer) between 4-5 February 2024, initially believed to affect only 36,545 people. The true scope was …

Data leak

NTT Communications Japan Data Breach (17,891 Corporate Customers)

2024-02-01
Vector: Attackers gained unauthorized access to NTT Communications' order information system (Order Information Change System) through an undisclosed vulnerability, enabling data exfiltration of corporate customer contract records

NTT Communications Corporation, the international subsidiary of Japan's NTT Group, disclosed in March 2025 that a breach had exposed data for 17,891 corporate customers. The …

Supply chain [SC]

Audiens Third-Party Breach (February 2024)

2024-02-01 [vendor] Viamedis
Vector: Compromise of third-party service provider / vendor relationship

Data breach at French healthcare services firm puts millions at risk. French healthcare services firm Viamedis suffered a cyberattack that exposed the data of policyholders and …

Cryptocurrency

Tweet thread by zachxbt

2024-01-31 [vendor] Chris Larsen XRP theft [loss] $108M [chain] ripple
Vector: On-chain theft (attributed by zachxbt)

Blockchain sleuth zachxbt noticed the strange movement of around 213 million XRP, the native token for the Ripple project. These tokens were priced at around $112.5 million at the …

Data leak

<i>USA v. Lee</i>

2024-01-29 [vendor] Sam Lee
Vector: Regulatory / legal action

US Attorneys in Maryland and the US Securities and Exchange Commission filed criminal and civil lawsuits, respectively, against Sam Lee, the co-founder of the HyperVerse …

Cryptocurrency

Tweet by CertiK

2024-01-28 [vendor] Goledo Finance [loss] $2M [chain] ethereum
Vector: Flash loan attack on smart contract

Goledo Finance, an Aave-based lending protocol, was exploited through a flash loan attack. The attacker stole assets estimated by CertiK at around $1.7 million.Goledo Finance …

Ransomware

HIPAA Journal / CM Alliance / The Record

2024-01-26 [vendor] Lurie Children's Hospital of Chicago IT systems [malware] Rhysida
Vector: CWE-1391: Use of Weak Credentials (exact vector not publicly disclosed)

Rhysida ransomware attacked Lurie Children's Hospital of Chicago (pediatric hospital) Jan 26-31 2024. Patient-facing systems offline for ~3.5 months. 791,784 individuals notified …

Cryptocurrency

WSM exploiter wallets

2024-01-25 [vendor] WallStreetMemes [loss] $6M [chain] bsc
Vector: Smart contract exploit / hack

Hackers were able to exploit a vulnerability in the staking contract for WallStreetMemes ($WSM), a memecoin and online casino project targeted at the "meme warriors" who frequent …

Cryptocurrency

Tweet by ConcentricFi

2024-01-22 [vendor] Concentric Finance [loss] $2M [chain] ethereum
Vector: Social engineering attack

The Concentric Finance yield aggregator project issued a statement that the protocol had been exploited after a social engineering attack on a team member that had access to the …

Cryptocurrency

Chapter 11 petition

2024-01-21 [vendor] Terraform Labs files for bankruptcy [chain] terra
Vector: Regulatory / legal action

Terraform Labs, the company behind the Terra blockchain, has filed for bankruptcy. Its flagship product, the Terra stablecoin and associated LUNA token, failed spectacularly in May …

Data leak

AnyDesk Production System Breach — Source Code and Code Signing Certificates Stolen

2024-01-20 [vendor] AnyDesk production systems / code signing infrastructure
Vector: Undisclosed sophisticated attack on AnyDesk's production systems; AnyDesk described it as a cyberattack on their production systems that resulted in compromise of their private code signing keys and source code; no ransomware was deployed

In January 2024, AnyDesk — the widely-used remote desktop software with over 170,000 customers including major enterprises and government agencies — discovered a breach of its …

Ransomware [SC]

TietoEVRY Ransomware Attack (Swedish Universities, Municipalities, Companies)

2024-01-19 [vendor] TietoEVRY (cloud hosting and IT services) [malware] Akira ransomware
Vector: Akira ransomware group deployed ransomware against TietoEVRY's Sweden-based cloud hosting platform, impacting one of TietoEVRY's datacenters and disrupting cloud services for dozens of Swedish customers

On January 19-20, 2024, TietoEVRY, a Finnish-Norwegian IT company and one of the largest IT service providers in the Nordics, suffered an Akira ransomware attack against its …

Other

IBM Security Intelligence

2024-01-18 [vendor] Unitronics PLC / Muleshoe, TX water tower SCADA
Vector: CWE-1188: Insecure Default Initialization of Resource (default credentials on internet-exposed industrial control systems)

In January 2024, Russian hackers affiliated with Sandworm (a GRU/Russian military intelligence cyber unit) infiltrated water treatment systems in Muleshoe, Texas, causing a water …

Data leak

Trello user data scraped via unauthenticated REST API

2024-01-16 [vendor] Trello (Atlassian)
Vector: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (unauthenticated REST API endpoint allowed email-to-profile lookups)

Threat actor 'emo' fed 500 million email addresses from prior breach corpora into Trello's publicly accessible REST API which returned public user profile data for each match, …

Cryptocurrency

Tweet by the SEC

2024-01-09 [vendor] SEC Twitter account compromised [chain] bitcoin
Vector: Smart contract exploit / hack

As the crypto industry collectively turns blue holding its breath for a decision on a raft of bitcoin spot ETFs currently in front of the SEC, the SEC Twitter account was hacked. …

Other

<i>USA v. Rodney Burton</i>

2024-01-09 [vendor] Bitcoin Rodney arrest
Vector: Regulatory / legal action

A crypto influencer known as "Bitcoin Rodney" was arrested by US authorities for his involvement in the HyperVerse crypto scam, which fleeced victims out of over $1 billion. In …

Cryptocurrency

Web3 Is Going Great

2024-01-08 [vendor] "Undead Apes" [loss] $128,000 [chain] solana
Vector: Exit scam / rug pull

The creator of a Solana-based NFT project called Undead Apes Society has been charged with money laundering conspiracy and making false statements to investigators after …

Data leak

Tweet thread by CertiK

2024-01-07 [vendor] Narwhal exit [loss] $2M
Vector: Exit scam / rug pull

A cryptocurrency project called Narwhal appears to have rug-pulled, claiming that they were hacked. In a post on their Twitter account, they claimed that a "hacker attack" caused …

Data leak

Tweet by Cyvers

2024-01-06 [vendor] CoinsPaid [loss] $8M
Vector: Smart contract exploit / hack

The crypto payments platform CoinsPaid was hacked for the second time in six months. This time, around $7.5 million in various tokens was stolen.In July 2023, an attacker stole …

Cryptocurrency

"XKingdom Incident Analysis"

2024-01-06 [vendor] xKingdom [loss] $1M [chain] ethereum

The xKingdom project promised users a way to "build your kingdom" on Twitter, earning tokens by interacting with tweets and doing "quests". Users had to borrow XKING tokens in …

Data leak

Tweet by CertiK

2024-01-05 [vendor] CertiK Twitter
Vector: On-chain theft (attributed by zachxbt)

The Twitter account of the blockchain security company CertiK was hacked, then used to post tweets ostensibly warning of a massive crypto vulnerability and urging users to click a …

Ransomware

BleepingComputer

2024-01-04 [vendor] LoanDepot mortgage platform [malware] ALPHV/BlackCat ransomware
Vector: CWE-522: Insufficiently Protected Credentials

California-based mortgage lender LoanDepot was attacked by the ALPHV/BlackCat ransomware gang between January 3-5, 2024. Approximately 16.9 million customers had their personal …

Cryptocurrency

"Post-Mortem &amp; Remediation Plan"

2024-01-04 [vendor] Gamma Strategies [loss] $6M [chain] ethereum
Vector: Smart contract exploit / hack

The Gamma Strategies defi protocol suffered an exploit when an attacker targeted their vaults on several projects across the Arbitrum layer-2 network. The attacker successfully …

Cryptocurrency

Tweet thread by Bill Lou

2024-01-02 [vendor] Bill Lou [loss] $125,000 [chain] ethereum
Vector: Phishing attack

Bill Lou, the co-founder of a cryptocurrency wallet that claims to "revolutionize wallet security", was scammed out of 52 stETH (~$125,000) when he clicked a link promising an …

Cryptocurrency

Tweet thread by Radiant Capital

2024-01-02 [vendor] Radiant Capital [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

Radiant Capital, a cross-chain lending protocol built on the Arbitrum layer-2 network, was hacked for 1,900 ETH (~$4.5 million). The exploit relied on a flaw in the underlying …

Data leak

Kaiser Permanente web tracking pixel data disclosure (13.4 million)

2024-01-01 [vendor] Kaiser Permanente member portal and apps
Vector: CWE-359: Exposure of Private Personal Information to an Unauthorized Actor (third-party analytics/advertising tracking pixels embedded in patient-facing portal shared PHI with Google, Microsoft Bing, and X/Twitter)

Kaiser Permanente disclosed that tracking technologies (pixels) embedded in its website and mobile apps transmitted member health information to third-party tech companies …

Data leak

Outabox Biometric Data Breach (Australia)

2024-01-01
Vector: Insider threat: former developers based in the Philippines claimed to have exfiltrated data in response to unpaid wages (18 months of non-payment)

Outabox, an Australian hospitality IT provider offering facial recognition sign-in services for clubs, suffered a data breach exposing biometric and personal data of approximately …

Supply chain [SC]

Family Healthcare Third-Party Breach (January 2024)

2024-01-01 [vendor] Brady Martz & Associates
Vector: Compromise of third-party service provider / vendor relationship

Singing River Health System Confirms Ransomware Attack Affected 895,000 Patients. Singing River Health System has confirmed that 895,204 individuals were affected by an August 2023 …

Supply chain [SC]

Framework Computer Third-Party Breach (January 2024)

2024-01-01 [vendor] Keating Consulting Group
Vector: Compromise of third-party service provider / vendor relationship

Framework discloses data breach after accountant gets phished. Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers …

Supply chain [SC]

Primula Third-Party Breach (January 2024)

2024-01-01 [vendor] Tietoevry
Vector: Compromise of third-party service provider / vendor relationship

Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected. Finland-based Tietoevry said “one part of one of our Swedish datacenters” was attacked with …

Supply chain [SC]

Uppsala County Third-Party Breach (January 2024)

2024-01-01 [vendor] TietoEVRY
Vector: Compromise of third-party service provider / vendor relationship

Tietoevry ransomware attack causes outages for Swedish firms, cities. Finnish IT services and enterprise cloud hosting provider Tietoevry has suffered an Akira ransomware attack …

Credential theft

Tycoon2FA Phishing-as-a-Service Platform — AiTM MFA Bypass, Rebound 2026

2024-01-01 [vendor] Microsoft 365 and Google Workspace tenants (targeted via Tycoon2FA phishing kit) [malware] Tycoon2FA phishing kit
Vector: Tycoon2FA is a phishing-as-a-service (PhaaS) platform that implements adversary-in-the-middle (AiTM) techniques using reverse proxy infrastructure to intercept and steal session cookies from Microsoft 365 and Google Workspace users, bypassing multi-factor authentication in real time

Tycoon2FA is a sophisticated phishing-as-a-service platform discovered in 2023 and analysed in depth by Sekoia.io in March 2024. The platform operates as a reverse proxy between …

Cloud

Sisense Business Analytics Platform Breach (CISA Advisory)

2024-01-01 [vendor] GitLab (self-hosted); Amazon S3
Vector: Attackers gained access to Sisense's self-hosted GitLab code repository, found credentials/tokens granting access to Sisense's Amazon S3 buckets in the cloud, and exfiltrated customer access tokens, API keys, passwords, and certificates

CISA issued an urgent advisory on 11 April 2024 warning Sisense customers to immediately rotate all credentials used with the platform. Sisense (a business intelligence/analytics …

Cloud

Volkswagen Group CARIAD EV Location Data Leak (AWS Misconfiguration)

2024-01-01 [vendor] Amazon Web Services (AWS) S3
Vector: Amazon Web Services (AWS) cloud storage misconfiguration: data left unencrypted and publicly accessible in S3 buckets managed by Volkswagen's software subsidiary CARIAD

Volkswagen Group's software subsidiary CARIAD left data on approximately 800,000 EV owners unencrypted and publicly accessible in AWS cloud storage for months. Affected brands: …

Other [SC]

Healthcare Vendor Supply Chain Systemic Risk — Cascading Breaches Across US Hospital Systems

2024-01-01 [vendor] Healthcare technology vendor ecosystem — EHR vendors, billing processors, lab networks, pharmacy benefit managers
Vector: Healthcare vendor supply chain attacks exploit the concentration of sensitive patient data and operational dependencies in third-party EHR vendors, billing processors, managed care platforms, and file transfer systems; a single vendor breach cascades to hundreds of hospital and health plan clients simultaneously

By 2025-2026, healthcare vendor supply chain attacks had become the dominant breach vector in US healthcare, with HHS OIG and OCR reporting that third-party vendor incidents …

Other

Global Ransomware Law Enforcement Disruption Operations 2025-2026 — Europol, FBI, NCA

2024-01-01 [vendor] LockBit, BlackCat/ALPHV, Hive, Cl0p, Scattered Spider — ransomware operations disrupted 2024-2026 [malware] LockBit, ALPHV/BlackCat, Hive, Cl0p, REvil, Scattered Spider
Vector: Law enforcement disruption of ransomware infrastructure using proactive techniques: infiltrating group chats and affiliate portals months before public action (Operation Cronos / LockBit), seizing cryptocurrency from ransomware wallets, arresting affiliates and key operators globally, and publishing decryption keys for victims

By 2025-2026, international law enforcement agencies had significantly shifted their approach to ransomware disruption — moving from reactive arrests after the fact to proactive …

Data leak

Tweet by Scam Sniffer

2023-12-28 [vendor] Wallet gets phished for $4.4 million [loss] $4M
Vector: Phishing attack

Someone had a not so fun end to the year when they fell victim to a phishing attack and had around 275,700 LINK drained from their crypto wallet. Those tokens are priced at around …

Cryptocurrency

Memorandum &amp; Opinion

2023-12-28 [vendor] UST and LUNA deemed securities [chain] terra
Vector: Regulatory / legal action

The federal judge overseeing the SEC v. Terraform Labs case has determined that Terra's UST stablecoin, LUNA token, and related tokens were securities. "There is no genuine dispute …

Cryptocurrency

"Levana exploit postmortem"

2023-12-26 [vendor] Levana Protocol [loss] $1M [chain] cosmos
Vector: Smart contract exploit / hack

An attacker successfully manipulated an oracle to drain around 10% of the liquidity pool for the Levana Protocol, an Osmosis-based perpetual futures project. This amounted to …

Cryptocurrency

Tweet by Telcoin

2023-12-26 [vendor] Telcoin [loss] $1M [chain] polygon
Vector: Smart contract exploit / hack

$TEL, the token associated with the Telcoin remittances project, plunged 40% as an exploiter was able to steal around $1.25 million from the project. The company later disclosed …

Ransomware

Anna Jaques Hospital Money Message Ransomware

2023-12-25 [malware] Money Message
Vector: Money Message ransomware gained access to Anna Jaques Hospital network; initial access vector not publicly disclosed

Anna Jaques Hospital in Newburyport, Massachusetts was attacked on Christmas Day 2023 by the Money Message ransomware group, which claimed 600 GB of data was stolen. 316,342 …

Cryptocurrency

Tweet by CertiK

2023-12-25 [vendor] Megabot exit [chain] solana, ethereum, bsc
Vector: AI-assisted attack or AI-generated exploit

The Megabot project rug pulled, stealing $742,000 from those who bought in to the project's presale. The majority of the money — around $692,000 — was stolen on the Solana …

Data leak

Interim Cease Trade Order

2023-12-21 [vendor] Catalyx trading freeze
Vector: Withdrawal halt / insolvency

The Canadian Catalyx cryptocurrency exchange has frozen trading and halted withdrawals after an emergency order by the Alberta Securities Commission on December 21. Catalyx …

Data leak

Tweet thread by Scam Sniffer

2023-12-21 [vendor] MS drainer [loss] $59M
Vector: Smart contract exploit / hack

A new wallet drainer tool has stolen $58.98 million in cryptocurrency assets from more than 63,000 victims in the past nine months. People using the drainer software have pulled in …

Ransomware

First American Financial Cyberattack

2023-12-20
Vector: Threat actors gained access to First American Financial systems and exfiltrated non-production data before encrypting it; initial access vector not publicly disclosed

First American Financial Corp (one of the largest US title insurance providers) shut down its systems in late December 2023 after attackers accessed and encrypted non-production …

Data leak

St Vincent's Health Australia Cyberattack — Sensitive Health Data Stolen

2023-12-19 [vendor] St Vincent's Health Australia IT systems
Vector: Unknown cyber criminal group accessed St Vincent's Health Australia's network by exploiting vulnerabilities in their systems; specific attack vector not publicly disclosed; attacker was able to exfiltrate data before detection

On 19 December 2023, St Vincent's Health Australia — the country's largest non-government healthcare and aged care provider, operating hospitals and aged care facilities across New …

Supply chain [SC]

Ledger Connect Kit Supply Chain Attack — DRAINER injected via compromised npm account

2023-12-14 [vendor] Ledger Connect Kit (@ledgerhq/connect-kit npm package) [malware] Angel Drainer (cryptocurrency wallet drainer injected via CDN)
Vector: Former Ledger employee's NPMJS account was compromised via a targeted phishing attack after the employee left the company; attacker used the account to publish malicious versions (1.1.5, 1.1.6, 1.1.7) of the @ledgerhq/connect-kit package — a widely integrated JavaScript library that enables hardware wallet connections in DeFi front-ends — replacing the legitimate code with a wallet drainer that redirected cryptocurrency transactions to attacker-controlled addresses

On 14 December 2023, an attacker compromised the npm account of a former Ledger employee (whose account retained access to the @ledgerhq/connect-kit package despite employment …

Supply chain [SC]

Tweet thread by bantg

2023-12-14 [vendor] Ledger supply chain attack [loss] $610,000
Vector: Software supply chain attack

A supply chain attack on the Ledger connector application has rippled throughout the world of decentralized apps, which widely use the software to enable people to connect their …

Other

Chapter 7 Voluntary Petition

2023-12-14 [vendor] SafeMoon files for bankruptcy
Vector: Regulatory / legal action

The company behind the SafeMoon cryptocurrency scam has filed for Chapter 7 bankruptcy. Screenshots circulated on Twitter of a letter to employees citing "a number of operational …

Cryptocurrency

"Incident disclosure - 2023-12-11"

2023-12-11 [vendor] Yearn treasury swap [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

Periodically, Yearn Finance converts a small quantity of its treasury tokens into stablecoins to spend on operations. However, something went terribly wrong during this process …

Cryptocurrency

Tweet thread by zachxbt

2023-12-07 [vendor] Uranium Finance [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

In April 2021, an attacker stole $50 million from the defi exchange Uranium Finance. Blockchain investigator zachxbt now says that he believes this attacker has been able to cash …

Data leak

Tweet thread by zachxbt

2023-12-04 [vendor] Rob Robb [loss] $1M
Vector: On-chain theft (attributed by zachxbt)

If you're named Rob Robb, do you have any choice but go into a life of thievery?Robb, also known as "pokerbrat2019", convinced at least 11 people to give him a total of $1.2 …

Cryptocurrency

"Smart contract security vulnerability 12/4"

2023-12-04 [vendor] ThirdWeb vulnerability [chain] ethereum, polygon
Vector: Software bug / unintentional loss

Projects using the suite of pre-built smart contracts from crypto development platform ThirdWeb have been racing to migrate to patched versions as ThirdWeb has disclosed a …

Data leak

Twitter thread by ScamSniffer

2023-12-03 [vendor] Safe Wallet thefts [loss] $5M
Vector: Address poisoning attack

Users of the (not so) Safe Wallet have lost $2.05 million altogether in the past week as they've been targeted by an attacker using an address poisoning attack. The same attacker …

Cloud

Volexity / CISA AA24-060B / Google Cloud / Akamai

2023-12-01 [vendor] Ivanti Connect Secure / Policy Secure [malware] ZIPLINE backdoor / LIGHTWIRE webshell / WARPWIRE credential harvester / THINSPOOL dropper [cve] CVE-2023-46805 +2
Vector: CWE-305: Authentication Bypass by Primary Weakness chained with CWE-77: Command Injection

Chinese nexus APT UNC5221 exploited chained zero-days in Ivanti Connect Secure VPN gateways starting Dec 2023, publicly disclosed Jan 10 2024 by Volexity. CVE-2023-46805 (auth …

Cryptocurrency

Tweet by PeckShieldAlert

2023-11-30 [vendor] Florence Finance theft [loss] $1M [chain] ethereum
Vector: Address poisoning attack

An apparent address poisoning attack on the Florence Finance real-world asset lending protocol led to the loss of $1.45 million in the USDC stablecoin.As of December 4, Florence …

Other

Tweet thread by BitStable

2023-11-29 [vendor] BitStable sale failure

BitStable launched their BSSB token in a public sale only to watch as all tokens sold out in one block. Four entities acquired the majority of the BSSB tokens, an outcome that the …

Data leak [SC]

Geisinger Health - Nuance Communications Insider Breach

2023-11-27 [vendor] Nuance Communications (Microsoft subsidiary)
Vector: Insider threat: a former Nuance Communications IT employee (Andre J. Burk / 'Max Vance') accessed Geisinger patient records two days after being terminated from Nuance, using credentials that had not yet been deprovisioned

Geisinger Health (major Pennsylvania health system) discovered on 29 November 2023 that former Nuance employee Andre Burk (age 46, California) had accessed patient records from 27 …

Other

Iranian IRGC CyberAv3ngers Water Utility ICS Attacks — US and Israel Infrastructure

2023-11-22 [vendor] Unitronics Vision Series PLCs (programmable logic controllers) at US water and wastewater facilities [cve] CVE-2023-6448
Vector: CyberAv3ngers (affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command, IRGC-CEC) exploited internet-exposed Unitronics Vision Series PLCs at water and wastewater facilities; the PLCs had default factory passwords and were directly internet-accessible without authentication

Beginning 22 November 2023, CyberAv3ngers — a threat group affiliated with Iran's IRGC Cyber-Electronic Command — conducted attacks against Unitronics Vision Series PLCs at water …

Other

<i>SEC v. Kraken</i>

2023-11-20 [vendor] Kraken sued by U.S. SEC
Vector: Regulatory / legal action

Kraken is the latest cryptocurrency exchange to face a lawsuit from the U.S. Securities and Exchange Commission. According to the SEC, Kraken violated securities laws by listing …

Data leak

Tweet by Kronos

2023-11-18 [vendor] Kronos [loss] $26M
Vector: On-chain theft (attributed by zachxbt)

The cryptocurrency trading firm Kronos Research announced on Twitter that they had stopped trading while they investigated "unauthorized access of some of our API keys". They …

Data leak

Tweet by zachxbt

2023-11-14 [vendor] Twitter security account impersonator [loss] $300,000
Vector: On-chain theft (attributed by zachxbt)

On the evening of November 14 I logged on to Twitter to notice that #OpenSeaHackAlert and related hashtags were trending. But they were trending not because OpenSea had truly been …

Cloud

Cloudflare breach via stolen Okta credentials (nation-state, Thanksgiving 2023)

2023-11-14 [vendor] Cloudflare internal systems (Atlassian Confluence wiki, Jira bug tracker, Bitbucket source code)
Vector: CWE-287: Improper Authentication (stolen access tokens and service account credentials from Okta October 2023 breach reused; Cloudflare failed to rotate them)

Nation-state threat actor (attributed to Midnight Blizzard / Cozy Bear / APT29 in some reporting) used one access token and three service account credentials stolen during the Okta …

Cryptocurrency

"Randstorm: You Can’t Patch a House of Cards"

2023-11-14 [vendor] randstorm [chain] bitcoin, litecoin
Vector: Software bug / unintentional loss

While trying to help a Bitcoin holder who lost their password, researchers at Unciphered discovered a major flaw in the way early Bitcoin wallets had been created. Thanks to a flaw …

Data leak

Tweet thread by zachxbt

2023-11-12 [vendor] Binance-linked wallet [loss] $27M
Vector: On-chain theft (attributed by zachxbt)

An attacker apparently stole $27 million in the Tether stablecoin from a wallet that had just withdrawn the funds from their Binance account. The hacker quickly converted the funds …

Ransomware

DP World Australia Ransomware Attack (Port Operations Disrupted)

2023-11-10 [vendor] Citrix NetScaler ADC/Gateway [cve] CVE-2023-4966
Vector: Attackers exploited a Citrix Bleed vulnerability (CVE-2023-4966) in DP World's Citrix NetScaler infrastructure to gain unauthorized access to the company's network; the vulnerability allowed session token hijacking without authentication

DP World Australia, which operates approximately 40% of Australia's container port throughput across terminals in Sydney, Melbourne, Brisbane, and Fremantle, suffered a cyberattack …

Ransomware

DP World Australia Port Operations Cyberattack — 3-Day Freight Disruption

2023-11-10 [vendor] DP World Australia port operations technology
Vector: Unknown attacker (ALPHV/BlackCat ransomware suspected) gained access to DP World Australia's internal IT network by exploiting a vulnerability in internet-facing systems; the attack disrupted the operational technology systems managing container movements

On 10 November 2023, DP World Australia — one of Australia's largest port operators, managing approximately 40% of Australian container port operations across Port Botany (Sydney), …

Cryptocurrency

Tweet by CyversAlerts

2023-11-10 [vendor] Samudai treasury drained [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

The treasury of the Samudai DAO was apparently drained as an attacker compromised the project's multisignature wallets and the wallet belonging to the project's founder, Kushagra …

Cryptocurrency

Tweet by CyversAlerts

2023-11-08 [vendor] CoinSpot [loss] $2M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Australian cryptocurrency exchange CoinSpot appears to have been hacked for around 1,283 ETH (~$2.4 million). In two separate transactions, the ETH was transferred out of …

Cryptocurrency

Tweet thread by CertiK Alert

2023-11-07 [vendor] MEV bot 0x05f01 [loss] $2M [chain] ethereum, bitcoin
Vector: Flash loan attack on smart contract

An MEV bot was exploited after an attacker discovered a vulnerability in its code that allowed anyone to call one of its functions that sold wBTC for wETH. Using a flash loan to …

Cryptocurrency

Tweet by NGBxShpend

2023-11-05 [vendor] Yuga Labs' social media lead resigns [chain] ethereum

One might think that a social media lead might have a grasp on his own social media accounts, and might have scrubbed damning tweets made only shortly before they began their …

Cryptocurrency

Tweet by Bored Ape Yacht Club

2023-11-04 [vendor] ApeFest photokeratitis [chain] ethereum

Bored Ape collectors attending an ApeFest party in Hong Kong have now been subjected to the kind of eye pain the rest of us have felt for years having to look at their hideous, …

Cloud

Sumo Logic AWS Access Key Compromise

2023-11-03 [vendor] Amazon Web Services (AWS)
Vector: A threat actor used a compromised AWS access key credential belonging to Sumo Logic to gain unauthorized access to Sumo Logic's AWS infrastructure

On November 3, 2023, Sumo Logic, a cloud-native security analytics and log management platform, discovered that a compromised AWS access key had been used to gain unauthorized …

Supply chain [SC]

Dollar Tree Third-Party Breach (November 2023)

2023-11-01 [vendor] Zeroed-In Technologies
Vector: Compromise of third-party service provider / vendor relationship

Dollar Tree hit by third-party data breach impacting 2 million people. Discount store chain Dollar Tree was impacted by a third-party data breach affecting 1,977,486 people after …

Supply chain [SC]

Northwell Health Third-Party Breach (November 2023)

2023-11-01 [vendor] Perry Johnson & Associates, Inc., (PJ&A)
Vector: Compromise of third-party service provider / vendor relationship

Console & Associates, P.C.: PJ&A Reports Data Breach Exposing Social Security Numbers and PHI of an Unknown Number of Northwell Health Patients. /PRNewswire/ -- Millions of …

Supply chain [SC]

Sutter Health Third-Party Breach (November 2023)

2023-11-01 [vendor] Virgin Pulse
Vector: Compromise of third-party service provider / vendor relationship

Sutter Health Confirms 84K Individuals Affected by Cyberattack on Business Associate. Sutter Health, a healthcare provider serving Northern California, has recently confirmed that …

Supply chain [SC]

Taylor Rose Third-Party Breach (November 2023)

2023-11-01 [vendor] CTS
Vector: Compromise of third-party service provider / vendor relationship

EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions progressing - Property Industry Eye. EYE NEWSFLASH: Major ‘cybersecurity issue’ preventing transactions …

Supply chain [SC]

Westat, Inc. Third-Party Breach (November 2023)

2023-11-01 [vendor] Nuance Communications, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Westat. Notice of data security incident affecting Renown Health patient information. Learn about the MOVEit vulnerability and credit monitoring. Third-party company: Nuance …

Credential theft

Microsoft corporate email breach by Midnight Blizzard (Nobelium / APT29)

2023-11-01 [vendor] Microsoft corporate Office 365 email / source code repositories
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (password spray attack against a legacy non-production test tenant account lacking MFA)

Midnight Blizzard (Russian SVR, also known as Nobelium/Cozy Bear/APT29) conducted a password spray attack against a legacy Microsoft test tenant account with no MFA enabled in …

Cloud [SC]

1Password Third-Party Breach (November 2023)

2023-11-01 [vendor] Okta
Vector: Compromise of third-party service provider / vendor relationship

Okta breach: 134 customers exposed in October support system hack. Okta says attackers who breached its customer support system last month gained access to files belonging to 134 …

Cryptocurrency

CCS Wallet Incident

2023-11-01 [vendor] Monero community wallet [loss] $460,895 [chain] monero
Vector: Seed phrase / wallet compromise

Monero's Community Crowdfunding System (CCS) funds projects that aim to improve the ecosystem of Monero, a privacycoin. The CCS is funded by donations, and up until September 1, …

Data leak

Truist Bank Sp1d3r Dark Web Data Sale

2023-10-27
Vector: Unauthorized access to Truist Bank systems in October 2023; initial access vector not publicly confirmed; breach was 'immediately contained' per Truist

Truist Bank (6th-largest US bank) confirmed an October 2023 breach after threat actor 'Sp1d3r' listed the stolen data for sale on a dark web forum on 12 June 2024 for $1 million. …

Cryptocurrency

Findings of Fact &amp; Conclusions of Law

2023-10-25 [vendor] Ryder Ripps [chain] ethereum
Vector: Regulatory / legal action

A judge has ordered Ryder Ripps and his co-defendant Jeremy Cahen to pay almost $1.6 million in disgorgement and damages after they created a collection of identical NFTs to the …

Data leak

Marina Bay Sands Singapore Loyalty Programme Breach (665K Members)

2023-10-19
Vector: Unauthorized access to Marina Bay Sands' Sands LifeStyle loyalty programme customer database; attacker obtained credentials to access the loyalty programme's backend systems

On October 19-20, 2023, unauthorized actors accessed the Sands LifeStyle loyalty programme database of Marina Bay Sands, Singapore's iconic integrated resort and casino. The breach …

Other

"Superdao is closing down"

2023-10-19 [vendor] Superdao to
Vector: Protocol collapse / insolvency

Superdao, a project aiming to assist communities in forming DAOs, has announced it will be closing its doors. It was blunt in its announcement: "it became clear that the crypto …

Cryptocurrency

Reddit announcement

2023-10-17 [vendor] Reddit abandons blockchain-based Community Points [chain] ethereum
Vector: Exit scam / rug pull

Reddit's attempt to blockchainify their signature Reddit karma has come to an end as the company has decided to pull the plug on the feature. The idea was that users could "own a …

Data leak

Xfinity/Comcast CitrixBleed Data Breach (35.8M Customers)

2023-10-16 [vendor] Citrix NetScaler ADC/Gateway [cve] CVE-2023-4966
Vector: Exploitation of Citrix Bleed (CVE-2023-4966) — a critical vulnerability in Citrix NetScaler ADC/Gateway enabling session token hijacking without authentication; Citrix released a patch on October 10, 2023, but attackers breached Xfinity's systems October 16–19 before the patch was applied

Between October 16–19, 2023, attackers exploited the Citrix Bleed vulnerability (CVE-2023-4966) to gain unauthorized access to Comcast's Xfinity systems. Citrix had issued a patch …

Cryptocurrency

Tweet thread by ChainArgos

2023-10-16 [vendor] TrueUSD TEURO announcement [chain] ethereum
Vector: Private key compromise

A new, Euro-pegged stablecoin called $TEURO emerged on October 13, with an initial supply of around €70 million. However, TrueUSD subsequently tweeted that "we have zero …

Cryptocurrency

Tweet thread by PeckShield

2023-10-11 [vendor] Black Hole Token [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The Black Hole Token project suffered a $1.28 million apparent exploit, according to security firm PeckShield, though it's hard not to wonder if it might have been a rug pull.Black …

Cryptocurrency

"Lucky Star Currency, FSL"

2023-10-10 [vendor] FSL [loss] $2M [chain] bsc
Vector: Exit scam / rug pull

The BNB Chain-based FSL token rug pulled within 24 hours of launching, with developers draining $1.68 million of liquidity they had amassed. Total loss estimated at $1,680,000.

Cryptocurrency

Tweet by BigWhale

2023-10-03 [vendor] BigWhale [loss] $2M [chain] bsc
Vector: Private key compromise

The defi staking and lending project BigWhale announced that the private key to one of their crypto wallets had been leaked, and 7,200 BNB (~$1.5 million) had been stolen.In a long …

Ransomware

CISA Advisory AA23-325A / Computer Weekly / Help Net Security

2023-10-01 [vendor] Citrix NetScaler ADC / NetScaler Gateway [malware] LockBit 3.0 [cve] CVE-2023-4966
Vector: CWE-200: Exposure of Sensitive Information (Citrix Bleed - memory disclosure of valid session tokens enabling auth bypass)

LockBit 3.0 affiliates exploited Citrix Bleed (CVE-2023-4966) to breach Boeing Distribution Inc. (parts and distribution business). Session token extraction from Citrix NetScaler …

Supply chain [SC]

Arietis Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

RCM Company Reports Data Breach Tied to MOVEit Software, 1.9M Impacted | TechTarget. The revenue cycle management company reported a data breach that impacted more than 1.9 million …

Supply chain [SC]

Cook County Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Perry Johnson & Associates, Inc., (PJ&A)
Vector: Compromise of third-party service provider / vendor relationship

Cook County Health Patients Affected by Cyberattack at Medical Transcription Firm. Cook County Health, which operates John H. Stroger, Jr. Hospital and Provident Hospital in …

Supply chain [SC]

Humana Inc. Third-Party Breach (October 2023)

2023-10-01 [vendor] PNC Bank
Vector: Compromise of third-party service provider / vendor relationship

Cyberattacks Reported by Brooklyn Premier Orthopedics & Atlas Healthcare. Brooklyn Premier Orthopedics (BPO) in New York has confirmed the protected health information of 48,459 …

Supply chain [SC]

SA Health Third-Party Breach (October 2023)

2023-10-01 [vendor] Personify Care
Vector: Compromise of third-party service provider / vendor relationship

SA patient health info deleted in third-party app breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …

Supply chain [SC]

Sony Third-Party Breach (October 2023)

2023-10-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Sony confirms data breach impacting thousands in the U.S.. Sony Interactive Entertainment (Sony) has notified current and former employees and their family members about a …

Supply chain [SC]

Super SA Third-Party Breach (October 2023)

2023-10-01 [vendor] Former external service provider
Vector: Compromise of third-party service provider / vendor relationship

Super SA discloses third-party data breach. [](https://www.linkedin.com/company/itnews "follow us on Linkedin")[](https://twitter.com/itnews_au "follow us on …

Cloud

Mercedes-Benz GitHub Token Exposure — Source Code Repository Access

2023-09-29 [vendor] Mercedes-Benz GitHub Enterprise organization / source code repositories
Vector: A Mercedes-Benz employee inadvertently included a GitHub API token in a public GitHub repository; the token provided unrestricted read access (with no expiration date) to the entire Mercedes-Benz Enterprise GitHub organization, allowing access to all private repositories

In January 2024 (revealed for an exposure dating to September 2023), RedHunt Labs security researchers discovered that a GitHub API authentication token belonging to a …

Cloud

Okta October 2023 Support System Breach — All Customer Support Users Affected

2023-09-28 [vendor] Okta Customer Support System (Salesforce Service Cloud)
Vector: Attacker used a stolen credential to access Okta's customer support case management system (Salesforce Service Cloud); the credential was compromised because an Okta employee had signed into their personal Google account on a work device, and the credential was stored in the personal Google account which was later breached

On 28 September 2023, an attacker used a stolen service account credential to gain access to Okta's customer support case management system. The attacker downloaded a report …

Cloud

Okta Security / BeyondTrust / BleepingComputer

2023-09-28 [vendor] Okta Customer Support System
Vector: CWE-522: Insufficiently Protected Credentials (employee personal Google account compromise exposing corporate credentials)

Threat actor accessed Okta customer support case management system Sept 28 - Oct 17 2023 using credentials stolen from an employee's personal Google account. 134 Okta customers …

Ransomware

Johnson Controls International Ransomware — 27TB Data, $27M Impact, Physical Security Plans

2023-09-25 [vendor] Johnson Controls International plc IT infrastructure [malware] Dark Angels ransomware
Vector: Dark Angels ransomware group gained access to Johnson Controls' internal network via a compromised subsidiary (Asia-Pacific offices); established persistent access and exfiltrated approximately 27TB of data before deploying ransomware

On 25 September 2023, Johnson Controls International — a global conglomerate manufacturing building automation systems, HVAC systems, fire safety systems, and physical security …

Data leak

Tweet by Definalist

2023-09-24 [vendor] Upbit Aptos transaction spoofing
Vector: Smart contract exploit / hack

Upbit, a major South Korean cryptocurrency exchange, suddenly suspended deposits and withdrawals of the Aptos $APT token after some users were able to deposit and withdraw fake …

Cryptocurrency

Tweet thread by Justin Sun

2023-09-24 [vendor] Huobi exchange [chain] ethereum
Vector: Smart contract exploit / hack

Justin Sun confirmed on September 25 that his crypto exchange Huobi (recently rebranded to "HTX") had been hacked for 5,000 ETH ($8 million) the prior day. He reassured customers …

Data leak

Tweet by Mixin Kernel

2023-09-23 [vendor] Mixin Network [loss] $200M
Vector: Smart contract exploit / hack

The operators of the Mixin Network disclosed that hackers had stolen around $200 million in funds in the largest known hack of the year (to date). Mixin Network is a cross-chain …

Data leak

"Gone Phishing"

2023-09-20 [vendor] 0x5e422 phishing attack [loss] $4M
Vector: Phishing attack

Someone lost over $4.4 million of the Tether stablecoin after falling victim to a phishing scam that promised them fake mining rewards. A phisher lured in the victim, likely …

Cryptocurrency

Tweet by Balancer

2023-09-19 [vendor] Balancer frontend compromise [loss] $237,932 [chain] ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

Balancer issued an urgent warning to stop using its web interface, as it was evidently compromised by malicious actors who redirected the funds to themselves. Within 30 minutes of …

Cryptocurrency

SEC order

2023-09-13 [vendor] SEC charges Stoner Cats NFT project [chain] ethereum
Vector: Regulatory / legal action

In a rather amusing press release, the SEC announced they had charged "Stoner Cats 2 LLC" with conducting an unregistered securities offering when they raised $8.2 million selling …

Data leak

Tweet by CoinEx

2023-09-12 [vendor] CoinEx [loss] $70M
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Various blockchain watchers noticed suspicious transfers from a hot wallet known to belong to the CoinEx cryptocurrency exchange. CoinEx later confirmed a "security incident" …

Data leak

Tweet thread by Fortress Trust

2023-09-11 [vendor] Fortress Trust [loss] $15M
Vector: Social engineering attack

Fortress Trust is a crypto custody and blockchain infrastructure company, founded by Scott Purcell. Purcell is also known for founding Prime Trust, which later lost over $75 …

Cryptocurrency

Tweet by Banana Gun

2023-09-11 [vendor] Banana Gun bot flubbed token launch [chain] ethereum
Vector: Exit scam / rug pull

The team behind Banana Gun, a Telegram bot to help "snipe" token launches, launched a token associated with the project on September 11. Only hours later, they announced in a tweet …

Cryptocurrency

Tweet by Charlotte Fang

2023-09-11 [vendor] Remilia theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A developer working on an NFT project spearheaded by Remilia, the DAO behind the Milady NFT project, stole around $1 million from the group by diverting fees generated by their new …

Cryptocurrency

Bitcoin transaction

2023-09-10 [vendor] Paxos fee overpayment [chain] bitcoin
Vector: Software bug / unintentional loss

A wallet on the Bitcoin blockchain paid a 19.82 BTC ($499,171) fee to transfer 0.074 BTC ($1,865). Put another way, they spent 270x the transaction value to pay the fee. Bitcoin …

Cryptocurrency

Attacker wallet

2023-09-09 [vendor] Vitalik Buterin's Twitter account [loss] $691,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Twitter account belonging to Vitalik Buterin, inventor and effective leader of the Ethereum project, was hacked to promote a crypto scam. A tweet posted to his compromised …

Cloud

BleepingComputer / Morphisec / CSHub

2023-09-08 [vendor] MGM Resorts enterprise systems / Okta / VMware ESXi [malware] ALPHV/BlackCat
Vector: CWE-1391: Use of Weak Credentials (social engineering via LinkedIn identity theft + vishing helpdesk to bypass Okta MFA)

Scattered Spider (UNC3944) used LinkedIn to identify MGM employee, called IT helpdesk impersonating them to get Okta/Azure admin access. Waited 2 days then launched ransomware …

Cryptocurrency

Tweet thread by ScamSniffer

2023-09-06 [vendor] 0x13e38 phished [loss] $24M [chain] ethereum
Vector: Phishing attack

A crypto phisher hit it big today when they lured in a victim with a massive wallet balance. The victim wallet was drained of 4,851 rETH and 9,579 stETH, both wrapped versions of …

Cryptocurrency

Tweets by PeckShield

2023-09-05 [vendor] GMBL.COMPUTER [loss] $770,000 [chain] ethereum
Vector: Smart contract exploit / hack

The brand new Arbitrum-based defi casino GMBL.COMPUTER was exploited for around 471 ETH (~$770,000). The project, which promises to "generate yield from casino games", had …

Cryptocurrency

Tweet by zachxbt

2023-09-04 [vendor] Stake [loss] $41M [chain] bsc, polygon, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

Attackers managed to make transactions from hot wallets operated by the Stake betting platform, stealing approximately $15.7 million from their Ethereum wallet and around $25.6 …

Supply chain [SC]

890 Schools Third-Party Breach (September 2023)

2023-09-01 [vendor] National Student Clearinghouse (NSC)
Vector: Compromise of third-party service provider / vendor relationship

National Student Clearinghouse data breach impacts 890 schools. U.S. educational nonprofit National Student Clearinghouse has disclosed a data breach affecting 890 schools using …

Supply chain [SC]

Airbus Third-Party Breach (September 2023)

2023-09-01 [vendor] Turkish Airlines
Vector: Compromise of third-party service provider / vendor relationship

Airbus investigates data leak allegedly involving thousands of suppliers. The European aerospace giant Airbus said on Tuesday that it is investigating a cybersecurity incident …

Supply chain [SC]

Amerita Third-Party Breach (September 2023)

2023-09-01 [vendor] PharMerica
Vector: Compromise of third-party service provider / vendor relationship

Amerita Notifies Nearly 220K of PharMerica Data Breach | TechTarget. MedMinder Systems and PurFoods also reported healthcare data breaches recently. Amerita, a specialty infusion …

Supply chain [SC]

BORN Ontario Third-Party Breach (September 2023)

2023-09-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

SickKids impacted by BORN Ontario data breach that hit 3.4 million. The Hospital for Sick Children, more commonly known as SickKids, is among healthcare providers that were …

Supply chain [SC]

FTX Third-Party Breach (September 2023)

2023-09-01 [vendor] Kroll Inc.
Vector: Compromise of third-party service provider / vendor relationship

Kroll data breach exposes info of FTX, BlockFi, Genesis creditors. Multiple reports on social media warn of a data breach at financial and risk advisory company Kroll that resulted …

Other

<i>Schiermeyer v. Thurston</i>

2023-08-31 [vendor] Gala Games lawsuits
Vector: Regulatory / legal action

The two co-founders of blockchain gaming company Gala Games are suing each other. One lawsuit, filed by Gala Games CEO Eric Schiermeyer, alleges that Gala's director Wright …

Other

Tweet by belgio

2023-08-30 [vendor] Starknet upgrade leaves $550,000 inaccessible

"The wallets that did not upgrade in time will lose their assets," a StarkWare customer support representative said on Discord to an individual inquiring why they could no longer …

Cryptocurrency

Tweet by Balancer

2023-08-27 [vendor] Balancer [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

After warning users several days prior that a critical vulnerability had been discovered in their protocol, the Balancer defi project has been drained of around more than $2.1 …

Cryptocurrency

Tweet thread by Nick Garfield

2023-08-27 [vendor] Clockwork project to [chain] solana
Vector: Protocol collapse / insolvency

A year after raising $4 million in a seed round joined by Multicoin Capital, Solana Ventures, and Asymmetric, Clockwork co-founder Nick Garfield announced that the Solana-based …

Other

Retool MFA Bypass via Google Authenticator Cloud Sync Phishing

2023-08-27 [vendor] Google Authenticator (cloud sync feature); Okta
Vector: Attacker used spear phishing SMS (smishing) to social engineer a Retool employee into providing credentials and a Google Authenticator TOTP code, then used the synced OTP tokens from Google Account cloud sync (newly enabled feature) to bypass MFA and access Retool's Okta admin, then Google Workspace and internal systems

On August 27, 2023, a Retool employee received a convincing smishing (SMS phishing) message claiming to be from Retool IT support regarding a benefits enrollment issue requiring …

Cryptocurrency

Tweet thread by zachxbt

2023-08-25 [vendor] Magnate Finance [loss] $5M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Magnate Finance, a lending protocol built on the new Base layer-2 blockchain, rug pulled within hours of a warning from crypto sleuth zachxbt. Zachxbt had discovered that a wallet …

Cryptocurrency

Tweet thread by SOLBigBrain

2023-08-25 [vendor] SOL Big Brain phishing attack [loss] $1M [chain] ethereum
Vector: Phishing attack

The NFT collector SOL Big Brain lost around $1.5 million in ETH, stablecoins, and the Gearbox token after being targeted in a phishing scam. The attacker apparently compromised a …

Cryptocurrency

Tweet thread by ScamSniffer

2023-08-21 [vendor] Celer Bridge Google Ad phishing [loss] $900,000 [chain] ethereum
Vector: Phishing attack

Google Ad phishing is the practice of taking out a Google advertisement to promote a malicious website impersonating a legitimate project. By taking out the ad, the result is …

Data leak

Tweet thread by Harbor Protocol

2023-08-19 [vendor] Harbor Protocol
Vector: Smart contract exploit / hack

The "interchain stablecoin protocol" Harbor announced on August 19 that they had experienced an exploit that drained some of the funds in the project pools. They wrote on Twitter …

Cloud

Cybersecurity Dive / Chainalysis / McGriff

2023-08-18 [vendor] Caesars Entertainment loyalty program database / Okta [malware] Scattered Spider ransomware
Vector: CWE-1390: Weak Authentication (vishing / voice phishing social engineering of outsourced IT vendor to bypass Okta MFA)

Scattered Spider targeted Caesars' outsourced IT support vendor Aug 18 2023 via voice phishing, convincing vendor to hand over Okta credentials. Within days accessed 6TB loyalty …

Other

<i>Glow Token v. Crypto.com</i>

2023-08-18 [vendor] Crypto founder [loss] $273,000

Bryan Lawrence, the leader of a crypto project called Glow Token, recently shared that he'd fallen victim to scammers impersonating employees of the Crypto.com exchange. Lawrence …

Data leak

Slim CD Payment Gateway Breach

2023-08-17 [vendor] Slim CD (payment gateway)
Vector: Unauthorized access to payment gateway systems; attackers maintained persistent access from August 2023 through June 2024 before exfiltrating credit card data in a final two-day window

Payment gateway provider Slim CD disclosed that attackers had access to its systems from 17 August 2023, with credit card data specifically accessed 14-15 June 2024 before …

Cryptocurrency

Tweet thread by PeckShield

2023-08-16 [vendor] SwirlLend [loss] $460,000 [chain] ethereum

Despite the fact that Coinbase's Base blockchain was only officially launched a week ago, and a relatively small amount of funds are locked on the chain, it's already racking up …

Cryptocurrency

Tweet by PeckShield

2023-08-14 [vendor] RocketSwap [loss] $857,257 [chain] ethereum
Vector: Smart contract exploit / hack

Exploiters stole around 471 ETH (~$857,000) from the RocketSwap project on the Base Ethereum layer-2 blockchain. According to RocketSwap, the project had stored private keys on a …

Cryptocurrency

Tweet by Hayden Adams

2023-08-12 [vendor] FrensTech [loss] $25,900 [chain] ethereum
Vector: Exit scam / rug pull

After pulling off a rug pull that only netted 14 ETH (~$25,900), Allen Lin (known as AzFlin) lost his day job for the company that maintains the Uniswap DEX. Hope it was worth …

Ransomware

Clorox Cyberattack — $356 Million Business Impact, Production Disruption

2023-08-11 [vendor] Clorox Company IT infrastructure [malware] ALPHV/BlackCat ransomware
Vector: ALPHV/BlackCat ransomware affiliates (Scattered Spider) gained access to Clorox's network; the attack used the same social engineering techniques deployed against MGM and Caesars — helpdesk vishing and MFA fatigue to impersonate employees and gain network access

On 11 August 2023, Clorox Company — one of the world's largest consumer goods manufacturers (Clorox, Hidden Valley, Burt's Bees, Kingsford charcoal) — detected a cyberattack and …

Ransomware

Rapattoni MLS Software Ransomware Attack

2023-08-09 [vendor] Rapattoni MLS-as-a-Service
Vector: Ransomware attack on Rapattoni Corp. cloud infrastructure hosting MLS software as a service; initial vector not publicly disclosed

Ransomware hit Rapattoni Corp. (California-based MLS software provider serving ~100 MLSs and approximately 5% of US MLSs) on 9 August 2023. The attack froze MLS systems used by …

Data leak

Milksad.info

2023-08-09 [vendor] Libbitcoin vulnerability [loss] $900,000
Vector: Software bug / unintentional loss

A team of researchers led by the Distrust security research firm have disclosed a vulnerability they've called "Milksad". The popular Libbitcoin project was used by multiple …

Cryptocurrency

"April 2023 Exploit Response Vote"

2023-08-09 [vendor] Hundred Finance [chain] ethereum
Vector: Protocol collapse / insolvency

Hundred Finance is a lending protocol that was exploited in April 2023 for around $7 million, and in March for over $6 million. Since then, they've worked with law enforcement and …

Cryptocurrency

Tweet by FTM Ecologist

2023-08-09 [vendor] SpiritSwap to [chain] fantom
Vector: Protocol collapse / insolvency

SpiritSwap announced on its Discord that the project will be shutting down on September 1 unless they can find a new team to take over the project by that time. SpiritSwap lost …

Cryptocurrency

Tweet by Pau Bonet

2023-08-08 [vendor] Scammers target victims via web3 job search boards [loss] $1,172 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Scammers are constantly coming up with creative new ways to pull off their scams, and the latest seems to be targeting web3-interested individuals via dedicated web3 jobs portals. …

Supply chain [SC]

Dollar Tree/Family Dollar — Zeroed-In Technologies Breach (1.98M)

2023-08-07 [vendor] Zeroed-In Technologies HR analytics platform
Vector: Zeroed-In Technologies, an HR analytics vendor used by Dollar Tree and Family Dollar, suffered a data breach affecting its systems — attackers accessed systems and stole employee data; Dollar Tree and its subsidiary Family Dollar were downstream victims

Dollar Tree and its subsidiary Family Dollar disclosed in November 2023 that Zeroed-In Technologies, a third-party HR analytics vendor they used, suffered a data breach between …

Cryptocurrency

Tweet by Spreek

2023-08-07 [vendor] Steadefi [loss] $1M [chain] ethereum
Vector: Private key compromise

"NOTICE: Steadefi has been exploited and all funds are currently at risk," wrote Steadefi on Twitter after an attacker was able to change the contract owner to their own address — …

Cryptocurrency

Tweet by PeckShield

2023-08-02 [vendor] Uwerx [loss] $324,000 [chain] ethereum
Vector: Flash loan attack on smart contract

Uwerx is a nascent project intending to build a blockchain-based freelancer marketplace, because what better concepts to combine than blockchains and the gig economy? Sadly for …

Supply chain [SC]

Zillow Third-Party Breach (August 2023)

2023-08-01 [vendor] Rapattoni Corporation
Vector: Compromise of third-party service provider / vendor relationship

Ransomware Hit Disrupts Real Estate Property Listings in US. Property listings nationwide are being disrupted due to an apparent ransomware attack against California-based …

Cryptocurrency

Tweet thread by SlowMist

2023-08-01 [vendor] LeetSwap [loss] $624,000 [chain] ethereum
Vector: Smart contract exploit / hack

Although Coinbase's Base blockchain is at this stage intended for testing only, people have begun bridging substantial assets to the platform and using various services in …

Other

"SEC Charges Hex Founder Richard Heart with Misappropriating Millions of Dollars of Investor Funds from Unregistered Crypto Asset Securities Offerings that Raised more than $1 Billion"

2023-07-31 [vendor] SEC goes after Richard Heart and his projects Hex, PulseChain, and PulseX
Vector: Regulatory / legal action

The SEC filed charges against Richard Heart, the operator of Hex, PulseChain, and PulseX. Despite Heart's best attempts at evading securities laws — including by asking people to …

Cryptocurrency

Tweet by Chaofan Shou

2023-07-30 [vendor] Vyper vulnerability affecting Curve [loss] $36M [chain] ethereum
Vector: Smart contract exploit / hack

Some types of Curve factory pools, including one operated by AlchemixFi and one by JPEG'd, were exploited. The attack stemmed from an issue in the Vyper language, a smart contract …

Data leak

Tweet by YazanXBT

2023-07-28 [vendor] Pond0x bug [loss] $2M
Vector: Exit scam / rug pull

Traders hoping to get in on the next big memecoin eagerly snapped up a token called Pond0x, a Pepe the Frog-branded memecoin launched by Pauly0x. Pauly0x is Jeremy Cahen, a crypto …

Cryptocurrency

"DeFiLabs"

2023-07-27 [vendor] DeFiLabs [loss] $2M [chain] bsc
Vector: Exit scam / rug pull

A defi project called DeFiLabs was able to rug pull for $1.6 million thanks to a backdoor written into the smart contract. After traders bought into the project, its creator was …

Cryptocurrency

Tweet by Jameson Lopp

2023-07-25 [vendor] CoinsPaid [loss] $37M [chain] bitcoin
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The CoinsPaid crypto payment platform, which provides payment services to various online casinos, reportedly suspended withdrawals under mysterious circumstances. The company later …

Cryptocurrency

Tweet thread by EraLend

2023-07-25 [vendor] EraLend [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

The EraLend crypto lending platform was exploited for around $3.4 million after an attacker took advantage of a re-entrancy vulnerability to manipulate token prices and drain funds …

Cryptocurrency

Tweet thread by Conic Finance

2023-07-21 [vendor] Conic Finance [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

A re-entrancy vulnerability in the Conic Finance defi project enabled an attacker to steal 1,700 ETH (~$3.22 million) from the project's ETH pool.Conic Finance announced that they …

Other

Tweet by Spreekaway

2023-07-21 [vendor] Party Parrot treasury distribution

You almost have to hand it to the Party Parrot team, they really figured out how to take advantage of ostensibly "decentralized" governance to line their own pockets. After raising …

Cryptocurrency

Tweet thread by Beosin Alert

2023-07-18 [vendor] GMETA [loss] $4M [chain] bsc

The GMETA project on BNB Chain saw its price plummet to near zero as the project creators drained the funds from the project. The contract creator was able to transfer large …

Data leak

Tweet thread by zachxbt

2023-07-17 [vendor] Scammer "Soup" makes more than $1 million through Discord [loss] $1M
Vector: On-chain theft (attributed by zachxbt)

A Canadian named Dan, who goes by "Soup" online, made more than $1 million through various phishing scams targeting Discord projects including those belonging to the Pika Protocol …

Cryptocurrency

Tweet thread by Geist Finance

2023-07-14 [vendor] Geist Finance [chain] ethereum, fantom
Vector: Protocol collapse / insolvency

Defi lending project Geist Finance announced they would be shutting down after more than $200 million was drained from the Multichain project in two separate events in early July. …

Other

Tweet thread by Multichain

2023-07-14 [vendor] Multichain finally confirms their CEO was arrested in China
Vector: Regulatory / legal action

After a months-long saga involving "stuck" transactions, Multichain announcing they couldn't get in contact with their CEO, rumors that the whole team was arrested, and several …

Other

<i>United States v. Mashinksy</i>

2023-07-13 [vendor] Celsius lawsuits, CEO arrest
Vector: Ponzi / pyramid scheme

A multi-agency hammer came down on the bankrupt cryptocurrency lender and alleged Ponzi scheme that was Celsius. The co-founder and former CEO of the company, Alex Mashinsky, was …

Other

<i>CFTC v. Todd</i>

2023-07-12 [vendor] Digitex
Vector: Regulatory / legal action

Adam Todd, the CEO of the Digitex Futures exchange, has been ordered to pay $3.9 million in disgorgement and $11.7 million in penalties. The Commodity Futures Trading Commission …

Cryptocurrency

"OptyFi Project Update"

2023-07-11 [vendor] OptyFi [chain] ethereum
Vector: AI-assisted attack or AI-generated exploit

OptyFi, a so-called "AI-powered defi" project, announced it would be shutting down for a variety of reasons. First, they blamed their recent failed token sale, in which they had …

Cryptocurrency

Tweet by PeckShield

2023-07-11 [vendor] Platypus Finance [loss] $157,000 [chain] avalanche
Vector: Flash loan attack on smart contract

Platypus Finance paused their pools after they were alerted to what they described as "suspicious activities". Security firm PeckShield was apparently the first to notice the …

Data leak

Tweet thread by spreekaway

2023-07-10 [vendor] Multichain theft #3 [loss] $107M
Vector: Smart contract exploit / hack

Only five days after $130 million was emptied from the Multichain blockchain bridge, another $107 million in a wide range of assets has been taken. After the first theft, …

Other

Tweet thread by m4gicpotato

2023-07-10 [vendor] Arkham Intelligence referral program exposes user emails

In a somewhat amusing complement to Arkham Intelligence's "on-chain intelligence exchange" announcement, a new product which seeks to allow people to buy and sell private …

Cryptocurrency

Tweet by BarnBridge

2023-07-06 [vendor] "Decentralized" BarnBridge closes up shop after claiming they are under SEC investigation [chain] ethereum
Vector: Regulatory / legal action

A small and rather unknown project called BarnBridge aimed to build a variety of defi yield projects. BarnBridge claimed to be decentralized and governed by a DAO. On July 6, an …

Cryptocurrency

Tweet by nftperp.xyz

2023-07-06 [vendor] NFTPerp blows up [chain] ethereum

A project called NFTPerp was, as the name suggests, a perpetual futures exchange for NFTs, allowing people to take long or short positions against NFTs. It relied on a vAMM — …

Data leak

HCA Healthcare Data Breach — 11 Million Patients, Dark Web Sale

2023-07-05 [vendor] HCA Healthcare external patient email automation storage system
Vector: Data was stolen from an external storage location used by HCA Healthcare for email formatting — a tool used to format automated emails to patients; the external storage location was accessed without authorization

On 5 July 2023, a threat actor posted for sale on an online forum a database purporting to contain approximately 27.7 million records from HCA Healthcare — the largest US …

Cryptocurrency

Tweet thread by LoveMake.eth

2023-07-03 [vendor] LoveMake.eth wallet drain [loss] $213,000 [chain] ethereum
Vector: Phishing attack

Crypto personality LoveMake.eth wrote a Twitter thread about how they fell victim to a phishing scam in which an account appearing to belong to the cofounder of the popular Doodles …

Data leak

Dymocks Booksellers Data Breach — 836,000 Australian Customers

2023-07-01 [vendor] Dymocks Booksellers customer database
Vector: Unknown attacker exfiltrated a database containing customer records from Dymocks Booksellers; Troy Hunt of Have I Been Pwned was alerted to the breach by a third party who shared the data with him before Dymocks was aware

In September 2023, Dymocks Booksellers — Australia's largest book retailer operating approximately 65 stores — disclosed a data breach affecting approximately 836,000 customers. …

Supply chain [SC]

Postbank Third-Party Breach (July 2023)

2023-07-01 [vendor] Majorel
Vector: Compromise of third-party service provider / vendor relationship

Datenleck bei Postbank und Deutscher Bank / Kriminelle kopieren Bankdaten. Lahr (ots) - Hacker haben Daten von Kunden der Deutschen Bank bei einem Datenleck gestohlen. Auch die …

Cryptocurrency

Tweet thread by Cardinal Labs

2023-06-28 [vendor] Cardinal Labs [chain] solana
Vector: Protocol collapse / insolvency

A little less than a year after raising $4.4 million in seed funding to build a Solana NFT protocol that allowed for NFT rentals and other such things, Cardinal Labs has announced …

Cryptocurrency

Tweet by PeckShield

2023-06-27 [vendor] Themis Protocol [loss] $368,000 [chain] ethereum
Vector: Flash loan attack on smart contract

Themis Protocol is a lending platform that has had somewhat of an excruciating rollout, with users waiting ever longer for the platform to finally go live as they endured …

Other

Order to cease and desist

2023-06-22 [vendor] Prime Trust
Vector: Regulatory / legal action

The Nevada Financial Institutions Division issued a cease and desist to the Prime Trust crypto custodian. Earlier in the month, the apparently embattled Prime Trust signed a …

Cryptocurrency

Tweet by Elena

2023-06-21 [vendor] Elena stolen art [chain] bitcoin

Web3 influencer Elena announced she would be launching an NFT collection titled "Atomic Ordinals", which would be inscribed on the Bitcoin blockchain. She claimed that the 200 …

Other

Tweet thread by zachxbt

2023-06-16 [vendor] Machi Big Brother sues zachxbt
Vector: On-chain theft (attributed by zachxbt)

Crypto personality and creator of C.R.E.A.M. Finance Jeffrey Huang, aka "Machi Big Brother", has filed a defamation lawsuit against crypto sleuth zachxbt. Huang alleges that …

Other

Tweets by Wyre

2023-06-16 [vendor] Wyre finally
Vector: Protocol collapse / insolvency

The crypto payments platform Wyre finally announced they would be winding down "due to market conditions". This came after a January announcement from the CEO, where it was not …

Other

Abra cease and desist

2023-06-15 [vendor] Abra insolvency
Vector: Regulatory / legal action

In an emergency cease-and-desist issued on June 15, the Texas State Securities Board alleged that the Abra crypto lending firm was "insolvent or nearly insolvent" as of interviews …

Other

"출금 중지 조치 안내"

2023-06-14 [vendor] Delio suspends withdrawals
Vector: Withdrawal halt / insolvency

South Korean cryptocurrency lending platform Delio announced to its customers on June 14 that they would be suspending withdrawals. In a letter to customers, they wrote that the …

Other

Bankruptcy petition

2023-06-13 [vendor] Banq bankruptcy
Vector: Protocol collapse / insolvency

Banq, a subsidiary of the Prime Trust crypto custodian, has filed for bankruptcy. Banq is a "crypto-friendly" payment processor based in Nevada, though according to the bankruptcy …

Other

Order on Motion for Default Judgment

2023-06-09 [vendor] CFTC awarded summary judgment in case against Ooki DAO
Vector: Regulatory / legal action

Ooki DAO was sued in September of last year for allowing illegal trading of digital assets, engaging in activities only allowed by registered futures commission merchants, and not …

Cryptocurrency

Tweet by zachxbt

2023-06-06 [vendor] Binance Discord compromise [chain] bsc
Vector: On-chain theft (attributed by zachxbt)

Adding insult to injury in Binance's tough couple of days, someone has managed to hijack the Discord vanity URL used by BNB Chain, the blockchain project associated with Binance. …

Cryptocurrency

<i>SEC v. Binance</i>

2023-06-05 [vendor] SEC files complaint against Binance [chain] bsc, polygon, solana, cosmos, cardano
Vector: Regulatory / legal action

The SEC has filed a complaint against Binance, various related companies, and Binance CEO Changpeng "CZ" Zhao. They allege that the company has been acting with "blatant disregard" …

Supply chain [SC]

CoxHealth Third-Party Breach (June 2023)

2023-06-01 [vendor] Intellihartx LLC
Vector: Compromise of third-party service provider / vendor relationship

UPMC contractor detects patient data breach. A contractor for UPMC said it discovered a data breach that could have impacted customer and patient information. Tennessee-based …

Supply chain [SC]

DHL Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Extreme Networks emerges as victim of Clop MOVEit attack | Computer Weekly. Network equipment and services supplier Extreme Networks has revealed its instance of Progress …

Supply chain [SC]

Dublin Airport Third-Party Breach (June 2023)

2023-06-01 [vendor] Aon
Vector: Compromise of third-party service provider / vendor relationship

Dublin Airport staff pay data hit by criminals. Attackers accessed it via third-party services provider, says management group. It's an awkward Monday for Dublin Airport after pay …

Supply chain [SC]

Exeter Finance Third-Party Breach (June 2023)

2023-06-01 [vendor] NCB Management Services, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Capital One becomes latest bank affected by cyberattack on debt-buying giant. The initial response to the incident focused on former customers of Bank of America, but Capital One …

Supply chain [SC]

Majorel Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

MOVEit attack on Aon exposed data of the staff at the Dublin Airport. [](https://www.facebook.com/sec.affairs/)[](https://twitter.com/securityaffairs). UAT-10362 linked to …

Supply chain [SC]

Southwest Airlines Third-Party Breach (June 2023)

2023-06-01 [vendor] Pilot Credentials
Vector: Compromise of third-party service provider / vendor relationship

American Airlines, Southwest Airlines disclose data breaches affecting pilots. American Airlines and Southwest Airlines, two of the largest airlines in the world, disclosed data …

Supply chain [SC]

TJ Maxx Third-Party Breach (June 2023)

2023-06-01 [vendor] Ipswitch, Inc.
Vector: Compromise of third-party service provider / vendor relationship

media-center press-releases 2023 07 14 hillsborough-notifies-residents-vendors-of-global-data-breach. Skip to main content Enable accessibility for low vision Open the …

Cryptocurrency

Tweet by unshETH

2023-06-01 [vendor] unshETH [loss] $375,000 [chain] ethereum
Vector: Smart contract exploit / hack

After a developer leaked private keys to GitHub, someone used them to drain $375,000 from the unshETH defi project. The project emergency paused withdrawals of unshETH ether to …

Other

CISA

2023-06-01 [vendor] Consumer and SOHO routers, IP cameras, DVRs (multiple vendors) [malware] Flax Typhoon botnet (Raptor Train)
Vector: CWE-1188: Insecure Default Initialization of Resource (compromised SOHO routers and IoT devices with default/weak credentials)

In September 2024, the FBI and CISA announced the disruption of a botnet operated by Flax Typhoon, a Chinese state-sponsored threat actor (also tracked as RedJuliett/Ethereal …

Other

Tweet thread by Wu Blockchain

2023-05-31 [vendor] Binance reportedly begins layoffs

Crypto giant Binance has reportedly begun layoffs, according to independent crypto reporter Colin Wu, who cited several anonymous sources. The layoffs will amount to around 20% of …

Cryptocurrency

Tweet thread by zachxbt

2023-05-30 [vendor] Hopeexist1 NFT [loss] $117,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A person claiming to be battling cancer created a "charity NFT project" ostensibly to help with her treatment. She convinced some crypto influencers to promote the project, …

Other

"Notice on Exit from Canadian Market"

2023-05-30 [vendor] Bybit exits Canada
Vector: Regulatory / legal action

The cryptocurrency exchange Bybit announced that they would be exiting Canada. The company cited "recent regulatory development" in the country for their decision to stop offering …

Cryptocurrency

Tweet thread by PeckShield

2023-05-29 [vendor] El Dorado Exchange [chain] ethereum, bsc
Vector: Smart contract exploit / hack

The new Arbitrum-based El Dorado Exchange (EDE) was exploited for around $580,000. In an interesting twist, the attacker claimed to be a whitehat who was exposing that the …

Supply chain [SC]

CISA Advisory AA23-158A / Mandiant / Wikipedia

2023-05-27 [vendor] Progress Software MOVEit Transfer [malware] LEMURLOOT web shell [cve] CVE-2023-34362 +1
Vector: CWE-89: SQL Injection in MOVEit Transfer web application

CL0P ransomware gang exploited a zero-day SQL injection in Progress Software's MOVEit Transfer MFT product starting May 27 2023. Installed LEMURLOOT web shell to steal data. Over …

Supply chain [SC]

Welltok Healthcare SaaS MOVEit Breach — 8.5 Million Patient Records

2023-05-27 [vendor] Welltok MOVEit Transfer / patient health engagement SaaS platform [malware] Cl0p ransomware [cve] CVE-2023-34362
Vector: Cl0p ransomware group exploited CVE-2023-34362 (MOVEit Transfer SQL injection zero-day) against Welltok's MOVEit Transfer server; Welltok used MOVEit Transfer to transfer patient data files on behalf of healthcare clients including major US health plans

Welltok, Inc. — a healthcare SaaS company providing patient health engagement and communication services to major US health plans — was among the largest individual victims of the …

Supply chain [SC]

HIPAA Journal / BleepingComputer / SEC 8-K filing

2023-05-27 [vendor] Progress Software MOVEit Transfer / Maximus government services [malware] LEMURLOOT web shell [cve] CVE-2023-34362
Vector: CWE-89: SQL Injection in MOVEit Transfer web application (zero-day)

Maximus Inc. (US government contractor managing Medicare, Medicaid, student loan programs) was the largest single victim of Cl0p's MOVEit campaign. SEC 8-K filed July 26 2023 …

Cryptocurrency

Tweet thread by Arkham

2023-05-27 [vendor] Malfunctioning MEV bot [loss] $440,000 [chain] ethereum
Vector: MEV / sandwich attack

Some traders hoping to snipe new tokens launched by Poo Finance (yes, really) decided to try to use a MEV bot to snag priority ordering compared to other pending blockchain …

Other

"Unbanked will be winding down"

2023-05-26 [vendor] Unbanked to
Vector: Protocol collapse / insolvency

The US-based crypto payments and custody platform Unbanked announced in a blog post that they will be shutting down services. The company was founded in 2018, and claimed they …

Cryptocurrency

Tweet thread by zachxbt

2023-05-25 [vendor] Steve Aoki Twitter compromise [loss] $170,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Twitter account compromises remain a lucrative way to scam crypto enthusiasts. Someone was able to compromise the Twitter account belonging to electronic musician and crypto …

Data leak

Tweet by zachxbt

2023-05-23 [vendor] Morgan DF Fintoch exit [loss] $32M
Vector: On-chain theft (attributed by zachxbt)

A Ponzi scheme called Morgan DF Fintoch lured consumers by claiming to be owned by the American banking giant Morgan Stanley. Morgan Stanley themselves warned of the scheme, …

Cryptocurrency

Tweet by PeckShieldAlert

2023-05-23 [vendor] CS token [loss] $689,400 [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker exploited the brand new $CS token for almost $700,000 using a flash loan exploit. They then swapped the funds into around 383 ETH ($689,400) and laundered them through …

Cryptocurrency

Etherscan transactions

2023-05-20 [vendor] Tornado Cash DAO governance attack [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A proposal ostensibly to penalize cheating network participants in the Tornado Cash crypto tumbler project successfully passed by DAO vote. However, the proposer had added an extra …

Cryptocurrency

Grumpy Cat cease and desist NFT

2023-05-18 [vendor] Grumpy Cat cease and desist [chain] ethereum

A Grumpy Cat Coin memecoin emerged in May, with a website using illustrations of the late real-life Grumpy Cat to promote the coin. Crypto influencers, including the "SlumDoge …

Cryptocurrency

<i>United States of America v. Nevin Shetty</i>

2023-05-17 [vendor] Fabric CFO funds misappropriation [loss] $35M [chain] terra
Vector: Regulatory / legal action

Nevin Shetty, the former chief financial officer of the Fabric e-commerce platform, was federally indicted for wire fraud after allegedly misappropriating $35 million from Fabric …

Cloud

Storm-0558 Microsoft Exchange Online hack — US State Department and 22 organisations

2023-05-15 [vendor] Microsoft Exchange Online / Microsoft Azure AD (Entra ID)
Vector: CWE-287: Improper Authentication (forged authentication tokens using a stolen Microsoft MSA consumer signing key; used to access Exchange Online accounts across enterprise and personal tenants)

Storm-0558, a Chinese state-sponsored threat actor (attributed to MSS), acquired a Microsoft MSA consumer token signing key (method of acquisition still unclear as of CSRB review) …

Cryptocurrency

Tweet thread by MistTrack

2023-05-15 [vendor] HitBTC phishing website [loss] $15M [chain] ethereum, bitcoin
Vector: Phishing attack

Blockchain security firm SlowMist has reported that a phishing website appearing to be the real cryptocurrency exchange HitBTC has stolen more than $15 million worth of Bitcoin, …

Data leak

Stanford University / Maine AG / BleepingComputer

2023-05-12 [malware] Akira
Vector: CWE-506: Embedded Malicious Code (Akira ransomware targeting Stanford's Department of Public Safety network)

Akira ransomware group breached Stanford University's Department of Public Safety (SUDPS) network between May 12 and September 27 2023. Stanford disclosed the incident on October …

Cryptocurrency

Tweet thread by Andy Chorlian

2023-05-12 [vendor] Fractional NFT ownership platform Tessera [chain] ethereum

If you've found yourself thinking "man, I wish I could buy a hundredth of an NFT", you now have one fewer options. Andy Chorlian, co-founder and CEO of fractional NFT platform …

Other

Tweet by Binance

2023-05-12 [vendor] Binance exits Canada
Vector: Regulatory / legal action

Binance announced they would be exiting Canada, "proactively withdrawing" ahead of stablecoin regulation and crypto investment limits. As is becoming a trend in the industry, …

Cryptocurrency

Tweet by Aragon

2023-05-11 [vendor] Aragon DAO faces governance crisis [chain] ethereum
Vector: Social engineering attack

As the Aragon Association took steps to "progressively decentralize" their centralized project by assigning more control to the Aragon DAO, they encountered some challenges. …

Cryptocurrency

Tweet by Whale Alert

2023-05-07 [vendor] Ethereum user pays more than $100,000 in fees [chain] ethereum

A recent surge in memecoin popularity has caused Ethereum transaction fees to skyrocket. One trader paid the price, eating a 64 ETH ($118,000) transaction fee just to perform a …

Cryptocurrency

Tweet thread by zachxbt

2023-05-03 [vendor] WallStreetBets coin rugpull [loss] $635,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

WallStreetBets is a subreddit that became popular during the pandemic-fueled everyone-should-become-a-daytrader era, and is known for its memestocks and its users who often make …

Supply chain [SC]

Coles Third-Party Breach (May 2023)

2023-05-01 [vendor] Latitude Financial Services
Vector: Compromise of third-party service provider / vendor relationship

Coles confirms its customers impacted by Latitude Financial data breach. Supermarket giant Coles has confirmed it has been impacted by the Latitude Financial data breach, saying …

Supply chain [SC]

Intel Third-Party Breach (May 2023)

2023-05-01 [vendor] Micro Star International (MSI)
Vector: Compromise of third-party service provider / vendor relationship

Intel investigating leak of Intel Boot Guard private keys after MSI breach. Intel is investigating the leak of alleged private keys used by the Intel BootGuard security feature, …

Supply chain [SC]

Iowa Medicaid Third-Party Breach (May 2023)

2023-05-01 [vendor] Telligen, Inc.
Vector: Compromise of third-party service provider / vendor relationship

ILS Data Breach Affects Almost 21K Iowan Medicaid Recipients. The Iowa Department of Health and Human Services (DHHS) has confirmed a HIPAA compliance breach where the personal …

Supply chain [SC]

Kibble Equipment Third-Party Breach (May 2023)

2023-05-01 [vendor] Razor Consulting Solutions
Vector: Compromise of third-party service provider / vendor relationship

Kibble Equipment Data Breach Investigation – Turke & Strauss LLP. Turke & Strauss LLP, a leading data breach law firm, is investigating Kibble Equipment, LLC and its vendors, Razor …

Supply chain [SC]

Paramount Health Care Third-Party Breach (May 2023)

2023-05-01 [vendor] NationsBenefits Holding, LLC
Vector: Compromise of third-party service provider / vendor relationship

IL, KY, and TN Healthcare Orgs Recovering from Recent Cyberattacks. Morris Hospital & Healthcare Centers Investigating Royal Ransomware Attack Morris Hospital & Healthcare Centers …

Supply chain [SC]

VCU Health System Third-Party Breach (May 2023)

2023-05-01 [vendor] Credit Control Corporation
Vector: Compromise of third-party service provider / vendor relationship

Debt Collection Agency Data Breach Affects 345,523 Individuals. R&B Corporation of Virginia, doing business as Credit Control Corporation (CCC), has recently reported a data breach …

Supply chain [SC]

Webster Bank Third-Party Breach (May 2023)

2023-05-01 [vendor] Guardian Analytics, Inc.
Vector: Compromise of third-party service provider / vendor relationship

Webster Bank Reports Third-Party Data Breach at Guardian Analytics, Inc. | JD Supra. On April 10, 2023, Webster Bank filed a notice of data breach with the Maine Attorney General …

Supply chain [SC]

Whitman College Third-Party Breach (May 2023)

2023-05-01 [vendor] Brightline Health
Vector: Compromise of third-party service provider / vendor relationship

Brightline: At Least 964,300 Individuals Affected by Fortra GoAnywhere Hack. Brightline, a provider of virtual behavioral and mental services to families, has confirmed it was …

Cloud [SC]

Discord Third-Party Breach (May 2023)

2023-05-01 [vendor] Zendesk
Vector: Compromise of third-party service provider / vendor relationship

Discord Informs Users of Data Breach Involving Customer Support Provider. This website stores cookies on your computer. These cookies are used to improve your website experience …

Cryptocurrency

Tweet by CZ

2023-05-01 [vendor] CZ smacks down Justin Sun for trying to game SUI airdrop [chain] sui

"Binance LaunchPool are meant as air drops for our retail users, not just for a few whales," tweeted Changpeng "CZ" Zhao, the CEO of Binance, after seeing an alert showing that …

Cryptocurrency

Tweet by Level Finance

2023-05-01 [vendor] Level Finance [loss] $1M [chain] bsc
Vector: Smart contract exploit / hack

The Level Finance decentralized perpetual exchange was exploited after an attacker discovered a vulnerability in one of the project's smart contracts. They were able to drain …

Cryptocurrency

Tweets about "permit phishing" by ScamSniffer

2023-04-30 [vendor] "Permit phishing" [loss] $8M [chain] ethereum
Vector: Smart contract exploit / hack

Between March and April 2023, the Scam Sniffer organization has identified at least $7.7 million stolen by so-called "permit phishers". These attackers convince their victims to …

Credential theft

23andMe Credential Stuffing Data Breach

2023-04-29
Vector: Credential stuffing using username/password pairs stolen from prior unrelated breaches

Beginning April 29, 2023, a threat actor using the alias 'Golem' conducted credential stuffing against 23andMe's login portal over five months, gaining access to ~18,000 customer …

Ransomware

HWL Ebsworth Law Firm ALPHV/BlackCat Ransomware — Australia's Largest Law Firm Breach

2023-04-28 [vendor] HWL Ebsworth law firm internal systems [malware] ALPHV/BlackCat ransomware
Vector: ALPHV/BlackCat ransomware-as-a-service affiliates compromised HWL Ebsworth's network via unknown initial access vector; spent time in the network exfiltrating approximately 4 terabytes of data before being detected

In late April 2023, ALPHV/BlackCat ransomware affiliates breached HWL Ebsworth — one of Australia's largest national law firms with offices in all Australian capital cities and …

Other

"Suspension of activities"

2023-04-27 [vendor] Bit4You suspends activities
Vector: Protocol collapse / insolvency

The only Belgian crypto platform, the Bit4You crypto lender, announced they would be suspending activities after the CoinLoan crypto exchange was ordered to suspend activities …

Cryptocurrency

Tweet by TheMerlinDEX

2023-04-26 [vendor] Merlin theft [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

The brand new Merlin DEX had only just launched on the zkSync Ethereum layer-2, with a public token sale beginning on April 25. The following day, they suddenly asked users to …

Other

Notice of restraint on disposition

2023-04-25 [vendor] CoinLoan suspends withdrawals [loss] $10M
Vector: Withdrawal halt / insolvency

The Estonian crypto exchange CoinLoan announced they were immediately suspending all operations, including withdrawals. The action came after CoinLoan was declared insolvent by an …

Cryptocurrency

Tweet by CertiKAlert

2023-04-24 [vendor] Ordinals Finance [loss] $1M [chain] ethereum, bitcoin

Ordinals Finance was a short-lived project, emerging in late February with promises to help build out a defi ecosystem on the Bitcoin blockchain.On April 24, the project developer …

Cryptocurrency

Tweet thread by 0xQuit

2023-04-21 [vendor] Blur bid acceptance bug [chain] ethereum
Vector: Software bug / unintentional loss

The Blur NFT marketplace appeared to become vulnerable to a bug in which old, canceled bids could still be accepted. This meant that people who had placed bids on NFTs when they …

Data leak

Tweet thread by Tayvano_

2023-04-18 [vendor] Wallet draining operation [loss] $10M
Vector: Smart contract exploit / hack

Crypto researcher Tayvano posted a Twitter thread about a massive, mysterious wallet draining operation that has siphoned more than 5,000 ETH (~$9.88 million at today's prices) as …

Data leak

WebTPA Health Plan Administrator Data Breach

2023-04-18
Vector: Unknown network intrusion; suspicious activity identified April 23, 2023; investigators confirmed unauthorized access April 18–23, 2023

WebTPA, a Texas-based third-party health insurance plan administrator, suffered a data breach discovered in April 2023 but not publicly disclosed until May 2024 — a 13-month delay. …

Cryptocurrency

<i>Krzysztof Gagacki v. Edmond Truong</i>

2023-04-17 [vendor] Rebase co-founders lawsuit [chain] ethereum
Vector: Regulatory / legal action

Krzysztof Gagacki and Edmond Truong are co-founders of Rebase.gg, some sort of augmented reality app where people go hunting for NFTs. They're best known for helping to create a …

Cryptocurrency

Tweet thread by CertiKAlert

2023-04-15 [vendor] Hundred Finance [loss] $7M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to manipulate the exchange rate between tokens and their interest-bearing equivalents on the Hundred Finance system on the Optimism layer-2 network, ultimately …

Cryptocurrency

Post

2023-04-14 [vendor] Bitrue [loss] $23M [chain] ethereum
Vector: Smart contract exploit / hack

The Singapore-based Bitrue crypto exchange suffered a hack on April 14 in which attackers siphoned tokens including Ethereum, Shiba Inu, and MATIC (the token for the Polygon …

Cryptocurrency

Tweet by franklinisbored

2023-04-13 [vendor] Franklin claims to have been [loss] $4M [chain] ethereum
Vector: Exit scam / rug pull

Franklin, aka franklinisbored, has come to be known as one of the most prolific collectors of Bored Apes. At times, he's held more than fifty of the NFTs, and he can often be …

Cryptocurrency

Tweet thread by NicoleBehnam

2023-04-12 [vendor] Nicole Behnam pumps and dumps [loss] $38,000 [chain] ethereum

New passive voice Hall of Fame contender just dropped: "There were mistakes made in a wallet that I controlled." You would think someone who got their start as a writer might know …

Cryptocurrency

Trading Post shutdown announcement

2023-04-10 [vendor] Niantic shutters its web3 project [chain] polygon

Niantic, the creator of the popular Ingress and Pokémon Go augmented reality games, announced it will be shutting down its "Trading Post" product for NFT trading cards that it had …

Cryptocurrency

Tweet by PeckShieldAlert

2023-04-09 [vendor] Trader [loss] $61,000 [chain] ethereum

The former owner of Bored Ape #7810 presumably intended to agree to sell the ape to another buyer for 70 ETH (~$130,900). However, it's unlikely they intended for that buyer to …

Cryptocurrency

Tweet thread by PeckShield

2023-04-08 [vendor] 0xSifu [loss] $3M [chain] ethereum, polygon, avalanche, bsc
Vector: Smart contract exploit / hack

0xSifu, also known as Michael Patryn, also known as Omar Dahani, is the once-pseudonymous chief developer of the Wonderland protocol. His identity was discovered by zachxbt in …

Cryptocurrency

dez.eth

2023-04-07 [vendor] Dez Bryant's Bored Ape stolen [loss] $138,800 [chain] ethereum
Vector: Smart contract exploit / hack

The latest ape escape has affected Dez Bryant, a former NFL player now turned "web3 innovator". Bryant was the proud owner of Bored Ape #2902, an ape with leopard print skin …

Cryptocurrency

<i>Sphere 3D Corp. v. Gryphon Digital Mining, Inc.</i>

2023-04-07 [vendor] Sphere 3D and Gryphon Digital Mining dispute [loss] $500,000 [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin mining firm Sphere 3D has filed a biting lawsuit against its partner, Gryphon Digital Mining. According to Sphere 3D, Gryphon's CEO was fooled by multiple spoofing attacks …

Cryptocurrency

Tweet by Eden Au

2023-04-06 [vendor] Gemholic gets funds stuck [chain] ethereum

The Gemholic project raised 921 ETH (~$1.7 million) in a token sale only to discover there was no way for them to transfer those funds out of the smart contract. The project is …

Cryptocurrency

Tweet thread by Spreek

2023-04-04 [vendor] Sentiment [loss] $95,000 [chain] ethereum
Vector: Smart contract exploit / hack

The Sentiment liquidity protocol on the Arbitrum blockchain was attacked on April 4 for almost $1 million in various tokens, including wrapped Bitcoin and Ether, and several …

Data leak [SC]

HWL Ebsworth Law Firm — ALPHV/BlackCat Ransomware, Australian Government Data Exposed

2023-04-01 [vendor] HWL Ebsworth (Australian law firm, one of the largest in Australia) [malware] ALPHV/BlackCat ransomware
Vector: ALPHV/BlackCat ransomware group gained access to HWL Ebsworth's network; the group subsequently published 1.1 terabytes of stolen data on its dark web leak site after HWL Ebsworth refused to pay a ransom; the initial access vector was not publicly disclosed

HWL Ebsworth, one of Australia's largest law firms with over 2,500 staff and a significant federal and state government client base, was attacked by the ALPHV/BlackCat ransomware …

Cryptocurrency

Tweet by PeckShield

2023-04-01 [vendor] Allbridge [loss] $573,757 [chain] bsc
Vector: Smart contract exploit / hack

The Allbridge cross-chain bridge project was exploited for around 283,000 BUSD and 291,000 USDT (~$574,000). The thief was able to manipulate a vulnerability in the project's smart …

Other

"Important Message For Bittrex U.S. Customers"

2023-03-31 [vendor] Bittrex crypto exchange to close US operations
Vector: Regulatory / legal action

Bittrex, one of the oldest and largest cryptocurrency exchanges serving US customers, announced that it would be shuttering its US platform. "It's just not economically viable for …

Data leak [SC]

HIPAA Journal

2023-03-27 [vendor] Perry Johnson & Associates (PJ&A) medical transcription platform
Vector: CWE-284: Improper Access Control

Perry Johnson & Associates (PJ&A), a Nevada-based medical transcription services company, was breached between March 27 and May 2, 2023. The breach went undetected for over a …

Cryptocurrency

"Kokomo Finance"

2023-03-26 [vendor] Kokomo Finance [loss] $4M [chain] ethereum
Vector: Phishing attack

The Kokomo Finance project on the Optimism Ethereum layer-2 network rug pulled for $4.5 million in assets. The project positioned itself as a non-custodial lending platform.After …

Cryptocurrency

Tweet thread by NFTstatistics.eth

2023-03-24 [vendor] Collector accidentally burns their $123,000 NFT [chain] ethereum

The new owner of a CryptoPunk, one of the most popular early NFT projects, accidentally burned the NFT they had only just purchased. After spending 77 ETH ($123,434) on the NFT, …

Ransomware

Capita plc Black Basta Ransomware Attack

2023-03-22 [malware] Black Basta ransomware
Vector: Phishing email leading to malware download; threat actor then escalated privileges over 58 hours before deploying ransomware (critical 58-hour delay in quarantining the initially infected device)

Capita, a major UK outsourcing company providing services across government, defence, and pension administration, was hit by Black Basta ransomware on March 31, 2023 (initial …

Ai

OpenAI ChatGPT Redis Bug — Chat History & Payment Info Leak

2023-03-20 [vendor] OpenAI ChatGPT; Redis (redis-py library)
Vector: A bug in the Redis client library (redis-py) used by OpenAI caused race conditions in connection pooling under high load, resulting in users being served cached data from other users' sessions — exposing conversation titles and personal payment information

On March 20, 2023, OpenAI took ChatGPT offline after discovering a bug in its Redis client library (redis-py open-source library) that caused some users to see other users' …

Data leak [SC]

BleepingComputer / SecurityWeek / Security Boulevard

2023-03-16 [vendor] Latitude Financial Services / DXC Technology (service provider)
Vector: CWE-522: Insufficiently Protected Credentials (stolen employee login credentials used to access third-party service providers)

Attacker stole employee credentials and used them to access Latitude Financial's data held by two service providers including DXC Technology. 14 million records affected across …

Supply chain [SC]

Mandiant / Google Cloud Blog / Krebs on Security

2023-03-16 [vendor] 3CX DesktopApp [malware] SUDDENICON downloader / ICONICSTEALER infostealer [cve] CVE-2023-29059
Vector: CWE-506: Embedded Malicious Code (malicious DLL sideloaded into 3CX DesktopApp installer; itself seeded via poisoned Trading Technologies X_TRADER installer)

Lazarus Group (North Korea, subunit Labyrinth Chollima) trojanized 3CX DesktopApp versions 18.12.407 and 18.12.416 for Windows and Mac. Delivered SUDDENICON downloader which …

Other

Tweet thread by Stephane Kasriel

2023-03-13 [vendor] Meta ends support for NFTs

In a Twitter thread, Meta (formerly Facebook) Head of Commerce and Fintech Stephane Kasriel announced that they would be "down digital collectibles (NFTs) for now to focus on other …

Ransomware

PharMerica Pharmacy Network Money Message Ransomware — 5.8 Million Patient Records

2023-03-12 [vendor] PharMerica pharmacy benefits management systems [malware] Money Message ransomware
Vector: Money Message ransomware group gained access to PharMerica's network via unknown initial access vector; the group exfiltrated patient data and deployed ransomware; PharMerica is a major pharmacy benefits management company operating in long-term care facilities

In March 2023, Money Message ransomware attacked PharMerica Corporation — one of the largest pharmacy benefit management companies in the US, providing pharmacy services to …

Cryptocurrency

Thread by PeopleDAO

2023-03-11 [vendor] PeopleDAO theft [loss] $120,000 [chain] ethereum
Vector: Smart contract exploit / hack

PeopleDAO is the successor to ConstitutionDAO, a group that made an ill-fated attempt to buy a copy of the US Constitution in November 2021. When the accounting lead for PeopleDAO …

Cryptocurrency

Tweet by Spreekaway

2023-03-10 [vendor] Kyber bug [loss] $2M [chain] ethereum
Vector: MEV / sandwich attack

Someone tried to swap around 2.03 million 3CRV tokens (priced at around $1.97 million) for stablecoins using the KyberSwap decentralized exchange protocol. However, due to an …

Cryptocurrency

Web3 Is Going Great

2023-03-10 [vendor] USDC [chain] ethereum

The major stablecoin USDC lost its peg to the US dollar on March 10. Earlier that day, the collapse of the Silicon Valley Bank sent shockwaves through the financial system, and …

Other

Tweet by Coinbase

2023-03-10 [vendor] Coinbase

The collapse of the Silicon Valley Bank on March 10 led to concerns over the stability of the stablecoin USDC, after it was revealed that a portion (later specified at $3.3 …

Data leak

Washington D.C. Health Benefit Exchange Breach — 56,000 Legislators and Staff

2023-03-08 [vendor] DC Health Benefit Exchange Authority enrollment system
Vector: Ransomware group (IntelBroker, via BreachForums) exploited a vulnerability in the DC Health Benefit Exchange Authority's (DC HBX) health insurance enrollment system to access and exfiltrate personal data for approximately 56,000 individuals including US lawmakers, their families, and congressional staff

In March 2023, data for approximately 56,415 individuals enrolled in DC Health Link — the health insurance marketplace for Washington D.C. residents including US House of …

Cryptocurrency

"Togg to sell pre-order rights with NFTs"

2023-03-08 [vendor] Togg announces and then cancels NFT presale [chain] avalanche

Turkish electric vehicle startup Togg announced that interested customers would be able to buy obtain pre-order rights for the limited run of their "100 Year Special Series" cars …

Other

"Silvergate has collapsed"

2023-03-08 [vendor] Silvergate bank
Vector: Protocol collapse / insolvency

California-based Silvergate bank had pivoted almost entirely to serving crypto clients, a move that proved fatal to them in the wake of the FTX collapse and ensuing contagion. On …

Data leak

Tweet thread by zachxbt

2023-03-01 [vendor] BitBNS [loss] $8M
Vector: On-chain theft (attributed by zachxbt)

An investigation by crypto sleuth zachxbt uncovered that the Indian crypto exchange BitBNS had been hacked on February 1, 2022, but hid it from users. After experiencing a $7.5 …

Data leak

Ferrari Data Breach Ransom Demand — Customer PII, No Operational Impact

2023-03-01 [vendor] Ferrari N.V. customer data systems
Vector: Unknown ransomware/extortion group gained access to Ferrari's IT systems and exfiltrated customer data; Ferrari stated it received a ransom demand from the attackers but chose not to pay; Ferrari did not disclose the specific technical attack vector

In March 2023, Ferrari N.V. disclosed that it had received a ransom demand from a threat actor following unauthorized access to some of its IT systems. Ferrari detected the breach …

Supply chain [SC]

AT&T Third-Party Breach (March 2023)

2023-03-01 [vendor] Unknown
Vector: Compromise of third-party service provider / vendor relationship

AT&T alerts 9 million customers of data breach after vendor hack. AT&T is notifying roughly 9 million customers that some of their information has been exposed after one of its …

Supply chain [SC]

Cornell University, Ithaca College, Virginia Tech University, SUNY Oswego, Colorado State University, Loyola University Chicago and McMaster University Third-Party Breach (March 2023)

2023-03-01 [vendor] AudienceView
Vector: Compromise of third-party service provider / vendor relationship

Students' bank accounts hacked because of ticketing software breach - The Ithacan. After attending a concert at Cornell University featuring Beach Bunny on Jan. 28, several Ithaca …

Supply chain [SC]

Uber Third-Party Breach (March 2023)

2023-03-01 [vendor] Genova Burns
Vector: Compromise of third-party service provider / vendor relationship

Uber suffers another data breach after law firm’s servers attacked. This is the third time in six months that Uber has been the victim of a data breach. Uber has found itself in …

Data leak

HIPAA Journal

2023-02-28 [vendor] Orrick, Herrington & Sutcliffe file share [malware] SilentRansom/Luna Moth
Vector: CWE-284: Improper Access Control

San Francisco-based law firm Orrick, Herrington & Sutcliffe LLP — which ironically specializes in advising companies on cybersecurity incidents and data breaches — suffered a …

Data leak

Tweets by MyAlgo

2023-02-27 [vendor] Algorand wallet drains [loss] $3M
Vector: Smart contract exploit / hack

Over a period of several days, around 25 accounts on the Algorand blockchain have been drained of funds. The attack appears to be targeted at high-value accounts, and over 13 …

Cryptocurrency

Tweets by HideYoApes

2023-02-26 [vendor] hideyoapes wallet drain [loss] $208,000 [chain] ethereum
Vector: Smart contract exploit / hack

"I still don't quite understand what happened here", wrote hideyoapes.eth after their wallet was drained of around 30 NFTs. They had previously owned several pricey NFTs from the …

Ransomware

Dish Network / EchoStar BlackBasta Ransomware — Employee Data, 300K+ Affected

2023-02-23 [vendor] Dish Network / EchoStar internal systems [malware] Black Basta ransomware
Vector: Black Basta ransomware group attacked Dish Network's internal network; specific initial access vector not publicly disclosed; the attack encrypted internal systems and exfiltrated data

On 23 February 2023, Dish Network and its parent EchoStar suffered a Black Basta ransomware attack that caused a several-day outage affecting Dish Network's websites, call centers, …

Ransomware

Dish Network Ransomware Attack (Black Basta, Multi-Day Outage, 296K Employee Records)

2023-02-23 [malware] Black Basta ransomware
Vector: Attackers used compromised VPN credentials to access Dish Network's Windows Active Directory domain, then moved laterally and deployed ransomware across Dish's IT infrastructure

On February 23, 2023, Dish Network — a major US satellite TV provider — suffered a ransomware attack (attributed to Black Basta) that took down its internal systems, customer …

Cryptocurrency

Community notice

2023-02-23 [vendor] Metroverse blockchain game implodes [chain] ethereum
Vector: Exit scam / rug pull

The Metroverse NFT-based game caught the end of the 2021–22 crypto bull market, minting the Genesis collection in January 2022. The project sold out quickly, netting the project …

Other

Indictment

2023-02-23 [vendor] Sam Bankman-Fried indicted on four new charges in criminal case
Vector: Regulatory / legal action

Sam Bankman-Fried, the founder and former CEO of the now-bankrupt FTX exchange, was already facing eight criminal charges for offenses including wire fraud, securities fraud, money …

Cryptocurrency

Tweet thread by WazirXNFT

2023-02-22 [vendor] WazirX closes NFT marketplace [chain] bsc

Indian cryptocurrency exchange WazirX abruptly closed their NFT marketplace on February 22, giving its users no warning. In an announcement on Twitter, they wrote that they had …

Cryptocurrency

Tweet thread by DexibleApp

2023-02-17 [vendor] Dexible [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Decentralized exchange aggregator Dexible disclosed that they had suffered an exploit of one of their smart contracts, which allowed an attacker to steal funds from customer …

Cryptocurrency

"Loyalist: $4m stolen from over 400 victims"

2023-02-16 [vendor] "Loyalist" phishing [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has released research indicating that a cryptocurrency and NFT phishing scammer who goes by Loyalist/Lukas/Shibango has stolen more than $4 million of various …

Cryptocurrency

Inscription 2042

2023-02-15 [vendor] Fart noise reportedly sells for $280,000 [chain] bitcoin

You thought NFTs were dead? Think again. Perhaps longing for the halcyon days when you could mint an NFT on Ethereum and smile in satisfaction at the carbon emissions you just …

Data leak

CFPB Employee Emailed Sensitive Consumer Data to Personal Email Account

2023-02-14
Vector: Insider data exfiltration — a Consumer Financial Protection Bureau (CFPB) employee used their authorized access to CFPB systems to send 14 emails containing sensitive consumer data to their personal email account without authorization

The U.S. Consumer Financial Protection Bureau (CFPB) disclosed in March 2023 that a former CFPB employee had sent 14 emails containing sensitive personal and financial information …

Cryptocurrency

DForce Network

2023-02-13 [vendor] dForce Network [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker using flash loans to exploit a common re-entrancy vulnerability siphoned $3.65 million from the dForce defi project on both Arbitrum and Optimism, which are Ethereum …

Cryptocurrency

LocalBitcoins will discontinue its service

2023-02-09 [vendor] LocalBitcoins to [chain] bitcoin
Vector: Protocol collapse / insolvency

LocalBitcoins, a Finnish platform that allows individuals to trade Bitcoins with one another peer-to-peer, will be shutting down. The exchange is one of the longest running …

Other

<i>SEC v. Payward Ventures (dba Kraken)</i>

2023-02-09 [vendor] Kraken ends staking, pays $30 million in settlement with U.S. SEC
Vector: Regulatory / legal action

U.S. cryptocurrency exchange Kraken has reportedly agreed to close up shop on its crypto staking operation and pay a $30 million fine to the U.S. Securities and Exchange …

Cryptocurrency

Webaverse theft statement

2023-02-06 [vendor] Webaverse theft [loss] $4M [chain] ethereum
Vector: Social engineering attack

The metaverse gaming company Webaverse disclosed on February 6 that they had suffered a $4 million theft several months earlier. They outlined what appeared to be a complex scam in …

Data leak

CPO Magazine / CSHub / SecurityWeek

2023-02-05 [vendor] Reddit internal systems
Vector: CWE-1021: Improper Restriction of Rendered UI (targeted spear-phishing with real-time TOTP relay against single employee)

Attacker sent convincing phishing email mimicking Reddit IT, tricked employee into entering credentials and TOTP codes in real time on fake login page. Accessed internal documents, …

Cryptocurrency

<i>Holland v. CryptoZoo, Inc.</i>

2023-02-03 [vendor] Logan Paul slapped with a class action over CryptoZoo rugpull [chain] ethereum
Vector: Regulatory / legal action

Logan Paul is now facing a class action lawsuit over his CryptoZoo project, a planned NFT game that Paul apparently lost interest in and abandoned — after profiting handsomely, of …

Cryptocurrency

Tweet by PeckShield

2023-02-02 [vendor] Orion Protocol [loss] $3M [chain] ethereum
Vector: Reentrancy attack on smart contract

The decentralized exchange Orion Protocol suffered a loss of 1,757 ETH (about $2.9 million) from the company treasury funds thanks to a reentrancy attack.Orion Protocol CEO Alexey …

Supply chain [SC]

Boost Mobile Third-Party Breach (February 2023)

2023-02-01 [vendor] DISH Network Corporation
Vector: Compromise of third-party service provider / vendor relationship

The Week in Ransomware - March 3rd 2023 - Wide impact attacks. This week was highlighted by a massive BlackBasta ransomware attack targeting DISH Network and taking down numerous …

Supply chain [SC]

Sling TV Third-Party Breach (February 2023)

2023-02-01 [vendor] DISH Network Corporation
Vector: Compromise of third-party service provider / vendor relationship

Dish confirms ransomware attack allowed hackers to steal personal data | TechCrunch. Dish said a ransomware attack is to blame for an ongoing, multiday outage and warned that …

Cloud [SC]

Atlassian Third-Party Breach (February 2023)

2023-02-01 [vendor] Envoy
Vector: Compromise of third-party service provider / vendor relationship

Atlassian data leak caused by stolen employee credentials. Atlassian has confirmed that a breach at a third-party vendor caused a recent leak of company data and that their network …

Other

Infosecurity Magazine

2023-02-01 [vendor] FortiGate 300D firewall / Littleton Electric Light and Water Departments OT network
Vector: CWE-1188: Insecure Default Initialization of Resource (unpatched FortiGate 300D firewall — CVE patched December 2022, not applied until after breach)

Volt Typhoon (VOLTZITE per Dragos), a Chinese state-sponsored APT group, maintained persistent unauthorized access to the operational technology (OT) network of Littleton Electric …

Cryptocurrency

Tweet by LukeDashjr

2023-01-31 [vendor] Ordinals launch [chain] bitcoin

A recent project called "Ordinals" has the Bitcoin community up in arms. The project is the latest attempt to introduce NFTs to the Bitcoin blockchain, a controversial subject …

Cryptocurrency

Tweet showing email to users

2023-01-31 [vendor] Rally sidechain [chain] ethereum

Rally is an Ethereum sidechain built to support "social tokens" — typically, tokens intended for fans of various celebrities or groups.Fans of creators including Felicia Day …

Supply chain [SC]

Hatch Bank GoAnywhere MFT Breach (Cl0p, CVE-2023-0669)

2023-01-30 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p [cve] CVE-2023-0669
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra's GoAnywhere MFT administrative interface, to access Hatch Bank's file transfer environment on January 30–31, 2023 and steal customer names and Social Security numbers

Hatch Bank, a fintech-focused bank-as-a-service provider headquartered in San Francisco, was an early confirmed victim of the Cl0p ransomware group's mass exploitation of …

Supply chain [SC]

Community Health Systems GoAnywhere MFT Breach (Cl0p, CVE-2023-0669)

2023-01-28 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p [cve] CVE-2023-0669
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra's GoAnywhere MFT administrative interface, to exfiltrate data from Community Health Systems' managed file transfer environment between January 28–30, 2023; no ransomware encryption was deployed — data theft only

Community Health Systems (CHS), one of the largest for-profit hospital operators in the United States, was among the earliest publicly disclosed victims of Cl0p's mass-exploitation …

Cryptocurrency

One of the attacker wallets

2023-01-27 [vendor] Azuki Twitter [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Hackers were able to compromise the Twitter account belonging to the popular Azuki NFT project, which they then used to promote a fake NFT drop to its 334,000 followers. Users who …

Cryptocurrency

Tweet by Kevin Rose

2023-01-25 [vendor] Kevin Rose wallet [loss] $831,000 [chain] ethereum
Vector: Smart contract exploit / hack

Kevin Rose, perhaps best known as the founder of Digg, but also a prominent crypto investor and entrepreneur, lost a substantial number of pricey NFTs when he apparently signed a …

Supply chain [SC]

BleepingComputer / Fortra / CISA

2023-01-18 [vendor] Fortra GoAnywhere MFT [cve] CVE-2023-0669
Vector: CWE-78: OS Command Injection (pre-auth RCE in GoAnywhere MFT admin interface)

Cl0p exploited zero-day RCE in Fortra GoAnywhere MFT admin portal. ~130 organizations breached over 10 days in January 2023. Cl0p named 100+ victims on leak site through March …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Supply chain [SC]

Fortra GoAnywhere MFT Zero-Day Cl0p Exploitation — CVE-2023-0669, 130+ Organizations

2023-01-18 [vendor] Fortra GoAnywhere Managed File Transfer (MFT) [malware] Cl0p; Truebot web shell
Vector: Cl0p exploited CVE-2023-0669, a pre-authentication remote code injection vulnerability in Fortra GoAnywhere MFT's administrative interface; attackers installed a web shell ('Truebot') and exfiltrated data before the vulnerability was publicly known

Beginning 18 January 2023, Cl0p exploited a zero-day (CVE-2023-0669) in Fortra's GoAnywhere MFT, claiming to have breached approximately 130 organizations over 10 days before …

Data leak

Western Sydney University Data Breach — 10,000 Students and Staff (Microsoft 365 Compromise)

2023-01-17 [vendor] Western Sydney University Microsoft 365 / SharePoint
Vector: Attacker gained unauthorized access to Western Sydney University's Microsoft 365 email environment and SharePoint files via compromised credentials; maintained persistent access over several months exfiltrating data; a separate subsequent breach in 2024 affected the Student Management System

Western Sydney University (WSU) disclosed a data breach in May 2023 involving unauthorized access to its Microsoft 365 email environment and SharePoint files from approximately …

Cryptocurrency

Tweet thread by NFT GOD

2023-01-13 [vendor] NFT GOD wallet drain [loss] $25,800 [chain] ethereum
Vector: Phishing attack

According to NFT GOD, his computer was infected with malware when he clicked a sponsored link in a Google search when he went to download the streaming software OBS. This is …

Data leak

Tweet thread by LendHub

2023-01-12 [vendor] LendHub [loss] $6M
Vector: Smart contract exploit / hack

In a Twitter thread, LendHub published a message stating that "hackers stole about 6 million US dollars of assets from Lendhub". They wrote that they had "locked the hacker's …

Ransomware

BleepingComputer / TechCrunch / Computer Weekly

2023-01-10 [vendor] Royal Mail international shipping systems [malware] LockBit 3.0
Vector: CWE-1391: Use of Weak Credentials (compromised credentials; exact initial vector not publicly disclosed)

LockBit ransomware hit Royal Mail's Heathrow Worldwide Distribution Centre Jan 10 2023, disrupting international mail for 6 weeks. LockBit initially demanded $80M ransom, lowered …

Data leak

BleepingComputer

2023-01-05 [vendor] Forever 21 HR and payroll systems
Vector: CWE-284: Improper Access Control

Fast fashion retailer Forever 21 suffered a data breach where hackers had access to its systems from January 5 to March 21, 2023. The breach affected 539,207 current and former …

Cryptocurrency

Tweet by Magic Eden

2023-01-04 [vendor] Magic Eden lists fake NFTs [loss] $5,000 [chain] solana
Vector: Smart contract exploit / hack

Magic Eden, as with many NFT marketplaces, has a verification layer that shows popular projects as "verified" to reduce the chances of people being tricked by NFTs with the same …

Other

Tweet by CoffeeZilla

2023-01-04 [vendor] Logan Paul threatens to sue CoffeeZilla

Influencer-turned-(alleged)-crypto-grifter Logan Paul has threatened to sue scam researcher CoffeeZilla, who has exposed Paul's "CryptoZoo" blockchain game project as his latest …

Data leak

Tweet by coinpapi69

2023-01-03 [vendor] NFT marketplaces display porn
Vector: Smart contract exploit / hack

Users of NFT marketplaces and explorer applications including Magic Eden, NFT Explorer, and Rand Gallery were briefly shown pornographic images and still frames from the Big Bang …

Other

Tweet by DNP3

2023-01-03 [vendor] DNP3 gambled with investor funds

DNP3 is a streamer known for giving away large sums of money to other streamers. He is also a crypto founder behind projects including CluCoin, the Xenia play-to-earn game, the …

Cryptocurrency

"Nike's RTFKT COO Loses His NFTs in Massive Hack"

2023-01-02 [vendor] Nikhil Gopalani NFT theft [loss] $159,300 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker drained the wallet of Nikhil Gopalani, the COO of the Nike-owned crypto organization RTFKT. Most of the stolen NFTs were RTFKT NFTs, and the priciest were the nineteen …

Other

Tweet by Cameron Winklevoss

2023-01-02 [vendor] Tyler and Cameron Winklevoss, Gemini founders

On November 16, Genesis halted withdrawals from its lending service shortly after the FTX collapse. Gemini, who partners with Genesis lending to power their Earn program, halted …

Supply chain [SC]

KLM Third-Party Breach (January 2023)

2023-01-01 [vendor] Flying Blue
Vector: Compromise of third-party service provider / vendor relationship

Air France and KLM notify customers of account hacks. Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their …

Cloud [SC]

Datadog RPM Signing Key Exposed via CircleCI Breach

2023-01-01 [vendor] CircleCI CI/CD platform (customer secrets/environment variables)
Vector: CircleCI's January 2023 breach (malware on engineer laptop stole session token) allowed attackers to access CircleCI customer secrets; Datadog's RPM package signing key was stored in CircleCI CI/CD environment variables and was exposed

In January 2023, Datadog disclosed that its RPM (Red Hat Package Manager) signing key used to sign Datadog age nt packages had been exposed in the CircleCI breach. CircleCI's …

Cloud [SC]

Mailchimp Social Engineering Breach — 133 Customers Affected Including Trezor, Fanatics, WooCommerce

2023-01-01 [vendor] Mailchimp email marketing platform (internal admin tools)
Vector: Attackers used social engineering to target Mailchimp customer-facing operations staff, obtaining credentials to access internal tools used by Mailchimp's customer support and account administration teams; the attackers then used this access to view and export customer list data

In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …

Cloud [SC]

Mailchimp Social Engineering Breach — 133 Customers Affected Including Trezor, Fanatics, WooCommerce

2023-01-01 [vendor] Mailchimp email marketing platform (internal admin tools)
Vector: Attackers used social engineering to target Mailchimp customer-facing operations staff, obtaining credentials to access internal tools used by Mailchimp's customer support and account administration teams; the attackers then used this access to view and export customer list data

In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …

Other

Salt Typhoon AT&T / Verizon / Lumen Telecom Espionage (Confirmed)

2023-01-01 [vendor] Cisco IOS routers; CALEA lawful intercept systems [malware] Demodex (kernel-mode rootkit)
Vector: Chinese MSS-linked Salt Typhoon APT exploited vulnerabilities in telecom network infrastructure including Cisco routers; leveraged CALEA wiretap backdoor access and a Windows kernel-mode rootkit (Demodex) for persistence

Salt Typhoon (China MSS) breached at least 9 US telecom carriers including AT&T, Verizon, T-Mobile, Lumen, Spectrum, Consolidated Communications, and Windstream. Active for 1-2 …

Other

Wikipedia / SecurityWeek / Congress.gov CRS

2023-01-01 [vendor] AT&T / Verizon / T-Mobile / Lumen / Spectrum / Consolidated Communications / Windstream telecom infrastructure
Vector: CWE-287: Improper Authentication (exploitation of network edge devices and telecom infrastructure to access CALEA lawful intercept systems)

Chinese MSS-affiliated APT Salt Typhoon (FamousSparrow) breached at least 9 US telecoms including AT&T, Verizon, T-Mobile starting ~late 2022/early 2023. Accessed CALEA lawful …

Other

Unsellable NFTs website

2022-12-29 [vendor] Tax loss harvesting tool launched

If you bought an NFT for $1,000 and it's now worthless, you still have to find someone willing to buy it before you can claim it as a loss on your taxes. A project called …

Cryptocurrency

Tweet by PeckShieldAlert

2022-12-26 [vendor] BitKeep [loss] $8M [chain] bsc
Vector: Malicious code injection / supply chain

BitKeep, a popular cryptocurrency wallet in Asia, suffered a hack in which at least $8 million in various cryptocurrencies were stolen from user accounts.BitKeep has claimed that …

Data leak

Twitter thread by Rubic

2022-12-25 [vendor] Rubic [loss] $1M
Vector: Smart contract exploit / hack

The Rubic cross-chain exchange suffered an exploit in which attackers were able to siphon a total of around $1.4 million in user funds from their wallets. The exploit was enabled …

Data leak

Twitter thread by Rubic

2022-12-25

The Rubic cross-chain exchange suffered an exploit in which attackers were able to siphon a total of around $1.4 million in user funds from their wallets. The exploit was enabled …

Data leak [SC]

Toyota 240GB Data Leak

2022-12-25
Vector: Unauthorized access to a third-party contractor's environment; 240 GB of Toyota internal data surfaced on a hacking forum in August 2024, believed stolen as far back as December 2022

Toyota confirmed a data breach in August 2024 after threat actor ZeroSevenGroup posted 240 GB of data on a hacking forum. Data included employee and customer PII, contracts, …

Supply chain [SC]

PyTorch Nightly Dependency Confusion Attack — torchtriton Malicious Package

2022-12-25 [vendor] PyTorch nightly build (Meta AI deep learning framework) [malware] triton (malicious PyPI package — data stealer)
Vector: Dependency confusion attack: attacker uploaded a malicious package named 'torchtriton' to the public PyPI index that took precedence over the legitimate same-named package in PyTorch's private package index (download.pytorch.org); any user who installed PyTorch nightly builds between 25-30 December 2022 using pip received the malicious torchtriton package which stole sensitive data from the victim's system

On 25 December 2022, an attacker uploaded a malicious package named 'torchtriton' to the public PyPI index. PyTorch nightly builds depended on a package with the same name …

Cryptocurrency

Tweet by PeckShieldAlert

2022-12-23 [vendor] Defrost Finance [chain] avalanche
Vector: Flash loan attack on smart contract

Defrost Finance, a defi trading platform built on the Avalanche Network, apparently tried and failed to rug pull its users. The project claimed on December 23 that they were "sad …

Cryptocurrency

Tweet by Ray Youssef

2022-12-21 [vendor] Paxful delists ether [chain] bitcoin, ethereum

Peer-to-peer crypto marketplace Paxful announced that it will be delisting ether, citing "scams that have robbed people of billions".So close. You're almost there.Paxful CEO Ray …

Cryptocurrency

Tweet by Swan Bitcoin

2022-12-21 [vendor] Swan Bitcoin releases home equity Bitcoin product [chain] bitcoin

"Convert home equity into Bitcoin", Swan Bitcoin advertises with their new home equity product. Relatively few details are available on the new loan product they're offering, but …

Other

Announcement

2022-12-21 [vendor] Caroline Ellison and Gary Wang
Vector: Regulatory / legal action

Two of Sam Bankman-Fried's inner circle, Caroline Ellison and Gary Wang, have pled guilty to federal criminal charges and are cooperating in the case against Sam Bankman-Fried. …

Other

Tweet by Sasha Ivanov

2022-12-20 [vendor] Waves

Apparently adopting Do Kwon's belief that the solution to a crashing algorithmic stablecoin project is creating another project, Waves founder Sasha Ivanov has announced, "I will …

Cryptocurrency

Tweet thread by _sevenseason_

2022-12-17 [vendor] sevenseason NFT theft [loss] $1M [chain] ethereum
Vector: Smart contract exploit / hack

A scammer spent a month setting up a con in which they stole fourteen Bored Ape NFTs belonging to one individual. Posing as a casting director at a real film production …

Cloud

CircleCI Secrets Breach — Customer Environment Variables, Tokens, and Keys Stolen

2022-12-16 [vendor] CircleCI CI/CD platform (customer environment variables and secrets)
Vector: Malware was deployed on a CircleCI engineer's laptop that had access to production systems; the malware stole a valid session cookie and bypassed 2FA, allowing the attacker to impersonate the engineer's session; the attacker then exfiltrated customer data and encryption keys from CircleCI's production infrastructure

In December 2022 (disclosed 4 January 2023), CircleCI — a widely-used CI/CD platform with over 500,000 developer users — discovered that an attacker had stolen customer environment …

Cryptocurrency

"QuadrigaCX Has Had an Improbable Week"

2022-12-16 [vendor] QuadrigaCX "unauthorized" transfer [loss] $2M [chain] bitcoin
Vector: Exit scam / rug pull

QuadrigaCX was a Canadian crypto exchange that shut down and filed for bankruptcy in early 2019, with hundreds of millions more in liabilities than in assets. It later became …

Data leak

Tweet thread by LodestarFinance

2022-12-10 [vendor] Lodestar Finance attack [loss] $7M
Vector: Smart contract exploit / hack

The Arbitrum-based crypto lending platform Lodestar Finance was attacked by an exploiter who was able to manipulate the price of the plvGLP token, allowing them to "borrow" the …

Cryptocurrency

<i>Adonis Real v. Yuga Labs, Inc.</i>

2022-12-08 [vendor] Celebrity class action filed [chain] ethereum
Vector: Regulatory / legal action

A class action lawsuit against the company behind Bored Apes and its executives, those on the board of "Ape DAO", a whole host of celebrity promoters and brands, and the MoonPay …

Cryptocurrency

Tweet thread by OKHotshot

2022-12-08 [vendor] Vanessa Sierra [loss] $316,320 [chain] ethereum
Vector: Exit scam / rug pull

After a stint on Season 2 of Love Island Australia, Vanessa Sierra has made a career as a successful OnlyFans performer. In 2021, she also began offering crypto trading tips in a …

Cryptocurrency

Tweet by jac0xb.sol

2022-12-07 [vendor] FTX NFTs break [chain] ethereum, solana

After FTX declared bankruptcy, the entire FTX.us domain was redirected to a page providing information on the bankruptcy proceedings.However, NFTs that had been minted on the FTX …

Data leak

Activision Employee Data Breach via HR Smishing (19K Employees, Call of Duty Roadmap)

2022-12-04
Vector: Attacker sent an SMS phishing (smishing) message to an Activision HR employee impersonating the company's IT department; the employee provided their MFA code, giving the attacker access to Activision's internal HR and communications systems

On December 4, 2022, an attacker used SMS phishing (smishing) to social-engineer an Activision HR employee into providing their MFA authentication code. With access to Activision's …

Ransomware

Rackspace Hosted Exchange Play Ransomware Attack — Permanent Service Shutdown

2022-12-02 [vendor] Rackspace Hosted Exchange (managed Microsoft Exchange service) [malware] Play ransomware [cve] CVE-2022-41080 +1
Vector: Play ransomware group exploited CVE-2022-41080 (OWASSRF — Microsoft Exchange Server ProxyNotShell bypass) combined with CVE-2022-41082 to achieve remote code execution on Rackspace's Hosted Exchange environment; the vulnerability bypassed existing mitigations Rackspace had applied for ProxyNotShell

On 2 December 2022, Play ransomware attacked Rackspace's Hosted Exchange email service, forcing Rackspace to permanently shut down the service. Rackspace had approximately 30,000 …

Supply chain [SC]

Sobeys Third-Party Breach (December 2022)

2022-12-01 [vendor] Empire Co.
Vector: Compromise of third-party service provider / vendor relationship

Inside the turmoil at Sobeys-owned stores after ransomware attack | CBC News. Employees of Empire Co., the parent company of Sobeys, have begun to speak out about the turmoil …

Supply chain [SC]

St. Luke's Health Third-Party Breach (December 2022)

2022-12-01 [vendor] Adelanto Healthcare Ventures
Vector: Compromise of third-party service provider / vendor relationship

Third-party breach impacts St. Luke's Health. HealthITSecurity reports that Texas-based St. Luke's Health has disclosed experiencing a third-party data breach involving consulting …

Cloud

CommuteAir Jenkins Misconfiguration Exposes AWS Credentials and No-Fly List

2022-12-01 [vendor] Jenkins (CI/CD); Amazon S3
Vector: A publicly accessible Jenkins CI/CD server misconfiguration at CommuteAir exposed AWS credentials, which a security researcher used to access multiple S3 buckets — including one containing the TSA's No Fly List

In January 2023, a security researcher discovered that CommuteAir, a US regional airline, had a publicly exposed Jenkins build server with no authentication required. The Jenkins …

Cryptocurrency

Tweet by Ankr

2022-12-01 [vendor] Ankr [loss] $5M [chain] bsc
Vector: Malicious code injection / supply chain

The BNB Chain-based Ankr defi protocol suffered an exploit of their aBNBc token. "We are currently working with exchanges to immediately halt trading," they wrote. However, the …

Cloud

LastPass Second Breach — Source Code Used to Target Employee, Decrypt Customer Vault Backups

2022-11-30 [vendor] LastPass cloud storage / AWS S3 customer vault backups [malware] Keylogger (via vulnerable Plex Media Server)
Vector: Attacker used information stolen in the August 2022 LastPass breach (source code and technical data) to target a senior LastPass DevOps engineer at home; exploited a vulnerable third-party media software package on the engineer's personal computer to install a keylogger; captured the employee's master password and MFA credentials to access their LastPass corporate vault; then accessed a LastPass AWS S3 cloud backup containing encrypted customer password vaults

In November-December 2022, attackers who had previously breached LastPass in August 2022 (stealing source code and technical documentation) used that information to identify and …

Other

Tweet by TBD

2022-11-29 [vendor] TBD

TBD is a subsidiary of Block (formerly Square), a tech company co-founded by billionaire social media mogul and Twitter founder Jack Dorsey. In July, they unveiled the concept of …

Other

BlockFi Inc. bankruptcy filing

2022-11-28 [vendor] BlockFi bankruptcy [loss] $1.3B
Vector: Protocol collapse / insolvency

Crypto lending firm BlockFi has filed for Chapter 11 bankruptcy in the wake of the FTX collapse. The company was in dire straits in the spring after Terra and Three Arrows Capital …

Cryptocurrency

Web3 Is Going Great

2022-11-26 [vendor] Elon statue fails to impress [chain] ethereum

A shitcoin project desperate for the kind of pump that sometimes occurs when Elon Musk tweets about a cryptocurrency has gone to new lengths to get his attention. The group spent …

Data leak

BleepingComputer / Traceable / Wikipedia

2022-11-25 [vendor] T-Mobile US customer portal / API
Vector: CWE-306: Missing Authentication for Critical Function (unauthenticated API endpoint exposing customer data)

Attackers exploited an unprotected API endpoint starting Nov 25 2022, exfiltrating data over weeks undetected. 37 million customer records exposed including names, phone numbers, …

Other

Tweet by Wu Blockchain

2022-11-24 [vendor] CoinList
Vector: Withdrawal halt / insolvency

Beginning in mid-November, users of the CoinList exchange and ICO platform reported that they couldn't withdraw assets from the platform. On November 24, CoinList tweeted, "There …

Other

Tweets by Coinhouse

2022-11-17 [vendor] Coinhouse
Vector: Withdrawal halt / insolvency

The French crypto broker Coinhouse announced that they would be suspending withdrawals from their crypto "savings account" product. Coinhouse partners with Genesis to offer the …

Other

Tweet by Coffeezilla

2022-11-15 [vendor] Salt
Vector: Withdrawal halt / insolvency

The crypto lending firm SALT announced that they would be halting withdrawals due to exposure to FTX. "I am sorry to report that the collapse of FTX has impacted our business," …

Other

Tweet by CZ

2022-11-14 [vendor] Binance announces industry recovery fund

CZ of Binance announced on Twitter that Binance would be forming an "industry recovery fund", which he says is intended for projects that are "otherwise strong, but in a liquidity …

Other

Tweet thread by Travis Kling

2022-11-14 [vendor] Ikigai Asset Management reveals FTX exposure

The founder and chief investment officer of the Californian crypto hedge fund Ikigai Asset Management wrote on Twitter, "Last week Ikigai was caught up in the FTX collapse. We had …

Cryptocurrency

Tweet by PeckShield

2022-11-13 [vendor] Flare token [loss] $17M [chain] bsc
Vector: Exit scam / rug pull

Exploits and rug pulls of random tokens on BNB Chain are fairly commonplace, but typically the amount of money lost is fairly minimal. In this case, exploiters or insiders were …

Other

Tweet by Wu Blockchain

2022-11-13 [vendor] Huobi reveals FTX exposure

Huobi announced to shareholders that they had $18.1 million in crypto assets on the FTX exchange, where they can't be withdrawn. They reported that approximately $13.2 million of …

Cryptocurrency

Tweet by jconorgrogan

2022-11-12 [vendor] Crypto.com admits erroneous transfer [chain] ethereum

A Twitter user posted Etherscan screenshots showing a massive flow of crypto from the Crypto.com cryptocurrency exchange to another exchange, Gate.io. "Anyone know why Crypto.com …

Cryptocurrency

Tweet by DeFiAI

2022-11-12 [vendor] DeFiAI [loss] $4M [chain] bsc
Vector: Smart contract exploit / hack

"Our contract has been hacked and has caused a lot of losses," wrote DeFiAI simply in their announcement. That same day, the project had announced the launch of a new website for …

Other

Tweet by cryptogle

2022-11-12 [vendor] Tokensoft intentionally publishes user data

Tokensoft is a project that aims to help web3 projects launch fairly, without the launches being gamed. The group evidently thought they had come across 5,000 or so users who had …

Cloud

FTX Bankruptcy AWS Multi-Account Secrets Compromise

2022-11-11 [vendor] Amazon Web Services (AWS)
Vector: Attackers (believed to be either FTX insiders or nation-state actors) accessed AWS infrastructure secrets and private key material for multiple FTX-affiliated entities shortly after FTX filed for bankruptcy, draining approximately $400M from FTX and related exchange wallets

On November 11-12, 2022, within hours of FTX's bankruptcy filing, approximately $400 million was drained from FTX exchange and FTX US wallets in a series of unauthorized …

Other

Tweet by FTX

2022-11-11 [vendor] FTX [loss] $1.7B
Vector: Protocol collapse / insolvency

Aaaand there it goes.FTX announced that it had filed for Chapter 11 bankruptcy in the United States. Sam Bankman-Fried resigned as CEO.SBF had spoken about trying to raise …

Data leak

Tweet thread by Bo Shen

2022-11-10 [vendor] Bo Shen wallet compromise [loss] $42M
Vector: Seed phrase / wallet compromise

Bo Shen, a general partner at Fenbushi Capital and an early adopter of cryptocurrencies, tweeted on November 22 that two weeks prior, someone had stolen $42 million in …

Cryptocurrency

Tweet thread by CertiKAlert

2022-11-10 [vendor] DFX Finance attack [loss] $5M [chain] ethereum
Vector: Flash loan attack on smart contract

An attacker was able to use a flash loan to exploit a vulnerability in the smart contract for DFX Finance, a decentralized forex trading platform. The platform suffered a loss …

Other

Tweet by BlockFi

2022-11-10 [vendor] BlockFi
Vector: Withdrawal halt / insolvency

BlockFi had a tough time this past June, floundering after substantial losses in the crypto downturn. They were bailed out by FTX, who extended them a $250 million loan, then …

Other

Media release

2022-11-10 [vendor] Securities Commission of the Bahamas freezes FTX assets
Vector: Protocol collapse / insolvency

The Securities Commission of the Bahamas (where FTX is headquartered) announced they had frozen the assets of FTX and "related parties" — presumably Alameda. They also disclosed …

Other

Tweet by Binance

2022-11-09 [vendor] Binance rescinds FTX bailout
Vector: Protocol collapse / insolvency

It's over as quickly as it started, and it started pretty dang quickly. Binance walked away from the non-binding letter of intent that Binance signed to acquire FTX, which doesn't …

Other

Tweet thread by Sam Bankman-Fried

2022-11-08 [vendor] Binance offers FTX bailout

Surprising just about everyone, FTX's Sam Bankman-Fried and Binance's Changpeng "CZ" Zhao announced suddenly that Binance had signed a "non-binding [letter of intent], intending to …

Data leak

Etherscan transaction message

2022-11-06 [vendor] Pando [loss] $20M
Vector: Oracle price manipulation

The defi protocol Pando suffered a $20 million loss when it was exploited with an oracle manipulation attack. The protocol suspended several of its projects in response to the …

Other

Telegram message from Pavel Durov

2022-11-05 [vendor] Telegram repossesses usernames

In August, the popular messaging app Telegram started repossessing some desirable usernames that were already being used. Shortly afterwards, Telegram founder Pavel Durov explained …

Cryptocurrency

Tweet thread by zachxbt

2022-11-04 [vendor] Monkey Drainer phishing attack [loss] $867,042 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The "Monkey Drainer" NFT phishing scammer first identified by blockchain detective zachxbt has struck again. They successfully emptied 7 CryptoPunks and 20 Otherside NFTs, which …

Data leak

Tweet thread by Rubic

2022-11-02

An attacker was able to compromise the private key of an admin wallet for the Rubic crypto exchange, transferring around 34 million Rubic tokens. The attacker then sold the tokens …

Data leak

Tweet by Skyward Finance

2022-11-02 [vendor] Skyward Finance [loss] $3M
Vector: Smart contract vulnerability exploit

Skyward Finance is a project based on the NEAR blockchain, aiming to help users with initial token distribution. The project's treasury was drained of 1.1 million NEAR (~$3.2 …

Cryptocurrency

"Financing and Bitmain Prepayment Update"

2022-11-02 [vendor] Iris Energy close to defaulting on loans [chain] bitcoin
Vector: Protocol collapse / insolvency

Iris Energy, an Australian "sustainable Bitcoin mining company", has announced that they are close to defaulting on loans used to purchase $103 million of Bitcoin mining rigs. …

Cryptocurrency

Tweet thread by Rubic

2022-11-02 [vendor] Rubic [loss] $814,000 [chain] bsc, ethereum
Vector: Smart contract exploit / hack

An attacker was able to compromise the private key of an admin wallet for the Rubic crypto exchange, transferring around 34 million Rubic tokens. The attacker then sold the tokens …

Cryptocurrency

Tweet by Solend

2022-11-02 [vendor] Solend attack [loss] $1M [chain] solana
Vector: Oracle price manipulation

Solend announced that an exploiter had manipulated the oracle price of an asset on their platform, allowing them to take out a loan that left the platform with $1.26 million in bad …

Data leak

Tweet thread by Deribit

2022-11-01 [vendor] Deribit [loss] $28M
Vector: Smart contract exploit / hack

Major crypto exchange Deribit suffered a hot wallet compromise that resulted in a $28 million theft. The exchange halted withdrawals to perform security checks, but urged that …

Data leak

TPG Telecom / Australian Cyber Security Centre / ZDNet Australia

2022-11-01 [vendor] Microsoft Exchange (hosted)
Vector: CWE-307: Improper Restriction of Excessive Authentication Attempts (credential-based unauthorised access to a hosted Microsoft Exchange service)

TPG Telecom, Australia's second-largest telco (which acquired iiNet in 2015), disclosed on December 14 2022 that an unauthorised party had accessed its Hosted Exchange email …

Data leak

Tweet by Team Finance

2022-10-27 [vendor] Team Finance [loss] $1M
Vector: Software bug / unintentional loss

Team Finance is a project that helps projects lock their tokens to be released after a certain period or on a schedule. A hacker exploited a vulnerability in a smart contract that …

Cryptocurrency

friesDAO

2022-10-27 [vendor] friesDAO attack [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

friesDAO describes itself as a "a decentralized social experiment where a crypto community builds and governs a fast food franchise empire via wisdom of the crowd". Welcome to the …

Cryptocurrency

Tweet thread by zachxbt

2022-10-25 [vendor] Monkey Drainer phishing [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A phishing scammer called "Monkey Drainer" stole around 700 ETH (~$940,000) in 24 hours on October 25, according to blockchain sleuth zachxbt. The scammer used malicious phishing …

Cryptocurrency

Tweet thread by Layer2DAO

2022-10-23 [vendor] Layer2DAO [loss] $87,000 [chain] ethereum
Vector: Smart contract exploit / hack

An attacker was able to siphon nearly 50 million L2DAO tokens from a multi-sig wallet on the Optimism protocol. These tokens would nominally have been valued at around $400,000 at …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-10-23 [vendor] QuickSwap attack [loss] $188,260 [chain] polygon
Vector: Oracle price manipulation

Adding to the recent string of oracle manipulation attacks is an attack on the miMATIC ($MAI) market on the QuickSwap decentralized exchange. An exploiter was able to manipulate …

Other

Tweet thread by Freeway

2022-10-23 [vendor] Freeway [loss] $160M
Vector: Withdrawal halt / insolvency

Freeway, a financial scheme where users buy "Superchargers", which are crypto "simulations" that promise to pay out rewards of up to 43% annually, seems to have taken the off-ramp. …

Cryptocurrency

Tweets by Wu Blockchain

2022-10-22 [vendor] 3Commas [loss] $6M [chain] bitcoin
Vector: Phishing attack

Several users of the automated trading bot 3Commas reported losing over a million dollars each in a hack or phishing scam affecting users who had connected it to their FTX …

Cryptocurrency

Tweet thread by Lee Bousfield

2022-10-18 [vendor] BitBTC vulnerability [chain] bitcoin, ethereum
Vector: Smart contract exploit / hack

A security researcher published a frustrated Twitter thread reporting that "BitBTC's Optimism bridge is trivially vulnerable. Their team has ignored my messages, so I'm going to …

Cryptocurrency

Tweet thread by Moola Market

2022-10-18 [vendor] Moola Market attack [loss] $588,000 [chain] celo
Vector: Oracle price manipulation

The Celo-based borrowing and lending platform, Moola Market, suffered a major exploit when an attacker manipulated collateral prices to steal a collection of assets notionally …

Cryptocurrency

Tweet by Rusty Bill

2022-10-18 [vendor] Roofstock claims to have sold house as NFT [chain] ethereum

If you've ever wished you could put the same amount of thought into buying a $100,000+ home as you do ordering another bag of dog food from your online retailer of choice, you're …

Cryptocurrency

"Why we’re no longer offering .coin"

2022-10-18 [vendor] Unstoppable Domains disables .coin extensions [chain] ethereum

Unstoppable Domains is in the business of selling "domains" — at least that's what they call them, but they're not the kind of domain that you can plug into your web browser. …

Cryptocurrency

Tweet thread by BitKeep Wallet

2022-10-17 [vendor] BitKeep Swap [loss] $100,000 [chain] bsc
Vector: Smart contract exploit / hack

The Swap feature of the BitKeep crypto wallet suffered an exploit that landed a hacker more than $1 million worth of BNB. The project acknowledged the hack, and promised to …

Other

In re: Voyager Digital Holdings, et al

2022-10-17 [vendor] Texas Securities investigators looking into FTX
Vector: Regulatory / legal action

Joseph Jason Rotunda, Director of the Enforcement Division of the Texas State Securities Board, submitted a filing to the ongoing Voyager bankruptcy case. FTX is the highest bidder …

Cryptocurrency

Tweet thread by Syntropy

2022-10-15 [vendor] Syntropy theft [chain] ethereum
Vector: Smart contract exploit / hack

The web3 company Syntropy suffered the loss of 15 million of their $NOIA tokens when they attempted to transfer them to a venture capital firm, but instead they ended up with a …

Data leak [SC]

Advocate Aurora Health Web Tracking Pixel Disclosure — 3 Million Patients

2022-10-14 [vendor] Advocate Aurora Health patient web portals (Meta Pixel / Google Analytics)
Vector: Third-party web tracking pixels (Meta Pixel and Google Analytics) embedded in Advocate Aurora Health's patient-facing web portals transmitted protected health information to Meta and Google; the pixels were present on patient scheduling, billing, and MyChart portal pages

Advocate Aurora Health — an integrated health system with 26 hospitals across Wisconsin and Illinois — disclosed in October 2022 that it had notified approximately 3 million …

Cryptocurrency

Tweet by MevRefund

2022-10-14 [vendor] Earning.Farm attack [loss] $971,248 [chain] ethereum
Vector: Flash loan attack on smart contract

The defi project Earning.Farm lost 748 ETH (~$971,000) to a hacker using a flash loan attack. The project contract was missing a check that a flash loan was initiated by the …

Cryptocurrency

Twitter thread by Cami

2022-10-13 [vendor] Blu3DAO accusations [chain] ethereum

Blu3DAO is a DAO that describes itself as "focused on empowering women, non-binary people, and allies to learn, earn, and play in web3 towards financial freedom". The group was the …

Cryptocurrency

Tweet by Vault by CNN

2022-10-11 [vendor] CNN abandons Vault NFT project [chain] flow
Vector: Exit scam / rug pull

In June 2021, CNN launched "Vault": a project to "make moments from history available for purchase". The project involved minting as NFTs various clips of CNN footage and …

Cryptocurrency

Web3 Is Going Great

2022-10-11 [vendor] Harassment at Ethereum conference [chain] ethereum

A Black woman attending the major Devcon Ethereum community event in Bogotá posted to Twitter a photograph of a man at the conference, writing, "Day 1 of Devcon and a group of us …

Cryptocurrency

Attacker's account

2022-10-11 [vendor] Mango Markets [loss] $50M [chain] solana
Vector: Oracle price manipulation

Mango Markets, a Solana-based defi project offering borrowing, lending, and leverage trading, was exploited for $116 million. An attacker manipulated the supposed value of their …

Cryptocurrency

Tweet thread by Rabby Wallet

2022-10-11 [vendor] Rabby Wallet [loss] $194,500 [chain] ethereum
Vector: Smart contract exploit / hack

Rabby Swap, a feature of the Rabby crypto wallet, was exploited a month after it was first rolled out. An attacker discovered an apparent vulnerability in the Rabby Swap smart …

Cryptocurrency

"DeFi Protocol Temple DAO Struck by $2.3M Exploit"

2022-10-11 [vendor] STAX Finance [loss] $2M [chain] ethereum
Vector: Smart contract access control vulnerability

A hacker discovered a vulnerability in the smart contract for the STAX project, which is built on the TempleDAO defi protocol. STAX is a liquidity provider for $TEMPLE/$FRAX.Poor …

Credential theft

MyDeal Australia Data Breach — 2.2 Million Customers via Compromised Credentials

2022-10-09 [vendor] MyDeal CRM system
Vector: Attacker used compromised user credentials to access MyDeal's CRM system, which contained customer data; the compromised credentials allowed the attacker to extract approximately 2.2 million customer records

On 9 October 2022, MyDeal — an Australian online retail marketplace owned by Woolworths Group (acquired in 2022 for A$217 million) — was breached via compromised user credentials …

Cryptocurrency

Tweet thread by OxQuit

2022-10-08 [vendor] Laszlo_btc NFT theft [loss] $2M [chain] ethereum
Vector: Phishing attack

In an incredible display of misfortune and perhaps ineptitude, an NFT collector was scammed out of a Bored Ape and then scammed out of six more Bored Apes when he tried to revoke …

Other

Tweets by Zcash Media

2022-10-05 [vendor] Zcash spam attack

Zcash is a privacycoin which, unlike popular blockchains like Bitcoin and Ethereum, allows users to obscure who they are sending money to and how much. Since June or July, the …

Ransomware

CommonSpirit Health Hive Ransomware Attack — 140 Hospitals, 623K Patients

2022-10-03 [vendor] CommonSpirit Health hospital IT infrastructure [malware] Hive ransomware
Vector: Hive ransomware group gained access to CommonSpirit's internal network via compromised credentials; attackers had access from 16 September through 3 October 2022 before the attack was detected; specific initial access vector (likely phishing or RDP) was not fully disclosed

On 3 October 2022, CommonSpirit Health — the second-largest nonprofit hospital system in the United States with 140 hospitals and over 1,000 care sites across 21 states — was hit …

Data leak

"Transit Swap"

2022-10-01 [vendor] Transit Swap [loss] $6M
Vector: MEV / sandwich attack

Transit Swap is a multi-chain decentralized exchange aggregator. Users of the project were collectively exploited for approximately $21 million when an attacker took advantage of a …

Supply chain

Barracuda Email Security Gateway Zero-Day CVE-2023-2868 — UNC4841 China APT

2022-10-01 [vendor] Barracuda Email Security Gateway (ESG) hardware appliance [malware] SALTWATER, SEASPY, SEASIDE, SUBMARINE, WHIRLPOOL [cve] CVE-2023-2868
Vector: UNC4841 (China-nexus APT) exploited CVE-2023-2868, a remote command injection zero-day in Barracuda ESG's email attachment scanning module triggered by specially crafted TAR file names sent via email; no authentication or user interaction required — attacker simply emailed malicious attachments to any recipient at a victim organisation using a Barracuda ESG appliance

Beginning in October 2022 (nearly eight months before disclosure), UNC4841 — a China-nexus espionage group assessed by Mandiant as acting in support of Chinese state interests — …

Cryptocurrency

Tweet by Laine

2022-09-30 [vendor] Solana outage [chain] solana

In the latest illustration of our marvelous new decentralized, resilient blockchain future, one single Solana node apparently was able to take down the entire Solana network. …

Cryptocurrency

"RIP MEV BOT"

2022-09-28 [vendor] 0xbadc0de MEV bot [loss] $1M [chain] ethereum
Vector: MEV / sandwich attack

MEV bots are a controversial category of bots who frontrun transactions in ways that are often detrimental to users. One such bot, known as 0xbadc0de, earned a windfall when a …

Cryptocurrency

Tweet thread by Jason Falovitch

2022-09-25 [vendor] Jason Falovitch NFT theft [loss] $150,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Sports manager turned crypto entrepreneur Jason Falovitch is now perhaps best known for his influence in the NFT space. He co-founded the Leverage Game Media company along with …

Cryptocurrency

Tweet thread by Evgeny Gaevoy

2022-09-20 [vendor] Wintermute [loss] $160M [chain] ethereum
Vector: Smart contract exploit / hack

The algorithmic market maker Wintermute suffered a major hack, according to their CEO. He estimated the loss at around $160 million, also writing that the company is "solvent with …

Data leak

Wikipedia / UpGuard / ACMA / SecurityScorecard

2022-09-19 [vendor] Optus telecommunications customer portal
Vector: CWE-306: Missing Authentication for Critical Function (internet-exposed API with no authentication due to 2018 coding error not remediated on sub-domain)

Australian telco Optus exposed an unauthenticated internet-facing API due to coding error from 2018 not fully remediated. Attacker used simple trial-and-error over 3 days in Sept …

Other

FTX

2022-09-19 [vendor] UK FCA warns against FTX

The United Kingdom's Financial Conduct Authority issued a warning that FTX is not authorized by them, but is targeting consumers in the UK. "Almost all firms and individuals …

Cryptocurrency

Tweet by LakeShowTJ

2022-09-18 [vendor] LakeShowTJ NFT theft [loss] $17,515 [chain] ethereum
Vector: Smart contract exploit / hack

The owner of Mutant Ape #21080 was approached with an offer to trade their ape for another Mutant Ape (#55) and an extra 0.5 ETH ($675) to sweeten the deal. The trader agreed, and …

Data leak

Rockstar Games GTA 6 Source Code and Video Leak — Scattered Spider

2022-09-17 [vendor] Rockstar Games internal Slack / Confluence / development systems
Vector: Scattered Spider attacker (same individual as the 2022 Uber breach) gained access to Rockstar Games' Slack workspace using compromised employee credentials; from Slack, the attacker accessed Confluence wikis and was able to download internal development materials and GTA 6 footage

On 17-18 September 2022 — just two days after the Uber breach — the same 18-year-old Scattered Spider attacker (Arion Kurtaj) breached Rockstar Games' internal systems and leaked …

Cryptocurrency

Tweet thread by CryptoCondom

2022-09-17 [vendor] AVAX chart [loss] $400,000 [chain] avalanche
Vector: Software bug / unintentional loss

GMX is a decentralized cryptocurrency exchange that boasts zero price impact trades. On most exchanges, users have to contend with slippage: a difference between the price of a …

Credential theft

Dark Reading / UpGuard / InfoQ

2022-09-15 [vendor] Uber corporate network / Thycotic PAM
Vector: CWE-1390: Weak Authentication (MFA push notification fatigue / bombing combined with social engineering via WhatsApp)

18-year-old Lapsus$-affiliated attacker purchased stolen contractor VPN credentials from dark web. Bypassed Duo MFA by bombing target with push notifications for >1 hour then …

Cryptocurrency

Tweet by Molly White

2022-09-14 [vendor] Ethereum merge double-your-money [loss] $314,307 [chain] ethereum
Vector: Smart contract exploit / hack

If it seems like you've been seeing a lot of Ethereum co-founder and figurehead Vitalik Buterin around Twitter lately, it may be due to the influx of hacked verified Twitter …

Other

Tweet thread by Brian Armstrong

2022-09-14 [vendor] Coinbase rolls out politics feature

When the "politics" were widespread civil unrest in the summer of 2020 triggered by the police murder of George Floyd, and pressure on the company to release a statement in support …

Credential theft

Revolut Social Engineering Customer Data Breach — 50,150 Users

2022-09-11 [vendor] Revolut internal customer support database
Vector: Targeted social engineering attack against a Revolut employee who was tricked into granting the attacker access to Revolut's internal customer support database; the attacker used the employee's legitimate credentials and access to query and exfiltrate customer records

On 11 September 2022, an attacker used a sophisticated social engineering technique to gain access to Revolut's customer support system through a Revolut employee. The attacker …

Credential theft

Revolut Social Engineering Attack (50K Customers)

2022-09-11
Vector: Social engineering — a threat actor used targeted phishing/social engineering techniques against a Revolut employee to obtain credentials, gaining unauthorized access to Revolut's internal database systems

On September 11, 2022, Revolut — a UK/EU-based neobank and fintech company with over 20 million customers — suffered a brief but significant data breach via a social engineering …

Other

Tweet by Stephanie Martin

2022-09-08 [vendor] Celsius Monopoly

After what USA Strong Head of Sales & Partnerships described as "months and months" of work, apparently the company had decided they had sunk too much effort into the …

Cryptocurrency

Tweet by CertiKAlert

2022-09-06 [vendor] Avalanche flash loan attacks [loss] $370,000 [chain] avalanche
Vector: Flash loan attack on smart contract

An attacker using the Avalanche blockchain successfully executed a flash loan attack impacting one contract and several other liquidity providers. The attacker made around $370,000 …

Cryptocurrency

Tweet by DavidBowieReal

2022-09-06 [vendor] David Bowie NFT announcement [chain] ethereum

The latest entry in "group launches NFTs, fans hate it" comes from the David Bowie estate, who decided that "Bowie on the Blockchain" would be a cool idea to raise money for …

Ransomware

Los Angeles Unified School District Ransomware (Vice Society, 500GB Data)

2022-09-03 [malware] Vice Society ransomware
Vector: Vice Society ransomware group gained access to LAUSD's network; initial access vector not officially confirmed but consistent with credential theft or exploitation of internet-facing systems; attackers exfiltrated approximately 500GB of data before deploying ransomware over the Labor Day weekend

The Los Angeles Unified School District (LAUSD), the second-largest school district in the United States (serving approximately 600,000 students and 74,000 employees), suffered a …

Cryptocurrency

Tweet thread by Rug Pull Finder

2022-09-02 [vendor] Bad Guys promotional artwork [loss] $4,000 [chain] ethereum
Vector: Exit scam / rug pull

The group Rug Pull Finder aims to combat fraud, scams, and hacks in the NFT space, often investigating crypto rug pulls and offering audits for projects and smart contracts. They …

Supply chain [SC]

Anthem MaineHealth Third-Party Breach (September 2022)

2022-09-01 [vendor] Alight.com (Choice Health prev)
Vector: Compromise of third-party service provider / vendor relationship

Anthem MaineHealth Reports Third Party Data Breach Related to Incident at Choice Health | JD Supra. On September 30, 2022, Anthem MaineHealth (“AMH Health”) filed an official …

Supply chain [SC]

Humana Third-Party Breach (September 2022)

2022-09-01 [vendor] Alight.com (Choice Health prev)
Vector: Compromise of third-party service provider / vendor relationship

Humana Announces Reports Third-Party Data Breach Involving Data Security Incident at Choice Health | JD Supra. On September 21, 2022, Humana confirmed that the company experienced …

Supply chain [SC]

Magento Third-Party Breach (September 2022)

2022-09-01 [vendor] FishPig
Vector: Compromise of third-party service provider / vendor relationship

Hackers breach software vendor for Magento supply-chain attacks. Hackers have injected malware in multiple extensions from FishPig, a vendor of Magento-WordPress integrations that …

Cryptocurrency

Tweet by CertiKAlert

2022-09-01 [vendor] ShadowFi [loss] $298,200 [chain] bsc
Vector: Smart contract exploit / hack

An attacker discovered that anyone could call the burn function on the liquidity pool contract for the ShadowFi project. They were able to exploit this vulnerability by calling the …

Cryptocurrency

"Babylon Finance is shutting down"

2022-08-31 [vendor] Babylon Finance [loss] $3M [chain] ethereum
Vector: Protocol collapse / insolvency

In April, an attacker exploited vulnerabilities in the defi lending project Rari Capital to steal $80 million. The asset management project Babylon Finance was a major lending pool …

Other

"Proposal To Upgrade To UAV V3"

2022-08-30 [vendor] Compound Finance cETH bug
Vector: Software bug / unintentional loss

Compound Finance released an update to change the price feed used by the Compound v2 protocol. Despite being audited by three firms, no one caught a bug that caused all …

Cryptocurrency

"From Fanfaron"

2022-08-26 [vendor] Ragnarok treasury mismanagement [loss] $2M [chain] ethereum

Ragnarok is a metaverse role-playing game that launched its character NFTs in April 2022. The project received $1.75 million in seed funding, plus another $17.5 million from NFT …

Ransomware

OAIC / UpGuard / TechCrunch / Cyber.gov.au

2022-08-25 [vendor] Medibank Private health insurance platform [malware] BlogXX / REvil variant
Vector: CWE-308: Use of Single-Factor Authentication (stolen VPN credentials; VPN lacked MFA, only requiring device certificate or username/password)

Russian cybercriminal (Aleksandr Ermakov, sanctioned by Australia Jan 2024) accessed Medibank's network Aug 25 - Oct 13 2022 via stolen privileged VPN credentials without MFA. …

Cryptocurrency

Tweet thread by ENS DAO

2022-08-25 [vendor] eth.link domain at risk [chain] ethereum
Vector: Phishing attack

Some people might be familiar with ENS, the "Ethereum Name Service", which seeks to be a web3 equivalent of DNS. If you've seen people with usernames ending in .eth, that's an ENS …

Data leak

Tweet thread by zachxbt

2022-08-24 [vendor] Cameron Redman accused of crypto Twitter
Vector: On-chain theft (attributed by zachxbt)

In 2020, a Canadian teenager used SIM swapping to steal US$37 million in Bitcoin and Bitcoin Cash from a single person. Canadian police announced his arrest in November 2021 after …

Cryptocurrency

Tweet by CertikAlert

2022-08-24 [vendor] PokemonFi [loss] $708,000 [chain] bsc

It's not much compared to at least three separate crypto Pokémon ripoffs since February that have each taken millions, but apparently the love of Pokémon still drew people in to …

Data leak

Plex Media Server Data Breach — 15 Million User Accounts

2022-08-23 [vendor] Plex Media Server user database
Vector: Unauthorized access to a Plex database; attacker used unknown means to access the Plex database containing user account information; the breach was disclosed the day after discovery

On 23 August 2022, Plex — a media management and streaming platform with approximately 30 million registered users — discovered that an attacker had accessed a subset of their …

Cryptocurrency

Tweet by zachxbt

2022-08-20 [vendor] 0x47dF5 NFT theft [loss] $116,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

In what might be a new record, someone bought a Bored Ape NFT for 70.69 ETH (~$116,000) and had it stolen from them less than two hours later. The scammer quickly flipped the NFT …

Cryptocurrency

Tweet by penguin_curator

2022-08-20 [vendor] OpenSea listing bug [chain] ethereum
Vector: Software bug / unintentional loss

The same issue that led to OpenSea paying out $1.8 million to users who lost their NFTs is apparently still alive and well (despite OpenSea's introduction of an "Inactive listings" …

Data leak

Twitter thread by korpi87

2022-08-18 [vendor] Trader signs malicious message [loss] $469,146
Vector: Smart contract exploit / hack

An experienced crypto trader lost $470,000 to a hack when they signed a malicious message that permitted an attacker to drain all of their USDC stablecoins from their crypto hot …

Cryptocurrency

"Magic Eden Response to Degen Town"

2022-08-18 [vendor] DegenTown [loss] $923,000 [chain] solana
Vector: Exit scam / rug pull

DegenTown, a collection of brightly-colored cel shaded humanoid figures, launched with much promotion from Magic Eden on their Launchpad minting service. Magic Eden aims to provide …

Other

Tweet thread by zachxbt

2022-08-18 [vendor] Bribe Protocol [loss] $6M
Vector: On-chain theft (attributed by zachxbt)

The Bribe Protocol promised a DAO infrastructure tool where "token holders get paid to govern", and raised $5.5 million in funding in January to work on their extensive roadmap. …

Data leak

Tweet by CelerNetwork

2022-08-17 [vendor] Celer Network bridge [loss] $240,000
Vector: DNS hijacking / domain takeover (front-end compromise)

The Celer Network's cBridge project was targeted with a BGP hijacking attack. Users who tried to access the bridge's frontend were instead shown a site that prompted them to …

Cryptocurrency

HUSD on CoinMarketCap

2022-08-17 [vendor] HUSD [chain] ethereum

HUSD, a stablecoin linked to the Huobi crypto exchange, lost its peg and dropped to around $0.85. HUSD is a cash-backed stablecoin intended to be pegged to the US dollar, but the …

Data leak

Tweet thread by AcalaNetwork

2022-08-14 [vendor] Acala [loss] $2M
Vector: Software bug / unintentional loss

A misconfiguration in a newly-deployed liquidity pool allowed an attacker to mint 1.2 billion aUSD, a stablecoin built on the Polkadot network. The exploit caused aUSD to lose its …

Cryptocurrency

Tweet by zachxbt

2022-08-14 [vendor] ASEC_APE NFT theft [loss] $546,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

An NFT collector who goes by ASEC_APE lost four Bored Ape Yacht Club NFTs to a phishing attack. The attacker quickly flipped three of the four NFTs for a total of around 200 ETH …

Cryptocurrency

Tweet thread by Philneeds

2022-08-13 [vendor] Fake Apecoin [loss] $163,770 [chain] ethereum
Vector: Smart contract exploit / hack

A scammer created a fake ApeCoin contract on the NFT Trader service, with tokens that appeared identical to the true ApeCoins but were actually worthless. After "chatt[ing] for a …

Cryptocurrency

Tweet by Velodrome

2022-08-13 [vendor] Velodrome theft by team member [chain] ethereum
Vector: Smart contract exploit / hack

On August 4, the team behind the Velodrome exchange and liquidity marketplace noticed that $350,000 had been taken from a team-operated wallet that was normally used for …

Other

Etherscan address of "hacker"

2022-08-12 [vendor] Martin Shkreli [loss] $459,261
Vector: Exit scam / rug pull

I've almost got to give it to him. When I wrote up Druglike, Martin "Pharma Bro" Shkreli's new "web3" project for drug discovery, and asked him some questions in the project …

Cryptocurrency

Tweet by takenstheorem

2022-08-11 [vendor] Ethermine blocks Tornado transactions [chain] ethereum

The Ethermine mining pool is responsible for over a quarter of all Ethereum mining, making them the largest miner for that blockchain. On August 11, three days after OFAC added the …

Other

Announcement

2022-08-11

Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …

Other

Announcement

2022-08-11 [vendor] Untamed Isles squanders Kickstarter funds on crypto

Over 3,000 backers put a combined ~NZ$841,000 (~US$535,000) into Untamed Isles, a Pokémon-like MMORPG. Although the developers did eventually plan to add optional crypto elements …

Other

Tweet thread by OpenSea

2022-08-10 [vendor] OpenSea requires police report to freeze NFTs

The dominant NFT platform, OpenSea, has changed its policy around NFTs that are reported as stolen. OpenSea now requires those who have reported an NFT as stolen to produce a …

Cryptocurrency

Tweet by Curve Finance

2022-08-09 [vendor] Curve Finance [chain] ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

Curve Finance's frontend at curve.fi was compromised, prompting users to give token approval to a malicious smart contract. Stolen funds were then transferred out to the FixedFloat …

Data leak

Tweet thread by OKHotshot

2022-08-08 [vendor] Discord compromises
Vector: Smart contract exploit / hack

I've largely stopped covering crypto Discord compromises because they occur so frequently it would drown out everything else. OKHotshot has been keeping count, though, and …

Cloud

LastPass Blog / Wikipedia / Cybersecurity Dive

2022-08-08 [vendor] LastPass Password Manager [cve] CVE-2020-5741
Vector: CWE-1232: Improper Lock of Memory That Contains Resource (developer laptop compromise via malware; second stage via vulnerable Plex Media Server CVE-2020-5741)

Two-stage breach in 2022. Aug 8-11: attacker compromised software developer's laptop, stole 14 source code repositories. Aug 12: senior DevOps engineer's personal computer …

Cryptocurrency

"Scammers In Paris"

2022-08-08 [vendor] Bored Ape animation [loss] $2M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has uncovered a French scam duo, Mathys and Camille, who he believes were behind the March "turn your BAYC animated" phishing scam in which they stole a …

Cryptocurrency

Riot Blockchain press release

2022-08-08 [vendor] Riot blockchain curtailment [chain] bitcoin

The Bitcoin mining firm Riot Blockchain produced 318 BTC in July, valued at around $6.88 million, from its mining operations located in central Texas. The firm also received $9.5 …

Other

Specially Designated Nationals List Update

2022-08-08 [vendor] OFAC sanctions Tornado Cash
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The U.S. Office of Foreign Assets Control (OFAC) added Tornado Cash to its SDN list: a list of "Specially Designated Nationals And Blocked Persons" with whom U.S. individuals and …

Cryptocurrency

Tweet by CertiK Alert

2022-08-07 [vendor] "Saxon James Musk" coin [loss] $442,000 [chain] bsc
Vector: Exit scam / rug pull

Who could have predicted that the shitcoin named after one of Elon Musk's 16-year-old sons could turn out to be a scam? Well, besides the people who fell for previous rug pulls of …

Cryptocurrency

Tweet by Steven Galanis

2022-08-06 [vendor] Steven Galanis wallet compromise [loss] $231,000 [chain] ethereum
Vector: Seed phrase / wallet compromise

A hacker compromised the wallet belonging to Steven Galanis, the CEO of Cameo, an app that allows people to pay various celebrities to record short messages for them. The hacker …

Data leak

Tweet by CertiK Alert

2022-08-03 [vendor] ZB exchange [loss] $4M
Vector: Smart contract exploit / hack

The self-described "world's most secure digital asset exchange", ZB, suffered an exploit in which attackers stole a large number of different cryptocurrencies, estimated by various …

Other

Tweet by zachxbt

2022-08-03 [vendor] News outlets publish wrong recovery address after Nomad
Vector: On-chain theft (attributed by zachxbt)

After the August 1 Nomad bridge exploit, Nomad created an address where people who took money out of the bridge could return it.However, that was not the address that CoinGape …

Cryptocurrency

Tweet thread by 0xfoobar

2022-08-02 [vendor] Slope wallet attack [loss] $6M [chain] solana
Vector: Smart contract exploit / hack

Nearly 8,000 Solana wallets were drained for at least $6 million worth of assets, including native SOL tokens and SPL tokens like USDC. The attack went on for nearly a day before …

Data leak

Tweet by 0xfoobar

2022-08-01 [vendor] Nomad bridge [loss] $153M
Vector: Smart contract exploit / hack

After an attacker began exploiting a vulnerability in the Nomad bridge, many people rushed to replicate the attack and steal some of the roughly $190 million of various …

Supply chain [SC]

Kiplepay Sdn Bhd Third-Party Breach (August 2022)

2022-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Kiplepay informs users on potential indirect data breach through third-party payment gateway provider. KUALA LUMPUR: E-wallet service provider Kiplepay Sdn Bhd had informed its …

Supply chain [SC]

NHS Third-Party Breach (August 2022)

2022-08-01 [vendor] Advanced
Vector: Compromise of third-party service provider / vendor relationship

NHS IT supplier held to ransom by hackers. Its IT provider says it may take three or four weeks to fully recover from the cyber-attack. A cyber-attack on a major IT provider of the …

Cloud [SC]

Mailchimp Social Engineering Breach — 133 Customers Affected Including Trezor, Fanatics, WooCommerce

2022-08-01 [vendor] Mailchimp email marketing platform (internal admin tools)
Vector: Attackers used social engineering to target Mailchimp customer-facing operations staff, obtaining credentials to access internal tools used by Mailchimp's customer support and account administration teams; the attackers then used this access to view and export customer list data

In April 2022, Mailchimp discovered that a malicious actor had conducted a social engineering attack on Mailchimp employees and contractors, gaining access to Mailchimp's internal …

Cloud

DoorDash 0ktapus/Twilio Campaign Third-Party Vendor Breach

2022-08-01
Vector: 0ktapus / Scattered Spider threat actors phished an employee of an unnamed third-party vendor with access to DoorDash systems via SMS phishing (smishing), then used the stolen credentials to access DoorDash's internal tools and customer data

On August 25, 2022, DoorDash disclosed a data breach caused by a phishing attack against an employee of an unnamed third-party vendor with access to DoorDash's internal systems. …

Cloud [SC]

Signal Third-Party Breach (August 2022)

2022-08-01 [vendor] Twilio
Vector: Compromise of third-party service provider / vendor relationship

Twilio hack exposed Signal phone numbers of 1,900 users. Phone numbers of close to 1,900 Signal users were exposed in the data breach Twilio cloud communications company suffered …

Cryptocurrency

"Multi-Strategy Vault Post-Mortem"

2022-08-01 [vendor] Reaper Farm [loss] $2M [chain] fantom
Vector: Smart contract exploit / hack

Yield farming project Reaper Farm suffered an exploit that resulted in a $1.7 million loss. The attackers discovered a vulnerability that allowed them to withdraw anyone else's …

Other

Nomad Bridge Exploit ($190M Drained, 'Chaotic' Free-for-All)

2022-08-01 [vendor] Nomad cross-chain bridge
Vector: A routine smart contract upgrade introduced a misconfiguration in Nomad's Replica contract — setting the 'trusted root' to 0x00, causing the contract to accept any message as valid; once the initial exploit was noticed on-chain, hundreds of copycat exploiters joined to drain the remaining funds

On August 1, 2022, the Nomad cross-chain bridge was drained of approximately $190 million in a chaotic 'free-for-all' exploit. A recent routine upgrade had inadvertently set the …

Other

"CoinFLEX Update: July 29, 2022"

2022-07-29 [vendor] CoinFLEX layoffs
Vector: Protocol collapse / insolvency

CoinFLEX, a yield farming platform that stopped withdrawals in late June, announced they had made major staff cuts to reduce their cost base by 50–60%. "The intention is to remain …

Other

Tweet thread by Dan Olson

2022-07-27 [vendor] SpiceDAO wraps up

"DAO delusion was at its peak when the community went into this journey together", wrote SpiceDAO founder Soban "Soby" Saqib. SpiceDAO (named for the Dune drug) won an auction to …

Other

Tweet thread by Johnny Lyu

2022-07-26 [vendor] Yes, they have a

Those in the crypto ecosystem have long claimed to embrace the principles of censorship resistance and freedom of speech, but apparently some of them draw the line at speech that's …

Cryptocurrency

"Audius Governance Takeover Post-Mortem 7/23/22"

2022-07-23 [vendor] Audius governance attack [loss] $1M [chain] ethereum
Vector: Governance attack / malicious on-chain proposal

An attacker was able to create and pass a governance proposal to transfer out 18.5 million AUDIO tokens from the community treasury. They then successfully swapped these for 705 …

Cryptocurrency

"Falling Man"

2022-07-23 [vendor] Gamestop NFT platform hosts 9/11 NFT [chain] ethereum

GameStop's brand new NFT platform, which launched on July 12, is off to a less than promising start. Unlike some other NFT platforms like OpenSea, Gamestop does not allow just …

Other

Celsius court docket

2022-07-22 [vendor] Celsius customers send letters to bankruptcy judge
Vector: Protocol collapse / insolvency

Celsius customers have begun to send letters to the judge presiding over Celsius Network's bankruptcy case in the Southern District of New York. More than fifty letters have been …

Cryptocurrency

Tweet by franklinisbored

2022-07-20 [vendor] Franklin joke loss [loss] $150,646 [chain] ethereum

Bored Ape aficionado franklinisbored has apparently found a new source of entertainment by placing high bids on his own ENS domains with amusing names, causing a Twitter bot that …

Other

"Minecraft and NFTs"

2022-07-20

Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …

Other

"Minecraft and NFTs"

2022-07-20 [vendor] Minecraft disallows NFTs

Minecraft is a massively popular sandbox-style video game that had almost 140 million monthly active users as of 2021. Its developer, Mojang Studios, published a blog post …

Cryptocurrency

Tweet by PeckShieldAlert

2022-07-19 [vendor] Raccoon Network and Freedom Protocol [loss] $21M [chain] bsc

20.8 million BUSD, a dollar-pegged stablecoin on BNB Chain, was transferred from Raccoon Network and the Freedom Protocol on July 19. Security firm PeckShield identified the …

Cryptocurrency

Tweet by 0xQuit

2022-07-17 [vendor] PREMINT [loss] $680,800 [chain] ethereum
Vector: Smart contract exploit / hack

PREMINT is an NFT service intended to help project creators build access lists for new NFT projects based on various qualifications. The project was compromised on July 17, and …

Cryptocurrency

Tweet thread by zachxbt

2022-07-14 [vendor] Boneheads [loss] $3M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt has accused the NFT project "Boneheads" of rug pulling only weeks after the project minted in August 2021. Although they promised physical collectibles, more …

Other

Tweet by Betty Boop

2022-07-14 [vendor] Betty Boop NFT announcement
Vector: Ponzi / pyramid scheme

The studio behind Betty Boop decided there was no better time to launch a Betty Boop NFT collection than during a period of record low interest in NFTs (or, more likely, they …

Cryptocurrency

Tweet by PeckShieldAlert

2022-07-11 [vendor] Citizen Finance [loss] $94,300 [chain] polygon, bsc
Vector: Exit scam / rug pull

Citizen Finance, a multichain platform that has something to do with NFTs and blockchain gaming, claimed to have suffered an attack by an outside party who obtained access to a …

Cryptocurrency

Tweet by CZ

2022-07-11 [vendor] Uniswap phishing attack [loss] $8M [chain] ethereum
Vector: Phishing attack

In a successful, broadly-targeted phishing campaign, more than 70,000 addresses connected to Uniswap were airdropped tokens that baited users into approving transactions that …

Other

Rogers Communications Network Outage / Breach — 12 Million Canadians Disrupted

2022-07-08 [vendor] Rogers Communications network infrastructure
Vector: A network maintenance update to Rogers' IP routing policy distributed during a network upgrade caused a cascade failure across Rogers' core network; the failure was a configuration error rather than a cyberattack; the outage took down mobile, internet, and cable services for approximately 12 million Canadian customers

On 8 July 2022, Rogers Communications — Canada's largest telecommunications company serving approximately 12 million wireless customers — suffered a massive network outage that …

Other

Tweet thread by 0x_b1

2022-07-07 [vendor] Former Celsius asset manager accuses them of Ponzi scheme
Vector: Ponzi / pyramid scheme

Jason Stone, founder of the KeyFi company who formerly managed assets for Celsius, filed a complaint against Celsius Network in a New York court, alleging the company was operating …

Other

"Temporary change in withdrawal limits"

2022-07-04 [vendor] CoinLoin limits withdrawals
Vector: Withdrawal halt / insolvency

Claiming that they had no exposure to the various high profile collapses in the crypto industry lately, CoinLoan announced that they nevertheless would be reducing account …

Other

"Corporate statement"

2022-07-04 [vendor] Vauld
Vector: Withdrawal halt / insolvency

Vauld, a major cryptocurrency lender backed by the likes of Coinbase and Peter Thiel, announced they have suspended withdrawals, trading, and deposits due to the crypto market …

Cryptocurrency

Tweet thread by Crema Finance

2022-07-02 [vendor] Crema Finance [loss] $2M [chain] solana
Vector: Smart contract exploit / hack

Solana liquidity protocol Crema Finance was exploited for around 69,500 SOL (~$2.3 million) and around $6.5 million worth of stablecoins for a total loss of around $8.8 million. …

Supply chain [SC]

American Health Imaging, Banner Medical Group, Belle Point Dental, Duck Creek Family Dental, Partners In Periodontics, and 652 organizations Third-Party Breach (July 2022)

2022-07-01 [vendor] Professional Finance Company
Vector: Compromise of third-party service provider / vendor relationship

Ransomware attack one of year's biggest health data breaches. A cyberattack on a little-known debt collection firm affects over 650 healthcare facilities across the U.S. A …

Supply chain [SC]

Arlington Skin Third-Party Breach (July 2022)

2022-07-01 [vendor] Virtual Private Network Solutions
Vector: Compromise of third-party service provider / vendor relationship

First Choice Community Healthcare Data Breach Affects 101,000 Patients. First Choice Community Healthcare in Albuquerque, NM, has started notifying certain patients that an …

Supply chain [SC]

Celsius Third-Party Breach (July 2022)

2022-07-01 [vendor] Customer.io
Vector: Compromise of third-party service provider / vendor relationship

Blockworks. $72.1K $72,120.00 $2.2K $2,214.14 $602.5 $602.46 $84 $83.95 $41.4 $41.37. 24hr Spot DEX Volume $6.03B -0.75%24hr App Revenue $11.81M -0.01%24hr Blockchain REV $229.96M …

Cryptocurrency

"Two Polygon, Fantom Front Ends Hit by DNS Attack"

2022-07-01 [vendor] Ankr [chain] polygon, fantom
Vector: DNS hijacking / domain takeover (front-end compromise)

The Ankr public RPC gateways (basically an API for dApps and other services to communicate with the blockchain) for Polygon and Fantom were impacted when attackers compromised the …

Cryptocurrency

"Voyager Digital Provides Market Update"

2022-07-01 [vendor] Voyager Digital suspends withdrawals [chain] bitcoin
Vector: Withdrawal halt / insolvency

Voyager Digital announced that they had suspended trading, deposits, withdrawals, and loyalty rewards. This came after it was revealed that Voyager had issued a notice of default …

Cryptocurrency

Web3 Is Going Great

2022-06-30 [vendor] Coca-Cola Pride Bottle #8 [chain] polygon

If it wasn't already nauseating to watch a huge corporation like Coca-Cola use LGBTQ Pride Month to market their products and pay lip service to supporting LGBTQ rights while …

Other

Tweet by KenneyNL

2022-06-29 [vendor] w3itch.io steals website code and games

A somewhat blundering group of developers decided to create "w3itch.io", an online marketplace for game creators. The marketplace said it was intended to be friendly to games …

Data leak

Tweet thread by PeckShield

2022-06-26 [vendor] XCarnival [loss] $2M
Vector: Smart contract exploit / hack

XCarnival is a project describing itself as a "metaverse asset bank". The project drew in users by promising high rewards, with one marketing campaign promising 41% APY.A hacker …

Other

"The Way Forward"

2022-06-24 [vendor] Bitpanda layoffs

The Austrian cryptocurrency exchange Bitpanda joined the recent litany of crypto companies laying off employees. In an announcement to staff, later shared publicly, the company …

Cryptocurrency

Tweet thread by Harmony

2022-06-23 [vendor] Horizon Bridge [loss] $100M [chain] bsc, ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

The Horizon Bridge is a blockchain bridge allowing assets to be used across Ethereum, BNB, and Harmony blockchains. The bridge is run by the Harmony blockchain project.On June 23, …

Other

"Update on withdrawals"

2022-06-23 [vendor] CoinFLEX
Vector: Withdrawal halt / insolvency

Yield farming platform CoinFLEX is the latest crypto platform to stop allowing customers to withdraw their money. Customers had raised concerns about withdrawals not processing, …

Other

RFIA bill

2022-06-23 [vendor] Lummis and Gillibrand solicit feedback on bill via Github
Vector: Regulatory / legal action

After announcing their crypto-friendly proposed legislation earlier in June, Senators Lummis and Gillibrand have uploaded it to Github to solicit feedback, as was apparently widely …

Cryptocurrency

Tweet by Daniel Hong

2022-06-20 [vendor] Terraforms Labs employees banned from leaving Korea [chain] terra
Vector: Regulatory / legal action

A former employee of Terraform Labs, the company behind the Terra project that collapsed in May, found that he was banned from leaving the country. According to the former …

Other

Tweet thread by Wu Blockchain

2022-06-20 [vendor] Bybit plans layoffs

Bybit, a Dubai-based cryptocurrency exchange, is reportedly joining the group of crypto companies laying off employees amidst plummeting cryptocurrency markets. Journalist Colin Wu …

Cryptocurrency

Tweet by OKHotshot

2022-06-19 [vendor] Lacoste Discord [chain] ethereum
Vector: Smart contract exploit / hack

So, apparently polo shirts have NFTs now. Fashion brand Lacoste's NFT project is titled "Undw3", which is apparently supposed to be pronounced "underwater" — I guess if you say the …

Cryptocurrency

"SLND1: Mitigate Risk From Whale"

2022-06-19 [vendor] Solend DAO passes proposal to take over account [chain] solana

Solend DAO, the DAO behind the Solend lending protocol on Solana, just passed its first ever governance proposal. A whale used their platform to take out an enormous margin …

Other

"Announcement of Withdrawl on Hoo"

2022-06-19 [vendor] Hoo
Vector: Withdrawal halt / insolvency

The Hong Kong-based cryptocurrency exchange Hoo announced that they would be pausing withdrawals, after so many customers tried to withdraw their crypto that they began to run out …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-06-16 [vendor] Inverse Finance [loss] $6M [chain] ethereum
Vector: Flash loan attack on smart contract

A hacker was able to perform an oracle manipulation attack enabled by flash loans to siphon crypto worth around $1.26 million from Inverse Finance. The loss to the protocol was …

Other

Twitter thread by Danny 8BC

2022-06-15 [vendor] 8 Blocks Capital calls to freeze Three Arrows Capital funds

8 Blocks Capital is a Hong Kong-based trading firm. In a Twitter thread, Danny Yuan explained that 8BC had been using 3AC's trading accounts to reduce their trading fees. He wrote, …

Data leak

Tweet by KnownOrigin

2022-06-14 [vendor] Known Origin Discord compromise
Vector: Smart contract exploit / hack

The Discord server for Known Origin, a fairly major NFT platform, was compromised. The scammer used their access to advertise a fake free NFT mint, which actually would steal NFTs …

Other

Twitter thread by Tim Connors

2022-06-14 [vendor] Merit DAO votes to renege on deal

Members of the Merit DAO, a DAO operating in the play-to-earn space, voted on proposals renege on a deal signed with an early investor to the DAO, Yield Guild Games (YGG). The …

Cryptocurrency

Tweet by Flip McBot

2022-06-13 [vendor] NFT collector sells at huge loss [chain] ethereum

In October 2021, an NFT collector dropped 300 ETH (then $1.05 million) on CrypToadz #2155, a pixel art image of a blue toad skeleton on a blue background. On June 13, they sold the …

Cryptocurrency

Tweet thread by SmallCapScience

2022-06-12 [vendor] stETH [chain] ethereum

Lido-staked ETH, a project that offers to allow users to stake ETH for the purposes of securing it after the Ethereum "merge" — that is, the ever-delayed move to proof-of-stake. …

Other

"A Memo to the Celsius Community"

2022-06-12 [vendor] Celsius
Vector: Withdrawal halt / insolvency

The Celsius platform announced that they would be pausing all withdrawals, swaps, and transfers due to "extreme market conditions".There has been a lot of concern lately about …

Data leak

Tweet by NFTherder

2022-06-09

Scammers successfully compromised the Twitter account for El Universal, a Venezuelan newspaper. The account is verified, and has five million followers. The scammers used the …

Cryptocurrency

Tweet by NFTherder

2022-06-09 [vendor] El Universal Twitter account [loss] $30,000 [chain] ethereum
Vector: Smart contract exploit / hack

Scammers successfully compromised the Twitter account for El Universal, a Venezuelan newspaper. The account is verified, and has five million followers. The scammers used the …

Cryptocurrency

Tweets by Offline Cash

2022-06-09 [vendor] Offline Cash project announcement [chain] bitcoin

Some crypto advocates have long promoted crypto as a proper digital equivalent to cash. Physical dollars have a lot of benefits, including that you don't need a bank account to use …

Cryptocurrency

Tweet by ApolloX

2022-06-08 [vendor] ApolloX exchange attack [loss] $2M [chain] bsc
Vector: Smart contract exploit / hack

The ApolloX exchange suffered an exploit where an attacker was able to withdraw around 40 million $APX, which they were able to swap for around $1.5 million. This also caused the …

Cryptocurrency

Tweet by PeckShieldAlert

2022-06-08 [vendor] Baby Elon coin [loss] $178,994 [chain] bsc
Vector: Exit scam / rug pull

The Baby Elon project on BNBChain rug pulled on June 8, with the token price plummeting 98% as the team withdrew 623 BNB (~$179,000) from the project. They quickly moved the funds …

Cryptocurrency

Tweet by PeckShield Inc.

2022-06-08 [vendor] GYM Network [loss] $2M [chain] bsc
Vector: Software bug / unintentional loss

Attackers stole around $2.1 million from the GYM Network defi project after exploiting a bug in a recently-deployed contract that failed to check the identity of the caller. The …

Cryptocurrency

"Republican Rep. Madison Cawthorn failed to properly disclose 2-dozen more cryptocurrency trades, including 'Let's Go Brandon' coin, bitcoin, and ethereum"

2022-06-08 [vendor] Madison Cawthorn belatedly reports trades [chain] ethereum, bitcoin, solana
Vector: Regulatory / legal action

Representative Madison Cawthorn (R-NC) is facing an ethics investigation pertaining to his involvement with the Let's Go Brandon coin, which includes allegations of insider trading …

Cryptocurrency

Thread by zachxbt

2022-06-08 [vendor] Players Only NFT [loss] $1M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto-sleuth zachxbt reported on June 8 that Players Only, and NFT project created by a group of NBA players including Michael Carter-Williams and Jerami Grant, appears to be a …

Cryptocurrency

Tweet by Yung Ape Squad

2022-06-06 [vendor] Early June 2022 Discord compromises [loss] $243,000 [chain] ethereum
Vector: Phishing attack

The June 4 compromise of the Bored Apes Discord was only one of several Discord hacks in a several-day period. All the attacks appeared to involve user accounts of individual …

Cryptocurrency

Thread by CertiK Alert

2022-06-04 [vendor] Bored Apes Discord compromise [loss] $250,000 [chain] ethereum
Vector: Smart contract exploit / hack

Scammers were able to compromise the Discord account of a Bored Apes community manager, then use it to post an announcement of an "exclusive giveaway" to anyone who held a Bored …

Cryptocurrency

Tweet by topshotkief

2022-06-04 [vendor] topshotkief NFT theft [loss] $365,000 [chain] ethereum
Vector: Smart contract exploit / hack

An NFT collector hoping to claim NFTs from the Goblintown collection was phished, resulting in ten of their NFTs being stolen from them. The scammers took two Mutant Ape NFTs and …

Cryptocurrency

Tweet thread by zachxbt

2022-06-02 [vendor] Animoon [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Animoon is yet another Pokémon rip-off NFT project, with artwork that was ripped directly from Pokémon artwork and recolored. They claim to have a "signed NDA" with Pokémon …

Cryptocurrency

Tweet thread by FedorLinnik

2022-06-02 [vendor] Goblin Asses project preempted [chain] ethereum

Hoping to riff off the popularity of the recent and weird Goblintown NFT project, some NFT enthusiasts decided to make their own "Goblin Asses" project, which is exactly what it …

Other

"Tiger Incident Analysis"

2022-06-02 [vendor] Forest Tiger Pro [loss] $5M
Vector: Exit scam / rug pull

The TIGER project was supposed to be a DAO aiming to "support global technical teams" and protect wild animals and the environment. The project was broad-ranging, and had NFT, …

Supply chain [SC]

Baptist Health System, Resolute Health Hospital, The Hospitals of Providence Memorial Campus, Valley Baptist Medical Center – Brownsville, Valley Baptist Medical Center – Harlingen Third-Party Breach (June 2022)

2022-06-01 [vendor] Conifer Revenue Cycle Solutions
Vector: Compromise of third-party service provider / vendor relationship

Not Found. Best in Class Identity Protection Services | ID Theft Protection | IDX. Best identity protection services to keep you safe from cyber crime with credit and identity …

Supply chain [SC]

OpenSea Third-Party Breach (June 2022)

2022-06-01 [vendor] Customer.io
Vector: Compromise of third-party service provider / vendor relationship

OpenSea users' email addresses leaked in data breach. If you’ve shared your email address with the NFT marketplace, you should assume to be impacted. The company is working with …

Supply chain [SC]

Priority Health Third-Party Breach (June 2022)

2022-06-01 [vendor] Warner Norcross & Judd
Vector: Compromise of third-party service provider / vendor relationship

120K Priority Health Members Impacted By Third-Party Data Breach | TechTarget. Michigan-based health plan Priority Health notified 120,000 individuals of a third-party data breach …

Credential theft

Marriott International 2022 Social Engineering Breach — 20GB Data Stolen

2022-06-01 [vendor] Marriott International employee workstation / local property data
Vector: Attacker used social engineering to trick a Marriott employee at a Maryland property into granting remote access to their workstation; once access was established, approximately 20GB of data was exfiltrated over a period prior to detection

In June 2022, Marriott International suffered its third significant data breach in four years (after the 2018 Starwood breach affecting 383M guests and the 2020 employee credential …

Cloud [SC]

TechCrunch / The Register / Group-IB (0ktapus research)

2022-06-01 [vendor] Twilio Communications Platform
Vector: CWE-1021: Improper Restriction of Rendered UI Layers (SMS phishing / smishing with real-time OTP relay to fake login page)

Twilio employees received smishing SMS impersonating IT dept claiming password expiry. Employees entered credentials on fake Twilio login page with real-time MFA relay bypassing …

Cryptocurrency

OpenSea transaction history

2022-06-01 [vendor] Bored Ape typo [chain] ethereum

NFT collector onekiller purchased Bored Ape #7256 for 188 ETH a month ago — at the time worth about $513,000. On June 1, they sold the ape for 0.088 ETH, or $161.It's not quite …

Cryptocurrency

Tweet by CryptoWhale

2022-06-01 [vendor] Solana outage [chain] solana

Solana is one of the more popular proof-of-stake blockchains, and is often trotted out as an alternative to Ethereum when people bring up Ethereum's environmental impact, slowness, …

Other

Press release

2022-06-01 [vendor] OpenSea insider trader arrested
Vector: Regulatory / legal action

Nate Chastain was asked to resign from his position as Head of Product at OpenSea in September 2021 following allegations of NFT insider trading. Online sleuths had discovered that …

Cryptocurrency

Tweet by nftmetaman.eth

2022-05-30 [vendor] Bored Ape typo [loss] $181,000 [chain] ethereum

An NFT collector trying to list their Bored Ape NFT for sale on OpenSea made a typo, and accidentally listed it for sale for 10 ETH (around $19,000) instead of 105 ETH (around …

Cryptocurrency

Tweet thread by FatMan

2022-05-30 [vendor] Mirror Protocol [loss] $2M [chain] terra
Vector: Software bug / unintentional loss

Someone has been able to drain more than $2 million from the Mirror Protocol in the Terra ecosystem. It appears they are exploiting an issue with the price oracle for "Luna …

Cryptocurrency

Tweet by RugPull Finder

2022-05-30 [vendor] Superlative Apes [loss] $3M [chain] ethereum
Vector: Exit scam / rug pull

The Superlative Apes NFTs are a collection of Bored Apes derivative NFTs that feature colorful pastels. The project amassed a large following (including, apparently, the rapper …

Cryptocurrency

Tweet by PINKCATNFT

2022-05-30 [vendor] Toronto Comic Arts Festival NFT artist controversy [chain] ethereum

The Toronto Comic Arts Festival angered artists and fans alike when they invited Saba Moeel, the artist behind the Pink Cat NFT collection, to attend as a featured guest. This was …

Cryptocurrency

Tweet thread by FatMan

2022-05-28 [vendor] Luna 2.0 [chain] terra

All holders of Luna, who saw their holdings crash to nothing in the Terra collapse, received an airdrop of the new Luna tokens with the release of Terra 2.0 (electric boogaloo). …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-27 [vendor] PokeMoney [loss] $4M [chain] bsc
Vector: Exit scam / rug pull

The token associated with yet another crypto Pokémon rip-off, PokeMoney, suddenly crashed in price when around 11,800 BNB ($3.5 million) worth of it was pulled out of the project. …

Cryptocurrency

Thread by FatMan

2022-05-26 [vendor] Mirror Protocol vulnerability [loss] $88M [chain] terra
Vector: Smart contract exploit / hack

A crypto researcher who goes by "FatMan" discovered that the Mirror Protocol in the Terra ecosystem contained a serious vulnerability, that was quietly patched with no announcement …

Cryptocurrency

Tweet thread by Terra

2022-05-25 [vendor] Terra 2.0 announcement [chain] terra

Following the dramatic collapse of Terra earlier this month, the Terra ecosystem voted to pass a proposal by Do Kwon to create "Terra 2.0". The project intends to "effectively …

Credential theft

Cisco Yanluowang Ransomware Attack — Employee Google Account and VPN Breach

2022-05-24 [vendor] Cisco corporate network / VPN
Vector: Yanluowang ransomware affiliate gained access to a Cisco employee's personal Google Chrome profile that had Cisco VPN credentials saved; the employee's personal Google account was compromised, exposing the saved credentials; the attacker then conducted extensive MFA push fatigue attacks and vishing calls impersonating Cisco IT support to convince the employee to approve MFA push notifications

On 24 May 2022, a Yanluowang ransomware affiliate (linked to UNC2447/Lapsus$ connections) compromised Cisco Systems through a combination of credential theft from a personal Google …

Cryptocurrency

Tweet by CertiK Alert

2022-05-24 [vendor] DecentraWorld [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The creators of the Decentraworld project, and its associated $DEWO token, rug pulled for 3127 BNB, valued at just over $1 million. The project promised an "ecosystem of dapps with …

Cryptocurrency

Tweet by CirrusNFT

2022-05-24 [vendor] Digital Ornithologist NFT theft [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

A scammer was able to trick a prolific NFT collector into signing a transaction on a fake trading website, which then allowed them to maliciously transfer 29 pricey Moonbirds NFTs …

Cryptocurrency

Tweet thread by sniko

2022-05-22 [vendor] Beeple Twitter [loss] $438,000 [chain] ethereum
Vector: Smart contract exploit / hack

Attackers gained control of the Twitter account belonging to Beeple, an artist known for "selling" an NFT for $69 million in March 2021 and for his recent horror-inducing NFT …

Cryptocurrency

Tweet thread by TheJonnyReid

2022-05-22 [vendor] Johnny Reid wallet [loss] $203,000 [chain] ethereum
Vector: Phishing attack

Crypto speculator Jonny Reid wrote on May 22 that his crypto wallet had been hacked and drained of approximately $203,000. He wrote that he had never owned a hardware wallet before …

Cryptocurrency

Tweet thread by 0xngmi

2022-05-22 [vendor] Milady founders controversy [chain] ethereum

The founder of the Remilia Collective and its popular "Milady Maker" NFT project, "Charlotte Fang", was discovered to have been a key player in a white supremacist cult known as …

Other

HUMBL lawsuit

2022-05-20 [vendor] HUMBL class action
Vector: Regulatory / legal action

A litigation firm filed a class action lawsuit against HUMBL, a financial services company that touts its web3 and defi products. The lawsuit alleges that HUMBL and its executives …

Cryptocurrency

Reptilian Renegade Twitter account

2022-05-19 [vendor] Reptilian Renegades [chain] solana
Vector: Exit scam / rug pull

The serial rug-puller who was behind the Balloonsville rug pull in February and Doodled Dragons rug pull in January has popped up once again, this time with a Solana NFT project …

Cryptocurrency

Tweet thread by FatMan

2022-05-19 [vendor] Stablegains [loss] $44M [chain] terra
Vector: Regulatory / legal action

A class action law firm sent a letter to the yield generation project Stablegains, demanding records on customer accounts, marketing and advertising strategies, and communications …

Data leak

Tweet by QANplatform

2022-05-18 [vendor] QAN bridge [loss] $707,000
Vector: Smart contract exploit / hack

The $QANX token for the QAN project suddenly plummeted in value as an attacker stole more than 4 million QANX from the project. The attacker subsequently swapped the tokens for …

Data leak

Tweet by QANplatform

2022-05-18

The $QANX token for the QAN project suddenly plummeted in value as an attacker stole more than 4 million QANX from the project. The attacker subsequently swapped the tokens for …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-18 [vendor] "Feminist Metaverse" token [loss] $533,000 [chain] bsc
Vector: Smart contract exploit / hack

The "Feminist Metaverse" ($FM) token suddenly plunged in value by 99.7% after an attacker stole 1,838 BNB ($533,000). The hacker quickly transferred the stolen funds to the Tornado …

Data leak

Tweet by PeckShieldAlert

2022-05-17 [vendor] Multiple Discords compromised
Vector: Smart contract exploit / hack

Members of several large NFT Discord servers began seeing suspicious-looking messages announcing supposed NFT mints that turned out to be fakes. Affected communities appeared to …

Cryptocurrency

Tweet by Seth Green

2022-05-17 [vendor] Seth Green NFT theft [loss] $300,000 [chain] ethereum
Vector: Phishing attack

Actor Seth Green tweeted that he had been targeted with a phishing attack that resulted in the theft of four pricey NFTs: a Bored Ape, two Mutant Apes, and a Doodle. The thief …

Cryptocurrency

Tweet thread by CZ

2022-05-16 [vendor] CZ tweets about Binance's Terra/Luna holdings [chain] terra

On May 15, Binance CEO Changpeng Zhao (widely known as CZ) created a tweet thread in which he attempted to speak nonchalantly about questions that had "just occurred to [him]" …

Cryptocurrency

Tweet thread by CertiKAlert

2022-05-15 [vendor] "Feed Every Gorilla" token [loss] $2M [chain] ethereum, bsc
Vector: Flash loan attack on smart contract

A flash loan attack on the "Feed Every Gorilla" (FEG) token swap contracts pulled $1.3 million from the project, also tanking the token price by 80%. The project operates on both …

Cryptocurrency

"LUNA Trading Incident on Crypto.com App"

2022-05-13 [vendor] Crypto.com reverses Luna trades [chain] terra
Vector: Oracle price manipulation

One of the features of crypto that its proponents sometimes highlight is that transactions can't be reversed. This, of course, is not true when making trades on exchanges like …

Cryptocurrency

Tweet thread by Spirit Swap

2022-05-13 [vendor] SpiritSwap domain hijacking attack [loss] $18,000 [chain] fantom
Vector: DNS hijacking / domain takeover (front-end compromise)

In what is beginning to become a pattern, SpiritSwap was the latest project where attackers gained control of their domain and were able to modify the frontend to divert funds to a …

Cryptocurrency

Tweet by Terra

2022-05-12 [vendor] Terra blockchain halted [chain] terra
Vector: Governance attack / malicious on-chain proposal

After $LUNA dropped below $0.01, Terra announced that they halted the Terra blockchain. "Terra validators have decided to halt the Terra chain to prevent governance attacks …

Cryptocurrency

"Venus Protocol Official Statement regarding LUNA"

2022-05-12 [vendor] Terra oracle attacks [loss] $22M [chain] terra, avalanche, bsc
Vector: Smart contract exploit / hack

Earlier today, Terra halted their blockchain after a devastating few days. Subsequently, Chainlink's oracle paused the price feed, causing it to fall out of sync with the apparent …

Cryptocurrency

Luna/USD

2022-05-11 [vendor] Terra ($LUNA) to USD from April 11–May 11 [chain] terra
Vector: Protocol collapse / insolvency

Terraform Labs develops two cryptocurrencies: TerraUSD ($UST), an algorithmic stablecoin meant to be pegged to the U.S. dollar, and $LUNA, a crypto asset used both for speculation …

Other

Coinbase 05/10/2022 Form 10-Q

2022-05-10 [vendor] Coinbase adds bankruptcy language to quarterly report

Coinbase added new language to its latest 10-Q, a quarterly report submitted by public companies to the SEC. In the section outlining risks to the business, Coinbase wrote: …

Cryptocurrency

"A Builder’s Journey"

2022-05-09 [vendor] Azuki #2821 [chain] ethereum
Vector: Exit scam / rug pull

In a blog post titled "A Builder's Journey", the founder of the popular Azuki NFT project admitted that he had also been behind the NFT projects CryptoPhunks (note the "h"), …

Cryptocurrency

Tweet by PeckShieldAlert

2022-05-09 [vendor] G.O.A.T. token [loss] $260,956 [chain] ethereum

The G.O.A.T. ("Greatest of all Tokens") project claimed to be "the new standard in cryptocurrency", with vague claims that it would "add value by addressing scalability and risk …

Cryptocurrency

TerraUSD/USD on CoinMarketCap

2022-05-09 [vendor] Terra/Luna [loss] $40.0B [chain] terra
Vector: Protocol collapse / insolvency

It's been a rough few days for TerraUSD, one of several popular stablecoins pegged to the US dollar. Unlike many stablecoins like Tether or USDC, Terra is an algorithmic …

Cryptocurrency

Archived Cashera website

2022-05-08 [vendor] Cashera [loss] $89,200 [chain] bsc

Cashera was a project claiming to provide a "banking revolution" with its CSR crypto token. The project did many things to try to appear legitimate, including linking to government …

Cryptocurrency

Tweet thread by Jetfuel Finance

2022-05-08 [vendor] Fortress Protocol [loss] $3M [chain] ethereum
Vector: Oracle price manipulation

An attacker was able to steal 1,048 ETH (~$2.65 million) and 400,000 DAI from the Fortress Protocol borrowing and lending platform in what appears to have been an oracle …

Cryptocurrency

Tweet thread by CertiKAlert

2022-05-08 [vendor] Hunter [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

Under the pretense of a contract upgrade, the Hunter defi project team drained the liquidity from the project, swapping the tokens for assets worth around $1.2 million. The team …

Cryptocurrency

Tweet by Rug Pull Finder

2022-05-07 [vendor] Fury of the Fur [loss] $303,000 [chain] ethereum

The Fury of the Fur NFT project was a collection of 3D models that sort of resembled bears. The project advertised that the models were "metaverse and game-ready", and the roadmap …

Cryptocurrency

Thread by CertiKAlert

2022-05-06 [vendor] Day of Defeat [loss] $1M [chain] bsc
Vector: Exit scam / rug pull

The token associated with the Day of Defeat project, which describes itself as a "radical social experiment token mathematically designed to give holders 10,000,000X PRICE …

Cryptocurrency

Tweet by CertiK Alert

2022-05-05 [vendor] Pragma [loss] $2M [chain] fantom
Vector: Exit scam / rug pull

The Pragma defi project on the Fantom blockchain announced that their treasury and project wallets had been drained for around $1.5 million in $FTM.The rug pull appeared to have …

Cryptocurrency

Tweet by MM.Finance

2022-05-04 [vendor] MM.Finance [loss] $2M [chain] cosmos, ethereum
Vector: DNS hijacking / domain takeover (front-end compromise)

MM.Finance, a group of crypto projects based on the Cronos blockchain, suffered an attack that allowed a hacker to redirect more than $2 million worth of crypto assets that were …

Other

Web3 Is Going Great

2022-05-04 [vendor] ape holders can use multiple slurp juices on a single ape

a lotta yall still dont get itape holders can use multiple slurp juices on a single apeso if you have 1 astro ape and 3 slurp juices you can create 3 new apesTonight's slurp juice …

Other

"NFT Sales Are Flatlining"

2022-05-03 [vendor] NFT sales down 92%

The Wall Street Journal reported that "the NFT market is collapsing", citing data from NonFungible that showed daily average sales of NFTs had dropped 92% from their September …

Supply chain [SC]

EvergreenHealth Third-Party Breach (May 2022)

2022-05-01 [vendor] MyCare
Vector: Compromise of third-party service provider / vendor relationship

Illinois Gastroenterology Group Data Breach Impacts 228K | TechTarget. Optima Dermatology, EvergreenHealth, and SAC Health also faced healthcare data breaches recently. Illinois …

Supply chain [SC]

K12 Schools in NY Third-Party Breach (May 2022)

2022-05-01 [vendor] Illuminate Education
Vector: Compromise of third-party service provider / vendor relationship

Illuminate Education Mega-Breach Affects K-12 Students. New York state officials are investigating a data breach at Illuminate Education, maker of a widely used software platform …

Supply chain [SC]

Mangatoon Third-Party Breach (May 2022)

2022-05-01 [vendor] Elasticsearch
Vector: Compromise of third-party service provider / vendor relationship

Mangatoon data breach exposes data from 23 million accounts. Manga comic reading app Mangatoon has suffered a data breach that exposed the account information of 23 million users …

Supply chain [SC]

St. Luke's Third-Party Breach (May 2022)

2022-05-01 [vendor] Kaye-Smith
Vector: Compromise of third-party service provider / vendor relationship

St. Luke's says customers hit with data breach that may have exposed personal, financial, medical information. St. Luke’s Health System issued a news release Wednesday saying an …

Cryptocurrency

Tweet thread by BlockSec

2022-04-30 [vendor] Fei Protocol [loss] $80M [chain] ethereum
Vector: Smart contract exploit / hack

A hacker attacked multiple Rari liquidity pools relating to the Fei Protocol, exploiting a known re-entrancy vulnerability that exists on forks of the Compound protocol. The …

Cryptocurrency

Tweet thread by Molly White

2022-04-30 [vendor] Otherside launch spikes gas fees [chain] ethereum

The much-awaited Bored Ape Yacht Club "Otherside" metaverse land sale began, and its popularity just about wrecked Ethereum for everyone else. Gas fees, which increase based on …

Cryptocurrency

Tweet thread by zachxbt

2022-04-30 [vendor] Otherside phishing sites [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

In what should surprise nobody, some of the historically phishing-prone fans of the pricey Bored Apes project fell for scams that pretended to be the Bored Apes' new land project, …

Cryptocurrency

Tweet thread by PeckShield

2022-04-30 [vendor] Saddle Finance [loss] $11M [chain] ethereum
Vector: Flash loan attack on smart contract

An exploiter used a flash loan attack to pull 3,933 ETH (~$11 million) from the "decentralized automated market maker" Saddle Finance. Shortly after the attack, the hacker began …

Cryptocurrency

Tweet thread by Solana Status

2022-04-30 [vendor] Solana outage [chain] solana

On April 30, NFT minting bots began flooding the Solana network with 4 million transactions per second, causing the network to lose consensus. The project tweeted that "Engineers …

Cryptocurrency

Tweet by OxQuit

2022-04-30 [vendor] Teenage Mutant Ninja Turtles project buys forged contract [chain] ethereum
Vector: Exit scam / rug pull

A project to create Teenage Mutant Ninja Turtles NFTs stirred up a lot of excitement, garnering more than 100,000 Twitter followers on a verified Twitter account that described …

Cryptocurrency

Tweet thread by PeckShield Inc.

2022-04-28 [vendor] Deus Finance [loss] $13M [chain] fantom
Vector: Flash loan attack on smart contract

The defi project Deus Finance was hit with a flash loan attack that netted the hacker $13.4 million. The loss to the protocol was likely larger than what the hacker was able to …

Cryptocurrency

Twitter thread by JennieCuteCat

2022-04-27 [vendor] Fake Louis Vuitton project [chain] ethereum
Vector: Smart contract exploit / hack

Scammers created a project on OpenSea with Louis Vuitton branding, which invited individuals to visit an external site to mint exclusive NFTs. They placed a blue checkmark on the …

Ransomware

Yuma Regional Medical Center Ransomware — 700K Patients, Arizona

2022-04-25 [vendor] Yuma Regional Medical Center hospital IT systems
Vector: Ransomware group breached Yuma Regional Medical Center's network, gaining access to systems containing patient information; the specific initial access vector was not publicly disclosed

On 25 April 2022, Yuma Regional Medical Center (YRMC) — the primary regional hospital for southwestern Arizona serving Yuma, Arizona and surrounding areas — discovered a ransomware …

Cryptocurrency

Tweet by Bored Ape Yacht Club

2022-04-25 [vendor] Bored Apes Instagram [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Bored Ape Yacht Club's Instagram account was compromised and used to advertised a fake airdrop for metaverse land. This was particularly believable, as the much-anticipated …

Cryptocurrency

Tweet thread by 0xfoobar

2022-04-22 [vendor] AkuDreams bug [loss] $34M [chain] ethereum
Vector: Software bug / unintentional loss

Micah Johnson, an artist and former professional baseball player, launched an astronaut-themed NFT project called AkuDreams. The auction was based around a Dutch auction, with the …

Cryptocurrency

Tweet thread by Molly White

2022-04-22 [vendor] Epoch Times writers send crypto mailer [chain] bitcoin

Bob Byrne and Tim Collins, two prolific contributors to the far-right Epoch Times, have expanded their grift to crypto. A twenty-page-long "newspaper" titled Wall Street Today …

Cryptocurrency

Web3 Is Going Great

2022-04-20 [vendor] Binance Twitter branded hashtag looks like a swastika [chain] bsc

Binance, the world's largest crypto exchange, used Twitter's branded hashtag feature to add a custom emoji to Twitter when people use the hashtags #Binance or #BNB. The hashtag …

Cryptocurrency

Tweet thread by zachxbt

2022-04-20 [vendor] Rogue Society [loss] $6M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Rogue Society NFT project launched in September, with an ambitious roadmap that included a theme song, comic book series, 3D figurines, an augmented reality app, and an …

Cryptocurrency

Tweet thread by SlowMist

2022-04-20 [vendor] Terra Google ad phishing [loss] $4M [chain] terra
Vector: Seed phrase / wallet compromise

Scammers ran Google ads for popular search queries relating to the Terra ecosystem. When users searched for things like "Anchor protocol" or "Astroport", the first result was …

Data leak

Tweet thread by CertiK Alert

2022-04-19 [vendor] $CHEDDA [loss] $1M
Vector: Smart contract exploit / hack

The price of the $CHEDDA token suddenly plummeted 50% when a developer removed $1.17 million from the project. The withdrawal was accomplished with a function only available to …

Cryptocurrency

Tweet thread by 0x_fxnction

2022-04-19 [vendor] 0x_fxnction wallet compromise [loss] $240,000 [chain] solana
Vector: Smart contract exploit / hack

NFT influencer 0x_fxnction reported that his wallet had been compromised, and 2349 SOL (~$240,000) had been stolen. The money had primarily been profit from the DeGods project, he …

Cryptocurrency

Tweet thread by zachxbt

2022-04-19 [vendor] Rich Bulls Club [loss] $4M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Crypto sleuth zachxbt researched the Rich Bulls Club, an NFT project that launched in December with NFTs priced at 0.3 ETH (~$1,350) a pop. The project included a clause where …

Cryptocurrency

Tweet by CertiKAlert

2022-04-18 [vendor] 2omb and Redemption [loss] $189,625 [chain] fantom
Vector: Flash loan attack on smart contract

Redemption provides the liquidity pools for 2omb, a Fantom-based algorithmic stablecoin project with big promises: "What if you could invest in a golden goose? Something you can …

Cryptocurrency

Tweet thread by Domenic Iacovone

2022-04-18 [vendor] MetaMask iCloud backup vulnerability [loss] $650,000 [chain] ethereum
Vector: Phishing attack

Some MetaMask users using iOS were shocked to discover that their MetaMask credentials were automatically being stored to iCloud today, after MetaMask acknowledged this was the …

Cryptocurrency

Tweet thread by CertiK Alert

2022-04-17 [vendor] Beanstalk Farms [loss] $182M [chain] ethereum
Vector: Flash loan attack on smart contract

All my magic beans gone. An attacker successfully used a flash loan attack to exploit a flaw in Beanstalk Farms' stablecoin protocol, which allowed them to make off with 24,830 ETH …

Cryptocurrency

Tweet thread by zachxbt

2022-04-16 [vendor] Moonbirds Sybil attack [chain] ethereum

The NFT project "Moonbirds" generated so much hype that they implemented a raffle system for the many people who hoped to get on the project's allowlist, hoping to make it more …

Cryptocurrency

Tweet by PeckShield

2022-04-15 [vendor] Rikkei Finance [loss] $1M [chain] bsc
Vector: Smart contract exploit / hack

Rikkei Finance, which describes itself as a metaverse defi project, was apparently exploited. 2,571 BNB, priced at around $1.07 million, was transferred out of the protocol and …

Cryptocurrency

Announcement tweet

2022-04-14 [vendor] Archieverse NFT announcement [chain] ethereum

Archie Comics announced they would be launching an NFT project called "Archieverse", which centers around their spooky "Madam Satan" character and invites people to "unlock the …

Cryptocurrency

Tweet thread by zachxbt

2022-04-14 [vendor] The Real Tarzann [loss] $700,000 [chain] ethereum
Vector: Exit scam / rug pull

Influencer, conservationist, and exotic animal whisperer "The Real Tarzann" (a.k.a. Mike Holston) announced in October 2021 his plans for an NFT project called "Tribes of Ogun". …

Cryptocurrency

Tweet thread by TheBreadMakerr

2022-04-14 [vendor] Unicorn Nodes [loss] $129,000 [chain] avalanche
Vector: Exit scam / rug pull

Unicorn Nodes claimed to be a "defi-as-a-service" project. It launched its $RNBW token on April 14, despite warnings from "TheBreadmaker", who rates various protocols. Only hours …

Cryptocurrency

Tweet by Tim Beiko

2022-04-13 [vendor] Ethereum delays proof-of-stake [chain] ethereum

For years now, Ethereum has been talking about a transition from its energy-intensive, expensive proof-of-work consensus model to a proof-of-stake consensus model, which sports a …

Cryptocurrency

Tweet thread by Tanner Woodworth

2022-04-13 [vendor] Fake SkyVerse project [loss] $153,050 [chain] ethereum
Vector: Smart contract exploit / hack

A scammer recreated the Twitter account for SkyVerse, a much-anticipated NFT land project due to launch in "mid-April". More than 250 NFT collectors eager to get in on a mint that …

Other

Lifshitz Law Firm, P.C. Announces Investigations of Cassava Sciences, Inc. (NASDAQCM: SAVA), Coinbase Global, Inc. (NASDAQGS: COIN), HyreCar, Inc. (NASDAQCM: HYRE), and Longeveron Inc. (NASDAQCM: LGVN)

2022-04-13 [vendor] Coinbase class action lawsuit filed
Vector: Regulatory / legal action

A group of shareholders have filed a class-action lawsuit against Coinbase, alleging that the registration and prospectus statements provided for the company's IPO were false and …

Cryptocurrency

Tweet by PeckShieldAlert

2022-04-12 [vendor] Elephant Money [loss] $22M [chain] bsc
Vector: Flash loan attack on smart contract

A person was able to use a flash loan attack to drain the Elephant Money project, crashing the token price to 0 while cashing out 27,416 BNB ($11 million). Losses to the project …

Other

Tweet by Cobie

2022-04-12 [vendor] Coinbase insider trading

On April 11, Coinbase announced 50 new cryptocurrencies they were considering listing on their exchange. These announcements tend to increase the price of the tokens under …

Other

Tweet by Pierce Brown

2022-04-12 [vendor] Solar Society promotional art

"Don't make your dystopian books our reality, Pierce," a fan replied to sci-fi author Pierce Brown's announcement of an NFT project. Brown, the author of the bestselling Red Rising …

Cryptocurrency

Tweet by Casper

2022-04-11 [vendor] Casper NFT theft [loss] $600,000 [chain] ethereum
Vector: Smart contract exploit / hack

NFT collector "Casper" discovered their wallet had been compromised, and an attacker had stolen around 114 NFTs worth around $600,000. The collector took to Twitter to urge people …

Cryptocurrency

Tweet by PeckShield

2022-04-11 [vendor] Creat Future [loss] $2M [chain] bsc
Vector: Smart contract exploit / hack

An attacker stole about $1.9 million after exploiting a bug in the smart contract for the Creat Future token. The contract's transfer function was defined as public, with no …

Cryptocurrency

Instagram video of $APE transaction

2022-04-09 [vendor] Bored & Hungry restaurant opens [chain] ethereum

A restaurateur opened "Bored & Hungry", a Bored Ape-themed restaurant in Long Beach, California that offers a simple menu of hamburgers or plant-based burgers (with or without …

Cryptocurrency

"NFTs Are Here to Ruin D&amp;D"

2022-04-08 [vendor] Gripnr announcement [chain] polygon

Because, really, what is even the point of playing Dungeons & Dragons if you're not buying a premade character from a limited set of options, playing premade adventures with …

Other

Industroyer2 Ukraine Power Grid Attack — Sandworm (Detected and Blocked)

2022-04-08 [vendor] IEC 60870-5-104 SCADA; Ukrainian high-voltage substations [malware] Industroyer2; CaddyWiper; ORCSHRED; SOLOSHRED; AWFULSHRED
Vector: Sandworm (GRU Unit 74455) pre-positioned in Ukrainian energy sector network with undisclosed initial access vector (likely spearphishing or supply chain); deployed Industroyer2 IEC 60870-5-104 payload targeting high-voltage substations; simultaneously deployed five wiper variants (CaddyWiper, ORCSHRED, SOLOSHRED, AWFULSHRED) targeting Windows, Linux, and Solaris systems

On April 8, 2022 — during Russia's full-scale military invasion of Ukraine — Sandworm (GRU Unit 74455) attempted to deploy an upgraded version of Industroyer malware (dubbed …

Cloud [SC]

Heroku / Travis CI OAuth Token Theft — GitHub Private Repositories Exposed

2022-04-07 [vendor] GitHub OAuth / Heroku integration / Travis CI integration
Vector: An attacker obtained stolen OAuth user tokens issued to Heroku and Travis CI (two third-party GitHub integrations); used the tokens to enumerate and download private GitHub repositories for organizations that had granted these integrations OAuth access; then used credentials found in those repositories to access downstream systems

In April 2022, GitHub detected that an attacker had used stolen OAuth user tokens issued to third-party integrations — specifically Heroku Dashboard (OAuth app ID 145909) and …

Cryptocurrency

Tweet thread by CertiK Alert

2022-04-07 [vendor] Starstream [loss] $4M [chain] ethereum
Vector: Smart contract exploit / hack

Starstream, a defi project built on the Andromeda layer 2 Ethereum protocol, had its treasury drained. Blockchain security company CertiK reported that the treasury appeared to …

Cryptocurrency

Tweet thread by Kevin Homiak

2022-04-07 [vendor] Tyler Gaye alleged misappropriation [loss] $400,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

Attorney Kevin Homiak tweeted that his firm would be representing several individuals who contributed money to a developer, Tyler Gaye, who promised to be working on an NFT …

Cryptocurrency

Scam wallet

2022-04-06 [vendor] Fake Revoke.cash site [loss] $16,000 [chain] ethereum
Vector: Smart contract exploit / hack

It's not exactly straightforward to revoke wallet permissions once they've been granted, and so many users use a site called revoke.cash to remove permissions in the case of …

Cryptocurrency

Tweet by cr0ss.eth

2022-04-05 [vendor] VaynerSports gas fee issue [chain] ethereum

AJ Vaynerchuk, brother of prominent NFT personality Gary Vaynerchuk (aka Gary Vee), launched his VaynerSports NFT collection. The popularity of the project resulted in surging gas …

Cryptocurrency

Tweet thread by 0xQuit

2022-04-04 [vendor] s27 NFT theft [loss] $587,000 [chain] ethereum
Vector: Smart contract exploit / hack

A trader who owned a Bored Ape and two Mutant Ape NFTs apparently reached a deal to trade them for three different Bored Ape NFTs. Because OpenSea doesn't support swapping NFTs …

Other

Web3 Is Going Great

2022-04-04 [vendor] Robert Malone speaking to trucker convoy

Robert W. Malone, a COVID-19 conspiracy theorist, gave a speech to a group of anti-vax truckers in which he announced plans to dox over 4,000 "[World Economic Forum] trainees" by …

Cryptocurrency

"I fell victim to the Trezor phishing scam"

2022-04-03 [vendor] Trezor phishing attack [loss] $72,000 [chain] bitcoin
Vector: Seed phrase / wallet compromise

A Bitcoin holder using a Trezor hardware wallet fell victim to a phishing scam after attackers stole email lists from a third-party vendor use by Trezor. The user wrote on Reddit …

Cryptocurrency

Tweet by PeckShieldAlert

2022-04-02 [vendor] Inverse Finance [loss] $16M [chain] ethereum
Vector: Oracle price manipulation

An attacker targeting the defi project Inverse Finance was able to manipulate the price oracle of INV/ETH, artificially inflating the apparent price of INV and allowing the …

Supply chain [SC]

Dis-Chem Third-Party Breach (April 2022)

2022-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Dis-Chem says it won't share more info on data breach that hit 3.6m clients | News24. In April an “unauthorised person” accessed 3.6 million customers’ first names, surnames, email …

Supply chain [SC]

Sunwing Airlines Third-Party Breach (April 2022)

2022-04-01 [vendor] Airline Choice
Vector: Compromise of third-party service provider / vendor relationship

Cyber-Attackers Hit Sunwing Airlines. Thousands of passengers of Canadian low-cost airline face delays after third-party system was hacked. Thousands of passengers of Canadian …

Cryptocurrency

Tweet by BoredApeYC

2022-04-01 [vendor] Multiple Discord compromises [chain] ethereum
Vector: Smart contract exploit / hack

Another day, another Discord compromise — or in this case, many Discord compromises. Bored Apes wrote on their Twitter account in the early hours of the morning, "STAY SAFE. Do not …

Cryptocurrency

Tweet by Dirty Bubble Media

2022-03-31 [vendor] Cosmic Cowgirls [loss] $1M [chain] ethereum

The former head moderator of the Cosmic Cowgirls NFT project Discord, Esh, wrote on Twitter that that the project team had fired all moderators and scrapped all of their roadmaps. …

Cryptocurrency

"Community Alert: Ronin Validators Compromised"

2022-03-29 [vendor] Axie Infinity bridge [loss] $619M [chain] ethereum
Vector: Nation-state attack (Lazarus/DPRK) — private key or social engineering compromise

One of the most popular play-to-earn games, Axie Infinity, suffered an enormous hack to the Ronin network on which it runs. The project announced that a majority of Ronin validator …

Cryptocurrency

Tweet thread by zachxbt

2022-03-29 [vendor] Bored Bunny [loss] $21M [chain] ethereum
Vector: Exit scam / rug pull

Many had written off the Bored Bunny NFT project (and its subsequent spin-off NFT collections) as a rug pull. After releasing several new NFT collections that appeared to be little …

Cryptocurrency

Tweet thread by Phillip Lietz

2022-03-28 [vendor] Andrew Yang stiffs artist [chain] ethereum

In February, perennial political candidate Andrew Yang announced he had created "Lobby3", a DAO which he says will push for crypto-friendly regulation and "eradicate poverty". The …

Cryptocurrency

Tweet by Cameron Moulène

2022-03-28 [vendor] Cameron Moulène NFT theft [loss] $368,660 [chain] ethereum
Vector: Smart contract exploit / hack

NFT collector Cameron Moulène was excited to see a link promising a merch drop in the bio of an account with the same branding as Bored Ape Yacht Club, but with the handle …

Cryptocurrency

Web3 Is Going Great

2022-03-28 [vendor] MkLeo Twitter account [chain] ethereum
Vector: Smart contract exploit / hack

MkLeo, who is widely considered to be the best Smash Ultimate player in the world, had his 217,000-follower Twitter account hacked and repurposed for NFT shilling. The scammers …

Cryptocurrency

Tweet thread by manifold.xyz

2022-03-28 [vendor] Pak NFT transaction failures [chain] ethereum

Collectors were excited for a chance to obtain NFTs from the artist Pak's upcoming collection, "Ash Chapter II: Metamorphosis". Pak is an extremely popular digital artist, and his …

Cryptocurrency

"Revest Protocol Exploit Recovery Plan"

2022-03-27 [vendor] Revest Finance [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

The Revest protocol was targeted with an attack that stole $BLOCKS, $ECO, and $RENA tokens from their vault. The protocol wrote that the attacker used a "highly sophisticated …

Cryptocurrency

Tweet by 0xQuit

2022-03-27 [vendor] taylorRichie.eth NFT theft [loss] $73,585 [chain] ethereum
Vector: Smart contract exploit / hack

A trader known by taylorRichie.eth agreed to swap their Morie NFT for a Doodle, in a trade they'd coordinated with a user on Discord. Because OpenSea doesn't support trading one …

Data leak [SC]

MCG Health Patient Care Guidelines Breach — 1.1 Million Patients

2022-03-25 [vendor] MCG Health patient care guidelines platform
Vector: Unknown attacker gained unauthorized access to MCG Health's IT environment and accessed a file containing patient personal data stored on MCG Health's systems; the specific intrusion vector was not publicly disclosed

In March 2022, MCG Health — a Hearst Health subsidiary providing evidence-based patient care guidelines and clinical decision support software to health plans and hospitals — …

Cryptocurrency

Tweet by PeckShieldAlert

2022-03-24 [vendor] Pye [loss] $3M [chain] bsc
Vector: Flash loan attack on smart contract

The security firm PeckShield reported that the Pye ecosystem had been targeted with a flash loan attack, which drained around $2.6 million from the protocol. Pye is a group of defi …

Cryptocurrency

Ronin Network / Axie Infinity Lazarus Group Hack ($625M, Largest Crypto Theft)

2022-03-23 [vendor] Ronin Network (Ethereum sidechain bridge) [chain] ethereum
Vector: North Korea's Lazarus Group targeted Sky Mavis (Axie Infinity developer) employees with fake LinkedIn job offers; a senior engineer downloaded a malicious PDF 'job offer' that installed macOS spyware; Lazarus used this foothold to compromise 5 of the 9 Ronin validator private keys

On March 23, 2022, the Lazarus Group (North Korea, DPRK Bureau 121) stole 173,600 ETH and 25.5 million USDC ($625 million at the time) from the Ronin Network — the Ethereum …

Cryptocurrency

Tweet by Arthur_0x

2022-03-21 [vendor] Arthur_0x NFT theft [loss] $2M [chain] ethereum
Vector: Smart contract exploit / hack

Arthur_0x, a crypto investor and NFT whale, had two of their hot wallets compromised. The attacker stole ETH and transferred some big-ticket NFTs out of the wallets, including at …

Cryptocurrency

Tweet by Zachxbt

2022-03-21 [vendor] Bored Apes animation [loss] $900,000 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

An NFT collector fell for a scam website promising to "turn your BAYC animated". After connecting their wallet, the attacker transferred their three pricey Bored Ape NFTs to their …

Cryptocurrency

Winamp Twitter thread

2022-03-16 [vendor] Winamp announces NFT plans [chain] ethereum

A week after LimeWire emerged from cryostasis to announce it would become an NFT platform, Winamp decided to jump in as well. Winamp was a Windows media player that first launched …

Cryptocurrency

Tweet thread by Tiffany Hutchinson

2022-03-15 [vendor] NFTBOOKS token distribution chart [chain] bsc

A project called NFTBOOKS has cropped up, promising to "transform the world of book-readings" by creating an NFT economy of authors, book-lenders, readers, translators, and, of …

Cryptocurrency

Twitter thread by Louis Nel

2022-03-14 [vendor] Clipboard malware [chain] bitcoin
Vector: Smart contract exploit / hack

Bitcoin wallet addresses look something like bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq, and so it's not always obvious at a glance if one string of random characters might have …

Cryptocurrency

Twitter thread by SerpentAU

2022-03-14 [vendor] Wizard Pass Discord [loss] $169,000 [chain] ethereum
Vector: Smart contract exploit / hack

Wizard Pass is an NFT trading community and package of various software tools that can be joined for a price: a collection of 3,000 NFTs gates access to the community. The NFTs had …

Cryptocurrency

Tweet by Rob Freund

2022-03-12 [vendor] Rare Pepes lawsuit [chain] ethereum, bitcoin
Vector: Regulatory / legal action

Matt Furie is the original creator of the Pepe the Frog cartoon that was later co-opted as an alt-right hate symbol, and which has also been popular among crypto enthusiasts and …

Cryptocurrency

"An Update on Our NFT..."

2022-03-11 [vendor] MeUndies' modified Bored Ape illustration [chain] ethereum

Believe me, I was as shocked as you were to discover that the MeUndies underwear brand has a "community". But that community apparently objected to the brand's purchase of a Bored …

Cryptocurrency

Tweet by dino_dealer

2022-03-10 [vendor] EtherRock typo [chain] ethereum

The owner of EtherRock #44 tried to list their NFT for sale for 444 ETH (almost $1.2 million), but erroneously listed it for 444 wei — the fractional unit of ETH typically used for …

Cryptocurrency

Tweet thread by Bored Ape Yacht Club

2022-03-10 [vendor] Yuga Labs requests KYC [chain] ethereum

Yuga Labs, the company behind the Bored Ape Yacht Club (BAYC) project, announced a new project in partnership with blockchain gaming group Animoca Brands. The signup required KYC — …

Cryptocurrency

Tweet thread by rifftrader

2022-03-09 [vendor] Crypto exchange glitch costs user [chain] bitcoin, litecoin

Something apparently went terribly wrong on the trading platform that Twitter user rifftrader was using (though they didn't say which) when 10 BTC (~$385,000) was erroneously …

Cryptocurrency

Tweet by Fantasm Finance

2022-03-09 [vendor] Fantasm Finance [loss] $3M [chain] fantom
Vector: Software bug / unintentional loss

An exploiter was able to use a bug in the Fantasm Mint contract to drain more than 1,000 ETH ($2,640,000) from Fantasm Finance. Fantasm urged their users to redeem their tokens …

Cryptocurrency

Tweet thread by BlockSecTeam

2022-03-09 [vendor] Pirate X Pirate [loss] $78,000 [chain] bsc
Vector: Smart contract exploit / hack

The Pirate X Pirate blockchain gaming platform was exploited, with an attacker selling of more than 9.6 million $PXP. They were able to dump the tokens into the market for a profit …

Cryptocurrency

"Exposing Jake Paul's Scams"

2022-03-07 [vendor] Jake Paul undisclosed promotion accusations [chain] ethereum

Jake Paul, who is already in hot water after being named in the class-action lawsuit against SafeMoon, has now been implicated by YouTube detective CoffeeZilla in $2.2 million …

Other

Tweet thread by Anton Nell

2022-03-06 [vendor] Andre Cronje and Anton Nell leave crypto

Andre Cronje and Anton Nell, the prolific developers of around 25 defi projects including yearn.fi and the new Solidly exchange, suddenly announced on Twitter that they would be …

Cryptocurrency

Tweet thread by Bacon Protocol

2022-03-05 [vendor] Bacon Protocol [loss] $1M [chain] ethereum
Vector: Reentrancy attack on smart contract

Bacon Protocol, a defi project seeking to provide NFT mortgage liens (yes, really) was hacked. A reentrancy bug in their smart contract enabled attackers to get more lending …

Cryptocurrency

Tweet by danvee.eth

2022-03-05 [vendor] BattleCatsArena [loss] $54,943 [chain] ethereum
Vector: Exit scam / rug pull

The NFT project BattleCatsArena appears to have rug pulled on March 5, about three weeks after its launch. The project had been announced late last year, with a post from its …

Data leak

TechCrunch / BleepingComputer / SecurityAffairs

2022-03-04 [vendor] Samsung Electronics
Vector: CWE-522: Insufficiently Protected Credentials (exact vector not disclosed; Lapsus$ used credential theft and social engineering techniques)

Lapsus$ hacking group leaked 190GB of alleged Samsung source code and proprietary data in March 2022. Stolen data included: TrustZone trusted applet source code, biometric unlock …

Cryptocurrency

Tweet by Frooxius

2022-03-04 [vendor] NeosVR abandons crypto [chain] ethereum

NeosVR, a virtual reality project originally released in 2018, introduced "Neos Credits" (NCR) in 2018 with the idea that it could enable in-game transactions. The crypto component …

Cryptocurrency

Nemus Earth whitepaper

2022-03-03 [vendor] Nemus Earth NFT [chain] ethereum

A project called Nemus Earth has emerged, offering to sell you an Ethereum NFT to become a "Guardian" of the Brazilian Amazon rainforest. The project has lofty plans to create a …

Cryptocurrency

Brian Rose

2022-03-02 [vendor] Brian Rose and David Icke [chain] ethereum

Conspiracy theorists Brian Rose and David Icke are together known for their April 7, 2020 interview where Icke attempted to draw unsubstantiated links between the rollout of 5G …

Cryptocurrency

Tweet by KeyboardMonkey3

2022-03-02 [vendor] Treasure NFT marketplace bug [loss] $1M [chain] ethereum
Vector: Software bug / unintentional loss

The Treasure NFT marketplace on Arbitrum (a layer 2 network built atop Ethereum) apparently experienced a bug that allowed someone to "buy" NFTs in transactions where they sent 0 …

Supply chain [SC]

Acro Third-Party Breach (March 2022)

2022-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Supply chain [SC]

DataHEALTH Third-Party Breach (March 2022)

2022-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data Breach Alert: DataHEALTH, Inc. | JD Supra. Recently, DataHEALTH, Inc. confirmed that certain consumer data was compromised as a result of the company being the target of a …

Supply chain [SC]

Highmark Third-Party Breach (March 2022)

2022-03-01 [vendor] Quantum Group
Vector: Compromise of third-party service provider / vendor relationship

Highmark issues statement on ‘data security incident’ with vendor. [](https://circulation.timesleader.com/product/times-leader-e-edition/). Times Leader Wilkes-Barre, PA News, …

Supply chain [SC]

Rennline Third-Party Breach (March 2022)

2022-03-01 [vendor] Freestyle Solutions
Vector: Compromise of third-party service provider / vendor relationship

Page Not Found | JD Supra. Opens in a new window Opens an external website Opens an external website in a new window. This website utilizes technologies such as cookies to enable …

Cryptocurrency

Thread by zachxbt

2022-03-01 [vendor] Malicious Fiverr developer [loss] $580,325 [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

A developer offering his services on the freelancer marketplace Fiverr was hired by 32 different NFT projects, for which he wrote and deployed the smart contracts. The first …

Cryptocurrency

Tweet by Memofrogwell

2022-02-28 [vendor] Elexir Finance [loss] $1M [chain] avalanche
Vector: Exit scam / rug pull

Elexir Finance promised a platform where users could build passive income via "yield bearing NFTs". They drew in more than $1.3 million in investments since the project's launch on …

Cryptocurrency

GenomesDAO Docs

2022-02-28 [vendor] GenomesDAO launch [chain] ethereum

GenomesDAO has created a platform which they promise will allow people who wish to sell their genetic data to have more control over it. They write that genetic data is "data that …

Cryptocurrency

Armijo v. Ozone Networks, Inc. d/b/a Opensea

2022-02-28 [vendor] Robert Armijo NFT theft [loss] $300,000 [chain] ethereum
Vector: Phishing attack

Robert Armijo is the former owner of three valuable NFTs — one Bored Ape and two Mutant Apes — which he bought for a total of around $300,000 between November 2021 and January …

Other

"WAGMI" video

2022-02-28 [vendor] Randi Zuckerberg music video

Apparently hoping to create the "rallying cry for the women of web3", Randi Zuckerberg released her second crypto-themed song "WAGMI", a parody of Twisted Sister's "We're Not Gonna …

Other

Tweet by Gavin Wood

2022-02-27 [vendor] Gavin Wood tries to use Ukraine invasion as marketing opportunity

On February 26, the Ukrainian government tweeted Bitcoin and Ethereum addresses, allowing cryptocurrency donations directly to the government to support their resistance to the …

Data leak

Tweet by Doodles

2022-02-26 [vendor] Doodles phishing attack
Vector: Smart contract exploit / hack

The enormously popular "Doodles" NFT project announced on February 26 that their Discord server had been "penetrated by a hacked bot", and that all messages should be ignored. They …

Cryptocurrency

Thread by HOWLERZNFT

2022-02-26 [vendor] Howlerz fake contract [loss] $675,000 [chain] ethereum
Vector: Smart contract exploit / hack

A heavily-hyped NFT project called "Howlerz" released its project via "secret mint" with no allowlist, and it went very, very poorly. Would-be buyers who were excitedly waiting for …

Cryptocurrency

Tweet thread by MetaMehdee

2022-02-26 [vendor] Starcatchers insider trading [loss] $140,000 [chain] ethereum

The Starcatchers NFT project sold NFTs which did not immediately show the image associated with them, but would instead be revealed at a later date. An observant collector noticed …

Other

Tweet by ESETresearch

2022-02-26 [vendor] Scammers try to profit off Ukraine invasion

Cryptocurrency scammers have turned to the crisis in Ukraine to provide fodder for their scams. Some have taken the tactic of pretending to be a person trying to escape the country …

Cryptocurrency

Tweet by molly0xfff

2022-02-25 [vendor] Associated Press mishandles controversy [chain] polygon

After the fiasco the previous day in which some group of people at the Associated Press apparently decided turning an image of human suffering into an NFT was a brilliant idea, …

Cryptocurrency

Tweet thread by zachxbt

2022-02-25 [vendor] Pixelmon [loss] $70M [chain] ethereum
Vector: Smart contract exploit / hack

The Pixelmon project promised an ambitious roadmap including a Pokémon-like game where the pixelized Pokémon could be caught and traded, a land project, and rewards to buyers of …

Cryptocurrency

Archived tweet by the Associated Press

2022-02-24 [vendor] Associated Press releases NFT of migrants [chain] polygon

The Associated Press announced they would be dropping a new NFT on the platform they launched in January, which notably doesn't allow users to sell their NFTs off-platform or …

Other

Cyberattacks in Modern Armed Conflicts — Russia-Ukraine, Israel-Hamas, Taiwan Strait 2022-2026

2022-02-24 [vendor] Ukrainian government, financial, energy, and media infrastructure; Israeli government and critical infrastructure; civilian internet services globally [malware] HermeticWiper, WhisperGate, CaddyWiper, IsaacWiper, Sandworm AcidRain, Industroyer2, SolarWinds SUNBURST [cve] CVE-2022-24521
Vector: Coordination of destructive wiper malware, DDoS campaigns, information operations, and OT/ICS attacks by state-sponsored threat actors and hacktivist auxiliaries alongside conventional military operations; use of pre-positioned access (established months or years before conflict activation) against critical infrastructure

The 2022-2026 period fundamentally documented the integration of cyberattacks into modern armed conflicts as a standard component of military operations. Key documented cyber …

Data leak

Nvidia Lapsus$ Data Breach — 1TB Data, 71K Employee Credentials, DLSS Source Code

2022-02-23 [vendor] Nvidia internal developer network
Vector: Lapsus$ gained initial access through a VPN session hijack using credentials stolen via an infostealer (reportedly from an Nvidia employee's personal device); the group gained access to Nvidia's internal development environment and exfiltrated approximately 1 terabyte of data

On approximately 23 February 2022, the Lapsus$ extortion group compromised Nvidia's internal network and exfiltrated approximately 1 terabyte of data, including proprietary GPU …

Credential theft

NVIDIA LAPSUS$ Breach: GPU Designs, DLSS Source Code, 71K Employee Credentials

2022-02-23
Vector: LAPSUS$ gained access to NVIDIA's network (method not fully disclosed, believed to involve compromised employee VPN credentials and an employee whose personal computer was infected with malware connecting to corporate systems)

On February 23, 2022, LAPSUS$ — a cybercriminal extortion group — gained access to NVIDIA's internal systems and exfiltrated approximately 1TB of data. NVIDIA was alerted to the …

Cryptocurrency

Project contract

2022-02-23 [vendor] De'Aaron Fox [loss] $2M [chain] ethereum
Vector: Exit scam / rug pull

Sacramento Kings player De'Aaron Fox announced his "SwipaTheFox" NFT project in mid-December, and the "high utility NFT collection" went live on January 15. The project roadmap …

Cryptocurrency

Space Crypto (SPE) to USD Chart

2022-02-23 [vendor] Space Crypto tokenomics flop [chain] bsc

Space Crypto, a play-to-earn game that launched on February 15, announced on February 23 that users wouldn't be able to withdraw all their reward tokens, as expected. Without …

Cryptocurrency

Tweet by schniggie

2022-02-22 [vendor] Ocean Protocol vulnerability [chain] ethereum
Vector: Software bug / unintentional loss

Ocean Protocol is a web3 project promising to help people "publish, discover, and consume data in a secure, privacy-preserving fashion". Recently, they've been promoting the ALGA …

Other

Tweet thread by Brian Armstrong

2022-02-21 [vendor] Coinbase takes credit for ad

Coinbase CEO Brian Armstrong embarked on a 12-tweet-long thread congratulating Coinbase employees for coming up with the bouncing QR code Super Bowl ad. He wrote, "I guess if there …

Other

Tweet thread by zachxbt

2022-02-20 [vendor] Composable Finance exec unmasked as Omar Zaki
Vector: On-chain theft (attributed by zachxbt)

Composable Finance is a company that makes infrastructure tools for defi. Until recently, their head of product has been known only as 0xbrainjar, and has operated pseudonymously. …

Cryptocurrency

Tweet by Jon_HQ

2022-02-19 [vendor] OpenSea phishing attacks [loss] $3M [chain] ethereum
Vector: Phishing attack

Panic erupted on February 19 as a few users saw their wallets emptied of valuable NFTs without knowing why, and many others feared the same could happen to them. Early explanations …

Cryptocurrency

Tweet thread by dcsilver

2022-02-18 [vendor] Bitconnect lawsuit continues [chain] bitcoin
Vector: Ponzi / pyramid scheme

An appeals court found that a legal claim could continue to be pursued against some of the major voices that promoted Bitconnect online. Bitconnect was a Ponzi scheme that …

Cryptocurrency

Tweet by NFTCryptoChicks

2022-02-18 [vendor] Crypto.Chicks art theft controversy [chain] ethereum

Polly, a member of the popular Crypto.Chicks NFT team, apologized for "drawing inspiration from" artists and "inadvertently cop[ying]" their work, after it is discovered that she …

Cryptocurrency

<i>McKimmy v. OpenSea</i>

2022-02-18 [vendor] Timothy McKimmy NFT theft [loss] $300,000 [chain] ethereum
Vector: Regulatory / legal action

Businessman Timothy McKimmy is the former owner of Bored Ape #3475, an NFT he purchased in December for 55 ETH (then about $232,000). In a lawsuit against OpenSea, McKimmy alleged …

Cryptocurrency

Tweet from MetaDeckz

2022-02-16 [vendor] MetaDecks unauthorized NFTs [chain] ethereum
Vector: Regulatory / legal action

An artist creating and selling trading cards of various streamers without asking their permission claims he was "just trying to do something cool for the community". He originally …

Cryptocurrency

Tweet by katienotopoulos

2022-02-16 [vendor] Robness harasses journalist [chain] ethereum

"Robness", an NFT artist who is somewhat known for selling a photograph of a trashcan for more than $250,000, apparently took issue with BuzzFeed News journalist Katie Notopoulos, …

Other

Tweet by Gary Vaynerchuk

2022-02-16 [vendor] Gary Vee calls out shadiness

Gary Vaynerchuk, an entrepreneur and now crypto/NFT personality, took to Twitter to express his frustration with some projects that airdrop their NFTs to big-name collectors and …

Cryptocurrency

Tweet thread by CertiKCommunity

2022-02-15 [vendor] BNB42 [loss] $3M [chain] bsc

BNB42 was a "100% decentralized investment platform" that promised investors a 20% daily return on their investments. Unsurprisingly, that turned out to be too good to be true when …

Cryptocurrency

Tweet thready by zachxbt

2022-02-15 [vendor] helloimmorgan fails to disclose paid promotions [chain] ethereum

More shadiness emerges around the Jacked Ape Club as it's discovered that the popular NFT influencer account Morgan (aka @helloimmorgan and morgan.eth) failed to disclose being …

Cryptocurrency

The Kiss NFT website

2022-02-14 [vendor] Belvedere Museum auctions scraps of painting [chain] ethereum

In a Valentine's Day-themed stunt, the otherwise reputable Belvedere Museum in Austria decided to sell Gustav Klimt's The Kiss as NFTs. But making one NFT was apparently not enough …

Cryptocurrency

Tweet by finance_build

2022-02-14 [vendor] BuildFinance governance attack [loss] $470,000 [chain] ethereum
Vector: Smart contract exploit / hack

A person managed to submit a proposal to the DAO that governs BuildFinance, a "decentralized venture builder", that would allow them to take over the project contract. The attacker …

Cryptocurrency

Tweet by Hantao

2022-02-13 [vendor] Jacked Ape Club team melts down [chain] ethereum
Vector: Exit scam / rug pull

The team behind Jacked Ape Club, another NFT project featuring computer-generated apes, briefly erupted in chaos, shaking the confidence of many in the project. Several days prior, …

Other

"Taxman makes first ever seizure of NFTs"

2022-02-13 [vendor] British authorities seize NFTs in tax investigation
Vector: Regulatory / legal action

British tax authorities seized three NFTs in what they said was an attempt to dodge £1.4 million ($1.9M) in taxes. Officials stated that the seizure was a "warning to anyone who …

Other

Tweet by coloradotravis

2022-02-13 [vendor] Coinbase outage

People were apparently tempted by Coinbase's Super Bowl ad — which was just a QR code bouncing around the screen like the DVD screensaver — so much so that it took the Coinbase …

Cryptocurrency

Tweet thread by thomasg.eth

2022-02-12 [vendor] Air taxi DAO founder narrowly escapes [chain] ethereum
Vector: Smart contract exploit / hack

thomasg.eth is the founder of Arrow, a DAO that is working to create "open-source VTOL [vertical take-off and landing] aircraft and air taxi protocol". In a long Twitter thread, he …

Cryptocurrency

Tweet by JackedApeClub

2022-02-11 [vendor] Jacked Ape Club deception [chain] ethereum

The Jacked Ape Club launched their public sale on February 10, offering 8,888 NFTs of illustrated apes much like the Bored Apes, but muscular. The following day they tweeted that, …

Cryptocurrency

Tweet by Coffeezilla

2022-02-11 [vendor] Lana Rhoades [loss] $2M [chain] ethereum

Lana Rhoades put her celebrity status behind the "CryptoSis" NFT project, which launched on January 22 and raised about $1.8 million. The project featured a detailed roadmap, …

Other

"Exposing A Game Developer"

2022-02-11 [vendor] TitanReach alleged fund misappropriation [loss] $150,000

The "Runescape-like" MMO game known as TitanReach has had a bumpy history so far, first failing to reach its Kickstarter goal in a crowdfunding project launched in 2020, but …

Cryptocurrency

Tweet thread by mtgDAO

2022-02-10 [vendor] mtgDAO legal notice [chain] ethereum
Vector: Regulatory / legal action

The fledgling mtgDAO promised to deliver a "crypto NFT card economy" based around the Magic: The Gathering card game published by Wizards of the Coast. Needless to say, WotC sent …

Cryptocurrency

Tweet by PeckShieldAlert

2022-02-09 [vendor] Dego Finance [loss] $10M [chain] bsc
Vector: Smart contract exploit / hack

Hackers drained more than $10 million from the project Dego Finance. This also plunged the value of the project's $DEGO token by about 78%. Dego claims that the hackers compromised …

Cryptocurrency

"Ira Financial and Gemini"

2022-02-08 [vendor] IRA Financial [loss] $36M [chain] bitcoin
Vector: Smart contract exploit / hack

IRA Financial, a platform for managing retirement investments, boasts of being "the first self-directed IRA company to allow their clients to invest in cryptocurrencies, such as …

Cryptocurrency

"Superfluid - REKT"

2022-02-08 [vendor] Superfluid [loss] $9M [chain] polygon
Vector: Software bug / unintentional loss

A vulnerability in the Superfluid crypto streaming protocol allowed an attacker to drain $8.7 million, affecting projects including Mai Finance, Stacker Ventures, Stake DAO, and …

Other

Tweet thread by duckrabbitblog

2022-02-08 [vendor] British Journal of Photography replaces Twitter account

The British Journal of Photography is a magazine and institution within the fine art and documentary photography world dating to 1854. In June 2021, they asked for investments, but …

Cryptocurrency

Tweet from earnhubBSC

2022-02-07 [vendor] EarnHub [loss] $284,000 [chain] bsc
Vector: Exit scam / rug pull

EarnHub, a DeFi platform with its own rap song, suddenly saw 660 wBNB (around $284,000) disappear from their project. EarnHub wrote on Twitter that "A hacker was able to exploit …

Other

Tweet thread by NFTtheft

2022-02-07 [vendor] NFT Music Stream unauthorized marketplace

Following close on the heels of the disaster of an idea that was HitPiece, a new project called "NFT Music Stream" cropped up. Like HitPiece, the project appeared to be scraping …

Other

Tweet by SuperRare

2022-02-07 [vendor] SuperRare community manager controversy

The same week as bigoted tweets from an ENS director Brantly Millegan surfaced, so too did racist tweets by Ashni Christenson, then-community manager for the NFT platform …

Cryptocurrency

Tweet by Zilverk

2022-02-06 [vendor] Ratz Club [loss] $140,000 [chain] solana
Vector: Smart contract exploit / hack

Mexican VTuber Zilverk created an NFT project called Ratz Club, built on the Solana blockchain. On February 6, the project announced that a developer they had contracted drained …

Data leak

Tweet thread by Meter_IO

2022-02-05 [vendor] Meter Passport bridge [loss] $4M
Vector: Smart contract exploit / hack

A bug in the Meter Passport smart contract allowed an attacker to pull 1400 ETH (~$4.2 million) and 2 wrapped Bitcoin (~$83,000) from the Meter Passport blockchain bridge. This was …

Cryptocurrency

Tweet by damedoteth

2022-02-05 [vendor] ENS leadership controversy [chain] ethereum

Brantly Millegan is the director of operations for the Ethereum Name Service, which is basically a blockchain version of DNS, and is also how some people get their wallet to show …

Other

Tweet by boxbrown

2022-02-04 [vendor] Gumroad NFT controversy

Brian Box Brown, an artist who had previously worked for the digital self-publishing platform Gumroad, tweeted that he was ramping up his original art sales because "my former …

Cryptocurrency

Tweet by wormholecrypto

2022-02-02 [vendor] Wormhole bridge [loss] $180M [chain] solana
Vector: Smart contract exploit / hack

The Wormhole Network is a blockchain bridge between Solana and various other blockchains, allowing assets to be traded across the different and not otherwise interoperable chains. …

Other

Wormhole Bridge Exploit ($320M Stolen)

2022-02-02 [vendor] Wormhole cross-chain bridge (Solana/Ethereum)
Vector: Attacker exploited a signature verification vulnerability in Wormhole's Solana smart contract — a failure to properly validate 'guardian' program accounts allowed the attacker to spoof a valid signature and fraudulently mint 120,000 wETH (wrapped Ethereum) on Solana without depositing collateral

On February 2, 2022, the Wormhole cross-chain bridge — which facilitates token transfers between Solana, Ethereum, and other blockchains — suffered a smart contract exploit …

Ransomware

Australian Clinical Labs / Medlab Pathology Breach (223K Patients, First Privacy Act Civil Penalty)

2022-02-01
Vector: Ransomware attackers compromised Medlab Pathology (subsidiary of Australian Clinical Labs) via an unpatched internet-facing system, exfiltrating patient pathology records before deploying ransomware

In approximately February 2022, Australian Clinical Labs' Medlab Pathology subsidiary suffered a ransomware attack that exfiltrated approximately 223,000 patients' sensitive …

Supply chain [SC]

Not disclosed Third-Party Breach (February 2022)

2022-02-01 [vendor] Comprehensive Health Services
Vector: Compromise of third-party service provider / vendor relationship

2 Vendor Hacking Incidents Affect Over 600,000 Individuals. Two recent hacking breaches affecting hundreds of thousands of individuals - one reported by a firm that provides …

Cryptocurrency

Tweet by Choke Chain

2022-02-01 [vendor] HitPiece unauthorized marketplace [chain] ethereum

The industrial band Choke Chain tweeted, "Yo a bunch of industrial scene acts (including me) have NFTs for sale on the site hitpiece.com I did not put it online and I assume you …

Cryptocurrency

WWF NFT website

2022-01-31 [vendor] WWF NFT announcement [chain] polygon, ethereum

The UK branch of the World Wildlife Fund (WWF) announced their upcoming "Tokens For Nature" NFT project, which is meant to support endangered species. The WWF was quick to tout …

Cryptocurrency

Twitter thread by Omar Farooq

2022-01-30 [vendor] Colors NFTs [chain] ethereum

As the NFT gold rush continues and people attempt to slap price tags on everything in sight, Omar Farooq detailed his plans to sell colors on the blockchain. He said he will then …

Cryptocurrency

Twitter feed of Qubit Finance

2022-01-30 [vendor] Qubit bounty negotiation [chain] bsc
Vector: Smart contract exploit / hack

After a bug in their code allowed an attacker to make off with $80 million, Qubit immediately began trying to contact the exploiter and convince them to return the money. First …

Cryptocurrency

Tweet thread by smlundberg

2022-01-28 [vendor] Khan Academy wash trading controversy [chain] ethereum

Khan Academy, an otherwise excellent non-profit offering online educational tools, announced they would be participating in an NFT charity auction on January 19. The auction …

Cryptocurrency

Tweet thread by NFT Ethics

2022-01-28 [vendor] Lazy Lion Ape Club [loss] $125,000 [chain] ethereum

Lazy Lion Ape Club, an NFT project in somewhat resembling the mega-popular Bored Apes, listed their NFTs on OpenSea on January 26. In addition to the NFTs, the project promised to …

Cryptocurrency

Tweet by cr0ssETH

2022-01-28 [vendor] OpenSea listing bug continues [chain] ethereum
Vector: Software bug / unintentional loss

OpenSea began reimbursing users who lost money earlier this month through what some have described as a bug with the platform, but which others argue is just a misunderstanding on …

Cryptocurrency

Tweet by Qubit Finance

2022-01-27 [vendor] Qubit Finance [loss] $80M [chain] bsc
Vector: Software bug / unintentional loss

An attacker exploited a bug in Qubit Finance, a decentralized lending platform. The bug allowed them to call the "deposit" function without actually depositing any funds. This …

Other

Reddit thread on r/defi

2022-01-27 [vendor] Wonderland developer exposed as Michael Patryn
Vector: On-chain theft (attributed by zachxbt)

Sifu, the pseudonymous chief developer of the Wonderland protocol, was revealed to be Michael Patryn, previously known as Omar Dahani. Patryn was a co-founder of the Canadian …

Cryptocurrency

Tweet by PeckShieldAlert

2022-01-26 [vendor] WeGro [loss] $378,000 [chain] bsc
Vector: Exit scam / rug pull

WeGro, a project to allow "everyone to safely participate in the hemp and cannabis industry through the supply chain", saw its token tank in price as the deployer drained 1,000 BNB …

Other

Tweet by PeckShieldAlert

2022-01-26 [vendor] Let's Go Brandon coin crashes

The "Let's Go Brandon" $LGB coin tied to NASCAR driver Brandon Brown, and created as an apparent way to support "the American dream" and stick it to Joe Biden (somehow), suddenly …

Cryptocurrency

Tweet by NFT Ethics

2022-01-25 [vendor] Blockverse [loss] $1M [chain] ethereum
Vector: Exit scam / rug pull

Blockverse, a project that promised to build a play-to-earn game on top of Minecraft, rug pulled two days after launch. The initial NFT collection sold out in only eight minutes, …

Cryptocurrency

Tweet by Nayib Bukele

2022-01-24 [vendor] Nayib Bukele insults [chain] bitcoin

El Salvadoran president Nayib Bukele gives us Americans a painful reminder of having a president who truly cannot be trusted with the reins of a country, much less a Twitter …

Cryptocurrency

Tweet thread by NFTethics

2022-01-23 [vendor] Cryptopunks insider trading [chain] ethereum

The enormously popular Cryptopunks project, created by the LarvaLabs group, is actually on its second version. A bug in the original smart contract allowed users to retrieve their …

Cryptocurrency

Tweet by GeorgeBTurner

2022-01-22 [vendor] NFT Conservation Fund announcement [chain] ethereum

Conservationist and wildlife photographer George Benjamin tweeted about his new project, "The NFT Conservation Fund". "Over the last decade I've seen first-hand the devastation …

Other

Tweet by NFTtheft

2022-01-20 [vendor] McDonalds steals artwork

Shortly after rolling out their hexagonal NFT profile pictures, @twitter posted "gm, looking for an nft pfp". The next day, McDonald's German language communications account, …

Cryptocurrency

Tweet from PeckShieldAlert

2022-01-19 [vendor] Kingfund Finance [loss] $141,000 [chain] bsc
Vector: Exit scam / rug pull

Kingfund Finance suddenly drained more than 300 WBNB (about $141,000) from their project. This happened a few days after users began to report being blocked by the project's …

Data leak

Red Cross International ICRC Data Breach — 515,000 Vulnerable People Records

2022-01-18 [vendor] International Committee of the Red Cross (ICRC) / Zoho ManageEngine ADSelfService Plus [malware] BEACON, GLASSTOKEN (custom malware) [cve] CVE-2021-40539
Vector: Sophisticated nation-state-level attacker (ICRC later assessed the attack as deliberate, targeted, and state-sponsored) exploited an unpatched critical authentication bypass vulnerability (CVE-2021-40539) in Zoho ManageEngine ADSelfService Plus deployed by a third-party contractor; attacker deployed webshells and custom malware BEACON and GLASSTOKEN

On 18 January 2022, the International Committee of the Red Cross (ICRC) discovered a cyberattack on servers hosted by a contractor in Switzerland that stored data for its Restoring …

Cryptocurrency

PeckShieldAlert tweet

2022-01-18 [vendor] BNB Heroes [loss] $190,000 [chain] bsc
Vector: Exit scam / rug pull

The BNB Heroes play-to-earn game apparently rug pulled after a period of inactivity from the development team. The developer drained almost $200,000 from the token pool, plummeting …

Cryptocurrency

Tweet from MastercardNews

2022-01-18 [vendor] Mastercard partners with Coinbase [chain] ethereum

Apparently the real issue with crypto grifts all along has been that it's just too dang hard to put your money into them. Mastercard has shown up to fix that, announcing a new …

Other

Instagram statement by MetaBirkins

2022-01-17 [vendor] MetaBirkins lawsuit
Vector: Regulatory / legal action

Mason Rothschild, the creator of "MetaBirkins" NFTs, was the target of a trademark lawsuit by Birkin bag-maker Hermès. The lawsuit came after he ignored a cease and desist from the …

Cloud

Okta / Critical Start / Hunters Security

2022-01-16 [vendor] Okta Identity Platform [malware] Mimikatz
Vector: CWE-1391: Use of Weak Credentials (third-party support contractor workstation compromise via RDP + credential harvesting)

Lapsus$ accessed Okta's network via compromised Sitel/Sykes contractor support workstation starting Jan 16 2022. Attacker used RDP lateral movement, accessed …

Cryptocurrency

PeckShield tweet

2022-01-16 [vendor] CryptoBurgers [loss] $770,000 [chain] bsc
Vector: Flash loan attack on smart contract

The value of the $BURG token associated with the CryptoBurgers game suddenly plummeted after being hacked shortly after launching earlier that day. The game allowed users to earn …

Cryptocurrency

Tweet by Pranksy

2022-01-16 [vendor] NotASecretNFT project [chain] ethereum
Vector: Exit scam / rug pull

Enthusiasts rushed to buy NFTs from a project called NotASecretNFT after seeing NFT mega-whale Pranksy buy in, even though the OpenSea description was simply, "1000 secrets, …

Other

Tweet by Bojjisama_AoA

2022-01-15 [vendor] InvertedCulture and MadHashers

Shortly after it was discovered that the images used for the NFT project "InvertedCulture" were nothing more than unauthorized flipped copies from a different NFT project, DNA …

Data leak

Tweet thread by FloatProtocol

2022-01-14 [vendor] Float Protocol [loss] $850,000
Vector: Oracle price manipulation

Lack of liquidity in the Uniswap V3 FLOAT/USDC oracle allowed an attacker to manipulate the prices within the pool, then deposit it at a much higher rate. The hacker pulled about …

Cryptocurrency

Tweet by codenamehugs

2022-01-12 [vendor] Global Game Jam sponsorship controversy [chain] ethereum

Global Game Jam, an annual event where people collaborate to make video games, proudly plugged The Sandbox as their "primary headline sponsor" on Twitter. The Sandbox is a platform …

Cryptocurrency

Tweet thread by SolRarity_

2022-01-11 [vendor] Big Daddy Ape Club [loss] $1M [chain] solana
Vector: Exit scam / rug pull

The creators of "Big Daddy Ape Club" rug pulled shortly after mint, deleting their social media and website and making off with around $1.2 million. The project's creators were …

Cryptocurrency

Tweet thread by questauthority

2022-01-10 [vendor] Associated Press NFT marketplace announcement [chain] polygon

I can safely describe most NFT marketplaces as bizarre, but the AP is really trying to top the bunch. The marketplace will provide a place for trading the NFTs they plan to create …

Cryptocurrency

Tweet by CoinersTakingLs

2022-01-09 [vendor] Doodled Dragons [loss] $30,000 [chain] solana

A SolSea-verified NFT project on the Solana blockchain, Doodled Dragons, touted that they would distribute all profits "straight to charities protecting animals on the brink of …

Cryptocurrency

Tweet thread by zachxbt

2022-01-09 [vendor] Rich Dwarves Tribe [loss] $3M [chain] ethereum
Vector: On-chain theft (attributed by zachxbt)

The Rich Dwarves Tribe was an NFT project announced in December 2021, which minted in January 2022. The project had been heavily promoted by musicians including NeYo, Jason Derulo, …

Cryptocurrency

<i>SEC v. Crowd Machine, Inc.</i>

2022-01-06 [vendor] CrowdMachine SEC lawsuit [chain] ethereum
Vector: Regulatory / legal action

The SEC alleged that Craig Sproule, founder of companies CrowdMachine and Metavine, ran a fraudulent and unregistered ICO when he launched "Crowd Machine Compute Tokens" (CMCTs). …

Other

Original tweet by @Mozilla

2022-01-06 [vendor] Original Mozilla tweet

Someone on the Mozilla Foundation's social team inexplicably thought that tweeting "Dabble in @dogecoin? HODLing some #Bitcoin & #Ethereum? We're using @BitPay to …

Cryptocurrency

Tweet thread by 9x9x9

2022-01-05 [vendor] Pudgy Penguin attempted [chain] ethereum

Pudgy Penguins, a popular NFT project that somehow warranted a full-length New York Times article by Kevin Roose, apparently is trying something pretty shady. This was revealed by …

Cryptocurrency

Tweet thread by ElectionDayMad1

2022-01-04 [vendor] Franklin exposed for undisclosed shilling [chain] ethereum
Vector: Exit scam / rug pull

NFT collector and influencer Franklin posted a tweet thread about how he had hyped a project that later rugpulled. He was paid about 18 ETH (about $63,000) to promote the …

Cryptocurrency

Tweet by PeckShieldAlert

2022-01-03 [vendor] ArbixFinance [loss] $10M [chain] bsc
Vector: Exit scam / rug pull

Yield farming platform ArbixFinance was drained of at least $10 million, with some reporting amounts up to $32 million. Some optimistic users hoped it was a glitch, but the fact …

Data leak

Twitter API Zero-Day: 5.4M Account Phone/Email Exposures (Irish DPC €450K Fine)

2022-01-01 [vendor] Twitter API
Vector: Unauthenticated API endpoint introduced in a June 2021 code change allowed any caller to submit phone numbers or email addresses and receive the associated Twitter account ID — enabling mass enumeration of accounts linked to private contact information

A vulnerability in Twitter's account authentication system, introduced in a June 2021 code change, allowed any caller of Twitter's `id.twitter.com` API to submit a phone number or …

Data leak

WhatsApp 487M Phone Number Scrape (84 Countries)

2022-01-01 [vendor] WhatsApp
Vector: Automated enumeration and scraping of WhatsApp's user phone number registration/lookup mechanism to compile a database of active WhatsApp user phone numbers across 84 countries

In November 2022, a threat actor using the alias 'Ryushi' posted a dataset of 487 million WhatsApp user phone numbers for sale on the Breached hacking forum, claiming it was …

Supply chain [SC]

Avamere Health Services Third-Party Breach — 75+ Long-Term Care Organizations

2022-01-01 [vendor] Avamere Health Services (managed healthcare services provider)
Vector: Avamere Health Services — a managed services provider for senior living and post-acute care facilities — suffered a ransomware or unauthorized access incident that exposed patient data for 75+ affiliated healthcare organizations

In January-February 2022, Avamere Health Services — a Wilsonville, Oregon-based managed services provider for senior living, skilled nursing, and rehabilitation facilities — …

Supply chain [SC]

Ciox Health Third-Party Breach — Baptist Memorial, Children's Healthcare of Atlanta, Hoag, 28+ Health Systems

2022-01-01 [vendor] Ciox Health (health information management services)
Vector: Ciox Health — a major health information management (HIM) services provider — suffered a phishing-related breach that exposed patient data across 28+ hospital and health system clients

In January 2022, Ciox Health — a major provider of health information management (HIM) services including medi cal record retrieval, release-of-information (ROI), and coding …

Supply chain [SC]

Good Samaritan Society, Mission Healthcare at Renton, Prestige Care, Rockwood South Hill, Kin On Health Care Center, and 63 organizations Third-Party Breach (January 2022)

2022-01-01 [vendor] Infinity Rehab
Vector: Compromise of third-party service provider / vendor relationship

Page not found - Infinity Rehab. [](https://www.facebook.com/InfinityRehabCommunity "Facebook")[](https://twitter.com/infinityrehab "X")[](https://www.instagram.com/infinityrehab/ …

Cloud

Pegasus Airlines AWS S3 Bucket Exposure — 6.5TB Flight Records, Source Code, Crew Data

2022-01-01 [vendor] Pegasus Airlines AWS S3 bucket (Electronic Flight Bag / EFB data)
Vector: Misconfigured publicly accessible Amazon S3 bucket containing Pegasus Airlines' Electronic Flight Bag (EFB) software — airline operational data systems — was discovered by SafetyDetectives researchers; the bucket required no authentication to access

In early 2022, SafetyDetectives researchers discovered a publicly accessible Amazon S3 bucket belonging to Pegasus Airlines — a major Turkish airline with approximately 74 million …

Cloud

Football Australia AWS S3 Bucket IAM Credential Exposure

2022-01-01 [vendor] Amazon S3; Amazon Web Services (IAM)
Vector: An AWS IAM access key was inadvertently exposed in a publicly accessible Football Australia S3 bucket, enabling unauthorized access to backend systems and customer data spanning football players and fans

Football Australia, the governing body for association football (soccer) in Australia, suffered a data breach when AWS IAM credentials were exposed in a misconfigured Amazon S3 …

Cryptocurrency

"CryptoBike showing signs of scam"

2022-01-01 [vendor] CryptoBike [loss] $1M [chain] bsc

A Vietnamese play-to-earn game called CryptoBike became popular shortly after its December 25 launch, soaring to around $41.6 million in daily trading volume. However, on January …

Other

Tweet thread by carsonturner

2022-01-01 [vendor] Carson Turner NFT loss [loss] $38,000
Vector: Software bug / unintentional loss

Carson Turner accused ACYCapital of "exploiting @BoredApeYC through a glitch in @rarible" after they bought his Bored Ape NFT that he had listed for sale (and which he has …

Other

Tweet by usdcoinprinter

2022-01-01 [vendor] Tether prints $1 billion

Shortly after midnight on January 1, Tether added another $1 billion to its total supply. Although Tether claims that all of its supply is fully backed by actual currency, many …

Cryptocurrency

Tweet by NFTtheft

2021-12-29 [vendor] Fake Baby Ape Social Club NFTs [loss] $52,000 [chain] polygon
Vector: Smart contract exploit / hack

A clone of Solana's popular "Baby Ape Social Club" project popped up on OpenSea, using the Polygon blockchain. The project enjoyed 14.3 ETH in trading volume (about $52,000) before …

Cryptocurrency

Tweet from WakaFlocka

2021-12-28 [vendor] Waka Flocka NFT theft [loss] $19,000 [chain] ethereum
Vector: Smart contract exploit / hack

Waka Flocka Flame posted to Twitter: "@opensea One of me wallets was hacked wtf man". In a video, he showed NFTs in his OpenSea wallet, saying "This is fake, this is fake, this is …

Cryptocurrency

"MetaDAO Makes Off With $3.2M in Rug Pull"

2021-12-27 [vendor] MetaDAO [loss] $3M [chain] ethereum
Vector: Smart contract exploit / hack

A project that promised to be "the DAO of DAOs" managed to accumulate and then make off with 800 ETH, which was worth around $3.2 million at the time of the scam. The project …

Cryptocurrency

Tweet by jilliancyork

2021-12-26 [vendor] Cipher Punks NFTs created without permission [chain] ethereum

The "Cipher Punks" NFT project tried to sell NFTs with illustrations of various cypherpunks, or at least the ones that were listed on Wikipedia. The project said that it intended …

Cryptocurrency

"OpenSea freezes $2.2M of stolen Bored Apes"

2021-12-25 [vendor] bergpay.eth NFT theft [loss] $41,100 [chain] ethereum
Vector: Smart contract exploit / hack

bergpay.eth checked his MetaMask wallet on the day after Christmas only to discover that all his NFTs had been stolen, including five from the popular "Jungle Freaks" collection …

Cryptocurrency

Tweet by Fr0zenBuffal0

2021-12-23 [vendor] Fr0zenBuffal0 NFT theft [loss] $290,000 [chain] ethereum
Vector: Smart contract exploit / hack

An NFT collector lost his Bored Ape NFT to a scammer impersonating the well-known NFT collector Jeffrey Huang, aka "Machi Big Brother". The real Huang did eventually buy the NFT …

Cryptocurrency

Tweet thread by Kris Nóva

2021-12-22 [vendor] Open source NFTs made without permission [chain] ethereum

Some prominent open source advocates and contributors were surprised to find that their likenesses were turned into NFTs by an artist who photographed them in 2018. Kris Nóva …

Cryptocurrency

Tweet by commenstar

2021-12-21 [vendor] Monkey Kingdom Discord [loss] $1M [chain] solana
Vector: Phishing attack

An NFT trader hoping to get in on the "Monkey Kingdom" NFT collection was duped by a scam link in the project's official Discord channel, and sent 650 SOL (about $116,000) to a …

Cryptocurrency

Tweet thread by _elcomisionado_

2021-12-18 [vendor] Chivo Wallet bug [loss] $96,224 [chain] bitcoin

A Twitter thread showed dozens of people reporting amounts from hundreds to tens of thousands of dollars disappearing from their Chivo Wallets, the Bitcoin wallet backed by El …

Cryptocurrency

Tweet from NFTtheft

2021-12-17 [vendor] OpenSea ignores stolen artwork reports [chain] ethereum

Artists going through the greuling process of reporting individual NFTs created without permission from their work reported tickets being automatically rejected. Artists were also …

Other

Tweet thread by LiamRSharp

2021-12-17 [vendor] Artist may need to close online gallery

Comics artist Liam Sharp wrote on Twitter that he would likely need to close his DeviantArt gallery, which he has maintained for fourteen years, because his artwork keeps being …

Cryptocurrency

Tweet by Molly White

2021-12-16 [vendor] Bored Ape owner messages [chain] ethereum

The apparent owner of Bored Ape #5262, of which this site header is a derivative work, contacted me on Twitter to say "I believe you are using my ape on your website without my …

Cryptocurrency

Tweet from NFT_Shady

2021-12-15 [vendor] Doodles typo [chain] ethereum

A misplaced decimal point caused an NFT trader to sell their "beloved" Doodle NFT for 0.37 ETH (about $1,500) instead of their intended 3.7 ETH (about $15,000). The trader tried …

Cryptocurrency

Tweet thread by zachxbt

2021-12-14 [vendor] Laurent Correia [loss] $960,000 [chain] ethereum

Laurent Correia, a French influencer and the creator of "Billionaire Tips" sports betting app, launched an NFT project called "Billionaire Dogs" in December. Promising perks …

Cryptocurrency

Tweet thread by Loish

2021-12-13 [vendor] Loish art thefts [chain] ethereum

Digital artist Loish discovered more than one hundred instances where people had created NFTs from her art without her permission, and had to spend hours reporting each individual …

Ransomware [SC]

UKG / BleepingComputer / SHRM / Reuters

2021-12-11 [vendor] UKG Kronos Private Cloud
Vector: CWE-506: Embedded Malicious Code (ransomware; attack vector not publicly disclosed by UKG)

Ransomware struck UKG's (Ultimate Kronos Group) Kronos Private Cloud on December 11 2021, taking down workforce management and payroll processing systems used by thousands of large …

Ransomware [SC]

Kronos Workforce Management Platform Ransomware — Global HR/Payroll Outage (Weeks)

2021-12-11 [vendor] UKG (Ultimate Kronos Group) Kronos Private Cloud
Vector: Unknown ransomware group compromised UKG/Kronos's cloud-based workforce management platform (Kronos Private Cloud); specific initial access vector was not disclosed; the attack encrypted the Kronos Private Cloud environment requiring several weeks to restore

On 11 December 2021, UKG (Ultimate Kronos Group) — one of the world's largest workforce management software providers serving over 40 million people across 57,000 organisations …

Data leak

Cash App Insider Data Breach — 8.2 Million Current and Former Customers

2021-12-10 [vendor] Cash App Investing (Block, Inc.) internal reporting system
Vector: A former Cash App employee who retained access to internal reports after leaving the company downloaded customer brokerage account data without authorization; the employee downloaded reports after their employment terminated

In December 2021, a former employee of Cash App Investing — a subsidiary of Block, Inc. (formerly Square) — downloaded CSV reports containing brokerage account data for 8.2 million …

Ransomware [SC]

Eye Care Leaders EHR Ransomware — 3.6 Million Ophthalmology Patients

2021-12-04 [vendor] Eye Care Leaders myCare Integrity EHR platform
Vector: Unknown ransomware group attacked Eye Care Leaders' myCare Integrity EHR platform — a managed service ophthalmology-specific EHR system used by hundreds of practices; attackers encrypted data and deliberately deleted database tables and audit logs, making it impossible to determine the full scope of data access

On 4 December 2021, Eye Care Leaders — a provider of EHR and practice management software specifically designed for ophthalmology practices — suffered a ransomware attack that …

Other

BitMart Exchange Hack — $196M Hot Wallet Theft

2021-12-04 [vendor] BitMart (cryptocurrency exchange, Cayman Islands)
Vector: Theft of private keys for two of BitMart's hot wallets — one on Ethereum and one on Binance Smart Chain; the exact method of key compromise was not publicly disclosed by BitMart

On December 4, 2021, security firm PeckShield identified large unauthorized outflows from BitMart's hot wallets totaling approximately $196 million — approximately $100 million …

Cryptocurrency

Tweet by @BadWritingTakes

2021-12-02 [vendor] CODEX launches [chain] flow

A platform called "CODEX" announced that they intend to "upgrade the digital book market industry to Web3". This, apparently, involves artificially limiting the number of copies of …

Ransomware

Lincoln College Ransomware Attack (Led to College Closure)

2021-12-01
Vector: Ransomware attackers compromised Lincoln College's systems in December 2021, encrypting systems critical to student recruitment, retention, and fundraising operations; the attack prevented access to all institutional data for several months

Lincoln College, a historically Black liberal arts college in Lincoln, Illinois, founded in 1865 (the same year Abraham Lincoln was assassinated), announced in May 2022 that it …

Data leak

Twitter API Developer Scrape — 5.4 Million Accounts, Dark Web Sale

2021-12-01 [vendor] Twitter API (phone/email lookup endpoint)
Vector: A vulnerability in Twitter's API allowed anyone with a phone number or email address to query and retrieve the associated Twitter account, effectively enabling the enumeration of Twitter accounts and the collection of public profile data linked to private contact information; the vulnerability was reported via HackerOne bug bounty in January 2022

In December 2021, a threat actor exploited a Twitter API vulnerability that allowed them to query any phone number or email address and receive the corresponding Twitter account …

Other

CISA / Apache Software Foundation / CrowdStrike

2021-12-01 [vendor] Apache Log4j 2 [malware] Conti (ransomware), various cryptominers, Orcus RAT [cve] CVE-2021-44228 +2
Vector: CWE-917: Improper Neutralization of Special Elements in Expression Language (JNDI injection in log4j)

Critical CVSS 10.0 RCE vulnerability in Apache Log4j 2 logging library. Publicly disclosed Dec 9 2021; patch released same day (2.15.0). Nation-state actors from China, Iran, North …

Other [SC]

BadgerDAO Frontend Exploit ($120M Stolen via Injected Approvals)

2021-11-10 [vendor] BadgerDAO (Bitcoin yield DeFi protocol); Cloudflare CDN
Vector: Attackers compromised the Cloudflare API key for BadgerDAO's frontend, injecting malicious JavaScript that prompted users to approve unlimited ERC-20 token transfers to attacker-controlled addresses when interacting with the BadgerDAO web application

BadgerDAO, a DeFi protocol allowing users to earn yield on Bitcoin via Ethereum-based vaults, suffered a frontend supply chain attack beginning approximately November 10, 2021, …

Supply chain [SC]

ICRC (Red Cross) Data Breach via Zoho ManageEngine Vulnerability

2021-11-09 [vendor] Zoho ManageEngine ADSelfService Plus [cve] CVE-2021-40539
Vector: Exploitation of unpatched CVE-2021-40539 in Zoho ManageEngine ADSelfService Plus, enabling unauthenticated remote code execution on ICRC servers hosted by a third-party contractor in Switzerland

On 19 January 2022, the International Committee of the Red Cross (ICRC) disclosed a sophisticated cyberattack that compromised personal data on more than 515,000 highly vulnerable …

Cryptocurrency

Cryptoland pitch video

2021-11-06 [vendor] Cryptoland video [chain] ethereum

Signs unfortunately point to this being an actual, real project rather than satire, but the video purporting to advertise it dunks on cryptobros harder than most satirists have …

Credential theft

Robinhood Customer Support Social Engineering Breach (7M Records)

2021-11-03
Vector: Attacker called a Robinhood customer support phone line and social-engineered a support employee into providing access to the customer support system, then used that access to exfiltrate customer records

On November 3, 2021, an attacker called Robinhood's customer support line and socially engineered a customer support employee into granting them unauthorized access to the customer …

Data leak

Tweet thread by Vesper Finance

2021-11-02 [vendor] Vesper Finance [loss] $3M
Vector: Oracle price manipulation

By manipulating the price of a low-liquidity, beta-stage stablecoin, an attacker was able to borrow all tokens in a Rari Fuse pool using the initial token as (inflated) collateral. …

Supply chain [SC]

QRS Clients Third-Party Breach (November 2021)

2021-11-01 [vendor] QRS
Vector: Compromise of third-party service provider / vendor relationship

320K Impacted in EHR Vendor Breach, Ransomware Hits Health Systems | TechTarget. Unauthorized email access and ransomware disrupted the operations of other health systems, while nn …

Supply chain [SC]

Uber Eats Data Exposed via Third Party — 820,000 Delivery Drivers' Data

2021-11-01 [vendor] Uber Eats third-party marketing vendor systems
Vector: A third-party vendor contracted by Uber to provide marketing services to Uber Eats experienced a data security incident that exposed Uber Eats driver data stored in the vendor's systems

In early 2022, Uber disclosed that data for approximately 820,000 Uber Eats delivery driver accounts had been exposed through a third-party vendor that provided marketing services …

Cryptocurrency

Tweet from Becerra announcing the theft

2021-10-31 [vendor] Calvin Becerra NFT theft [loss] $1M [chain] ethereum
Vector: Social engineering attack

NFT collector Calvin Becerra fell for some social engineering on Discord: "Guys posing as buyers in Discord were helping me troubleshoot a problem we thought was happening... They …

Other

Cream Finance DeFi Flash Loan Attack — $130M (Third Exploit)

2021-10-27 [vendor] Cream Finance (DeFi lending protocol, Ethereum)
Vector: Flash loan attack exploiting a price oracle manipulation vulnerability in Cream Finance's lending protocol; attackers used flash loans from multiple DeFi protocols to manipulate the price oracle for the yUSD token (a Yearn Finance vault token), inflating its reported collateral value and enabling the attacker to borrow far more than the actual collateral value across multiple transactions

On October 27, 2021, Cream Finance suffered its third exploit of the year (previous hacks in February 2021 for $37.5M and August 2021 for $18.8M). This third attack was the …

Supply chain [SC]

ua-parser-js npm Package Hijack — Cryptominer and Password Stealer

2021-10-22 [vendor] ua-parser-js npm package (User-Agent string parsing library) [malware] XMRig (Monero cryptominer), jsextension (Linux), sdd.dll (Windows password stealer / DanaBot)
Vector: Attacker compromised the npm account of ua-parser-js package maintainer (faisalman) via credential theft and published three malicious versions (0.7.29, 0.8.0, 1.0.0) containing a postinstall script that deployed a cryptominer (XMRig) on Linux systems and a password-stealing trojan (DanaBot) on Windows systems; the package had approximately 22 million weekly downloads and was a dependency of thousands of packages including Facebook/Meta, Microsoft, Apple, Amazon, Google, and IBM projects

On 22 October 2021, the npm account of Faisal Salman, maintainer of the popular ua-parser-js package, was compromised. The attacker published malicious versions 0.7.29, 0.8.0, and …

Cryptocurrency

"Inside the Realms of Ruin"

2021-10-21 [vendor] Realms of Ruin fails to launch [chain] solana

Six popular young-adult fiction writers attempted to launch an NFT project where they created a base universe, and participants would contribute their own stories (which they would …

Cloud

Twitch Source Code and Internal Data Leak — 125GB Anonymous Dump

2021-10-06 [vendor] Twitch (Amazon subsidiary) internal Git / source code infrastructure
Vector: Anonymous actor (posting as 'Anonymous' on 4chan) claimed a server misconfiguration allowed access to Twitch's internal Git repositories; the attacker obtained credentials or tokens that granted access to Twitch's internal infrastructure

On 6 October 2021, an anonymous actor posted a 125 GB torrent on 4chan containing Twitch's entire source code, internal security tools, mobile and desktop clients, proprietary …

Cloud

Twitch Source Code and Creator Payout Leak — 125GB via Anonymous 4chan Post

2021-10-04
Vector: Server misconfiguration — Twitch stated the data was exposed due to an error in a Twitch server configuration change; the specific nature of the misconfiguration was not detailed, but the attacker accessed and exfiltrated data from Twitch's internal Git repositories and infrastructure

On October 6, 2021, an anonymous user posted a 125GB torrent to 4chan claiming it was a complete Twitch data dump intended to 'foster more disruption and competition in the online …

Supply chain [SC]

Anthem, Humana Third-Party Breach (October 2021)

2021-10-01 [vendor] PracticeMax
Vector: Compromise of third-party service provider / vendor relationship

Third-Party Vendor Ransomware Attack Impacts Humana, Anthem Members | TechTarget. PracticeMax, a billing and IT solutions provider, experienced a ransomware attack that impacted …

Supply chain [SC]

Fullerton Health Third-Party Breach (October 2021)

2021-10-01 [vendor] Agape Connecting People
Vector: Compromise of third-party service provider / vendor relationship

Third-party data breach in Singapore hits healthcare provider. Fullerton Health says its third-party vendor, which platform facilitates appointment booking, had suffered a security …

Data leak

Ambulance Victoria Data Breach — 2,000 Paramedic Personnel Records

2021-09-07 [vendor] Ambulance Victoria website file storage
Vector: A file containing Ambulance Victoria staff personal data was inadvertently uploaded to a publicly accessible part of Ambulance Victoria's website, where it was accessible without authentication

In September 2021, Ambulance Victoria — the state ambulance service providing emergency medical services across Victoria, Australia — inadvertently uploaded a file containing staff …

Data leak

GoDaddy Managed WordPress Hosting Breach — 1.2 Million Customers

2021-09-06 [vendor] GoDaddy Managed WordPress hosting infrastructure
Vector: An unauthorized third party used a compromised password to gain access to GoDaddy's Managed WordPress hosting environment's provisioning system in their legacy codebase

On 6 September 2021, an unauthorized actor used a compromised password to access GoDaddy's Managed WordPress hosting provisioning system. GoDaddy is the world's largest domain …

Credential theft

GoDaddy WordPress Managed Hosting Breach (1.2M Customers, SSL Keys Exposed)

2021-09-06 [vendor] GoDaddy Managed WordPress
Vector: Attacker used a compromised password to gain access to GoDaddy's Managed WordPress provisioning system; the password granted access since at least September 6, 2021 — giving the attacker 2+ months of undetected access

On September 6, 2021, an attacker used a compromised password to access GoDaddy's Managed WordPress hosting provisioning system, where they maintained access for over two months …

Data leak

"The NFT scammers are here"

2021-08-24 [vendor] Sohrob Farudi NFT theft [loss] $800,000
Vector: Smart contract exploit / hack

After asking for help in the OpenSea Discord channel, Nicholas was successfully scammed by individuals posing as customer support. After convincing the investor to share his …

Data leak

Apria Healthcare Data Breach (2021) — 1.87 Million Patients via Email Phishing, Two Intrusion Periods

2021-08-22 [vendor] Apria Healthcare employee email systems
Vector: Phishing emails compromised employee email accounts at Apria Healthcare; the company experienced two separate unauthorized access periods (May-August 2019 and August-October 2021); the 2019 intrusion was discovered during investigation of the 2021 compromise

Apria Healthcare, a major US home healthcare equipment provider (durable medical equipment, infusion therapy, oxygen therapy), disclosed in May 2022 that it had experienced two …

Other

Microsoft Exchange ProxyShell Zero-Days RCE — CVE-2021-34473, CVE-2021-34523, CVE-2021-31207

2021-08-13 [vendor] Microsoft Exchange Server (on-premises) [malware] LockFile ransomware, Babuk ransomware, web shells (various) [cve] CVE-2021-34473 +2
Vector: Multiple threat actors exploited three chained vulnerabilities in Microsoft Exchange Server (ProxyShell) after their technical details were demonstrated at Black Hat and DEF CON 2021; the chain allows unauthenticated remote code execution on Exchange servers by combining server-side request forgery, privilege escalation, and arbitrary file write

ProxyShell is a chain of three Microsoft Exchange Server vulnerabilities — CVE-2021-34473 (SSRF/ACL bypass), CVE-2021-34523 (privilege escalation), and CVE-2021-31207 (arbitrary …

Cryptocurrency

Tweet by PeckShieldAlert

2021-08-12 [vendor] DAO Maker [loss] $7M [chain] ethereum
Vector: Smart contract exploit / hack

The DAO Maker project (not to be confused with the well-known MakerDAO) is a launchpad that claims to be "building the future of venture capital". Its website boasts that users who …

Other

Poly Network DeFi Cross-Chain Exploit ($611M Stolen, Fully Returned)

2021-08-10 [vendor] Poly Network (cross-chain DeFi bridge)
Vector: Cryptographic vulnerability in Poly Network's cross-chain smart contract: attacker exploited the _executeCrossChainTx function's keeper role privilege escalation across Ethereum, Binance Smart Chain, and Polygon to override ownership of the protocol's fund management contract

On August 10, 2021, an attacker exploited a critical vulnerability in Poly Network's cross-chain interoperability protocol to steal approximately $611 million across three …

Cloud

Microsoft Azure ChaosDB Cosmos DB Vulnerability — All Azure Customers at Risk

2021-08-09 [vendor] Microsoft Azure Cosmos DB (globally distributed cloud database)
Vector: Wiz.io researchers discovered a chain of vulnerabilities in Azure Cosmos DB's Jupyter Notebook integration that allowed complete access to any Azure Cosmos DB customer's database — without any action required from the victim; the vulnerability enabled attackers to read, write, and delete data in Cosmos DB accounts belonging to any Azure customer

On 9 August 2021, Wiz.io security researchers discovered a critical vulnerability chain in Microsoft Azure Cosmos DB — Microsoft's flagship globally distributed database service …

Ransomware

Eskenazi Health Ransomware — Indiana Safety-Net Hospital Patient Data Stolen

2021-08-04 [vendor] Eskenazi Health hospital IT systems [malware] Vice Society ransomware
Vector: Ransomware group (Vice Society) gained access to Eskenazi Health's network during a dwell period prior to the attempted encryption; Eskenazi detected the encryption attempt and brought systems offline before full encryption was completed; however, attackers had already exfiltrated patient data during the dwell period

On 4 August 2021, Eskenazi Health — Indianapolis's primary safety-net hospital serving the city's most vulnerable and uninsured populations, and the only Level I adult trauma …

Other

Web3 Is Going Great

2021-08-04 [vendor] Uulala SEC settlement
Vector: Regulatory / legal action

The company Uulala, which aimed to provide underbanked individuals with opportunities to build credit, settled with the SEC over charges that they ran an unregistered ICO that …

Ransomware

Roper St. Francis Healthcare Ransomware — 92K Patients, Charleston SC

2021-08-01 [vendor] Roper St. Francis Healthcare — South Carolina hospital system IT systems
Vector: Ransomware group breached Roper St. Francis Healthcare's network and accessed a scheduling application containing patient demographic and appointment data; the specific initial access vector was not publicly disclosed

On approximately 1 August 2021, Roper St. Francis Healthcare — a nonprofit hospital system based in Charleston, South Carolina operating multiple hospitals and medical facilities — …

Data leak

T-Mobile 2021 Data Breach: John Binns (54.6M Records)

2021-08-01
Vector: Attacker John Binns (21-year-old US-born, living in Turkey) brute-forced his way through T-Mobile's unprotected GPRS tunneling protocol (GTP) routers exposed on the internet, gained access to a testing environment, then used that foothold to reach and download T-Mobile's IMSI database and customer data

In August 2021, John Binns — a 21-year-old US citizen living in Turkey — exploited an improperly secured T-Mobile testing environment that had been exposed to the internet, gaining …

Data leak

BleepingComputer

2021-08-01 [vendor] T-Mobile US customer systems
Vector: CWE-284: Improper Access Control

T-Mobile agreed to pay a $31.5 million FCC settlement in September 2024 covering four separate data breaches between 2021 and 2023. The 2021 breach (discovered August 2021) …

Supply chain [SC]

Catholic Health Third-Party Breach (August 2021)

2021-08-01 [vendor] CaptureRx
Vector: Compromise of third-party service provider / vendor relationship

Catholic Health Impacted by CaptureRx Data Breach, Patients’ PHI Exposed | TechTarget. The CaptureRx data breach is impacting 17K Catholic Health patients in New York. Catholic …

Other

Tweet by Cory Doctorow

2021-07-20 [vendor] Norton Antivirus mines crypto

Norton, the makers of the popular Norton Antivirus software, started installing "Norton Crypto" on customers' machines when they install the popular Norton 360 antivirus and …

Cloud [SC]

CISA / NCSC / Wikipedia / Varonis

2021-07-02 [vendor] Kaseya VSA [malware] REvil / Sodinokibi [cve] CVE-2021-30116
Vector: CWE-89: SQL Injection in Kaseya VSA web interface (zero-day)

REvil ransomware gang exploited zero-day SQL injection and auth bypass (CVE-2021-30116) in Kaseya VSA endpoint management software on July 4th weekend 2021. Delivered malicious …

Supply chain [SC]

Hospitals Third-Party Breach (July 2021)

2021-07-01 [vendor] ClearBalance
Vector: Compromise of third-party service provider / vendor relationship

ClearBalance Data Incident Impacts Over 200,000 US Patients' PII | TechTarget. A new cyberattack is impacting over 200,000 patients across the country. ClearBalance, a …

Supply chain [SC]

Hospitals Third-Party Breach (July 2021)

2021-07-01 [vendor] PracticeFirst
Vector: Compromise of third-party service provider / vendor relationship

Supply Chain Ransomware Breach Affects 1.2 Million. A supply chain ransomware attack affecting more than 1.2 million individuals is among the largest health data breaches reported …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-07-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

SpreadGroup Customers Third-Party Breach (July 2021)

2021-07-01 [vendor] Spreadshirt, Spreadshop, and TeamShirts
Vector: Compromise of third-party service provider / vendor relationship

DarkSide behind Guess breach. Print-on-demand vendor data compromises. Patient data phished from lender. Gambling venue operator breached.. Experts guess DarkSide behind Guess …

Cloud [SC]

Kaseya VSA REvil Supply Chain Ransomware — 1,500 Businesses, $70M Demand

2021-07-01 [vendor] Kaseya VSA remote monitoring and management (RMM) platform [malware] REvil (Sodinokibi) ransomware
Vector: REvil exploited multiple zero-day vulnerabilities in Kaseya VSA (CVE-2021-30116, CVE-2021-30119, CVE-2021-30120) to push malicious script execution to all managed endpoints without authentication; exploitation was conducted over the Independence Day holiday weekend

See comprehensive record: data/supply-chain/2021-07_kaseya-vsa-revil.yaml. Kaseya VSA is used by MSPs (Managed Service Providers) to remotely manage client endpoints — a single …

Cloud

UNC2903 IMDSv1 AWS Instance Metadata Service Abuse

2021-06-21 [vendor] Amazon Web Services EC2 IMDSv1 (Instance Metadata Service v1)
Vector: UNC2903 exploited Server-Side Request Forgery (SSRF) vulnerabilities in web applications running on AWS EC2 instances to query the IMDSv1 (Instance Metadata Service v1) endpoint at 169.254.169.254, retrieving temporary IAM role credentials without authentication

UNC2903 is a financially-motivated threat actor tracked by Mandiant/Google Cloud that systematically exploited IMDSv1 vulnerabilities in AWS deployments. Beginning in mid-2021, …

Data leak

EA Games Lapsus$ Source Code Theft — FIFA 21, Frostbite Engine, 780GB Data

2021-06-06 [vendor] EA Games internal development network / Slack
Vector: Attackers purchased stolen Slack authentication cookies from an underground criminal marketplace for $10 and used them to impersonate an EA employee in Slack; used Slack access to social engineer EA's IT support into issuing a multi-factor authentication token, granting VPN and corporate network access

In early June 2021, a group (later attributed to early Lapsus$ affiliates) breached Electronic Arts' internal network using purchased Slack cookies worth approximately $10 …

Data leak

Latitude Financial 2021 OAIC — Pre-2023 Data Collection Practices Investigation

2021-06-01 [vendor] Latitude Financial Services customer data systems
Vector: A vulnerability in Latitude Financial's data systems allowed unauthorized access to a subset of customer personal information; this earlier incident preceded the much larger March 2023 breach in which 14 million customer records were stolen via a compromised managed service provider credential

In mid-2021, Latitude Financial Services suffered an earlier, smaller data security incident — separate from the major March 2023 breach (which affected 14 million customers via a …

Data leak

Have I Been Pwned / Twitter privacy blog / CSO Online

2021-06-01 [vendor] Twitter / X
Vector: CWE-284: Improper Access Control (unauthenticated API endpoint allowed email-to-account enumeration)

Twitter API change in June 2021 introduced vulnerability allowing anyone to look up Twitter accounts via email/phone. Threat actors scraped at scale before patch in Jan 2022. …

Supply chain [SC]

AmeriGas Third-Party Breach (June 2021)

2021-06-01 [vendor] J. J. Keller
Vector: Compromise of third-party service provider / vendor relationship

Largest US propane distributor discloses '8-second' data breach. America's largest propane provider, AmeriGas, has disclosed a data breach that lasted ephemerally but impacted 123 …

Supply chain [SC]

CVS Health Third-Party Breach (June 2021)

2021-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

CVS Health Faces Data Breach,1B Search Records Exposed | TechTarget. A CVS Health data breach led to over 1 billion search records being accidentally posted online, as reported by …

Supply chain [SC]

Saudi Aramco Contractor Data Breach — 1TB Exfiltrated, $50M Ransom Demand, 14,000 Employee Records

2021-06-01 [vendor] Unnamed third-party contractor (Saudi Aramco)
Vector: Compromise of a third-party contractor with access to Saudi Aramco internal data; exfiltration via the contractor's systems rather than Aramco's own network

In July 2021, a threat actor using the name "ZeroX" began advertising 1 terabyte of data stolen from Saudi Arabian Oil Company (Saudi Aramco) on a darknet forum, demanding $50 …

Other

CISA Advisory AA24-038A / Microsoft Security Blog

2021-06-01 [vendor] Cisco routers / Fortinet VPN / various SOHO network devices [cve] CVE-2021-40539 +1
Vector: CWE-77: Command Injection / exploitation of internet-facing SOHO routers and VPN devices to establish footholds

Chinese state-sponsored group Volt Typhoon (Bronze Silhouette) active since mid-2021, targeting US critical infrastructure sectors: communications, energy, transportation, …

Ransomware

NPR / Wikipedia / CNN Business

2021-05-30 [vendor] JBS USA meat processing systems [malware] REvil / Sodinokibi
Vector: CWE-521: Weak Password Requirements (brute-forced or leaked credentials; poor overall security posture confirmed by DHS internal review)

REvil (Russian) ransomware attack on JBS S.A., world's largest meat processor, May 30 2021. Disrupted beef and pork slaughter facilities in US, Canada, Australia. JBS paid $11M USD …

Ransomware

JBS Foods REvil Ransomware Attack ($11M Ransom, Global Meat Supply Disruption)

2021-05-30 [vendor] JBS Foods IT infrastructure (North America and Australia) [malware] REvil (Sodinokibi)
Vector: REvil ransomware-as-a-service affiliate obtained credentials to JBS's VPN; specific initial access vector was compromised remote access credentials; the attack targeted JBS's North American and Australian operations simultaneously

On 30 May 2021, JBS S.A. — the world's largest meat processing company, processing approximately one-fifth of all US beef — was hit by a REvil ransomware attack that forced the …

Ransomware

Ireland HSE Conti Ransomware Attack (National Health System Shutdown, €100M+)

2021-05-14 [malware] Conti ransomware; Cobalt Strike
Vector: Phishing email delivered to a workstation on March 16, 2021; the workstation had a Cobalt Strike beacon installed, enabling remote access; attackers spent 8 weeks conducting reconnaissance before deploying Conti ransomware on May 14, 2021

On May 14, 2021, Conti ransomware operators attacked Ireland's Health Service Executive (HSE) — the country's entire national public health system — encrypting approximately 80,000 …

Ransomware

CISA / Wikipedia / TechTarget

2021-05-07 [malware] DarkSide
Vector: CWE-308: Use of Single-Factor Authentication (compromised VPN account lacking MFA)

DarkSide ransomware affiliate (Russian-based) compromised Colonial Pipeline via leaked VPN credentials on a legacy account lacking MFA. 100 GB of data exfiltrated day before …

Data leak

LinkedIn 700M Profile API Scrape (93% of All Users)

2021-05-01 [vendor] LinkedIn (public profile API)
Vector: Systematic API scraping and data aggregation from LinkedIn's public profile data and APIs; attacker 'GOD User TomLiner' combined LinkedIn API data with other publicly available sources

In June 2021, data for approximately 700 million LinkedIn users — representing 93% of LinkedIn's total user base at the time — was posted for sale on RaidForums by a user calling …

Supply chain [SC]

Ardagh Clients Third-Party Breach (May 2021)

2021-05-01 [vendor] Ardagh
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Supply chain [SC]

Canada Post Third-Party Breach (May 2021)

2021-05-01 [vendor] CommPort Communications
Vector: Compromise of third-party service provider / vendor relationship

Canada Post hit by data breach after supplier ransomware attack. Canada Post has informed 44 of its large commercial customers that a ransomware attack on a third-party service …

Supply chain [SC]

Fujitsu ProjectWEB Breach — Japanese Government Agencies, 76,000 Email Addresses, Narita Airport Data

2021-05-01 [vendor] Fujitsu ProjectWEB
Vector: Stolen/compromised user account credentials for Fujitsu's ProjectWEB collaboration platform, enabling unauthorized access to client project workspaces

In May 2021, multiple Japanese government agencies disclosed that sensitive data had been exfiltrated via Fujitsu's ProjectWEB platform, an enterprise project information-sharing …

Supply chain [SC]

U.S. Government Third-Party Breach (May 2021)

2021-05-01 [vendor] BlueForce
Vector: Compromise of third-party service provider / vendor relationship

US defense contractor BlueForce apparently hit by ransomware | TechTarget. A Virginia-based U.S. defense contractor has apparently been hit by ransomware, according to a ransomware …

Cloud [SC]

Fasttrack Customers Third-Party Breach (May 2021)

2021-05-01 [vendor] Fasttrack Recruitment
Vector: Compromise of third-party service provider / vendor relationship

A UK recruitment firm exposed sensitive applicants data for months. FastTrack Reflex Recruitment firm recently joined the ranks of other companies that have been affected by data …

Cloud

Microsoft Power Apps Portals Misconfiguration — 38 Million Records Exposed from 47 Organizations

2021-05-01 [vendor] Microsoft Power Apps Portals (low-code platform)
Vector: Microsoft Power Apps portals defaulted to allowing public table access; organizations inadvertently exposed internal databases containing PII because Microsoft's default configuration required administrators to explicitly disable public access — a non-intuitive security posture that many missed

Security researchers at Upguard and Wiz.io discovered in mid-2021 that Microsoft Power Apps portals had a default configuration that left internal data tables publicly accessible …

Ransomware

BleepingComputer / ZDNet / Wired

2021-04-28 [malware] DarkSide
Vector: CWE-312: Cleartext Storage of Sensitive Information (DarkSide actors purchased stolen credentials to access the corporate network)

DarkSide ransomware attacked Brenntag, one of the world's largest chemical distribution companies (Germany-headquartered, North America division targeted), on approximately April …

Other

Uranium Finance DeFi BSC Exploit — $50 Million Stolen via Liquidity Migration Attack

2021-04-28 [vendor] Uranium Finance (Binance Smart Chain DeFi protocol) v2 liquidity migration contracts
Vector: Uranium Finance's v2 smart contracts contained a critical arithmetic error in the liquidity migration function; the attacker exploited the bug during the protocol's migration from v1 to v2, using flash loans to manipulate reserve balances and drain funds from liquidity pools; the exploit required only a small initial capital to trigger and was executed in a single transaction

On 28 April 2021, an attacker exploited a critical vulnerability in Uranium Finance — a decentralised exchange (DEX) and automated market maker (AMM) protocol built on Binance …

Ransomware

Scripps Health Ransomware Attack (Conti, 147K Patients, $113M Losses)

2021-04-26 [malware] Conti ransomware
Vector: Conti ransomware operators gained access to Scripps Health's network on April 26, 2021; exfiltrated patient data before deploying ransomware on May 1, 2021, taking Scripps systems offline; a Russian national (Maksim Galochkin) was later federally indicted in connection with the attack as part of the Conti/TrickBot prosecution

On May 1, 2021, Scripps Health — San Diego's second-largest healthcare provider operating five hospitals and 19 outpatient facilities — suffered a Conti ransomware attack that took …

Cloud [SC]

Click Studios Passwordstate Supply Chain Attack — Malicious Update, 29,000 Companies

2021-04-20 [vendor] Click Studios Passwordstate [malware] Moserpass
Vector: CWE-506: Embedded Malicious Code — attackers hijacked Passwordstate's In-Place Upgrade CDN endpoint to serve trojanized update containing Moserpass infostealer

Click Studios, the Australian developer of the enterprise password manager Passwordstate, suffered a supply chain compromise between April 20–22, 2021 (a 28-hour window). Attackers …

Ransomware

Reproductive Biology Associates (RBA) DoppelPaymer Ransomware — 227K IVF Patients

2021-04-07 [vendor] Reproductive Biology Associates (RBA) — Atlanta fertility clinic IT systems [malware] DoppelPaymer ransomware
Vector: DoppelPaymer ransomware group breached Reproductive Biology Associates' network, encrypted a file server containing embryology data, and exfiltrated patient data including highly sensitive fertility treatment records and embryo storage information

On 7 April 2021, Reproductive Biology Associates (RBA) — an Atlanta, Georgia fertility clinic — and its affiliate My Egg Bank North America suffered a DoppelPaymer ransomware …

Data leak

Blue Shield of California Google Analytics/Ads PHI Exposure - 4.7M Members

2021-04-01 [vendor] Google Analytics; Google Ads
Vector: Misconfigured Google Analytics integration on Blue Shield member websites inadvertently shared protected health information with Google Ads for advertising targeting purposes

Blue Shield of California disclosed on April 9, 2025, that a misconfigured Google Analytics integration had been sharing member protected health information (PHI) with Google Ads …

Supply chain [SC]

Celcius Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Celsius Suffers Third-Party Data Breach, Customers Report Phishing Texts, Emails. The crypto lender's data leak comes almost a year to the date after a similar data leak hit …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-04-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Department of Health and Human Services,UChicago, King's Daughters' Health System, OSF HealthCare, Aspirus, UChicago Medicine, and Memorial Hermann Health System. Third-Party Breach (April 2021)

2021-04-01 [vendor] MedData
Vector: Compromise of third-party service provider / vendor relationship

Patient Data from Multiple Providers Leaked in Third-Party GitHub Incident | TechTarget. Data breach notifications and a report reveal a former MedData employee uploaded troves of …

Supply chain [SC]

Ei2 Third-Party Breach (April 2021)

2021-04-01 [vendor] I-vic International
Vector: Compromise of third-party service provider / vendor relationship

Third-party security breach compromises data of Singapore job-matching service. Job-matching institute e2i says the personal details of 30,000 individuals may have been illegally …

Supply chain [SC]

Park Mobile Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users. Someone is selling account information for 21 million customers of ParkMobile, a mobile parking app …

Supply chain [SC]

Peach Aviation, ZIPAIR Tokyo, Air Belgium, Sky Airlines, Air Transat, Vietravel, Aero K Airlines, Salam Air, FlySafair, Air India Express, Wingo Third-Party Breach (April 2021)

2021-04-01 [vendor] Radixx (subsidiary of Sabre Corporation)
Vector: Compromise of third-party service provider / vendor relationship

Malware attack on Radixx Res disrupts 20 airlines' ticket reservation systems - DataBreaches.Net. Radixx , a subsidiary of Sabre Corporation, provides an air passenger ticket …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-04-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Upstox Third-Party Breach (April 2021)

2021-04-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Upstox alerts its users of data breach; funds, securities safe. On receipt of e-mails claiming unauthorized access into Upstox database, the company has appointed a cyber-security …

Supply chain [SC]

Wiener & Kennedy Third-Party Breach (April 2021)

2021-04-01 [vendor] Perkins & Co, Netgain (4th party)
Vector: Compromise of third-party service provider / vendor relationship

Wieden+Kennedy Employees Exposed to a Data Breach. This is a preview. This ad will run at the top of the page as expected when running (or previewing) on your website. …

Ransomware

Nine Entertainment Conti Ransomware — Australian Media Company, Sunday Telegraph Offline

2021-03-28 [vendor] Nine Entertainment Company IT and broadcast systems [malware] Conti ransomware
Vector: Conti ransomware group attacked Nine Entertainment via unknown initial access vector; the attack encrypted systems across Nine's network including broadcast and production systems

On 28 March 2021, Nine Entertainment — Australia's largest media and entertainment company, operating the Nine Network (free-to-air TV), The Sydney Morning Herald, The Age, The …

Ransomware

CNA Financial Ransomware Attack ($40M Ransom Paid, Phoenix CryptoLocker)

2021-03-21 [malware] Phoenix CryptoLocker (WastedLocker variant); SocGholish
Vector: Evil Corp-affiliated attackers used a fake browser update (SocGholish/FakeUpdates malware) delivered via a watering hole or malicious website to gain initial access; deployed Phoenix CryptoLocker (a variant of WastedLocker) across CNA's network

CNA Financial Corporation, one of the largest commercial insurance companies in the United States, suffered a ransomware attack on March 21, 2021 that disrupted its operations for …

Ransomware

CNA Financial Phoenix CryptoLocker Ransomware Attack ($40M Ransom)

2021-03-21 [vendor] CNA Financial internal network and endpoint systems [malware] Phoenix CryptoLocker (Evil Corp)
Vector: Evil Corp affiliate used a fake browser update delivered via a legitimate website (watering hole / drive-by download) to deploy the Phoenix CryptoLocker ransomware; CNA employees were redirected to a malicious page that pushed a malicious update package

On 21 March 2021, CNA Financial — one of the largest commercial insurance companies in the United States — suffered a ransomware attack using a new malware strain called Phoenix …

Data leak

Luxottica EyeCare Data Breach — 70 Million Customer Records

2021-03-16 [vendor] Luxottica partner appointment scheduling application
Vector: Unknown attacker gained unauthorized access to a Luxottica partner application used for managing eye care appointments; the application stored scheduling and patient data for EyeMed Vision Care and Lenscrafters patients

In March 2021, an unauthorized actor gained access to a Luxottica partner appointment scheduling application that contained patient data for customers of Luxottica's vision care …

Ransomware

REvil Ransomware Attack on Acer: $50M Demand via ProxyLogon

2021-03-14 [vendor] Microsoft Exchange Server [malware] REvil (Sodinokibi) ransomware [cve] CVE-2021-26855
Vector: REvil gained initial access to Acer's network via the ProxyLogon Microsoft Exchange Server vulnerability (CVE-2021-26855) — exploiting the critical zero-day mere days after public disclosure

On March 14, 2021, REvil ransomware operators attacked Acer, the Taiwanese PC manufacturer, using the freshly-disclosed ProxyLogon Exchange vulnerability (CVE-2021-26855, disclosed …

Cloud

Verkada Security Camera Network Breach: 150,000 Live Feeds Exposed

2021-03-08 [vendor] Verkada (cloud-managed security cameras)
Vector: Attackers (led by Swiss hacker Tillie Kottmann / 'deletescape') found 'Super Admin' credentials for Verkada's cloud video platform in a publicly accessible Jenkins server; used them to gain root access to all 150,000 cameras across thousands of Verkada's enterprise customers

In March 2021, a collective including Swiss hacker Tillie Kottmann ('deletescape') gained access to Verkada's global security camera management platform by discovering Verkada …

Supply chain [SC]

Austin ISD Third-Party Breach (March 2021)

2021-03-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Austin ISD warns of possible data breach. Those who have been affected are being offered free identity monitoring. AUSTIN, Texas — Austin ISD notified parents last week after it …

Supply chain [SC]

Calviva Health Third-Party Breach (March 2021)

2021-03-01 [vendor] Health Net Community Solutions, Inc, Accellion
Vector: Compromise of third-party service provider / vendor relationship

Local health plan manager announces data breach. [](http://thebusinessjournal.com/local-health-plan-manager-announces-data-breach/#menu-location-primary). …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Israeli Likud Party Third-Party Breach (March 2021)

2021-03-01 [vendor] Elector Software
Vector: Compromise of third-party service provider / vendor relationship

Personal details of all Israeli voters again leaked online, day before election. Anonymous hackers publish databases with 6.5 million names and ID numbers, including where people …

Supply chain [SC]

Poll County Schools Third-Party Breach (March 2021)

2021-03-01 [vendor] PCS Revenue Systems
Vector: Compromise of third-party service provider / vendor relationship

Data breach involving former Polk County Schools vendor could impact thousands. This issue involves a company hired by Polk Schools to collect information about students using the …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-03-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Air India SITA Passenger Service System Breach — 4.5 Million Passengers

2021-02-26 [vendor] SITA Passenger Service System (third-party aviation IT provider)
Vector: SITA Passenger Service System (PSS) — a third-party aviation IT infrastructure provider serving 90% of the world's airlines — was breached by an unknown attacker; the breach affected airline passenger data stored on SITA's servers; multiple airlines' passenger data was compromised through the single SITA breach

On 26 February 2021, SITA — the world's leading IT provider to the air transport industry, serving approximately 90% of international airlines — disclosed that its Passenger …

Supply chain [SC]

Singapore Airlines KrisFlyer Frequent Flyer SITA Breach — 580,000 Members

2021-02-26 [vendor] SITA Passenger Service System (third-party aviation IT)
Vector: SITA Passenger Service System (PSS) breach — the same third-party aviation IT provider breach that affected Air India; Singapore Airlines KrisFlyer member data stored on SITA's PSS servers was accessed by the attacker; the SITA breach affected multiple airlines simultaneously

Singapore Airlines disclosed on 5 March 2021 that its KrisFlyer frequent flyer programme member data had been compromised through the SITA Passenger Service System breach disclosed …

Supply chain [SC]

SITA Passenger Service System Breach — 2.1M+ Frequent Flyer Records, 11 Airlines Affected

2021-02-24 [vendor] SITA Passenger Service System (Horizon PSS)
Vector: Highly sophisticated attack on SITA's Passenger Service System (PSS) server infrastructure; exact initial intrusion method not publicly disclosed by SITA

On February 24, 2021, SITA — one of the world's largest aviation IT companies, serving approximately 90% of global airlines through its Passenger Service System (PSS) — detected …

Ransomware

BleepingComputer / Maine AG disclosure

2021-02-19 [malware] DarkSide
Vector: CWE-506: Embedded Malicious Code (DarkSide ransomware)

DarkSide ransomware attacked fashion retailer Guess (NYSE: GES) in February 2021, exfiltrating data before encryption. DarkSide published a sample of stolen files on their leak …

Data leak

"Alpha Homora exploited for $37.5M"

2021-02-13 [vendor] C.R.E.A.M. [loss] $38M
Vector: Smart contract exploit / hack

A hacker was able to code a smart contract that tricked C.R.E.A.M. into believing it was from a trusted source. They were then able to make off with $37.5 million worth of Ethereum …

Supply chain [SC]

CaptureRx Ransomware Breach — 1.9M Patients, 340B Healthcare Providers Across US

2021-02-06 [vendor] CaptureRx (NEC Networks) [malware] Ransomware (strain not publicly identified)
Vector: Ransomware with data exfiltration prior to encryption (double-extortion) targeting CaptureRx, a 340B pharmaceutical administration services vendor

NEC Networks LLC, doing business as CaptureRx, a San Antonio, Texas-based provider of 340B drug pricing program administrative services to healthcare organizations, suffered a …

Other

Oldsmar Florida Water Treatment Plant — TeamViewer HMI Remote Access Attack

2021-02-05 [vendor] TeamViewer remote access software; water treatment SCADA/HMI
Vector: TeamViewer remote desktop software left installed and accessible on a water treatment plant HMI (Human Machine Interface) workstation; shared/weak credentials with no multi-factor authentication; attacker gained remote control of the operator's screen and mouse while the operator watched

On February 5, 2021, an unknown attacker gained remote access via TeamViewer to the HMI (Human Machine Interface) workstation of the City of Oldsmar, Florida's water treatment …

Supply chain [SC]

Airbus, Air Caraïbes, ArcelorMittal, BT, Luxottica, Kuehne + Nagel, Ministère de la Justice français, New Zealand Police, PWC Russia, Salomon, Sanofi, and Sephora (possibly) Third-Party Breach (February 2021)

2021-02-01 [vendor] Centreon
Vector: Compromise of third-party service provider / vendor relationship

Hackers Exploit IT Monitoring Tool Centreon to Target Several French Entities. Russia-linked state-sponsored hackers Sandworm targeted IT monitoring software company Centreon in a …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-02-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Accellion FTA Zero-Day Cl0p Mass Breach — 100+ Organizations

2021-02-01 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell
Vector: Cl0p ransomware group exploited four zero-day vulnerabilities (CVE-2021-27101 through CVE-2021-27104) in Accellion's legacy File Transfer Appliance (FTA); the FTA was a 20-year-old product that Accellion was actively trying to migrate customers away from

See comprehensive record: data/supply-chain/2021-01_accellion-fta-clop.yaml. The Accellion FTA breach affected 100+ organizations worldwide including Reserve Bank of New Zealand, …

Supply chain [SC]

Codecov Bash Uploader Supply Chain Attack — CI/CD Credential Exfiltration

2021-01-31 [vendor] Codecov Bash Uploader (codecov.io CI/CD code coverage reporting tool)
Vector: Attacker exploited a flaw in Codecov's Docker image creation process to extract credentials from Codecov's Google Cloud Storage bucket; used these credentials to modify the bash uploader script (bash.codecov.io/bash) — distributed to CI/CD pipelines globally — to exfiltrate environment variables including secrets, API tokens, and credentials to an attacker-controlled server (opcode.io)

Between 31 January and 1 April 2021, attackers silently modified Codecov's popular bash uploader script, which thousands of CI/CD pipelines used to upload code coverage reports. …

Cloud [SC]

Codecov Bash Uploader Supply Chain Attack — CircleCI, Twilio, Atlassian, Confluent Downstream

2021-01-31 [vendor] Codecov Bash Uploader (codecov.io CI/CD coverage tool)
Vector: Attacker exploited a flaw in Codecov's Docker image creation process that allowed extraction of credentials from Codecov's Google Cloud Storage bucket; used these to modify the bash uploader script distributed to CI/CD pipelines; the tampered script exfiltrated CI environment variables (secrets, tokens, keys) to attacker-controlled server

Between 31 January and 1 April 2021, attackers modified Codecov's popular bash uploader script — used by thousands of CI/CD pipelines to upload code coverage reports — to …

Cloud [SC]

Codecov Bash Uploader Supply Chain Attack — CI Token Theft, Rapid7/Twilio/Monday.com/Mercari Among Victims

2021-01-31 [vendor] Codecov Bash Uploader
Vector: CWE-506: Embedded Malicious Code — attackers exploited a Docker image build flaw in Codecov's CI pipeline to insert a credential-harvesting curl command into the Bash Uploader script

Codecov, a widely used code coverage reporting service, suffered a sophisticated supply chain compromise that began January 31, 2021, and was not discovered until April 1, 2021 — …

Ransomware

WestRock Ransomware Attack (OT/Manufacturing Systems Disrupted)

2021-01-23
Vector: Ransomware attackers penetrated WestRock's network and deployed ransomware that affected both IT systems and operational technology (OT) systems, including manufacturing and operational systems at packaging production facilities

WestRock Company, one of the largest corrugated packaging and paperboard manufacturers in the world, disclosed on January 25, 2021 that it had suffered a ransomware attack on …

Supply chain [SC]

SonicWall SMA 100 Zero-Day Exploitation (January 2021)

2021-01-22 [vendor] SonicWall Secure Mobile Access (SMA) 100 Series [cve] CVE-2021-20016
Vector: Zero-day SQL injection vulnerability in SonicWall SMA 100 series VPN appliances exploited for credential theft and remote code execution

In late January 2021, SonicWall disclosed that its own internal systems and Secure Mobile Access (SMA) 100 series VPN appliances were targeted by sophisticated threat actors …

Cryptocurrency

"Saddle Finance"

2021-01-19 [vendor] Saddle Finance [loss] $275,000 [chain] bitcoin
Vector: Smart contract exploit / hack

The Saddle Finance defi project, a fork of the Curve Finance project, launched on January 20. It promised it would "eliminate slippage".The project was exploited only hours later, …

Supply chain

Nevada Restaurant Services (Dotty's) Malware Breach (2021)

2021-01-16 [vendor] Nevada Restaurant Services / Dotty's [malware] unspecified malware
Vector: Malware infection enabling unauthorized data exfiltration from internal systems

Nevada Restaurant Services (NRS), the parent company of slot machine parlor chain Dotty's, disclosed a data breach in September 2021 after identifying the presence of malware on …

Supply chain [SC]

ASIC Accellion FTA Breach — Australian Securities Regulator File Transfer Compromise

2021-01-15 [vendor] Accellion File Transfer Appliance (FTA) used by ASIC [malware] Cl0p / DEWMODE web shell [cve] CVE-2021-27101 +3
Vector: Cl0p ransomware group exploited zero-day vulnerabilities in Accellion File Transfer Appliance (FTA) that ASIC used to receive and send documents; the vulnerability allowed unauthorized access to file transfer systems and exfiltration of files that had been submitted to ASIC

In January 2021, the Australian Securities and Investments Commission (ASIC) — Australia's corporate, markets, and financial services regulator — disclosed that its Accellion File …

Cloud

20/20 Eye Care Network Breach — 3.25 Million Patients via AWS S3 Deletion

2021-01-11 [vendor] 20/20 Eye Care Network AWS S3 storage
Vector: Unknown attacker gained access to 20/20 Eye Care Network's AWS environment and accessed and deleted files stored in S3 buckets containing member information; 20/20 discovered the deletion and was unable to determine whether data was exfiltrated prior to deletion

On 11 January 2021, 20/20 Eye Care Network — a managed vision care benefits company providing administration services to health plans — discovered that an unauthorized actor had …

Data leak

Parler Data Scrape — 70TB of Posts, Photos, and Metadata Before Takedown

2021-01-09
Vector: API scraping via enumerable insecure direct object references (IDOR) — Parler's API endpoints used sequential integer IDs with no authentication required; after Amazon Web Services announced it would terminate Parler's hosting (in response to its role in organizing the January 6 Capitol attack), researchers and archivists systematically scraped the entire public-facing API before the site went offline

On January 8, 2021, Amazon Web Services notified Parler — a social media platform popular with right-wing users — that it would terminate Parler's hosting services on January 10 …

Other

Microsoft Security Blog / CISA AA21-062A / CSO Online

2021-01-03 [vendor] Microsoft Exchange Server (on-premises) [malware] China Chopper webshell / HAFNIUM custom tooling [cve] CVE-2021-26855 +3
Vector: CWE-918: Server-Side Request Forgery (SSRF auth bypass chained with post-auth arbitrary file write for webshell installation)

Chinese state-sponsored group HAFNIUM exploited four zero-days in on-premises Microsoft Exchange starting Jan 3 2021. CVE-2021-26855 (SSRF auth bypass) chained with CVE-2021-27065 …

Data leak

Neopets Breach — 69 Million User Accounts, Live Database Access Sold

2021-01-01 [vendor] Neopets user database and game systems
Vector: Unknown attacker gained persistent access to Neopets' databases; the attacker allegedly had access for approximately 18 months before the breach was publicly discovered; the attacker offered both the stolen data and continued live read/write access to Neopets' databases for sale

On 20 July 2022, a threat actor posted on BreachForums offering to sell 69 million Neopets user records and — uniquely — live access to Neopets' database (with read and write …

Data leak

Peloton API Misconfiguration — Private User Profile Data Exposed

2021-01-01 [vendor] Peloton API
Vector: Broken object-level authorization (BOLA/IDOR) — Peloton's API allowed unauthenticated access to any user's profile data by supplying a target user ID; private accounts that users had specifically set to 'private' in the app returned full profile data to unauthenticated API requests

Security researcher Jan Masters (working with Pen Test Partners) discovered in January 2021 that Peloton's API endpoints did not enforce authentication or authorization checks, …

Supply chain [SC]

Bonobos Third-Party Breach (January 2021)

2021-01-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data breach at Bonobos hits up to 7 million: What to do [updated]. When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works. Here at …

Supply chain [SC]

OmniTRAX Third-Party Breach (January 2021)

2021-01-01 [vendor] Broe Group
Vector: Compromise of third-party service provider / vendor relationship

Ransomware Attack Hits Short Line Rail Operator OmniTRAX. Colorado-based short line rail operator and logistics provider OmniTRAX was hit by a recent ransomware attack and data …

Cloud

Socialarks Elasticsearch Exposure — 214 Million Social Media Profiles Scraped

2021-01-01 [vendor] Socialarks Elasticsearch database
Vector: Socialarks — a Chinese social media management company — left an Elasticsearch database exposed publicly without authentication; the database contained scraped and aggregated social media profile data collected by Socialarks from LinkedIn, Facebook, Instagram, and other platforms

In January 2021, security researchers at vpnMentor discovered a publicly accessible Elasticsearch database belonging to Socialarks — a Chinese social media management company that …

Cloud

Pulse Secure / Ivanti VPN Zero-Day Exploitation by APT5 (US Defense Industrial Base)

2021-01-01 [vendor] Pulse Connect Secure VPN (Pulse Secure / Ivanti) [cve] CVE-2021-22893 +2
Vector: Multiple Chinese APT groups (UNC2630 / APT5, and others) exploited CVE-2021-22893 and related zero-day vulnerabilities in Pulse Connect Secure VPN appliances to gain unauthorized access to targeted organizations' networks without authentication

In April 2021, Mandiant (FireEye) and CISA disclosed that at least two Chinese APT groups (tracked as UNC2630 and UNC2717, attributed to APT5 / MANGANESE) had been exploiting …

Supply chain [SC]

Mandiant / CISA AA21-055A / BleepingComputer / Tenable

2020-12-25 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE webshell / FINTEAM [cve] CVE-2021-27101 +3
Vector: CWE-89: SQL Injection (CVE-2021-27101 HOST header injection) leading to DEWMODE webshell installation

FIN11 / UNC2546 (linked to Cl0p/TA505) exploited four zero-days in legacy 20-year-old Accellion FTA product starting Dec 25 2020. Used DEWMODE webshell to exfiltrate data. ~100 of …

Supply chain [SC]

Accellion FTA Breach — Reserve Bank of New Zealand and ASIC (January 2021)

2020-12-23 [vendor] Accellion File Transfer Appliance (FTA) [malware] DEWMODE web shell [cve] CVE-2021-27101 +3
Vector: SQL injection and OS command injection zero-days in Accellion File Transfer Appliance (FTA) legacy software

The Accellion FTA (File Transfer Appliance) breach was one of the most consequential supply-chain attacks of early 2021, affecting dozens of major organisations worldwide through a …

Cloud

Ubiquiti Insider Threat: Employee Steals Data and Extorts Company

2020-12-10 [vendor] Amazon Web Services (AWS); GitHub
Vector: Senior cloud engineer at Ubiquiti used his legitimate privileged AWS and GitHub access to clone the company's source code repositories and steal customer data, then used a VPN to disguise his identity while extorting the company

In December 2020, Nickolas Sharp, a senior cloud engineer at Ubiquiti Networks (maker of UniFi networking equipment), used his legitimate access to Ubiquiti's AWS infrastructure …

Supply chain [SC]

Microsoft Third-Party Breach (December 2020)

2020-12-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Russian hackers compromised Microsoft cloud customers through third party, putting emails and other data at risk. Outside Microsoft’s French headquarters in Issy-Les-Moulineaux, …

Supply chain [SC]

Now:Pensions Third-Party Breach (December 2020)

2020-12-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data breach hits 30,000 signed up to workplace pensions provider. Fraud worries as UK company Now:Pensions says ‘third-party contractor’ posted personal details of clients to …

Cloud [SC]

SolarWinds Orion SUNBURST Supply Chain Attack — Russia SVR, 18,000 Organizations

2020-12-01 [vendor] SolarWinds Orion IT monitoring platform [malware] SUNBURST, TEARDROP, RAINDROP
Vector: Russia SVR/Cozy Bear/APT29 compromised SolarWinds' Orion software build pipeline and injected the SUNBURST backdoor into legitimate Orion updates, signed with SolarWinds' code signing certificate and distributed to ~18,000 organizations

See comprehensive record: data/supply-chain/2020-12_solarwinds-sunburst.yaml. The SolarWinds Orion supply chain attack is the defining supply chain cyber incident of the decade — …

Supply chain [SC]

WildWorks Third-Party Breach (November 2020)

2020-11-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Animal Jam Hacked, 46M Records Roam the Dark Web. Animal Jam, just the latest in a string of attacks on gaming apps, has adopted a transparent communications strategy after stolen …

Supply chain

Lazada RedMart Singapore Database Breach (October 2020)

2020-10-29 [vendor] Not disclosed
Vector: Unauthorized access to an unsecured legacy MongoDB database for the old RedMart app and website; data predated March 2019

Lazada, the Alibaba-owned Southeast Asian e-commerce platform, disclosed a data breach affecting approximately 1.1 million customers of its Singapore-based grocery delivery service …

Ransomware

Vermont Attorney General / AHA / Health IT Security

2020-10-28 [malware] DoppelPaymer
Vector: CWE-506: Embedded Malicious Code (DoppelPaymer ransomware; likely delivered via phishing)

DoppelPaymer ransomware crippled the University of Vermont Health Network on October 28 2020, affecting all six of its hospitals and hundreds of medical staff. The attack knocked …

Ransomware

UVM Medical Center DoppelPaymer Ransomware Attack — 20 Hospitals Affected

2020-10-28 [vendor] University of Vermont Health Network IT infrastructure (6-hospital network) [malware] DoppelPaymer ransomware
Vector: DoppelPaymer ransomware group gained initial access via phishing email delivering the Emotet banking trojan, which subsequently dropped the Ryuk precursor; the attack targeted the University of Vermont Medical Center and its health network affiliate hospitals simultaneously

On 28 October 2020, the University of Vermont Medical Center (UVMMC) and its University of Vermont Health Network — encompassing six hospitals and approximately 1,000 providers …

Other

Harvest Finance Flash Loan Attack ($34M)

2020-10-26 [vendor] Harvest Finance (DeFi yield aggregator)
Vector: Attacker used a large flash loan to manipulate the USDC/USDT price in Curve Finance's Y pool, which Harvest Finance relied on for pricing; by temporarily moving the oracle price, the attacker could deposit and withdraw stablecoins at artificially favorable exchange rates, extracting value in repeated cycles

On October 26, 2020, Harvest Finance — a DeFi yield aggregator managing over $1 billion in assets — suffered a flash loan economic attack resulting in approximately $34 million in …

Data leak

Nitro PDF Service Breach — 77 Million Users, 1 Million Documents

2020-10-21 [vendor] Nitro PDF cloud database and document storage
Vector: Unknown attacker gained unauthorized access to Nitro PDF's user database and document storage; Nitro PDF is a document productivity service used by major enterprises for PDF editing and e-signatures

In October 2020, Nitro Software — the company behind Nitro PDF, a widely used PDF productivity and e-signature service — suffered a data breach that exposed data for approximately …

Data leak

Gravatar Profile Data Scraping — 167M User Records

2020-10-03 [vendor] Gravatar (Globally Recognized Avatar service, operated by Automattic)
Vector: Systematic API/web scraping of Gravatar's public-facing user profile API endpoint; Gravatar's service is designed to return publicly accessible profile information (username, display name, avatar, location, biographical info) for any user by querying their MD5-hashed email address — attackers enumerated MD5 hashes of email addresses to harvest profiles at scale, then cracked the weak MD5 email hashes to obtain the original email addresses

In October 2020, security researcher Carlo di Dato published details of a dataset containing 167 million Gravatar user records obtained by systematically scraping Gravatar's public …

Supply chain [SC]

JM Bullion Third-Party Breach (October 2020)

2020-10-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Precious Metal Trader JM Bullion Acknowledges Breach. In a notification letter filed to the Montana Department of Justice, precious metal trader JM Bullion has revealed that an …

Cloud [SC]

FireEye / Mandiant SolarWinds Breach: Red Team Tooling Stolen (SUNBURST Discovery)

2020-10-01 [vendor] SolarWinds Orion (supply chain) [malware] SUNBURST; TEARDROP
Vector: Russian SVR (Cozy Bear / UNC2452) compromised FireEye via the SUNBURST backdoor in a trojanized SolarWinds Orion update — the same supply chain attack as the broader SolarWinds campaign; FireEye was the first organization to detect and publicly disclose the SUNBURST backdoor

FireEye (now Mandiant) was one of the first and most notable victims of the SUNBURST supply chain attack via SolarWinds Orion. Unlike most SUNBURST victims, FireEye was …

Cloud

Broadvoice VoIP Data Exposure (October 2020)

2020-09-28 [vendor] Broadvoice
Vector: Misconfigured Elasticsearch cluster left publicly accessible without authentication

Broadvoice, a VoIP (Voice over IP) service provider serving small and medium-sized businesses across the United States, inadvertently exposed a massive Elasticsearch cluster …

Ransomware

Universal Health Services Ryuk Ransomware Attack (400 Hospitals, $67M Damages)

2020-09-27 [malware] Ryuk ransomware; TrickBot; Emotet
Vector: Phishing email leading to TrickBot banking trojan infection, which then delivered Emotet and ultimately Ryuk ransomware across UHS's network via lateral movement

On September 27, 2020, Universal Health Services (UHS) — one of the largest US hospital chains with 400 facilities across the US and UK — was struck by Ryuk ransomware, causing one …

Other

KuCoin Exchange Hack — $281M Stolen, Attributed to Lazarus Group (DPRK)

2020-09-25 [vendor] KuCoin (Seychelles-based global cryptocurrency exchange)
Vector: Theft of private keys for KuCoin's hot wallets; the precise method of initial access was not disclosed, but the private keys for hot wallets holding Bitcoin, Ethereum, ERC-20 tokens, and other cryptocurrencies were compromised, enabling mass unauthorized withdrawals

On September 25, 2020, KuCoin detected large unauthorized outflows from its hot wallets across multiple blockchains including Bitcoin, Ethereum, Litecoin, XRP, Stellar, TRON, and …

Cloud

Cisco WebEx AWS IAM User Compromise

2020-09-24 [vendor] Amazon Web Services (IAM); Cisco WebEx
Vector: Attackers compromised AWS IAM user credentials associated with Cisco WebEx's infrastructure, gaining access to Cisco's cloud environment and exfiltrating data before the intrusion was detected

Cisco disclosed in February 2021 that unauthorized actors had compromised AWS IAM credentials associated with the Cisco WebEx Teams video conferencing service. The attackers …

Ransomware

University Hospital Düsseldorf Ransomware — First Ransomware-Attributed Patient Death

2020-09-09 [vendor] University Hospital Düsseldorf IT infrastructure / Citrix ADC [malware] DoppelPaymer ransomware [cve] CVE-2019-19781
Vector: Ransomware group exploited CVE-2019-19781 — a critical path traversal vulnerability in Citrix Application Delivery Controller (Citrix ADC / NetScaler) — to gain initial access to University Hospital Düsseldorf's network; the unpatched Citrix vulnerability had been known and widely exploited since January 2020

On 9 September 2020, ransomware (assessed as DoppelPaymer) crippled the IT systems of University Hospital Düsseldorf (Universitätsklinikum Düsseldorf) — one of Germany's largest …

Credential theft

Spotify Credential Stuffing Attack — ~350K Accounts

2020-09-01 [vendor] Spotify
Vector: Credential stuffing — attackers used a database of approximately 380 million records (username/password pairs from unrelated third-party breaches) to systematically attempt logins on Spotify accounts; valid credential matches were used for account takeover

In November 2020, security researchers at vpnMentor discovered an unsecured Elasticsearch database containing approximately 380 million records including usernames, passwords, and …

Supply chain [SC]

Luxottica Breach Affecting LensCrafters, EyeMed, Target Optical (August–September 2020)

2020-08-05 [vendor] Luxottica [malware] Nefilim ransomware
Vector: Hacking of Luxottica's web-based appointment scheduling application; followed by separate Nefilim ransomware attack on September 18, 2020

Luxottica, the Italian eyewear conglomerate and parent company of EyeMed Vision Care, LensCrafters, Target Optical, and Pearle Vision, suffered two separate but related security …

Supply chain [SC]

Jack Daniel's Third-Party Breach (August 2020)

2020-08-01 [vendor] Brown-Forman
Vector: Compromise of third-party service provider / vendor relationship

Jack Daniel’s-Maker Suffers REvil Ransomware Breach. Attackers claim to have 1TB of stolen data in their possession. US wine and spirits giant Brown-Forman has become the latest …

Supply chain [SC]

Rochester YMCA Third-Party Breach (August 2020)

2020-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Data Breach May Have Affected Some Rochester YMCA Accounts. Donors of the Rochester YMCA have been notified of a data breach that may have affected their personal information. …

Cloud

Razer Gaming Peripheral Data Exposure — 100,000 Customers' PII via Elasticsearch

2020-08-01 [vendor] Razer customer Elasticsearch cluster
Vector: Razer's customer data was inadvertently exposed through a misconfigured Elasticsearch cluster that was publicly accessible without authentication; the misconfiguration was set up by a vendor and the public exposure lasted approximately one month before being discovered

In August 2020, security researcher Volodymyr Diachenko discovered a publicly accessible Elasticsearch cluster belonging to Razer — the US gaming hardware company known for gaming …

Ransomware

Garmin WastedLocker Ransomware Attack — Evil Corp ($10M Ransom, 5-Day Outage)

2020-07-23 [malware] WastedLocker ransomware; FakeUpdates (SocGholish)
Vector: Evil Corp used FakeUpdates (SocGholish) — fake browser update JavaScript injected into compromised websites — to deliver a NetSupport RAT dropper that installed WastedLocker ransomware on Garmin's corporate network

On July 23, 2020, Evil Corp (a Russian cybercrime organization led by Maksim Yakubets, sanctioned by OFAC) deployed WastedLocker ransomware against Garmin, encrypting the company's …

Ai

Microsoft AI Research Team 38TB Exposure via Misconfigured Azure SAS Token

2020-07-20 [vendor] Microsoft Azure Blob Storage (SAS token misconfiguration)
Vector: Misconfigured Azure SAS (Shared Access Signature) token published to a public GitHub repository by Microsoft AI researchers; the SAS token was configured with 'full control' permissions on an entire Azure Blob Storage account rather than read-only access to a specific folder — granting any GitHub visitor read, write, and delete access to all 38TB of data in the account

On July 20, 2020, Microsoft's AI research team published open-source AI training data to GitHub and inadvertently included an overpermissioned Azure SAS token in the repository. …

Other

GEDmatch DNA Genealogy Database Breach — 1.45 Million Profiles Opted Into Law Enforcement

2020-07-19 [vendor] GEDmatch DNA genealogy database
Vector: An attacker compromised GEDmatch's database and changed the privacy settings of all 1.45 million user profiles from 'opt-out' to 'opt-in' for law enforcement searches; separately, a distributed denial-of-service (DDoS) attack was used to distract from the breach; the full details of the intrusion vector were not disclosed

On 19-20 July 2020, GEDmatch — a popular free genealogy DNA comparison service with approximately 1.45 million registered users — suffered a cyberattack that changed the privacy …

Credential theft

Twitter 2020 Bitcoin Scam: Social Engineering of Admin Tools (130 High-Profile Accounts)

2020-07-15 [vendor] Twitter internal admin tools ('God Mode')
Vector: Vishing (voice phishing) calls targeting Twitter employees not in the office due to COVID-19; attackers impersonated Twitter IT staff to trick employees into providing credentials to a fake VPN portal, then used those credentials to access Twitter's internal admin tools

On July 15, 2020, attackers hijacked approximately 130 high-profile Twitter accounts including Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple, Uber, Jeff Bezos, Kanye West, …

Data leak

Freepik / Flaticon Breach — 8.3 Million User Accounts

2020-07-01 [vendor] Freepik / Flaticon website database
Vector: An attacker used an SQL injection vulnerability in Freepik's website to access the Freepik and Flaticon user databases; the SQL injection gave the attacker access to the database tables containing user credentials and personal information

In August 2020, Freepik — one of the world's largest stock photography and design resources websites (along with its vector icon subsidiary Flaticon) — disclosed a data breach …

Supply chain [SC]

Citrix Third-Party Breach (July 2020)

2020-07-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Citrix data exposed in third-party breach | TechTarget. Citrix Tuesday published a blog confirming that a third-party organization is investigating a possible data breach after a …

Supply chain [SC]

Promo.com Third-Party Breach (July 2020)

2020-07-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Web Application Security, Testing, & Scanning - PortSwigger. PortSwigger offers tools for web application security, testing, & scanning. Choose from a range of security tools, & …

Ai

Microsoft AI Research Division 38TB Data Exposure via SAS Token — GitHub Misconfiguration

2020-07-01 [vendor] Microsoft Azure Storage (AI division internal data)
Vector: Microsoft AI researchers accidentally included an overly permissive Azure Shared Access Signature (SAS) token when publishing open-source training data to a public GitHub repository; the SAS token granted full read-write-delete access to the entire Azure Storage account — not just the intended public dataset

In July 2020, Microsoft's AI research division accidentally published an Azure Shared Access Signature (SAS) token with overly permissive access when sharing an open-source …

Credential theft

MEDNAX AWS Misconfiguration Breach — 1.3 Million Patients via Phishing

2020-06-17 [vendor] MEDNAX Microsoft Office 365 / patient data systems
Vector: A phishing attack compromised the Microsoft Office 365 email accounts of multiple MEDNAX employees; the attackers used the compromised email accounts to access MEDNAX's business systems and then exfiltrated patient data from the company's healthcare platforms

In June 2020, MEDNAX — a national health solutions company providing physician services management, including neonatology and pediatric subspecialty care, to approximately 120,000 …

Cloud

Drizly GitHub Credentials and RDS Database Breach

2020-06-12 [vendor] GitHub; Amazon RDS; Amazon Web Services
Vector: Attacker found Drizly AWS credentials stored in an unsecured GitHub repository (accessible to all Drizly employees), used them to access an RDS database containing 2.5 million customer records

In June 2020, Drizly (an online alcohol delivery service) suffered a data breach when an attacker discovered AWS credentials stored in a plaintext format in an internal GitHub …

Supply chain [SC]

Dave Banking App via Waydev OAuth Token Theft (July 2020)

2020-06-10 [vendor] Waydev (git analytics third-party vendor)
Vector: Blind SQL injection in Waydev analytics platform used to steal GitHub and GitLab OAuth tokens, enabling downstream access to Dave user database

In July 2020, the personal data of approximately 7.5 million users of Dave — a US-based neobank and personal finance app — was compromised and subsequently leaked on a public …

Data leak

Wattpad Data Breach — 268 Million User Accounts

2020-06-01 [vendor] Wattpad user database
Vector: Database breach via unknown vulnerability in Wattpad's backend infrastructure; approximately 268 million records were obtained from the platform's user database and subsequently offered for sale on hacker forums

In June 2020, Wattpad — the online creative writing platform with over 90 million users — suffered a data breach exposing approximately 268 million user records. The data was …

Supply chain [SC]

Keepnet Third-Party Breach (June 2020)

2020-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Keepnet Labs confirms contractor exposed 'data breach database' of 5 billion records. Keepnet Labs has confirmed that a contractor temporarily exposed a database containing five …

Supply chain [SC]

MU Health Third-Party Breach (June 2020)

2020-06-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

MU Health reports data breach. University of Missouri Health Care said Thursday that it has notified patients affected by a September data breach. The organization said in a news …

Supply chain [SC]

Police Departments Third-Party Breach (June 2020)

2020-06-01 [vendor] NetSentiel
Vector: Compromise of third-party service provider / vendor relationship

‘BlueLeaks’ Exposes Files from Hundreds of Police Departments. Hundreds of thousands of potentially sensitive files from police departments across the United States were leaked …

Credential theft

Wattpad Data Breach (268M Users, ShinyHunters)

2020-06-01
Vector: Unauthorized database access by ShinyHunters threat group; exact initial access vector not disclosed by Wattpad; database exfiltrated containing 268M user account records

In approximately June 2020, ShinyHunters — a prolific cybercrime group responsible for multiple major 2020 breaches (Tokopedia, Dave.com, Microsoft GitHub repos) — breached Wattpad …

Cloud [SC]

Joomla Third-Party Breach (June 2020)

2020-06-01 [vendor] Open Source Matters
Vector: Compromise of third-party service provider / vendor relationship

Joomla team discloses data breach. Joomla says a team member left an unencrypted backup of the JRD portal on a private AWS S3 bucket. The team behind the Joomla open source content …

Data leak

Experian South Africa Data Breach (24M Individuals, 793K Businesses)

2020-05-01
Vector: A fraudster posing as a legitimate client of Experian South Africa used social engineering to convince Experian to provide a dataset containing personal information; the attacker presented fraudulent credentials and business information to obtain the data transfer

In August 2020, Experian South Africa disclosed that a suspected fraudster had obtained personal data of approximately 24 million South African individuals and 793,749 businesses …

Supply chain [SC]

Bank of America Third-Party Breach (May 2020)

2020-05-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Bank of America Responds to Breach. Bank of America blames a suspected breach of credit card data on an unidentified third party. What happened, and what can other institutions do …

Supply chain [SC]

MNS' Healthcare Clients Third-Party Breach (May 2020)

2020-05-01 [vendor] Management and Network Services – MNS
Vector: Compromise of third-party service provider / vendor relationship

Management and Network Services Notifies 30,132 Patients About PHI Breach. Management and Network Services has discovered multiple email accounts have been compromised. The PHI of …

Supply chain [SC]

TrueCaller Third-Party Breach (May 2020)

2020-05-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

TrueCaller Data of 4.75 Cr Indians for Sale On Dark Web: Report. Online intelligence firm Cyble flagged that a cybercriminal was selling Truecaller records of 4.75 crore Indians on …

Ransomware

Cognizant / BleepingComputer / SC Magazine

2020-04-18 [malware] Maze
Vector: CWE-506: Embedded Malicious Code (Maze ransomware; initial access vector not publicly confirmed, likely phishing or exploitation of exposed services)

Maze ransomware group attacked Cognizant, a Fortune 500 IT managed services provider with ~300,000 employees, on April 18 2020. The attack disrupted services for clients across …

Ransomware

Magellan Health Ransomware Attack (365K Patients)

2020-04-11
Vector: Attackers sent a spear-phishing email impersonating a Magellan Health client, gaining access to a corporate server; exfiltrated data then deployed ransomware

Magellan Health, one of the largest managed care companies in the United States (specializing in behavioral health and pharmacy benefits), disclosed in May 2020 that it suffered a …

Ransomware

Magellan Health Ransomware Breach — 365,000 Patients and Employees

2020-04-11 [vendor] Magellan Health managed care / specialty health company IT systems
Vector: Ransomware attackers sent a phishing email impersonating a Magellan Health client to a Magellan employee; the email installed malware that harvested login credentials; the attacker used stolen credentials to gain access to the Magellan server and deployed ransomware after exfiltrating data

On 11 April 2020, Magellan Health — a Fortune 500 managed care company specialising in behavioral health, pharmacy benefits, and radiology benefits management — suffered a …

Credential theft

Service NSW Phishing Breach — 186,000 Customers, 3.8 Million Documents

2020-04-04 [vendor] Service NSW staff email accounts / customer correspondence
Vector: Phishing emails compromised the email accounts of 47 Service NSW staff members; from the compromised email accounts, attackers were able to access customer data processed through Service NSW email correspondence and attached documents

In April 2020, 47 Service NSW employee email accounts were compromised through a phishing attack, allowing unauthorized access to customer data processed through those email …

Credential theft

Nintendo Account Credential Stuffing — 160,000 Accounts Breached

2020-04-01 [vendor] Nintendo Account / Nintendo Network ID (NNID) system
Vector: Attackers used credential stuffing — username and password combinations from other data breaches — to log into Nintendo accounts via the legacy Nintendo Network ID (NNID) login system; the NNID system was being deprecated and allowed third-party login to Nintendo accounts

In April 2020, Nintendo disclosed that approximately 160,000 Nintendo accounts had been accessed without authorisation using a credential stuffing attack against the Nintendo …

Cloud

Zoom Credential Stuffing — 500,000 Accounts Sold on Dark Web

2020-04-01 [vendor] Zoom Video Communications user accounts
Vector: Credential stuffing using credentials from previously breached services — attackers compiled email/password combinations from unrelated data breaches and tested them against Zoom accounts, successfully accessing accounts where users had reused passwords

In April 2020, at the height of the COVID-19 pandemic when Zoom usage had surged from approximately 10 million to 300 million daily meeting participants in three months, …

Cloud [SC]

FireEye / CISA / US GAO / Rapid7

2020-03-26 [vendor] SolarWinds Orion Platform [malware] SUNBURST / TEARDROP / SUNSPOT [cve] CVE-2020-10148
Vector: CWE-506: Embedded Malicious Code inserted into SolarWinds Orion build pipeline

Russian SVR (APT29/Cozy Bear) compromised SolarWinds build environment and injected SUNBURST backdoor into Orion software updates distributed March-June 2020. ~18,000 customers …

Cloud

CAM4 Elasticsearch Misconfiguration (10.88 Billion Records, Sexual Orientation Data)

2020-03-16 [vendor] Elasticsearch
Vector: Misconfigured Elasticsearch production logging database left publicly accessible on the internet without authentication; no malicious actor required — the data was fully open to anyone who found the server

On March 16, 2020, researchers at Safety Detectives discovered a production Elasticsearch logging database belonging to CAM4 (an adult live-streaming platform operated by Granity …

Ransomware

ProPublica / BleepingComputer / DataBreaches.net

2020-03-13 [malware] CLOP
Vector: CWE-506: Embedded Malicious Code (CLOP ransomware; initial vector not confirmed)

CLOP ransomware group attacked ExecuPharm, a US clinical research organisation (CRO) and pharmaceutical services company, on March 13 2020. After the company declined to pay, CLOP …

Cloud

First Republic Bank AWS Insider Threat Data Exfiltration

2020-03-11 [vendor] Amazon Web Services (AWS)
Vector: A First Republic Bank employee with legitimate AWS access used their credentials to exfiltrate customer data from AWS-hosted banking systems

In March 2020, First Republic Bank (a US private bank and wealth management company) disclosed that an insider threat incident had occurred. A bank employee with legitimate access …

Data leak

Norwegian Cruise Line Holdings Data Breach — Employee Phishing Attack

2020-03-01
Vector: Phishing — employees of Norwegian Cruise Line Holdings were targeted with phishing emails that resulted in unauthorized access to employee email accounts; attackers then accessed personal data of employees, travel agents, and some customers stored in those accounts

Norwegian Cruise Line Holdings (NCLH), parent company of Norwegian Cruise Line, Regent Seven Seas Cruises, and Oceania Cruises, disclosed in July 2020 that it had suffered a data …

Supply chain [SC]

Chubb Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Cyber insurer Chubb had data stolen in Maze ransomware attack. Chubb, a major cybersecurity insurance provider for businesses hit by data breaches, has itself become a target of a …

Supply chain [SC]

General Electric Third-Party Breach (March 2020)

2020-03-01 [vendor] Canon Business Services
Vector: Compromise of third-party service provider / vendor relationship

Third-party data breach exposes GE employees' personal information. Past and present employees of GE are learning that their sensitive information has been exposed by a data breach …

Supply chain [SC]

Radio.com Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Radio.com users affected in data breach. Entercom, the second-largest radio company in the United States, has announced that it suffered a cybersecurity incident that affected …

Supply chain [SC]

T-Mobile Third-Party Breach (March 2020)

2020-03-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

T-Mobile warns customers about a recent data breach. T-Mobile this week notified customers about a data breach. According to the alert, a malicious third-party gained access to …

Credential theft

Nintendo Network ID (NNID) Credential Stuffing — 160,000 Accounts Compromised

2020-03-01 [vendor] Nintendo Network ID (NNID) / Nintendo Account
Vector: Credential stuffing — attackers used previously leaked username/password combinations to log into Nintendo Network IDs (NNIDs) via a legacy login portal; successful logins allowed attackers to access linked Nintendo Accounts and make fraudulent purchases via saved payment methods

In April 2020, Nintendo disclosed that approximately 160,000 Nintendo Network IDs (NNIDs) — a legacy login system from the Nintendo 3DS and Wii U era — had been compromised via …

Cloud

Zoom Credential Stuffing — 530K Accounts Sold on Dark Web

2020-03-01 [vendor] Zoom Video Communications
Vector: Credential stuffing — attackers used large lists of username/password combinations from prior unrelated data breaches to attempt automated logins to Zoom accounts; successful matches were then compiled and sold

In April 2020, cybersecurity firm Cyble reported discovering approximately 530,000 Zoom account credentials being sold on dark web forums for as little as a fraction of a cent …

Credential theft

T-Mobile / Motherboard Vice / BleepingComputer

2020-02-19
Vector: CWE-285: Improper Authorisation (malicious actors gained access to T-Mobile employee email accounts, which contained customer information)

T-Mobile disclosed a breach on March 5 2020 affecting approximately 200,000 customers. Attackers had accessed some T-Mobile employee email accounts containing customer proprietary …

Ransomware [SC]

Blackbaud Cloud CRM Ransomware and Data Exfiltration — Nonprofits, Universities, Hospitals

2020-02-07 [vendor] Blackbaud CRM (cloud fundraising and constituent relationship management platform)
Vector: Ransomware group gained access to Blackbaud's self-hosted customer cloud environments; the attackers spent approximately five months conducting reconnaissance and exfiltrating data prior to deploying ransomware; initial access vector was not fully disclosed

In February 2020, attackers breached Blackbaud — the world's largest provider of nonprofit and education CRM/fundraising software — and spent approximately five months in the …

Supply chain [SC]

Blackbaud CRM Ransomware/Data Theft (Nonprofits, Universities, Healthcare)

2020-02-07 [vendor] Blackbaud cloud CRM platform
Vector: Ransomware attackers infiltrated Blackbaud's self-hosted cloud environment; before deploying ransomware, exfiltrated a copy of a subset of data from its cloud backup environment; Blackbaud paid the ransom in exchange for assurance the data was deleted

Blackbaud, the world's largest provider of cloud software for nonprofits, universities, healthcare organizations, and foundations, disclosed in July 2020 that it had suffered a …

Supply chain [SC]

Blackbaud Ransomware Attack Affecting Universities Globally (May–July 2020)

2020-02-07 [vendor] Blackbaud (cloud CRM and fundraising software) [malware] ransomware
Vector: Ransomware attack on Blackbaud cloud CRM infrastructure with prior data exfiltration; ransom paid to obtain deletion assurances

In May 2020, Blackbaud — one of the world's largest providers of cloud-based CRM and fundraising software for universities, hospitals, and nonprofits — suffered a ransomware attack …

Data leak

Clearview AI Database Breach — Entire Customer List, Search History Stolen

2020-02-01 [vendor] Clearview AI client database and search history systems
Vector: Unknown attacker gained unauthorised access to Clearview AI's systems and exfiltrated the company's entire client list — including law enforcement agencies, government clients, and private entities — along with their search histories (faces searched)

In February 2020, Clearview AI — a controversial facial recognition company that scraped billions of photos from social media to build its facial recognition database, primarily …

Supply chain [SC]

Carson City Third-Party Breach (February 2020)

2020-02-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Hackers compromise financial information for Carson City residents who pay water bill online - Carson Now. According to a letter sent out to a group of residents who pay their …

Supply chain [SC]

Nedbank Third-Party Breach (February 2020)

2020-02-01 [vendor] Computer Facilities (Pty) Ltd
Vector: Compromise of third-party service provider / vendor relationship

Nedbank says 1.7 million customers impacted by breach at third-party provider. Hacker(s) believed to have exploited a vulnerability to breach Nedbank's marketing contractor. …

Supply chain [SC]

Rutters Store Third-Party Breach (February 2020)

2020-02-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Rutters store chain reveals malware attacked its POS system. Convenience store company warns that malware collected payment card details as they were being processed. Convenience …

Supply chain [SC]

Amazon Insider Data Leak (January 2020)

2020-01-10 [vendor] Amazon
Vector: Malicious insider / rogue employee data exfiltration to unauthorized third party

In January 2020, Amazon discovered that one or more employees had shared customer email addresses and phone numbers with an unauthorized third party in violation of company policy. …

Data leak

EasyJet Data Breach — 9 Million Customers, 2,208 Credit Cards

2020-01-01 [vendor] EasyJet customer booking systems
Vector: Sophisticated cyber attack; specific technical vector not publicly disclosed; EasyJet stated it was a highly sophisticated attacker; email addresses and travel details were the primary target alongside payment card data for a subset of customers

EasyJet disclosed on 19 May 2020 that it had suffered a cyberattack that exposed the personal data of approximately 9 million customers. The attack was first detected in late …

Data leak

EasyJet Data Breach — 9 Million Customers, 2,208 Credit Cards

2020-01-01
Vector: Sophisticated cyberattack against easyJet's systems; the specific technical attack vector was not publicly disclosed by the airline, but the UK's National Cyber Security Centre (NCSC) and ICO investigated

In May 2020, easyJet (the UK-based low-cost airline) disclosed that it had suffered a cyberattack in which approximately 9 million customers had their email addresses and travel …

Data leak

National General / Allstate Insurance Quoting Portal Data Breach

2020-01-01
Vector: Application vulnerability in online quoting websites that displayed full driver's licence numbers in plain text with minimal user input; scraped by automated attackers

National General (later acquired by Allstate) suffered two sequential data breaches via its online auto insurance quoting portals. First breach (2020): exposed driver's licence …

Supply chain [SC]

Regus Third-Party Breach (January 2020)

2020-01-01 [vendor] Applause
Vector: Compromise of third-party service provider / vendor relationship

WeWork rival Regus in massive employee data breach. This feature is available for registered users. Please register or log in to continue. …

Credential theft

Marriott International 2020 Breach — 5.2 Million Guests via Employee Credentials

2020-01-01 [vendor] Marriott guest services application
Vector: An attacker used the login credentials of two Marriott employees at a franchise property to access a Marriott application used to provide services to guests; the attacker accessed guest data through the legitimate employee login for approximately two months before detection

In March 2020, Marriott International disclosed a second data breach (separate from the 2018 Starwood breach affecting 383 million guests) in which an attacker used the login …

Cloud

Estée Lauder Unsecured Elasticsearch Database — 440 Million Records

2020-01-01 [vendor] Estée Lauder Companies Elasticsearch database
Vector: Security researcher Jeremiah Fowler discovered that Estée Lauder's internal Elasticsearch database was publicly accessible without any authentication or password protection; the database contained internal records and email addresses

In February 2020, security researcher Jeremiah Fowler discovered a publicly accessible Elasticsearch database belonging to Estée Lauder — one of the world's largest cosmetics and …

Cloud

Travelex REvil Ransomware via Unpatched Pulse Secure VPN (Company Collapse)

2019-12-31 [vendor] Pulse Secure VPN [malware] REvil (Sodinokibi) ransomware [cve] CVE-2019-11510
Vector: REvil (Sodinokibi) exploited CVE-2019-11510, a critical path traversal vulnerability in Pulse Secure VPN that allowed unauthenticated remote file reading, including cached plaintext VPN credentials; patch had been available since April 2019

On New Year's Eve 2019, REvil ransomware operators exploited CVE-2019-11510 in Travelex's unpatched Pulse Secure VPN to gain initial access to Travelex's corporate network. …

Supply chain [SC]

City of Sioux Third-Party Breach (December 2019)

2019-12-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Data security breach impacts City of Sioux City customers. SIOUX CITY -- A data security breach has potentially impacted more than 3,500 City of Sioux City customer utility and …

Data leak

T-Mobile Prepaid Account Data Breach — 1 Million Customers (CPNI Exposure)

2019-11-22 [vendor] T-Mobile prepaid account management systems
Vector: Unknown attacker gained unauthorized access to T-Mobile's prepaid account information through a misconfigured API or application server; T-Mobile stated it was a criminal attack that gained access to prepaid account subscriber information

On 22 November 2019, T-Mobile detected and stopped a cyberattack that gained access to information for approximately 1 million T-Mobile prepaid customers. T-Mobile disclosed the …

Supply chain [SC]

Florida Blue Third-Party Breach (November 2019)

2019-11-01 [vendor] Magellan Health Inc
Vector: Compromise of third-party service provider / vendor relationship

Data breach put thousands of Florida Blue members' personal information at risk. A data breach at Magellan Health Inc. has put the personal information of Florida Blue members at …

Supply chain [SC]

Macy's Third-Party Breach (November 2019)

2019-11-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Macy’s suffers online Magecart card-skimming attack, data breach. The department store detected malicious code in its online payment portal. Macy's has announced a data breach …

Credential theft

T-Mobile 2019 Prepaid Customer Breach (1.26M Accounts)

2019-11-01
Vector: Unauthorized access to T-Mobile systems containing prepaid customer data; specific access vector not disclosed publicly; distinct from the 2021 John Binns breach affecting 54M records

In November 2019, T-Mobile's cybersecurity team identified and shut down unauthorized access to systems containing prepaid customer account information. Approximately 1.26 million …

Data leak

Cerebral Mental Health Tracking Pixel Breach (3.18M Patients, Meta/Google/TikTok)

2019-10-12 [vendor] Meta Pixel; Google advertising SDK; TikTok Pixel
Vector: Intentional data sharing via third-party advertising tracking pixels — Cerebral embedded Meta Pixel, Google analytics/advertising, TikTok Pixel, and other trackers on its website and apps that transmitted sensitive mental health patient data to advertising platforms without patients' knowledge or valid HIPAA authorization

Cerebral, a US telehealth startup specializing in mental health treatment (therapy, psychiatry, and medication management), disclosed in March 2023 that it had transmitted …

Data leak

Cerebral Mental Health Data Shared with Meta and Google — 3.1 Million Patients

2019-10-01
Vector: Third-party tracking pixels — Cerebral used Meta Pixel, Google Analytics, TikTok Pixel, and other advertising trackers on its website and app; these trackers automatically captured and transmitted sensitive mental health information, medication details, and personal identifiers to advertising platforms

Cerebral, a telehealth company specializing in mental health services (particularly ADHD and anxiety/depression treatment), disclosed in March 2023 that it had shared sensitive …

Supply chain [SC]

CenturyLink Third-Party Breach (October 2019)

2019-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

CenturyLink customers may have had data exposed in 'security incident'. The company says the incident involving a third party vendor may have exposed contact information. GOLDEN …

Supply chain [SC]

UniCredit Third-Party Breach (October 2019)

2019-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Our pick of the top fintech news stories this week includes Revolut, Coinbase, Bolt, FundApps, and more. Copyright © 2026 Informa PLC. Informa PLC is registered in England and …

Supply chain [SC]

Active Network Blue Bear Platform — Web Skimming Attack on School Stores (2019–2020)

2019-10-01 [vendor] Active Network (Blue Bear platform) [malware] JavaScript web skimmer
Vector: Web skimming (Magecart-style) attack — malicious JavaScript injected into Blue Bear school e-commerce platform to harvest payment card data at point of entry

Between October 1 and November 13, 2019, unknown attackers gained unauthorized access to Blue Bear, Active Network's web-based school accounting and online store management …

Supply chain [SC]

Malinda Air Third-Party Breach (September 2019)

2019-09-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Malinda Air locks down publicly exposed servers. Indonesian budget airline Malindo Air reported on September 19 it had locked down the formerly publicly exposed servers that had …

Supply chain [SC]

Yves Rocher Third-Party Breach (September 2019)

2019-09-01 [vendor] Aliznet
Vector: Compromise of third-party service provider / vendor relationship

Cosmetics Giant Yves Rocher Caught in Data Leak Impacting Millions of Customers. International cosmetics brand Yves Rocher found itself caught in a third-party data exposure …

Supply chain [SC]

Mastercard Priceless Specials Loyalty Program Breach

2019-08-19 [vendor] Priceless Specials loyalty platform (third-party operated)
Vector: Third-party loyalty program operator compromise; data exfiltrated and posted publicly online

On August 19, 2019, data belonging to approximately 90,000 members of Mastercard's Priceless Specials loyalty program was posted publicly on the internet, triggering Mastercard to …

Ransomware

Wood Ranch Medical Clinic — Ransomware Causes Permanent Closure

2019-08-10 [vendor] Wood Ranch Medical Clinic (Simi Valley, California)
Vector: Ransomware attack against Wood Ranch Medical Clinic's servers and electronic health record (EHR) backup systems; both primary and backup systems were encrypted, making recovery impossible without paying the ransom; the clinic did not have offline backups

Wood Ranch Medical Clinic, a small family medical practice in Simi Valley, California, announced in August 2019 that it would permanently close on December 17, 2019 following a …

Supply chain [SC]

DeKalb School District 428, Wilmette Public Schools District 39,The School District of Clayton,Brighton, Brockport, East Irondequoit, Fairport, East Rochester, Greece, Pittsford, Rochester, Spencerport, Victor, Webster and West Irondequoit school districts Third-Party Breach (August 2019)

2019-08-01 [vendor] Pearson Clinical Assessment (AIMSweb)
Vector: Compromise of third-party service provider / vendor relationship

Daily Chronicle. News • Sports • eNewspaper • Obituaries • Election • The Scene • 175 Years. …

Supply chain [SC]

Volkswagen/Audi Shift Digital Breach — 3.3M Customers, Unsecured Cloud Data 2019–2021

2019-08-01 [vendor] Shift Digital (digital marketing vendor for Volkswagen Group of America)
Vector: Misconfigured cloud storage — Shift Digital left an unsecured dataset containing VW/Audi customer data exposed on the internet between August 2019 and May 2021

Volkswagen Group of America and Audi of America disclosed in June 2021 that approximately 3.3 million customers and prospective buyers had their personal data exposed due to an …

Cloud

BioStar 2 Biometric Security Platform Exposure — 27.8 Million Records, 1 Million Fingerprints

2019-08-01 [vendor] Suprema BioStar 2 biometric access control platform
Vector: Security researchers at vpnMentor discovered that Suprema's BioStar 2 web-based security platform had a publicly accessible, unprotected Elasticsearch database; the database was accessible without authentication and contained the biometric and security management data for the platform's clients

In August 2019, vpnMentor security researchers Noam Rotem and Ran Locar discovered a publicly accessible Elasticsearch database belonging to Suprema — a South Korean security …

Data leak [SC]

Choice Hotels Vendor MongoDB Exposure (700K Guest Records)

2019-07-02 [vendor] MongoDB (third-party vendor deployment)
Vector: Third-party vendor misconfigured an unauthenticated MongoDB database, publicly exposing 5.6 million guest records copied from Choice Hotels' systems for use in testing a security product — without authorization; automated scripts also left a ransom note demanding 0.4 BTC

On approximately July 2, 2019, security researcher Bob Diachenko (working with Comparitech) discovered a publicly accessible, unauthenticated MongoDB database containing …

Data leak

7-Eleven Japan Mobile App Flaw — $500K Stolen from Customers

2019-07-01 [vendor] 7pay mobile app (Seven & i Holdings)
Vector: Application vulnerability — the 7pay app (7-Eleven Japan's new mobile payment application) had a flawed password reset mechanism that allowed attackers to reset any account's password by supplying only the account holder's email address, date of birth, and phone number; a design flaw also allowed password reset links to be sent to a third-party email address

On July 1, 2019, the day the 7pay mobile payment app launched in Japan, criminals immediately began exploiting a critical vulnerability in the app's password reset mechanism. The …

Supply chain

Dickey's Barbecue Pit POS Malware Breach — 3M Cards on Joker's Stash (2019–2020)

2019-07-01 [vendor] Not disclosed [malware] POS memory-scraping malware (specific family not disclosed)
Vector: Point-of-sale (POS) malware installed on in-store payment systems; likely facilitated by remote access compromise or supply chain intrusion into POS provider

Dickey's Barbecue Pit, a Dallas-based smoked-meat restaurant chain with approximately 469 locations across the United States, suffered a prolonged point-of-sale (POS) malware …

Cloud

MGM Resorts 2019 Data Breach — 10.6 Million Guests, Dark Web Dump 2020

2019-07-01 [vendor] MGM Resorts cloud server (guest data)
Vector: An unauthorized attacker gained access to a cloud server used by MGM Resorts and extracted guest data; MGM had stored the data in a cloud server that was accessible without proper authentication controls; the breach was not discovered until ZDNet reporter Catalin Cimpanu was alerted to the data being circulated on a hacking forum

In July 2019, an attacker accessed a cloud server at MGM Resorts International and extracted personal data for approximately 10.6 million hotel guests. The breach went undetected …

Supply chain [SC]

Mitsubishi Electric Breach — Tick APT / Trend Micro OfficeScan Zero-Day (2019–2020)

2019-06-28 [vendor] Trend Micro OfficeScan (via China-based affiliated company) [cve] CVE-2019-18187
Vector: Exploitation of zero-day vulnerability (CVE-2019-18187) in Trend Micro OfficeScan antivirus via compromised China-based affiliate, enabling lateral movement to Japan headquarters

On June 28, 2019, threat actors — widely attributed to the Chinese state-sponsored APT group known as Tick (also tracked as Bronze Butler and associated with APT40) — breached …

Data leak

Bulgarian National Revenue Agency Hack — 5 Million Taxpayer Records

2019-06-01 [vendor] Bulgarian National Revenue Agency (NAP) web application / taxpayer database
Vector: A hacker (later identified as a 20-year-old Bulgarian cybersecurity specialist) exploited a SQL injection vulnerability in the Bulgarian National Revenue Agency (NRA) web application to extract taxpayer data from the agency's database

In July 2019, the Bulgarian National Revenue Agency (Национална агенция за приходите, NAP) suffered the largest data breach in Bulgarian history. A hacker sent a link to the stolen …

Data leak [SC]

Sprint Customer Data Exposure via Samsung 'Add a Line' Website Vulnerability

2019-06-01 [vendor] Samsung 'Add a Line' retail portal for Sprint
Vector: Third-party website vulnerability — hackers exploited a security flaw in Samsung's 'Add a Line' webpage (a retail portal used to add new Sprint lines), which allowed unauthorized access to Sprint customer account data

In June/July 2019, Sprint discovered that hackers had exploited a vulnerability on Samsung's 'Add a Line' promotional webpage — a co-branded retail portal used to add new Sprint …

Supply chain [SC]

Komodo Third-Party Breach (June 2019)

2019-06-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Latest Blockchain News, BSV Insights, and AI Web3 Trends from CoinGeek. A serious vulnerability has been discovered in a cryptocurrency wallet app, putting millions of dollars’ …

Data leak

Canva Data Breach — 137 Million Users, GnosticiPlayers

2019-05-24 [vendor] Canva user database / Google Cloud Storage
Vector: The hacker GnosticiPlayers (responsible for multiple high-profile breaches in 2019) accessed Canva's user database via an unknown vulnerability; the attacker was able to view file names of private design files stored in Google Cloud Storage but could not access their contents

On 24 May 2019, the graphic design platform Canva was breached by the GnosticiPlayers hacker collective. Approximately 137 million user records were stolen, containing usernames, …

Credential theft

Canva Data Breach (137M Users, GnosticPlayers)

2019-05-24
Vector: Unauthorized database access by threat actor GnosticPlayers; attacker claimed to have exploited a vulnerability in Canva's systems (exact vector not publicly confirmed by Canva); affected database contained user account records including bcrypt-hashed passwords

On May 24, 2019, Canva — the Australian graphic design SaaS platform — suffered a data breach in which threat actor GnosticPlayers exfiltrated approximately 137 million user …

Supply chain [SC]

Instagram Influencer Data Exposed via Chtrbox Unsecured Database

2019-05-14 [vendor] Chtrbox (Mumbai-based Instagram influencer marketing platform)
Vector: Misconfigured cloud database (unauthenticated instance, no password protection)

In May 2019, security researcher Anurag Sen discovered a large, unsecured database containing scraped Instagram profile data for approximately 49 million users, which he traced to …

Other

Binance Bitcoin Exchange Hack — 7,000 BTC (~$40M)

2019-05-07 [vendor] Binance (world's largest cryptocurrency exchange by trading volume)
Vector: Coordinated attack combining phishing, viruses, and other techniques to steal API keys, two-factor authentication codes, and potentially other user information; attackers accumulated API keys and 2FA codes from a large number of Binance users over an extended period, then executed the withdrawal in a single large transaction that bypassed Binance's automated risk management systems by exploiting the user-level API permissions

On May 7, 2019, Binance CEO Changpeng Zhao (CZ) announced that hackers had stolen 7,000 BTC (worth approximately $40 million) from the exchange's hot wallet in a single large …

Data leak

StockX Sneaker Marketplace Breach — 6.8 Million Users

2019-05-01 [vendor] StockX sneaker resale marketplace user database
Vector: An unknown hacker gained unauthorized access to StockX's systems and obtained a copy of the user database; the attacker reached out to Vice/Motherboard journalist Lorenzo Franceschi-Bicchierai offering to sell the stolen data, which prompted investigation and disclosure

In May 2019, an attacker obtained user data from StockX — the Detroit-based sneaker and streetwear authentication and resale marketplace valued at over $1 billion. The breach went …

Supply chain [SC]

4,600 websites Third-Party Breach (May 2019)

2019-05-01 [vendor] Picreel and Alpaca Forms
Vector: Compromise of third-party service provider / vendor relationship

Hackers are collecting payment details, user passwords from thousands of sites. Servers of at least seven companies compromised to deliver malicious code to thousands of sites. …

Supply chain [SC]

Forbes Third-Party Breach (May 2019)

2019-05-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Forbes Becomes Latest Victim of Magecart Payment Card Skimmer. The web skimming script was recently found stealing payment data on the websites of Forbes Magazine as well as seven …

Supply chain [SC]

Truecaller Third-Party Breach (May 2019)

2019-05-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Truecaller Users’ Phone Numbers & Email IDs For Sale on Dark Web. Truecaller Number Search App: The caller ID company with more than millions of users in India caters to mobile …

Supply chain [SC]

U.S. Customs and Border Protection via Perceptics Subcontractor Breach

2019-05-01 [vendor] Perceptics LLC [malware] ransomware (unnamed, targeted subcontractor network)
Vector: Unauthorized data transfer to subcontractor network followed by ransomware attack on subcontractor

In May–June 2019, U.S. Customs and Border Protection (CBP) experienced a major privacy and cybersecurity incident involving the unauthorized exposure of traveler facial recognition …

Supply chain [SC]

UNIQLO Third-Party Breach (May 2019)

2019-05-01 [vendor] not
Vector: Compromise of third-party service provider / vendor relationship

Cyber-attack affects over 460,000 online store accounts. The compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase …

Supply chain [SC]

Webstorage users Third-Party Breach (May 2019)

2019-05-01 [vendor] ASUS Webstorage
Vector: Compromise of third-party service provider / vendor relationship

ASUS WebStorage abused to spy on users at the router level. Vulnerable software is potentially facilitating surveillance and data theft. The ASUS WebStorage system is being …

Supply chain [SC]

Cable ONE Employee Email Account Breach

2019-05-01 [vendor] not disclosed (third-party email or HR vendor)
Vector: Unauthorized access to employee email accounts via compromised third-party vendor; approximately 14 accounts accessed

In May 2019, Cable ONE (now Sparklight), a US cable television and internet provider headquartered in Phoenix, Arizona, discovered that an unauthorized individual had gained access …

Cloud

Docker Hub Database Breach — 190,000 User Accounts, GitHub and Bitbucket Tokens

2019-04-25 [vendor] Docker Hub user database
Vector: Unauthorized access to a database storing a subset of non-financial Docker Hub user data; Docker stated the database was accessed without authorization but did not disclose the specific attack vector

On 25 April 2019, Docker discovered unauthorized access to a Docker Hub database containing data for approximately 190,000 accounts (less than 5% of Hub users). Docker Hub is the …

Supply chain [SC]

PrismRBS / Mirrorthief Magecart Skimming Attack — 201 Campus Stores, 176+ Colleges (April 2019)

2019-04-14 [vendor] PrismRBS (PrismWeb e-commerce platform) [malware] Mirrorthief JavaScript card skimmer
Vector: Magecart-style JavaScript skimmer injected into shared e-commerce library of PrismWeb platform by threat actor Mirrorthief; affected all online stores built on the platform

PrismRBS is a subsidiary of Nebraska Book Company that operates PrismWeb, a white-label e-commerce platform specifically designed for college and university campus bookstores. In …

Supply chain [SC]

Westpac Bank PayID Enumeration Attack

2019-04-07 [vendor] NPP Australia PayID platform
Vector: API enumeration / credential abuse against PayID lookup service

In June 2019, Westpac Bank disclosed that attackers had exploited its PayID lookup service to harvest the names and phone numbers of approximately 98,000 Australian banking …

Cloud

Capital One AWS SSRF/IMDSv1 Breach (106M Records, $190M Settlement)

2019-03-22 [vendor] Amazon Web Services (WAF, EC2 IMDSv1, S3)
Vector: Paige Thompson (former AWS engineer) exploited a Server-Side Request Forgery (SSRF) vulnerability in a misconfigured AWS WAF to reach the EC2 Instance Metadata Service (IMDSv1) endpoint, stealing temporary IAM role credentials; used those credentials to access 700+ S3 buckets containing Capital One customer data

On March 22-23, 2019, Paige Thompson (alias 'erratic'), a former AWS software engineer, exploited a misconfigured AWS Web Application Firewall (WAF) running on Capital One's EC2 …

Ransomware

Norsk Hydro / Norwegian NCSC / Wired / Reuters

2019-03-19 [malware] LockerGoga
Vector: CWE-522: Insufficiently Protected Credentials (Active Directory compromise via stolen credentials, possibly via prior phishing)

LockerGoga ransomware struck Norsk Hydro, one of the world's largest aluminium producers, on March 19 2019. The attack spread across 22,000 computers in 40 countries, encrypting …

Credential theft

Boost Mobile Credential Stuffing Attack (Sprint Subsidiary)

2019-03-14
Vector: Credential stuffing / account takeover — unauthorized parties used lists of phone number and PIN combinations (likely from prior breaches) to access Boost Mobile customer accounts through the customer portal

On March 14, 2019, unauthorized parties used credential stuffing techniques — using phone numbers as usernames combined with account PINs — to access an unknown number of Boost …

Supply chain [SC]

China Railway Third-Party Breach (February 2019)

2019-02-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Hacking, gone off the rails: Holiday travelers react to data breach · TechNode. We went to Beijing’s busiest train stations to ask travelers about the recent ticket-platform …

Data leak [SC]

Medibank Private 2019 Unauthorised Third-Party Access — Pre-2022 Breach

2019-02-01 [vendor] Medibank Private third-party vendor systems
Vector: Unauthorised access was obtained to customer data stored in systems managed by a third-party vendor providing services to Medibank Private; the vendor's systems were accessed without authorisation

In early 2019, Medibank Private experienced an earlier, smaller breach via a third-party vendor that accessed customer data without authorisation. This breach predated the much …

Cloud

Verifications.io Elasticsearch Exposure — 763 Million Email Records

2019-02-01 [vendor] Verifications.io Elasticsearch database
Vector: Verifications.io, an email verification service, left an Elasticsearch database containing 763 million records exposed publicly on the internet without authentication; the database was discovered by security researchers Bob Diachenko and Vinny Troia

In March 2019, security researchers Bob Diachenko and Vinny Troia discovered a massive publicly accessible Elasticsearch database belonging to Verifications.io — an email …

Supply chain [SC]

Amadeus Flight Booking System Vulnerability (January 2019)

2019-01-15 [vendor] Amadeus
Vector: Insecure direct object reference (IDOR) in web-based booking portal allowing unauthenticated enumeration of passenger name records (PNRs)

In January 2019, security researcher Noam Rotem discovered a critical vulnerability in the Amadeus Global Distribution System (GDS) that exposed passenger reservation data for …

Data leak

Tim Hortons App Covert Location Tracking — PIPEDA Investigation, Class Action

2019-01-01 [vendor] Tim Hortons mobile loyalty app (Restaurant Brands International)
Vector: The Tim Hortons mobile app collected continuous location data from users even when the app was not in use — far exceeding what was necessary for the app's stated functionality; the covert tracking persisted between app sessions without adequate consent disclosure

In June 2022, Canada's Office of the Privacy Commissioner (OPC), together with privacy commissioners from Alberta, British Columbia, and Quebec, published findings of a joint …

Data leak

Facebook 533M Phone Number Scrape (2019 Data Dumped Publicly April 2021)

2019-01-01 [vendor] Facebook (contact import API)
Vector: Attackers exploited Facebook's 'Add friend by phone number' contact import feature, which allowed mass enumeration of user accounts by phone number without rate limiting; scraped in 2019, patched by Facebook in August 2019

In early 2019, attackers exploited a feature in Facebook's contact import tool that allowed them to upload large lists of phone numbers and identify which were linked to Facebook …

Data leak

CNN Business

2019-01-01 [vendor] AT&T customer account database
Vector: CWE-284: Improper Access Control

In March 2024, AT&T confirmed that a dataset containing personal information on approximately 73 million people (7.6 million current and 65.4 million former AT&T customers) had …

Supply chain [SC]

Ascension Third-Party Breach (January 2019)

2019-01-01 [vendor] OpticsML
Vector: Compromise of third-party service provider / vendor relationship

Millions of bank loan and mortgage documents have leaked online | TechCrunch. A trove of more than 24 million financial and banking documents, representing tens of thousands of …

Supply chain [SC]

Hanover County Third-Party Breach (January 2019)

2019-01-01 [vendor] Click2Gov
Vector: Compromise of third-party service provider / vendor relationship

Custom404 • Hanover County, VA • CivicEngage. This website is AudioEye enabled and is being optimized for accessibility. To open the AudioEye Toolbar, press "shift + =". Some …

Supply chain [SC]

Humana Third-Party Breach (January 2019)

2019-01-01 [vendor] LCP Corp.
Vector: Compromise of third-party service provider / vendor relationship

Humana has notified customers of a third-party security incident that might have exposed some of their personal information. According to a breach notification letter obtained by …

Supply chain [SC]

LocalBitcoins Third-Party Breach (January 2019)

2019-01-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

LocalBitcoins blames security breach on forum 'third-party software'. Hackers appears to have stolen $28,200 from users' accounts after phishing login credentials and 2FA one-time …

Supply chain [SC]

ASUS Live Update ShadowHammer Supply Chain Attack — Lazarus Group / OPERATION ShadowHammer

2019-01-01 [vendor] ASUS Live Update Utility (ASUS pre-installed automatic update tool) [malware] ShadowHammer backdoor
Vector: Attackers (assessed as Lazarus Group / BARIUM) compromised ASUS's software signing infrastructure and injected malicious code into the legitimate ASUS Live Update Utility; the trojanized utility was signed with genuine ASUS digital certificates and distributed via ASUS's official update servers to approximately 1 million ASUS laptop and desktop computers worldwide

Between June 2018 and November 2018 (disclosed March 2019), attackers compromised ASUS's software build and signing infrastructure to inject a backdoor into the ASUS Live Update …

Supply chain [SC]

PHP PEAR Package Manager Supply Chain Compromise (January 2019)

2018-12-20 [vendor] PHP PEAR [malware] Perl reverse shell backdoor
Vector: Compromise of open-source package repository web server; malicious backdoor injected into official go-pear.phar installer distributed via pear.php.net

In January 2019, the PHP PEAR (PHP Extension and Application Repository) team announced that the official pear.php.net web server had been compromised by an unknown attacker who …

Data leak

Georgia Tech / Georgia AG / Inside Higher Ed

2018-12-14
Vector: CWE-89: SQL Injection (unauthorised access to a central data warehouse via a web application vulnerability)

Georgia Institute of Technology disclosed on April 2 2019 that an unknown external actor had exploited a vulnerability in a web application to access a central data warehouse …

Data leak

Quora Question-Answer Platform Breach — 100 Million Users

2018-12-03 [vendor] Quora user database and content systems
Vector: An unauthorized third party gained access to Quora's systems via unknown means; Quora stated it discovered the breach on Friday 30 November 2018 and immediately began investigation

On 3 December 2018, Quora — the popular question-and-answer platform with approximately 300 million monthly unique visitors — disclosed that an unknown attacker had accessed data …

Supply chain [SC]

Redwood Eye Center Third-Party Breach (December 2018)

2018-12-01 [vendor] IT Lighthouse
Vector: Compromise of third-party service provider / vendor relationship

Microsoft Word - Redwood-AG Notification - California 4848-2006-9506 v.1. > ARIZONA •CALIFORNIA •COLORADO •CONNECTICUT •FLORIDA •GEORGIA •ILLINOIS •INDIANA •KANSAS •KENTUCKY …

Supply chain [SC]

Easy Programming Language (EPL) Supply Chain Attack — Taobao, Alipay, Baidu Cloud (2018)

2018-12-01 [vendor] Easy Programming Language (EPL / EasyLanguage) — Chinese programming software [malware] Credential-stealing trojan targeting Taobao, Alipay, Baidu Cloud, JD.com, NetEase 163, QQ, AliWangWang; ransomware component demanding WeChat Pay payment; signed with certificate stolen from Tencent Technologies
Vector: Trojanized Easy Programming Language (EPL/EasyLanguage) compiler/IDE distributed to Chinese developers; malicious code injected into the EPL software build environment propagated to applications compiled with it, targeting Chinese platform credentials and deploying ransomware

In late November and early December 2018, a sophisticated supply chain attack targeting Chinese internet users emerged, exploiting Easy Programming Language (EPL, also known as …

Supply chain [SC]

Gate.io / StatCounter Supply Chain Attack (2018)

2018-11-03 [vendor] StatCounter (web analytics provider) [malware] Custom JavaScript Bitcoin address-replacement skimmer
Vector: Compromise of StatCounter's web analytics platform; attackers injected malicious JavaScript into the StatCounter tracking script (counter.js), which silently replaced Bitcoin withdrawal destination addresses in real time on Gate.io's withdrawal page

On November 3, 2018, attackers compromised the StatCounter web analytics platform — used by hundreds of thousands of websites worldwide — and modified the StatCounter JavaScript …

Supply chain [SC]

BitPay Third-Party Breach (November 2018)

2018-11-01 [vendor] Right9ctrl
Vector: Compromise of third-party service provider / vendor relationship

Sophos News - The Sophos Blog. .svg?width=185&quality=80&format=auto&cache=true&immutable=true&cache-control=max-age%3D31536000). Sophos Insights LLM AI Exploit vulnerability …

Supply chain [SC]

Ontario Cannabis Store / Canada Post Data Breach (2018)

2018-11-01 [vendor] Canada Post
Vector: Unauthorized access to Canada Post's online parcel delivery tracking tool by an external actor, exposing shipment metadata for Ontario Cannabis Store customer orders

Shortly after the Ontario Cannabis Store (OCS) launched online sales following the legalization of recreational cannabis in Canada on October 17, 2018, a data breach was disclosed …

Supply chain [SC]

Image-I-Nation Technologies Supply Chain Breach Affecting Credit Bureau Customers (2018–2019)

2018-11-01 [vendor] Image-I-Nation Technologies
Vector: Network intrusion at third-party hosting and background screening software provider shared by Equifax, Experian, and TransUnion

Image-I-Nation Technologies, Inc. is a technology and hosting company that provides background screening software and data services to consumer reporting agencies (CRAs). In late …

Credential theft

Dunkin Donuts Credential Stuffing Attack — 325,000 DD Perks Accounts

2018-10-31 [vendor] Dunkin Donuts DD Perks loyalty program
Vector: Cybercriminals used credential stuffing — testing large volumes of username/password combinations stolen from other data breaches — against Dunkin' Donuts's DD Perks rewards program; the attack targeted the mobile app login and successfully authenticated using previously compromised credentials from unrelated breaches

In late October 2018, Dunkin Donuts — one of the world's largest coffee and baked goods chains — suffered a credential stuffing attack against its DD Perks loyalty rewards program. …

Supply chain [SC]

Nordstrom Employee Data Breach via Contractor (2018)

2018-10-09 [vendor] Unnamed contractor (vendor identity not publicly disclosed)
Vector: Insider mishandling of employee data by a contract worker with authorized system access; unauthorized exfiltration or exposure of HR and payroll data

In October 2018, Nordstrom discovered that a contract worker had improperly handled employee personal data, resulting in the potential exposure of sensitive HR and payroll …

Supply chain [SC]

VestaCP Third-Party Breach (October 2018)

2018-10-01 [vendor] not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Vesta control panel servers infected with DDoS malware after supply chain attack. An open-source hosting panel software provider, Vesta Control Panel (VestaCP), has admitted that …

Supply chain [SC]

UK Conservative Party conference app breach via CrowdComms (September 2018)

2018-09-30 [vendor] CrowdComms conference app
Vector: Missing authentication vulnerability in a conference app built by third-party provider CrowdComms — the app allowed any user to log in as any other attendee using only an email address, with no password required, exposing profile data including personal mobile phone numbers for hundreds of MPs, ministers, journalists, and conference delegates

On September 30, 2018, during the UK Conservative Party's annual conference in Birmingham, a serious security vulnerability in the official conference mobile application was …

Supply chain [SC]

Facebook "View As" access token breach affects 50 million accounts (September 2018)

2018-09-25 [vendor] Facebook Login / Facebook platform
Vector: Exploitation of a chain of three software bugs in the Facebook "View As" privacy feature — the interaction of a misconfigured birthday video composer, a flawed video uploader that incorrectly generated access tokens with mobile app permissions, and a logic error that generated tokens for the viewed user rather than the viewer allowed attackers to harvest OAuth access tokens for approximately 50 million accounts without knowing account passwords

On the afternoon of September 25, 2018, Facebook's engineering team discovered an active attack exploiting a critical vulnerability in the platform's "View As" feature — a privacy …

Supply chain [SC]

Atrium Health / AccuDoc Solutions Data Breach (2018)

2018-09-22 [vendor] AccuDoc Solutions Inc.
Vector: Exploitation of security vulnerability at AccuDoc Solutions' third-party hosting vendor, enabling unauthorized access to AccuDoc databases containing Atrium Health patient billing data

Atrium Health, a major Charlotte, North Carolina hospital network, suffered a significant data breach affecting 2,650,000 patients through its billing services vendor AccuDoc …

Supply chain [SC]

event-stream npm Package Malware — Targeting Copay Bitcoin Wallet

2018-09-09 [vendor] event-stream npm package (Node.js event streaming utility) [malware] flatmap-stream (malicious dependency with obfuscated payload)
Vector: Attacker (right9ctrl) socially engineered the original event-stream package maintainer (dominictarr) into transferring ownership of the npm package; then published a new version that included a malicious dependency (flatmap-stream) containing obfuscated code specifically targeting the Copay bitcoin wallet application by attempting to steal private keys and transaction data from users with wallets containing more than 100 BTC

In September 2018, an unknown attacker using the account 'right9ctrl' approached the original maintainer of the popular Node.js npm package 'event-stream' (dominictarr) and …

Supply chain [SC]

Foosackly Third-Party Breach (September 2018)

2018-09-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Foosackly's reports payment-card data breach. Mobile-based chicken-finger chain Foosackly's is warning customers of a data breach in its payment system. According to information …

Supply chain [SC]

Perth Mint Depository Online data breach via third-party IT provider (September 2018)

2018-09-01 [vendor] Not disclosed (third-party IT provider hosting Depository Online database)
Vector: Compromise of an unnamed third-party IT provider that hosted an older 2016 database of Perth Mint Depository Online customer records — the Perth Mint's own internal systems were not directly breached; attackers targeted the external provider's infrastructure to obtain the hosted dataset

In September 2018, The Perth Mint — the government-owned precious metals enterprise operated by the Government of Western Australia — disclosed a data breach affecting customers of …

Supply chain [SC]

Wolverine Solutions Group Ransomware Breach — 700+ Healthcare Clients, 1.2M Patients (2018–2019)

2018-09-01 [vendor] Wolverine Solutions Group [malware] Ransomware (variant not publicly identified)
Vector: Ransomware infection at Wolverine Solutions Group; attackers encrypted company records and disrupted operations, exposing patient data held on behalf of Michigan healthcare clients

Wolverine Solutions Group (WSG) is a Detroit, Michigan-based company that provides mailing, printing, and administrative services to hospitals and healthcare organisations — …

Cloud [SC]

UpGuard / Bitdefender / Healthcare IT News

2018-08-24 [vendor] MedCall Healthcare Advisors
Vector: Misconfigured AWS S3 bucket exposing 7GB of sensitive medical records and patient-doctor audio recordings

On August 24, 2018, cybersecurity researchers at UpGuard discovered a publicly accessible, misconfigured Amazon Web Services S3 storage bucket belonging to MedCall Healthcare …

Supply chain

Air Canada mobile app data breach (August 2018)

2018-08-22 [vendor] Air Canada mobile app
Vector: Credential stuffing attack against the Air Canada mobile app — attackers used email/password combinations from prior data breaches to systematically attempt logins against the app's authentication endpoint, successfully accessing approximately 20,000 of the 1.7 million registered accounts between August 22–24, 2018

Between August 22 and 24, 2018, Air Canada detected unusual login behaviour on its smartphone mobile application and moved quickly to lock all 1.7 million app user accounts as a …

Data leak [SC]

British Airways Magecart Payment Card Skimming Breach

2018-08-21 [vendor] British Airways website / mobile app (Modernizr library) [malware] Magecart skimmer
Vector: Magecart Group 6 injected a 22-line JavaScript skimmer into British Airways' website and mobile app via a compromised third-party Modernizr JavaScript library; skimmer exfiltrated payment card data to attacker-controlled domain baways.com

Between 21 August and 5 September 2018, a Magecart Group 6 skimmer silently exfiltrated payment card details from approximately 500,000 British Airways customers who purchased …

Supply chain [SC]

British Airways Magecart payment card skimming attack (August–September 2018)

2018-08-21 [vendor] British Airways website / booking platform [malware] Magecart web skimmer
Vector: Magecart web-skimmer attack — attackers initially accessed British Airways' network via stolen credentials belonging to a third-party supplier, moved laterally through a Citrix-based remote access system, then injected 22 lines of malicious JavaScript into a modified Modernizr library loaded from the BA baggage claim information page; the skimmer exfiltrated payment card data in real-time to an attacker-controlled server in Romania during the booking checkout flow

The British Airways Magecart breach of 2018 is one of the most technically documented payment card skimming attacks on record and led to a landmark GDPR enforcement action. The …

Data leak

T-Mobile August 2018 Data Breach — 2 Million Customers via API Vulnerability

2018-08-20 [vendor] T-Mobile customer API
Vector: An international hacker (later identified as a 21-year-old in the Netherlands) exploited an API vulnerability in T-Mobile's system to access and extract customer data; the vulnerability allowed access to customer account data without proper authentication

On 20 August 2018, T-Mobile detected and shut down an attack that exploited a vulnerability in T-Mobile's API, exposing account data for approximately 2 million customers. T-Mobile …

Other

Cosmos Bank India ATM Cashout ($13.5M, Proxy Switch, 28 Countries)

2018-08-11 [vendor] Bank ATM payment switch server
Vector: Attackers pre-positioned malware on Cosmos Bank's ATM payment switch infrastructure (the server that approves/declines ATM transactions); the malware created a fraudulent proxy switch that intercepted card authorization requests and returned approvals for compromised cloned cards, bypassing the legitimate Visa/RuPay networks

On August 11 and 13, 2018, Cosmos Co-operative Bank Ltd. of Pune, India — one of India's oldest cooperative banks — suffered a sophisticated two-weekend ATM cashout operation …

Supply chain [SC]

BevMo / NCR Corp. E-Commerce Payment Breach (2018)

2018-08-02 [vendor] NCR Corp. [malware] JavaScript payment card skimmer (Magecart-style)
Vector: Magecart-style JavaScript skimmer injected into BevMo's e-commerce checkout page via compromise of NCR Corp.'s managed website platform; malicious code siphoned payment card data at point of entry in real time

BevMo, a California-based alcohol retail chain, disclosed in late 2018 that its e-commerce website had been compromised by a payment card skimming attack affecting 14,579 …

Data leak [SC]

AMCA/Quest Diagnostics/LabCorp Billing Breach (11.9M Patients)

2018-08-01 [vendor] AMCA (American Medical Collection Agency) billing portal
Vector: Web payment portal of American Medical Collection Agency (AMCA), a third-party billing collections vendor, was compromised — attackers skimmed payment card data and personal information from AMCA's web payment system for approximately 8 months

Between August 1, 2018 and March 30, 2019, the web payment portal of American Medical Collection Agency (AMCA) — a third-party medical debt collections company — was compromised by …

Supply chain [SC]

Fiserv Event Manager vulnerability exposes customer data at hundreds of banks (August 2018)

2018-08-01 [vendor] Fiserv Event Manager
Vector: Insecure direct object reference (IDOR) vulnerability in Fiserv's Event Manager messaging platform — editing a single digit in a bank website URL parameter allowed any authenticated user to view other customers' account alert data, including email addresses, phone numbers, and partial account numbers

In August 2018, KrebsOnSecurity reported a significant security flaw in Fiserv's web banking platform that exposed personal and financial details of customers at hundreds of …

Supply chain [SC]

Mention Third-Party Breach (August 2018)

2018-08-01 [vendor] Not disclosed
Vector: Compromise of third-party service provider / vendor relationship

Media monitoring app Mention suffers third-party data breach. Web and social media monitoring app Mention has revealed that a third-party provider has been hit by a data breach. …

Supply chain [SC]

AMCA (American Medical Collection Agency) Third-Party Breach — Quest Diagnostics, LabCorp, 20M Patients

2018-08-01 [vendor] AMCA web payment portal
Vector: Attacker compromised AMCA's web payment portal via unknown initial access vector; malicious code siphoned payment card data and personal information over an eight-month period before detection; AMCA was a third-party billing collections vendor for multiple major healthcare laboratories

American Medical Collection Agency (AMCA), a major third-party billing and collections vendor for US healthcare laboratories, suffered a long-running breach of its web payment …

Supply chain [SC]

Managed Health Services of Indiana / LCP Transportation Phishing Breach (2018)

2018-07-30 [vendor] LCP Transportation (LCP Corp.)
Vector: Phishing attack against LCP Transportation employees who surrendered email credentials; attackers gained remote access to employee email accounts containing Medicaid member PHI between July 30 and September 7, 2018

Managed Health Services of Indiana (MHS), which administers Indiana's Hoosier Healthwise and Hoosier Care Connect Medicaid managed care programs, disclosed in December 2018 that …

Ransomware

LabCorp Ransomware Attack — Sample Collection and Test Results Disrupted

2018-07-14 [vendor] Laboratory Corporation of America Holdings (LabCorp) IT infrastructure [malware] SamSam ransomware
Vector: Ransomware (SamSam variant) infected LabCorp's network; the attack vector was consistent with SamSam group's known techniques of exploiting exposed RDP endpoints or leveraging JBOSS server vulnerabilities to gain initial access and then deploy ransomware across the network

On 14 July 2018, LabCorp — one of the world's largest clinical laboratory networks, processing approximately 2.5 million patient specimens per week — suffered a SamSam ransomware …

Credential theft

Timehop Social Memory App Breach — 21 Million Users, Access Tokens

2018-07-04 [vendor] Timehop cloud production environment / user database
Vector: An attacker used a compromised cloud environment credential (lacking multi-factor authentication) to access Timehop's production cloud environment; from there, the attacker accessed Timehop's production database and social network access tokens

On 4 July 2018 (US Independence Day), an attacker used a compromised cloud environment credential — which lacked multi-factor authentication — to access Timehop's production cloud …

Supply chain [SC]

US Department of Defense travel records breach via unnamed contractor (October 2018)

2018-07-01 [vendor] Not disclosed (DoD travel management contractor)
Vector: Intrusion into an unnamed commercial travel management contractor's systems that processed and stored travel records for DoD personnel — the contractor's network was compromised, exposing travel itinerary data and associated payment card information for approximately 30,000 military and civilian DoD employees

On October 12, 2018, the US Department of Defense disclosed that a data breach at an unnamed commercial contractor had exposed travel records — including personal information and …

Supply chain [SC]

Central Banking / Central Bank of the Bahamas

2018-06-28 [vendor] Third-party website hosting provider (not disclosed)
Vector: Unauthorized access to external-facing public website via compromised third-party website hosting vendor

On June 28, 2018, the Central Bank of the Bahamas was made aware of unauthorized access to its external-facing public website. The bank's investigation confirmed that the breach …

Data leak

SingHealth Singapore National Health Database Breach (1.5M Patients, PM Lee Targeted)

2018-06-27 [vendor] SingHealth Sunrise Clinical Manager (SCM) patient database [malware] Custom RAT (remote access trojan)
Vector: Advanced persistent threat group (assessed as state-sponsored, linked to Chinese APT10/APT41) used phishing email to compromise a SingHealth front-end workstation, moved laterally to the SCM database via multiple infected machines, and used a custom remote access tool to extract data over approximately three weeks

Between 27 June and 4 July 2018, attackers exfiltrated personal data of 1.495 million patients from SingHealth's Sunrise Clinical Manager outpatient database — approximately 25% of …

Cloud [SC]

GoDaddy server configuration data exposed via misconfigured AWS S3 bucket (June–August 2018)

2018-06-19 [vendor] Amazon Web Services S3
Vector: Misconfigured Amazon S3 bucket created by an AWS salesperson with public read permissions — the bucket named "abbottgodaddy" was created to store pricing proposal documents for a GoDaddy AWS engagement and was not locked down to account-owner-only access as required by best practice

On June 19, 2018, researchers from UpGuard's Cyber Risk Team discovered a publicly accessible Amazon S3 bucket named "abbottgodaddy" that contained sensitive configuration and …

Supply chain [SC]

Reddit / Krebs on Security / TechCrunch

2018-06-14 [vendor] SMS-based 2FA provider (not disclosed)
Vector: SMS-based two-factor authentication interception (SIM swap or SS7 exploitation) to compromise employee cloud and source code hosting accounts

On August 1, 2018, Reddit disclosed a security incident in which an attacker compromised several Reddit employee accounts at the company's cloud and source code hosting providers …

Cloud [SC]

Krebs on Security

2018-06-14 [vendor] Mailgun
Vector: SMS interception bypassing two-factor authentication on employee cloud and source code hosting accounts

Between June 14 and June 18, 2018, an attacker compromised several Reddit employee accounts at the company's cloud hosting and source code hosting providers by intercepting …

Data leak

Flipboard Social News App Breach — 145 Million Users

2018-06-02 [vendor] Flipboard social news aggregator user database
Vector: Unauthorized access to Flipboard's databases; the attacker accessed and potentially exfiltrated user data on two separate occasions — once between 2 June 2018 and 22 March 2019, and again between 21-22 April 2019; Flipboard detected the second intrusion through monitoring of its systems

Flipboard — the popular social news aggregation app — disclosed on 28 May 2019 that it had suffered two separate periods of unauthorized access to its databases. The first period …

Cloud

Exactis Unprotected Elasticsearch Database (340M Consumer and Business Records)

2018-06-01 [vendor] Elasticsearch
Vector: Exactis, a data broker, left a 2TB Elasticsearch database publicly accessible on the open internet with no authentication required; discovered by security researcher Vinnie Troia

Security researcher Vinnie Troia discovered in June 2018 that Exactis, a Florida-based data broker and marketing aggregation company, had left a 2-terabyte Elasticsearch database …

Cloud [SC]

Bleeping Computer

2018-05-30 [vendor] Agilisium
Vector: Unsecured Apache Airflow server deployed by contractor without authentication

On May 30, 2018, security researcher Bob Diachenko of Kromtech Security Center discovered an Apache Airflow server belonging to Agilisium, a cloud data contractor for Universal …

Other

Banco de Chile SWIFT Heist + Wiper Distraction ($10M, Lazarus)

2018-05-24 [vendor] SWIFT financial messaging; bank endpoint workstations [malware] KillMBR wiper (custom variant); SWIFT transaction injector
Vector: Lazarus Group-affiliated attackers gained access to Banco de Chile's internal network; deployed a custom MBR (Master Boot Record) wiping malware across ~9,000 workstations and 500 servers as a distraction; while IT teams responded to the destructive attack, attackers simultaneously submitted fraudulent SWIFT transfer instructions

On May 24, 2018, Banco de Chile — Chile's largest bank — suffered a sophisticated coordinated attack combining a destructive cyber operation with financial fraud. Attackers …

Supply chain [SC]

IT Pro / Enterprise Times / Silicon UK

2018-05-23 [vendor] PageUp [malware] Unspecified malware on PageUp systems
Vector: Malware infection of PageUp HR SaaS platform compromising authentication credentials and personal data

In June 2018, Whitbread plc -- the parent company of Costa Coffee, Premier Inn, Brewers Fayre, Beefeater, and other UK hospitality chains -- disclosed that personal data of job …

Supply chain

Houzz Data Breach — ~49 Million Users (2018–2019)

2018-05-23 [vendor] Houzz
Vector: Unauthorised access to Houzz user database; third-party attacker obtained user account data including hashed passwords

Houzz is a leading home design and renovation platform with tens of millions of registered users worldwide. In early 2019, the company disclosed that it had suffered a significant …

Cloud [SC]

PageUp People HR SaaS Platform Breach — Australian HR Vendor Affecting 100+ Employers

2018-05-23 [vendor] PageUp People HR recruitment SaaS platform
Vector: Unknown attacker compromised PageUp People's cloud-based HR and recruitment platform; PageUp described it as unusual activity in its IT infrastructure suggesting a malware infection; the platform stored candidate and employee data for over 100 Australian and global employers

In May 2018, PageUp People — a Melbourne-based HR and recruitment software company with clients across Australia, UK, US, Canada, and other countries — discovered unusual activity …

Cloud [SC]

PageUp HR SaaS Breach — Australia, Used by Telstra, NAB, Coles, Australian Government

2018-05-23 [vendor] PageUp (Australian HR and recruitment SaaS platform)
Vector: Malware infection of PageUp's systems; PageUp detected unusual activity on May 23, 2018 and confirmed malware had compromised some of its infrastructure; the precise initial intrusion vector (e.g., spearphishing, unpatched vulnerability) was not publicly disclosed

On June 1, 2018, PageUp — an Australian HR software company whose recruitment platform is used by over 100 Australian and international enterprises — disclosed that it had detected …

Supply chain [SC]

SC Media

2018-04-05 [vendor] Corporation Service Company (CSC)
Vector: Unauthorized network intrusion and data exfiltration from CSC systems

Corporation Service Company (CSC), a major provider of domain registration, corporate compliance, and agent-for-service-of-process services to Fortune 500 companies and other …

Cloud

Chegg S3 Root Credentials Data Breach (40M Users)

2018-04-01 [vendor] Amazon S3; Amazon Web Services
Vector: A contract worker with knowledge of the credentials used Chegg's AWS root account credentials and shared access keys to access an S3 bucket containing user data, exfiltrating records for 40 million users

In April 2018, Chegg, an American education technology company, suffered a data breach when a contract worker used Chegg's AWS root account credentials — which had been shared …

Data leak

UnityPoint Health Phishing Breach — 1.4M Patients

2018-03-14 [vendor] UnityPoint Health (Iowa-based integrated health system)
Vector: Business email compromise (BEC) phishing attack targeting UnityPoint Health employees; attackers sent emails impersonating a trusted executive, convincing employees to provide their email credentials; the compromised employee email accounts were then accessed by attackers who could view and exfiltrate protected health information from email contents

UnityPoint Health, a major Iowa-based health system operating 32 hospitals and 280+ clinics across Iowa, Illinois, and Wisconsin, suffered two phishing-related breaches in 2018. …

Credential theft

UnityPoint Health Phishing Attack — 1.4 Million Patient Records

2018-03-14 [vendor] UnityPoint Health employee email / patient data systems
Vector: Business email compromise (BEC) phishing — a sophisticated email fraud campaign impersonating a UnityPoint Health executive directed employees to click a link and enter credentials, compromising multiple employee email accounts; the attacker used compromised email accounts to access patient data and attempt additional payroll and wire fraud

In March and May 2018, UnityPoint Health — a major Iowa-based health system operating approximately 32 hospitals and 280 clinics in Iowa, Illinois, and Wisconsin — suffered two …

Data leak

Cathay Pacific Airways Data Breach — 9.4 Million Passengers, 860K Passport Numbers

2018-03-01 [vendor] Cathay Pacific Airways passenger data systems
Vector: An attacker gained access to Cathay Pacific's IT systems containing passenger data; Cathay discovered suspicious activity on its network in March 2018 but did not identify the breach until May 2018; the attack vector was not publicly disclosed in detail

In March 2018, an attacker accessed Cathay Pacific's IT systems and obtained data for approximately 9.4 million passengers — one of the largest aviation data breaches ever. Cathay …

Supply chain [SC]

Bleeping Computer

2018-03-01 [vendor] Not disclosed [malware] POS RAM-scraping malware
Vector: Point-of-sale RAM-scraping malware deployed on restaurant POS systems

Brinker International, the parent company operating over 1,600 Chili's Grill and Bar restaurants worldwide, disclosed a payment card data breach on May 12, 2018, one day after …

Supply chain [SC]

NordVPN Finland Datacenter Server Breach

2018-03-01 [vendor] Unnamed Finland datacenter provider (remote management system)
Vector: Unauthorized access via undisclosed IPMI (Intelligent Platform Management Interface) remote management account installed by datacenter provider without NordVPN's knowledge

In October 2019, NordVPN disclosed that one of its rented servers at a datacenter in Finland had been accessed without authorization. The actual breach occurred in March 2018 — …

Cloud

LA Times Publicly Accessible S3 Bucket Cryptomining Attack

2018-02-09 [vendor] Amazon S3
Vector: LA Times' Amazon S3 bucket hosting the Homicide Report web application was publicly writable due to misconfigured S3 ACLs; attackers injected Coinhive cryptocurrency mining JavaScript into the page

In February 2018, the LA Times' Homicide Report website was discovered to be running Coinhive cryptocurrency mining code injected by attackers who had exploited a publicly writable …

Data leak

Under Armour MyFitnessPal Breach — 150 Million Accounts

2018-02-01 [vendor] MyFitnessPal (Under Armour) user database
Vector: Unauthorized party acquired data associated with MyFitnessPal user accounts; specific technical attack vector was not disclosed by Under Armour; data was obtained from the MyFitnessPal app and website user database

In February 2018, an unauthorized party obtained data from approximately 150 million MyFitnessPal user accounts. Under Armour, which had acquired MyFitnessPal in 2015 for $475 …

Supply chain [SC]

Ticketmaster UK Inbenta Magecart Supply Chain Attack — 40,000 Payment Cards

2018-02-01 [vendor] Inbenta Technologies chatbot (third-party vendor loaded on Ticketmaster payment pages) [malware] Magecart skimmer
Vector: Magecart Group 5 compromised Inbenta Technologies — a third-party AI-powered customer support chatbot provider — and injected malicious JavaScript into the Inbenta chat widget code; the malicious script was then automatically loaded onto Ticketmaster's payment pages, skimming payment card data in real-time

From approximately February to June 2018, Magecart Group 5 skimmed payment card data from Ticketmaster UK customers by compromising Inbenta Technologies — a third-party customer …

Ransomware [SC]

Allscripts Ransomware Attack — EHR Vendor, 1,500+ Physician Practices Disrupted

2018-01-18 [vendor] Allscripts Healthcare Solutions (EHR and practice management software vendor) [malware] SamSam ransomware
Vector: SamSam ransomware variant delivered via exploitation of vulnerable internet-facing servers (likely via RDP brute force or exploitation of unpatched JBoss/Java application servers — the same TTPs used in other SamSam campaigns); the ransomware encrypted servers hosting Allscripts' Professional EHR and electronic prescriptions for controlled substances (EPCS) cloud-hosted services

On January 18, 2018, Allscripts Healthcare Solutions — one of the largest electronic health record (EHR) vendors in the United States, serving more than 45,000 physician practices …

Ransomware [SC]

Allscripts Healthcare Ransomware — SamSam Encrypts Cloud EHR, 1,500 Practices Offline

2018-01-18 [vendor] Allscripts Healthcare Solutions cloud EHR hosting infrastructure [malware] SamSam ransomware
Vector: SamSam ransomware attackers targeted Allscripts' data centers in Raleigh, NC and Malvern, PA; SamSam is deployed via brute force of RDP credentials or exploitation of server vulnerabilities (JBOSS, JMX); the attackers gained access and deployed ransomware across Allscripts' cloud hosting infrastructure

On 18 January 2018, SamSam ransomware attackers encrypted systems at Allscripts Healthcare Solutions data centers, taking offline cloud-hosted electronic health record (EHR) and …

Ransomware

German BKA Police Unmask REvil Ransomware Leader — GandCrab Successor Identified

2018-01-01 [vendor] Multiple global victims of REvil/Sodinokibi and GandCrab ransomware (2018-2021) [malware] REvil (Sodinokibi), GandCrab
Vector: REvil (Sodinokibi) is a ransomware-as-a-service (RaaS) operation that evolved from the GandCrab RaaS (which ran 2018-2019 and claimed revenues of over $2 billion); the REvil core developer and administrator was identified through a multi-year international law enforcement investigation involving German BKA, FBI, Europol, and partner agencies

In April 2026, German Federal Criminal Police (BKA — Bundeskriminalamt) announced that it had, in conjunction with international law enforcement partners, identified and publicly …

Data leak

HealthEngine Patient Privacy Breach — Australia, Data Sold to Lawyers Without Consent (OAIC)

2018-01-01 [vendor] HealthEngine patient appointment booking platform (Australia)
Vector: HealthEngine shared patient appointment and health data with Slater & Gordon law firm and health insurance funds without adequate patient consent, using fine print in terms of service that patients were unlikely to read; separately, HealthEngine edited negative reviews posted on its platform before publication

HealthEngine, Australia's largest health appointment booking platform with over 17 million users across approximately 60,000 healthcare practices, was found by Australian …

Supply chain [SC]

The Register

2018-01-01 [vendor] Not disclosed
Vector: Unauthorized access to external vendor system used for secure data storage

Western Union disclosed in early 2018 that customer information had been accessed without authorization through a computer intrusion targeting an external vendor system formerly …

Credential theft

Collection #1 — 773M Email Credential Aggregation (Largest Credential Dump)

2018-01-01
Vector: Compilation of data from 2,000+ previously breached databases, aggregated into a single 87GB credential collection and posted on MEGA cloud storage and hacking forums, designed for use in credential stuffing attacks at scale

On January 17, 2019, Troy Hunt (creator of HaveIBeenPwned) disclosed 'Collection #1' — an 87GB aggregated credential dump that had appeared on MEGA cloud storage and hacking …

Supply chain [SC]

PR Newswire / Latest Hacking News

2017-12-11 [vendor] SOCIAPlus [malware] JavaScript skimmer
Vector: Malicious JavaScript injection via compromised third-party analytics tool (SOCIAPlus)

Klook, a Hong Kong-based travel activities and services booking platform, disclosed on June 29, 2018 that it had suffered a data breach through a compromised third-party web …

Other

NiceHash Cryptocurrency Mining Marketplace Hack — ~4,736 BTC (~$64M)

2017-12-06 [vendor] NiceHash (Slovenian cryptocurrency mining marketplace)
Vector: Social engineering of a NiceHash employee; attackers obtained the employee's credentials (likely via spearphishing), used them to access NiceHash internal systems, and ultimately gained access to the payment system's Bitcoin wallet private keys, draining the entire contents of the company's payment wallet in a single transaction

On December 6, 2017, NiceHash — a platform where users sell their computing power for cryptocurrency mining — halted operations after discovering that its internal payment system …

Supply chain [SC]

HIPAA Journal

2017-12-01 [vendor] Undisclosed transcription service provider
Vector: Transcription vendor misconfigured database access during software upgrade

Orlando Orthopaedic Center reported a breach of 19,101 patient records caused by an error made by its third-party transcription service provider during a software upgrade in …

Supply chain [SC]

Threatpost

2017-11-23 [vendor] RMH Franchise Holdings [malware] POS RAM-scraping malware
Vector: Point-of-sale RAM-scraping malware deployed on POS systems at franchise locations

RMH Franchise Holdings, one of the largest Applebee's franchise operators in the United States, discovered malware on point-of-sale systems at its restaurants on February 13, 2018, …

Supply chain [SC]

Domino's Australia Customer Data Leak via Former Supplier

2017-10-01 [vendor] Unnamed former supplier (online rating system)
Vector: Compromise of former third-party supplier's online rating system

In October 2017, Domino's Australia customers began receiving targeted spam and phishing emails that addressed them by first name and referenced their local suburb, suggesting the …

Supply chain [SC]

StateScoop / Dark Reading / Gemini Advisory

2017-10-01 [vendor] Click2Gov (Superion / CentralSquare Technologies) [malware] SJavaWebManage web shell [cve] CVE-2017-3248 +2
Vector: Exploitation of Oracle WebLogic vulnerabilities (CVE-2017-3248, CVE-2017-3506, CVE-2017-10271) to upload web shell and enable payment card logging

Between late 2017 and late 2018, at least 46 US cities were compromised through vulnerabilities in Click2Gov, a self-service bill payment portal used by municipalities for utility …

Cloud

Imperva RDS Database Snapshot Publicly Exposed (Cloud WAF Customer Data)

2017-10-01 [vendor] Amazon RDS (Relational Database Service)
Vector: Imperva's internal database migration process created an Amazon RDS snapshot and made it publicly accessible; the snapshot contained customer authentication tokens, password hashes, and API keys. An attacker later found and accessed this snapshot

Imperva, a cybersecurity company providing cloud-based web application firewall (WAF) and DDoS protection services, disclosed in August 2019 that a data breach had exposed customer …

Supply chain [SC]

CNN Business

2017-09-27 [vendor] [24]7.ai
Vector: Malicious code injection into [24]7.ai online customer service chat widget

Between September 27 and October 12, 2017, an unauthorized third party gained access to [24]7.ai's online customer service chat platform and injected malicious code designed to …

Supply chain [SC]

CCleaner Supply Chain Backdoor — 2.27 Million Users, Stage 2 Targets Samsung/Intel/Sony

2017-09-01 [vendor] Piriform CCleaner 5.33 (PC optimization utility, Windows) [malware] Floxif backdoor (Stage 1); Stage 2 GhostRat-variant (for high-value targets)
Vector: Chinese APT (BARIUM/Winnti Group) compromised Piriform's (later acquired by Avast) build environment and injected a two-stage backdoor into the legitimate CCleaner 5.33 Windows application; the trojanized software was digitally signed with Piriform's legitimate certificate and distributed through official download channels to millions of users

Between mid-August and 12 September 2017, Piriform (a subsidiary of Avast Security) distributed a backdoored version of CCleaner 5.33 — a widely used Windows PC cleaning utility — …

Supply chain [SC]

RiskIQ / Threatpost / ICO

2017-09-01 [vendor] Inbenta Technologies [malware] Magecart JavaScript card skimmer
Vector: Magecart JavaScript skimmer injected into Inbenta Technologies chatbot code running on Ticketmaster payment pages

In June 2018, Ticketmaster disclosed that malicious code had been found within a customer support chatbot function on its websites, hosted by third-party AI company Inbenta …

Data leak

Panera Bread Plaintext Customer Data Exposure — 37 Million Records, 8-Month Delay

2017-08-01 [vendor] Panera Bread website / customer API
Vector: An unauthenticated API endpoint on Panera Bread's website exposed customer records in plaintext — accessible to anyone with a web browser; the vulnerability was reported to Panera by security researcher Dylan Houlihan in August 2017 but Panera took 8 months to fix it

In August 2017, security researcher Dylan Houlihan discovered that Panera Bread's website had an unauthenticated API endpoint at panerabread.com that returned customer records in …

Supply chain [SC]

Huddle House POS Malware Breach via Third-Party Vendor (2017–2019)

2017-08-01 [vendor] Huddle House (POS vendor not publicly named) [malware] POS RAM scraper (card track data harvesting)
Vector: Attackers compromised a third-party POS vendor's support tools to gain remote access to Huddle House POS systems and deploy payment card scraping malware

Huddle House is a family-style restaurant chain headquartered in Atlanta, Georgia, with approximately 400 corporate and franchisee locations primarily across the southeastern …

Data leak

HBO Game of Thrones Hack — 1.5TB Data, Scripts, Unreleased Episodes

2017-07-31 [vendor] HBO internal content management and production systems
Vector: A hacker group (later identified as Behzad Mesri, an Iranian national) gained access to HBO's internal network via unknown means and exfiltrated approximately 1.5 terabytes of data including scripts, episodes, and internal company documents; the attacker demanded $6 million in Bitcoin ransom

In late July/early August 2017, a hacker exfiltrated approximately 1.5 terabytes of data from HBO's internal systems including unreleased episodes of Game of Thrones (the most …

Data leak [SC]

Aetna HIV Medication Mailing Breach (11,887 Patients, $17M Settlement)

2017-07-28
Vector: Vendor mailing error — a third-party mailing vendor used envelopes with an oversized clear window cutout that allowed the letter body text (which referenced HIV medications by name) to be visible through the envelope without opening it, disclosing members' HIV status to anyone who handled the mailing

In late July 2017, Aetna mailed letters to approximately 11,887 members nationwide regarding a court-ordered change to HIV prescription coverage policy (members were being notified …

Supply chain [SC]

NetSarang ShadowPad Supply Chain Backdoor — 100+ Corporate Victims

2017-07-01 [vendor] NetSarang Xmanager Enterprise / Xshell / Xftp (server management software) [malware] ShadowPad modular backdoor
Vector: Chinese APT (BRONZE ATLAS / Winnti Group) compromised NetSarang's software build infrastructure and inserted the ShadowPad modular backdoor into NetSarang's legitimate server management software products (Xmanager, Xshell, Xftp, Xlpd) before code signing; the signed trojanized software was distributed through NetSarang's official website

In July 2017, Kaspersky Lab researchers discovered that NetSarang Computer's server management software suite — used by hundreds of large enterprises globally for SSH, telnet, and …

Supply chain [SC]

Wikipedia

2017-06-27 [vendor] MeDoc (Intellect Service) [malware] NotPetya (Petya variant / wiper disguised as ransomware) [cve] CVE-2017-0144 +1
Vector: Compromised software update mechanism of MeDoc Ukrainian tax accounting software

On June 27, 2017, the NotPetya cyberattack struck, becoming one of the most destructive and costly cyberattacks in history with estimated global damages exceeding $10 billion. The …

Supply chain [SC]

NotPetya Supply Chain Wiper via M.E.Doc Update (Sandworm, $10B+ Damages)

2017-06-27 [vendor] M.E.Doc (MeDoc) Ukrainian tax accounting software [malware] NotPetya (Petya variant / wiper) [cve] CVE-2017-0144
Vector: Russian GRU Sandworm APT compromised M.E.Doc (MeDoc), a Ukrainian tax accounting software used by ~80% of Ukrainian companies, and trojanized the automatic update mechanism to deliver the NotPetya destructive wiper; lateral spread used EternalBlue + Mimikatz credential harvesting

On June 27, 2017, Russian military intelligence (GRU Unit 74455 / Sandworm) deployed NotPetya — a destructive wiper disguised as ransomware — by trojanizing the automatic update …

Credential theft

UK Parliament Email Brute-Force Attack (~90 Accounts Compromised)

2017-06-23 [vendor] Microsoft Outlook Web Access (OWA)
Vector: Sustained brute-force attack against UK Parliament's internet-facing Outlook Web Access (OWA) email portal; attackers targeted accounts where MPs and staff used weak passwords without multi-factor authentication enforced on remote access

On June 23–24, 2017, an unknown attacker conducted a sustained brute-force attack against the UK Parliament's Outlook Web Access (OWA) email portal at Westminster. Parliament's IT …

Cloud

Deep Root Analytics 2016 Voter Data Exposure — 198 Million Americans

2017-06-01 [vendor] Deep Root Analytics AWS S3 bucket
Vector: Deep Root Analytics, a data analytics firm contracted by the Republican National Committee, misconfigured an Amazon S3 bucket that was set to public access; the bucket contained detailed voter data compiled from multiple sources including publicly available voter registration records, proprietary commercial data, and political modeling scores

In June 2017, UpGuard cybersecurity researcher Chris Vickery discovered an Amazon S3 bucket belonging to Deep Root Analytics — a data analytics firm that had been contracted by the …

Cloud [SC]

UpGuard

2017-06-01 [vendor] Deep Root Analytics
Vector: Unsecured Amazon S3 bucket with no access controls or authentication

On June 12, 2017, UpGuard cyber risk analyst Chris Vickery discovered a publicly accessible Amazon S3 cloud storage bucket containing approximately 1.1 terabytes of data on 198 …

Cloud [SC]

Verizon Customer Data Exposure via NICE Systems — 14 Million Records on AWS S3

2017-06-01 [vendor] NICE Systems AWS S3 bucket (Verizon customer data)
Vector: NICE Systems — an Israel-based enterprise software company contracted by Verizon for call center quality improvement — misconfigured an Amazon S3 bucket to be publicly accessible; the bucket contained customer account data from Verizon's customer call center operations

In July 2017, UpGuard security researchers discovered that NICE Systems — an enterprise software company contracted by Verizon to manage call center quality assurance — had left an …

Other

TRITON/TRISIS Malware: First Attack Targeting Industrial Safety Systems (Saudi Aramco Petrochemical)

2017-06-01 [vendor] Schneider Electric Triconex Safety Instrumented System (SIS) [malware] TRITON (TRISIS, HatMan)
Vector: Russian state-sponsored actors (attributed to the Central Scientific Research Institute of Chemistry and Mechanics / CNIIHM, Moscow) gained IT network access via spear-phishing, pivoted to the OT network, then developed a zero-day exploit targeting Schneider Electric Triconex Safety Instrumented System (SIS) controllers

TRITON (also known as TRISIS and HatMan) is the world's first known malware specifically designed to attack industrial Safety Instrumented Systems (SIS) — the last line of …

Cloud

OneLogin Single Sign-On Breach — Customer Data Decrypted by Attacker

2017-05-31 [vendor] OneLogin single sign-on / identity management platform
Vector: Attacker obtained access keys to the AWS platform used by OneLogin's US data region via an unknown mechanism, then used those keys to create AWS API calls to enumerate OneLogin's infrastructure and access customer data; the attacker used AWS API access to decrypt data stored in OneLogin's environment

On 31 May 2017, OneLogin — an enterprise single sign-on and identity management provider serving approximately 2,000 enterprise customers — suffered a breach in which an attacker …

Data leak

Zomato Food Delivery Platform Breach — 17 Million User Records

2017-05-17 [vendor] Zomato user database
Vector: An unknown attacker (who later reached out to Zomato directly) gained access to Zomato's database and exfiltrated user records; Zomato's engineering team determined that an internal vulnerability allowed the attacker access; the attacker offered to sell the data and then agreed to delete it after Zomato engaged with them

On 17-18 May 2017, Zomato — India's largest food delivery and restaurant discovery platform, operating in 24 countries with approximately 120 million monthly visitors — disclosed …

Supply chain [SC]

CSO Online

2017-05-13 [vendor] Apache Struts [cve] CVE-2017-5638
Vector: Exploitation of unpatched Apache Struts vulnerability (CVE-2017-5638) in web application portal

Between May 13 and July 30, 2017, attackers exploited a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) to breach Equifax, one of the three major US …

Ransomware

WannaCry Global Ransomware Worm (150+ Countries, NSA EternalBlue)

2017-05-12 [vendor] Microsoft Windows (SMBv1) [malware] WannaCry (WannaCrypt, WannaCryptor) [cve] CVE-2017-0144 +2
Vector: Self-propagating worm exploiting EternalBlue (CVE-2017-0144), an NSA-developed SMBv1 exploit leaked by Shadow Brokers on April 14, 2017; required no user interaction — propagated autonomously over TCP port 445 to vulnerable Windows systems

On May 12, 2017, WannaCry — a self-propagating ransomware worm — began spreading globally, infecting approximately 230,000 systems in 150+ countries within 24 hours. WannaCry …

Ransomware

WannaCry NHS Attack — 80 of 236 NHS Trusts Hit, £92M Cost

2017-05-12 [vendor] NHS England / NHS Scotland IT infrastructure (Windows XP/7 systems) [malware] WannaCry ransomware [cve] CVE-2017-0144 +1
Vector: WannaCry ransomware worm exploited the EternalBlue NSA exploit (CVE-2017-0144) targeting unpatched Windows XP and Windows 7 systems across NHS organisations; many NHS trusts had not applied the March 2017 MS17-010 patch and were running legacy Windows XP systems no longer supported by Microsoft

On 12 May 2017, WannaCry ransomware caused the most significant cyberattack on the UK National Health Service in history. Of the 236 NHS Trusts in England, 80 were affected — about …

Data leak

Bell Canada / CBC / The Globe and Mail

2017-05-01
Vector: CWE-284: Improper Access Control (unauthorised access to Bell systems by an unnamed hacker who threatened to release data unless Bell lobbied against Canadian internet regulation)

An unnamed hacker breached Bell Canada in May 2017 and exfiltrated data on approximately 1.9 million active and former customer accounts, including names, email addresses, phone …

Data leak

Hudson's Bay / Saks Fifth Avenue / Lord & Taylor Joker's Stash POS — 5 Million Cards

2017-05-01 [vendor] Saks Fifth Avenue / Lord & Taylor POS systems (Hudson's Bay Company) [malware] Carbanak POS RAM-scraping malware
Vector: FIN7 cybercriminal group (JokerStash/Carbanak) installed POS RAM-scraping malware on point-of-sale systems across Saks Fifth Avenue and Lord & Taylor stores nationwide; the malware captured payment card track data from device memory during transactions for approximately 10 months

Between May 2017 and March 2018, the FIN7 cybercriminal group (operating the JokerStash carding shop) compromised point-of-sale systems at all Saks Fifth Avenue and Lord & Taylor …

Supply chain [SC]

Handbrake macOS App Supply Chain Attack — Mac Users' Credentials Stolen

2017-05-01 [vendor] HandBrake video transcoder (mirror download server) [malware] Proton RAT (Remote Access Trojan) for macOS
Vector: Attackers compromised the HandBrake download mirror server and replaced the legitimate macOS HandBrake installer (HandBrake-1.0.7.dmg) with a trojanized version containing the Proton RAT; users who downloaded HandBrake from the compromised mirror between 2-6 May 2017 received malware instead of the legitimate application

Between 2-6 May 2017, attackers compromised one of HandBrake's macOS download mirror servers and replaced the legitimate HandBrake installer with a trojanized version containing …

Credential theft

Saks Fifth Avenue / Lord & Taylor FIN7 POS Breach (5M Cards)

2017-05-01 [malware] BOOSTWRITE / POS malware (FIN7)
Vector: FIN7 cybercrime syndicate (affiliated with Joker's Stash carding marketplace) deployed POS malware across all Lord & Taylor stores and 83 Saks Fifth Avenue locations in North America; malware captured payment card Track data from magnetic stripe readers at physical retail locations

Between approximately May 2017 and March 2018 (approximately 10 months), the FIN7 cybercriminal organization's Joker's Stash carding marketplace operators deployed POS malware …

Supply chain [SC]

Forever 21 Point-of-Sale Malware Breach

2017-04-03 [malware] POS RAM-scraping malware (unnamed)
Vector: Point-of-sale malware installed on in-store payment systems where encryption had been disabled

Between April 3 and November 18, 2017, point-of-sale malware infected payment systems at an undisclosed number of Forever 21 retail stores across the United States. The breach …

Credential theft

Forever 21 POS Malware Breach (7-Month Encryption Failure)

2017-04-03 [malware] POS malware
Vector: POS malware exploiting disabled or non-functioning point-to-point encryption (P2PE) on Forever 21 payment terminals; malware captured plaintext card data at terminals where encryption was not active, and also accessed completed transaction logs stored on POS devices

Between approximately April 3 and November 18, 2017 (~7 months), POS malware infected Forever 21 retail store locations in the United States. Forever 21 issued an initial public …

Data leak

Wonga Payday Loans Data Breach — 270,000 UK and 25,000 Poland Customers

2017-04-01 [vendor] Wonga Finance UK customer database
Vector: Unknown attacker gained unauthorized access to Wonga's systems and customer data; Wonga identified the breach through internal monitoring and immediately launched an investigation; the specific attack vector was not disclosed publicly

In April 2017, Wonga Finance — the UK's largest payday loan company at its peak, with approximately 1 million UK customers — suffered a data breach affecting approximately 270,000 …

Data leak

Chipotle Mexican Grill POS Malware Breach — Payment Card Skimming at Majority of Restaurants

2017-03-24 [vendor] Chipotle point-of-sale systems [malware] POS RAM scraping malware
Vector: Attackers installed point-of-sale (POS) malware on payment systems at the majority of Chipotle restaurant locations; the malware read payment card data from the magnetic stripe track data in RAM (RAM scraping) during the transaction window

Between 24 March and 18 April 2017, attackers installed malware on point-of-sale systems at most Chipotle Mexican Grill restaurant locations in the United States. The malware …

Credential theft

Chipotle Mexican Grill POS Malware Breach (Most U.S. Restaurants)

2017-03-24 [malware] POS malware (Track data scraper)
Vector: POS malware installed on payment devices at the majority of Chipotle Mexican Grill restaurant locations; malware searched for and captured Track 1 and Track 2 magnetic stripe data as it was routed through POS processing systems

Between March 24 and April 18, 2017, POS malware infected the majority of approximately 2,250 Chipotle Mexican Grill restaurant locations across 47 U.S. states and Washington D.C., …

Supply chain [SC]

Hyatt Hotels Second Payment Card Breach (41 Properties)

2017-03-18 [malware] POS RAM-scraping malware (unnamed, dual-capability for swiped and manually entered cards)
Vector: Point-of-sale malware injected into front desk payment systems at managed hotel properties

Between March 18 and July 2, 2017, point-of-sale malware infected front desk payment systems at 41 Hyatt Hotels properties across 11 countries. The malware was capable of capturing …

Data leak

CSO Online / Wikipedia / Apache Software Foundation

2017-03-10 [vendor] Equifax online dispute portal [cve] CVE-2017-5638
Vector: CWE-20: Improper Input Validation / Apache Struts OGNL injection

Apache disclosed CVE-2017-5638 March 7 2017 and patched same day. Equifax security scans failed to identify the vulnerable system. Attackers exploited Apache Struts flaw in …

Data leak

First American Financial IDOR — 885M Mortgage Documents Exposed (SEC Fine)

2017-03-01 [vendor] First American EaglePro web application
Vector: Insecure Direct Object Reference (IDOR) in First American's EaglePro web application — any authenticated user with a valid document link could increment a sequential numeric document ID in the URL to access any other document without authorization; vulnerability exploitable by any logged-in user without special privileges

First American Financial Corporation, one of the largest title insurance and real estate settlement services providers in the United States, had an IDOR (Insecure Direct Object …

Data leak

Aadhaar India Biometric Identity Database Exposure — 1.1 Billion Citizens

2017-01-01 [vendor] Aadhaar (UIDAI — Unique Identification Authority of India) national biometric identity system
Vector: Multiple vulnerabilities and unauthorized access points were identified in the Aadhaar ecosystem: anonymous database access was sold via WhatsApp groups for ₹500; state government portals and websites operated by utility companies exposed Aadhaar numbers; the Aadhaar eKYC API lacked proper rate limiting and access controls

India's Aadhaar national biometric identity system — which stores fingerprint and iris scan data for approximately 1.2 billion Indian citizens and links to bank accounts, mobile …

Data leak

Desjardins Insider Data Breach — 4.2 Million Members, 2.7 Years of Exfiltration

2017-01-01 [vendor] Desjardins Group internal member database
Vector: Malicious insider — a Desjardins employee who had legitimate access to member data as part of their role — exfiltrated member personal data over approximately 26 months and shared the data with third parties outside the organization

A Desjardins Group employee with legitimate access to member data exfiltrated personal information of members over approximately 26 months (from early 2017 to March 2019) and …

Data leak

Desjardins Group Insider Data Theft (4.2M Members)

2017-01-01
Vector: A malicious insider (a Desjardins employee) collected and exfiltrated personal data of members over a period of approximately 26 months, sharing the data with unauthorized third parties outside the organization

Desjardins Group, Canada's largest federation of credit unions with over 7 million members, disclosed in June 2019 that a malicious insider (a now-former employee) had been …

Data leak

GoodRx FTC Health Breach Notification Rule Enforcement ($1.5M Fine, 55M Users)

2017-01-01 [vendor] GoodRx health savings platform; Meta Pixel; Google advertising SDK
Vector: Intentional data sharing — GoodRx embedded third-party tracking pixels (from Meta/Facebook, Google, Criteo, Branch.io, and Twilio) on its website and apps that transmitted users' sensitive health and prescription information to advertising platforms for targeting and retargeting purposes

GoodRx, the US prescription drug discount platform with approximately 55 million users, disclosed its use of third-party advertising trackers in 2023 when the FTC took enforcement …

Data leak

GoodRx Health Data Sharing with Meta and Google — FTC First Health Breach Notification Enforcement

2017-01-01
Vector: Third-party tracking pixels and SDKs — GoodRx embedded Meta Pixel, Google Analytics, and other advertising trackers on its website and app that automatically transmitted users' health and prescription information to advertising platforms for targeted advertising purposes

GoodRx, a health technology company offering prescription drug discount coupons and telehealth services, shared sensitive user health data with Facebook/Meta, Google, Criteo, …

Credential theft

Sonic Drive-In POS Malware Breach (~5M Payment Cards)

2017-01-01 [malware] POS malware
Vector: POS malware deployed across Sonic Drive-In restaurant locations; malware copied payment card data at each swipe from magnetic stripe readers and exfiltrated it to attacker infrastructure

In September 2017, security journalist Brian Krebs reported that a large batch of approximately 5 million stolen payment cards linked to Sonic Drive-In locations had appeared on …

Other

French Presidential Campaign (En Marche! / Macron) Hack — APT28, #MacronLeaks

2017-01-01 [vendor] En Marche! presidential campaign (Emmanuel Macron, France)
Vector: APT28 (GRU / Fancy Bear) spearphishing targeting En Marche! campaign staff with credential-harvesting domains mimicking the campaign's email infrastructure; phishing domains registered beginning in March 2017

In the final hours before France's legally mandated media blackout ahead of the May 7, 2017 presidential election runoff, approximately 9GB of documents and emails allegedly stolen …

Supply chain [SC]

Healthcare IT News

2016-12-22 [vendor] Unnamed patient management software vendor
Vector: Misconfiguration of third-party vendor patient management system

On December 22, 2016, an unauthorized individual gained access to electronic files stored on computer systems maintained by a third-party vendor that provided patient management …

Other

Industroyer/CrashOverride: Ukraine Power Grid Attack (Kyiv Blackout, Sandworm)

2016-12-17 [vendor] IEC 60870-5-101/104 SCADA; Siemens SIPROTEC relays (CVE-2015-5374) [malware] Industroyer (CrashOverride); KillDisk
Vector: Sandworm (GRU Unit 74455) deployed Industroyer malware that natively spoke industrial communication protocols (IEC 60870-5-101/104, IEC 61850, OPC DA) to directly communicate with and manipulate power grid SCADA/ICS equipment without requiring attackers to understand specific OT configurations

On December 17, 2016, exactly one year after the first Ukraine power grid attack (BlackEnergy 2015), Russian military intelligence (GRU Sandworm team) deployed Industroyer against …

Data leak

Three Mobile UK Breach — 133,827 Customer Upgrade Orders, Insider Threat

2016-11-01 [vendor] Three Mobile UK customer upgrade database
Vector: Fraudsters used a legitimate employee login credential (obtained via an insider or social engineering) to access Three Mobile's customer upgrade database; they then used customer data to intercept handset upgrades — diverting new handsets to fraudsters rather than legitimate customers

In November 2016, Three Mobile UK — one of the UK's major mobile network operators — disclosed a breach of its customer upgrade system. Fraudsters used compromised employee login …

Cloud [SC]

Zendesk 2016 Breach Disclosed 2019 (Uber, Slack, FCC Affected)

2016-11-01 [vendor] Zendesk Support and Chat
Vector: Unauthorized access to Zendesk Support and Chat customer account databases; breach originated in 2016 and disclosed to affected customers in October 2019

In October 2019, Zendesk — a major customer service software platform used by over 145,000 organizations — disclosed a security breach that affected customer accounts created …

Data leak [SC]

Australian Red Cross Blood Service SQL Dump Exposure (550K Donors)

2016-10-26
Vector: A web developer working for the Red Cross Blood Service's website contractor accidentally uploaded a production database backup file (.sql dump) to a publicly accessible directory on the redcrossblood.org.au website; discovered by an independent security researcher who responsibly disclosed it

In October 2016, a contractor responsible for building Australian Red Cross Blood Service's donor portal accidentally included a 1.74 GB SQL database backup file in a publicly …

Data leak [SC]

Australian Red Cross Blood Service Data Breach — 550,000 Donor Records (OAIC First Civil Penalty)

2016-10-25 [vendor] Australian Red Cross Blood Service / Precedent Communications web hosting
Vector: A web development contractor (Precedent Communications, later identified) inadvertently uploaded a backup file of donor registration data to a publicly accessible directory on the Australian Red Cross Blood Service website; the file was discovered by a security researcher and reported responsibly

On 25 October 2016, a file named 'donorquestionnaire.bak' containing registration data for 550,000 blood donors was inadvertently left in a publicly accessible directory on the …

Credential theft

Arby's POS Malware Breach (355K+ Payment Cards)

2016-10-25 [malware] POS malware (Track 1/Track 2 scraper)
Vector: POS malware deployed on corporate-owned Arby's restaurant systems (not franchise locations); malware captured Track 1 and Track 2 magnetic stripe data as it transited infected POS devices

Between approximately October 25, 2016 and January 19, 2017, POS malware infected corporate-owned Arby's restaurant locations across the United States. Franchise locations were not …

Data leak

Dailymotion Data Breach — 85.2M Email Addresses and Hashed Passwords

2016-10-20 [vendor] Dailymotion (French video-sharing platform, owned by Vivendi)
Vector: Database compromise of Dailymotion's user account database; the specific initial access vector was not publicly disclosed

On December 6, 2016, data breach tracking service LeakedSource reported that a dataset containing 85.2 million Dailymotion user records had been offered for sale and contained data …

Cloud [SC]

Uber 2016 Data Breach and Cover-Up (57 Million Users)

2016-10-13 [vendor] GitHub
Vector: Credential stuffing attack on Uber engineers' GitHub accounts using passwords from prior breaches; AWS access keys found in private repositories

In October 2016, two hackers used credential stuffing to access Uber engineers' private GitHub repositories, leveraging passwords exposed in previous data breaches. Uber did not …

Data leak

FriendFinder Network LFI Breach (412M Accounts Across 6 Adult Sites)

2016-10-01
Vector: Local File Inclusion (LFI) vulnerability on FriendFinder Network servers allowed attackers to read arbitrary files, including the password database; passwords stored in plaintext or reversible SHA-1 hashes

FriendFinder Networks, the operator of adult dating websites, suffered a breach that exposed approximately 412 million accounts across six properties including …

Data leak

Deloitte Email Server Breach — Internal Client Communications Exposed

2016-10-01 [vendor] Deloitte Microsoft Azure email / Active Directory
Vector: Attacker compromised an administrator account on Deloitte's Microsoft Azure-hosted email platform that had no multi-factor authentication enabled; this granted unrestricted access to the Azure Active Directory storing email for all partners and staff

An attacker compromised a single Deloitte administrator account that lacked multi-factor authentication, granting access to Deloitte's global email server hosted on Microsoft …

Cloud

NPR / DOJ / TechCrunch / Washington Post

2016-10-01 [vendor] Uber / AWS S3
Vector: CWE-312: Cleartext Storage of Sensitive Information (AWS credentials exposed in GitHub repository, used to access S3 bucket with customer data)

Attackers found Uber AWS credentials in GitHub and downloaded data affecting 57M users and drivers (names, emails, phone numbers; 600K US driver license numbers). Uber CSO Joe …

Cloud

Uber AWS GitHub Credentials Theft — 57 Million Riders and Drivers, $148M Settlement

2016-10-01 [vendor] Uber private GitHub repository / AWS S3
Vector: Attackers found Uber's private GitHub repository containing hardcoded AWS credentials; used those credentials to access an AWS S3 bucket containing a backup archive with rider and driver personal data; attackers contacted Uber and demanded $100,000 in exchange for deleting the data

In October-November 2016, two attackers discovered that Uber's private GitHub code repository contained hardcoded AWS credentials. Using those credentials, they accessed an AWS S3 …

Data leak

LifeBridge Health Network Breach — 538,127 Patients

2016-09-27 [vendor] LifeBridge Health (Baltimore, Maryland integrated health system)
Vector: Malware installed on LifeBridge Health's server supporting its registration and billing systems and electronic medical records; the malware gained unauthorized access to a server connected to systems containing patient data — the precise initial intrusion vector was not disclosed; the breach was discovered more than a year after it began

LifeBridge Health, a Maryland-based health system operating Sinai Hospital, Northwest Hospital, Levindale Hebrew Geriatric Center, and other facilities, disclosed in May 2018 that …

Cloud

Cloudflare Cloudbleed Memory Leak — OAuth Tokens, Passwords, Private Keys Exposed

2016-09-22 [vendor] Cloudflare reverse proxy / CDN / security service
Vector: A bug in Cloudflare's HTML parser (introduced 22 September 2016) caused the parser to read past the end of a buffer when processing certain HTML constructs (including server-side includes, email obfuscation, and automatic HTTPS rewrites); the overrun memory contained data from other Cloudflare customers' HTTP requests including authentication tokens, session cookies, passwords, and private messages — this data was served in HTTP responses to users and cached by Google, Bing, and other search engines

On 22 September 2016, Cloudflare deployed a change to its HTML parsing pipeline that introduced a buffer overread bug (named 'Cloudbleed' by researcher Tavis Ormandy, in reference …

Supply chain [SC]

HIPAA Journal

2016-08-28 [vendor] Managed service provider (unnamed)
Vector: Exposed RDP port opened by managed service provider to bypass VPN restrictions

Between August 28, 2016, and January 14, 2017, the Diamond Institute for Infertility and Menopause, a fertility clinic based in Millburn, New Jersey, suffered repeated unauthorized …

Other

Shadow Brokers NSA Exploit Leak (EternalBlue → WannaCry/NotPetya)

2016-08-13 [vendor] NSA Tailored Access Operations (TAO) toolset [malware] EternalBlue; EternalRomance; FUZZBUNCH; DoublePulsar; DanderSpritz [cve] CVE-2017-0144 +1
Vector: A group calling themselves 'The Shadow Brokers' claimed to have stolen cyberweapons from the NSA's Tailored Access Operations (TAO) unit; released NSA exploit tools in staged leaks from August 2016 through April 2017; method of original exfiltration from NSA never officially confirmed

Between August 2016 and April 2017, a group known as 'The Shadow Brokers' released staged leaks of what they claimed were NSA cyberweapon repositories stolen from the NSA's elite …

Data leak [SC]

Sabre Hospitality Solutions SynXis POS Breach — Hotel Reservations and Payment Cards

2016-08-10 [vendor] Sabre Hospitality Solutions SynXis Central Reservations system
Vector: Unauthorized actor gained access to Sabre Hospitality Solutions' SynXis Central Reservations (CR) system via compromised credentials of an authorised system user; once inside the SynXis CR system, the attacker accessed payment card data and personally identifiable information

Between 10 August 2016 and 9 March 2017, an unauthorized actor gained access to Sabre Corporation's SynXis Central Reservations (CR) hospitality technology system — a hotel …

Supply chain [SC]

Sabre SynXis Hospitality Reservation System Breach

2016-08-10 [vendor] Sabre Corp. (SynXis)
Vector: Unauthorized access to SynXis central reservation system using compromised account credentials

Between August 10, 2016, and March 9, 2017, an unauthorized party gained access to Sabre Corporation's SynXis central-reservations system, a widely used platform that processes …

Credential theft [SC]

Sabre SynXis Central Reservations Breach (1.3M Cards, 36K Hotels)

2016-08-10 [vendor] Sabre SynXis Central Reservations System
Vector: Attacker compromised an administrator-level account in Sabre's SynXis central reservations system; the admin password was stored in plaintext within the system; the attacker used the admin account to access payment processing pages and exfiltrate card data daily over approximately 7 months

Between approximately August 10, 2016 and March 9, 2017, an attacker used a compromised administrator account in Sabre Corporation's SynXis Hospitality Solutions central …

Other [SC]

Bitfinex Bitcoin Exchange Hack — 119,756 BTC (~$72M)

2016-08-02 [vendor] Bitfinex (Hong Kong-based cryptocurrency exchange, iFinex Inc.); BitGo (multi-signature wallet co-signer)
Vector: Attackers compromised BitGo's multi-signature co-signing service integrated with Bitfinex's wallet infrastructure; the exact initial access vector was never fully disclosed, but the attack involved manipulating Bitfinex's API to authorize fraudulent withdrawal transactions that BitGo's servers co-signed without detecting the anomaly

On August 2, 2016, Bitfinex — at the time the world's largest USD-denominated Bitcoin exchange — announced that 119,756 BTC had been stolen from customer accounts, worth …

Credential theft

InterContinental Hotels Group (IHG) POS Breach (1,200 Franchise Locations)

2016-08-01 [malware] POS malware (Track data scraper)
Vector: POS malware deployed on restaurant and bar point-of-sale systems at IHG franchise hotel locations; malware searched for and captured Track 1 and Track 2 payment card data as it transited affected POS servers

Between approximately August 1 and December 29, 2016, POS malware was deployed at IHG franchise hotel properties across the United States and Puerto Rico. IHG (InterContinental …

Cloud

DataDog AWS Access Keys Exposed in Breach

2016-07-07 [vendor] Amazon Web Services (AWS)
Vector: An attacker gained access to DataDog's internal systems and obtained AWS access keys, which could have been used to access customer AWS environments where the DataDog agent was installed

On July 7-8, 2016, DataDog, a cloud monitoring and analytics platform, detected unauthorized access to its internal systems and discovered that AWS access keys had been exposed. …

Data leak

Dark Overlord Extortion Group — Healthcare Data Theft and Patient Extortion

2016-07-01 [vendor] Multiple healthcare providers (clinics, therapy centres, oncology practices)
Vector: The Dark Overlord gained access to multiple healthcare clinics and providers by exploiting Remote Desktop Protocol (RDP) vulnerabilities — specifically brute-forcing RDP credentials or exploiting unpatched RDP vulnerabilities on internet-facing systems; stolen data was then used for extortion of both the healthcare providers and directly of patients

Beginning in mid-2016, a cybercriminal group calling themselves 'The Dark Overlord' (TDO) conducted a sustained campaign of healthcare data theft and extortion against multiple US …

Supply chain [SC]

Oracle MICROS POS System Breach — 330,000 Payment Terminals at Risk

2016-07-01 [vendor] Oracle MICROS customer support portal [malware] Carbanak malware
Vector: Carbanak/Anunak criminal group (Russian cybercriminal gang responsible for banking malware attacks) breached Oracle's MICROS customer support portal by installing malware on Oracle systems; the attacker gained access to the MICROS support portal used to service restaurant, hotel, and retail POS systems globally

In mid-2016, the Carbanak/Anunak cybercriminal gang — responsible for stealing over $1 billion from banks globally through sophisticated malware campaigns — breached Oracle's …

Data leak

Banner Health Data Breach — 3.7 Million Patients and Health Plan Members

2016-06-17 [vendor] Banner Health patient records / payment card systems [malware] POS RAM-scraping malware
Vector: Attackers first compromised Banner Health's food and beverage payment card systems (targeting point-of-sale systems at Banner's healthcare facility cafeterias and restaurants) and used that initial foothold to pivot into Banner's main healthcare network, accessing patient data systems

Between 23 June and 7 July 2016, attackers first compromised Banner Health's point-of-sale (POS) systems at food and beverage outlets within Banner Health facilities, using …

Data leak

Banner Health POS Pivot to Patient Database Breach (3.7M Individuals)

2016-06-17 [malware] POS malware
Vector: Attackers first compromised Banner Health's food and beverage payment processing systems (POS attack at hospital dining locations) on June 17, 2016, then used that foothold to pivot laterally into Banner's healthcare IT network to access patient, member, and provider databases

Banner Health, a Phoenix, Arizona-based nonprofit hospital system operating 28 hospitals and numerous clinics across seven western states, disclosed on August 3, 2016 that it had …

Data leak [SC]

Newkirk Products BCBS Health Plan ID Card Vendor Breach (3.3M Members)

2016-05-21 [vendor] Newkirk Products health plan ID card printing system
Vector: Unauthorized access to a production server at Newkirk Products containing health plan member data; attacker gained access to the server hosting membership data; the server was shut down upon discovery on July 6, 2016

Newkirk Products, Inc., a New York-based company that printed and mailed health plan identification cards on behalf of multiple Blue Cross Blue Shield (BCBS) plans, disclosed a …

Supply chain [SC]

Newkirk Products Health Insurance ID Card Printer Breach — 3.4 Million Members

2016-05-11 [vendor] Newkirk Products ID card printing server
Vector: Unknown attacker gained unauthorized access to a server maintained by Newkirk Products — a company that prints and mails health insurance ID cards for multiple US health plans; the server contained personal information for health plan members across numerous client health insurers

On 11 May 2016, an unauthorized party gained access to a server maintained by Newkirk Products, Inc. — a company that prints and mails health insurance identification cards for …

Data leak

Philippine COMELEC Voter Database Leak — 55 Million Registered Voters

2016-03-27 [vendor] Philippine Commission on Elections (COMELEC) voter database
Vector: Hacktivist group 'LulzSec Pilipinas' defaced the Commission on Elections (COMELEC) website and dumped the entire voter database; a second group called 'Anonymous Philippines' also separately published the database; the initial defacement was carried out by exploiting a vulnerability in the COMELEC website

On 27 March 2016, hacktivist group LulzSec Pilipinas defaced and dumped the Philippines Commission on Elections (COMELEC) entire voter database — weeks before the 9 May 2016 …

Credential theft

Russian GRU DNC / Podesta Email Hack — 2016 US Presidential Election Interference

2016-03-19 [vendor] Google Gmail (Podesta) / DNC internal network [malware] X-Agent, X-Tunnel, Mimikatz, PlugX
Vector: Russian GRU Unit 26165 (Fancy Bear / APT28) sent spear-phishing emails to Democratic National Committee (DNC) staff and John Podesta (Clinton campaign chairman) that harvested their Google account credentials via a fake Google security alert page; access to Podesta's Gmail was obtained after a staffer incorrectly characterised the phishing email as 'legitimate'

Beginning in March 2016, Russian military intelligence operatives from GRU Unit 26165 (Fancy Bear/APT28) and Unit 74455 (Sandworm) conducted a comprehensive hacking campaign …

Other

DNC / Podesta Email Hack — APT28/GRU, Russian Election Interference 2016

2016-03-19 [vendor] Democratic National Committee (DNC) IT infrastructure; Hillary Clinton Campaign Chair John Podesta's Gmail [malware] X-Agent (Sofacy) keylogger/credential harvester; X-Tunnel network tunneling tool; Mimikatz credential dumper
Vector: APT28 (GRU Unit 26165 / Fancy Bear) spearphishing via Google OAuth credential-harvesting pages; John Podesta clicked a link in a fake Google security alert email on March 19, 2016; DNC compromise involved separate APT28 intrusion beginning in approximately March 2016 alongside APT29 (Cozy Bear) intrusion from mid-2015

In 2016, two separate Russian GRU units conducted coordinated cyber intrusions against the Democratic Party and Clinton presidential campaign. APT29 (GRU Unit 29155 / Cozy Bear) …

Credential theft

Snapchat Employee Payroll Data Theft via CEO Impersonation

2016-02-26 [vendor] Snapchat HR / payroll systems
Vector: An attacker impersonated Snapchat's CEO Evan Spiegel in a phishing email sent to a Snapchat payroll employee, requesting payroll information; the employee complied and sent payroll data for a number of current and former employees to the attacker — a classic CEO fraud / business email compromise (BEC) attack

On 26 February 2016, a Snapchat payroll department employee received an email purportedly from CEO Evan Spiegel requesting payroll information for employees. The employee complied …

Other

Bangladesh Bank SWIFT Heist ($81M Stolen via SWIFT Messaging, Lazarus Group)

2016-02-04 [vendor] SWIFT Alliance Access messaging software [malware] EVTDIAG; MSOUTC; MSOUTC (SWIFT-specific malware suite)
Vector: Lazarus Group (DPRK) spearphishing targeted Bangladesh Bank employees; malware installed on bank's internal network gained access to the SWIFT Alliance Access software and credentials; attackers monitored bank operations for months before submitting fraudulent SWIFT transfer instructions

On the night of February 4–5, 2016, Lazarus Group (North Korean state-sponsored hackers) submitted 35 fraudulent SWIFT transfer instructions from Bangladesh Bank's account at the …

Other

Bangladesh Bank SWIFT Heist — $81 Million Stolen via Fraudulent SWIFT Messages

2016-02-04 [vendor] Bangladesh Bank SWIFT terminal / SWIFT Alliance Access software [malware] EVTDIAG, MSOUTC, MSOUTC (Lazarus custom malware)
Vector: North Korean Lazarus Group gained access to Bangladesh Bank's SWIFT messaging terminals by compromising workstations at the bank using malware introduced via a malicious PDF; the attackers installed malware that modified SWIFT software to forge outgoing payment messages and delete evidence of the fraudulent transfers

In February 2016, North Korea's Lazarus Group executed the most audacious central bank heist in history by compromising Bangladesh Bank's SWIFT messaging system and fraudulently …

Data leak

Weebly Website Builder Breach — 43 Million Users

2016-02-01 [vendor] Weebly website builder user database
Vector: Unknown attacker gained unauthorized access to Weebly's user database and exfiltrated account credentials and associated data for approximately 43 million users; the breach data was acquired by data breach researcher Troy Hunt and added to Have I Been Pwned

In February 2016, Weebly — a popular drag-and-drop website builder platform serving approximately 40 million users and 625,000 paying customers — suffered a data breach. The breach …

Data leak

Centene Corporation Missing Hard Drives (950K Members)

2016-01-07
Vector: Physical loss — six unencrypted hard drives containing health plan member data were misplaced and could not be located during an IT data project; the drives were being used to store laboratory test result data for a health outcomes improvement initiative

On January 7, 2016, Centene Corporation — one of the largest Medicaid-focused managed care organizations in the United States, operating health plans in over 25 states — discovered …

Data leak

Minecraft / Lifeboat Network Breach — 7 Million Accounts Exposed

2016-01-01 [vendor] Lifeboat Minecraft network user database
Vector: Unknown attacker gained access to the Lifeboat Minecraft server network database; Lifeboat is a popular Minecraft Pocket Edition server network with millions of registered child and teen players; the attacker accessed email addresses and weakly hashed (MD5) passwords

In early 2016, Lifeboat — one of the most popular Minecraft Pocket Edition server networks with over 3 million registered accounts — was breached. The breach affected approximately …

Data leak

Verizon Enterprise Solutions 1.5 Million Records Exposed on Dark Web

2016-01-01 [vendor] Verizon Enterprise Solutions customer management portal
Vector: Unknown attackers exploited a vulnerability in a Verizon Enterprise Solutions web portal and exfiltrated customer business data; the data was subsequently offered for sale in a Russian cybercriminal forum for $100,000 or $10,000 per portion

In early 2016, Verizon Enterprise Solutions — the business division of Verizon that provides managed network services to Fortune 500 companies and government agencies — suffered a …

Cloud

Vitagene Unprotected S3 Buckets Expose Genetic and Health Data

2016-01-01 [vendor] Amazon S3
Vector: Vitagene left Amazon S3 buckets containing customer raw DNA data and health profile files publicly accessible without authentication, with no CloudTrail logging enabled to detect unauthorized access

Vitagene, a consumer DNA and ancestry testing company, left Amazon S3 buckets containing raw genetic data files, health reports, and personal information for customers publicly …

Other

FASTCash ATM Cashout Operations — DPRK Lazarus BeagleBoyz ($100M+, 30+ Banks)

2016-01-01 [vendor] IBM AIX payment switch servers; bank ATM networks [malware] FASTCash implant (AIX trojan)
Vector: Spearphishing targeting bank employees for initial access; lateral movement to payment switch application servers running IBM AIX; deployment of custom AIX malware that intercepted ATM transaction approval requests and returned fraudulent approvals for compromised cards even with zero balances; pre-positioned mule networks executed simultaneous global ATM withdrawals

FASTCash was a multi-year North Korean state-sponsored campaign (2016–ongoing) targeting bank payment switch servers — the AIX-based systems that approve or decline ATM …

Other

BlackEnergy/KillDisk: First Cyberattack Causing a Power Outage (Ukraine, Sandworm)

2015-12-23 [vendor] Microsoft Office (macro); ICS SCADA systems [malware] BlackEnergy3; KillDisk
Vector: Sandworm (GRU) sent spear-phishing emails with malicious Microsoft Word documents containing BlackEnergy3 macros to Ukrainian energy company employees; gaining access to IT networks before pivoting to SCADA systems; operators were locked out via KillDisk wiping workstations while attackers opened breakers via VPN

On December 23, 2015, coordinated cyberattacks against three Ukrainian electricity distribution companies — Prykarpattyaoblenergo, Chernivtsioblenergo, and Kyivoblenergo — caused …

Data leak

VTech Children's Learning Tablet Breach — 11.6 Million Parents, 6.4 Million Children

2015-11-14 [vendor] VTech Learning Lodge app store / Kid Connect
Vector: A hacker accessed VTech's Learning Lodge app store (used by parents to download apps for VTech children's devices) and the Kid Connect messaging app database via SQL injection vulnerability in the website; attacker extracted customer and children's databases

On 14 November 2015, a hacker breached VTech's Learning Lodge — the app store and content platform for the company's range of children's electronic learning tablets and toys. VTech …

Data leak

TalkTalk Cyberattack — 157,000 UK Customers, £400K ICO Fine

2015-10-21 [vendor] TalkTalk website / legacy Metapack database component
Vector: Three teenagers exploited a SQL injection vulnerability in a legacy web component of TalkTalk's website (an outdated Metapack database acquired in 2009 that was inadequately secured); the attackers scraped customer data from the vulnerable endpoint

On 21 October 2015, TalkTalk — one of the UK's largest broadband and telecoms providers serving approximately 4 million customers — was attacked by a group of teenagers who …

Data leak

21st Century Oncology Data Breach — 2.2 Million Patients, FBI Investigation

2015-10-03 [vendor] 21st Century Oncology patient database
Vector: FBI notified 21st Century Oncology that its systems had been compromised by an unknown attacker who gained access to its patient database; specific technical attack vector was not disclosed; the FBI discovered the breach during an unrelated investigation and tipped off the cancer treatment provider

In October 2015, an unknown attacker compromised the patient database of 21st Century Oncology Holdings — the largest radiation oncology treatment chain in the United States, …

Data leak

21st Century Oncology FBI-Notified Breach (2.2M Patients, $2.3M HIPAA Fine)

2015-10-03
Vector: External attacker gained unauthorized access to 21st Century Oncology's patient database; on November 13, 2015 the FBI notified the company that a hacker had illegally obtained data from their systems; exact initial access vector not publicly disclosed

21st Century Oncology, the largest integrated cancer care provider in the United States at the time (operating 180+ locations in 17 states plus international), suffered a database …

Supply chain [SC]

Wendy's POS Malware Breach — 1,025 Restaurant Locations, Payment Cards

2015-10-01 [vendor] Wendy's restaurant POS systems (via third-party support vendor) [malware] Carbanak variant POS malware
Vector: Attackers compromised Wendy's third-party POS support vendor and used the vendor's remote access credentials to install memory-scraping malware (a variant of Carbanak/Anunak BlackPOS) on POS systems at Wendy's franchise locations; the malware captured Track 2 payment card data from device memory during transactions

Between October 2015 and mid-2016, a sophisticated POS malware attack — attributed to the Carbanak/Anunak criminal group — affected point-of-sale systems at 1,025 Wendy's franchise …

Credential theft [SC]

Wendy's POS Malware Breach (1,025 Franchise Locations)

2015-10-01 [malware] POS malware (two distinct strains)
Vector: Attackers compromised remote access credentials belonging to a third-party service provider with access to Wendy's franchisee POS systems, then installed POS malware across multiple franchise locations; a second distinct malware strain was also discovered affecting additional locations

Between approximately fall 2015 and spring 2016, POS malware was deployed at Wendy's franchise restaurant locations in the United States. Wendy's first disclosed the breach in May …

Supply chain [SC]

Experian / T-Mobile Data Breach — 15 Million T-Mobile Customer Applications

2015-09-01 [vendor] Experian Decision Analytics (T-Mobile credit check server)
Vector: An unknown attacker accessed Experian's server that stored personal information on behalf of T-Mobile; the server processed T-Mobile's credit application data and was accessed via a compromised credential that provided administrative access

In September 2015, Experian — a major US credit bureau — suffered a breach of a server it operated on behalf of T-Mobile for processing mobile phone service credit applications. …

Supply chain [SC]

T-Mobile/Experian Data Breach (CNBC, NPR, T-Mobile Newsroom)

2015-09-01 [vendor] Experian (credit check and decisioning services)
Vector: Unauthorized access to an Experian server containing T-Mobile credit application data; specific intrusion method not publicly disclosed

On October 1, 2015, Experian disclosed that hackers had gained unauthorized access to a server containing personal information of approximately 15 million people who had applied …

Credential theft

Hyatt Hotels POS Malware Breach (250 Hotels in 50 Countries)

2015-08-13 [malware] POS malware
Vector: POS malware installed on payment processing computers at Hyatt-managed hotels, primarily targeting restaurant and food/beverage outlet POS terminals; malware harvested cardholder names, card numbers, expiration dates, and internal verification codes as data was processed

Between approximately August 13 and December 8, 2015, POS malware infected payment processing systems at 250 Hyatt-managed hotels across 50 countries, including 100 hotels in 26 …

Data leak

Ashley Madison Impact Team Breach and Doxing (37M Accounts)

2015-07-12
Vector: Impact Team claimed to have insider access to Avid Life Media's (ALM) systems; exfiltrated user account database, company email, source code, and payment records; threatened to publish unless the site was shut down

On July 12, 2015, a hacking group calling themselves 'Impact Team' notified Ashley Madison (a dating website for married people seeking affairs, operated by Avid Life Media) that …

Data leak

Hacking Team Italian Surveillance Software Maker Breach — 400GB Data Dump

2015-07-05 [vendor] Hacking Team (HT S.r.l.) internal systems and source code
Vector: An unknown attacker (later claimed to be Phineas Fisher, a hacktivist) penetrated Hacking Team's internal network by first attacking an embedded system (a router), pivoting to internal systems, and ultimately obtaining access to Hacking Team's source code repositories, email archives, and internal documents; tools and zero-day exploits were also stolen

On 5 July 2015, Hacking Team — an Italian cybersecurity company that sold offensive surveillance software (Remote Control System, branded 'Galileo') to governments and law …

Cloud

LastPass 2015 Data Breach — Email Addresses, Password Reminders, Authentication Hashes

2015-06-12 [vendor] LastPass password manager user database
Vector: Unknown attacker compromised LastPass's network and gained access to the LastPass database; specific intrusion vector was not disclosed; the attacker accessed user account email addresses, password reminders, server per-user salts, and authentication hashes

On 12 June 2015, LastPass — one of the world's most widely used password managers with tens of millions of users — discovered that its network had been compromised and that user …

Supply chain [SC]

PNI Digital Media Photo Center Breach (Krebs on Security, NBC News, SC Magazine)

2015-06-01 [vendor] PNI Digital Media (online photo printing platform)
Vector: Malware installed on PNI Digital Media servers used to capture and exfiltrate customer payment card data and personal information from online photo center transactions

In June and July 2015, attackers compromised servers operated by PNI Digital Media, a Canadian company (subsidiary of Staples) that provided online photo printing and processing …

Data leak [SC]

Medical Informatics Engineering (MIE) / WebChart Breach — 3.9 Million Patients

2015-05-07 [vendor] Medical Informatics Engineering WebChart EHR (electronic health records)
Vector: An attacker used a compromised username and password to access Medical Informatics Engineering's cloud-based EHR system (WebChart) hosted server; the specific method of initial credential compromise was not disclosed but may have involved stolen credentials from other breaches or phishing

Between 7 and 26 May 2015, an attacker accessed Medical Informatics Engineering's (MIE) WebChart EHR cloud server using compromised credentials. MIE is a health information …

Other

Bundestag (German Parliament) APT28 Hack — 16GB Data, Full Network Rebuild

2015-04-01
Vector: APT28 (Fancy Bear / GRU Unit 26165) spearphishing emails delivering trojanized links to Bundestag employees; malware installation enabled keylogging and credential harvesting; attackers then moved laterally across the 20,000-node parliamentary IT network for several weeks

Between approximately April and May 2015, Russian military intelligence (GRU) APT28 (Fancy Bear) conducted a sophisticated intrusion into the German Federal Parliament (Bundestag) …

Data leak

Sally Beauty POS Breach — 25,000 Payment Cards (Second Breach)

2015-03-01 [malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on Sally Beauty point-of-sale systems to capture payment card track data at checkout; similar attack methodology to the retailer's first breach in 2014

In May 2015, Sally Beauty Holdings disclosed its second payment card breach in approximately one year. The beauty supply retailer discovered unauthorized access to payment card …

Other

U.S. CENTCOM Twitter and YouTube Account Hijack by ISIS Sympathizers

2015-01-12 [vendor] Twitter, YouTube (Google)
Vector: Social media account compromise — attackers claiming affiliation with ISIS obtained credentials for the official U.S. Central Command (CENTCOM) Twitter and YouTube accounts, likely via phishing or credential reuse, and posted propaganda

On January 12, 2015, individuals calling themselves 'CyberCaliphate' and claiming affiliation with the Islamic State (ISIS) hijacked the official Twitter and YouTube accounts of …

Credential theft

IRS 'Get Transcript' Breach — SSN-Based Account Takeover (100K+ Taxpayer Accounts)

2015-01-01
Vector: Attackers used stolen personally identifiable information (SSNs, dates of birth, tax filing status, and street addresses — likely from prior third-party breaches) to pass the IRS 'Get Transcript' online application's knowledge-based authentication questions and access prior-year tax transcripts

Between January and May 2015, sophisticated cybercriminals exploited the IRS 'Get Transcript' web application to access prior-year tax return transcripts for over 100,000 …

Credential theft

IRS Get Transcript Identity Theft Attack — 100,000+ Taxpayer Accounts

2015-01-01 [vendor] IRS Get Transcript online application
Vector: Sophisticated crime ring (attributed to Russian-speaking criminal syndicate) used previously stolen personal data (Social Security numbers, dates of birth, addresses, filing status) obtained from external sources to pass the IRS Get Transcript application's authentication questions and access prior-year tax returns for use in fraudulent refund claims

Between January and May 2015, a sophisticated crime ring accessed the IRS's 'Get Transcript' online application — which allowed taxpayers to retrieve prior-year tax returns — and …

Other

TV5Monde Broadcast Disruption — APT28 False-Flag Operation (CyberCaliphate)

2015-01-01 [vendor] TV broadcast encoding hardware; social media accounts
Vector: APT28 (Sandworm / GRU) spearphishing targeting TV5Monde employees beginning approximately January 2015; credential theft and lateral movement over approximately 3 months; pre-positioned access to broadcast encoding infrastructure; coordinated simultaneous attack on broadcast systems and social media accounts

On April 9, 2015, TV5Monde — France's international television network broadcasting to 200 million people in 160 countries — had all 11 of its TV channels knocked off the air …

Data leak

Anthem Health Insurance Nation-State Breach (78.8M Records)

2014-12-10
Vector: China-linked threat actor (Indrik Spider / Deep Panda) used a spear-phishing email targeting an Anthem subsidiary to establish initial access, then moved laterally to Anthem's enterprise data warehouse containing unencrypted member records

Anthem (now Elevance Health), the second-largest US health insurer, disclosed in February 2015 that attackers had gained access to its enterprise data warehouse and exfiltrated …

Data leak

Morgan Stanley Insider Breach — Financial Advisor Stole 350K Client Records

2014-12-01
Vector: Insider threat — a Morgan Stanley financial advisor (Galen Marsh) with authorized access to client data used his legitimate credentials to download and exfiltrate approximately 350,000 client records from internal systems over the course of several months

In late 2014, Morgan Stanley financial advisor Galen Marsh used his authorized access to the firm's internal systems to download account information for approximately 350,000 …

Other

Sony Pictures Hack: Lazarus Group Wiper + Data Exfiltration

2014-11-24 [malware] Destover (wiper/backdoor)
Vector: North Korea's Lazarus Group (Bureau 121) used spear-phishing to gain initial access to Sony Pictures' network, conducted months of reconnaissance, then deployed 'Destover' destructive malware (wiper) while simultaneously exfiltrating terabytes of data

On November 24, 2014, attackers identifying themselves as 'Guardians of Peace' (GOP) deployed the Destover destructive wiper malware across Sony Pictures' corporate network, wiping …

Cloud

BrowserStack Forgotten AWS Access Key Breach

2014-11-09 [vendor] Amazon S3; Amazon Web Services
Vector: An old, forgotten AWS access key from a former employee's prototype environment was discovered by an attacker and used to access BrowserStack's production customer database in Amazon S3

In November 2014, BrowserStack, a cloud-based browser and device testing platform, suffered a breach when an attacker discovered a forgotten, active AWS access key that had been …

Data leak

U.S. State Department Unclassified Email System Breach (2014–2015)

2014-10-01
Vector: Russian state-sponsored hackers (attributed to APT29 / Cozy Bear) gained access to the U.S. State Department's unclassified email network; initial access likely via spear-phishing followed by lateral movement and persistent backdoor implants

In late 2014, Russian state-sponsored hackers breached the U.S. State Department's unclassified email system (SBU — Sensitive But Unclassified network), gaining persistent access …

Data leak

UCLA Health System Breach — 4.5 Million Patients, China APT

2014-09-01 [vendor] UCLA Health System patient network
Vector: A sophisticated cyberattacker (assessed as China-linked APT, consistent with the wave of health insurer breaches in 2014-2015) gained access to UCLA Health's network and accessed parts of the network containing personal and medical information for approximately 4.5 million individuals

In September 2014, a sophisticated cyberattacker accessed portions of the UCLA Health network containing protected health information. UCLA Health — one of California's largest …

Data leak

UCLA Health Data Breach (4.5M Patients, APT)

2014-09-01
Vector: Nation-state attackers (believed to be Chinese APT) gained access to UCLA Health's network and moved laterally to unencrypted parts of the network containing patient data; initial vector not publicly confirmed

UCLA Health, one of the leading academic medical centers in the United States, disclosed in July 2015 that attackers had accessed parts of its network containing personal and …

Credential theft

Kmart / Sears Holdings POS Malware Breach — Payment Card Data

2014-09-01 [vendor] Kmart (Sears Holdings Corporation) [malware] POS RAM-scraping malware (specific variant not publicly named)
Vector: Point-of-sale (POS) malware installed on Kmart store payment terminals; the malware was undetected by Kmart's and Sears Holdings' antivirus systems for approximately one month before discovery; the precise initial intrusion vector (how malware was installed on the POS systems) was not disclosed

On October 10, 2014, Sears Holdings announced that Kmart stores had been the victim of a data breach involving malware installed on point-of-sale systems. The company stated that …

Data leak

Bell Canada / CBC / Vice Motherboard

2014-08-01
Vector: CWE-89: SQL Injection (hacker group NullCrew exploited SQL injection in Bell's systems)

Hacker collective NullCrew claimed responsibility for a breach of Bell Canada, Canada's largest telecom, disclosed August 28 2014. Approximately 1.9 million email addresses and …

Supply chain [SC]

Marriott International / Starwood Data Breach (2018)

2014-07-29 [vendor] Starwood Hotels & Resorts Worldwide (acquired by Marriott in 2016) [malware] Remote Access Trojan (RAT); Mimikatz credential-harvesting tool; memory-scraping malware
Vector: Web shell planted on Starwood Accolade application server in July 2014 via compromised employee credentials (likely phishing), followed by RAT deployment for persistent access; credential harvesting with Mimikatz; lateral movement through Starwood guest reservation database (SPG) over four years before detection in September 2018

The Marriott/Starwood breach is one of the largest data breaches in history and a landmark case study in the risks of inheriting a compromised IT environment through corporate …

Data leak

K-Box Entertainment Karaoke Chain Breach — 317,000 Members (PDPC Singapore First Case)

2014-07-01 [vendor] K Box Entertainment Group membership database
Vector: Unknown attacker gained unauthorized access to K Box's membership database through a vulnerability in their website; the database was not adequately protected and allowed access to member personal information

K Box Entertainment Group — a Singapore-based karaoke chain with approximately 25 outlets — suffered a breach of its customer membership database in 2014, exposing data for …

Data leak

U.S. Office of Personnel Management (OPM) Security Clearance Breach (21.5M Records)

2014-07-01
Vector: APT10 (Chinese state-sponsored) used stolen credentials from a KeyPoint Government Solutions contractor to access OPM's network, then pivoted to the SF-86 security clearance database via a legacy Oracle database with no multi-factor authentication

The 2015 OPM breach is widely regarded as the most damaging government data breach in U.S. history. Chinese state-sponsored hackers (APT10/Deep Panda) used credentials stolen from …

Supply chain [SC]

Lowe's Driver Records Breach via SafetyFirst E-Driver File Platform

2014-07-01 [vendor] SafetyFirst E-Driver File (driver management platform)
Vector: SafetyFirst's E-Driver File online database system — used by Lowe's to store driver qualification records for commercial vehicle operators — had a configuration error or vulnerability that exposed driver records to unauthorized access

In a letter to both current and former employees, Lowe’s says that personal information might have been compromised after a third-party vendor exposed it to the public. In a letter …

Cloud

Code Spaces AWS Multi-Account Ransomware Destruction (Company Shutdown)

2014-06-17 [vendor] Amazon Web Services (EC2, S3, EBS)
Vector: Attacker gained access to Code Spaces' AWS management console (EC2 control panel) using stolen credentials, then launched a DDoS attack and demanded payment; when Code Spaces attempted to regain control, the attacker systematically deleted all EC2 instances, S3 buckets, EBS snapshots, and machine images

Code Spaces was a code hosting and project management platform (similar to GitHub) that operated entirely on AWS. On June 17, 2014, an attacker gained access to Code Spaces' AWS …

Data leak

Domino's Pizza Belgium/France Customer Data Breach — 600,000 Records

2014-06-13 [vendor] Domino's Pizza (European operations, Belgium and France)
Vector: SQL injection or web application attack against Domino's Pizza's online ordering system in Belgium and France; hacker group Rex Mundi claimed responsibility and threatened to publish the data unless a ransom of €30,000 was paid

In June 2014, hacker group Rex Mundi announced they had stolen approximately 592,000 customer records from Domino's Pizza's online ordering systems in Belgium and France. Rex Mundi …

Data leak

CareFirst BlueCross BlueShield Cyberattack — 1.1 Million Members, China APT

2014-06-01 [vendor] CareFirst BlueCross BlueShield member database
Vector: China-linked nation-state APT (same group attributed to Anthem and Premera breaches) gained access to CareFirst's network approximately eleven months before detection; initial access vector was consistent with spear-phishing used in contemporaneous health insurer breaches

In June 2014, a sophisticated cyberattacker — assessed by Mandiant as the same China-linked group responsible for the Anthem (February 2015) and Premera Blue Cross (March 2015) …

Data leak

Domino's Pizza France and Belgium Breach — 650,000 Customer Records

2014-06-01 [vendor] Domino's Pizza France and Belgium online ordering database
Vector: A group called Rex Mundi gained access to Domino's Pizza France and Belgium's online ordering systems and databases through a vulnerability in the web application; the group claimed to have exploited SQL injection or similar techniques to access customer order databases

In June 2014, Rex Mundi — a cybercriminal extortion group known for targeting European companies — compromised Domino's Pizza France and Belgium's online ordering systems and …

Data leak

JPMorgan Chase Comet/JPMC Hack — 76 Million Households, 7 Million Businesses

2014-06-01 [vendor] JPMorgan Chase internal network / customer data systems
Vector: Russian criminal group (linked to Bitcoin exchange operators) exploited an unpatched vulnerability on a JPMorgan Chase server — specifically a zero-day in the bank's website that was not updated to use two-factor authentication; attackers gained root privileges on more than 90 servers

Between June and August 2014, a sophisticated attack attributed to a Russian cybercriminal group compromised JPMorgan Chase's internal network, gaining access to data for 76 …

Data leak

JPMorgan Chase Breach — 83 Million Accounts (Russia-Linked)

2014-06-01
Vector: Attackers exploited a missed security upgrade on a single JPMorgan server — a bank employee had forgotten to enable two-factor authentication on one web application server — allowing the attackers to obtain a root-level list of applications and servers, then pivot to over 90 bank servers

In June 2014, a sophisticated hacking group breached JPMorgan Chase's network and maintained access until it was discovered approximately in August 2014. The attackers accessed …

Data leak

CareFirst BlueCross BlueShield APT Breach (1.1M Members)

2014-06-01
Vector: Chinese APT intrusion (same infrastructure as Anthem and Premera breaches); attackers first compromised CareFirst's network in April 2014, but that incursion was identified and contained; attackers re-entered via backdoors in June 2014 and maintained access until April 2015 when Mandiant detected the intrusion

CareFirst BlueCross BlueShield, the dominant health insurer for the Washington D.C./Maryland/Virginia region, disclosed on May 20, 2015 that approximately 1.1 million members had …

Supply chain [SC]

JPMorgan Chase 2014 Data Breach (WSJ, NYT, SEC filings)

2014-06-01 [vendor] JPMorgan Chase corporate network and web applications
Vector: Stolen employee credentials from a compromised personal computer; attackers exploited a vulnerability in a web application server and escalated access due to a missing two-factor authentication token on one network server

In June 2014, attackers compromised a JPMorgan Chase employee's personal computer and obtained login credentials, which they used to gain initial access to the bank's corporate …

Cloud

Uber Canada GitHub Credentials — 2014 AWS S3 Breach of 50,000 Driver Records

2014-05-12 [vendor] Uber private GitHub / AWS S3 driver database
Vector: An Uber software engineer stored AWS credentials in a private GitHub repository; the repository was accessed by a third party who used the credentials to access an Amazon S3 bucket containing the driver database backup; the third party used the AWS access to download approximately 50,000 driver names and licence numbers

In May 2014, a third party accessed an Uber software engineer's private GitHub repository that contained AWS credentials stored in code. Using these credentials, the attacker …

Data leak

Premera Blue Cross Data Breach — 11 Million Members, Nation-State APT (Winnti)

2014-05-05 [vendor] Premera Blue Cross member database
Vector: Nation-state APT group (assessed as Winnti/APT41, China-linked) gained initial access via a spear-phishing email; maintained persistent access for approximately 9 months while conducting lateral movement and data exfiltration from Premera's member database

On 5 May 2014, attackers believed to be a Chinese APT group (assessed as Winnti/APT41) gained access to Premera Blue Cross's network via a spear-phishing attack. The attackers …

Data leak

Premera Blue Cross Data Breach (11M Members, APT)

2014-05-05
Vector: Nation-state attackers (believed to be Chinese APT, same campaign as Anthem breach) gained initial access via spear-phishing email with malicious attachment; established persistent access to Premera's IT environment for approximately 9 months before detection

Premera Blue Cross, one of the largest health insurance carriers in the Pacific Northwest, disclosed in March 2015 that attackers had gained access to its IT systems beginning May …

Other

Heartbleed OpenSSL Vulnerability — Mass Exploitation of CVE-2014-0160

2014-04-07 [vendor] OpenSSL 1.0.1 through 1.0.1f (used by approximately 17% of all HTTPS web servers) [cve] CVE-2014-0160
Vector: Critical buffer over-read vulnerability in OpenSSL's TLS heartbeat extension (RFC 6520) allowed remote unauthenticated attackers to read up to 64KB of memory per request from vulnerable servers, potentially exposing private keys, session tokens, and plaintext credentials

CVE-2014-0160 (Heartbleed) was a critical vulnerability in OpenSSL's TLS/DTLS heartbeat extension, introduced in OpenSSL 1.0.1 (released March 2012) and present in all versions …

Data leak

Community Health Systems Chinese APT Breach — 4.5 Million Patient Records

2014-04-01 [vendor] Community Health Systems patient database (206 hospitals in 29 states) [malware] Custom Mimikatz variant
Vector: Advanced persistent threat group (Mandiant/FireEye attributed to China, assessed as APT18/Wekby) used spear-phishing to gain initial access and deployed a customized version of the Mimikatz credential-harvesting tool; attacker moved laterally across CHS's 200+ hospital network

Between April and June 2014, a China-linked APT group (assessed as APT18/Wekby by Mandiant, who CHS hired to investigate) compromised Community Health Systems (CHS) — at the time …

Data leak

Staples POS Malware Breach — 1.16 Million Payment Cards

2014-04-01 [vendor] Staples office supply stores POS systems [malware] POS RAM-scraping malware
Vector: Cybercriminals installed POS RAM-scraping malware on point-of-sale systems at Staples office supply stores; the malware captured payment card track data from device memory during transaction processing

Between April and September 2014, POS malware infected point-of-sale systems at 115 Staples store locations across the United States. The breach resulted in approximately 1.16 …

Data leak

Community Health Systems APT18 Breach via Heartbleed (4.5M Patients)

2014-04-01 [vendor] Juniper VPN (Heartbleed) [cve] CVE-2014-0160
Vector: APT18 (Dynamite Panda), a Chinese state-linked threat actor, exploited the Heartbleed vulnerability (CVE-2014-0160) against Community Health Systems' Juniper VPN appliance to extract VPN credentials from memory; used stolen credentials to authenticate as a legitimate user and access the network

Between approximately April and June 2014, APT18 (also known as Dynamite Panda, Threat Group-0416, or Wekby), a Chinese state-linked advanced persistent threat group attributed by …

Data leak

Home Depot BlackPOS Malware POS Breach (56M Cards)

2014-04-01 [malware] BlackPOS (Kaptoxa) RAM-scraper
Vector: Attackers used stolen vendor credentials (from a third-party vendor) to access Home Depot's network, then exploited an unpatched Windows vulnerability to move laterally and deploy a custom variant of BlackPOS RAM-scraping malware on self-checkout POS systems

Between April and September 2014, attackers used stolen credentials belonging to a third-party Home Depot vendor to gain initial access to the retailer's network. They exploited an …

Data leak

Staples POS Breach — 1.16 Million Payment Cards

2014-04-01 [malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on point-of-sale systems at Staples retail stores, capturing payment card track data at the time of purchase

Between approximately April and September 2014, attackers deployed POS malware at Staples retail stores across the eastern United States. Staples first acknowledged an …

Supply chain [SC]

Boston Medical Center Patient Records Breach via MDF Transcription Services

2014-04-01 [vendor] MDF Transcription Services
Vector: MDF Transcription Services, a medical transcription vendor contracted by Boston Medical Center, inadvertently posted patient records to a publicly accessible website without authentication; the records were uploaded to an internet-accessible server rather than a secure private system

Boston Medical Center said it has fired a transcription service after a health care provider reported that the medical records of about 15,000 patients at the hospital were posted …

Data leak

OPM Personnel Files Breach (4.2M Federal Employees) — Earlier Intrusion Disclosed June 2015

2014-03-01 [malware] PlugX RAT
Vector: Chinese state-sponsored attackers (APT3/Gothic Panda, potentially distinct from the APT10 intrusion responsible for the SF-86 clearance breach) gained access to OPM's personnel records system; the initial vector involved stolen credentials, with attackers using the PlugX RAT for persistence

The OPM breach disclosed in June 2015 actually comprised two distinct intrusions. This earlier intrusion — dating to approximately March 2014 or possibly as early as late 2013 — …

Data leak

University of Maryland Data Breach — 310,000 Records

2014-02-18
Vector: Attackers gained unauthorized access to a University of Maryland database server containing records for all faculty, staff, and students who had been issued a university ID; the specific technical attack vector was not fully disclosed but involved unauthorized access to a records database

On February 18, 2014, the University of Maryland suffered a data breach in which attackers accessed a database containing records for 309,079 faculty, staff, and students who had …

Data leak

Kickstarter User Data Breach — Usernames, Emails, Hashed Passwords

2014-02-12 [vendor] Kickstarter (crowdfunding platform)
Vector: SQL injection attack against Kickstarter's database; law enforcement notified Kickstarter of the unauthorized access on February 12, 2014

On February 12, 2014, Kickstarter was notified by law enforcement that its database had been accessed by unauthorized attackers via a SQL injection vulnerability. Kickstarter …

Data leak

Federal Aviation Administration (FAA) Employee Data Breach (45,000 Records)

2014-02-01
Vector: Unauthorized access to an FAA internal computer system containing employee records; the agency reported the system was accessed without authorization, though the specific technical vector was not fully disclosed publicly

In early 2014, the Federal Aviation Administration (FAA) suffered an unauthorized intrusion into an agency computer system that contained personally identifiable information for …

Credential theft

eBay Employee Credential Breach (145M User Records)

2014-02-01
Vector: Attackers compromised the login credentials of a small number of eBay employees with database access, then used those credentials to access eBay's corporate network and exfiltrate the customer database

In approximately February-March 2014, attackers compromised the credentials of a small number of eBay corporate employees and used those credentials to access the company's …

Data leak

Morrisons UK Supermarket Insider Data Breach — 100,000 Employees, Landmark Ruling

2014-01-01 [vendor] Morrisons supermarket internal payroll / employee HR database
Vector: A disgruntled Morrisons senior internal IT auditor (Andrew Skelton) with legitimate access to payroll data deliberately copied and leaked the personal and financial data of 99,998 Morrisons employees to newspaper outlets and multiple file sharing websites, motivated by a personal grievance over a disciplinary matter

In early 2014, Andrew Skelton — a senior IT auditor at Morrisons, one of the UK's largest supermarket chains — deliberately leaked the personal data of 99,998 Morrisons employees …

Data leak

Indiana University Data Exposure — 146,000 Social Security Numbers

2014-01-01
Vector: Data exposure — files containing student and former student personally identifiable information including Social Security numbers were left accessible on a publicly reachable server without proper access controls; discovered during a routine security audit

Indiana University discovered in May 2014 that files containing Social Security numbers and other personal data for approximately 146,000 current and former students had been …

Data leak

U.S. Postal Service (USPS) Employee Data Breach (800K Records, China-Attributed)

2014-01-01
Vector: Chinese state-sponsored hackers gained persistent access to USPS corporate networks; the exact initial vector was not fully disclosed publicly but likely involved spear-phishing or exploitation of an internet-facing system followed by lateral movement

In November 2014, the U.S. Postal Service disclosed that Chinese government hackers had breached its corporate networks and accessed personnel data for approximately 800,000 …

Data leak

Marriott press release / CSO Online / FTC / NY AG

2014-01-01 [vendor] Starwood Hotels guest reservation system [malware] Remote Access Trojan (name undisclosed)
Vector: CWE-506: Embedded Malicious Code / Remote Access Trojan deployed in Starwood network prior to Marriott acquisition

Chinese state-sponsored hackers (linked to PLA) compromised Starwood Hotels reservation system as early as 2014, 2 years before Marriott acquired Starwood (2016). Breach persisted …

Supply chain [SC]

NBC News

2014-01-01 [vendor] iHealth Innovations
Vector: Misconfigured rsync backup server left publicly accessible without authentication

On May 3, 2017, security researcher Bob Diachenko of the Kromtech Security Research Center discovered a massive trove of patient records from Bronx-Lebanon Hospital Center in New …

Supply chain [SC]

Mercedes-Benz USA Cloud Vendor Breach — 1.6M Records Exposed, SSNs and Credit Card Data for ~1,000

2014-01-01 [vendor] Unnamed cloud storage vendor (Mercedes-Benz USA)
Vector: Misconfigured cloud storage platform — an unnamed vendor left a dataset of Mercedes-Benz customer records unsecured and accessible via the internet

Mercedes-Benz USA (MBUSA) disclosed on June 11, 2021, that a vendor had inadvertently left sensitive customer and prospective buyer data accessible on a cloud storage platform. The …

Data leak

Excellus BlueCross BlueShield Data Breach — 10.5 Million Members, Nation-State APT

2013-12-23 [vendor] Excellus BlueCross BlueShield member database
Vector: Nation-state APT group (assessed as same Chinese threat actor responsible for Anthem and Premera breaches) gained initial access in December 2013 via unknown means and maintained persistent access for approximately 20 months before being discovered during a forensic investigation

In December 2013, a sophisticated cyberattack — widely attributed to a China-linked nation-state APT group believed to be the same threat actor responsible for the Anthem and …

Data leak

Excellus BlueCross BlueShield APT Breach (10.5M Members, 20 Months Undetected)

2013-12-01
Vector: Sophisticated APT intrusion (consistent with Chinese state-linked APT campaign that also targeted Anthem, Premera Blue Cross, and CareFirst BCBS in the same period); attackers maintained undetected access for approximately 20 months; Excellus engaged Mandiant after sister organizations were breached, which revealed the compromise

Excellus BlueCross BlueShield, a Rochester, New York-based health insurer covering approximately 3.5 million members in upstate New York, disclosed on September 10, 2015 that …

Other [SC]

US Senate Commerce Committee / BreachSense / Huntress

2013-11-15 [vendor] Target Corporation POS systems [malware] BlackPOS / Kaptoxa
Vector: CWE-1104: Use of Unmaintained Third-Party Components (phishing of HVAC vendor Fazio Mechanical for network credentials, then lateral movement to POS environment)

Attackers phished Fazio Mechanical (HVAC vendor) to steal Target network credentials in Nov 2013. Moved laterally from vendor-accessible HVAC network segment to POS environment due …

Cloud

Toyota Connected GPS Data Exposure — 2.15 Million Vehicles, 10-Year Undetected Cloud Misconfiguration

2013-11-06 [vendor] Toyota Connected cloud platform / Toyota T-Connect telematics service
Vector: Misconfigured Toyota Connected cloud environment exposed vehicle location data to the public internet; the data was stored in a cloud environment (managed by Toyota's subsidiary Toyota Connected) with misconfigured access controls that made it publicly accessible without authentication for approximately 10 years

Toyota disclosed in May 2023 that vehicle data for 2.15 million Toyota and Lexus customers in Japan had been publicly accessible via a misconfigured cloud environment for …

Cloud

Toyota Connected Vehicle Cloud Misconfiguration (2.15M Customers, 10-Year Exposure)

2013-11-06 [vendor] Toyota Connected cloud environment (T-Connect, G-Link, G-Link Lite, G-BOOK)
Vector: Cloud misconfiguration — Toyota's connected vehicle cloud environment was configured to be publicly accessible without authentication; the misconfiguration resulted from 'insufficient explanation and thoroughness of data handling rules' causing data not to be stored with appropriate access controls

Toyota Motor Corporation disclosed on May 12, 2023 that vehicle location data and other connected vehicle information for approximately 2.15 million customers in Japan had been …

Data leak

Cupid Media Dating Sites Breach — 42 Million User Accounts in Plaintext

2013-11-01 [vendor] Cupid Media / CupidPlc dating site databases
Vector: An attacker gained access to Cupid Media's database — an Australian company operating approximately 35 niche online dating websites; the stolen database surfaced in a cache of databases found on a server used by cybercriminals that had been seized by investigators

In November 2013, Cupid Media — an Australian company operating approximately 35 niche online dating websites including ChristianCafe, CatholicMingle, MilfDate, AsianDating, and …

Data leak

AT&T Insider Breach — Outsourced Call Center Employees Sold Customer Data (FCC $25M Fine)

2013-11-01
Vector: Insider threat — employees at AT&T's outsourced call centers in Colombia, Mexico, and the Philippines improperly accessed and sold customer data (names and partial/full Social Security numbers) to unauthorized third parties to facilitate unauthorized phone unlocking for profit

Between approximately November 2013 and April 2014, employees at AT&T's outsourced call centers in Colombia, Mexico, and the Philippines improperly accessed records of …

Supply chain [SC]

Target Corporation BlackPOS POS Malware Breach via Fazio Mechanical HVAC Vendor

2013-11-01 [vendor] Fazio Mechanical Services (HVAC contractor) / Target vendor portal [malware] BlackPOS (Kaptoxa) RAM-scraping malware; Citadel malware (on vendor's systems)
Vector: Attackers stole network credentials from Fazio Mechanical Services — a Pennsylvania HVAC (heating, ventilation, and air conditioning) contractor — by infecting Fazio employee computers with Citadel malware; these credentials provided access to Target's vendor portal, from which attackers pivoted to Target's POS network and installed BlackPOS RAM-scraping malware

Last week, Target told reporters at The Wall Street Journal and Reuters that the initial intrusion into its systems was traced back to network credentials that were stolen from a …

Supply chain [SC]

Florida Healthy Kids Corporation (FHKC) / Jelly Bean Communications Design breach

2013-11-01 [vendor] Jelly Bean Communications Design (web hosting vendor for FHKC enrollment portal)
Vector: Unpatched web application vulnerabilities at third-party hosting vendor exploited over seven years; vendor failed to apply CMS/PHP security patches from November 2013 through December 2020

Florida Healthy Kids Corporation (FHKC) administers the Florida KidCare health insurance program, providing subsidized health and dental coverage to children across Florida. FHKC …

Data leak

Scottrade Brokerage Breach — 4.6 Million Customers

2013-10-01
Vector: Sophisticated targeted attack — attackers breached Scottrade's network via methods consistent with the same criminal group responsible for the JPMorgan Chase 2014 breach; the investigation found unauthorized access to a database containing customer contact information

In October 2015, Scottrade announced that it had been notified by federal law enforcement that its systems had been breached between approximately late 2013 and early 2014. The …

Credential theft

P.F. Chang's POS Malware Breach (2M Cards, FIN6)

2013-09-01 [malware] POS malware (FIN6)
Vector: FIN6 cybercrime group deployed POS malware on P.F. Chang's restaurant payment systems; malware captured Track 1 and Track 2 magnetic stripe data from in-store transactions over approximately 9 months

P.F. Chang's China Bistro, a US casual dining restaurant chain, confirmed in June 2014 that its payment systems had been compromised by POS malware for approximately 9 months …

Credential theft

P.F. Chang's POS Malware Breach — 2 Million Payment Cards (FIN6)

2013-09-01 [malware] POS RAM-scraping malware
Vector: POS malware — attackers compromised P.F. Chang's corporate network and installed RAM-scraping malware on point-of-sale systems at restaurant locations; the specific initial network intrusion vector was not fully disclosed

P.F. Chang's China Bistro, a national casual dining restaurant chain, confirmed in June 2014 that it had suffered a payment card breach after KrebsOnSecurity reported that a large …

Data leak

Adobe Systems Breach: Source Code Theft and 153M User Records

2013-08-01
Vector: Attackers gained access to Adobe's network and exfiltrated source code for Acrobat, ColdFusion, and Reader; also accessed the customer database containing passwords encrypted with 3DES using the same key for all accounts

In October 2013, Adobe disclosed two simultaneous major security incidents: (1) Source code theft: attackers exfiltrated source code for Adobe Acrobat, Adobe Reader, Adobe …

Supply chain [SC]

SEC Administrative Proceeding against R.T. Jones Capital Equities Management

2013-07-22 [vendor] Artesys (third-party web server hosting)
Vector: Compromise of third-party-hosted web server (Artesys platform); attackers gained access and copy rights to PII stored on the server

On July 22, 2013, R.T. Jones Capital Equities Management, a St. Louis-based registered investment adviser, discovered that its third-party-hosted web server had been compromised by …

Data leak

Neiman Marcus POS Malware Breach — 350K Payment Cards (2013–2014)

2013-07-16 [malware] POS RAM-scraping malware
Vector: POS malware — attackers installed malware on Neiman Marcus point-of-sale terminals that scraped payment card track data (including magnetic stripe data) from memory as cards were swiped at checkout

Between approximately July 16, 2013 and October 30, 2013, attackers installed RAM-scraping malware on Neiman Marcus point-of-sale (POS) systems at the luxury retailer's stores. The …

Data leak

Advocate Health Care Stolen Unencrypted Computers (4M Patients, $5.55M HIPAA)

2013-07-15
Vector: Physical theft of four unencrypted desktop computers from Advocate Medical Group's administrative offices in Park Ridge, Illinois; two subsequent smaller incidents involved theft of an unencrypted laptop from an employee's car and a business associate (Blackhawk Consulting Group) compromise

On July 15, 2013, four unencrypted desktop computers were stolen from Advocate Medical Group's administrative offices in Park Ridge, Illinois. The computers contained personal and …

Data leak

Advocate Health Care Data Breach — 4 Million Patients, Stolen Laptops

2013-07-15 [vendor] Advocate Medical Group unencrypted laptops
Vector: Four unencrypted laptops were stolen from an Advocate Medical Group administrative office in Park Ridge, Illinois; the laptops contained patient data for approximately 4 million patients and were not encrypted despite Advocate's data security policies

On 15 July 2013, four unencrypted laptops were stolen from an administrative office of Advocate Medical Group — the largest physician practice group in Illinois, associated with …

Credential theft

Yahoo 3-Billion-Account Breach (2013 + 2014, Disclosed 2016–2017)

2013-07-01
Vector: Two separate breaches: (1) 2013 — attackers forged authentication cookies using stolen Yahoo proprietary cookie-minting code, bypassing password requirements entirely; (2) 2014 — Russian state-sponsored actors (FSB/Karim Baratov/Alexsey Belan) used spear-phishing to steal Yahoo admin credentials and copied the User Account Database backup

Yahoo suffered two separate mega-breaches that collectively represent the largest credential theft in internet history. (1) August 2013 breach (disclosed December 2016, revised to …

Data leak

Facebook Cambridge Analytica API Abuse (87M User Profiles)

2013-06-01 [vendor] Facebook Open Graph API
Vector: Aleksandr Kogan's app 'This Is Your Digital Life' exploited Facebook's Open Graph API permission model, which allowed apps to harvest not only the personal data of users who installed the app but also all of their friends' data — without those friends' consent or knowledge

Between 2013-2015, Aleksandr Kogan (Cambridge University researcher) built a personality quiz app ('This Is Your Digital Life') and used Facebook's Open Graph API to harvest …

Data leak

Michaels Stores POS Malware Breach — 3 Million Payment Cards

2013-05-08 [vendor] Michaels Stores / Aaron Brothers point-of-sale systems [malware] POS RAM-scraping malware
Vector: Sophisticated POS RAM-scraping malware was installed on point-of-sale terminals at Michaels arts-and-crafts retail stores and its subsidiary Aaron Brothers; the malware was specifically engineered to evade Michaels' security tools and captured payment card track data from memory during transactions

Between 8 May 2013 and 27 January 2014, POS malware infected approximately 7.2% of Michaels stores' point-of-sale terminals nationwide, capturing payment card data for …

Credential theft

Michaels Stores POS Malware Breach (2.6M Cards, Aaron Brothers)

2013-05-08 [malware] POS malware (Track data scraper)
Vector: POS malware deployed on payment systems at Michaels arts and crafts stores and Aaron Brothers stores; initial access likely via compromised third-party vendor credentials; malware captured Track 1 and Track 2 magnetic stripe data

Michaels Stores, the US arts and crafts retail chain, confirmed in April 2014 that a data breach between May 8, 2013 and January 27, 2014 (approximately 9 months) had compromised …

Credential theft

Michaels Stores POS Malware Breach — 2.6 Million Payment Cards

2013-05-08 [malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on point-of-sale terminals at Michaels Stores and Aaron Brothers (subsidiary) retail locations, capturing full payment card track data as cards were swiped at checkout

Michaels Stores, the large arts and crafts retail chain, disclosed in January 2014 that it was investigating a potential data security breach involving payment cards used at its …

Data leak

Tumblr Breach — 65.5M Email Addresses and Passwords (2013, Discovered 2016)

2013-05-01 [vendor] Tumblr (microblogging and social media platform, owned by Yahoo at time of disclosure)
Vector: Database compromise; the breach occurred in early 2013 but was not disclosed until the dataset appeared for sale on dark web markets in May 2016 — Tumblr was notified by threat intelligence company Mapbox subsidiary Haveibeenpwned/Troy Hunt; the original attack vector was not publicly identified due to the three-year delay

In May 2016, a dataset containing 65.5 million Tumblr user email addresses and hashed passwords appeared for sale on dark web markets, offered by the same seller ('peace_of_mind') …

Data leak

LivingSocial Breach — 50 Million User Accounts

2013-04-26 [vendor] LivingSocial customer database (Amazon subsidiary)
Vector: Unknown attacker gained unauthorized access to LivingSocial's customer database; specific technical attack vector was not disclosed; attacker accessed and exfiltrated up to 50 million customer records

On 26 April 2013, LivingSocial — a daily deals website owned by Amazon — disclosed that attackers had accessed its database containing up to 50 million customer records. Exposed …

Data leak

LivingSocial Hack — 50 Million Customer Accounts

2013-04-01
Vector: Unauthorized access to LivingSocial's database systems; the specific technical vector was not disclosed publicly, but the attacker gained read access to a customer database

In late April 2013, LivingSocial (an online deals and local offers marketplace, then majority-owned by Amazon) suffered a cyberattack in which hackers accessed a database …

Data leak

Evernote Database Breach — 50 Million User Accounts Forced Password Reset

2013-02-28 [vendor] Evernote user database
Vector: Unknown attacker gained access to Evernote's user database; Evernote described the attack as targeting their network infrastructure; attacker accessed usernames, email addresses, and encrypted passwords

In late February 2013, Evernote — the popular note-taking application with approximately 50 million registered users — detected and blocked suspicious activity on its network. The …

Supply chain [SC]

Goodwill Industries POS Malware Breach — Payment Card Data at Thrift Stores

2013-02-01 [vendor] C&K Systems (third-party POS service provider for Goodwill Industries) [malware] POS RAM-scraping malware
Vector: Malware was installed on point-of-sale systems at Goodwill Industries stores nationwide through a compromised third-party payment processing vendor (C&K Systems); the malware collected payment card track data during transactions

Beginning in February 2013, a third-party point-of-sale service provider to Goodwill Industries — C&K Systems, a payment processing vendor — had its systems compromised with …

Data leak

Imgur Breach — 1.7M Email Addresses and Passwords (2013, Discovered 2017)

2013-01-01 [vendor] Imgur (image hosting platform)
Vector: Database compromise of Imgur's user account database; the breach occurred in 2013 but was not discovered until security researcher Troy Hunt shared a file containing Imgur credentials with the company in November 2017; the precise initial attack vector was not identified due to the years-long delay

In November 2017, security researcher Troy Hunt (operator of Have I Been Pwned) notified Imgur that a dataset containing 1.7 million Imgur user email addresses and passwords had …

Credential theft

Schnucks Markets POS Malware Breach — 2.4 Million Cards

2012-12-01 [malware] POS RAM-scraping malware
Vector: POS malware — attackers installed RAM-scraping malware on Schnucks' point-of-sale systems at multiple grocery store locations, capturing payment card track data during checkout transactions

Schnucks, a regional Midwestern grocery chain headquartered in St. Louis, Missouri, with approximately 100 store locations, disclosed in March 2013 that it had suffered a payment …

Data leak

Penn State University Computer Science Network Breach — APT (18,000 Individuals)

2012-09-01
Vector: Two separate nation-state APT intrusions: one attributed to China-based actors (active from approximately September 2012) and one from an unattributed threat actor; the attackers used sophisticated malware to gain persistent access to Penn State's College of Engineering network

In May 2015, Pennsylvania State University disclosed that its College of Engineering computer network had been compromised by two separate sophisticated cyberattacks. One was …

Data leak

Blizzard Entertainment Battle.net Breach — 14 Million Accounts

2012-08-04 [vendor] Blizzard Entertainment Battle.net user database
Vector: An unauthorized party illegally accessed Battle.net's internal network and obtained information from Blizzard's user database; the specific intrusion vector was not disclosed; the attacker gained access to database servers in the Americas region

On 4 August 2012, Blizzard Entertainment — maker of World of Warcraft, Diablo, and StarCraft — discovered that an unauthorized party had illegally accessed their internal network …

Credential theft

Barnes & Noble PIN Pad Skimmer Attack (63 Stores, FBI-Delayed Disclosure)

2012-08-01
Vector: Physical tampering — attackers installed hardware skimming devices (including PIN capture overlays) on PIN pad terminals at 63 Barnes & Noble stores across 9 states; tampered terminals captured both the magnetic stripe data and PIN from debit card transactions

Barnes & Noble, the US bookseller, disclosed in October 2012 that PIN pad payment terminals at 63 retail stores across 9 states had been physically tampered with — skimming devices …

Data leak

Disqus Comment Platform Breach — 17.5 Million Users (2012 Data Disclosed 2017)

2012-07-01 [vendor] Disqus commenting platform user database
Vector: Unknown attacker gained access to a snapshot of Disqus's user database dating from July 2012; the specific intrusion mechanism was not disclosed; the breach data sat dormant for over five years before being shared with security researcher Troy Hunt who alerted Disqus

Disqus — the widely-used blog comment hosting service embedded across millions of websites — disclosed in October 2017 that a database snapshot from July 2012 containing data for …

Data leak

Disqus Breach — 17.5M Email Addresses and Hashed Passwords (2012, Discovered 2017)

2012-07-01 [vendor] Disqus (comment hosting and management service)
Vector: Database compromise; the breach occurred in July 2012 but was not discovered until security researcher Troy Hunt provided Disqus with a copy of the dataset in October 2017 — five years after the breach

On October 5, 2017, Disqus disclosed that it had been notified by security researcher Troy Hunt that a dataset containing user data from a 2012 breach had been provided to him by …

Cloud

Dropbox Credential Reuse Breach via LinkedIn (68M Accounts)

2012-07-01
Vector: A Dropbox employee reused their LinkedIn password for their Dropbox work account; when the 2012 LinkedIn breach exposed that password, attackers used it to log into the employee's Dropbox work account, which contained a document with hashed Dropbox user passwords

The Dropbox breach of approximately July 2012 originated from employee password reuse. A Dropbox employee had reused their LinkedIn account password for their corporate Dropbox …

Data leak

South Carolina DHHS Medicaid Data Breach — 228,000 Recipients

2012-06-14
Vector: Insider threat — a former employee of South Carolina's Department of Health and Human Services (DHHS) accessed the Medicaid eligibility database and transferred files containing beneficiary data to an unauthorized location; the employee later posted the data online

In August 2012, the South Carolina Department of Health and Human Services disclosed that a former agency employee, Christopher Lykes Jr., had accessed the state's Medicaid …

Credential theft

Barnes & Noble POS PIN Pad Tampering — 63 Stores, Card Skimmers

2012-06-01
Vector: Physical PIN pad tampering — attackers physically installed hardware skimmers or modified PIN pad devices at Barnes & Noble retail checkout terminals in 63 stores across nine US states; the tampered devices captured payment card magnetic stripe data and PINs

Barnes & Noble disclosed in October 2012 that criminals had tampered with at least one PIN pad terminal at each of 63 of its retail bookstore locations across nine states …

Credential theft

LinkedIn Unsalted SHA-1 Password Breach (117M Credentials)

2012-05-01
Vector: SQL injection or server compromise allowed attackers to exfiltrate LinkedIn's password database containing unsalted SHA-1 password hashes; in 2016, the full scope (117M records) was revealed when the data appeared for sale

In June 2012, LinkedIn disclosed that a subset of member passwords had been compromised after approximately 6.5 million unsalted SHA-1 password hashes appeared on a Russian …

Credential theft

eHarmony Password Breach — 1.5 Million Unsalted MD5 Hashes Leaked

2012-05-01
Vector: Database breach — attackers gained unauthorized access to eHarmony's member database and extracted hashed passwords; eHarmony stored passwords as unsalted MD5 hashes, making them highly susceptible to rainbow table and brute-force cracking

On June 6, 2012, eHarmony confirmed that a subset of its member passwords had been compromised and posted to an online password cracking forum. Approximately 1.5 million password …

Credential theft

eHarmony Password Hash Breach (1.5M Unsalted MD5 Passwords)

2012-05-01
Vector: Unauthorized access to eHarmony's user database; attackers obtained and published approximately 1.5 million unsalted MD5 password hashes online

eHarmony, the US online dating service, disclosed on June 6, 2012 that a subset of its member passwords had been compromised and posted online. Approximately 1.5 million unsalted …

Credential theft

Last.fm Password Breach — 43 Million Unsalted MD5 Hashes (Discovered 2016)

2012-03-01
Vector: Database breach — attackers obtained Last.fm's user credential database; the passwords were stored as unsalted MD5 hashes, enabling mass cracking; the breach was not discovered publicly until 2016 when the database appeared on underground markets

Last.fm, the music discovery and social listening service (owned by CBS Interactive from 2007), suffered a breach of its user database that occurred around 2012 but was not …

Data leak

Zappos Breach — 24 Million Customer Accounts

2012-01-15
Vector: Attackers breached a Zappos database server located in Kentucky; the specific initial attack vector was not fully disclosed by the company, but the attacker accessed the internal network and the customer database

On approximately January 15-16, 2012, Zappos (the online shoe and clothing retailer owned by Amazon) suffered a breach in which attackers accessed a customer database server. …

Data leak

Facebook Stored 600 Million Passwords in Plaintext — Internal Access for Years

2012-01-01 [vendor] Facebook internal authentication logging systems
Vector: Internal system design failure: Facebook's password logging infrastructure incorrectly logged user passwords in plaintext to internal log files; these log files were stored in searchable plaintext accessible by thousands of Facebook engineers; this was a systemic implementation error rather than an external attack

In March 2019, security journalist Brian Krebs reported that Facebook had been storing hundreds of millions of user passwords in plaintext in internal log files since as early as …

Data leak

Global Payments Card Processor Breach (1.5M Cards, PCI Compliance Decertified)

2012-01-01
Vector: Attackers used an undisclosed method to breach Global Payments' systems and exfiltrate track 1 and track 2 magnetic stripe card data (full card data for card cloning) for approximately 1.5 million card accounts

Global Payments, a major Atlanta-based credit card processing company, disclosed in March 2012 that it had suffered a data breach affecting approximately 1.5 million credit and …

Data leak

Sutter Health Stolen Laptop (4.24M Patients, Largest 2011 Healthcare Breach)

2011-10-15
Vector: Physical theft — an unencrypted desktop computer was stolen from a Sutter Medical Foundation administrative office in Sacramento, California; the computer contained a Microsoft Access database with patient information

On October 15, 2011, an unencrypted desktop computer was stolen from a Sutter Medical Foundation administrative office in Sacramento, California. The computer contained an …

Data leak

Sutter Health Stolen Laptop Breach — 4.24 Million Patients

2011-10-14
Vector: Physical theft — an unencrypted desktop computer was stolen from a Sutter Physicians Services administrative office in Sacramento, California; the computer contained an unencrypted database file with patient information

On October 14, 2011, a desktop computer was stolen from a Sutter Physicians Services administrative office in Sacramento, California. The computer contained an unencrypted …

Data leak [SC]

TRICARE / SAIC Stolen Backup Tapes (4.9M Military Health Beneficiaries)

2011-09-14
Vector: Physical theft — backup tapes containing TRICARE beneficiary data were stolen from an employee's car in San Antonio, Texas; the tapes were being transported between SAIC facilities by a contractor employee

On September 14, 2011, backup tapes containing personal and protected health information for approximately 4.9 million TRICARE (US military healthcare) beneficiaries were stolen …

Data leak

TRICARE Military Health Backup Tape Theft — 4.9 Million Beneficiaries

2011-09-14
Vector: Physical theft — backup tapes were stolen from a Science Applications International Corporation (SAIC) employee's vehicle in San Antonio, Texas while the employee was transporting them; the tapes were unencrypted

On September 14, 2011, backup tapes containing TRICARE (the U.S. military health insurance program) data were stolen from a car belonging to an employee of Science Applications …

Other

Mt. Gox Bitcoin Exchange Collapse — 850,000 BTC Lost (Hack + Insolvency)

2011-09-01 [vendor] Mt. Gox (bitcoin exchange, Tokyo, operated by Tibanne Ltd., CEO Mark Karpelès)
Vector: Multiple attack vectors over multiple years: (1) 2011 auditor laptop compromise allowed private key theft and price manipulation; (2) ongoing transaction malleability exploitation allowed attackers to claim non-received Bitcoin withdrawals were unprocessed and have them re-sent; (3) internal control failures and alleged insider theft; Mt. Gox repeatedly processed duplicate withdrawal requests due to mishandling of Bitcoin transaction IDs

Mt. Gox was once the world's largest Bitcoin exchange, handling over 70% of global BTC transactions at its peak. On February 7, 2014, Mt. Gox suspended all Bitcoin withdrawals …

Data leak

Sony PlayStation Network and SOE Breach (77M Accounts, 23-Day Outage)

2011-04-17 [vendor] Apache HTTP Server
Vector: Attackers exploited a known vulnerability in Apache HTTP Server running on Sony's PlayStation Network infrastructure, gaining access to the PSN and Sony Online Entertainment (SOE) databases

Between April 17-19, 2011, attackers exploited a known Apache vulnerability to breach Sony's PlayStation Network (PSN) and Sony Online Entertainment (SOE) — the online gaming and …

Data leak

Citigroup Direct Web Application Breach — 360K Accounts

2011-04-01
Vector: Direct web application attack — hackers exploited an insecure direct object reference (IDOR) vulnerability in Citi's online banking portal by manipulating account numbers embedded in the site URL, allowing them to access other customers' account pages without authorization

In May 2011 (discovered internally, disclosed June 2011), hackers breached Citigroup's online banking portal by exploiting a straightforward insecure direct object reference (IDOR) …

Data leak [SC]

Epsilon Data Management Breach (60M+ Email Records, 75+ Companies)

2011-03-01 [vendor] Epsilon email marketing platform
Vector: Spear-phishing attack against Epsilon employees by Vietnamese cybercriminals; targeted phishing campaigns installed malware enabling access to Epsilon's customer email databases; attackers were part of a broader operation targeting multiple email marketing firms

In late March 2011, Epsilon Data Management — the world's largest permission-based email marketing company at the time (subsidiary of Alliance Data Systems) — suffered a data …

Other

RSA SecurID Seed Value Theft (40M Tokens Compromised)

2011-03-01 [vendor] RSA SecurID (two-factor authentication tokens); Adobe Flash [cve] CVE-2011-0609
Vector: Spear-phishing email with an Excel spreadsheet exploiting an Adobe Flash zero-day (CVE-2011-0609) was opened by an RSA employee; the embedded malware installed a backdoor enabling attackers to extract the SecurID token seed database

In March 2011, RSA Security (division of EMC) suffered a breach when a spear-phishing email titled '2011 Recruitment Plan' was opened by an employee. The Excel attachment exploited …

Credential theft

Subway Restaurants POS Malware Breach — 3 Million Cards (Romanian Gang)

2011-01-01 [malware] POS keylogger/scraping malware
Vector: Remote desktop protocol (RDP) intrusion — a Romanian criminal group remotely accessed franchise-owned Subway POS systems using weak or default RDP credentials; many Subway franchise locations ran their POS software on Windows computers with RDP enabled and inadequate passwords

A Romanian cybercrime group compromised point-of-sale systems at approximately 150 Subway franchise restaurants across the United States, stealing over 80,000 payment card numbers …

Data leak

NewYork-Presbyterian / Columbia University Hospital Shared Network Exposure — 6,800 Patients

2010-09-01
Vector: Network misconfiguration — a physician employed by Columbia University attempted to deactivate a personal computer server on the shared network; instead the misconfiguration exposed an application database, making patient records accessible on the internet

In September 2010, NewYork-Presbyterian Hospital (NYP) and Columbia University Medical Center (CUMC) disclosed that approximately 6,800 patient records had been exposed on the …

Data leak

New York-Presbyterian Hospital / Columbia University Shared Network Breach (4.8M HIPAA Fine)

2010-09-01
Vector: A Columbia University physician decommissioned a personal server that was connected to the shared Columbia/NYP network without following proper procedures; the server lacked server-level firewall protections, resulting in approximately 6,800 patient records becoming accessible on the internet

New York-Presbyterian Hospital (NYP) and Columbia University Medical Center (CU) operated a shared data network that included electronic health records. In September 2010, a …

Data leak

RockYou Plaintext Password Storage Breach (32M Passwords)

2009-11-01
Vector: SQL injection exploit against RockYou's web application allowed attacker to dump the entire user database, which stored 32 million passwords in plaintext with no hashing

RockYou was a social media widget company (popular Facebook/MySpace apps) that stored all 32 million user passwords in plaintext — with no hashing whatsoever. A SQL injection …

Data leak

FIS / Worldpay Prepaid Card Processor Breach — 13 Million Cards

2009-10-01 [vendor] RBS WorldPay (payment processor)
Vector: Network intrusion targeting RBS WorldPay's payment processing platform; attackers gained access to the card processing environment and stole encrypted payment card data along with the encryption keys, enabling them to decode and clone magnetic stripe data for prepaid payroll cards

In late 2008 through early 2009 (with disclosure occurring in late 2009 and broader reporting in 2010), RBS WorldPay (a payment processing subsidiary of the Royal Bank of Scotland …

Other

Operation Aurora — Chinese APT Nation-State Espionage (Google, Adobe, 30+ Companies)

2009-06-01 [vendor] Microsoft Internet Explorer 6/7/8 [malware] Hydraq (Aurora backdoor) [cve] CVE-2010-0249
Vector: Spear-phishing emails delivering a zero-day exploit for Internet Explorer (CVE-2010-0249, a use-after-free vulnerability in IE 6/7/8); watering hole attacks; lateral movement and data exfiltration once initial foothold established

Operation Aurora was a sophisticated, coordinated nation-state cyber espionage campaign originating in China and targeting at least 30 major corporations, with Google being the …

Other

Stuxnet / Operation Olympic Games — First Cyberweapon, Iran Natanz Centrifuges

2009-06-01 [vendor] Siemens Step7 SCADA; Siemens S7-300/S7-400 PLCs; Microsoft Windows [malware] Stuxnet [cve] CVE-2010-2568 +2
Vector: USB drive air-gap bypass for initial delivery into the isolated Natanz network; exploited four Windows zero-day vulnerabilities (CVE-2010-2568, CVE-2010-2772, CVE-2010-2729, CVE-2010-2568 LNK file); targeted Siemens Step7 SCADA software and Siemens S7-315/S7-417 PLCs; manipulated centrifuge rotor speeds while forging normal readings to SCADA operators

Stuxnet is the first publicly known cyberweapon designed to cause physical destruction of industrial equipment. Jointly developed by the United States (NSA, CIA — under 'Operation …

Credential theft

Twitter Admin Panel Brute-Force: Obama, Britney Spears, Fox News Accounts Hijacked

2009-01-05
Vector: Automated brute-force attack against Twitter's administrative control panel using common passwords; Twitter had no account lockout policy or rate limiting on administrative login attempts, allowing unlimited password guesses

In January 2009, a hacker gained access to Twitter's administrative control panel by guessing the password of a Twitter admin account using automated brute force — Twitter had …

Credential theft

RBS WorldPay ATM Cashout — First Major Coordinated Global ATM Fraud ($9.4M)

2008-11-04 [vendor] RBS WorldPay payment processing network
Vector: Eastern European cybercriminals (Sergei Tsurikov et al.) exploited vulnerabilities in RBS WorldPay's payment processing network, broke the encryption protecting payroll debit card account data, raised withdrawal limits on 44 compromised accounts, and cloned cards for distribution to a global network of ATM 'cashers'

RBS WorldPay, the US payment processing division of the Royal Bank of Scotland (distinct from the later Worldpay/FIS entity), suffered a coordinated cyberattack in early November …

Data leak

Wyndham Hotels Three Data Breaches (FTC Landmark Case, 619K Cards)

2008-04-01
Vector: Three separate network intrusions exploiting Wyndham's systemic security failures: unencrypted storage of payment card data, easily guessable passwords, failure to patch known vulnerabilities, failure to use firewalls, and failure to restrict third-party vendor access to the corporate network — attackers exfiltrated data to a domain registered in Russia

Between April 2008 and late 2010, Wyndham Hotel & Resorts suffered three separate network intrusions that collectively compromised approximately 619,000 consumer payment card …

Data leak

MySpace Server Compromise (360M Accounts, Unsalted SHA-1)

2008-01-01
Vector: Unknown server compromise; passwords stored as unsalted SHA-1 hashes of only the first 10 lowercase characters of each password — trivially crackable with rainbow tables

MySpace, once the world's largest social network, suffered a breach (believed to have occurred around 2008) that was not publicly revealed until May 2016 when approximately 360 …

Data leak

Hannaford Brothers Supermarkets POS Malware Breach (4.2M Cards, PCI Compliant)

2007-12-01
Vector: Attackers installed malware on Hannaford's point-of-sale servers that intercepted and transmitted unencrypted card data in real time as transactions were authorized, despite Hannaford being fully PCI-DSS compliant at the time

Hannaford Brothers, a supermarket chain operating in the northeastern United States, disclosed in March 2008 that its point-of-sale systems had been compromised by malware that …

Data leak

Heartland Payment Systems SQL Injection Network Sniffer Breach (130M Cards)

2007-12-01
Vector: Albert Gonzalez (TJX hacker) and accomplices used SQL injection to gain access to Heartland's payment processing network, planted a network packet sniffer in the internal payment processing system to capture card data in transit

Heartland Payment Systems, one of the largest payment processors in the United States, disclosed in January 2009 that it had been breached by Albert Gonzalez and two Russian …

Data leak

AOL Research Search Query Data Release (650K Users Re-Identified)

2006-08-04
Vector: AOL's Research department intentionally released 20 million anonymized search queries from 650,000 users to the public for academic research; the 'anonymization' was trivially reversible — reporters and researchers re-identified named individuals from their search patterns within days

On August 4, 2006, AOL's research team released a dataset of approximately 20 million search queries from 657,000 users to a public research website for academic purposes. Users …

Data leak

U.S. Department of Veterans Affairs Stolen Laptop (26.5M Veterans)

2006-05-03
Vector: A VA data analyst took home a VA-issued laptop and external hard drive containing 26.5 million veterans' PII without authorization; the equipment was stolen from his home in a burglary

On May 3, 2006, a laptop computer and external hard drive belonging to a U.S. Department of Veterans Affairs (VA) data analyst were stolen from his home in Aspen Hill, Maryland in …

Other

Samy Worm — First Self-Replicating XSS Worm (MySpace, 1M Infected in 20 Hours)

2005-10-04 [vendor] MySpace social network [malware] Samy worm (JavaScript XSS worm)
Vector: Reflected/stored cross-site scripting (XSS) vulnerability in MySpace user profiles exploited by a self-replicating JavaScript payload; the worm ran in any visitor's browser when they viewed an infected profile, automatically added the author as a friend, replicated itself to the visitor's own profile, and spread exponentially

On October 4, 2005, security researcher Samy Kamkar launched the Samy worm — the first self-replicating cross-site scripting (XSS) worm in history. The worm exploited an XSS …

Other

Samy Worm — MySpace XSS Self-Propagating Worm (1 Million Infected in 20 Hours)

2005-10-04 [vendor] MySpace social network [malware] Samy worm (JS/Samy)
Vector: Stored cross-site scripting (XSS) — the worm exploited a flaw in MySpace's profile page rendering that allowed JavaScript injection despite MySpace's attempted input sanitization; the author used CSS style attributes to smuggle JavaScript that MySpace's filters failed to strip

On October 4, 2005, Samy Kamkar released a self-propagating JavaScript worm on MySpace, the then-dominant social network. The worm exploited a stored XSS vulnerability in MySpace …

Other

Zotob Worm — Windows 2000 MS05-039 Exploit (CNN, NYT, DHS Disrupted)

2005-08-13 [vendor] Microsoft Windows 2000 Plug and Play service [malware] Zotob (IRCBot variant) [cve] CVE-2005-1983
Vector: Exploitation of MS05-039 (CVE-2005-1983), a critical buffer overflow vulnerability in the Windows Plug and Play service affecting Windows 2000 systems; the worm propagated automatically via TCP port 445 without requiring user interaction, exploiting unpatched systems within 4 days of the security patch release

The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 security patch for a critical Plug and Play buffer overflow vulnerability in …

Other

Zotob Worm — Windows 2000 Plug and Play Exploit (CNN, NYT, DHS Disrupted)

2005-08-13 [vendor] Microsoft Windows 2000 [malware] Zotob (W32/Zotob, also Tpbot, Esbot, Rbot variants) [cve] CVE-2005-1983
Vector: Remote code execution exploit (MS05-039) against the Windows Plug and Play service on unpatched Windows 2000 systems; the worm appeared within days of Microsoft's August 9, 2005 Patch Tuesday release, exploiting the vulnerability before most organizations could patch

The Zotob worm emerged on August 13, 2005 — just four days after Microsoft released the MS05-039 patch for a critical Plug and Play buffer overflow vulnerability in Windows 2000. …

Data leak

TJX Companies WiFi Wardriving Breach (94M Cards)

2005-07-01
Vector: Albert Gonzalez and ShadowCrew crew 'wardrived' TJX store parking lots with laptop antennas, cracking WEP-encrypted Wi-Fi to access in-store networks, then moved laterally to TJX's central transaction database in Framingham, MA

The TJX breach was the largest retail breach in history at the time of disclosure. Beginning around July 2005, Albert Gonzalez's crew drove through TJX store parking lots with …

Data leak

Paris Hilton T-Mobile Sidekick Hack — Celebrity Address Book and Photos Leaked

2005-02-19 [vendor] T-Mobile Sidekick (Danger Hiptop) cloud service
Vector: Account compromise via knowledge-based authentication bypass — attacker used Paris Hilton's publicly known personal details (dog's name 'Tinkerbell') to correctly answer the T-Mobile Sidekick password reset security question, gaining access to her cloud-synced account data

In February 2005, the contents of Paris Hilton's T-Mobile Sidekick device were stolen and posted on the internet — including her celebrity contact list, personal photos, and SMS …

Credential theft

DSW Designer Shoe Warehouse Payment Card Breach (1.4M Cards, FTC Action)

2005-01-01
Vector: Attackers gained unauthorized access to DSW's store networks through connections with other DSW stores; exploited lack of network segmentation and inadequate access controls to access point-of-sale transaction data stored in network files

DSW (Designer Shoe Warehouse) Inc. disclosed in March 2005 that a data breach had compromised payment card information from 108 of its 175 retail stores across the United States. …

Data leak

DSW Designer Shoe Warehouse Payment Card Breach — 1.4 Million Cards

2005-01-01
Vector: Network intrusion — attackers breached DSW's in-store networks and accessed point-of-sale systems; DSW stored unencrypted payment card data including full magnetic stripe track data in transaction files on store systems, which were accessible via the corporate network

DSW Inc. (Designer Shoe Warehouse), operating approximately 175 shoe retail stores across the United States, disclosed in March 2005 that attackers had accessed its computer …

Other

MyDoom Email Worm (Fastest-Spreading Ever, $38B Damages)

2004-01-26 [vendor] Microsoft Windows [malware] MyDoom (W32/Mydoom, Novarg, Mimail.R)
Vector: Email attachment with social engineering lures (fake mail delivery failure notices, rejected email messages); also spread via Kazaa P2P shared folders; installed a backdoor on TCP port 3127 for spam relay and DDoS

MyDoom, discovered on January 26, 2004, remains the fastest-spreading email worm in recorded history — a record unbroken as of 2026. Within the first 36 hours, MyDoom was …

Data leak

ChoicePoint Social Engineering Fraud (163K Records, Triggered US Breach Notification Laws)

2004-01-01
Vector: Fraudsters posed as legitimate small businesses and used stolen identities to create approximately 50 fake business accounts with ChoicePoint's data brokerage portal; then used those authorized accounts to legally purchase 163,000 consumer credit and identity records

ChoicePoint, one of the largest US data brokers, disclosed in February 2005 that fraudsters had created approximately 50 fake business subscriber accounts using stolen identities …

Data leak

CardSystems Solutions SQL Injection Breach (40M Cards, Company Destruction)

2004-01-01
Vector: SQL injection vulnerability in CardSystems' web application allowed attackers to access the payment processing database; CardSystems violated card network rules by retaining full magnetic stripe track data after transaction authorization

CardSystems Solutions, a payment card processor based in Tucson, Arizona, was breached via SQL injection between approximately January 2004 and May 2005. The attackers accessed …

Other

SQL Slammer Worm (75K Hosts in 10 Minutes, Global Internet Disruption)

2003-01-25 [vendor] Microsoft SQL Server 2000; Microsoft MSDE 2000 [malware] SQL Slammer (W32/SQLSlam, Sapphire) [cve] CVE-2002-0649
Vector: Single-packet UDP buffer overflow (376 bytes total) against Microsoft SQL Server 2000 and MSDE 2000 (MS02-039); patch available 6 months prior; worm fit entirely in one UDP packet and required no TCP handshake, enabling maximum propagation speed

SQL Slammer, also known as Sapphire, is the fastest-spreading computer worm in recorded history. Launched at 05:30 UTC on January 25, 2003, the 376-byte worm doubled the number of …

Data leak

BJ's Wholesale Club Payment Card Breach (FTC Consent Order)

2003-01-01
Vector: POS system compromise — attackers gained unauthorized access to BJ's wireless network and then to in-store point-of-sale systems; BJ's had stored full magnetic stripe track data and CVV2 codes indefinitely on its systems in violation of card network rules, enabling large-scale card counterfeiting

BJ's Wholesale Club, a membership warehouse retailer operating in the eastern United States, suffered a payment card breach that was publicly disclosed in March 2004. Attackers …

Credential theft

BJ's Wholesale Club Payment Card Breach (FTC Consent Order)

2003-01-01
Vector: Attackers gained access to BJ's wireless network and exploited security weaknesses to intercept payment card data; BJ's stored full magnetic stripe data and CVV codes in violation of card network rules, and failed to use encryption on its wireless network

BJ's Wholesale Club, a members-only retail warehouse chain on the US East Coast, suffered payment card data breaches beginning as early as 2003 due to systemic security failures, …

Credential theft

ShadowCrew / Operation Firewall: Underground Carding Forum Takedown (1.7M Cards)

2002-08-01
Vector: Centralized underground internet forum enabling buying, selling, and trading of stolen credit card data, identity documents, and malware tools; supplied by members conducting phishing, skimming, malware deployment, and SQL injection attacks against financial institutions and retailers

ShadowCrew was an underground carding forum operating from August 2002 until its takedown on October 26, 2004 in Operation Firewall — a joint US Secret Service operation involving …

Other

Nimda Multi-Vector Worm (Five Propagation Methods, Most Widespread in 22 Minutes)

2001-09-18 [vendor] Microsoft IIS; Microsoft Outlook; Microsoft Internet Explorer [malware] Nimda (W32/Nimda, 'admin' reversed) [cve] CVE-2001-0333 +1
Vector: Five simultaneous propagation vectors: (1) email attachment exploit; (2) infected IIS web servers serving malicious JavaScript to visitors; (3) open network shares; (4) IIS 4.0/5.0 directory traversal (Unicode/double decode vulnerabilities); (5) backdoors installed by Code Red II

Nimda (released exactly one week after the September 11 attacks) became the most widespread internet virus in history within 22 minutes of release, surpassing Code Red. Its five …

Other

Code Red IIS Buffer Overflow Worm (359K Hosts, $2.6B Damages)

2001-07-13 [vendor] Microsoft IIS (Internet Information Services) [malware] Code Red (W32/CodeRed) [cve] CVE-2001-0500
Vector: Buffer overflow vulnerability in Microsoft IIS 4.0/5.0 Index Server (MS01-033 / CVE-2001-0500); patch available one month prior; worm propagated by scanning random IP addresses and exploiting unpatched IIS servers with no user interaction

Code Red exploited a buffer overflow in the IDQ.DLL component of Microsoft IIS web server software (documented in MS01-033). The worm required no user interaction — it scanned …

Data leak

Gary McKinnon: US Military Network Intrusions (92 Systems, 'Biggest Military Hack')

2001-03-01 [vendor] Microsoft Windows (default blank admin passwords)
Vector: Scanned US military and NASA .mil/.gov domains for Windows machines with blank administrator passwords using a perl script and the RemotelyAnywhere admin tool; exploited default credentials to install backdoors and packet sniffers

Between March 2001 and March 2002, Gary McKinnon — a 36-year-old IT administrator from London, UK, operating under the alias 'Solo' — conducted what the US government called 'the …

Other

ILOVEYOU / Love Bug VBScript Worm (45M Computers, $10–15B Damages)

2000-05-04 [vendor] Microsoft Windows Script Host; Microsoft Outlook [malware] ILOVEYOU (VBS/LoveLetter)
Vector: Email with subject 'ILOVEYOU' and attachment 'LOVE-LETTER-FOR-YOU.TXT.vbs'; VBScript executed automatically via Windows Script Host, overwrote files, propagated via Outlook to entire address book, and downloaded a password-stealing Trojan

On May 4-5, 2000, the ILOVEYOU worm began spreading from the Philippines, where computer science student Onel de Guzman had released it via a stolen internet access account. The …

Credential theft

CD Universe Maxus Credit Card Extortion (300K Cards, First Major Breach Extortion)

1999-12-01
Vector: Attacker (known only as 'Maxus,' believed to be an Eastern European teenager) exploited a vulnerability in CD Universe's payment processing software to access the customer credit card database

In December 1999, an attacker known only as 'Maxus' (believed to be a ~19-year-old Eastern European) exploited a vulnerability in the payment processing systems of CD Universe, an …

Data leak

Jonathan James (c0mrade): NASA and DoD Intrusions — First Juvenile Jailed for Cybercrime

1999-08-01
Vector: Installed backdoor and network sniffer on a DTRA (Defense Threat Reduction Agency) server; intercepted usernames and passwords of DoD employees; also exploited vulnerabilities to access NASA's Marshall Space Flight Center network

Between August and October 1999, Jonathan James — a 15-year-old from Pinecrest, Florida using the handle 'c0mrade' — conducted a series of intrusions against US government systems …

Other

Melissa Virus Email Macro Worm ($80M Damages)

1999-03-26 [vendor] Microsoft Word (macro); Microsoft Outlook [malware] Melissa (W97M/Melissa)
Vector: Word document macro virus emailed as attachment with 'Important Message From [sender]' subject; the VBA macro auto-forwarded itself to the first 50 addresses in the victim's Outlook address book and defaced documents with Simpsons references

On March 26, 1999, David Lee Smith of Aberdeen, New Jersey posted the Melissa macro virus to the alt.sex Usenet newsgroup using a stolen AOL account. The virus was embedded in a …

Data leak

Solar Sunrise: DoD Network Intrusions Initially Mistaken for Iraqi State Attack (1998)

1998-02-01 [vendor] Sun Solaris
Vector: Probe-then-exploit methodology: attackers scanned DoD systems for a known Solaris OS vulnerability, installed sniffers to harvest usernames/passwords, then returned to exfiltrate data — conducted through Israeli academic network as proxy

In February 1998, during the height of the Iraq crisis (US was preparing military action against Iraq over UN weapons inspections), unknown actors began systematically attacking US …

Data leak

Moonlight Maze: Russian State Espionage Against US DoD, NASA, DoE (1996–1999)

1996-10-01
Vector: Russian state-sponsored actors (later linked to Turla APT) compromised US university and research institution computers as proxies, then used them to conduct systematic intrusions against DoD, NASA, DoE, and contractor networks — discovered when an administrator noticed late-night connections from a Cyrillic-keyboard system

Moonlight Maze is one of the first documented nation-state cyber espionage campaigns against the United States. Beginning as early as October 1996 and continuing through at least …

Contribute a Breach

This dataset is open source. Help keep it accurate and up to date by submitting new incidents via GitHub.

1

Pick a category

Each breach lives in one of eight folders: ransomware/, data-leak/, supply-chain/, credential-theft/, ai/, cloud/, cryptocurrency/, or other/.

2

Create a YAML file

Name it YYYY-MM_slug.yaml and fill in the required fields below. Use an existing record as a reference.

3

Open a Pull Request

Submit your file on GitHub. A maintainer will review and merge it, and the site rebuilds automatically.

Full Schema

# ── Core fields (always present) ───────────────────────────────────────────────
source_name: "Publication or organization reporting the breach"
source_url: "https://example.com/direct-link-to-report"
date_of_breach: "YYYY-MM-DD"          # also accepts YYYY-MM or YYYY
date_of_disclosure: "YYYY-MM-DD"      # empty string "" if unknown
category: "ransomware | data-leak | supply-chain | credential-theft | ai | cloud | cryptocurrency | other"
notes: "Narrative summary of the incident including timeline, scope, threat actor attribution, and any known impact."

# ── Traditional breach fields ───────────────────────────────────────────────────
date_of_customer_notification: ""     # YYYY-MM-DD or "" if unknown
initial_attack_vector: "CWE-NNN: Short description, or free-text description of the attack method"
cve: []                               # list of CVE/GHSA IDs, e.g. ["CVE-2024-3094"], empty if none
vendor_product: "Vendor Product Name" # affected vendor or product
software_package: ""                  # package name for software supply chain incidents, "" otherwise
malware: ""                           # malware family name if identified, "" otherwise
supply_chain_claimed: false           # true if a third-party vendor relationship was the attack vector

# ── Crypto / Web3 fields ───────────────────────────────────────────────────────
blockchain: "ethereum"                # blockchain(s) involved, e.g. "ethereum, solana"; omit if not applicable
financial_loss_usd: 0                 # numeric USD value of funds lost; omit if not applicable
financial_recovered_usd: 0           # numeric USD value recovered after the incident; omit if not applicable
affected_count: 0                    # number of affected wallets, users, or individuals; omit if not applicable

# ── AI fields ─────────────────────────────────────────────────────────────────
ai_model_name: ""                    # AI model involved, e.g. "ChatGPT", "Claude", "Gemini"; omit if not applicable
ai_model_provider: ""                # organization behind the model, e.g. "OpenAI", "Anthropic"; omit if not applicable
ai_attack_vector: ""                 # AI-specific attack method, e.g. "prompt injection", "deepfake"; omit if not applicable

# ── Cloud / SaaS fields ──────────────────────────────────────────────────────
cloud_provider: ""                   # cloud provider, e.g. "AWS", "Azure", "GCP", "Snowflake"; omit if not applicable
cloud_shared_responsibility: ""      # "vendor" | "customer" | "shared" | "unknown"
cloud_resource_crit: ""              # CRIT identifier, e.g. "arn:aws:s3:::{bucket}"; omit if not applicable