Supply Chain 768 incidents

Software and hardware supply chain compromise incidents

Snowflake UNC5537 Mass Customer Breach Campaign

2024-04-01 Lumma; Vidar; RedLine; RisePro; Raccoon (infostealers used to harvest credentials)

UNC5537 compromised approximately 165 Snowflake customer tenants in a mass credential-stuffing campaign from April 2024. Known victims include AT&T (110M records), Ticketmaster (560M), Santander, …

Easy Programming Language (EPL) Supply Chain Attack — Taobao, Alipay, Baidu Cloud (2018)

2018-12-01 Credential-stealing trojan targeting Taobao, Alipay, Baidu Cloud, JD.com, NetEase 163, QQ, AliWangWang; ransomware component demanding WeChat Pay payment; signed with certificate stolen from Tencent Technologies

In late November and early December 2018, a sophisticated supply chain attack targeting Chinese internet users emerged, exploiting Easy Programming Language (EPL, also known as EasyLanguage or Yi Yu …

Krebs on Security

2018-06-14

Between June 14 and June 18, 2018, an attacker compromised several Reddit employee accounts at the company's cloud hosting and source code hosting providers by intercepting SMS-based two-factor …

Bleeping Computer

2018-05-30

On May 30, 2018, security researcher Bob Diachenko of Kromtech Security Center discovered an Apache Airflow server belonging to Agilisium, a cloud data contractor for Universal Music Group (UMG), that …

SC Media

2018-04-05

Corporation Service Company (CSC), a major provider of domain registration, corporate compliance, and agent-for-service-of-process services to Fortune 500 companies and other businesses, disclosed …

Bleeping Computer

2018-03-01 POS RAM-scraping malware

Brinker International, the parent company operating over 1,600 Chili's Grill and Bar restaurants worldwide, disclosed a payment card data breach on May 12, 2018, one day after discovering the security …

The Register

2018-01-01

Western Union disclosed in early 2018 that customer information had been accessed without authorization through a computer intrusion targeting an external vendor system formerly used by Western Union …

HIPAA Journal

2017-12-01

Orlando Orthopaedic Center reported a breach of 19,101 patient records caused by an error made by its third-party transcription service provider during a software upgrade in December 2017. The vendor …

Threatpost

2017-11-23 POS RAM-scraping malware

RMH Franchise Holdings, one of the largest Applebee's franchise operators in the United States, discovered malware on point-of-sale systems at its restaurants on February 13, 2018, and publicly …

StateScoop / Dark Reading / Gemini Advisory

2017-10-01 SJavaWebManage web shell CVE-2017-3248, CVE-2017-3506, CVE-2017-10271

Between late 2017 and late 2018, at least 46 US cities were compromised through vulnerabilities in Click2Gov, a self-service bill payment portal used by municipalities for utility payments, parking …

CNN Business

2017-09-27

Between September 27 and October 12, 2017, an unauthorized third party gained access to [24]7.ai's online customer service chat platform and injected malicious code designed to capture payment card …

RiskIQ / Threatpost / ICO

2017-09-01 Magecart JavaScript card skimmer

In June 2018, Ticketmaster disclosed that malicious code had been found within a customer support chatbot function on its websites, hosted by third-party AI company Inbenta Technologies. The Magecart …

Wikipedia

2017-06-27 NotPetya (Petya variant / wiper disguised as ransomware) CVE-2017-0144, CVE-2017-0145

On June 27, 2017, the NotPetya cyberattack struck, becoming one of the most destructive and costly cyberattacks in history with estimated global damages exceeding $10 billion. The attack was …

UpGuard

2017-06-01

On June 12, 2017, UpGuard cyber risk analyst Chris Vickery discovered a publicly accessible Amazon S3 cloud storage bucket containing approximately 1.1 terabytes of data on 198 million American …

CSO Online

2017-05-13 CVE-2017-5638

Between May 13 and July 30, 2017, attackers exploited a critical remote code execution vulnerability in Apache Struts (CVE-2017-5638) to breach Equifax, one of the three major US consumer credit …

Healthcare IT News

2016-12-22

On December 22, 2016, an unauthorized individual gained access to electronic files stored on computer systems maintained by a third-party vendor that provided patient management software applications …

HIPAA Journal

2016-08-28

Between August 28, 2016, and January 14, 2017, the Diamond Institute for Infertility and Menopause, a fertility clinic based in Millburn, New Jersey, suffered repeated unauthorized access to its …

NBC News

2014-01-01

On May 3, 2017, security researcher Bob Diachenko of the Kromtech Security Research Center discovered a massive trove of patient records from Bronx-Lebanon Hospital Center in New York City exposed on …