CuraSec

tag: Data-Breach · 43 items

2026-09-02 · Krebs on Security · source ↗ #data-breach#identity-theft#vendor-risk
  • Engineer — Plan: If your platform uses a third-party identity verification or KYC service — particularly one based in Louisiana — audit that integration and check whether user-submitted ID scans are in scope; no patch action applies, but vendor contract and data-handling review is warranted this quarter.
  • SOC/IR — Learn: 153M+ stolen driver’s licenses will likely fuel account-takeover and synthetic-identity fraud campaigns; no IOCs or TTPs are published yet, but flag for future hunting context once the affected vendor is named publicly.
  • Leader — Act: Confirm this week whether your organization uses the implicated Louisiana-based identity verification vendor and request an incident attestation; the scale of this exposure is likely to generate customer and board questions before the week is out.
2026-09-02 · BleepingComputer · source ↗ #data-breach#healthcare#vendor-risk
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Plan: A 9.5-million-patient breach at a healthcare services company is sector-level news; audit your vendor inventory for any Aesto Health dependency, confirm HIPAA BAA status, and assess whether downstream data exposure requires notification review.
2026-09-01 · BleepingComputer · source ↗ #data-breach#healthcare#patient-data
  • Engineer — Skip
  • SOC/IR — Learn: Healthcare sector breach with limited technical detail; no IOCs, TTPs, or detection artifacts published — monitor for follow-on disclosure with actionable indicators.
  • Leader — Learn: A healthcare cyberattack exposing patient PII is a sector-relevant signal; if Novocure is a vendor or partner, confirm exposure and review their incident communications, but at 1,400 affected this is unlikely to be board-level.
2026-08-30 · BleepingComputer · source ↗ #data-breach#ransomware#travel-sector
  • Engineer — Skip
  • SOC/IR — Learn: Actor profile worth logging: FulcrumSec targets travel/transport sector and appears to exfiltrate before disclosure; no IOCs or TTPs published to act on yet.
  • Leader — Act: If your organisation uses MAG airports or shares traveller data with them, request a formal incident report and assess whether your customers’ data is in scope for notification obligations.
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs or TTPs published; monitor for follow-on phishing lures targeting Hasbro employees that could appear in broader campaigns.
  • Leader — Plan: Review whether your organization has vendor or partner relationships with Hasbro that involve shared employee or financial data; add to third-party breach tracker and revisit data-sharing agreements.
2026-08-27 · BleepingComputer · source ↗ #data-breach#shinyhunters#retail
  • Engineer — Skip
  • SOC/IR — Learn: ShinyHunters continues active extortion operations; no IOCs or TTPs published from this incident to act on, but useful for tracking the group’s targeting patterns.
  • Leader — Act: If Carhartt is a vendor or employee-benefits partner, request their incident report and confirm scope of data shared; separately, brief leadership given the scale (12.9M accounts) in case customers or press ask.
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A UK airport operator breach involving Wi-Fi registration data is a useful prompt to review what data third-party venue services collect on behalf of employees, but no immediate action is warranted for most non-UK enterprises given the regional scope and absence of published IOCs or attack detail.
2026-08-26 · BleepingComputer · source ↗ #healthcare#data-breach#incident
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A healthcare-sector peer breach involving exfiltrated data from hospital systems — useful context for board briefings on sector risk and a prompt to verify any Nutex Health service or data-sharing relationships your organization holds.
2026-08-26 · BleepingComputer · source ↗ #data-breach#breach-notification#pii
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A delayed disclosure involving SSNs and medical records is a useful benchmark for breach notification timelines and data-type risk classification, though no vendor exposure or systemic risk is indicated for enterprise security programs.
2026-08-21 · BleepingComputer · source ↗ #data-breach#third-party-risk#healthcare
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A third-party software flaw exposed HR-category data (employee and applicant records) at a major hospital with no patient-record impact — a useful reference case for vendor risk assessments covering HR/recruiting platforms, particularly in healthcare.
2026-08-20 · BleepingComputer · source ↗ #data-breach#cloud-provider#vendor-risk
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Act: If your organization uses Sakura Internet for cloud or data center services, confirm whether your account data was affected and request an incident report from the vendor this week.
2026-08-20 · BleepingComputer · source ↗ #data-breach#healthcare#hipaa
  • Engineer — Skip
  • SOC/IR — Learn: Large-scale healthcare breach worth noting for sector awareness, but no IOCs, TTPs, or detection surface are provided in this disclosure.
  • Leader — Act: If CareCloud is a vendor in your ecosystem, request their incident report and assess PHI exposure; healthcare CISOs should also brief leadership given HIPAA breach notification obligations and potential board or customer questions at this scale.
2026-08-18 · BleepingComputer · source ↗ #third-party-breach#logistics#data-breach
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A logistics vendor breach affecting Pokémon Center customers in UK and Germany illustrates supply-chain data exposure risk; useful as a reference case if your organization relies on CEVA Logistics or similar third-party fulfillment providers for customer data handling.
2026-08-18 · BleepingComputer · source ↗ #azure#credential-theft#data-breach
  • Engineer — Plan: The alleged vector is compromised credentials, not a platform vulnerability — audit Azure Entra ID sign-in logs for anomalous authentication, verify MFA is enforced on all accounts, and review conditional access policies for gaps.
  • SOC/IR — Plan: No IOCs or confirmed TTPs are available yet, but if your estate includes Azure, queue a hunt for unusual authentication patterns in Entra ID logs (off-hours logins, new service principals, bulk data exports) and monitor breach-data feeds for your org’s domains.
  • Leader — Act: If Azure is in your estate, contact your Microsoft account team this week to ask whether your tenant appears in this claimed dataset, and prepare a brief for leadership in case the story gains traction or your company is named.
2026-08-17 · BleepingComputer · source ↗ #data-breach#cryptocurrency#customer-data
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: Small-scale breach at a consumer crypto hardware wallet vendor with no enrichment signals; relevant only if the organization has SafePal as a vendor or employees use it for corporate crypto assets — confirm exposure if in fintech or crypto sectors.
2026-08-17 · BleepingComputer · source ↗ #ransomware#data-breach#supply-chain
  • Engineer — Skip
  • SOC/IR — Learn: Clop’s data theft methodology (exfiltration without full encryption) is worth tracking; no IOCs or TTPs published yet to act on.
  • Leader — Act: If your organization uses GE or Philips products or services, contact vendor account reps this week to request breach scope confirmation and any applicable incident attestations; prepare a brief for leadership given Clop’s history of public data releases.
2026-08-17 · BleepingComputer · source ↗ #data-breach#government#pii
  • Engineer — Skip
  • SOC/IR — Learn: Government financial authority breach with no published IOCs or TTPs; monitor for follow-on phishing campaigns using stolen French taxpayer data but no actionable detection surface yet.
  • Leader — Learn: Large-scale government PII breach in the EU; useful context for board discussions on public-sector breach risk and GDPR notification timelines, but no direct vendor or operational exposure for a US/global enterprise.
2026-08-15 · BleepingComputer · source ↗ #ransomware#data-breach#clop
  • Engineer — Skip
  • SOC/IR — Learn: Clop continues targeting large enterprises via data theft extortion; no IOCs or TTPs published yet — monitor for technical follow-up reports to inform detection tuning against Clop’s known access patterns.
  • Leader — Act: If Shell is a vendor or partner, request their incident status and any attestation of scope this week; even without confirmed breach, brief leadership before this surfaces in board or customer questions.
2026-08-14 · BleepingComputer · source ↗ #data-breach#vendor-risk#supply-chain
  • Engineer — Skip
  • SOC/IR — Learn: Third-party logistics provider compromise exposing customer data is a useful reminder that vendor integrations extend the attack surface; no IOCs or TTPs published to act on.
  • Leader — Plan: Review whether any logistics or fulfillment vendors your organization uses have similar access to customer PII, and verify contractual breach-notification obligations with those third parties.
2026-08-14 · BleepingComputer · source ↗ #data-breach#third-party-risk#saas
  • Engineer — Skip
  • SOC/IR — Learn: ShinyHunters claimed this breach in July; no IOCs or TTPs published yet, so no detection action is possible — file for actor-tracking context.
  • Leader — Act: If RingCentral is in your vendor stack, confirm scope with your account rep, request their incident report, and assess whether affected data triggers customer or regulatory notification obligations.
2026-08-12 · BleepingComputer · source ↗ #data-breach#ransomware#supply-chain
  • Engineer — Skip
  • SOC/IR — Learn: ExfilSquad is an active extortion actor worth tracking; no IOCs or TTPs are publicly available yet to act on, but monitor for follow-on disclosures with actionable detection detail.
  • Leader — Act: If Wesco is a vendor or supplier in your ecosystem, contact them now for an incident scope statement and assess whether shared data or integrations are at risk; brief leadership before this surfaces in broader news.
2026-08-10 · BleepingComputer · source ↗ #data-breach#supply-chain#vendor-risk
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Plan: Review whether CEVA Logistics or similar third-party logistics/shipping vendors handle personal data on behalf of your organization; add logistics vendor data handling to your vendor risk review cycle.
2026-08-09 · BleepingComputer · source ↗ #data-breach#healthcare#third-party-risk
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs or TTPs published; breach occurred in October 2025 with delayed disclosure — useful context on healthcare software supply-chain exposure but no detection action available.
  • Leader — Act: If your organization uses Unlimited Technology Systems or any of their healthcare software products, confirm exposure this week and request an incident report; the 3.8M-record scale and healthcare data sensitivity may trigger notification obligations or customer questions.
2026-08-09 · BleepingComputer · source ↗ #sql-injection#zero-day#data-breach
  • Engineer — Act: Metabase is widely deployed for BI/analytics and this SQLi is confirmed exploited with no patch available at attack time; if you run Metabase, isolate the instance, apply any available patch or vendor mitigation immediately, and audit logs for signs of unauthorized data access.
  • SOC/IR — Act: Active zero-day exploitation with confirmed data theft against named organizations warrants an immediate assume-breach sweep on any Metabase instances in your estate; hunt for anomalous outbound data transfers and unusual SQL query patterns originating from Metabase since the earliest known attack date.
  • Leader — Act: Named companies (Framework and Tally) have had customer data stolen via this zero-day; confirm whether your organization or key SaaS vendors run Metabase and request attestations, and prepare a brief for leadership in case customers surface questions about exposure.
2026-08-09 · BleepingComputer · source ↗ #social-engineering#data-breach#corporate
  • Engineer — Learn: No specific software vulnerability or patch action here; the attack vector was employee social engineering leading to data exfiltration from endpoints, which reinforces the value of endpoint DLP and least-privilege data access controls but requires no immediate technical change.
  • SOC/IR — Learn: A real-world social engineering campaign that reached corporate data on employee machines, but the summary surfaces no IOCs, ATT&CK TTPs, or detection signatures to act on today.
  • Leader — Learn: A named-brand breach via targeted employee social engineering is a useful reference for board discussions on human-layer risk and awareness program investment, but Levi’s is not a common enterprise IT vendor, so no vendor-exposure check is warranted.
2026-08-07 · Krebs on Security · source ↗ #data-breach#cloud-security#threat-actor
  • Engineer — Learn: The 2024 Snowflake credential-stuffing campaign is legally concluded with no new technical disclosures; reinforces that MFA enforcement on cloud data warehouses is non-negotiable, but no immediate action is required if controls were hardened after the original incident.
  • SOC/IR — Learn: The guilty plea closes attribution on a major 2024 campaign but surfaces no new IOCs, TTPs, or detection opportunities; useful for building institutional knowledge about the attacker’s methods (credential reuse at scale against SaaS platforms).
  • Leader — Learn: A high-profile case closure illustrating the scale of SaaS vendor risk when MFA is absent; valuable reference for board-level narratives on third-party cloud risk and regulatory exposure tied to customer data held by a vendor.
  • Engineer — Skip
  • SOC/IR — Learn: The guilty plea closes the loop on a major credential-based cloud breach campaign; review whether your org’s Snowflake tenant MFA and network policies would have detected or blocked the access patterns used in 2024.
  • Leader — Learn: A high-profile conviction in a breach affecting 100M people and 165 orgs is useful context for board discussions on cloud vendor risk and credential-based attack exposure; no immediate action required unless your org was among those affected.
  • Engineer — Learn: The guilty plea closes the legal chapter on a credential-stuffing campaign that bypassed MFA-less Snowflake accounts; no new vulnerability or patch, but reinforces ensuring MFA and session token controls are enforced on all cloud data warehouse accounts.
  • SOC/IR — Skip
  • Leader — Learn: The case confirms 165 organizations were breached through stolen credentials at a single cloud provider, a useful data point for board-level discussions on cloud vendor risk and MFA mandates — no immediate action required given the incident predates this plea.
2026-08-04 · BleepingComputer · source ↗ #data-breach#law-enforcement#threat-actor
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A large-scale personnel-data breach at a UK criminal justice database is a useful benchmark for board discussions on insider/third-party data exposure risk, but requires no direct action for US/global enterprise leaders without PNLD dependencies.
2026-07-28 · BleepingComputer · source ↗ #supply-chain#data-breach#extortion
  • Engineer — Learn: Supply-chain credential theft at a major professional services firm is a relevant attack pattern, but no specific compromised component, IOCs, or affected systems have been identified yet — nothing to patch or audit without further detail.
  • SOC/IR — Learn: ShinyHunters remains an active extortion actor using supply-chain pivots; no IOCs or TTPs are published in this disclosure, so no hunt can be launched today — watch for follow-on reporting with technical indicators.
  • Leader — Act: E&Y provides audit, tax, and advisory services to a large share of enterprises, meaning your firm’s confidential data may be in scope; contact your E&Y relationship manager this week to confirm exposure and request a formal incident attestation before customers or auditors ask first.
2026-07-28 · BleepingComputer · source ↗ #data-breach#healthcare#third-party-risk
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs or TTPs published; this breach offers no immediate detection surface, but it reinforces the pattern of healthcare billing vendors as high-value targets worth monitoring for sector-specific threat campaigns.
  • Leader — Act: If your organization uses MCBS or similar third-party medical billing vendors, confirm whether you are among the 1.26M affected and request an incident attestation letter; this breach carries HIPAA notification obligations and may prompt patient or board inquiries.
2026-07-28 · BleepingComputer · source ↗ #ransomware#data-breach#supply-chain
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs or TTPs published yet; monitor for follow-on reporting with technical indicators before building detections.
  • Leader — Act: A named breach at a major consumer brand subsidiary is likely to prompt board or customer questions — brief leadership now and verify whether your organization shares any vendor or data relationship with Fairlife or its parent.
2026-07-26 · BleepingComputer · source ↗ #sextortion#data-breach#shinyhunters
  • Engineer — Skip
  • SOC/IR — Learn: ShinyHunters-leaked emails are now being used as lures in sextortion campaigns; no novel TTPs or IOCs are provided, but awareness helps triage any related user-reported phishing tickets.
  • Leader — Learn: If your organization’s user emails were exposed in ShinyHunters breaches, employees may receive these extortion emails; brief HR and helpdesk on the campaign so they can field employee reports without escalating to a formal incident.
2026-07-25 · BleepingComputer · source ↗ #data-breach#third-party-risk#pii
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs or TTPs disclosed; breach at a logistics vendor with no actionable detection surface for enterprise defenders at this time.
  • Leader — Act: If OnTrac is in your vendor portfolio or used by employees for business shipments, confirm exposure scope and request an incident report from OnTrac this week before customer or leadership questions surface.
2026-07-25 · BleepingComputer · source ↗ #credential-stuffing#data-breach#consumer
  • Engineer — Learn: Credential stuffing via website and mobile app is a recurring pattern; use this as a prompt to review your own bot mitigation, rate limiting, and breached-password detection controls.
  • SOC/IR — Skip
  • Leader — Learn: Small-scale breach at a consumer brand with no enterprise vendor or supply-chain relevance; useful as a credential-stuffing benchmark example but requires no immediate action.
2026-07-23 · BleepingComputer · source ↗ #data-breach#fintech#financial-fraud
  • Engineer — Learn: Breach post-mortem showing how stolen data is monetized through downstream fraud at scale, but no technical attack details or vulnerability specifics are disclosed to act on.
  • SOC/IR — Skip
  • Leader — Learn: A concrete example of stolen data translating directly into quantifiable financial loss ($13M), useful for illustrating data-breach business risk in board or audit conversations.
2026-07-23 · BleepingComputer · source ↗ #data-breach#government#espionage
  • Engineer — Skip
  • SOC/IR — Learn: A ten-month undetected compromise of a government education portal is a useful dwell-time reference case; no IOCs or TTPs are published, so no immediate detection action is possible.
  • Leader — Learn: Illustrates risk of extended dwell time in auxiliary systems (online education portals) that hold sensitive personnel data — useful framing for third-party and non-core-system risk reviews.
2026-07-22 · BleepingComputer · source ↗ #credential-stuffing#data-breach#consumer
  • Engineer — Learn: No novel technique here, but a useful reminder to audit your own login endpoints for rate-limiting, MFA enforcement, and anomalous login velocity detection if you operate a consumer-facing auth surface.
  • SOC/IR — Learn: Credential stuffing campaigns often recycle breach corpuses across targets; consider whether your org’s consumer-facing portals show similar login anomaly patterns worth hunting.
  • Leader — Plan: If your company operates consumer accounts or a loyalty program, benchmark your credential stuffing controls (rate limiting, MFA, breach-password screening) against this incident before a similar disclosure lands on your desk.
2026-07-22 · BleepingComputer · source ↗ #ransomware#data-breach#threat-actor
  • Engineer — Skip
  • SOC/IR — Learn: Anubis ransomware group is expanding its public extortion activity against recognizable brands; no IOCs or TTPs released yet, so track the actor for future intel but no hunt work is actionable now.
  • Leader — Learn: A named ransomware attack on a major consumer brand with threatened data publication is useful context for board conversations about ransomware risk, but no same-week action is warranted unless your organization has a direct vendor relationship with Fairlife.
2026-07-21 · BleepingComputer · source ↗ #oracle-ebs#data-breach#erp
  • Engineer — Plan: If your org runs Oracle E-Business Suite (especially for HR), review Oracle’s recent security advisories for EBS patches and audit privileged access to HR data — no specific CVE or PoC is published yet, so active exploitation pressure is unclear.
  • SOC/IR — Learn: High-profile ERP-targeting breach with no published IOCs, TTPs, or attacker attribution to act on; file for context that Oracle EBS HR modules are being targeted, but there’s no detection work to do today.
  • Leader — Act: If your organization uses Oracle E-Business Suite, direct your team this week to confirm patch status and assess whether employee or customer PII is exposed via the same flaw; this breach will prompt customer and board questions if you operate in consumer goods or retail.
  • Engineer — Skip
  • SOC/IR — Learn: The breach originated through a third-party support ticketing system, illustrating a lateral entry path worth reviewing in your own vendor-managed tool integrations — no IOCs or TTPs published to act on yet.
  • Leader — Act: If EY is a vendor or auditor your organization uses, confirm whether your data was in scope and request EY’s incident report; brief leadership now, before this becomes a customer or auditor question.
2026-07-17 · BleepingComputer · source ↗ #data-breach#settlement#third-party-risk
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A genetic-data breach resulting in an $18M multistate AG settlement illustrates the regulatory and financial exposure from third-party vendors handling sensitive biometric/health data — useful context for vendor risk assessments and board-level privacy risk discussions.
2026-07-14 · BleepingComputer · source ↗ #third-party-risk#data-breach#supply-chain
  • Engineer — Skip
  • SOC/IR — Skip
  • Leader — Learn: A named retailer’s breach traced to an unnamed service provider is a clean case study for third-party risk reviews; no specific vendor is identified in reporting, so no immediate exposure check is actionable, but it reinforces the value of contractual breach-notification SLAs with SaaS and logistics vendors.