Healthcare equipment provider AdaptHealth confirmed that attackers stole patient health data and passwords in a data breach. The company disclosed that sensitive personal and medical information was compromised, affecting patients who use its home medical equipment and supplies.
#data-breach
30 items
The US government confirmed it suffered another cyberattack, marking a recurring breach of federal systems. Officials acknowledged the incident but did not immediately disclose the extent of the damage or which agencies were affected. The attack follows a pattern of high-profile intrusions targeting government networks.
Over 900 internet-exposed Oracle E-Business Suite instances are being actively targeted in ongoing attacks. The attacks exploit vulnerabilities, including CVE-2022-21587 and a newly discovered one, to steal data or deploy malware. Organizations are urged to patch affected systems immediately.
Hackers gained access to Madison Square Garden's systems, compromising data and highlighting security vulnerabilities at the iconic New York venue. The breach exposed sensitive information, raising concerns about cybersecurity measures in major entertainment and sports facilities.
Insurance company Aflac disclosed a data breach after hackers compromised a subsidiary's system. The breach exposed personal information of some individuals, though Aflac stated its core systems were not affected and the incident was contained.
A ransomware group breached Tata Electronics, an Apple supplier in India, leaking documents with component lists, supplier details, and photos of the unreleased iPhone 18 Pro on the dark web. The data exposes Apple's supply chain structure and supplier dependencies.
Nissan has reported that a breach of its Oracle PeopleSoft system may have exposed payroll records and Social Security numbers of its employees. The carmaker disclosed the incident, which involved unauthorized access, and stated that investigations are ongoing to determine the full scope of the data spill.
A data breach has compromised up to 14.2 million email login credentials from six internet service providers, exposing email addresses and passwords that were stored in plain text. The affected ISPs include several smaller providers, and the leaked data poses a significant risk for credential stuffing and account takeover attacks.
A database containing approximately one million passport records from 18 countries was leaked online. The exposed data includes passport images, nationalities, and personal details such as full names and dates of birth, raising significant cybersecurity and privacy concerns.
PuffPal, an app used by Spanish cannabis clubs for age verification, leaked over one million users' passport photos and personal data due to weak security. A researcher found hardcoded API keys and publicly accessible image URLs. The breach exposed celebrities and international visitors, highlighting risks of using high-value credentials in low-security systems.
Over one million passport images were leaked online after a major travel document processing company suffered a data breach. The exposed data includes high-resolution scans of passport photos and personal information, raising significant concerns about identity theft and fraud. Security experts warn that the leaked documents could be used for sophisticated impersonation and financial crimes.
A security incident at LastPass resulted in another data breach affecting its users. The breach involved unauthorized access to user data, marking a recurring issue for the password management service. The article details the ongoing security concerns for LastPass customers.
The article announces the publication of real-time metrics on multiple security threat categories, including exposed databases, leaked credentials, exposed AI keys, known exploited vulnerabilities (KEV) exposures, and subdomain takeovers. The data is continuously updated based on the publisher's scanning infrastructure.
A report claims that Russian hackers were responsible for a $2.5 billion hack targeting Jaguar Land Rover, marking one of the largest cyberattacks in the automotive industry. The breach reportedly involved ransomware and significant data exfiltration, causing major operational disruption for the carmaker.
Mercor reported a July 27, 2024 security incident where an unauthorized party accessed an employee's computer, potentially copying personal information. The company says production systems, the AI assessment platform, and candidate database were unaffected. Additional security measures have been implemented.
Staff at Cambridge University Hospitals NHS Foundation Trust are under investigation for allegedly accessing the medical records of a young boy who was injured after falling into a crocodile pit at a wildlife park in Australia. The trust has launched a formal inquiry into the unauthorized access of confidential patient data by multiple employees.
LastPass has notified users of another data breach, exposing encrypted vault data including URLs, usernames, and passwords. The company states that master passwords were not compromised, but advises users to remain vigilant against potential phishing attacks and to update their credentials.
Hackers leaked data from Madison Square Garden and the New York Knicks online, including internal documents and employee information. The breach, claimed by a group targeting the entertainment and sports sectors, exposed sensitive company files. The compromised data was published on a hacking forum.
Leaked internal chats from 4vps.su reveal a culture of political indifference, where administrators and users avoid taking sides in geopolitical conflicts, prioritizing operational continuity and profit over political stances.
LastPass has confirmed a data breach after a hacker compromised its supply chain, gaining access to customer data through a developer's compromised device. The breach involved encrypted vaults, but the company stated that master passwords and customer accounts were not affected. The incident highlights ongoing security vulnerabilities in the password manager's infrastructure.
LastPass confirmed a data breach after a supply chain attack targeting its workforce management tool, Klue, exposed customer metadata including usernames and billing addresses. The breach occurred through a compromised third-party vendor, with no evidence of encrypted vault data being accessed. LastPass has since rotated credentials and enhanced security measures.
Hackers have leaked data online belonging to the New York Knicks and Madison Square Garden, including internal documents and customer information. The breach exposed sensitive records from the sports and entertainment organization, raising concerns over data security and privacy.
Meta accidentally exposed data from its controversial employee-tracking program, allowing employees to access each other's keystroke data. The internal data leak occurred due to a misconfiguration, raising concerns about privacy and the company's monitoring practices.
A report details "search your target" (SYT) services, a market where cybercriminals pay to search stolen credential databases for specific targets. These services aggregate data from multiple breaches, enabling buyers to find compromised accounts for individuals or organizations.
The Texas Parks and Wildlife Department (TPWD) announced a data security incident that may have exposed certain personal information. The agency is notifying affected individuals and providing steps to protect their information. An investigation is ongoing to address the breach and enhance security measures.
A leaked GitHub token exposed Novo Nordisk's proprietary Ozempic formula, with cybersecurity firm FulcrumSec disclosing that the breach occurred in 2026 and could have severe competitive and financial consequences for the pharmaceutical company.
Weil, Gotshal & Manges reportedly paid up to $20 million to hackers who stole client data. The ransom payment, one of the largest known for a law firm cyberattack, came after the hackers exfiltrated sensitive client information. The incident highlights escalating cybersecurity risks facing major law firms.
A data breach at Texas Parks and Wildlife Department's vendor exposed personal information of more than 3 million hunters and anglers who purchased licenses online. The compromised data includes names, birth dates, driver's license numbers, partial Social Security numbers, and payment details, prompting the state to urge affected individuals to monitor for fraud.
The Adama City government in Ethiopia exposed a 29 GB database containing sensitive personal information of its citizens, including full names, phone numbers, ID numbers, and financial records. The data breach, discovered by security researchers, involved an unsecured database accessible without authentication, potentially putting thousands of residents at risk of identity theft and fraud.
A major mobile carrier was found storing sensitive customer PII, including names, addresses, and call logs, in plaintext in a database accessible with only sudo-level credentials. The security lapse exposed personal data without encryption or adequate access controls.