Breaches: Page


  • A logo sits illuminated outside the Microsoft pavilion on the opening day of the World Mobile Congress at the Fira Gran Via Complex on February 22, 2016 in Barcelona, Spain.
    Image attribution tooltip
    David Ramos via Getty Images
    Image attribution tooltip

    Microsoft hardens key issuance systems after state-backed hackers breach Outlook accounts

    The China-linked group, which Microsoft calls Storm-1558, has adopted new techniques after it took steps to disrupt their recent hacking activity.

    By July 17, 2023
  • 3D digital circular dynamic wave.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip
    Deep Dive

    MOVEit mass exploit timeline: How the file-transfer service attacks entangled victims

    The slow-moving disaster has ensnared some of the world's largest enterprises. Cybersecurity experts expect further damage to come.

    By July 14, 2023
  • Trendline

    Managing and securing identity sprawl

    Cyber threat actors know the simplest way to hack into an enterprise and remain under the radar is with stolen, legitimate user credentials -- and AI is making managing and securing digital identities more challenging than ever.

    By Cybersecurity Dive staff
  • Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol. 3d rendering.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Johns Hopkins hit with class action suit following MOVEit data breach

    The suit alleges that the health system failed to implement safeguards to secure patients’ health information and provided insufficient details about the stolen data.

    By Sydney Halleman • July 12, 2023
  • Petro-Canada has more than 1,500 retail locations across the nation of Canada.
    Image attribution tooltip
    Courtesy of Suncor
    Image attribution tooltip

    Suncor Energy confirms hackers breached Petro-Canada gas stations’ customer rewards data

    The company, the largest integrated energy firm in Canada, said field operations were not impacted.

    By July 6, 2023
  • Rendered image depicting global networks.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MOVEit vulnerability snags almost 200 victims, more expected

    The education sector has been hit particularly hard as many widely used vendors in the space confirm impacts linked to the mass exploited vulnerability.

    By July 5, 2023
  • American Airlines and Southwest Airlines jets on the runway at Los Angeles International Airport.
    Image attribution tooltip
    David McNew/Getty via Getty Images
    Image attribution tooltip

    Cyberattack exposes data on nearly 9K American and Southwest Airlines pilot applicants

    Two of the world’s largest airlines no longer use recruitment portal Pilot Credentials after a cyberattack at the end of April.

    By June 27, 2023
  • Smiling businesswoman in headphones taking notes, working with laptop and talking smartphone, blue glowing information protection icons. Padlock, cloud and digital interface. Cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    MOVEit vulnerability ensnares more victims

    Some organizations have been impacted due to their direct use of MOVEit while others have been exposed by third-party vendors.

    By June 27, 2023
  • PwC logo outside of London, England
    Image attribution tooltip
    Jack Taylor via Getty Images
    Image attribution tooltip

    Big names disclose MOVEit-related breaches, including PwC, EY and Genworth Financial

    More than 100 organizations have been hit as part of the MOVEit attack campaign, including PBI Research Services, which exposed millions of customer data files to theft. 

    By June 23, 2023
  • Dole, produce
    Image attribution tooltip
    Retrieved from Dole.
    Image attribution tooltip

    Dole says February ransomware attack breached data of almost 3,900 US workers

    The fresh produce giant disclosed the data security impact in a filing with the Maine Attorney General.

    By June 22, 2023
  • Gavel sitting on paper saying class action suit
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Progress Software faces federal class action lawsuits as MOVEit breach exposure widens

    Louisiana residents allege their personal financial information was put at risk after the state's motor vehicles department had data exposed in the MOVEit data breach. 

    By June 21, 2023
  • An aerial view of Washington, D.C. that includes the Washington Monument.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    US puts $10M bounty on Clop as federal agencies confirm data compromises

    Additional private sector companies have disclosed attacks after multiple vulnerabilities were found in MOVEit Transfer software.

    By June 20, 2023
  • The U.S. Capitol Building at night with lightning in the background.
    Image attribution tooltip
    Naomi Eide/Cybersecurity Dive
    Image attribution tooltip

    Another MOVEit vulnerability found, as state and federal agencies reveal breaches

    The third vulnerability since Progress Software first disclosed a MOVEit Transfer zero day arrived just as CISA officials said a “small number” of federal agencies were impacted. 

    By Naomi Eide • June 16, 2023
  • The red lock and its structure explode in a digital computer setting.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Clop names a dozen MOVEit victims, but holds back details

    As its deadline expired, the ransomware group released the first batch of victim organizations, most of which were U.S.-based, ReliaQuest found.

    By Naomi Eide • June 15, 2023
  • City skyline in background, snowy highways in foreground
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Minnesota Department of Education exposed in MOVEit data breach

    The departments discovered on May 31 that 24 of its files on the MOVEit server had been accessed by an outside entity, including 95,000 student names in foster care across the state.

    By Anna Merod • June 14, 2023
  • sand dunes on the florida coast
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Ahead of summer holiday weekends, IT security leaders brace for deliberate cyber mischief

    Recent history shows holiday weekends and vacations provide an attack surface bonanza for threat actors.

    By May 26, 2023
  • close up programmer man hand typing on keyboard laptop for register data system or access password at dark operation room , cyber security concept - stock photo
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    CISA updates ransomware guide 3 years after its debut

    The #StopRansomware guide, updated in partnership with the FBI, NSA and MS-ISAC, reflects aggressive new techniques used by threat actors, including double extortion.

    By May 24, 2023
  • Taco Bell exterior
    Image attribution tooltip
    Courtesy of Taco Bell
    Image attribution tooltip

    Yum Brands faces class action suits from employees after ransomware attack

    The Taco Bell and KFC operator is facing litigation after some personal data of company employees was stolen in the attack.

    By May 16, 2023
  • A group of people in shadow in front of a glowing square with a sign for Western Digital
    Image attribution tooltip
    Ian Tuttle / Stringer via Getty Images
    Image attribution tooltip

    Western Digital cyberattack not expected to have material impact on future earnings

    The company is coordinating with law enforcement while it continues a forensic investigation. 

    By May 15, 2023
  • Futuristic electronic semiconductor and telecommunication network concept
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Dragos says it thwarted extortion bid by known ransomware threat group

    The hackers accessed limited information by impersonating a new employee, and the cybersecurity firm warns some stolen data may be leaked.

    By May 11, 2023
  • Western Digital and Wired host "A Data-Driven Future: The Future of Mobility and Transportation in 2039."
    Image attribution tooltip
    Ian Tuttle via Getty Images
    Image attribution tooltip

    Western Digital confirms customer data accessed by hackers in attack

    The company has begun notifying customers about stolen data and expects to restore its online store next week.

    By May 8, 2023
  • Man using facial recognition technology on city street
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Google, Dashlane separately move to eliminate passwords

    In unrelated moves, the companies highlighted a growing effort to phase out dependence on passwords amid a rise in phishing attacks.

    By May 4, 2023
  • Abstract planet made up of squares.
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    3CX threat actor named as company focuses on security upgrades, customer retention

    Mandiant attributed the supply chain attack to a North Korea-linked adversary that targeted systems using Windows-based malware.

    By April 12, 2023
  • Western Digital and Wired host "A Data-Driven Future: The Future of Mobility and Transportation in 2039."
    Image attribution tooltip
    Ian Tuttle via Getty Images
    Image attribution tooltip

    Western Digital restores local access to My Cloud Home customers following security breach

    The data storage company has provided limited updates to customers after disclosing the initial incident.

    By April 11, 2023
  • A Samsung flag flies outside the Samsung office on August 25, 2017 in Seoul, South Korea.
    Image attribution tooltip
    Chung Sung-Jun via Getty Images
    Image attribution tooltip

    Samsung employees leaked corporate data in ChatGPT: report

    Data privacy is a concern for companies with employees using ChatGPT’s web-based interface, as input data is used to train and improve the tool.

    By Lindsey Wilkinson • April 10, 2023
  • Employee in front of a laptop
    Image attribution tooltip
    Getty Images
    Image attribution tooltip

    Broad MFA, rapid patching a must to stop cyberattacks, Marsh McLennan finds

    A study says organizations need to implement automated hardening techniques to protect systems against future data breaches. 

    By April 6, 2023