The Deutsche Bank breach is under investigation after the Unsafe ransomware group claimed to have stolen employee data and published alleged evidence on its leak site. The attackers shared screenshots that appear to show database exports containing employee information. However, Deutsche Bank says the incident stems from a third-party service provider and that there is…
A Nextcloud data leak exposed around 367,000 internal records after a hosting misconfiguration left an Elasticsearch database publicly accessible. The leaked data included invoices, contracts, employee information, emails, and infrastructure scripts. Researchers discovered the exposed database on May 18. Nextcloud secured it two days after receiving a responsible disclosure report. The company says the incident…
US medical equipment provider AdaptHealth has disclosed a cyberattack that exposed patient information after hackers tricked a third-party contractor through a social engineering attack. The AdaptHealth data breach affected several cloud-based business applications. The company later determined the incident was material and notified the US Securities and Exchange Commission (SEC). Social Engineering Attack Compromised Contractor…
The Medtronic data breach has entered a new phase as the medical technology company begins notifying customers whose personal information was exposed during a cyberattack earlier this year. The incident, which the ShinyHunters extortion group claimed, involved unauthorized access to corporate IT systems but did not affect the company’s medical devices. Unauthorized Access Lasted Nearly…
A Microsoft Power BI data breach at the Avans University of Applied Sciences exposed sensitive personal information to unauthorized users for nearly a year before staff discovered the issue. The university has since fixed the vulnerability, notified affected individuals, and reported the incident to Dutch data protection authorities. Misconfiguration Exposed Personal Data for Nearly a…
A major Aflac Japan data breach has exposed the personal, policy, and bank account information of approximately 4.38 million customers after attackers compromised systems belonging to the insurance giant’s Japanese subsidiary. The company says the incident affected only its operations in Japan and did not impact systems supporting its U.S. business. The disclosure comes roughly…
The 1-800-Dentist data breach is under investigation after the Qilin ransomware group claimed it had compromised the popular dental referral platform and stolen company data. While the company has not confirmed the attackers’ claims, the incident has raised concerns because of the large amount of patient and business information the platform manages. If confirmed, the…
The Nissan data breach has prompted the automaker to investigate a cyberattack targeting an Oracle PeopleSoft environment that stores employee information. The intrusion forms part of a wider hacking campaign against organizations running vulnerable Oracle enterprise software. Nissan continues to examine the incident to determine what information the attackers accessed and how many people the…
The National Association of Insurance Commissioners (NAIC) has shared new findings from its investigation into a recent cyberattack, saying the incident mainly exposed information that was already publicly available rather than highly sensitive consumer data. The organization issued the update after the ShinyHunters hacking group claimed responsibility for the breach and alleged it had stolen…
KDDI has confirmed a major data breach that may affect up to 14.2 million email accounts across six Japanese internet service providers. The Japanese telecom giant says attackers accessed a shared email platform after exploiting flaws in third-party software. The breach involved systems that support email services for several providers, which increased the possible impact.…