BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasn’t Publicly Confirmed

Overview and Background This is the first of what will likely be several updates to this site’s exclusive reporting on the “BlueLeaks 2.0” incident that exposed anonymous and sensitive tips by and about students on a platform that pro… Continue reading BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasn’t Publicly Confirmed

Vercel Confirms Cyber Incident After Sophisticated Attacker Exploits Third‑Party Tool

Phil Muncaster reports: Next.js developer Vercel has confirmed a cyber-incident  conducted by a “highly sophisticated” attacker which may have resulted in threat actors getting hold of sensitive internal data. The US firm, which provides developer tool… Continue reading Vercel Confirms Cyber Incident After Sophisticated Attacker Exploits Third‑Party Tool

Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims

And then there were three…. A third man has pleaded guilty to conspiring with two other cybersecurity professionals and BlackCat to use BlackCat’s ransomware and negotiation platform to target U.S. firms. Ryan Goldberg of Georgia and Kevin … Continue reading Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims

Breach at BE PRIME cybersecurity company exposes client data and surveillance systems; Be Prime threatens journalists

Alberto Payo reports: A cybersecurity company based in Mexico, BePrime, was reportedly the victim of a cyberattack that allegedly resulted in the leak of 12.6 GB of data and access to network infrastructure and video surveillance, according to informat… Continue reading Breach at BE PRIME cybersecurity company exposes client data and surveillance systems; Be Prime threatens journalists

Qilin’s 2024 attack on NHS vendor continues to impact patient care for one NHS Trust

Long-term follow-ups are important, and DataBreaches is glad that Alexander Martin points out that at least one NHS Trust is still impacted by the Qilin ransomware attack on Synnovis in 2024. From his reporting: At South London and Maudsley NHS Foundat… Continue reading Qilin’s 2024 attack on NHS vendor continues to impact patient care for one NHS Trust

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware

Daryna Antoniuk reports: Hackers have targeted Ukrainian hospitals and local government bodies in a new espionage campaign using a malware tool dubbed AgingFly, researchers say. Ukraine’s computer emergency response team (CERT-UA) said the activity was… Continue reading Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware

Tax documents for school employees potentially stolen across Los Angeles County

Jason Henry reports: The Los Angeles County Office of Education is investigating the possibility that bad actors gained access to the electronic tax documents of teachers and administrators after employees at schools around the county received letters … Continue reading Tax documents for school employees potentially stolen across Los Angeles County

Judge lets state auditor’s investigation into data breach affecting Blue Cross Blue Shield members move forward

There’s an update to a lawsuit involving Blue Cross Blue Shield of Montana’s parent company, HCSC, and Montana’s state auditor. As previously reported, after BCBSMT notified the state of the Conduent breach that had affected 462,000 m… Continue reading Judge lets state auditor’s investigation into data breach affecting Blue Cross Blue Shield members move forward