Dell notifies customers of breach; seller “Menelik” is ShinyHunters (1)

On April 28, a new forum user on BreachForums called “Menelik” claimed to have 49 million Dell Technologies customer records for sale. The Daily Dark Web provided a screencap and details from the listing.  The customer data purportedly incl… Continue reading Dell notifies customers of breach; seller “Menelik” is ShinyHunters (1)

Dell notifies customers of breach; seller “Menelik” is ShinyHunters (1)

On April 28, a new forum user on BreachForums called “Menelik” claimed to have 49 million Dell Technologies customer records for sale. The Daily Dark Web provided a screencap and details from the listing.  The customer data purportedly incl… Continue reading Dell notifies customers of breach; seller “Menelik” is ShinyHunters (1)

Guardant notifies patients of unintended information exposure going back to October 2020

A notification by Guardant Health, Inc. in California (“Guardant”) caught DataBreaches’ eye yesterday. Guardant is a laboratory that performs cancer screening tests on samples received from its physician and hospital partners. Patient information… Continue reading Guardant notifies patients of unintended information exposure going back to October 2020

More than 380,000 additional NYC students had info breached in 2022 Illuminate Education hack

Carl Campanile reports: More than 380,000 additional city public-school students had their personal data hacked in a massive cyber attack — bringing the total number of kids affected to well over 1 million, The Post has learned. The New York City Depar… Continue reading More than 380,000 additional NYC students had info breached in 2022 Illuminate Education hack

Fred Hutch notifies more patients of November 2023 attack

In December 2023, UW’s Fred Hutchinson Cancer Center  (“Fred Hutch”) reported a November cyberattack that involved the exfiltration of patient data and attempted extortion of patients. DataBreaches contacted Fred Hutch on December 8 t… Continue reading Fred Hutch notifies more patients of November 2023 attack

CISA’s KEV catalog making a positive difference to defenders

Jonathan Greig reports that a CISA resource is having a positive effect at both a federal level as well as for non-governmental organizations: The Cybersecurity and Infrastructure Security Agency (CISA) has run its Known Exploited Vulnerabilities (KEV)… Continue reading CISA’s KEV catalog making a positive difference to defenders

Former Cybersecurity Consultant Arrested For $1.5 Million Extortion Scheme Against IT Company

For those who would like a timely reminder about making sure you terminate access and take control of devices immediately when an employee or contractor terminates employment, consider this press release from the Southern District of New York on May 1…. Continue reading Former Cybersecurity Consultant Arrested For $1.5 Million Extortion Scheme Against IT Company

United Healthcare, Optum, and Change Healthcare Involved in Northeast Ohio Neighborhood Health Data Breach

Note: Marco A. De Felice (aka @amvinfe) has been doing some great investigative blogging on ransomware groups and incidents. If you’re not checking his  SuspectFile site regularly, you are missing out on some of his exclusive reporting.   De Feli… Continue reading United Healthcare, Optum, and Change Healthcare Involved in Northeast Ohio Neighborhood Health Data Breach