Hackmanac Cyber Alerts
الذهاب إلى القناة على Telegram
لا توجد بيانات
المشتركون
-624 ساعات
-567 أيام
-15230 أيام
أرشيف المشاركات
🚨Cyberattack Update ‼️
🇪🇸Spain - Tendam
Tendam admits that the cyberattack it suffered puts at risk data such as the ID numbers of its loyalty club members.
Article by El Pais:
https://elpais.com/economia/2024-10-08/tendam-admite-que-el-ciberataque-que-sufrio-pone-en-peligro-datos-como-el-dni-de-los-miembros-de-sus-clubes-de-fidelidad.html
On September 7th, we reported that the Medusa hacking group claimed to have breached Grupo Cortefiel (Tendam) and demanded $800,000.
A few days later, on September 16th, the cybercriminal group "Valencia Ransomware" also claimed to have attacked Tendam.
🚨Cyberattacks Alert ‼️
The Play ransomware group has been particularly active in recent hours, adding six new victims to their data leak site:
🇺🇸Accounting Resource Group
🇸🇪AnVa Industries
🇺🇸Saratoga Liquor
🇺🇸Smokers Choice
🇺🇸Eagle Recovery Associates
🇺🇸Aaren Scientific
The ransom deadlines expire between October 11 and 12.
404 Media reported that hacked data from an "AI girlfriend" website reveals prompts describing child sexual abuse.
A hacker targeted a site where users create uncensored, AI-powered sexual partners, stealing a massive database of user interactions with their chatbots.
Additionally, @haveibeenpwned analyzed that the "AI girlfriend" site Muah[.]ai experienced a breach of 1.9 million email addresses last month. The data included AI prompts, many sexual in nature, with some describing child exploitation.
404 Media article:
https://www.404media.co/hacked-ai-girlfriend-data-shows-prompts-describing-child-sexual-abuse-2/
HIBP permalink:
https://haveibeenpwned.com/PwnedWebsites#Muah
🚨Cyberattack Alert ‼️
🇨🇳China - Ping An Group
Kill Security hacking group claims to have breached Ping An Group, one of the largest integrated finance groups in the world, serves over 232 million customers in China
Allegedly, exfiltrated data include detailed insurance coverage information, such as policyholder names, identification numbers, periods of coverage, and financial amounts insured. The data also encompass policy details covering medical expenses, accidental death, and disability benefits.
Ransom deadline: 16th Oct 24.
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 02 - 08 October 2024
⚠️103 cyberattacks across 21 countries⚠️
The most active ransomware group this week is RansomHub, claiming responsibility for 15 attacks.
The United States is the most affected country, accounting for 57% of the victims. The Professional, Scientific, and Technical sectors are the most impacted, representing 24% of the claimed targets, followed by the Manufacturing sector with 21%.
Overall, the claimed stolen data amounts to approximately 33 Terabytes.
The average Cyber Risk Factor stands at 4.0.
Follow the link for the full list of victims⬇️
https://hackmanac.com/news/hack-tuesday-week-02-08-october-2024
#Hackmanac #HT #Cybersecurity
🚨Data Breach Alert ‼️
🇺🇸USA - CreditRiskMonitor
On July 19, 2024, CreditRiskMonitor, Inc. (CRMZ) detected unauthorized access to its computer network.
An investigation revealed that files containing personally identifiable information (PII) of employees and independent contractors were potentially viewed or copied between July 8 and July 17, 2024.
The breach did not involve customer data, and no misuse of the PII has been detected so far.
FORM 8-K:
https://www.sec.gov/Archives/edgar/data/315958/000114036124043034/ef20036707_8k.htm
🚨Cyberattack Alert ‼️
🇬🇧United Kingdom - Matki
Cactus ransomware group claims to have breached Matki.
Allegedly, 267 GB of data were exfiltrated, including personally identifiable information, database backups, financial documents, executives' and employees' personal data, and corporate confidential data and correspondence.
🚨Cyberattack Alert ‼️
🇺🇸USA - Corporate Job Bank
Cactus ransomware group claims to have breached Corporate Job Bank.
Allegedly, 65 GB of data were exfiltrated, including personally identifiable information, corporate confidential documents and correspondence, employees and executives' personal data, project details, and customer information.
🚨Cyberattack Alert ‼️
🇮🇱Israel - MaxShop
The pro-Palestinian hacktivist group Handala claims to have hacked Max Shop, a store terminal cloud software used by over 9,000 stores in Israel and the occupied territories.
The group reportedly exfiltrated 1.5 TB of data, defaced kiosk monitor screens, sent threatening messages to more than 250,000 individuals, and wiped all data from the systems.
Allegedly, the database includes details of over 250,000 orders.
The confirmation or denial of these claims has yet to be verified
🚨Cyberattack Alert ‼️
🇯🇵Japan - Casio (カシオ計算機)
Casio Computer Co., Ltd. experienced unauthorized access to its network on October 5, 2024, resulting in a system failure that disrupted some services.
The company is currently investigating the breach with the help of external specialists to determine whether any personal or sensitive information has been leaked.
Soruce:
https://www.casio.co.jp/release/2024/1008-incident/
N.B.: At Hackmanac, we previously reported that on April 5 this year, the Indian branch of Casio was reportedly compromised by the Stormous hacking group.
The attack allegedly led to the exfiltration of 175 GB of data, including confidential personal identification data, private information, financial data, construction projects, agreements, drawings, corporate correspondence, accounting, operational data, and personal folders of top managers and key employees, among others.
Hackmanac Casio India post: https://x.com/H4ckManac/status/1776250880423039352
🚨Cyberattack Alert ‼️
🇺🇸USA - Superior Court of California, Sonoma County
Meow hacking group claims to have breached the Superior Court of California, Sonoma County.
Allegedly, 5 GB of data were exfiltrated, including employee data, client information, scanned payment documents, personal data (including dates of birth and Social Security numbers), agreements, certificates, addresses, banking information, and criminal records.
🚨Cyberattack Alert ‼️
🇪🇸Spain - Arelance
Medusa ransomware group claims to have breached Arelance.
Ransom demand: $100,000.
Ransom deadline: 17th Oct 24.
🚨Cyberattack Alert ‼️
🇮🇱Israel - Pearl Cohen
BianLian ransomware group claims to have breached Pearl Cohen, an international law firm with offices in New York, Boston, Los Angeles, Tel Aviv, and London
Allegedly, 1.2 TB of data were exfiltrated, including company customer data (technical, briefs, new and prospective customers, paperwork, negotiations), project data, HR data, business files, technical data, MSG and email archives up to 2024, operational SQL backups, and fileserver data.
+1
🚨Cyberattack Update ‼️
🇯🇵Japan - ITOCHU Techno-Solutions Corporation
On August 13, 2024, ITOCHU Techno-Solutions Corporation reported a potential information leakage after one of its subcontractors was attacked by a ransomware group, resulting in unauthorized access to a file-sharing service used for business operations. This potentially exposed corporate and personal information of business partners, including customers.
On October 7, 2024, ITOCHU provided an update confirming that no files were exfiltrated. The investigation revealed that a subcontractor's PC had been compromised via a brute-force attack, leading to the execution of ransomware and access to a cloud-based file-sharing service. However, no sensitive files related to ITOCHU’s business were found on the compromised PC, and no downloads from the file-sharing service were detected.
Source
August 13: https://www.ctc-g.co.jp/company/info/20240813-01779.html
October 07: https://www.ctc-g.co.jp/company/info/20241007-01799.html
Universal Music Group Admits Data Breach
According to a filing with the Maine Attorney General’s Office, the breach may have exposed the personal information of 680 US residents.
More details:
https://www.infosecurity-magazine.com/news/umg-data-breach-680-us-residents/
🚨Cyberattack Alert ‼️
🇯🇵Japan - Tokyo Sompo Appraisal (東京損保鑑定株式会社)
Tokyo Sompo Appraisal Co., Ltd., reported unauthorized access to its server, resulting in the encryption of files through ransomware on August 29, 2024.
The company established a task force and involved security experts and lawyers to assess the damage, prevent further spread, and conduct recovery efforts. As of October 4, no data leaks or unauthorized use of information have been confirmed.
The investigation is ongoing, with results expected after November.
Source:
https://to-son.co.jp/news/25858
🚨Cyberattack Alert ‼️
🇺🇸USA - Albany College of Pharmacy and Health Sciences
Medusa ransomware group claims to have breached Albany College of Pharmacy and Health Sciences.
Ransom demand: $150,000.
Ransom deadline: 11th Oct 24.
On September 19, NEWS10 ABC reported that Albany College of Pharmacy and Health Sciences experienced a disruption to their computer systems due to a "network security incident."
https://www.news10.com/news/albany-county/cyber-threat-under-investigation-at-albany-college-of-pharmacy-and-health-sciences/
🚨Cyberattack Alert ‼️
🇮🇳India - The Wedding Company (Weddings by Betterhalf)
Kill Security hacking group claims to have breached The Wedding Company, previously known as Weddings by Betterhalf.
Allegedly, exfiltrated data include personal information, family details, educational records, employment data, medical records, government-issued documents, biometric data, financial details, religious information, caste data, astrological details, vaccination records, and identity numbers.
🚨Cyberattack Alert ‼️
🇪🇸Spain - Ibermutua
Hunters International ransomware group claims to have breached Ibermutua, a mutual society collaborating with Spain's social security system.
Allegedly, 647.7 GB (386,607 files) of data were exfiltrated, including source code, database information, passwords, PII, financial data, customer data, and government data.
At the time of writing, the Ibermutua website is not functioning.
🚨Cyberattack Alert ‼️
Kill Security Claims to Have Breached Yassir, but Sample Shows Sensitive Medical and Financial Documents Tied to Italy and Spain.
Kill Security hacking group claims to have breached Yassir. Allegedly, the exfiltrated data includes personal identification information, medical records, diagnostic test results, healthcare provider details, financial information, business documents, tax-related data, and institutional information.
Interestingly, the samples provided by the ransomware group contain diagnostic data from the Italian healthcare facility "Ospedale Italiano Policlinico San Martino" and invoices belonging to the Italian and Spanish branches of Top Doctors.
According to our database, Top Doctors was listed among the victims of RansomHub on September 16.
Whether these data are connected to Yassir remains to be determined, but it wouldn't be the first time a hacking group mislabels the victim's name.
