Hackmanac Cyber Alerts
رفتن به کانال در Telegram
🚩 Channel was restricted by Telegram
نمایش بیشتراطلاعاتی وجود ندارد
مشترکین
-624 ساعت
-567 روز
-15230 روز
آرشیو پست ها
🚨Cyberattack 🚨
🇷🇴Romania - District 5 City Hall
RansomHub officially claimed responsibility for the attack on District 5 City Hall with a post on its data leak site.
On October 26, 2024, Bucharest’s District 5 City Hall reported a ransomware attack by RansomHub targeting its servers, with hackers demanding a ransom of USD 5 million. The attack disrupted services, including the telephone switchboard, and displayed a ransom message on the servers.
Mayor Cristian Popescu Piedone refused to pay the ransom, instead opting to collaborate with the Ministry of Research, Innovation, and Digitization, along with the National Cyber Security Directorate, to address the issue. Only the main headquarters was affected, leaving other offices unaffected.
🚨Cyberattack Alert ‼️
🇹🇿Tanzania - College of Business Education (CBE)
Hellcat hacking group claims to have breached the College of Business Education (CBE).
Allegedly, 366 MB of data, including over 500,000 student records with personally identifiable information (PII) such as full names, phone numbers, email addresses, billing, and financial information, have been fully leaked.
🚨Data Breach Alert 🚨
🇻🇳Vietnam - Zalo
The threat actor with the moniker "binanhang123" claims to have breached 100 million customer records belonging to the Vietnamese messaging app Zalo.
The sample provided shows information such as phone numbers, usernames, and display names.
The confirmation or denial of these claims has yet to be verified, but in the meantime, Zalo users are advised to be cautious of potential scam attempts.
+3
🟧 #HackTuesday 🟧
Hack Tuesday: Week 30 Oct - 05 Nov 2024
⚠️204 cyberattacks across 39 countries ⚠️
➡️The most active threat actor this week is RansomHub claiming responsibility for 32 attacks
➡️The 🇺🇸USA is the most affected country, accounting for 42% of the victims, followed by 🇬🇧United Kingdom with 11%.
➡️The Gov / Mil / LE sector is the most impacted, representing 13% of the claimed targets, followed by the Manufacturing with 11%.
➡️Overall, the claimed compromised data amounts to approximately 32 TB.
☣️The average ESIX® (Estimated Severity Index) is 4.6.
Follow the link for list of referred victims:
https://hackmanac.com/news/hack-tuesday-week-30-oct-05-nov-2024
#Hackmanac #HT #Cybersecurity
🚨Cyberattack Alert ‼️
🇬🇧UK - Fylde Coast Academy Trust (FCAT)
Rhysida ransomware group claims to have breached Fylde Coast Academy Trust (FCAT).
Allegedly, exfiltrated data include confidential information and personally identifiable information (PII).
Ransom demand: 20 BTC (approx. $1,400,000). Ransom deadline: 12th Nov 24.
🚨Cyberattack Alert ‼️
🇺🇸USA - Sundt Construction
RansomHub hacking group claims to have breached Sundt Construction, one of the top 100 largest firms in the U.S. construction industry.
Allegedly, exfiltrated data include financial reports, sales documents, accounting data, personal information of investors, client lists, assessments, agreements, personal data of employees and clients (addresses, contact information, document copies), confidential internal correspondence, passwords, credentials, and SQL databases.
Ransom deadline: 11th Nov 24.
🚨Cyberattack Alert ‼️
🇺🇸USA - Memorial Hospital and Manor in Bainbridge
Embargo ransomware group claims responsibility for the attack on Memorial Hospital and Manor in Bainbridge and claims to have exfiltrated 1.15 TB of data.
On November 3rd, in a Facebook post, the hospital reported experiencing a ransomware attack on its Electronic Health Record (EHR) system, which was discovered early Saturday morning.
In the interim, staff have reverted to paper-based processes, potentially resulting in longer wait times for patients.
Ransom deadline: November 8, 2024.
🚨Data Breach Alert ‼️
🇯🇵Japan - Hakubun Eikodo (博文栄光堂オンラインショップ)
The Hakubun Eikodo online shop, operated by Tozai Philosophy Publishing (株式会社東西哲学書院), reported a breach in which unauthorized access led to the leak of 18,394 customers' credit card information and 50,338 individuals' personal information.
The breach, discovered on May 29, 2024, involved tampering with the payment application due to system vulnerabilities. Compromised credit card details, belonging to 15,986 customers who made purchases between April 7, 2021, and May 29, 2024, include cardholder names, numbers, expiration dates, and security codes. Personal data, including names, addresses, phone numbers, and order history, was also compromised for individuals who entered information between May 1, 2018, and May 29, 2024.
Credit card transactions on the affected site have been suspended and impacted individuals are being notified via email or postal letter.
Source:
https://hakubun-eikodo.jp/
🚨 CyberAttack 🚨
🇯🇴 Jordan Ministry of Education
Hellcat hacking group claims to have breached Jordan Ministry of Education.
The hackers allegedly exfiltrated 458 MB (compressed) of data, including identification cards, divorce papers, and various letters addressed to the Minister.
The data has been fully leaked.
🚨Cyberattack Alert ‼️
🇫🇷France - Schneider Electric
Hellcat hacking group claims to have breached Schneider Electric.
Allegedly, 40 GB of data, including projects, issues, plugins, and over 400,000 rows of user data, were exfiltrated.
Ransom demand: $125,000.
🚨Cyberattack Alert ‼️
🇧🇦Bosnia and Herzegovina - International University of Sarajevo (IUS)
Medusa ransomware group claims to have breached the International University of Sarajevo (IUS).
Samples have been provided.
Ransom demand: $180,000.
Ransom deadline: 12th Nov 24.
🚨 Cyberattack Update 🚨
🇺🇸 USA - Summit Pathology Laboratories, 1.8 Million Individuals Affected
Summit Pathology Laboratories, Inc., a pathology provider based in Colorado, has confirmed that a ransomware attack by the Medusa group in April 2024 affected 1,813,538 individuals.
The breach was detected on April 18, 2024, following the discovery of suspicious activity that prompted an immediate investigation. A cybersecurity firm determined that patient data—including names, addresses, birthdates, Social Security numbers, financial, and health information—was accessed or acquired by the attackers.
The breach reportedly originated from a phishing email containing a malicious attachment.
Although it remains unclear if a ransom was paid, Summit Pathology has not been listed on Medusa’s data leak site, which frequently names victims who refuse to pay.
Full article:
https://www.hipaajournal.com/summit-pathology-data-breach/
🚨Cyberattack Alert ‼️
🇺🇸USA - San Francisco Ballet
INC Ransom hacking group claims to have breached San Francisco Ballet.
Allegedly, exfiltrated data include financial data, email correspondence, personally identifiable information (PII), and students’ data.
🚨🚨🚨Cyberattack Alert ‼️
🇪🇺European External Action Service (EEAS)
Hunters International ransomware group claims to have breached the European External Action Service (EEAS), the diplomatic service in charge of executing all international relations of the European Union.
Allegedly, 52.3 GB (21,680 files) of confidential data, including employees’ data, databases, financial records, personally identifiable information (PII) and more, were exfiltrated.
🚨Cyberattacks Alert 🚨
The RansomHub ransomware group appears to be targeting companies in the construction sector, claiming 5 attacks in the USA in the past few hours:
- Kriger Construction
- Lambert Marble
- Case Construction
- CSU Inc.
- Red Phoenix Construction
🚨Data Breach Alert - NOKIA
IntelBroker, in collaboration with the threat actor EnergyWeaponUser, claims to be selling a substantial collection of Nokia’s source code, allegedly obtained through a third-party contractor directly involved with Nokia’s internal tool development.
The compromised data reportedly includes SSH keys, source code, RSA keys, Bitbucket credentials, SMTP accounts, webhooks, and hardcoded credentials.
A file tree has been provided as evidence.
🚨Cyberattack - 🇺🇸Memorial Hospital and Manor in Bainbridge
Memorial Hospital and Manor in Bainbridge, Georgia, experienced a ransomware attack on its Electronic Health Record (EHR) system, discovered early Saturday morning.
In the interim, staff have reverted to paper-based processes, which may result in longer wait times for patients.
🚨Cyberattack Alert ‼️
🇫🇷France - Cerp Bretagne Nord
Hunters International ransomware group claims to have breached Cerp Bretagne Nord.
Allegedly, 2.1 TB (1,120,065 files) of data were exfiltrated. Ransom deadline: 06th Nov 24.
On October 19, the pharmaceutical distribution cooperative CERP Bretagne-Atlantique suffered a cyberattack, impacting its online ordering system for pharmacies across multiple French regions, including Bretagne, Centre-Val de Loire, Pays de la Loire, and Nouvelle-Aquitaine.
🚨Cyberattack Alert - 🇺🇸Hope Valley Recovery
Rhysida ransomware group claims to have breached Hope Valley Recovery.
Ransom demand: 10 BTC (approx. $700,000).
Ransom deadline: 08th Nov 24.
🚨Cyberattack Alert ‼️
🇧🇷Brazil: Companhia de Saneamento Básico do Estado de São Paulo - Sabesp
RansomHouse hacking group claims to have breached and encrypted Sabesp.
The company announced on October 22 that it had fallen victim to a cyber attack, leading to instability in its digital network.
According to Sabesp, forensic investigations to date have not indicated any compromise of customers' personal data.
