#CybersecurityBreach
October 2, 2025 at 8:16 PM
October 2, 2025 at 8:17 PM
Well, how's everyone's egg price? #cybersecuritybreach
February 4, 2025 at 12:43 AM
Daniel J. Berulis, a federal employee who described DOGE's actions which created a significant cybersecurity breach, has said he was stalked and threatened by an unknown person while he was compiling his disclosure on the department.

#DOGE #DanielBerulis #CybersecurityBreach #Newsweek
DOGE whistleblower says he was stalked and threatened after raising alarm
A National Labor Relations Board employee noticed the removal of information from databases following DOGE intervention.
www.newsweek.com
April 18, 2025 at 11:43 AM
A whistleblower complaint filed by an IT staffer claims Elon Musk and his DOGE team gained access to sensitive data that could have led directly to a “significant cybersecurity breach.”
#ElonMusk #DOGE #NLRB #Whistleblower #CybersecurityBreach #RussianHackAttempt #StarLink #Treason
NLRB whistleblower claims Musk's DOGE potentially caused significant security breach
YouTube video by PBS NewsHour
www.youtube.com
April 18, 2025 at 1:14 AM
Microsoft SharePoint experienced a breach impacting DHS and HHS. This is a reminder of the importance of robust security measures for all businesses.
www.cbsnews.com/news/microso...
#CybersecurityBreach #DataSecurity #MicrosoftSharePoint #GovernmentSecurity
DHS and HHS among federal agencies hacked in Microsoft SharePoint breach
Department of Homeland Security headquarters, several of its agencies and the Department of Health and Human Services have been hacked as part of a wider breach of Microsoft SharePoint.​
www.cbsnews.com
September 7, 2025 at 9:30 PM
Microsoft SharePoint experienced a breach impacting DHS and HHS. This is a reminder of the importance of robust security measures for all businesses. buff.ly/GcJIAYQ #CybersecurityBreach #DataSecurity #MicrosoftSharePoint #GovernmentSecurity #CyberAttack #Itsecurity
DHS and HHS among federal agencies hacked in Microsoft SharePoint breach
Department of Homeland Security headquarters, several of its agencies and the Department of Health and Human Services have been hacked as part of a wider breach of Microsoft SharePoint.​
buff.ly
September 2, 2025 at 3:35 PM
Microsoft SharePoint experienced a breach impacting DHS and HHS. This is a reminder of the importance of robust security measures for all businesses.

#CybersecurityBreach #DataSecurity #MicrosoftSharePoint #GovernmentSecurity #CyberAttack #ITsecurity
DHS and HHS among federal agencies hacked in Microsoft SharePoint breach
Department of Homeland Security headquarters, several of its agencies and the Department of Health and Human Services have been hacked as part of a wider breach of Microsoft SharePoint.​
www.cbsnews.com
September 7, 2025 at 2:55 PM
Just read the new report on the OpenAI security slip—missed warnings, a sandbox escape, and a METR breach that could affect Hugging Face models. Curious how AI agents slipped through? Dive in for the full breakdown. #OpenAI #SandboxEscape #CybersecurityBreach

🔗 aidailypost.com/news/report-...
August 26, 2026 at 9:53 PM
Origin Energy cybersecurity incident exposes millions of customer records

🤖 IA: It's clickbait ⚠️
👥 Users: It's clickbait ⚠️

#cybersecuritybreach #dataleak

View full AI summary:
Origin Energy cybersecurity incident exposes millions of customer records
Origin Energy, Australia's largest energy provider, confirmed a cybersecurity incident where unauthorised access to customer data may have occurred. The breach potentially exposed personal information including names, addresses, emails, dates of birth, phone numbers, and bill history for up to 4.8 million customers. While the company stated credit card and bank details were not compromised, the Australian Federal Police, Cyber Security Centre, and Information Commissioner have been notified. Shares fell nearly 3% following the announcement. The incident follows reports that a hacker shared 50 sample records with The Australian newspaper, though no ransom has been demanded. Origin Energy is conducting urgent investigations and will provide further updates as appropriate. This breach highlights vulnerabilities in critical infrastructure sectors and raises concerns about data privacy protections for consumers.
en.killbait.com
July 22, 2026 at 2:16 PM
Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned #CybersecurityBreach #DarkWeb #DataBreach
Govt: Kudankulam Data Breach Did Not Impact Nuclear Security, No Immediate Review Planned
 The Centre has attempted to reassure the public that the data breach incident involving electronic files of the Kudankulam Nuclear Power Plant (KKNPP) has no implication on the nation’s nuclear security or reactor operations. Union Minister of State for Atomic Energy Jitendra Singh stated that the breach did not affect any sensitive nuclear facility or infrastructure.  Singh stated during an interaction with reporters on the sidelines of the press conference on July 16 that there was no need for an immediate security review since the breach did not concern nuclear activities or reactors. Nuclear Power Corporation of India Limited (NPCIL), which manages the Kudankulam plant, claimed that the data breach incident did not disclose any sensitive information about reactors.  “In the given scenario, the data breach is related to the Engineering, Procurement and Construction (EPC) contract for the Common Services–Balance of Plant (BoP) package for Units 3 and 4 under Implementation Agreement 7 (IA-7),” the NPCIL stated. It added that the EPC contract is signed with Reliance Infrastructure via a public tender process in 2018 for Kudankulam NPP. “The balance of plant involves many elements such as auxiliary systems, services, and infrastructure like cooling towers, which are comparable to those in conventional thermal power stations,” NPCIL noted. It added that the BoP does not contain any nuclear power plant equipment or components or safety and security features. “In this context, NPCIL is not contemplating any First Information Report (FIR) as the cyber-attack was on the data of Reliance Infrastructure,” an NPCIL spokesperson said. They added that the information shared with Reliance Infrastructure during the tendering procedure included indicative drawings and technical specifications on the common services balance of plant, typically provided to all bidders. “This information did not include any sensitive nuclear safety information,” the spokesperson added.  NPCIL stated that Reliance Infrastructure develops engineering drawings using the technical specifications and drawings provided by NPCIL in coordination with original equipment manufacturers (OEMs) for the approval process. The breach of data came after Reuters reported that ransomware group World Leaks exfiltrated more than 19,000 files from servers hosting Kudankulam Nuclear Power Plant, covering the 2016 fiscal year through mid-2025.  According to the report, the documents contain details on control, cooling, and ventilation systems, suppliers, inspections conducted by Indian and Russian personnel, meeting records, and insurance data. The breach was attributed to a server managed by data centre infrastructure provider Yotta, hosted by third-party Reliance Group, which was responsible for the EPC contract for the Kudankulam NPP, admitting that the attack resulted in a partial data breach.  Tamil Nadu-based Kudankulam Nuclear Power Plant currently operates two 1,000 MW VVER reactors and is set to commission four more reactors under the Russian technical collaboration agreement. The project aims to make Kudankulam one of India’s largest nuclear power parks with a total capacity of 6,000 MW. The data breach incident does not appear to affect the nuclear security or safety of the nation, as the government and NPCIL continue to emphasize.  The breach did, however, raise concerns about the safety of digital assets and data security in various contracts, including those of critical infrastructure like Kudankulam NPP.
dlvr.it
July 16, 2026 at 3:14 PM
June 25, 2026 at 1:26 AM
Of course he did. They're either incompetent or have no morals to work in this administration. All the good people got out or refused to work there.

Freaking #ChatGPT? Really???
#Trump #incompetent #BottomOfTheBarrel #cybersecuritybreach
Trump's acting cybersecurity chief uploaded sensitive government docs to ChatGPT | TechCrunch
A report cited officials as saying that Homeland Security sought to determine if there was any harm to government security as a result of the lapse.
techcrunch.com
January 29, 2026 at 4:16 AM
Massive Cyber Espionage Campaign Hits Fortinet Devices, Exposing Organizations Across 15 Countries #cyberespionage #CybersecurityBreach #DataBreach
Massive Cyber Espionage Campaign Hits Fortinet Devices, Exposing Organizations Across 15 Countries
  A large-scale cyber espionage operation targeting devices manufactured by Fortinet has resulted in widespread security compromises worldwide, according to cybersecurity researchers. The campaign is believed to have affected organizations across more than 15 countries, with evidence indicating stolen credentials from Fortune 500 companies and government institutions. Cybercrime intelligence firm Hudson Rock reported that the majority of impacted devices were located in the United States, India and Taiwan. The company characterized the extent of the operation as "staggering." "The scale of this breach touches nearly every sector of the global economy, sparing no industry," the firm stated in a blog post published on Wednesday. Researchers estimate that approximately 75,000 Fortinet firewall and VPN devices were compromised during the operation. These systems are commonly used by organizations to secure networks and provide remote access for employees. The breach could potentially allow threat actors to gain deeper access into affected networks and extract sensitive information. In response, Fortinet acknowledged awareness of an ongoing effort aimed at stealing login credentials from its firewall and VPN products. The company explained that attackers were leveraging information obtained "from previous incidents" and using repeated password-guessing attempts — a method known as bruteforcing — to gain unauthorized access to targeted devices and networks. Fortinet further clarified that the malicious activity was "not related to any recent incident or advisory." The company did not provide additional details regarding the overall scale of the campaign identified by researchers. Reuters was also unable to determine how many of the stolen credentials ultimately resulted in successful network intrusions. Officials from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Office of the National Cyber Director did not immediately respond to requests for comment. Cybersecurity authorities in India and Taiwan also did not provide immediate responses. Several state agencies in Washington and Nevada, whose credentials reportedly appeared in the compromised data, likewise did not respond to inquiries. In South Carolina, one agency employee told Reuters they were unaware of the issue, while another indicated the matter would be reviewed before further information could be shared. Hudson Rock's findings also revealed that nearly 120 unique credentials linked to five government entities in Puerto Rico were included in the exposed dataset. Among the affected organizations was the Puerto Rico Police Department. A department spokesperson redirected questions to the Puerto Rico Innovation and Technology Service, which did not immediately respond to requests for comment. The exposed data was first identified by cybersecurity researcher Bob Diachenko, owner of SecurityDiscovery.com, who said he uncovered the information on an unsecured server during routine monitoring activities. "This is quite significant," Diachenko said, adding the campaign showed a "very creative approach to bruteforcing, with a multilayer password cracking architecture." According to Diachenko, scripts found within the dataset contained instructions written in Russian, indicating that the operation may be linked to a Russian cybercrime group.
dlvr.it
June 21, 2026 at 6:54 PM
Hackers List 8.3 Million U.S. Crime Tip Records for $10,000, Raising Major Security Concerns #BlueLeaks20 #crimetipdataleak #CybersecurityBreach
Hackers List 8.3 Million U.S. Crime Tip Records for $10,000, Raising Major Security Concerns
  Hackers responsible for stealing 8.3 million crime tip records are now attempting to sell the dataset for $10,000 in cryptocurrency, escalating concerns around one of the largest breaches involving sensitive law enforcement information. The compromised data includes confidential crime tips submitted to hundreds of Crime Stoppers programs run by law enforcement agencies across the United States. It also extends to submissions made to certain branches of the U.S. military and even educational institutions. The sale offer, posted on a cybercrime forum, highlights the serious implications of the breach involving cloud-based intelligence firm P3 Global Intel. The leaked database reportedly contains extensive personal information about individuals identified in tips, including names, email addresses, dates of birth, phone numbers, home addresses, license plate details, Social Security numbers, and criminal histories. In some cases, it also reveals identities and details of informants, potentially putting them at risk of retaliation. Cybersecurity experts had earlier warned that the breach could also pose national security risks, given that some of the exposed tips were submitted to federal agencies and the military. The dataset was originally stolen late last year by a hacker group known as INTERNET YIFF MACHINE and later shared with Straight Arrow News and the nonprofit transparency group Distributed Denial of Secrets (DDoSecrets). The collection, referred to as BlueLeaks 2.0, spans records from February 1987 through November 2025. In a statement, a member of the hacking group confirmed their involvement in listing the data for sale, expressing reluctance over the decision. “It’s truly not something I want to do and it goes against my principles,” the hacker said. “However, it was out of necessity. Principles are for the well-fed, and I’m unfortunately not in a great place.” The hacker also indicated that there is already interest from potential buyers, some of whom may have malicious intent. “I assume this will likely attract customers related to fraud, extortion, or at worst, finding and targeting informants,” they said. “Again, this isn’t something I feel good about doing, but it’s necessary.” They added that the intention is to sell the dataset to a single buyer. Mailyn Fidler, assistant professor at the University of New Hampshire Franklin School of Law specializing in cybersecurity and cybercrime, warned that exposure of such data could lead to “severe harm and even death to police informants.” P3 Global Intel’s parent company, Navigate360, has not responded to inquiries regarding the attempted sale. Earlier, CEO JP Guilbault stated that a third-party forensic investigation was underway to determine the extent of any breach. “To this point, we have not confirmed that any sensitive information has been accessed or misused,” Guilbault said at the time. The company has not issued further updates, and its services continue to operate. However, some users have taken precautionary measures. For instance, the Portland Police Bureau in Oregon recently advised the public to temporarily refrain from submitting tips through its Crime Stoppers program due to the ongoing concerns.
dlvr.it
April 30, 2026 at 11:13 AM
Neon App Rebounds After Data Exposure Scare, Secures $25 Million and Revamps Security #AITrainingData #appstoretrends #CybersecurityBreach
Neon App Rebounds After Data Exposure Scare, Secures $25 Million and Revamps Security
  Neon, an app that incentivizes users to sell personal data they would otherwise share for free, quickly gained traction after its September debut—rising to the second spot among the most downloaded free apps on Apple’s App Store within just eight days. The platform’s model revolves around users voluntarily recording phone calls and selling that data to artificial intelligence firms for training purposes. However, concerns around privacy surfaced almost immediately. A probe by TechCrunch revealed that Neon’s servers were vulnerable, allowing unauthorized access to more than users may have intended to share. Exposed data reportedly included metadata such as phone numbers, along with call transcripts and audio recordings. Some reviewed transcripts even suggested that in-person conversations had been recorded without clear consent. Despite the early controversy, Neon has staged a comeback. Six months post-launch, the company has raised $25 million and relaunched its platform with a stronger focus on security and transparency. Founder and CEO Alex Kiam addressed the incident candidly, acknowledging the company’s initial shortcomings. “We had not done [penetration] testing, and TechCrunch was able to get into the database, and so we immediately shut it off. We basically went back to the drawing board,” Kiam says. Following the breach, Neon collaborated with external cybersecurity specialists, including Unit 42, a research division owned by Palo Alto Networks, and brought on Ian Reid, former chief technology officer at Stamped, who now serves as Neon’s CTO. The team undertook a comprehensive code audit before relaunching the app in early November. According to Kiam, the updated version of Neon quickly regained popularity, climbing to the third position on the App Store charts. He credits user trust and transparency for the app’s renewed success. “I think the reason people came back is because they had a great experience with the app. Because we had been transparent with them during, I think they were able to give us a second chance. And we’re really grateful for that,” he says. Even with its viral growth and financial backing, industry observers remain cautious about the broader implications of monetizing personal data, especially in a time when privacy concerns are becoming increasingly critical.
dlvr.it
April 13, 2026 at 5:09 AM
3.7 Million Records Exposed in AI Chatbot Data Leak Due to Poor Security Practices #AIchatbotdataleak #CybersecurityBreach #exposeddatabases
3.7 Million Records Exposed in AI Chatbot Data Leak Due to Poor Security Practices
  A recent investigation has revealed that millions of pieces of sensitive user data were exposed—not due to a sophisticated cyberattack, but because of inadequate security measures. The findings, published by ExpressVPN and led by cybersecurity researcher Jeremiah Fowler, demonstrate how easily personal information can be compromised when essential protections like encryption and password security are overlooked. The report uncovered a major data exposure involving AI-powered chatbots used by retailers for customer service. These systems, designed to streamline interactions, were found to be storing vast amounts of customer data without proper safeguards. While many users rely on VPN services to protect their online privacy through strong encryption, such tools cannot prevent data leaks caused by negligence on the part of companies or third-party providers handling user information. Fowler identified three publicly accessible databases that lacked both password protection and encryption. Together, these databases contained approximately 3.7 million records, including highly sensitive personal details such as email addresses, home addresses, and phone numbers. Even a small sample of the exposed data highlighted the scale of the issue. It included 1,422,577 customer audio recordings, 3.9TB of text transcripts, 207,381 Excel files, and 415.2GB of audio data. The sampled data was linked to Sears Home Services, a US-based retail and repair company that uses AI chatbots in English and Spanish to manage scheduling, phone calls, and online customer interactions. Among the files were 54,359 complete chatbot conversation transcripts along with corresponding audio recordings. Fowler also noted a concerning flaw in the system: audio recordings continued even if a customer failed to properly end a call. As a result, some recordings captured up to four hours of background audio, potentially including sensitive conversations and biometric voice data. To illustrate the severity of the issue, Fowler shared screenshots showing how easily the data could be accessed, including interfaces that allowed users to browse files and play audio recordings directly in a web browser. How to Stay Safe Although Fowler confirmed that access to the exposed databases was restricted shortly after he reported the issue to Transformco, the parent company of Sears Home Services, he emphasized ongoing concerns about data security practices. The investigation underscores the growing risks associated with AI-driven systems that store large volumes of sensitive information. With projections suggesting that deepfake-enabled fraud losses could reach $40 billion by 2027, such data exposures could have serious consequences. Stolen data of this scale could allow cybercriminals to piece together identities or create convincing digital replicas for fraudulent activities. In these scenarios, even advanced privacy tools like VPNs offer little protection if the breach originates from trusted services themselves. ExpressVPN advises users to remain cautious by adopting strong passwords and exercising care when sharing sensitive information. Users should also be wary of unsolicited communications—such as emails, texts, or calls—that reference personal details. Additionally, to guard against voice cloning scams, it is recommended to establish a verification password with trusted contacts, especially for situations involving urgent financial or personal requests.
dlvr.it
March 28, 2026 at 12:51 PM
Russian-Linked Surveillance Tech Firm Protei Hacked, Website Defaced and Data Published #CyberAttacks #CybersecurityBreach #DataBreaches
Russian-Linked Surveillance Tech Firm Protei Hacked, Website Defaced and Data Published
 A telecommunications technology provider with ties to Russian surveillance infrastructure has reportedly suffered a major cybersecurity breach. The company, Protei, which builds systems used by telecom providers to monitor online activity and restrict access to websites and platforms, had its website defaced and internal data stolen, according to information reviewed by TechCrunch. The firm originally operated from Russia but is now based in Jordan and supplies technology to clients across multiple regions, including the Middle East, Europe, Africa, Mexico, Kazakhstan and Pakistan.  Protei develops a range of systems used by telecom operators, including conferencing platforms and connectivity services. However, the company is most widely associated with deep packet inspection (DPI) tools and network filtering technologies — software commonly used in countries where governments impose strict controls on online information flow and communication. These systems allow network providers to inspect traffic patterns, identify specific services or websites and enforce blocks or restrictions.  It remains uncertain exactly when the intrusion occurred, but archived pages from the Wayback Machine indicate the public defacement took place on November 8. The altered site contained a short message referencing the firm’s involvement in DPI technology and surveillance infrastructure. Although the webpage was restored quickly, the attackers reportedly extracted approximately 182 gigabytes of data from Protei’s systems, including email archives dating back several years.  A copy of the exposed files was later supplied to Distributed Denial of Secrets (DDoSecrets), an organization known for cataloging leaked data from governments, law enforcement agencies and companies operating in surveillance or censorship markets. DDoSecrets confirmed receiving the dataset and made it available to researchers and journalists.  Prior to publication, TechCrunch reached out to Protei leadership for clarification. Mohammad Jalal, who oversees the company’s Jordan branch, did not initially respond. After publication, he issued an email claiming the company is not connected to Russia and stating that Protei had no confirmed knowledge of unauthorized data extraction from its servers.  The message left by the hacker suggested an ideological motive rather than a financial one. The wording referenced SORM — Russia’s lawful interception framework that enables intelligence agencies to access telecommunications data. Protei’s network filtering and DPI tools are believed to complement SORM deployments in regions where governments restrict digital freedoms.  Reports from research organizations have previously linked Protei technology to censorship infrastructure. In 2023, Citizen Lab documented exchanges suggesting that Iranian telecommunications companies sought Protei’s systems to log network activity and block access to selected websites. Documents reviewed by the group indicated the company’s ability to deploy population-level filtering and targeted restrictions.  The breach adds to growing scrutiny surrounding technology vendors supplying surveillance capabilities internationally, especially in environments where privacy protections and freedom of expression remain vulnerable.
dlvr.it
November 27, 2025 at 2:34 PM
GlobalLogic Moves to Protect Workforce After Oracle-Related Data Theft #ClopGroup #CybersecurityBreach #DataBreach
GlobalLogic Moves to Protect Workforce After Oracle-Related Data Theft
  A new disclosure that underscores the increasing sophistication of enterprise-level cyberattacks underscores the need to take proactive measures against them. GlobalLogic has begun notifying more than ten thousand of its current and former employees that their personal information was compromised as a result of a security breach connected to an Oracle E-Business Suite zero-day flaw.  An engineering services firm headquartered in the United States, owned by Hitachi, announced the breach to regulators after determining that an unknown attacker exploited an unpatched vulnerability in the Oracle platform, the core platform used to manage finance, human resources, and operational processes at the company, so that sensitive data belonging to 10,000 employees was stolen.  The Maine Attorney General's office reported to the Maine State Attorney General that attackers had infiltrated GlobalLogic's environment with an advanced SQL-injection chain mapped to MITRE techniques T1190 and T1040, deploying a persistent backdoor through an Oracle Forms vulnerability, obtaining extensive employee data, including identification, contact information, passport information, tax and salary data, and bank account numbers, as well as extensive employee records.  The signs of compromise point to a coordinated data-extortion campaign in which privilege-escalation events were used to maintain prolonged access to data. Indicators like malicious IP ranges and rogue domains indicate that the attack was coordinated. In the aftermath of Oracle's security patches being released, GlobalLogic announced that an immediate investigation had been conducted, and the company is now urging the rapid implementation of vendor updates, enhanced logging, and temporary hardening measures in order to mitigate further risk.  With Hitachi's acquisition of the company in 2021, it has now served more than 600 enterprise clients around the world, and the company has officially reported the breach to California and Maine regulators, who confirmed that more than 10,500 current and former employees' personal information was exposed in the attack.  During GlobalLogic's investigation, it was discovered that the intrusion was a part of a larger campaign that was coordinated by the Clop ransomware group, which has been exploiting a zero-day flaw in Oracle's E-Business Suite since at least July in order to snare huge amounts of corporate information. There have been reports that several companies have been caught in this wave of attacks, and many are only aware of their compromise after they receive extortion emails from extortionists. Analysts are claiming that dozens of companies have been compromised. It is reported by GlobalLogic that the company discovered the breach on October 9 but it was later discovered that the attackers gained access to the server on July 10, with the most recent malicious activity occurring on August 20 according to GlobalLogic's filings. Despite the fact that the incident was contained to the Oracle platform, the sheer amount of sensitive and high-level data stolen—from contact information to internal identifiers to passports to tax records to salary information to bank account numbers—does not make it easy for the severity of the attack to be noted.  A spokesperson for the company said that they immediately activated their incident response protocols, notified the law enforcement, and consulted external forensic experts after the zero-day exploit was discovered (CVE-2025-61882) was discovered, and that Oracle's patch for the vulnerability (CVE-2025-61882) was applied once it was released.  Security researchers later confirmed that Clop hacked numerous victims over a period of several months by exploiting multiple vulnerabilities within the same platform, demanding ransoms that often reached eight-figure sums. It has been reported that nearly 30 organizations are currently listed on Clop's website after a breach of their systems was discovered last week. If these organizations do not pay the restitution, they will face public exposure. The kind of information exposed in the GlobalLogic breach highlights how sophisticated the attackers were.  According to the company's disclosure, the stolen data was representative of a wide range of personal information that is typically kept in human resources systems, such as names, home addresses, telephone numbers, addresses for emergency contacts, and identifiers for internal employees. There were a variety of individuals whose exposure to cyber attacks was far more in-depth and involved email addresses, dates and countries of birth, nationalities, passports, tax and national identification numbers such as Social Security details, salary information, and full banking credentials for their online banking accounts.  A ransomware group known as Clop has been associated with several high-profile Oracle EBS data theft operations, as well as adding major companies to its Tor-based leak site, including Harvard University, Envoy Air, and The Washington Post, whose stolen data is already available via torrent downloads from a number of sources. Despite the fact that GlobalLogic's information has not yet appeared on the leak portal, security analysts have said that the omission may be indicative of ongoing negotiations, or that a ransom has already been paid by the company.  The company spokesperson refused to comment on whether any demands were being addressed, but confirmed Clop has publicly claimed responsibility for the breach. Now that the gang is being questioned more closely by the U.S. authorities after previously exploiting Accellion FTA, GoAnywhere MFT, Cleo, and MOVEit Transfer in mass-scale data breaches, they are under greater scrutiny than ever before.  According to the State Department, there is a reward for intelligence that can be provided tying the group's operations to a foreign government worth up to $10 million. In light of this incident, industry officials are calling for improved patch management, proactive threat hunting, and tighter oversight of third-party platforms supporting critical business operations that are used by critical business units.  According to GlobalLogic's analyst, the company's experience shows just how quickly a single vulnerability can lead to widespread damage when exploited by highly coordinated ransomware groups, particularly if the vulnerability has not yet been patched.  Despite continuing to investigate Clop's broader campaign, experts urge organizations to adopt continuous monitoring, strengthen vendor risk controls, and prepare for the likelihood that they will be the victim of future zero day exploits in the following years, as the modern enterprise threat landscape is now characterized by zero-day threats.
dlvr.it
November 22, 2025 at 3:04 PM
Hyundai faces security incident with potential data exposure #AutomotiveCyberattack #ConnectedCarSecurity #CybersecurityBreach
Hyundai faces security incident with potential data exposure
  In the past few months, Hyundai AutoEver America, a division of Hyundai Motor Group, has confirmed a recent data breach that exposed sensitive personal information after hackers infiltrated its internal IT environment earlier this year, revealing a recent data breach.  A company spokesperson told me that unauthorized access to the company's computer systems began on February 22, 2025 and went undetected until March 2, giving intruders nine days to access confidential data.  The early breach notices didn't specify how many people were affected, but according to state regulatory disclosures as well as a subsequent statement issued to Kelley Blue Book, approximately 2,000 people—out of the over 2.7 million users HAEA serves across Hyundai, Kia, and Genesis platforms—were impacted. There have been a number of compromises of the data, including names, Social Security numbers, and driving license information.  In response to the suspicious activity, HAEA contacted an external cybersecurity expert who conducted an investigation, contained the intrusion, and informed law enforcement. As officials continue to assess the full scope of the incident, officials have begun issuing formal notices to those whose information was possibly exposed.  It was only in the months that followed that it became increasingly clearer and more troubling just what the breach's consequences and the broader risks associated with connected vehicles were in the future. Even though Hyundai AutoEver America eventually acknowledged that the incident could have affected as many as 2.7 million Hyundai, Kia, and Genesis owners, internal assessments and state filings later narrowed the directly affected group to merely 2,000 individuals, yet the sensitive nature of the data involved makes even this smaller number quite significant.  A nine-day intrusion that took place between February 22 and March 2, 2025, revealed the names, addresses, phone numbers, driver’s license numbers, and Social Security numbers of several automobile manufacturers, revealing to intruders a full range of data and details that underpinned core digital services across the automaker’s brands during that period.  Among privacy experts, there is no doubt that what has caused concern is not just the scope of information but also that it has taken seven months for customers to be informed about the incident, a timeframe that gave the possibility for stolen identities to be misused or combined with other data circulating from other breaches. Hyundai is also experiencing a growing pattern of security breaches since 2023, which reinforces concerns that these are not isolated incidents but rather signs of deeper structural problems. As the episode illustrates, modern cars—once purely mechanical devices—now act as sophisticated data hubs, collecting everything from passengers’ financial details to route histories, biometric inputs, driving behaviour, and even information synced from their mobile devices, which is not visible to the driver.  Manufacturers are expanding their digital ecosystems and the breach has raised questions about the industry's ability to safeguard the vast and intimate data it collects on a regular basis. Immediately following the intrusion, Hyundai AutoEver America made an effort to reassure its customers by offering two years of complimentary identity theft and credit monitoring services through Epiq as a gesture of goodwill. In spite of this, security analysts note that such measures are rarely sufficient to relieve customers after sensitive information has been stolen. Additionally, Hyundai Motor Europe’s disclosure also brought back memories of a similar experience it suffered just a year earlier when it was attacked by a ransomware gang called Black Basta, which claimed to have taken over 3TB of internal files before appearing dormant in early 2025, when the company lost control of its operations.  All in all, these incidents emphasize one more uncomfortable reality: automakers now harvest and manage far greater amounts of personal information than most drivers are aware of. Besides the information required for financing or registration of vehicles, companies routinely collect (and in some cases monetize) data regarding the locations of their customers, their driving habits, the biometric patterns they use, and even behavioral patterns that can help them infer consumers' preferences with a remarkable degree of accuracy.  Following a complaint made by General Motors that it had shared driver data with third-parties to the point of being able to obtain their information from them, the Federal Trade Commission issued a five-year ban on the practice. In July, a U.S. Senate inquiry raised concerns about other manufacturers continuing the same data-sharing practices.  The HAEA notified the California Attorney General of the incident by notifying them that they had enlisted cybersecurity experts to determine the scope of the breach and confirm that the intrusion had been contained, even though investigators were unable to determine if the information was exfiltrated. Those affected customers have been given 90 days to enroll in monitoring services, and a hotline has also been established to assist customers.  As Hyundai AutoEver asserts, only a small number of users have been directly impacted by this incident, but the incident has ignited a wider industry debate over precisely how well automakers secure the ever-increasing amount of personal data embedded in most connected vehicles today. After Hyundai AutoEver America found out that a wide range of sensitive data points had been exposed as part of this breach, including a number of customer names, government-issued identification numbers, and passwords, it confirmed that the investigation of the technical footprint was continuing.  Among the records that were compromised, according to notification letters sent to the individuals affected, were Social Security numbers and driver's license information, with each recipient receiving a customized breakdown of which data elements applied to them in the initial notification. In order to conduct the analysis in a comprehensive way, extensive forensic work and collaboration with external cybersecurity specialists were necessary.  These specialists helped Hyundai AutoEver reconstruct the intrusion, assess database exposure, and determine which users needed formal notification. Hyundai AutoEver said it immediately terminated the intruder's access and implemented additional safeguards and was continuing to implement a comprehensive remediation program that was intended to prevent similar incidents in the future.  Consequently, Epiq Privacy Solutions has been contacted by the company to offer complimentary two-year credit monitoring and identity protection services to impacted customers, which will include three-bureau monitoring and fraud detection tools, as well as a 90-day enrollment period. It should be noted that these protections are only a layer of protection, however, according to security experts.  As a precautionary measure, they advise their customers to review financial statements, to check their credit reports, and to place fraud alerts or credit freezes with the major credit bureaus to reduce the risk of unauthorized account openings.  In addition, this incident has brought about renewed discussions about digital hygiene for vehicle owners, ranging from updating passwords and enabling multifactor authentication on connected car applications to avoiding stored payment information in the infotainment system. There are a number of cybercrime analysts who note that incidents of this nature often open the door to secondary scams, as cybercriminals impersonate automakers' support teams in order to steal more personal information from car owners through pages pretending to be account verifications and security updates.  These developments have been identified by industry observers as part of a dramatic shift in the way in which cars now collect far more information than most drivers are aware of. These include location histories, biometric identifiers, behavioral patterns, and synced mobile data, to name a few.  The results of this study indicate that consumers should adopt strong cybersecurity practices, including using reputable antivirus software, staying current on device updates, and thinking about data-removal solutions that will reduce exposure to data-broker websites as a result of data misuse. Several automakers have been affected by this new trend; the Federal Trade Commission imposed a five-year ban on General Motors' ability to sell data on drivers earlier this year.  Additionally, a Senate investigation has raised concerns about similar practices in other automakers, including Hyundai, as well. In spite of Hyundai AutoEver's assertion that only a relatively small number of its customers were directly affected by this breach, the incident has brought to light questions about the effectiveness with which carmakers are safeguarding the growing amounts of data embedded in connected cars, as well as what consumers should do in the rapidly growing digital world in order to protect themselves from the threat of fraud.  It is clear from the Hyundai AutoEver breach that the automobile industry needs to rethink how it approaches data security in an increasingly interconnected digital age, where vehicles become increasingly interconnected digital ecosystems. It is important to note that meaningful protection depends both on stronger corporate safeguards as well as on proactive vigilance on the part of drivers in light of increased regulatory oversight and consumers' increasing awareness of how their information is being used. It is vital that consumers play an important role in reducing future risks by practicing stricter digital hygiene, minimizing unnecessary data sharing, and demanding that automakers communicate their information more clearly, in order to ensure that the convenience of connected cars does not come at the expense of their individual privacy rights.
dlvr.it
November 21, 2025 at 1:20 PM