Src |
Date (GMT) |
Titre |
Description |
Tags |
Stories |
Notes |
 |
2025-03-19 15:00:00 |
Infosys pour payer 17,5 millions de dollars en règlement sur la violation de données de 2023 Infosys to Pay $17.5 Million in Settlement Over 2023 Data Breach (lien direct) |
> Le système Infosys McCamish a accepté de payer 17,5 millions de dollars pour régler six recours collectifs déposés contre une violation de données de 2023.
>Infosys McCamish System has agreed to pay $17.5 million to settle six class action lawsuits filed over a 2023 data breach.
|
Data Breach
|
|
★★
|
 |
2025-03-18 18:53:25 |
Le géant des spermatozoïdes California Cryobank met en garde contre une violation de données Sperm donation giant California Cryobank warns of a data breach (lien direct) |
Le géant des spermatozoïdes du sperme américain California Cryobank avertit les clients qu'il a subi une violation de données qui a exposé des informations personnelles. [...]
US sperm donor giant California Cryobank is warning customers it suffered a data breach that exposed customers\' personal information. [...] |
Data Breach
|
|
★★★
|
 |
2025-03-18 17:59:02 |
Western Alliance Bank affirme près de 22 000 impactés par la violation des logiciels de transfert de fichiers Western Alliance Bank says nearly 22,000 impacted by file transfer software breach (lien direct) |
La Western Alliance Bank, basée à Phoenix, a déposé des avis de violation de données disant que environ 22 000 personnes avaient été affectées par un incident impliquant un logiciel de transfert de fichiers.
Phoenix-based Western Alliance Bank filed data breach notices saying about 22,000 people were affected by an incident involving file transfer software. |
Data Breach
|
|
★★
|
 |
2025-03-18 15:50:25 |
Western Alliance Bank informe 21 899 clients de violation de données Western Alliance Bank notifies 21,899 customers of data breach (lien direct) |
La Western Alliance Bank, basée à l'Arizona, notifie près de 22 000 clients leurs informations personnelles ont été volées en octobre après que le logiciel de transfert de fichiers sécurisé d'un fournisseur tiers \\ ait été violé. [...]
Arizona-based Western Alliance Bank is notifying nearly 22,000 customers their personal information was stolen in October after a third-party vendor\'s secure file transfer software was breached. [...] |
Data Breach
|
|
★★
|
 |
2025-03-18 11:45:18 |
Western Alliance Bank révèle la violation des données liée à Cleo Hack Western Alliance Bank Discloses Data Breach Linked to Cleo Hack (lien direct) |
> Les informations personnelles de 22 000 clients de la Western Alliance Bank ont été volées dans une violation de données liée au piratage de l'outil de transfert de fichiers CLEO. par CL0P.
>The personal information of 22,000 Western Alliance Bank customers was stolen in a data breach linked to Cl0p\'s hacking of the Cleo file transfer tool.
|
Data Breach
Hack
Tool
|
|
★★
|
 |
2025-03-14 18:57:26 |
La cour d'appel confirme la peine pour l'ancien cyber-exécutif Uber Joe Sullivan Appellate court upholds sentence for former Uber cyber executive Joe Sullivan (lien direct) |
Un panel fédéral de trois juges en Californie a confirmé la peine que l'ancien directeur d'Uber Joe Sullivan a reçu après avoir été condamné dans une tentative de dissimulation d'une violation de données de 2016 à l'entreprise.
A federal three-judge panel in California upheld the sentence former Uber executive Joe Sullivan received after being convicted in an attempted coverup of a 2016 data breach at the company. |
Data Breach
|
Uber
|
★★★
|
 |
2025-03-13 05:06:14 |
Les nouvelles sombres du Kansas alors que le groupe médical de tournesol divulgue la violation des données Gloomy News from Kansas as Sunflower Medical Group Disclose Data Breach (lien direct) |
Sunflower Medical Group, basé au Kansas, a révélé aux autorités le 7 mars qu'ils avaient subi une violation de données compromettant les informations personnelles et confidentielles de 220 968 personnes. Dans une déclaration, leur site Web intitulé \\ 'Avis d'un incident de sécurité des données, \' Sunflower a fourni des détails sur l'attaque. Ils ont identifié à quel point c'était le 7 janvier 2025, lorsqu'ils [...]
Kansas-based Sunflower Medical Group disclosed to authorities on 7th March that they had suffered a data breach compromising the personal and confidential information of 220,968 individuals. In a statement on their website entitled \'Notice of a Data Security Incident,\' Sunflower provided details about the attack. They identified how it was on January 7, 2025, when they [...] |
Data Breach
Medical
|
|
★★★
|
 |
2025-03-12 11:48:08 |
Portail PowerSchool compromis des mois avant une violation de données massive PowerSchool Portal Compromised Months Before Massive Data Breach (lien direct) |
> Les pirates ont utilisé des informations d'identification compromises pour accéder au portail PowerSurce de PowerSchool \\ des mois avant la violation de données de décembre 2024.
>Hackers used compromised credentials to access PowerSchool\'s PowerSource portal months before the December 2024 data breach.
|
Data Breach
|
|
★★★★
|
 |
2025-03-11 16:30:00 |
New York poursuit Allstate sur la violation des données et les échecs de sécurité New York Sues Allstate Over Data Breach and Security Failures (lien direct) |
New York poursuit Allstate sur la violation des données, alléguant des échecs de sécurité qui ont exposé le nombre de licences du conducteur de près de 200 000 personnes
New York sues Allstate over data breach, alleging security failures that exposed the driver\'s license numbers of nearly 200,000 individuals |
Data Breach
|
|
★★
|
 |
2025-03-11 09:42:53 |
PowerSchool précédemment piraté en août, des mois avant la violation des données PowerSchool previously hacked in August, months before data breach (lien direct) |
PowerSchool a publié une enquête très attendue en crowdsstrike sur sa violation massive de données de décembre 2024, qui a déterminé que la société avait déjà été piratée plus de 4 mois plus tôt, en août, puis à nouveau en septembre. [...]
PowerSchool has published a long-awaited CrowdStrike investigation into its massive December 2024 data breach, which determined that the company was previously hacked over 4 months earlier, in August, and then again in September. [...] |
Data Breach
|
|
★★★
|
 |
2025-03-10 17:55:45 |
L'administration Trump termine le dossier de violation des données de Ransomware de FTC \\ contre MGM Resorts Trump administration ends FTC\\'s ransomware data breach case against MGM Resorts (lien direct) |
La Federal Trade Commission (FTC) a fermé son dossier contre MGM Resorts International a été centrée sur la gestion des données personnelles de la société volées lors d'une attaque de ransomware en 2023.
The Federal Trade Commission (FTC) shuttered its case against MGM Resorts International centered on the company\'s handling of personal data stolen during a 2023 ransomware attack. |
Ransomware
Data Breach
|
|
★★★
|
 |
2025-03-07 12:02:19 |
18 000 organisations touchées par la violation des données NTT COM 18,000 Organizations Impacted by NTT Com Data Breach (lien direct) |
> NTT Communications Corporation a divulgué une violation de données sur les informations de près de 18 000 organisations clients.
>NTT Communications Corporation has disclosed a data breach impacting the information of nearly 18,000 customer organizations.
|
Data Breach
|
|
★★
|
 |
2025-03-07 11:38:06 |
De nombreuses écoles signalent une violation des données après la société de services de retraite frappée par les ransomwares Many Schools Report Data Breach After Retirement Services Firm Hit by Ransomware (lien direct) |
> Des dizaines d'écoles et des milliers de personnes sont touchées par une violation de données résultant d'une attaque de ransomware contre Carruth Compliance Consulting.
>Dozens of schools and thousands of individuals are impacted by a data breach resulting from a ransomware attack on Carruth Compliance Consulting.
|
Ransomware
Data Breach
|
|
★★
|
 |
2025-03-07 08:48:21 |
Violation de données au géant des télécommunications japonais NTT frappe 18 000 entreprises Data breach at Japanese telecom giant NTT hits 18,000 companies (lien direct) |
Le fournisseur de services de télécommunications japonais NTT Communications Corporation (NTT) avertit près de 18 000 clients d'entreprise que leurs informations ont été compromises lors d'un incident de cybersécurité. [...]
Japanese telecommunication services provider NTT Communications Corporation (NTT) is warning almost 18,000 corporate customers that their information was compromised during a cybersecurity incident. [...] |
Data Breach
|
|
★★★
|
 |
2025-03-04 15:47:41 |
5 Questions d'entrevue pour poser des tests de pénétration 5 Interview Questions to Ask Penetration Testing Companies (lien direct) |
Si vous n'avez jamais connu de violation de données, considérez-vous chanceux. Si vous l'avez fait, vous savez que c'est un cauchemar absolu. Avec les cybercriminels à la recherche de vulnérabilités, une stratégie de cybersécurité forte est le meilleur moyen de lutter contre ces risques et de protéger votre intelligence critique.
If you\'ve never experienced a data breach, consider yourself lucky. If you have, you know it\'s an absolute nightmare. With cyber criminals looking for vulnerabilities, a strong cybersecurity strategy is the best way to combat these risks and protect your critical intelligence. |
Data Breach
Vulnerability
|
|
★★
|
 |
2025-03-03 11:20:00 |
Le courtier en stock indien Angel One révèle la violation des données Indian Stock Broker Angel One Discloses Data Breach (lien direct) |
> Angel One indique que les informations du client ont été compromises dans une violation de données impliquant son compte AWS.
>Angel One says client information was compromised in a data breach involving its AWS account.
|
Data Breach
|
|
★★★
|
 |
2025-03-03 09:30:12 |
Au-delà du périmètre: pourquoi l'échange de données de confiance zéro est essentiel pour la sécurité moderne Beyond the Perimeter: Why Zero Trust Data Exchange is Essential for Modern Security (lien direct) |
Le paysage des menaces de cybersécurité présente des défis de plus en plus désastreux pour les organisations du monde entier. Selon le coût en 2024 par IBM \\ d'un rapport de violation de données, le coût moyen mondial d'une violation de données a atteint un sommet de 4,88 millions de dollars, ce qui représente une augmentation de 15% au cours des trois dernières années. Cette même recherche révèle que les violations prennent maintenant [...]
The landscape of cybersecurity threats presents increasingly dire challenges for organisations worldwide. According to IBM\'s 2024 Cost of a Data Breach Report, the global average cost of a data breach has reached an all-time high of $4.88 million, representing a 15% increase over the past three years. This same research reveals that breaches now take [...] |
Data Breach
|
|
★★★
|
 |
2025-02-28 13:22:27 |
Dans d'autres nouvelles: Krispy Kreme Breach Cost, Pwn2own Berlin, Disney Hack Story In Other News: Krispy Kreme Breach Cost, Pwn2Own Berlin, Disney Hack Story (lien direct) |
> Des histoires remarquables qui auraient pu glisser sous le radar: la violation de données Krispy Kreme coûte 11 millions de dollars, Pwn2own déménage à Berlin, l'histoire du hack Disney 2024.
>Noteworthy stories that might have slipped under the radar: Krispy Kreme data breach costs $11M, Pwn2Own moves to Berlin, the story of the 2024 Disney hack.
|
Data Breach
Hack
|
|
★★★
|
 |
2025-02-27 13:44:03 |
Vos analyses de machines virtuelles testent-elles l'intégralité du réseau? Are Your VM Scans Testing the Entirety of the Network? (lien direct) |
De nombreuses organisations ont un problème de gestion de la vulnérabilité (VM) sans le savoir. La gestion de la vulnérabilité est une composante cruciale du programme de cybersécurité de toute organisation et est requise par la plupart des normes de conformité majeures en raison de son impact d'évier ou de swim sur la sécurité du réseau. L'un des plus grands problèmes de la machine virtuelle est que les organisations ne testent pas l'intégralité de leurs réseaux. Le vôtre pourrait-il être parmi eux? Nous savons déjà que l'exploitation de la vulnérabilité est en augmentation, avec une augmentation de près de 2023 à 2024 selon le dernier rapport d'enquête sur les violations de données de Verizon. Heureusement...
Many organizations have a vulnerability management (VM) problem without knowing it. Vulnerability management is a crucial component of any organization\'s cybersecurity program and is required by most major compliance standards because of its sink-or-swim impact on network security. One of the biggest issues in VM is that organizations aren\'t testing the entirety of their networks. Could yours be among them? We already know vulnerability exploitation is on the rise, with a nearly threefold increase from 2023 to 2024 according to the latest Verizon Data Breach Investigations Report. Luckily... |
Data Breach
Vulnerability
|
|
★★★
|
 |
2025-02-27 00:00:00 |
Industrie financière: Top Vulnérabilités en 2024 et ce qu'il faut surveiller en 2025 Finance industry: Top vulnerabilities in 2024 and what to watch for in 2025 (lien direct) |
Le secteur des services financiers continue d'être durement touché par des acteurs malveillants, le coût moyen d'une violation de données dans le secteur passant à 6,08 millions de dollars en 2024, contre 5,90 millions de dollars en 2023.
Étant donné que près de 1 entreprise financière sur 4 a été victime d'une violation de données, il n'est pas étonnant que cette industrie ait développé certaines des défenses les plus avancées pour sauvegarder I…
The financial services industry continues to be hit hard by malicious actors, with the average cost of a data breach in the sector increasing to $6.08 million in 2024, up from $5.90 million in 2023.
Given that nearly 1 in 4 financial businesses have fallen victim to a data breach, it\'s no wonder that this industry has developed some of the most advanced defenses to safeguard i… |
Data Breach
Vulnerability
|
|
★★★
|
 |
2025-02-26 16:00:00 |
DISA Global Solutions confirme la violation des données affectant 3,3 millions de personnes DISA Global Solutions Confirms Data Breach Affecting 3.3M People (lien direct) |
DISA Global Solutions confirme la violation des données affectant 3,3 millions de personnes, exposant des informations personnelles sensibles
DISA Global Solutions confirms data breach affecting 3.3M people, exposing sensitive personal info |
Data Breach
|
|
★★★
|
 |
2025-02-26 11:00:00 |
3,3 millions de personnes touchées par la violation des données DISA 3.3 Million People Impacted by DISA Data Breach (lien direct) |
> Le géant du dépistage des antécédents et des médicaments DISA a révélé qu'une violation de données de 2024 a un impact sur plus de 3,3 millions de personnes.
>Background and drug screening giant DISA has revealed that a 2024 data breach impacts more than 3.3 million people.
|
Data Breach
|
|
★★★
|
 |
2025-02-26 10:25:35 |
La vérification des antécédents des États-Unis est la violation des données de l'entreprise expose les enregistrements de 3,3 millions US Background Check Firm Data Breach Exposes 3.3M Records (lien direct) |
Une violation de données chez DISA Global Solutions, une entreprise fournissant des vérifications des antécédents et des services de test de drogues et d'alcool,…
A data breach at DISA Global Solutions, a firm providing background checks, and drugs and alcohol testing services,… |
Data Breach
|
|
★★★
|
 |
2025-02-25 22:27:04 |
Orange Group confirme la violation des données après la fuite Orange Group Confirms Data Breach After Leak (lien direct) |
Orange Group, l'un des principaux opérateurs de télécommunications et fournisseurs de services numériques de France, a confirmé une violation de données suite à la fuite en ligne d'un pirate de documents de l'entreprise.
Cela soulève des préoccupations concernant la sécurité des informations confidentielles commerciales et des risques potentiels pour les employés et les clients.
Le pirate, qui utilise l'alias Rey et est membre du Hellcat Ransomware Group, a affirmé sur un forum de piratage que les données volées proviennent principalement d'Orange Roumanie, la succursale régionale d'une entreprise.
De plus, Rey prétend avoir volé environ 6,5 Go de données de près de 12 000 fichiers en compromettant les systèmes d'Orange \\ en utilisant des informations d'identification et des vulnérabilités volées dans le logiciel JIRA de la société \\ pour le suivi des bogues / problèmes et d'autres portails internes .
Les données volées comprennent 380 000 adresses e-mail uniques, codes source, factures, contrats, informations sur les clients et les employés, les détails de la carte de paiement partiel des clients roumains, et les adresses e-mail et les noms des clients Yoxo, le service par abonnement d'Orange \\ . Après avoir tenté d'extorquer sans succès le groupe Orange, le pirate a publié publiquement des informations sur les données volées sur un forum de pirate.
dans une déclaration à BleepingComputer , le pirate a précisé qu'ils avaient violé l'orange indépendamment et qu'il ne s'agissait pas d'une opération de ransomware HellCat. Ils ont ajouté qu'ils avaient accès aux systèmes d'Orange \\ pendant plus d'un mois avant d'effectuer l'exfiltration des données.
Dimanche matin, le pirate a passé trois heures à extraire les données de l'entreprise sans être détectée par les systèmes de sécurité d'Orange.
Ils ont également affirmé avoir laissé une note de rançon sur le système compromis, mais Orange n'a pas répondu aux négociations.
Rey a partagé quelques échantillons avec BleepingComputer , qui comprenait des adresses e-mail assez anciennes d'anciens et actuels employés, partenaires et entrepreneurs d'Orange Roumanie. Les données contenaient également les détails de la carte de paiement partiel des clients roumains, mais beaucoup avaient déjà expiré. De plus, la fuite comprenait des adresses e-mail et des noms des clients Yoxo.
Orange Group a reconnu la violation dans une déclaration officielle et a déclaré qu'elle s'était produite sur une demande non critique. La société a ajouté qu'elle avait lancé une enquête pour déterminer le plein impact de l'incident et que les opérations des clients ne restent pas affectées.
«L'orange peut confirmer que nos opérations en Roumanie ont été la cible d'une cyberattaque. Nous avons pris des mesures immédiates, et notre priorité absolue demeure la protection des données et des intérêts de nos employés, clients et partenaires. Il n'y a eu aucun impact sur les opérations des clients, et la violation s'est avérée se produire sur une demande de back-office non critique », a déclaré Orange Group dans un communiqué.
La société a également ajouté que leurs «équipes informatiques de cybersécurité et informatique travaillent dur pour évaluer l'étendue de la violation et minimiser l'impact de cet incident».
Le communiqué a en outre indiqué: «Nous nous engageons à fournir des mises à jour régulières. De plus, nous nous engageons à nous conformer à toutes les obligations légales associées à de tels incidents et nous coopérons avec les aut |
Ransomware
Data Breach
Vulnerability
|
|
★★★★
|
 |
2025-02-25 17:07:50 |
Ai-je été pwned ajoute 284 millions de comptes volés par des logiciels malveillants infosiner Have I Been Pwned adds 284M accounts stolen by infostealer malware (lien direct) |
Le service de notification de violation de données a-je été-je ajouté plus de 284 millions de comptes volés par des logiciels malveillants d'information et trouvé sur un canal télégramme. [...]
The Have I Been Pwned data breach notification service has added over 284 million accounts stolen by information stealer malware and found on a Telegram channel. [...] |
Data Breach
Malware
|
|
★★★
|
 |
2025-02-25 15:04:57 |
Vérification des antécédents et fournisseur de tests de dépistage des drogues Disa Global Solutions rapporte la violation des données Background check and drug testing provider DISA Global Solutions reports data breach (lien direct) |
La société de dépistage des employés basée à Houston, Disa Global Solutions, affirme qu'une violation de données en 2024 a exposé les informations de plus de 3,3 millions de personnes.
Houston-based employee screening company DISA Global Solutions says a 2024 data breach exposed the information of more than 3.3 million people. |
Data Breach
|
|
★★★
|
 |
2025-02-25 11:44:33 |
La société de dépistage de drogues américaine dit que la violation des données a un impact sur 3,3 millions de personnes US drug testing firm DISA says data breach impacts 3.3 million people (lien direct) |
DISA Global Solutions, une entreprise de dépistage des antécédents américains et de test de drogue et d'alcool, a subi une violation de données ayant un impact sur 3,3 millions de personnes. [...]
DISA Global Solutions, a leading US background screening and drug and alcohol testing firm, has suffered a data breach impacting 3.3 million people. [...] |
Data Breach
|
|
★★
|
 |
2025-02-23 15:36:03 |
La violation des données de la maison intelligente expose 2,7 milliards d'enregistrements Smart Home Data Breach Exposes 2.7 Billion Records (lien direct) |
> Mars Hydro, une entreprise chinoise qui fabrique des appareils IoT comme les lumières LED et les équipements hydroponiques, a récemment subi une violation de données massive, exposant environ 2,7 milliards de dossiers. Cette violation a soulevé de sérieuses préoccupations concernant la sécurité des appareils connectés à Internet et les risques potentiels pour les consommateurs. Appareils à domicile intelligents, y compris les caméras de sécurité, les verrous intelligents et les assistants vocaux,…
>Mars Hydro, a Chinese company that makes IoT devices like LED lights and hydroponics equipment, recently suffered a massive data breach, exposing approximately 2.7 billion records. This breach has raised serious concerns about the security of internet-connected devices and the potential risks for consumers. Smart home devices, including security cameras, smart locks, and voice assistants, …
|
Data Breach
|
|
★★★
|
 |
2025-02-19 22:59:17 |
Insight Partners, VC Giant, Falls to Social Engineering (lien direct) |
The startup incubator and PR firm with holdings in more than 70 cybersecurity firms has announced a data breach with as-yet-unknown effects.
The startup incubator and PR firm with holdings in more than 70 cybersecurity firms has announced a data breach with as-yet-unknown effects. |
Data Breach
|
|
★★★
|
 |
2025-02-19 16:30:00 |
Finastra Notifies Customers of Data Breach (lien direct) |
Finastra notifies customers of data breach that took place more than three months ago, impacting sensitive financial information
Finastra notifies customers of data breach that took place more than three months ago, impacting sensitive financial information |
Data Breach
|
|
★★★
|
 |
2025-02-19 14:15:00 |
Australian IVF Clinic Suffers Data Breach Following Cyber Incident (lien direct) |
Australia-based Genea said it is investigating the cyber incident to determine whether any personal data was accessed by an unauthorized third party
Australia-based Genea said it is investigating the cyber incident to determine whether any personal data was accessed by an unauthorized third party |
Data Breach
|
|
★★
|
 |
2025-02-18 13:45:04 |
5 Ways Companies Safeguard Their Crown Jewels Of Data (lien direct) |
>This week in cybersecurity from the editors at Cybercrime Magazine –Read the Full Story in Forbes Sausalito, Calif. – Feb. 18, 2025 Data loss is becoming a bigger danger for businesses, both financially and numerically. According to an IBM report, the average data breach now often
>This week in cybersecurity from the editors at Cybercrime Magazine –Read the Full Story in Forbes Sausalito, Calif. – Feb. 18, 2025 Data loss is becoming a bigger danger for businesses, both financially and numerically. According to an IBM report, the average data breach now often
|
Data Breach
|
|
★★★
|
 |
2025-02-18 13:36:28 |
Finastra Starts Notifying People Impacted by Recent Data Breach (lien direct) |
>Financial software firm Finastra is notifying individuals whose personal information was stolen in a recent data breach.
>Financial software firm Finastra is notifying individuals whose personal information was stolen in a recent data breach.
|
Data Breach
|
|
★★★
|
 |
2025-02-18 11:14:41 |
Phishing Beyond Email: How Proofpoint Collab Protection Secures Messaging and Collaboration Apps (lien direct) |
Today\'s organizations are embracing messaging and collaboration tools to enhance productivity and connect distributed teams like never before. Just as quickly, cybercriminals are adapting and learning to exploit these new entry points. Instead of just email-based threats, bad actors are now targeting these platforms with attacks like phishing, malware and account takeovers.
To stay ahead of evolving threats, organizations need to protect their messaging and collaboration platforms with the same level of detection efficacy that they use for email. That\'s where Proofpoint Collab Protection can help.
The new cyber battleground: messaging and collaboration platforms
It might surprise you to learn that collaboration and messaging platforms don\'t have native security capabilities. So, they\'re unable to inspect or detect malicious URLs or block phishing attacks. In other words, your people and business are at risk if they use any of these platforms:
Messaging, like Messenger, WhatsApp, Snapchat
Collaboration, like Microsoft Teams, Slack, Zoom
Social media, like LinkedIn, Instagram, Facebook, Twitter/X
Cybercriminals exploit this opportunity by using these platforms as launchpads to send a variety of threats. Unfortunately, employees fall prey to these attacks for several reasons.
For starters, employees tend to trust internal collaboration tools more than email because they assume that messages are being sent by verified colleagues. Attackers exploit this trust. Take Microsoft Teams as an example. Bad actors might use Teams to impersonate an executive to direct an employee to use a fraudulent invoice payment portal.
Another issue is that, unlike email, messaging apps also encourage instant responses. Attackers use this to create a sense of urgency, pressuring victims into acting without verifying links or requests. They might ask employees to send payments, share their credentials or click a malicious URL. For example, a threat actor could use Messenger to impersonate the HR department, telling an employee to update their banking information immediately to avoid missing the next pay cycle.
How cybercriminals weaponize messaging and collaboration tools
Here\'s what the typical attack chain looks like for messaging or collaboration apps:
Stages in the attack chain for messaging and collaboration apps.
The most prevalent method for delivering payloads is malicious URLs. In the past three years, Proofpoint Threat Research has observed an alarming 2,524% increase in URL threats through SMS-based phishing (smishing). Compare that to threats delivered by email, which went up by only 119%.
With more exposure to risk, companies are more vulnerable to cyberattacks. And the consequences of those attacks can be severe. In 2024, the average cost of a single attack reached $4.88 million, according to the IBM Cost of a Data Breach Report.
Closing the gaps: how to secure your messaging and collaboration ecosystem
Proofpoint Collab Protection extends phishing protection against malicious URLs delivered via any messaging, collaboration or social media platforms. Powered by our industry-leading Nexus Threat Intel, it provides real-time URL reputation inspection and analysis as well as the ability to block malicious URLs at click-time. As attackers\' tactics evolve, Collab Protection will use more parts of the Nexus detection ensemble over time. This will ensure that your users are protected anywhere, anytime from advanced phishing attacks.
Protect people from malicious URLs
Collab Protection is powered by our industry-leading threat intelligence. It inspects and analyzes the reputation of URLs in real-time, and it can block malicious URLs at click-time.
Here\'s how it works. When an employee clicks on a suspicious link that\'s shared in a messaging or collaboration app, Collab Protection automatically evaluates how safe the link is. It does |
Data Breach
Malware
Tool
Threat
Mobile
|
|
★★★
|
 |
2025-02-18 10:01:27 |
Fintech giant Finastra notifies victims of October data breach (lien direct) |
Financial technology giant Finastra is notifying victims of a data breach after their personal information was stolen by unknown attackers who first breached its systems in October 2024. [...]
Financial technology giant Finastra is notifying victims of a data breach after their personal information was stolen by unknown attackers who first breached its systems in October 2024. [...] |
Data Breach
|
|
★★★
|
 |
2025-02-13 19:17:35 |
Doxbin Data Breach: Hackers Leak 136K User Records and Blacklist File (lien direct) |
Doxbin Data Breach: Hackers leak 136,000+ user records, emails, and a \'blacklist\' file, exposing those who paid to…
Doxbin Data Breach: Hackers leak 136,000+ user records, emails, and a \'blacklist\' file, exposing those who paid to… |
Data Breach
|
|
★★★
|
 |
2025-02-13 12:39:36 |
Hacker leaks account data of 12 million Zacks Investment users (lien direct) |
Zacks Investment Research (Zacks) last year reportedly suffered another data breach that exposed sensitive information related to roughly 12 million accounts. [...]
Zacks Investment Research (Zacks) last year reportedly suffered another data breach that exposed sensitive information related to roughly 12 million accounts. [...] |
Data Breach
|
|
★★★
|
 |
2025-02-13 04:59:12 |
Have I Been Pwned likely to ban resellers from buying subs, citing \\'shitty behavior\\' and onerous support requests (lien direct) |
\'What are customers actually getting from resellers other than massive price markups?\' asks Troy Hunt Troy Hunt, proprietor of data breach lookup site Have I Been Pwned, is likely to ban resellers from the service.…
\'What are customers actually getting from resellers other than massive price markups?\' asks Troy Hunt Troy Hunt, proprietor of data breach lookup site Have I Been Pwned, is likely to ban resellers from the service.… |
Data Breach
|
|
★★★
|
 |
2025-02-12 21:31:54 |
“Largest data breach in US history”: Three more lawsuits try to stop DOGE (lien direct) |
DOGE and Musk face three more lawsuits over "brazen ransacking" of private data.
DOGE and Musk face three more lawsuits over "brazen ransacking" of private data. |
Data Breach
|
|
★★★
|
 |
2025-02-12 14:30:00 |
Exclusive: Massive IoT Data Breach Exposes 2.7 Billion Records (lien direct) |
Massive IoT data breach exposed 2.7 billion records including Wi-Fi credentials
Massive IoT data breach exposed 2.7 billion records including Wi-Fi credentials |
Data Breach
|
|
★★★
|
 |
2025-02-11 15:56:56 |
Cisco Rejects Kraken Ransomware\\'s Data Breach Claims (lien direct) |
Cisco denies recent data breach claims by the Kraken ransomware group, stating leaked credentials are from a resolved 2022 incident. Learn more about Cisco\'s response and the details of the original attack.
Cisco denies recent data breach claims by the Kraken ransomware group, stating leaked credentials are from a resolved 2022 incident. Learn more about Cisco\'s response and the details of the original attack. |
Ransomware
Data Breach
|
|
★★
|
 |
2025-02-10 16:30:00 |
Georgia Hospital Alerts 120,000 Individuals of Data Breach (lien direct) |
Memorial Hospital and Manor, located in Bainbridge, Georgia, has alerted 120,000 individuals that their data was breached following a ransomware attack last November
Memorial Hospital and Manor, located in Bainbridge, Georgia, has alerted 120,000 individuals that their data was breached following a ransomware attack last November |
Ransomware
Data Breach
|
|
★★★
|
 |
2025-02-10 16:21:55 |
Handala Hackers Claim Massive Data Breach on Israeli Police, Leak 350,000 Files (lien direct) |
Iranian-linked hackers claim to have breached Israeli police systems, stealing 2.1TB of sensitive data. Police deny the breach. Learn more about the alleged hack and its implications.
Iranian-linked hackers claim to have breached Israeli police systems, stealing 2.1TB of sensitive data. Police deny the breach. Learn more about the alleged hack and its implications. |
Data Breach
Hack
Legislation
|
|
★★★
|
 |
2025-02-10 13:53:25 |
10th February – Threat Intelligence Report (lien direct) |
>For the latest discoveries in cyber research for the week of 10th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Grubhub, the US-based online food ordering and delivery platform, suffered a data breach due to unauthorized access through a compromised third-party service provider\'s account. The incident exposed personal details of customers, drivers, […]
>For the latest discoveries in cyber research for the week of 10th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Grubhub, the US-based online food ordering and delivery platform, suffered a data breach due to unauthorized access through a compromised third-party service provider\'s account. The incident exposed personal details of customers, drivers, […]
|
Data Breach
Threat
|
|
★★★
|
 |
2025-02-10 02:30:15 |
DeepSeek\\'s iOS app is a security nightmare, and that\\'s before you consider its TikTok links (lien direct) |
PLUS: Spanish cops think they\'ve bagged NATO hacker; HPE warns staff of data breach; Lazy Facebook phishing, and more! Infosec In Brief DeepSeek\'s iOS app is a security nightmare that you should delete ASAP, according to researchers at mobile app infosec platform vendor NowSecure.…
PLUS: Spanish cops think they\'ve bagged NATO hacker; HPE warns staff of data breach; Lazy Facebook phishing, and more! Infosec In Brief DeepSeek\'s iOS app is a security nightmare that you should delete ASAP, according to researchers at mobile app infosec platform vendor NowSecure.… |
Data Breach
Mobile
|
|
★★★
|
 |
2025-02-07 20:43:54 |
Label maker Avery says ransomware investigation also found credit-card scraper (lien direct) |
An investigation into a ransomware attack led label-maker Avery Products to also find malware that was skimming credit card details from transactions on its website, according to a data breach notification by the company.
An investigation into a ransomware attack led label-maker Avery Products to also find malware that was skimming credit card details from transactions on its website, according to a data breach notification by the company. |
Ransomware
Data Breach
Malware
|
|
★★★
|
 |
2025-02-07 14:21:16 |
HPE notifies employees of data breach after Russian Office 365 hack (lien direct) |
Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company\'s Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack. [...]
Hewlett Packard Enterprise (HPE) is notifying employees whose data was stolen from the company\'s Office 365 email environment by Russian state-sponsored hackers in a May 2023 cyberattack. [...] |
Data Breach
Hack
|
|
★★★
|
 |
2025-02-07 11:44:32 |
US health system notifies 882,000 patients of August 2023 breach (lien direct) |
Hospital Sisters Health System notified over 882,000 patients that an August 2023 cyberattack led to a data breach that exposed their personal and health information. [...]
Hospital Sisters Health System notified over 882,000 patients that an August 2023 cyberattack led to a data breach that exposed their personal and health information. [...] |
Data Breach
|
|
★★
|
 |
2025-02-06 19:41:51 |
OpenAI Data Breach: Threat Actor Allegedly Claims 20 Million Logins for Sale (lien direct) |
An anonymous threat actor has allegedly claimed responsibility for a massive data breach affecting OpenAI, offering for sale a database containing the login credentials of 20 million users on the dark web.
The unverified claim that surfaced on an underground hacking forum has raised concerns about data security for millions of users relying on OpenAI’s services.
The threat actor alleges they have access to a trove of login credentials, including emails and hashed passwords, purportedly sourced from OpenAI\'s user accounts.
To promote their discovery, they shared a post with a sample of the data and more being offered for a few dollars.
”When I realized that OpenAI might have to verify accounts in bulk, I understood that my password wouldn\'t stay hidden. I have more than 20 million access codes to OpenAI accounts. If you want, you can contact me – this is a treasure, and Jesus thinks so too,” reads the post by the threat actor on the hacker forum, which was shared by HackManac.
OpenAI and independent cybersecurity firms have neither officially confirmed nor denied the threat actor\'s claims.
If proven true, this breach would be one of the largest data leaks related to OpenAI and could also lead to phishing attacks, unauthorized access, and identity theft.
While the authenticity of the breach remains unconfirmed, OpenAI users should remain vigilant and prioritize digital security measures.
They are advised to take precautionary measures such as updating OpenAI passwords and avoiding using the same password across multiple sites, enabling two-factor authentication (2FA), and monitoring accounts linked to OpenAI for unusual login attempts or password reset requests.
Whether this is a legitimate breach or an elaborate hoax, the incident serves as a stark reminder of the persistent threats in the digital realm.
This is a developing story; updates will follow as new information emerges.
An anonymous threat actor has allegedly claimed responsibility for a massive data breach affecting OpenAI, offering for sale a database containing the login credentials of 20 million users on the dark web.
The unverified claim that surfaced on an underground hacking forum has raised concerns about data security for millions of users relying on OpenAI’s services.
The threat actor alleges they have access to a trove of login credentials, including emails and hashed passwords, purportedly sourced from OpenAI\'s user accounts.
To promote their discovery, they shared a post with a sample of the data and more being offered for a few dollars.
”When I realized that OpenAI might have to verify accounts in bulk, I understood that my password wouldn\'t stay hidden. I have more than 20 million access codes to OpenAI accounts. If you want, you can contact me – this is a treasure, and Jesus thinks so too,” reads the post by the threat actor on the hacker forum, which was shared by HackManac.
OpenAI and independent cybersecurity firms have neither officially confirmed nor denied the threat actor\'s claims.
If proven true, this breach would be one of the largest data leaks related to OpenAI and could also lead to phishing attacks, unauthorized access, and identity theft.
While the authenticity of the breach remains unconfirmed, OpenAI users should remain vigilant and prioritize digital security measures.
They are advised to take precautionary measures such as updating OpenAI passwords and avoiding using the same password across multiple sites, enabling two-factor authentication (2FA), and monitoring accounts linked to OpenAI for unusual login attempts or password reset requests.
Whether this is a legitimate breach or an elaborate hoax, the incident serves as a stark reminder of the persistent threats in the digital realm.
This is a developing story; updates will follow as new information emerges.
|
Data Breach
Threat
|
|
★★★
|
 |
2025-02-05 20:12:48 |
Thousands of McKinney, Texas, residents impacted by October data breach (lien direct) |
The Dallas suburb said its government systems were breached on October 31 but security systems only discovered the incident two weeks later.
The Dallas suburb said its government systems were breached on October 31 but security systems only discovered the incident two weeks later. |
Data Breach
|
|
★★★
|