Security News

Crypto exchange Gemini discloses third-party data breach
2024-07-26 19:31

Cryptocurrency exchange Gemini is warning it suffered a data breach incident caused by a cyberattack at its Automated Clearing House service provider, whose name was not disclosed. According to the notification, Gemini suffered a third-party data breach when an unauthorized actor breached its vendor's systems between June 3 and June 7, 2024.

FBCS data breach impact now reaches 4.2 million people
2024-07-26 18:47

Debt collection agency Financial Business and Consumer Solutions has again increased the number of people impacted by a February data breach, now saying it affects 4.2 million people in the US. FBCS is a US debt collection agency that collects unpaid debts from consumer credit, healthcare, commercial, auto loans and leases, student loans, and utilities. In late April, the firm reported that roughly 1.9 million people in the U.S. had sensitive personal information compromised in a data breach on February 14, 2024.

Verizon to pay $16 million in TracFone data breach settlement
2024-07-23 16:34

Verizon Communications has agreed to a $16,000,000 settlement with the Federal Communications Commission (FCC) in the U.S. concerning three data breach incidents its wholly-owned subsidiary,...

WazirX Cryptocurrency Exchange Loses $230 Million in Major Security Breach
2024-07-19 04:07

"A cyber attack occurred in one of our wallets involving a loss of funds exceeding $230 million," the company said in a statement. The Mumbai-based company said the attack stemmed from a mismatch between the information that was displayed on Liminal's interface and what was actually signed.

Yacht giant MarineMax data breach impacts over 123,000 people
2024-07-17 14:37

MarineMax, self-described as the world's largest recreational boat and yacht retailer, is notifying over 123,000 individuals whose personal information was stolen in a March security breach claimed by the Rhysida ransomware gang. While the Florida-based yacht seller initially stated in a March 12 SEC filing that no sensitive data was stored on the compromised systems, two weeks later, it said in a new 8-K filing that the attackers had stolen personal data belonging to an undisclosed number of people.

Rite Aid says June data breach impacts 2.2 million people
2024-07-16 14:54

In data breach notification letters filed with the Office of Maine's Attorney General, Rite Aid said it detected the incident on June 6, 12 hours after the attackers breached its network using an employee's credentials.Just as it told BleepingComputer when it first confirmed the data breach on Friday, Rote Aid added that the customers' Social Security numbers, financial information, or health information were not exposed in the incident.

I spy another mSpy breach: Millions more stalkerware buyers exposed
2024-07-15 02:01

Infosec in brief Commercial spyware maker mSpy has been breached - again - and millions of purchasers can be identified from the spilled records. "Comprising 142GB of user data and support tickets along with 176GB of more than half a million attachments, the data contained 2.4M unique email addresses, IP addresses names and photos," the mSpy entry on Have I Been Pwned reads.

Week in review: RADIUS protocol critical vuln, Microsoft 0-day exploited for a year, AT&T breach
2024-07-14 08:00

Critical vulnerability in the RADIUS protocol leaves networking equipment open to attackA new critical security vulnerability in the RADIUS protocol, dubbed BlastRADIUS, leaves most networking equipment open to Man-in-the-Middle attacks. Zero-day patched by Microsoft has been exploited by attackers for over a yearCVE-2024-38112, a spoofing vulnerability in Windows MSHTML Platform for which Microsoft has released a fix on Tuesday, has likely been exploited by attackers in the wild for over a year, Check Point researcher Haifei Li has revealed.

AT&T Confirms Data Breach Affecting Nearly All Wireless Customers
2024-07-13 05:51

American telecom service provider AT&T has confirmed that threat actors managed to access data belonging to "Nearly all" of its wireless customers as well as customers of mobile virtual network operators using AT&T's wireless network. This comprises telephone numbers with which an AT&T or MVNO wireless number interacted - including telephone numbers of AT&T landline customers and customers of other carriers, counts of those interactions, and aggregate call duration for a day or month.

Rite Aid confirms data breach after June ransomware attack
2024-07-12 18:49

Pharmacy giant Rite Aid confirmed a data breach after suffering a cyberattack in June, which was claimed by the RansomHub ransomware operation. The company told BleepingComputer on Friday that it's currently investigating a cyberattack detected in June and working on sending data breach notifications to customers affected by the resulting data breach.