<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/data-breaches" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Data-breaches ]]></title>
                <link>https://www.itpro.com/security/data-breaches</link>
        <description><![CDATA[ All the latest data-breaches content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 21 Jul 2026 07:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Businesses need to boost cyber resilience, here’s how ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how</link>
                                                                            <description>
                            <![CDATA[ The government’s recently released Cyber Security Breaches Survey shows gaps in firms’ cyber resilience. How can companies improve their approach? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WRPWhjrazx9Ks6gAAq7QNX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Jul 2026 17:43:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber attacks are still hitting businesses, despite increasing awareness following high-profile incidents such as the <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-u-turns-on-cyber-attack-containment-claims-admits-some-data-has-been-affected"><u>Jaguar Land Rover (JLR)</u></a> and <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-customer-personal-data-stolen"><u>Marks and Spencer (M&S)</u></a> breaches. </p><p>According to the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026" target="_blank"><u>Cyber Security Breaches Survey</u></a>, four in 10 businesses (43%) and three in ten charities (28%) fell victim to attacks in 2025.</p><p>The problem has not improved over the last year, with cybersecurity minister Liz Lloyd issuing a <a href="https://www.itpro.com/security/depressingly-familiar-cyber-security-breaches-survey-shows-work-still-to-be-done-on-cyber-preparedness"><u>warning</u></a> that business leaders must take action now to ensure robust security.</p><p>Regulations such as the incoming UK <a href="https://www.gov.uk/government/collections/cyber-security-and-resilience-bill" target="_blank"><u>Cyber Security and Resilience Bill</u></a> mandate that resilience is baked into organizations and their supply chains. How can firms boost cyber resilience as the risk of attack surges?</p><h2 id="resilience-gaps">Resilience gaps</h2><p>The price of failing to be resilient is already clear. The JLR attack <a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre"><u>cost</u></a> the business and its partners up to £1.9 billion, while it’s estimated the M&S breach <a href="https://www.bbc.co.uk/news/articles/c93x16zkl9do" target="_blank"><u>cost</u></a> the company over £100 million.</p><p>These headlines are difficult to ignore. Yet despite growing awareness of cyber risk following the incidents, many organizations are still struggling to translate awareness into “meaningful resilience improvements”, says Chris Brown, SVP UK market leader at NCC Group.</p><p>This is partly due to over-confidence in cybersecurity, which is leading businesses into “an under-preparation trap”, according to Brown. </p><p>“The growing interconnectedness of digital systems and third-party suppliers means leaders face an increasingly complex landscape of vulnerabilities and cyber risks, often without clear visibility of where their greatest exposures lie – or how to begin addressing them.”</p><p>The Cyber Security Breaches Survey also identified persistent resilience gaps linked to the rapid adoption of <a href="https://www.itpro.com/uk/technology/artificial-intelligence"><u>AI</u></a> without adequate governance or security controls. </p><p>“While board-level engagement with cyber risk is increasing, stronger operational action remains essential,” says Brown. </p><h2 id="pace-of-change">Pace of change</h2><p>Technology such as AI does have the potential to help boost productivity and improve security, but the pressure to adopt it quickly can lead firms to take unnecessary risks. The pace of change is one of the biggest challenges facing businesses, according to Rob O’Connor, Insight's <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>for EMEA.</p><p>“Organizations are under pressure to adopt technologies such as AI to improve efficiency, reduce costs and create new ways of working, but every new capability introduces new risks too,” he says. </p><p>The challenge, O’Connor adds, is implementing change securely, and doing so at a pace that keeps up with the wider business. </p><p>Company culture is another problem. One of the biggest barriers is that many firms still treat cybersecurity as a “specialist technical function” rather than a “core business resilience issue”, says Scott Beange, head of cyber strategy at Projective Group.</p><p>“Boards often receive large volumes of cyber reporting and compliance metrics, but relatively little clarity around operational survivability, recovery capability or dependency risk.”</p><p>The issue is made worse by a growing disconnect between modern digital ecosystems and traditional governance approaches, according to Beange. </p><p>“Organizations are now heavily reliant on cloud providers, <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas"><u>Software as a Service (SaaS)</u></a> platforms, managed services and interconnected supply chains. In many cases, firms no longer fully understand where their operational dependencies sit until disruption occurs.”</p><p>At the same time, attackers are increasingly targeting the areas organizations struggle to rehearse properly: Recovery processes and operational coordination under stress, says Beange. “Too many businesses still test intrusion prevention far more rigorously than degraded operations or prolonged recovery conditions.”</p><h2 id="regulation-resilience">Regulation resilience </h2><p>It comes at a time when regulations such as the European Union's <a href="https://www.itpro.com/security/digital-operational-resilience-act-dora"><u>Digital Operational Resilience Act (DORA)</u></a> and the UK’s <a href="https://www.gov.uk/government/collections/cyber-security-and-resilience-bill" target="_blank"><u>Cyber Security and Resilience legislation</u></a> are mandating resilience across the board.</p><p>At the EU level, a proposed update to the <a href="https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-act" target="_blank"><u>EU Cybersecurity Act</u></a> seeks to address fragmentation in requirements under the <a href="https://www.itpro.com/business/policy-legislation/370403/what-is-the-network-and-information-security-2-nis2-directive"><u>Network and Information Systems 2 Directive (NIS2)</u></a> and EU-wide certification schemes. </p><p>“But even with a more coherent framework including outcome-focused minimum standards and technical criteria, global organizations must still navigate evolving regulatory expectations across multiple jurisdictions,” Brown warns.</p><p>AI adoption is also mandating resilience, Brown points out. However, rather than introducing entirely new legislation to ensure secure and responsible AI adoption, states are weaving it into existing sector regulation, he says. He cites the example of the UK’s Online Safety Act, which is being <a href="https://www.gov.uk/government/news/pm-no-platform-gets-a-free-pass-government-takes-action-to-keep-children-safe-online" target="_blank"><u>amended</u></a> to close loopholes for chatbot providers.</p><h2 id="steps-to-boost-resilience">Steps to boost resilience </h2><p>With so many factors at play, it might seem complex, but there are a number of steps businesses can take to boost resilience now. </p><p>A “small set of controls taken together” will “eliminate the majority of preventable incidents”, according to Kevin Curran, senior IEEE member and professor of cybersecurity at Ulster University.</p><p>The starting point is <a href="https://www.itpro.com/security/what-businesses-need-to-know-about-the-update-to-cyber-essentials" target="_blank"><u>Cyber Essentials</u></a> Plus, he says. “It is not glamorous, but it forces patching discipline, <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>multi-factor authentication (MFA</u></a>), access control and boundary firewalling, and it is already a precondition for many public sector contracts, so the cost is recoverable."</p><p>From there, the “single highest-value technical investment” is phishing-resistant MFA such as hardware security keys or platform passkeys on every privileged account, he says. </p><p>Beyond identity, firms should segment their networks, particularly between IT and operational technology environments, says Curran. </p><p>“A compromised office laptop should never be able to reach a production line controller, and yet in many manufacturing firms it still can.”</p><p>Alongside segmentation sits the discipline of tested backups, Curran adds. He advocates the <a href="https://www.uschamber.com/co/run/technology/3-2-1-backup-rule" target="_blank"><u>3-2-1 rule</u></a>, “with at least one copy offline or immutable, and a restore rehearsed at least quarterly”.</p><p>Beange recommends making an effort to understand critical business services and the dependencies that underpin them. </p><p>“Firms should be regularly testing how they would operate under degraded conditions as rigorously as whether their security controls detect attacks.”</p><p>Boards should also demand clearer reporting focused on operational impact and decision-making rather than excessive technical detail, says Beange. </p><p>Questions such as, “how long could we operate without this supplier?”, or “what happens if identity systems fail for 48 hours?” are often more valuable than “another dashboard full of vulnerability statistics”, he advises.</p><p>O'Connor concurs that cyber resilience starts with understanding what matters most to your business, saying “Organizations should think like an attacker and ask: What are the assets or operations we simply cannot afford to lose?”</p><p>For some organizations, that may be customer data, for others intellectual property, or production systems, explains O’Connor. “Once you understand what would have the biggest operational and financial impact, security priorities become much clearer.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/health-tech-firm-craneware-admits-significant-volume-of-customer-and-employee-data-exposed-in-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ The incident has been contained and Craneware has launched a probe into the breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">b7PjqdeyzkrQRdNTGxjRvj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:38:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Scottish health tech company Craneware has revealed customer and employee data has been exposed in a “security incident”. </p><p>In a <a href="https://www.londonstockexchange.com/news-article/CRW/notice-of-cyber-security-incident/17694735" target="_blank"><u>notice </u></a>filed with the London Stock Exchange (LSEG) on 20 July, the company said it had launched an investigation into the attack, which has now been contained. </p><p>“The company's incident response plan has been activated, including the appointment by the Board of external cybersecurity and forensic specialists,” the advisory reads. </p><p>“Their investigation is ongoing, alongside the Craneware IT team and the Company's retained cyber security service providers. There has been no disruption to customer services or to the company’s operations.”</p><p>A preliminary investigation into the breach found that a “significant volume” of file names was viewed and exfiltrated by unauthorized individuals, although the company noted these weren’t sensitive and were already publicly available. </p><p>“A percentage of employee data as well as a subset of customer and partner records have been accessed and exfiltrated,” Craneware added. </p><p>Craneware  has since notified relevant regulators and law enforcement agencies, including the UK <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a> and the FBI. </p><p>The Edinburgh-headquartered company provides accounting and billing software for US healthcare operators, partnering with around 2,000 hospitals across the country. </p><p>This makes it a prime target for cyber criminals, according to Trevor Dearing, director of critical infrastructure at Illumio. </p><p>“Healthcare technology providers have become prime targets because they offer cybercriminals a shortcut into the healthcare supply chain,” he said. “Why target one hospital when you can target a provider connected to thousands?”</p><p>Attacks on the UK healthcare system and associated vendors have increased significantly over the last year, according to a recent <a href="https://www.sonicwall.com/resources/brief/protect-brief-healthcare-2026" target="_blank"><u>study from SonicWall</u></a>. Figures published by the <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm in June highlighted a tenfold increase in attacks so far in 2026. </p><p>Data collected through SonicWall's Intrusion Prevention System (IPS) showed upwards of 260,000 attempted cyber attacks between January and May this year. </p><p>While the Craneware incident has been contained, Dearing noted that employees and customers should still remain vigilant for potential follow-up attacks such as <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>- a common tactic employed in the wake of breaches. </p><p>“Even where stolen information appears low risk, employee, customer and partner data can be used to fuel phishing, social engineering and follow-on attacks,” he said. </p><p>“Employees, customers, and partners should remain cautious of any unsolicited communication or suspicious activity on their networks.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Lidl data breach: Supermarket chain warns customers after third-party 'IT incident' exposes customer information – here's what we know so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/lidl-data-breach-supermarket-chain-warns-customers-after-third-party-it-incident-exposes-customer-information-heres-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ The incident, affecting an unnamed service provider, is the latest to affect embattled retailers ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zyNrRndxDeXGefrowLPG33</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 14 Jul 2026 10:05:38 +0000</pubDate>                                                                                                                                <updated>Tue, 14 Jul 2026 12:12:54 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:description>                                                            <media:text><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of supermarket chain Lidl on a sign outside a branch in London, England.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oK8UtcdgcFnnJiAaRdKyPJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Supermarket chain Lidl has urged customers to remain vigilant after a data breach exposed personal information.</p><p>In an <a href="https://service.lidl.nl/html_mail.jsp?params=8LybHsuKa7Kn1nJNHJQVXNX0gmCmtqL%2BDv1%2FqBuU15CDljiqHnnM21YJF1q%2FnFUEywx3Rzgho98wZxcM9Vu14In%2BUF9apXtZuAjldylkmGg%3D" target="_blank"><u>advisory</u></a>, the firm revealed the ‘IT incident’ at a third-party service provider has impacted customers in Belgium, Germany, and the Netherlands. </p><p>"We were notified of this incident earlier this week," the message reads. </p><p>"Despite high IT security standards, unauthorized parties briefly gained access to a separately stored file containing customer data, and some of that data was stolen. The online shop system itself was not affected."</p><p>The stolen data relates to customers of Lidl's online shop, and includes first and last names, telephone numbers, email addresses, dates of birth, and customer numbers. </p><p>Lidl noted that data exposed in the incident does not include passwords, billing and delivery addresses, bank details, or other payment information. </p><h2 id="lidl-warns-customers-over-phishing-risks">Lidl warns customers over phishing risks</h2><p>The company said that while it currently has no concrete evidence this data has been misused, customers should remain vigilant for potential <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attacks or identity theft. </p><p>Customers should be wary of unexpected messages, always verify the authenticity of the sender, and avoid providing any information or clicking on unknown links. </p><p>Boris Cipot, principal security engineer at Black Duck, said the incident is a “textbook reminder” of the risks posed by third-party vendors. </p><p>"Even when a retailer's own systems hold, a compromised service provider can expose millions of customers to identity fraud, phishing, and account takeover attacks," Cipot commented. </p><p>"Personal data like names, birthdates, phone numbers, and email addresses may seem low-risk in isolation, but combined they become a powerful toolkit for social engineering. Additionally, the downstream costs to consumers and brand trust can far outlast the incident itself."</p><h2 id="lidl-vendor-acted-swiftly">Lidl vendor acted swiftly</h2><p>Lidl said its IT service provider responded immediately to fully restore the security of the affected IT systems, filed a report with the authorities and immediately engaged IT forensic experts to investigate the incident. </p><p>The company has also notified the relevant data protection authorities. Cipot commended the supermarket chain for its swift response and up-front communication with affected customers. </p><p>"Lidl deserves credit for moving quickly to notify customers and being transparent about what they don't yet know, including the possibility that passwords, addresses, and payment data could be involved. That kind of candor presents the appropriate posture under <a href="https://www.itpro.com/security/data-protection/gdpr">GDPR</a>," he said. </p><p>"The real test now is follow-through: how quickly they complete the forensic investigation, how clearly they communicate updates as the scope becomes known, and how rigorously they reassess the security requirements they place on their service providers going forward."</p><p>Lidl, which operates around 12,900 stores across 32 countries in Europe and the US, is just the latest retailer to be hit by a supply chain breach. </p><p>In the last year or so, victims have included <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-chair-calls-for-mandatory-reporting-of-cyber-attacks-after-traumatic-ransomware-incident-but-will-it-do-more-harm-than-good">Marks and Spencer</a>, Co-op, Louis Vuitton, Pandora, and <a href="https://www.itpro.com/security/cyber-attacks/harrods-cyber-attack">Harrods</a>. Many of these attacks have been linked to the <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">Scattered Spider</a> hacking group.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Nissan employee data exposed in Oracle PeopleSoft zero-day attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/nissan-employee-data-exposed-in-oracle-peoplesoft-zero-day-attacks</link>
                                                                            <description>
                            <![CDATA[ The car manufacturer has urged current and former employees to change banking passwords and remain vigilant for phishing emails ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iEFssRXnv84RqT2KkL5doK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 30 Jun 2026 16:18:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:description>                                                            <media:text><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Nissan logo and branding illuminated against a dark backdrop at the 2026 New York International Auto Show in New York City, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/CDWcH6YZibWtKGZ2YxnLPY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nissan has revealed it suffered a data breach after threat actors exploited flaws in Oracle’s PeopleSoft software, with information on both current and former staff exposed. </p><p>In a <a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-625558" target="_blank"><u>filing </u></a>with the California Attorney General’s Office, the car manufacturer said it is “working as quickly as possible” to establish the full scale and scope of the breach. </p><p>An initial investigation by the company reveals that personal information such as contact and banking information, social security numbers, and financial and tax data was exposed in the breach. </p><p>Current and former employees in the US, Canada, Mexico, and Brazil are among those affected, the company said. </p><p>“As we continue our investigation, individuals whose personal information has been exposed will receive further communication with additional details and next steps,” the filing reads. </p><p>Nissan urged employees to take a number of precautionary steps in the meantime, including remaining vigilant for <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>emails or fraudulent phone calls and text messages. </p><p>Staff were also advised to monitor financial accounts and credit reports for unusual activity, and urged to change passwords for “all significant accounts” - such as banking services. </p><p>Nissan noted that systems have since been secured and the company is working with technical experts to prevent further leaks. </p><p>“Upon learning about this issue, we quickly activated incident response protocols. We have been in communication with authorities throughout our response to this attack,” the filing reads. </p><p>“Our technical teams, along with external experts, have secured our systems and will continue to work with Oracle to address this issue. We have taken steps designed to end unauthorized access and to prevent further disclosure of the information.”</p><h2 id="oracle-peoplesoft-breach">Oracle PeopleSoft breach</h2><p>The announcement by Nissan comes in the wake of a “cyber event” involving Oracle’s PeopleSoft software, which is used to manage employee information such as payroll, tax, and other personnel details. </p><p>More than 100 organizations are believed to have been affected by the breach so far, which has been linked to the ShinyHunters threat group. </p><p>Earlier this month, the <a href="https://www.itpro.com/security/nottingham-university-cyber-attack-everything-we-know-so-far-as-shinyhunters-claims-responsibility">University of Nottingham</a> was among those impacted by the breach, with data belonging to around 450,000 present and former students compromised in the attack.</p><p>Simon Pamplin, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>at Certes, said the breach is a single <a href="https://www.itpro.com/security/zero-day-exploit/360447/why-zero-day-exploits-are-surging-on-an-unprecedented-scale">zero-day</a> in “widely deployed enterprise software can become a mass-casualty event”.</p><p>“Nissan was not the target of a bespoke attack. It was one of many companies caught in a campaign exploiting a shared vulnerability in HR and payroll infrastructure used across industries,” he said. </p><p>“The data involved here is particularly serious. Social Security numbers, banking details, tax information and dependent records are not generic employee data. They are the durable financial backbone of a person's identity, and they were sitting inside a system many organisations treat as core infrastructure rather than a high-value target.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Vercel data breach so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/everything-we-know-about-the-vercel-data-breach-so-far</link>
                                                                            <description>
                            <![CDATA[ An OAuth supply chain compromise saw 'non-sensitive' Vercel data compromised and some internal systems accessed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R8bnDH65phHDUjYQcpj2v</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nVJtF4erHdUjd43hfPHEeE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Apr 2026 11:07:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nVJtF4erHdUjd43hfPHEeE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo and branding of cloud development platform Vercel pictured on a smartphone screen with blurred multi-colored background.]]></media:description>                                                            <media:text><![CDATA[Logo and branding of cloud development platform Vercel pictured on a smartphone screen with blurred multi-colored background.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo and branding of cloud development platform Vercel pictured on a smartphone screen with blurred multi-colored background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nVJtF4erHdUjd43hfPHEeE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud development platform Vercel has confirmed it experienced a data breach after hackers claimed to have accessed its systems.</p><p>The Vercel platform is best known for supporting frameworks like Next.js, used by around two-thirds of <a href="https://www.itpro.com/development/30202/what-is-javascript-and-why-should-i-learn-it">JavaScript </a>developers.</p><p>The attackers gained entry through the compromise of Context.ai, a third-party AI tool used by a Vercel employee. </p><p>That access was then used to take over the employee's Google Workspace account, giving the hackers access to some Vercel environments and variables that weren't marked as 'sensitive'. </p><p>"We assess the attacker as highly sophisticated based on their operational velocity and detailed understanding of Vercel's systems,” the company said in a <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident#recommendations" target="_blank"><u>statement</u></a>. </p><p>“We are working with Mandiant, additional cybersecurity firms, industry peers, and law enforcement. We have also engaged Context.ai directly to understand the full scope of the underlying compromise.”</p><p>Vercel added that it worked closely with GitHub, Microsoft, npm, and Socket in the wake of the breach, stating that no npm packages were compromised. </p><p>“There is no evidence of tampering, and we believe the supply chain remains safe,” Vercel continued. </p><h2 id="some-customers-impacted-in-vercel-data-breach">Some customers impacted in Vercel data breach</h2><p>Vercel said it has identified a number of customers whose non-sensitive environment variables – those that decrypt to plaintext – were compromised.</p><p>The company has contacted affected customers and recommended an immediate rotation of credentials. </p><p>Vercel added it will keep customers updated if it finds any evidence of further compromise.</p><h2 id="who-is-responsible">Who is responsible?</h2><p>A threat group claiming to be ShinyHunters has claimed responsibility for the attack in a post on Telegram, offering data that includes access keys, source code, and databases for sale, along with access to internal deployments and API keys</p><p>The attackers said they had been in touch with Vercel and were demanding a ransom of $2 million.</p><p>However, Austin Larsen, principal threat analyst at Google Threat Intelligence, cast doubt on these claims in a <a href="https://www.linkedin.com/posts/austin-larsen_vercel-share-7451694308845408256-aHOX/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAAC2xvMBLPggh7Z3PC8i4V4yQ0JB56a2MlM" target="_blank"><u>post on LinkedIn</u></a>. In this instance, the threat actors behind the attack could be bluffing. </p><p>"It is likely this is an imposter attempting to use an established name to inflate their notoriety,” he said. </p><h2 id="what-should-vercel-users-do">What should Vercel users do?</h2><p>Vercel advised customers to add an additional layer of security by requiring at least two methods of authentication, configuring an authenticator app, and creating a passkey.</p><p>The company emphasized that simply deleting a project or account won’t work, as compromised secrets could still provide threat actors with access to production systems. Users are advised to rotate them first. </p><p>Customers should also take advantage of the sensitive environment variables feature so that secret values are protected from being read in the future.</p><p>Similarly, users are advised to review account activity logs and environments for suspicious activity, either through the dashboard or CLI. </p><p>Other tips included:</p><ul><li>Look out for recent, unexpected or suspicious-looking deployments</li><li>Delete those that arouse suspicious</li><li>Ensure Deployment Protect is set to Standard at a minimum</li><li>Rotate Deployment Protection tokens, if set</li></ul><h2 id="who-else-should-worry">Who else should worry?</h2><p>Vercel said the attack on Context’s Google Workspace OAuth app was the subject of a “broader compromise, potentially affecting its hundreds of users across many organisations”.</p><p>Meanwhile, Context AI has <a href="https://context.ai/security-update"><u>confirmed</u></a> that the hackers “likely compromised OAuth tokens for some of our consumer users”. </p><p>The firm said it in the process of contacting everyone identified as potentially impacted, with specific guidance on next steps. </p><p>Jaime Blasco, CTO of Nudge Security, advised users to switch to an “admin-managed consent” model when dealing with third-party applications. </p><p>"Start with OAuth consent. Most Google Workspace and Microsoft 365 environments are still configured to let any employee grant third-party apps access to their enterprise account,” he said.</p><p>"Inventory what you already have. OAuth grants accumulate, People try a tool, forget about it, leave the company, and the grant keeps living in the tenant with whatever scopes it asked for. Quarterly audits aren't enough especially when now we have agents using these grants. You need continuous visibility into who granted what, what scopes they granted, and whether the integration is even still being used."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘There was a manual deploy step that should have been better automated’: Claude Code creator confirms cause of massive source code leak  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/there-was-a-manual-deploy-step-that-should-have-been-better-automated-claude-code-creator-confirms-cause-of-massive-source-code-leak</link>
                                                                            <description>
                            <![CDATA[ Over half a million lines of Claude Code source code was leaked, with the company attributing the blunder to human error ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4p7UxnQFNVUTER5HGoCWaC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bKWbECsE5Qnj7e5jMR7JqR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 01 Apr 2026 15:58:52 +0000</pubDate>                                                                                                                                <updated>Thu, 02 Apr 2026 11:09:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bKWbECsE5Qnj7e5jMR7JqR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Anthropic&#039;s Claude AI tool imposed over computer source code.]]></media:description>                                                            <media:text><![CDATA[Logo of Anthropic&#039;s Claude AI tool imposed over computer source code.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Anthropic&#039;s Claude AI tool imposed over computer source code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bKWbECsE5Qnj7e5jMR7JqR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/software/development/claude-code-creator-boris-cherny-says-software-engineers-are-more-important-than-ever-as-ai-transforms-the-profession-but-anthropic-ceo-dario-amodei-still-thinks-full-automation-is-coming">Boris Cherny</a>, creator of Anthropic’s Claude Code tool, has revealed the cause of a leak that saw 500,000+ lines of source code exposed online. </p><p>In a <a href="https://x.com/bcherny/status/2039210700657307889?" target="_blank"><u>post on X,</u></a> Cherny said “mistakes happen” amid reports the leak was an accident on the part of an Anthropic employee. </p><p>“As a team, the important thing is to recognize it’s never an individual’s fault - it’s the process, the culture, or the infra,” he said. </p><p>In this instance, Cherny noted there was a “manual deploy step that should have been better automated”. </p><p>“Our team has made a few improvements to the automation for next time, a couple more on the way,” he added. </p><p>The leak marks the second for the AI provider in the space of a week. Reports from <a href="https://fortune.com/2026/03/26/anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities/" target="_blank"><u><em>Fortune </em></u></a>on 26 March revealed information pertaining to an upcoming AI model launch were found in a publicly accessible data cache. </p><p>Files reviewed by Fortune showed the company is working on a new model, dubbed ‘Claude Mythos’, which a spokesperson said represents a “step change” in capability and could pose cybersecurity risks. </p><h2 id="what-happened-with-the-claude-code-leak">What happened with the Claude Code leak?</h2><p>Reports of a potential leak first emerged online on Tuesday 31 March, with security researcher Chaofan Shou <a href="https://x.com/Fried_rice/status/2038894956459290963" target="_blank"><u>claiming </u></a>that source code was leaked through a map file in the company’s npm registry. </p><p>The leak prompted a flurry of activity online, with data backed up to a GitHub repository that was forked thousands of times, per reports from <a href="https://www.techradar.com/pro/security/anthropic-confirms-it-leaked-512-000-lines-of-claude-code-source-code-spilling-some-of-its-biggest-secrets" target="_blank"><u><em>Techradar</em></u></a>.</p><p>A Cloudflare storage bucket is believed to have contained 1,900 TypeScript files with upwards of 500,000 lines of code, as well as details on built-in tools and slash command libraries. </p><p>Anthropic has confirmed the incident and attributed the leak to human error, corroborating Cherny’s comments that steps have been taken to prevent a similar situation in future. </p><p>"A Claude Code release included some internal source code. No sensitive customer data or credentials were involved or exposed," a spokesperson told ITPro. </p><p>"This was a release packaging issue caused by human error, not a security breach. We're rolling out measures to prevent this from happening again.</p><p><a href="https://www.itpro.com/software/development/anthropic-labs-chief-mike-krieger-claims-claude-is-essentially-writing-itself-and-it-validates-a-bold-prediction-by-ceo-dario-amodei">Claude Code</a> has rapidly become one of Anthropic’s most popular tools since launching, helping automate code generation tasks for software developers.</p><p>Figures touted <a href="https://www.itpro.com/business/anthropic-series-g-investment-round-claude"><u>in the wake of a recent funding round</u></a> for Anthropic show Claude Code’s run-rate revenue has reached more than $2.5 billion. While exact figures on user numbers are unclear, active weekly users are believed to have doubled since 1st January amid soaring popularity. </p><p>Indeed, recent analysis from <a href="https://techcrunch.com/2026/03/28/anthropics-claude-popularity-with-paying-consumers-is-skyrocketing/" target="_blank"><u><em>Techcrunch</em></u></a> found the tool - along with <a href="https://www.itpro.com/technology/artificial-intelligence/everything-you-need-to-know-about-anthropic-claude-cowork">Claude Cowork</a> - are now massive drivers of paid subscriptions at the firm. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European Commission confirms data breach as ShinyHunters group claims responsibility ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/european-commission-confirms-data-breach-as-shinyhunters-group-claims-responsibility</link>
                                                                            <description>
                            <![CDATA[ The extortion group is believed to be behind a cyber attack affecting the Commission's cloud systems ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hq482EVjAgSjmX4sJSjdDM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Aaozf8FqfVDo3iYRAoFZtg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 30 Mar 2026 09:57:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Aaozf8FqfVDo3iYRAoFZtg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Facade of the Berlaymont building, headquarters of the European Commission, in Brussels, with EU flags fluttering in the wind.]]></media:description>                                                            <media:text><![CDATA[Facade of the Berlaymont building, headquarters of the European Commission, in Brussels, with EU flags fluttering in the wind.]]></media:text>
                                <media:title type="plain"><![CDATA[Facade of the Berlaymont building, headquarters of the European Commission, in Brussels, with EU flags fluttering in the wind.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Aaozf8FqfVDo3iYRAoFZtg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The European Commission has confirmed that it's been hit by a cyber attack on its Europa.eu web platform.</p><p>The Europa.eu platform hosts the websites of the Commission itself, along with the European Parliament, European Council, and other EU institutions. The attack, which has been claimed by the ShinyHunters extortion gang, targeted the website's host cloud infrastructure and was detected on 24 March.</p><p>"Immediate steps were taken to contain the attack," it said in a <a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_26_748" target="_blank"><u>statement</u></a>. "The Commission's swift response ensured the incident was contained and risk mitigation measures were implemented to protect services and data, without disrupting the availability of the Europa websites."</p><p>There are signs that data has been stolen, and the Commission is notifying all of the bodies that may have been affected. Internal systems weren't affected by the attack, it said. </p><p>"The Commission will continue to monitor the situation and take all necessary measures to ensure the security of its internal systems and data," it said. "It will analyze the incident and use the results to further enhance its <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>capabilities."</p><h2 id="what-happened-with-the-commission-attack">What happened with the Commission attack?</h2><p>The attack is believed to have affected the Commission's <a href="https://www.itpro.com/amazon-web-services">AWS </a>account, impacting multiple databases and reportedly exposing hundreds of gigabytes of data. </p><p>According to <a href="https://x.com/DarkWebInformer/status/2037909308323565879" target="_blank"><u>Dark Web Informer</u></a>, the extortion group ShinyHunters has claimed responsibility. The group said it had accessed mail servers, databases, confidential documents, contracts, "and much more sensitive material," and released more than 90GB of files on its Tor data leak site. </p><p>The data is believed to include emails and attachments, a full SSO user directory, DKIM signing keys, AWS config snapshots, NextCloud/Athena data and internal admin URLs.  </p><p>ShinyHunters first appeared on the scene in 2020, and has recently been responsible for a series of high profile attacks, frequently targeting SSO credentials and Salesforce data. </p><p>Victims include Google, Chanel, Canada Goose, and Panera Bread. It mainly uses <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> – particularly voice phishing – for its attacks. </p><p>Just two weeks ago, Salesforce was forced to issue <a href="https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach"><u>another customer alert</u></a> after uncovering an ongoing campaign targeting customers using misconfigured Experience Cloud platforms – a campaign claimed by ShinyHunters.</p><p>This latest attack is the second time this year that the European Commission has been hacked. In February, it <a href="https://www.itpro.com/technology/artificial-intelligence/european-commission-confirms-hackers-breached-mobile-management-platform"><u>revealed</u></a> that a data breach impacting the central infrastructure managing mobile devices might have given attackers access to some staff names and mobile phone numbers.</p><p>No mobile devices were compromised, it said, and the incident was contained and systems cleaned within nine hours. </p><p>The Commission is promising to do better, saying: "As Europe confronts persistent cyber and hybrid attacks targeting essential services and democratic institutions, the Commission is actively working on enhancing the EU's cybersecurity resilience." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know so far about the PayPal data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/everything-we-know-so-far-about-the-paypal-data-breach</link>
                                                                            <description>
                            <![CDATA[ While few PayPal customers saw their data exposed, some did experience unauthorized activity on their accounts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eiZBp8ARFqgdLyDV2WEZCn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dQqgjrZGynKbJAwruTzL9G-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 23 Feb 2026 10:21:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dQqgjrZGynKbJAwruTzL9G-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[PayPal logo and branding pictured on a smartphone screen with company coloring in the background.]]></media:description>                                                            <media:text><![CDATA[PayPal logo and branding pictured on a smartphone screen with company coloring in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[PayPal logo and branding pictured on a smartphone screen with company coloring in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dQqgjrZGynKbJAwruTzL9G-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>PayPal has issued an alert after a data breach saw customers exposed for several months. </p><p>According to a notification seen by <a href="https://www.bleepingcomputer.com/news/security/paypal-discloses-data-breach-exposing-users-personal-information/" target="_blank"><u><em>BleepingComputer</em></u></a> and sent to affected customers on February 10, the breach was caused by an error in the firm's PayPal Working Capital (PPWC) loan application.</p><p>This saw personal data belonging to a "small number" of customers exposed to unauthorized individuals between July 1 and December 13 last year. Data exposed in the incident is believed to have included business contact information. </p><p>Some customers did have unauthorized activity on their accounts as a result, although PayPal said it's refunded those people.</p><p>"Our investigation determined that some of your personal information was affected by this incident," the letter read. </p><p>"This could have included your business contact info: name, email address, phone number, business address combined with your Social Security number, and date of birth."</p><p>The company said it has launched an investigation into the incident and terminated the unauthorized access to PayPal’s systems - rolling back the code changes that caused the breach in the first place. </p><p>Affected PayPal accounts have also had passwords reset, requiring customers to create new login details. The payments giant also confirmed it has implemented enhanced security controls. </p><p>Free credit monitoring services will be offered to affected customers through Equifax, and customers are being told to be on the alert for any suspicious activity or fraudulent transactions.</p><h2 id="paypal-data-breach-could-have-downstream-impact">PayPal data breach could have downstream impact</h2><p>While PayPal has implemented changes in the wake of the breach, Kevin Knight, CEO of Talion, warned the incident could have downstream implications for customers, particularly given contact information was exposed. </p><p>“<a href="https://www.itpro.com/business/leadership/paypal-ceo-enrique-lores-hp-announcement">PayPal </a>has said it has refunded customers for the fraudulent transactions and updated the passwords on impacted accounts, but the attacker still has access to information that can’t be easily changed, which can still be of value to them in phishing scams and to sell to initial access brokers,” he said. </p><p><a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>scams are a common occurrence in the wake of data breaches, with threat actors using exposed contact details such as email addresses to target victims. </p><p>Notably, Knight said the timing of the letter is also concerning, with the incident having first occurred months before and the fact it was discovered in December.  </p><p>"What is most concerning about this breach is that an organization as large and reputable as PayPal, which holds highly sensitive data on its customers, has waited two months to notify individuals about this incident," said Knight.</p><p>"While credit monitoring has been offered, victims were left in the dark, while the actor behind the incident was able to access their financial and personal data and conduct fraudulent transactions."</p><p>In its customer notification, PayPal insisted it had not delayed the notification "as a result of any law enforcement investigation," it reads.</p><p><em>ITPro</em> has approached PayPal for comment. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A single compromised account gave hackers access to 1.2 million French banking records ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/a-single-compromised-account-gave-hackers-access-to-1-2-million-french-banking-records</link>
                                                                            <description>
                            <![CDATA[ Ficoba has warned that “numerous” scams are already in circulation following the data breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MctzL27C9DgHoFVWrZYiq4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 20 Feb 2026 10:55:22 +0000</pubDate>                                                                                                                                <updated>Fri, 20 Feb 2026 13:17:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Credentials stolen from a single government official enabled threat actors to access a French national database containing data on more than 1.2 million bank accounts.</p><p>The attackers were able to access the Fichier des comptes bancaires (Ficoba) database, which contains files on all bank accounts opened in France. </p><p>Stolen credentials were used by the threat actors to impersonate a civil servant and view data that included personal information such as bank account numbers, account holders' names and addresses, IBANs, and, in some cases, the account owner's tax number. </p><p>"Starting at the end of January 2026, a malicious actor, who had impersonated a civil servant with access rights as part of an inter-ministerial information exchange, was able to consult a portion of this file," Ficoba said in a <a href="https://presse.economie.gouv.fr/acces-illegitimes-au-fichier-national-des-comptes-bancaires-ficoba/" target="_blank"><u>statement</u></a>.</p><p>"As soon as this incident was detected, immediate access restrictions were implemented to stop the attack, limit the scope of the data accessed and extracted from this database – which reportedly includes 1.2 million accounts – and prevent any further unauthorized access." </p><p>Ficoba said IT teams at the French Public Finances Directorate, along with other bodies, were working to address this incident and strengthen security. The incident has also been reported to the French Data Protection Authority (CNIL), it said.</p><p>The chief of France's Public Finances told Agence France-Presse that affected individuals will be contacted over the next few days. Officials insisted the breach did not give attackers access to account balances or transactions.</p><h2 id="ficoba-breach-prompts-phishing-frenzy">FICOBA breach prompts phishing frenzy</h2><p>Security researchers at Cybernews said that this may not be the full story. While account balances can’t be accessed from this data alone, this incident “still poses risks” to users across the country. </p><p>“Exposed PII, such as names and addresses, can be combined with other leaked data to profile people and construct convincing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns that can pose as the national bank.”</p><p>When combined with tax identification numbers, researchers said this increases the risk of fraud and identity theft, as these numbers can be used as identifiers on government platforms.</p><p>Ficoba has warned that "numerous" scams are circulating via email or SMS, aiming to obtain information or payments from users. </p><p>Individuals contacted have been urged not to reply directly, and should instead contact their local tax office directly through the secure messaging system in their online account or by phone to check out the authenticity of the message.</p><p>Meanwhile, Michael Jepson, penetration testing manager at CybaVerse, said it's worrying that a single individual within the organization was able to access large volumes of sensitive data unilaterally.</p><p>"Traditionally, access scope often increased with seniority, an approach that is now widely recognized as problematic in modern threat environments," he said. </p><p>"Modern security practice recognizes that access should be determined strictly by operational need rather than hierarchy. Senior figures are frequently primary targets for threat actors, which makes <a href="https://www.itpro.com/cloud/cloud-security/are-your-cloud-resources-at-risk">excessive privilege</a> particularly dangerous."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts warn Substack users to brace for phishing attacks after breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/security-experts-warn-substack-users-to-brace-for-phishing-attacks-after-breach</link>
                                                                            <description>
                            <![CDATA[ Substack CEO Christ Best confirmed the incident occurred in October 2025 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7MCXZ7M3JJJe6sM7bNT9B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 06 Feb 2026 09:38:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:description>                                                            <media:text><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Substack logo and branding pictured on a laptop screen with hand placed on keyboard and blurred user head in foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k4Nndu7uQs2VrqAomgdw8R-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/28133/what-is-cyber-security">Cybersecurity </a>experts have warned Substack users to be on the lookout for potential phishing scams after the blogging platform suffered a data breach. </p><p>In an <a href="https://bsky.app/profile/newsguy.bsky.social/post/3me3dhsexmt2s" target="_blank"><u>email </u></a>distributed to users, CEO Chris Best revealed a “security incident” saw account email addresses, contact numbers, and “other internal metadata” exposed. </p><p>Exact details on how the breach unfolded are yet to be disclosed. However, on 3 February, the organization discovered an issue that allowed an unauthorized third-party to “access limited user data.”</p><p>A preliminary investigation found the data was first accessed in October 2025, Best added. </p><p>“Importantly, credit card numbers, passwords, and financial information were not accessed,” the email reads. </p><p>“We have fixed the problem with our system that allowed this to happen. We are conducting a full investigation and are taking steps to improve our systems and processes to prevent this type of issue from happening in the future.”</p><p>Substack hasn’t revealed information on the scale of the breach. However, reports from <a href="https://www.bleepingcomputer.com/news/security/newsletter-platform-substack-notifies-users-of-data-breach/" target="_blank"><u><em>BleepingComputer </em></u></a>suggest the incident could have impacted over half a million users. </p><p>On Monday 2 February, a threat actor uploaded a database to BreachForums allegedly containing 697,313 stolen records.</p><h2 id="substack-users-should-remain-vigilant">Substack users should remain vigilant</h2><p>Best noted that there is currently no evidence that information exposed in the breach is being misused, but nonetheless warned users to remain vigilant. </p><p>“We encourage you to take extra caution with any emails or text messages you receive that may be suspicious,” he said. </p><p>That same advice has since been reiterated by cybersecurity experts. <a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>attacks are a common occurrence in the wake of a data breach as cyber criminals look to capitalize on contact information to dupe unsuspecting users.</p><p>This information often represents a goldmine for threat actors, according to Jamie Akhtar, CEO of CyberSmart.</p><p>“While Substack has stated that sensitive data such as passwords and payment information was not accessed, exposure of contact details like email addresses and phone numbers can still be highly valuable to cyber criminals,” he said. </p><p>“This type of data is often used as the foundation for targeted phishing, impersonation attempts, and wider <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> campaigns.”</p><p>Javvad Malik, lead security awareness advocate at KnowBe4, echoed Akhtar’s comments, but noted that the information provided by Substack is limited, which could still leave some users at risk. </p><p>“It is a bit light on the details which can help people accurately judge the risk and take concrete action,” he said. The timeline is significant. If the data was accessed in October 2025, but only just disclosed, it's a significant dwell time.”</p><p>“That isn't to say there's negligence on part of Substack because detection can be difficult,” Malik added. “But impacted users deserve a clearer explanation of how the breach was identified.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know so far about the Nike data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/everything-we-know-so-far-about-the-nike-data-breach</link>
                                                                            <description>
                            <![CDATA[ Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RQPiXZQAgvbMN6mcFnWGYm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hKDg9HJeNfft4roCAaoUod-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 Jan 2026 14:52:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hKDg9HJeNfft4roCAaoUod-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Nike tick logo pictured on a storefront sign in San Francisco, USA.]]></media:description>                                                            <media:text><![CDATA[Nike tick logo pictured on a storefront sign in San Francisco, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Nike tick logo pictured on a storefront sign in San Francisco, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hKDg9HJeNfft4roCAaoUod-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Nike has confirmed it is investigating a potential data breach amidst claims hackers have accessed sensitive company data. </p><p>Hackers behind the WorldLeaks <a href="https://www.itpro.com/security/ransomware/the-top-ransomware-trends-for-businesses"><u>ransomware group</u></a> claim to have accessed up to 1.4TB of internal data, adding the company to its leak site. </p><p>Exact details on the data stolen by the group are yet to be revealed. However, a sample published by the group points toward design and manufacturing information. </p><p>Data shared by WorldLeaks includes directories titled “Women’s Sportswear” and “Training Resources - Factory”, for example. </p><p>At present, it does not appear that sensitive customer or employee data was compromised in the attack. </p><p>In a statement given to <a href="https://www.infosecurity-magazine.com/news/worldleaks-ransomware-14tb-nike/" target="_blank"><em>Infosecurity Magazine</em></a>, a spokesperson for Nike said: “We always take consumer privacy and data security very seriously. We are investigating a potential cybersecurity incident and are actively assessing the situation.”</p><p><em>ITPro</em> has approached Nike for additional comment and clarification. </p><h2 id="nike-data-breach-could-have-ramifications">Nike data breach could have ramifications</h2><p>Initial analysis of the data dump from threat intelligence group, <a href="https://x.com/justabreach/status/2015188216291180865" target="_blank"><u>Justabreach</u></a>, suggests the data stolen by WorldLeaks dates as far back as 2020. </p><p>While no customer data appears to have been compromised thus far, the long-term damage of this attack could be significant for the sportswear giant. </p><p>Sensitive documents on manufacturing processes and product information have been impacted. </p><p>Shankar Haridas, head of UKI at ManageEngine, said this could have huge ramifications for the company. </p><p>“For large brands, the risk rarely stops at customer records,” he said. </p><p>“Product roadmaps, supplier contracts, pricing models, and internal comms are often just as valuable to attackers. A leak of this scale can create long-term competitive and reputational damage, even before the facts are fully confirmed.”</p><h2 id="what-you-need-to-know-about-worldleaks">What you need to know about WorldLeaks</h2><p>WorldLeaks has claimed a number of victims in recent years, including Dell and <a href="https://www.itpro.com/security/ransomware/tata-technologies-hit-by-ransomware-attack"><u>Tata Technologies</u></a>, and is believed to be the successor group to Hunters International. </p><p>The notorious threat group <a href="https://www.itpro.com/security/ransomware/hunters-international-ransomware-shut-down"><u>confirmed plans to shut down</u></a> in July last year, offering victims a decryptor to regain access to stolen data. The announcement wasn’t quite a goodwill gesture, however. </p><p>Speaking to <em>ITPro </em>at the time, Dray Agha, senior manager of security operations at Huntress, said the group was essentially just rebranding under a new name. </p><p>David Sancho, senior threat researcher at Trend Micro, said the attack against Nike follows a dormant period for the group, which now appears to have large corporations in its crosshairs once again. </p><p>“There’s no question that World Leaks is going after large companies,” he said. “Nike is the latest and follows a ‘quiet period’ between the last observed Hunters International attack (last July) and the first attack after the group rebranded as “World Leaks” (last September).”</p><p>Sancho noted that the “standout trait” of WorldLeaks is that it’s a data exfiltration group, meaning it focuses primarily on stealing data, then asking for money in exchange for not leaking it to the public. </p><p>“This stands in contrast with the traditional ransomware strategy of encrypting the data and asking for payment in order to decrypt it.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 1,800 MSPs impacted in Pax8 data leak after company shared partner information via email ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/1-800-msps-impacted-in-pax8-data-leak-after-company-shared-partner-information-via-email</link>
                                                                            <description>
                            <![CDATA[ More than a thousand MSPs have been alerted that competitors may now have access to sensitive business data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Gt4EcKuet8rXtgvmHe23nd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 Jan 2026 11:20:24 +0000</pubDate>                                                                                                                                <updated>Fri, 16 Jan 2026 11:39:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud marketplace and distributor <a href="https://www.itpro.com/business/business-strategy/pax8-and-microsoft-are-teaming-up-to-supercharge-msp-growth">Pax8 </a>has issued a warning about a security breach that saw data on around 1,800 customers exposed. </p><p>An email was sent to 40 of the company's UK-based managed service provider (MSP) customers with an attachment generally used for day-to-day operational reporting. </p><p>This contained Pax8 pricing and program-related information associated with 17 stock-keeping units within four Microsoft Modern Work product categories. </p><div class="product"><a data-dimension112="91249864-781a-46eb-93dd-15946d6d5cc6" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="sponsored" data-dimension112="91249864-781a-46eb-93dd-15946d6d5cc6" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">Make Password Security Your New Year's Resolution</a></p><p>Get 50% off Keeper Personal and Family plans, and 30% off Keeper Business Starter today!<a class="view-deal button" href="https://click.linksynergy.com/deeplink?id=kXQk6%2AivFEQ&mid=42966&u1=itpro-gb-1046892004221913649&murl=https%3A%2F%2Fwww.keepersecurity.com%2Fen_GB%2Fnew-year-resolution.html" target="_blank" rel="nofollow" data-dimension112="91249864-781a-46eb-93dd-15946d6d5cc6" data-action="Deal Block" data-label="Make Password Security Your New Year's Resolution" data-dimension48="Make Password Security Your New Year's Resolution" data-dimension25="">View Deal</a></p></div><p>Almost all the customers whose data was shared were UK-based, with one located in Canada. </p><p>The email, titled "<em>Potential Business Premium Upgrade Tactic to Save Money</em>," was sent on January 13 and contained more than 56,000 entries in all. A follow-up email was sent immediately requesting deletion of the email, and asking recipients not to forward it.</p><p>Pax8 insists the breach did not involve any personally identifiable information (PII), authentication credentials, payment data, or any information that could enable system access. </p><p>However, the leaked data could reveal to the 40 competitors with which it was shared the MSP’s full client portfolio, what licenses they hold, and when these are due to expire, along with internal Pax8 pricing and margin information.</p><h2 id="threat-actors-are-approaching-affected-msps">Threat actors are approaching affected MSPs</h2><p>The data leak could help the victims' competitors poach customers by revealing which organizations use Pax8 as their distributor, the size of each customer's Microsoft environment, the timelines for contract renewal, and potentially the pricing tiers being paid.</p><p>A more sinister development has unfolded in the wake of the incident, however, with cyber criminals apparently capitalizing on the situation. According to reports from <a href="https://www.bleepingcomputer.com/news/security/cloud-marketplace-pax8-accidentally-exposes-data-on-1-800-msp-partners/" target="_blank"><u><em>BleepingComputer</em></u></a>, threat actors have approached some of the affected MSPs and offered to buy the data. </p><p>This information could be used by cyber criminals to craft convincing phishing attacks, for example by allowing an attacker to email a company just before their contract renewal date, pretending to be their MSP and requesting payment.</p><p>The company <a href="https://status.pax8.com/" target="_blank"><u>said</u></a> it has launched an internal review to work out how the breach happened and plans to ramp up its safeguards and processes to prevent a similar incident taking place in the future.</p><p>Access instructions have now been sent to affected partners, the company revealed, allowing them to securely review information that may have been shared. </p><p>That access will be limited to the Pax8 Marketplace Primary Partner Admin and/or Partner Admin for each organization.</p><p>"Our focus continues to be on responding directly to partner questions and supporting impacted partners as they review their data and follow up with us," said the firm. "In parallel, our internal review remains ongoing as we continue to strengthen safeguards and processes." </p><p>Pax8 said partners with questions or concerns should submit a Support ticket through the Pax8 Marketplace referencing <em>UK Partner Information Incident – Jan 13, 2026.</em></p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users – here’s how the incident unfolded ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/lastpass-hit-with-ico-fine-after-2022-data-breach-exposed-1-6-million-users-heres-how-the-incident-unfolded</link>
                                                                            <description>
                            <![CDATA[ The impact of the LastPass breach was felt by customers as late as December 2024 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ATQvZUPYifcPMYGMgxGcJM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TTRshdPVbcc5tTxbndpFXc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 12 Dec 2025 11:00:01 +0000</pubDate>                                                                                                                                <updated>Fri, 12 Dec 2025 11:01:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TTRshdPVbcc5tTxbndpFXc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LastPass logo pictured on a smartphone screen alongside earbuds and car key.]]></media:description>                                                            <media:text><![CDATA[LastPass logo pictured on a smartphone screen alongside earbuds and car key.]]></media:text>
                                <media:title type="plain"><![CDATA[LastPass logo pictured on a smartphone screen alongside earbuds and car key.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TTRshdPVbcc5tTxbndpFXc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Password manager provider <a href="https://www.itpro.com/security/information-security-infosec/370210/lastpass-breach-last-chance">LastPass</a> has been hit with a £1.2 million fine for failing to prevent a massive data breach.</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> found that a combination of two incidents over two days in August 2022 <a href="https://www.itpro.com/security/369776/lastpass-customer-password-vaults-stolen-targeted-phishing-attacks-likely">put more than 1.6 million customers at risk</a>. </p><p>According to the data protection watchdog, the company “failed to implement sufficiently robust technical and security measures”. </p><p>Commenting on the fine, information commissioner John Edwards said LastPass failed customers and “fell short” on expectations that the company would employ robust measures to protect personal data. </p><p>“<a href="https://www.itpro.com/software/368045/best-free-password-managers-in-2022">Password managers</a> are a safe and effective tool for businesses and the public to manage their numerous login details and we continue to encourage their use,” he said. </p><p>“However, as is clear from this incident, businesses offering these services should ensure that system access and use is restricted to ensure risks of attack are significantly reduced," Edwards added. </p><p>“LastPass customers had a right to expect the personal information they entrusted to the company would be kept safe and secure. However, the company fell short of this expectation, resulting in the proportionate fine being announced today."</p><h2 id="the-lastpass-breach-explained">The LastPass breach explained</h2><p>The LastPass breach unfolded in two separate phases. In the first incident, a hacker compromised an employee’s corporate laptop and gained access to the company’s development environment. </p><p>While no personal information was taken, encrypted company credentials were - which, if decrypted, would allow access to the company’s backup database.</p><p><a href="https://www.itpro.com/software/368008/lastpass-vs-1password">LastPass </a>took steps to mitigate the hacker’s activity, but thought the encryption keys were safe, as they were stored in the account vaults of four senior employees, outside the area accessed by the hacker.</p><p>However, the next day, the hacker targeted one of these employees, gaining access to their personal device via a known vulnerability in a third-party streaming service.</p><p>The hacker then installed a keylogger, capturing the employee’s master password and bypassing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a> using a trusted device cookie. This gave access to the employee’s personal and business LastPass vaults, which were linked using a single master password.</p><p>Thereafter, the threat actor gained access to the employee’s business vault, which contained the <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362608/what-is-aws">Amazon Web Service (AWS)</a> access key and decryption key. When combined with information taken the day before, this allowed the hacker to extract the contents of the backup database containing the customers' personal data.</p><h2 id="lastpass-zero-knowledge-system-prevented-disaster">LastPass’ ‘zero knowledge’ system prevented disaster</h2><p>As the ICO noted in its post-mortem of the incident, the threat actor responsible for the breach wasn't able to decrypt encrypted passwords and other credentials. </p><p>This was thanks to LastPass’ use of a ‘zero knowledge’ encryption system, whereby the master password required to access a password vault is stored locally on a customer’s own device and never shared with LastPass. </p><p>While this represented a reprieve for the company and users, the impact of the breach was felt by customers as late as December 2024. </p><p>A probe by crypto investigator ZachXBT found <a href="https://www.itpro.com/security/cyber-attacks/lastpass-breach-comes-back-to-haunt-users-as-hackers-steal-usd12-million-in-two-days">hackers stole $12.38 million in cryptocurrency from LastPass users</a> on 16 and 17 December 2024.</p><p>Chris Linnell, associate director of data privacy at Bridewell, said the ICO fine represents a “big moment” for the industry and highlights the need for more robust processes at password managers.</p><p>These platforms hold the keys to the castle for enterprises and consumers alike, and security practices at providers should reflect that. </p><p>"It’s not the largest penalty we’ve seen under John Edwards, but it definitely plays into public expectations - people trust password managers to keep them safe, so when they fall short, it makes headlines," he said.</p><p>"For service providers, this is a reminder that security isn’t just about the product itself. You need strong information security and privacy frameworks in place, and you can’t ignore the less obvious risks - backups, secondary databases, and other systems that attackers often target.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/most-passwords-take-a-matter-of-minutes-to-crack-heres-how-you-can-create-strong-hacker-resistant-credentials">Most passwords take a matter of minutes to crack</a></li><li><a href="https://www.itpro.com/security/passwords-are-a-problem-why-device-bound-passkeys-can-be-the-future-of-secure-authentication">Passwords are a problem: why device-bound passkeys can be the future of secure</a></li><li><a href="https://www.itpro.com/security/how-to-create-a-secure-password-policy">How to create a secure password policy</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI hailed for ‘swift move’ in terminating Mixpanel ties after data breach hits developers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/openai-mixpanel-data-breach-response</link>
                                                                            <description>
                            <![CDATA[ The Mixpanel breach prompted OpenAI to launch a review into its broader supplier ecosystem ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MDQfVCJ8MCJubZ3CYXKfEP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Nov 2025 10:14:10 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Nov 2025 10:14:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:description>                                                            <media:text><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has admitted a <a href="https://www.itpro.com/business-operations/supply-chain-management-scm/361208/supply-chain-cyber-security-breach-impacted">security breach at a third-party supplier</a> exposed customer emails, location information, and “limited analytics data related to some users of the API”.</p><p>The supplier, Mixpanel, provides data analytics services via OpenAI’s developer platform. OpenAI said the platform is used to help “understand product usage” and improve services for its API product, <em>platform.openai.com</em>. </p><p>On 9 November, Mixpanel discovered an attacker gained unauthorized access to systems. They then exfiltrated a dataset containing “limited customer identifiable information and analytics information”.</p><p>A full outline of data exposed, per an <a href="https://openai.com/index/mixpanel-incident/" target="_blank"><u>OpenAI statement</u></a> on the breach, includes:</p><ul><li>Names provided via Mixpanel API accounts</li><li>Email addresses associated with the API account</li><li>“Aproximate course location based on API user browsers” (including city, state, and country)</li><li>Information on operating systems and browsers used to access the API account</li><li>Referring websites associated with the API account</li></ul><p>OpenAI has been keen to stress that the breach only affects developers and not general <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT </a>users. It also said developer credentials – including passwords, payment information, and government IDs – weren’t exposed.</p><p>OpenAI added that it’s currently in the process of notifying those affected by the incident.</p><h2 id="a-swift-response-from-openai">A swift response from OpenAI </h2><p>Upon discovery of the breach, OpenAI said it removed Mixpanel from production services and began a review of affected datasets.</p><p>While the investigation is still ongoing, the company noted it has so far found “no evidence of any effect on systems or data outside Mixpanel’s environment”.</p><p>The company has since terminated its use of the data analytics platform and said it will conduct a review of its broader supplier ecosystem.</p><p>“Trust, security, and privacy are foundational to our products, our organisation, and our mission, OpenAI said in a statement. “We also hold our partners and vendors accountable for the highest bar for security and privacy of their services.” </p><p>Jake Moore, global <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>advisor at ESET, commended OpenAI for its “swift move” in alerting users and cutting ties with the supplier. Many organizations try to minimize security incidents and keep them “under the radar”, he said.</p><p>“Companies often fear the aftermath of an attack and presume it will be brand damaging,” Moore commented. “However, openness is now deemed far more important and speed is usually of the essence in making anyone affected aware of the situation.” </p><h2 id="developers-warned-to-remain-vigilant">Developers warned to remain vigilant</h2><p>OpenAI said information exposed in the breach could be used by hackers to carry out future attacks on users and encouraged them to “remain vigilant”. </p><p>These types of warnings are common in the wake of a data breach, according to Moore.</p><p>“Even though the exposed data was low-sensitivity, it could still be misused in the likes of <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> techniques or via phishing attacks because attackers could combine the data such as name, email, even approximate location data to craft convincing fraudulent messages,” he explained.</p><p>“As within the wake of typical data compromises, those affected need to remain vigilant for suspicious emails or other strange communications.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster">Gartner says 40% of enterprises will experience ‘shadow AI’ breaches by 2030</a></li><li><a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life">AI breaches aren’t just a scare story any more – they’re happening in real life</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/impact-of-asahi-cyber-attack-laid-bare-as-company-confirms-1-5-million-customers-exposed">Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Salesforce customers face second third-party incident this year with Gainsight breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/salesforce-customers-face-second-third-party-incident-this-year-with-gainsight-breach</link>
                                                                            <description>
                            <![CDATA[ Customers impacted in the Gainsight breach have been contacted by Salesforce ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qTE6fpj5PizQQtajB84wnX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AhWVHwr3N7svLFMPwB8hdj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Nov 2025 10:22:54 +0000</pubDate>                                                                                                                                <updated>Fri, 21 Nov 2025 10:23:40 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AhWVHwr3N7svLFMPwB8hdj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Salesforce logo pictured at the 8th China International Import Expo in Shanghai, China.]]></media:description>                                                            <media:text><![CDATA[Salesforce logo pictured at the 8th China International Import Expo in Shanghai, China.]]></media:text>
                                <media:title type="plain"><![CDATA[Salesforce logo pictured at the 8th China International Import Expo in Shanghai, China.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AhWVHwr3N7svLFMPwB8hdj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Salesforce has launched an investigation into a spate of customer data theft incidents following a breach at a third-party application provider. </p><p>In a statement on Thursday 20 November, the <a href="https://www.itpro.com/desktop-software/28214/what-is-crm">CRM </a>giant revealed it had revoked access and refresh tokens for Gainsight-published applications as part of its response to the breach.</p><p>Gainsight is a <a href="https://www.itpro.com/cloud/software-as-a-service-saas/362655/what-is-saas">software as a service (SaaS)</a> provider specializing in customer success and product experience, available to Salesforce customers via the company’s App Exchange platform. </p><div class="product"><a data-dimension112="aaaf8d71-fd4b-41f5-a201-e9907f237f2e" data-action="Deal Block" data-label="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" data-dimension48="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" href="https://go.nordstellar.net/aff_c?offer_id=927&aff_id=3013" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="prj52bKoz6iFWo8GH6geVE" name="01-Afiiliate-Black-friday-1200x1200" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/prj52bKoz6iFWo8GH6geVE.jpg" mos="" align="middle" fullscreen="" width="1200" height="1200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>Stay ahead of cyber risks with the NordStellar threat intelligence platform.</p><p><a href="https://go.nordstellar.net/aff_c?offer_id=927&aff_id=3013" target="_blank" rel="sponsored" data-dimension112="aaaf8d71-fd4b-41f5-a201-e9907f237f2e" data-action="Deal Block" data-label="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" data-dimension48="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" data-dimension25="">Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off</a><a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=927&aff_id=3013" target="_blank" rel="nofollow" data-dimension112="aaaf8d71-fd4b-41f5-a201-e9907f237f2e" data-action="Deal Block" data-label="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" data-dimension48="Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off" data-dimension25="">View Deal</a></p></div><p>“Salesforce has identified unusual activity involving Gainsight-published applications connected to Salesforce, which are installed and managed directly by customers,” the company said in an <a href="https://status.salesforce.com/generalmessages/20000233" target="_blank"><u>advisory</u></a>. </p><p>Salesforce noted that a preliminary investigation suggests the breach could have enabled “unauthorized access to certain customers’ Salesforce data” through Gainsight connections. </p><p>“Upon detecting the activity, Salesforce revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while our investigation continues,” the advisory added.</p><p>Exact details on the scope of the incident and those affected are yet to be revealed. However, Salesforce confirmed that affected customers have been notified. </p><h2 id="gainsight-the-latest-third-party-incident-for-salesforce">Gainsight the latest third-party incident for Salesforce</h2><p>The Gainsight incident marks the latest third-party application breach for Salesforce in recent months. </p><p>Earlier this year, the <a href="https://www.itpro.com/security/cyber-attacks/salesloft-drift-hackers-had-access-to-company-github-account-for-months-before-attacks">Salesloft Drift attack</a> impacted <a href="https://www.itpro.com/security/data-breaches/the-salesloft-drift-victim-list-keeps-growing-zscaler-is-the-latest-to-confirm-a-breach-warning-customers-to-remain-wary-of-follow-up-phishing-attacks">hundreds of companies</a> including Google, Zscaler, Cloudflare, and Palo Alto Networks.</p><p>Hackers gained access to sensitive customer data through compromised OAuth tokens associated with the third-party application. </p><p>Brian Soby, <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO </a>and co-founder at AppOmni, said the scale of Gainsight integrations means this latest incident could have equally wide-reaching implications for an array of businesses. </p><p>“Gainsight is widely deployed and tightly connected to Salesforce, Slack, Google, Microsoft, and numerous other SaaS environments,” he said. “Because of that footprint, customers now have to quickly identify every location where Gainsight was integrated.”</p><p>Soby added that the Gainsight incident once again highlights “persistent weaknesses” in SaaS <a href="https://www.itpro.com/software/enterprises-need-to-sharpen-up-on-software-supply-chain-security">supply chain security</a> practices. </p><p>“The attack closely mirrors the earlier Drift breach, which also targeted Salesforce, Google Workspace, and other widely used SaaS platforms,” he told ITPro. </p><p>“The scale of the Gainsight compromise underscores that many organizations did not apply the lessons they should have learned from Drift, leaving large portions of their SaaS supply chain exposed.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics">These five countries recorded the most third-party data breaches last year</a></li><li><a href="https://www.itpro.com/security/data-at-risk-helping-your-customers-close-gaps-in-their-supply-chain">How to help your customers close gaps in their supply chain</a></li><li><a href="https://www.itpro.com/security/insurance-sector-urged-to-sharpen-up-third-party-risk-management-as-attacks-surge">Insurance sector urged to sharpen up third-party risk management as attacks surge</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says reports of a 'huge' Gmail breach affecting millions of users are false, again ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/gmail-breach-google-response-false-reports</link>
                                                                            <description>
                            <![CDATA[ Reports of a major Gmail affecting millions of users have been flooding the web this week – Google says they're "false" and you've nothing to worry about. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YeLXVW2NwJY83JK9Us9oDD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gyQphU3BYARqyhz77wVsLV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Oct 2025 09:36:44 +0000</pubDate>                                                                                                                                <updated>Wed, 29 Oct 2025 09:39:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gyQphU3BYARqyhz77wVsLV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Gmail logo and branding pictured on a smartphone screen with laptop keyboard pictured in background.]]></media:description>                                                            <media:text><![CDATA[Gmail logo and branding pictured on a smartphone screen with laptop keyboard pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Gmail logo and branding pictured on a smartphone screen with laptop keyboard pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gyQphU3BYARqyhz77wVsLV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Google has hit back at claims of a massive Gmail breach, suggesting recent reports stem from a “misunderstanding of infostealer databases”.</p><p>In a <a href="https://x.com/NewsFromGoogle/status/1982893232934793655" target="_blank"><u>post on X</u></a>, the tech giant insisted Gmail's defenses are “strong, and users remain protected” in a bid to calm customer concerns. </p><p>“The inaccurate reports are stemming from a misunderstanding of <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">infostealer </a>databases, which routinely compile various credential theft activity occurring across the web,” Google said. </p><p>“It’s not reflective of a new attack aimed at any one person, tool, or platform.”</p><p>The company’s sharp response comes after a host of publications reported that 183 million Gmail accounts had been compromised in what one outlet described as a "huge data breach".</p><p>Speculation over a breach mounted after a sizable dataset was added to the <em>Have I Been Pwned</em> database, which allows web users to check if their credentials have been compromised. </p><p>In a <a href="https://www.troyhunt.com/inside-the-synthient-threat-data/" target="_blank"><u>blog post</u></a> dissecting the dataset, which was collated by researchers at Synthient, creator Troy Hunt noted these records were the culmination of several years’ worth of infostealer activity, instead of a newly discovered breach. </p><p>Regardless, several outlets pounced on the situation. In response to a comment under his original blog post, Hunt echoed Google’s response to the coverage. </p><p>“I think they're deliberately misleading and designed to drive eyeballs on ads whilst the truth gets buried somewhere further down in the story,” he wrote. </p><h2 id="gmail-breach-claims-are-a-dime-a-dozen">Gmail breach claims are a dime a dozen</h2><p>This isn’t the first time Google has been forced to push back against reports of a Gmail breach. Indeed, it’s the second in the space of three months. </p><p>In late August, reports of a <a href="https://www.itpro.com/security/cyber-attacks/google-says-claims-of-a-major-gmail-security-warning-are-false-following-recent-media-reports"><u>major incident that impacted some 2.5 billion Gmail accounts</u></a> began circulating online, once again prompting a statement from the tech giant in which it refuted the claims. </p><p>In a <a href="https://blog.google/products/workspace/gmail-security-protections/" target="_blank"><u>blog post</u></a>, Google described reports as “entirely false” and said there was no risk to users. </p><p>"We want to reassure our users that Gmail’s protections are strong and effective,” the company said. </p><p>“Several inaccurate claims surfaced recently that incorrectly stated that we issued a broad warning to all Gmail users about a major Gmail security issue. This is entirely false.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/warning-issued-over-critical-flaws-spotted-in-tp-link-routers">Warning issued over critical flaws spotted in TP-Link routers</a></li><li><a href="https://www.itpro.com/security/cisa-issues-alert-after-botched-windows-server-patch-exposes-critical-flaw">CISA issues alert after botched Windows Server patch exposes critical flaw</a></li><li><a href="https://www.itpro.com/security/enterprises-cant-keep-a-lid-on-surging-cyber-incident-costs">Enterprises can’t keep a lid on surging cyber incident costs</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Capita fined £14 million after it 'failed to ensure the security' of personal data ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/capita-fined-gbp14-million-after-it-failed-to-ensure-the-security-of-of-personal-data</link>
                                                                            <description>
                            <![CDATA[ Capita CEO Adolfo Hernandez has since "accelerated" the company's cybersecurity transformation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3LyRW5bgjJS55SgXfnzHvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bDxyuoGYyjQTo3VwC9iaP3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 15 Oct 2025 10:38:06 +0000</pubDate>                                                                                                                                <updated>Wed, 15 Oct 2025 10:53:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bDxyuoGYyjQTo3VwC9iaP3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Capita logo pictured on a smartphone with branding pictured in background.]]></media:description>                                                            <media:text><![CDATA[Capita logo pictured on a smartphone with branding pictured in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Capita logo pictured on a smartphone with branding pictured in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bDxyuoGYyjQTo3VwC9iaP3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A data breach affecting over six million people has resulted in a £14 million fine for professional services firm Capita following an investigation by the UK <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner’s Office (ICO)</a>.</p><p>The fine is split between Capita Plc and Capita Pension Solutions, which have been billed £8 million and £6 million respectively for the March 2023 attack.</p><p>According to the ICO, the UK’s data protection authority, Capita failed in three areas: preventing privilege escalation and unauthorized lateral movement, responding appropriately to security alerts, and penetration and risk assessment.</p><p>The <a href="https://www.itpro.com/security/data-breaches/capita-finally-admits-breach-affecting-4-of-its-servers">attack began on 22 March 2023</a> after an employee downloaded a malicious file, and an alert was issued within just 10 minutes. However, the company failed to act on this alert for over a day – 58 hours in total versus a target response time of one hour.</p><p>A lack of tiering for admin accounts also enabled the attacker to escalate privileges and move laterally across multiple domains, the ICO found. </p><p>According to the data protection watchdog, these actions were flagged on at least three occasions as a vulnerability but none were acted on. Ultimately this enabled the attacker to gain access to critical data, nearly one terabyte of which was exfiltrated. </p><p>On 31 March – nine days after the attack started – the threat actor deployed ransomware onto the company’s systems and reset all user passwords.</p><p>In total, 6.6 million people had their personal information stolen from Capita’s systems, including pension records, staff records, and the details of customers of organizations supported by Capita.</p><p>John Edwards, the UK’s information commissioner, said: “The scale of this breach and its impact could have been prevented had sufficient security measures been in place.</p><p><strong>“</strong>When a company of Capita’s size falls short, the consequences can be significant. Not only for those whose data is compromised – many of whom have told us of the anxiety and stress they have suffered – but for wider trust amongst the public and for our future prosperity. As our fine shows, no organisation is too big to ignore its responsibilities.”</p><p>"Maintaining good <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>is fundamental to economic growth and security,” Edwards continued. “Every organization, no matter how large, must take proactive steps to keep people's data secure. Cyber criminals don't wait, so businesses can't afford to wait either – taking action today could prevent the worst from happening tomorrow."</p><p>In response to the settlement, Capita said it’s “committed to upholding the security of its data and protection of our systems for our clients and their customers”. </p><p>The company added that it has contacted everyone affected or potentially affected by the breach.</p><p>Capita’s CEO Adolfo Hernandez, who joined the company a year after the attack, added: “When I joined as CEO … I accelerated our cybersecurity transformation, with new digital and technology leadership and significant investment. As a result, we have hugely strengthened our cybersecurity posture, built in advanced protections and embedded a culture of continuous vigilance."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/74-percent-of-companies-admit-insecure-code-caused-a-security-breach">74% of companies admit insecure code caused a security breach</a></li><li><a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life">AI breaches aren’t just a scare story any more – they’re happening in real life</a></li><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Plex data breach so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/everything-we-know-about-the-plex-data-breach-so-far</link>
                                                                            <description>
                            <![CDATA[ Plex advised users to sign out of any connected devices that are currently logged in and enable two-factor authentication if they haven’t already. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YMFuhVYN4e5aY8M9BPQeRU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wh6oNFSU5hvLkbCVQ4z3dc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 10 Sep 2025 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wh6oNFSU5hvLkbCVQ4z3dc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Plex streaming service logo pictured on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Plex streaming service logo pictured on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Plex streaming service logo pictured on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wh6oNFSU5hvLkbCVQ4z3dc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Plex streaming platform had told customers to reset their passwords following a data breach. </p><p>In an advisory, the company said users should also sign out of any connected devices that are currently logged in and enable two-factor authentication if they haven’t already.</p><p>"An unauthorized third party accessed a limited subset of customer data from one of our databases. While we quickly contained the incident, information that was accessed included device type, emails, user names and authentication data," it said.</p><div class="product"><a data-dimension112="dc40ec1d-ecea-4308-80b6-0e286c6a17d1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="dc40ec1d-ecea-4308-80b6-0e286c6a17d1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="dc40ec1d-ecea-4308-80b6-0e286c6a17d1" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"We’ve already addressed the method that this third party used to gain access to the system, and we’re undergoing additional reviews to ensure that the security of all of our systems is further strengthened to prevent future attacks."</p><p>Plex also said that any account passwords accessed were securely-hashed, and couldn't be read by a third party. It added that credit card data wasn't stored on its servers and was therefore secure.</p><h2 id="who-is-responsible-for-the-plex-data-breach">Who is responsible for the Plex data breach?</h2><p>No group has claimed responsibility for the attack thus far. While it's not known how many people may have been affected, the company has around 25 million users around the world.</p><p>Kev Breen, senior director of cyber <a href="https://www.itpro.com/security/hackers-are-using-ai-to-dissect-threat-intelligence-reports-and-vibe-code-malware">threat intelligence</a> at Immersive, said this makes Plex – and other streaming services – an attractive target. </p><p>“The infrastructure of streaming platforms often includes cloud storage, content delivery networks, APIs, and user-facing apps. This complex infrastructure creates multiple entry points for attackers to exploit," Breen commented.</p><p>"As well as personally identifiable information, streaming platforms also store data on user preferences, meaning attackers can develop more targeted social engineering campaigns. Such data is likely to be leveraged by cyber criminals to extort money from Plex, as well as for <a href="https://www.itpro.com/security/privacy/367885/identity-theft-what-it-is-and-how-it-can-affect-your-business">identity theft</a> and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns.</p><h2 id="plex-has-previous">Plex has previous</h2><p>This isn't the first time that Plex has experienced a data breach. Back in 2015, threat actors gained access to the company's forum and blog server, exposing IP addresses, private messages, emails, and encrypted forum passwords.</p><p>Similarly, in 2022 the <a href="https://www.itpro.com/security/data-breaches/368878/plex-confirms-passwords-emails-stolen-in-limited-data-breach"><u>company warned customers of a breach</u></a> after a database containing account information such as usernames and passwords was compromised. </p><p>Its message to users was uncannily similar to those being received by customers today. On that occasion, though, the company's servers struggled to cope with the large volume of password reset requests being made.</p><p>Breen warned that it's not just home users that need to take the warning seriously.</p><p>"Plex is unlikely to be used in an enterprise setting; however, people often re-use passwords or follow patterns when creating them. This means that a user affected at home could also have an impact on organizations," he said.</p><p>"Business leaders must be able to demonstrate cyber capabilities across their workforce through regular exercises, and improve them through targeted skills development.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/the-salesloft-drift-victim-list-keeps-growing-zscaler-is-the-latest-to-confirm-a-breach-warning-customers-to-remain-wary-of-follow-up-phishing-attacks">Zscaler is the latest company hit in the expanding Salesloft Drift victims list</a></li><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li><li><a href="https://www.itpro.com/security/74-percent-of-companies-admit-insecure-code-caused-a-security-breach">74% of companies admit insecure code caused a security breach</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Salesloft Drift victim list keeps growing: Zscaler is the latest to confirm a breach, warning customers to remain wary of follow-up phishing attacks ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/the-salesloft-drift-victim-list-keeps-growing-zscaler-is-the-latest-to-confirm-a-breach-warning-customers-to-remain-wary-of-follow-up-phishing-attacks</link>
                                                                            <description>
                            <![CDATA[ The company has warned customers that their data may have been accessed, saying it's implemented extra safeguards in response ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pWMpfispg8TG2K3UXJcYMB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hp6mLxakPPx4sAHg3VCe46-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 02 Sep 2025 15:15:00 +0000</pubDate>                                                                                                                                <updated>Tue, 02 Sep 2025 15:51:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hp6mLxakPPx4sAHg3VCe46-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zscaler logo displayed on a smartphone screen with branding in background.]]></media:description>                                                            <media:text><![CDATA[Zscaler logo displayed on a smartphone screen with branding in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Zscaler logo displayed on a smartphone screen with branding in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hp6mLxakPPx4sAHg3VCe46-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/what-are-the-benefits-of-unified-cloud-security">Cloud security</a> firm Zscaler is latest organization to disclose that it's been hit by a data breach linked to the recent Salesloft Drift attacks.</p><p>The incident, like many others, involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce databases to manage leads and contact information.</p><p>"As part of this campaign, unauthorized actors gained access to Salesloft Drift credentials of its customers including Zscaler," the company said in an <a href="https://www.zscaler.com/blogs/company-news/salesloft-drift-supply-chain-incident-key-details-and-zscaler-s-response" target="_blank">advisory</a>.</p><div class="product"><a data-dimension112="4b26be1f-c724-4337-acb3-91d981b4d042" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="4b26be1f-c724-4337-acb3-91d981b4d042" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="4b26be1f-c724-4337-acb3-91d981b4d042" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>"Following a detailed review as part of our ongoing investigation, we have determined that these credentials have allowed limited access to some Zscaler Salesforce information."</p><p>Data accessed in the breach consisted of publicly available details for points of contact, along with specific Salesforce-related content.</p><p>This included names, business email addresses, job titles, phone numbers, location details, Zscaler product licensing and commercial information, and plain text content from certain support cases, although this didn't include attachments, files, or images.</p><p>"After extensive investigation, Zscaler has currently found no evidence to suggest misuse of this information," said the firm. </p><h2 id="zscaler-moved-quickly-to-limit-exposure">Zscaler moved quickly to limit exposure</h2><p>In its advisory, the company said it has since moved to revoke Salesloft Drift’s access to Zscaler’s Salesforce data, rotated other API access tokens to be on the safe side, and launched a detailed investigation into the scope of the event. </p><p>This includes close collaboration with Salesforce to examine the incident.</p><p>It has also implemented extra safeguards and strengthened protocols to defend against similar incidents in the future, launched a third party risk management investigation for vendors used by Zscaler, and strengthened customer authentication protocol when responding to customer calls. </p><p>This, the company said, aims to safeguard against potential <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attacks in the wake of the incident. Like others impacted in Salesloft-related attacks, Zscaler has warned customers to remain vigilant for <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attempts. </p><p>"It’s crucial to exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information," it said. </p><p>"Always verify the source of communication and never disclose passwords or financial data via unofficial channels."</p><h2 id="what-happened-with-the-salesloft-drift-attacks">What happened with the Salesloft Drift attacks?</h2><p>The breach stems from an incident in early August, when attackers identified as UNC6395 compromised OAuth tokens associated with sales workflow automation software Salesloft Drift. </p><p>They then used these stolen tokens to extract large volumes of data from a number of corporate Salesforce instances, including sensitive credentials such as <a href="https://www.itpro.com/cloud/infrastructure-as-a-service-iaas/362608/what-is-aws">Amazon Web Services (AWS)</a> access keys (AKIA), passwords, and Snowflake-related access tokens.</p><p>Last week, Google’s Threat Intelligence Group (GTIG) <a href="https://www.itpro.com/security/cyber-attacks/warning-issued-to-salesforce-customers-after-hackers-stole-salesloft-drift-data"><u>warned</u></a> that the breach had been broader than first thought.</p><p>"Based on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations," it said. </p><p>"We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised.” </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/google-says-claims-of-a-major-gmail-security-warning-are-false-following-recent-media-reports">Google says 'claims of a major Gmail security warning are false'</a></li><li><a href="https://www.itpro.com/security/data-breaches/transunion-breach-what-can-customers-do">4.5 million people just had their data exposed in the TransUnion breach</a></li><li><a href="https://www.itpro.com/security/enterprises-need-to-patch-these-citrix-flaws-now">Enterprises need to patch these Citrix flaws now</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 4.5 million people just had their data exposed in the TransUnion breach – here’s what customers need to know ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/transunion-breach-what-can-customers-do</link>
                                                                            <description>
                            <![CDATA[ The credit reporting agency is believed to be the latest victim of a Salesforce-based attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EckGsnkJtukzomo3bGX38L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tcjbPDVR8ECqavtUZHFEma-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 29 Aug 2025 10:28:27 +0000</pubDate>                                                                                                                                <updated>Fri, 29 Aug 2025 11:37:33 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tcjbPDVR8ECqavtUZHFEma-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TransUnion logo pictured on a sign outside the company headquarters in Chicago, Illinois, USA.]]></media:description>                                                            <media:text><![CDATA[TransUnion logo pictured on a sign outside the company headquarters in Chicago, Illinois, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[TransUnion logo pictured on a sign outside the company headquarters in Chicago, Illinois, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tcjbPDVR8ECqavtUZHFEma-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Credit scoring and monitoring firm TransUnion has confirmed a data breach which exposed data belonging to nearly 4.5 million people. </p><p>TransUnion is one of the big three credit reporting agencies in the US, along with Experian and Equifax, collecting and updating credit information on consumers and businesses.</p><p>In a <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/3dcd9b7c-bce3-4685-bffd-f728ce96e2fd.html?7194ef805fa2d04b0f7e8c9521f97343" target="_blank"><u>filing</u></a> with the Office of the Maine Attorney General, the company revealed it experienced a breach on 28th July, which it discovered two days later. It said the data of 4,461,511 people had been affected.</p><p>"We recently experienced a cyber incident involving a third-party application serving our US consumer support operations. The unauthorized access includes some limited personal information belonging to you," TransUnion said in a template <a href="https://www.maine.gov/cgi-bin/agviewerad/ret?loc=2968" target="_blank"><u>letter</u></a> now being sent to customers.</p><p>"We regret any concern caused by this incident and take seriously the responsibility to help secure consumer information."</p><h2 id="what-data-was-exposed-in-the-transunion-breach">What data was exposed in the TransUnion breach?</h2><p>According to TransUnion, no credit information was accessed during the cyber incident. The company has promised customers two years’ free credit monitoring services and proactive fraud assistance from its Cyberscout subsidiary.</p><p>The incident is widely believed to be just the latest Salesforce breach, following attacks on more than 700 companies, including Google, Adidas, Farmers Insurance, Allianz Life, Workday, Cisco, Chanel and several airlines.</p><p>These attacks have been claimed by <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>group ShinyHunters, as well as, more recently, a group known as UNC6395.</p><p>“This incident poses a significantly higher risk to victims than many of the other Salesforce related breaches disclosed so far because it involves Social Security numbers in addition to contact and support data," said Cory Michal, chief security officer at AppOmni.</p><p>“While most of the previous attacks have exposed sensitive but less critical information, the compromise of SSNs creates far greater potential for identity theft, financial fraud, and long-term misuse of personal data," he added. </p><p>"That elevates the impact of the TransUnion breach well above other recent disclosures, even if the number of affected individuals is smaller."</p><h2 id="fresh-salesforce-warnings-issued">Fresh Salesforce warnings issued</h2><p>Earlier this week, Google's Threat Intelligence Group warned of 'widespread data theft', saying that attackers weren't just exploiting the Salesforce integration with Salesloft Drift, but <a href="https://www.itpro.com/security/cyber-attacks/warning-issued-to-salesforce-customers-after-hackers-stole-salesloft-drift-data"><u>that other integrations were impacted too</u></a>. </p><p>Salesloft Drift customers should treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised, it said.</p><p>Many more disclosures are likely coming, Michal suggested. </p><p>“What we’re seeing now is likely the leading edge of a much larger wave of public disclosures, as investigations conclude and regulatory timelines come due," he said. </p><p>"It’s also important to note that the TransUnion disclosure appears to stem from an earlier UNC6040 campaign, based on the breach dates in their filing, which underscores that multiple overlapping threat actor groups are actively exploiting SaaS environments like Salesforce."</p><p>The breach could cost TransUnion dear. In 2017, the personal data of more than 147 million people was accessed when rival credit bureau Equifax was hacked. </p><p>The company was forced by the Federal Trade Commission to set aside $425 million to help affected consumers.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life">AI breaches aren’t just a scare story any more</a></li><li><a href="https://www.itpro.com/security/data-breaches/air-france-and-klm-confirm-customer-data-stolen-in-third-party-breach">Air France and KLM confirm customer data stolen in third-party breach</a></li><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The Allianz Life data breach just took a huge turn for the worse ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/allianz-life-data-breach-customer-accounts-impacted</link>
                                                                            <description>
                            <![CDATA[ Around 1.1 million Allianz Life customers are believed to have been impacted in a recent data breach, making up the vast majority of the insurer's North American customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ADG2qEJ4qjUX9B5Uh9ZWSX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 20 Aug 2025 10:40:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:description>                                                            <media:text><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The true scale of the Allianz Life data breach has been laid bare, with leaked credential notification site <em>Have I Been Pwned</em> putting the number of affected accounts at 1.1 million.</p><p>The numbers represent the vast majority of the company's  1.4 million customers in the North America region, along with the data of financial professionals and some Allianz Life employees contained in Salesforce Accounts and Contacts databases.</p><p>Data exposed in the incident is <a href="https://haveibeenpwned.com/Breach/AllianzLife" target="_blank"><u>believed to include</u></a> dates of birth, email addresses, genders, names, phone numbers, and physical addresses. According to Allianz, Social Security numbers were also taken.</p><p>More than seven-in-ten of the exposed email addresses had already been affected by previously-disclosed data breaches. </p><p>When the <a href="https://www.itpro.com/security/data-breaches/everything-we-know-about-the-allianz-life-data-breach-so-far">breach was first confirmed</a>, Allianz Life said that 'most' of its North American customers had been affected, but that its core network and policy administration systems didn't appear to have been accessed.</p><p>The insurer said it would provide a full consumer notice once it has finished identifying and contacting affected individuals.</p><p>Jon Abbott, CEO of ThreatAware, described the scale of the breach as “significant”, noting that the data leaked represents a treasure trove of information to target victims. </p><p>"The sensitive and valuable information held in CRM tools is exactly why it’s targeted by attackers,” he said. “The data can be used by other cyber criminals for identity theft and <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns."</p><h2 id="what-happened-with-the-allianz-life-data-breach">What happened with the Allianz Life data breach?</h2><p>The breach, which took place on July 16 and was discovered a day later, is believed to have involved a <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attack that involved impersonating IT support staff.</p><p>This saw hackers ask employees to accept a connection to a Salesforce Data Loader, which was then used to exfiltrate data from the <a href="https://www.itpro.com/desktop-software/28214/what-is-crm">CRM </a>system. </p><p>The attackers used malicious OAuth applications to infiltrate Salesforce instances, before downloading the company databases.</p><p>The attack has since been claimed by <a href="https://www.itpro.com/security/hacking/369967/us-extradites-french-shinyhunters-hacker-faces-123-years-in-prison">the notorious ShinyHunters threat group</a>, which is believed to overlap with the <a href="https://www.itpro.com/security/cyber-crime/scattered-spider-group-marks-and-spencer">Scattered Spider</a> and Lapsus groups. They are now believed to be preparing a data leak site to pressure Allianz and other victims into making a ransom payment.</p><p>The group, which first emerged in 2020, is also believed to be responsible for attacks on Salesforce systems at several retailers, as well as at <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim">Google</a>, Cisco, <a href="https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed">Qantas</a>, Santander, Ticketmaster, Tokopedia, AT&T and most recently Workday. </p><p><a href="https://www.itpro.com/security/data-breaches/workday-data-breach-what-we-know-so-far">Workday confirmed it had fallen victim to an attack</a> last week, warning customers that exposed information could then be used in follow-up social engineering attacks - a common tactic for threat actors. </p><p>"Groups such as ShinyHunters rely on fast moving social engineering tactics – this typically involves calling and emailing employees of the victim organization and attempting to extort them. If this does not work, they then launch a leak site with the aim of pressuring victims into payment," said Abbott.</p><p>"This pattern in their attacks is why the security fundamentals are so important. Accurate asset inventories, tamper-proof identity verification and hardened service desk processes are all essential.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-kits-cyber-crime-dark-web">Cheap cyber crime kits can be bought on the dark web for less than $25</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Workday data breach so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/workday-data-breach-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ HR technology firm Workday has confirmed a data breach after threat actors gained access to a third-party CRM platform. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Jm5abTo6vo4uMAR9N8MDQg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3VSCM7dFbCcg8kjBcrEPoB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Aug 2025 10:48:57 +0000</pubDate>                                                                                                                                <updated>Mon, 18 Aug 2025 10:55:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3VSCM7dFbCcg8kjBcrEPoB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Workday logo and branding pictured on a sign in Davos, Switzerland ahead of the World Economic Forum (WEF).]]></media:description>                                                            <media:text><![CDATA[Workday logo and branding pictured on a sign in Davos, Switzerland ahead of the World Economic Forum (WEF).]]></media:text>
                                <media:title type="plain"><![CDATA[Workday logo and branding pictured on a sign in Davos, Switzerland ahead of the World Economic Forum (WEF).]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3VSCM7dFbCcg8kjBcrEPoB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/careers-and-training/workday-faces-lawsuit-over-alleged-ai-bias">Workday</a> has confirmed a data breach after threat actors gained access to a third-party <a href="https://www.itpro.com/desktop-software/28214/what-is-crm">customer relationship management (CRM)</a> platform. </p><p>In a <a href="https://blog.workday.com/en-us/protecting-you-from-social-engineering-campaigns-update-from-workday.html?" target="_blank"><u>blog post</u></a> on Friday, the HR tech giant said hackers gained access to sensitive information hosted on the affected CRM system, but insisted no customer tenants – or the data contained within – were accessed. </p><p>Information exposed in the breach primarily included contact details such as names, email addresses, and phone numbers, the company revealed. </p><p>“We recently identified that Workday had been targeted and threat actors were able to access some information from our third-party CRM platform,” the company stated in its advisory. </p><p>“There is no indication of access to customer tenants or the data within them. We acted quickly to cut the access and have added extra safeguards to protect against similar incidents in the future.”</p><p>Given the nature of the information exposed in the breach, Workday warned customers to be wary of potential social engineering campaigns in the wake of the incident. </p><p>“It’s important to remember that Workday will never contact anyone by phone to request a password or any other secure details,” the firm said. “All official communications from Workday come through our trusted support channels.”</p><p>Kevin Marriott, senior manager of cyber and head of <a href="https://www.itpro.com/security/fighting-the-always-on-culture-thats-savaging-mental-health-in-cyber-security">SecOps </a>at Immersive, said this is a typical tactic observed in the aftermath of a data breach. </p><p>“This information is then used in subsequent social engineering attempts, or combined with other data already collected to make future <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attempts even more personalized, using the data captured," he said.</p><h2 id="workday-data-breach-the-latest-crm-based-incident">Workday data breach the latest CRM-based incident</h2><p>While Workday didn’t specifically identify the CRM system affected in the breach, the news comes in the wake of a string of Salesforce-based attacks on enterprises globally.</p><p>Threat intelligence research shows that the ShinyHunters threats group has conducted a wide-reaching campaign targeting Salesforce users in recent months. </p><p>Companies impacted in the campaign are believed to include Qantas, <a href="https://www.itpro.com/security/data-breaches/everything-we-know-about-the-allianz-life-data-breach-so-far"><u>Allianz Life</u></a>, Adidas, and several other retail brands worldwide. </p><p>Similarly, Google recently confirmed it had been attacked as part of the campaign. The discovery came after threat researchers at the tech giant <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim"><u>investigating the ShinyHunters group realized it too had fallen victim</u></a>. </p><p>The social engineering campaign involves duping employees into linking a malicious OAuth app to the target company’s Salesforce instances. </p><p>Once access to an impacted database has been achieved, threat actors are then able to access, query, and exfiltrate sensitive information from customer environments, according to Google’s <a href="https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion?rev=7194ef805fa2d04b0f7e8c9521f97343" target="_blank"><u>blog post</u></a> detailing the campaign. </p><p>Marriott noted that CRM tools are a popular target for threat actors, largely due to the volume of useful information hosted on these platforms. </p><p>“CRM tooling is often a key target for threat actors as they typically store limited, but valuable information that threat actors can either use themselves or sell on, with databases full of information that is useful such as email addresses and other personal information,” he said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/banking-details-of-30-million-santander-customers-exposed-during-breach-allegedly-up-for-sale-on-the-dark-web">Banking details of 30 million Santander customers exposed during breach</a></li><li><a href="https://www.itpro.com/security/ransomware/nearly-one-third-of-ransomware-victims-are-hit-multiple-times-even-after-paying-up-to-hackers">Nearly one-third of ransomware victims are hit multiple times</a></li><li><a href="https://www.itpro.com/security/hacking/369967/us-extradites-french-shinyhunters-hacker-faces-123-years-in-prison">US extradites French ShinyHunters hacker, faces 123 years in prison</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 6.4 million Bouygues Telecom customers just had their data exposed in a huge data breach – and it's the second to hit French telecoms operators in a month ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/6-4-million-bouygues-telecom-just-had-their-data-exposed-in-a-huge-data-breach-and-its-the-second-to-hit-french-telecoms-operators-in-a-month</link>
                                                                            <description>
                            <![CDATA[ A broad range of customer data was exposed, according to Bouygues Telecom ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">f2msWyRyNUY4MiRYJDxXkK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WCVrVMmrn2pMKaF56iNA3j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 08 Aug 2025 10:25:06 +0000</pubDate>                                                                                                                                <updated>Mon, 11 Aug 2025 15:50:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WCVrVMmrn2pMKaF56iNA3j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Bouygues Telecom logo pictured on a storefront in Lille, France.]]></media:description>                                                            <media:text><![CDATA[Bouygues Telecom logo pictured on a storefront in Lille, France.]]></media:text>
                                <media:title type="plain"><![CDATA[Bouygues Telecom logo pictured on a storefront in Lille, France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WCVrVMmrn2pMKaF56iNA3j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Bouygues Telecom, France's third-largest phone carrier, has confirmed a data breach which exposed personal data belonging to millions of customers across the country. </p><p>The company, which provides mobile, broadband, and digital TV services, said it discovered the breach, affecting 6.4 million of its 27 million customers, earlier this week. </p><p>It acted quickly to halt the attack and tighten its security procedures, the bank said in a statement, and is in the process of contacting those affected. </p><p>The data exposed in the breach includes contact details, contractual data, civil status data or, in the case of business customers, company data, as well as International Bank Account Numbers (IBANs). </p><p>Bouygues Telecom said bank card numbers and passwords were not affected. </p><p>"This situation could expose you to fraud attempts: fraudulent emails or calls. By using your information, a fraudster could pretend to be Bouygues Telecom or another company (bank, insurance company, etc.) and try, for example, to obtain additional information such as your credit card number or your usernames and passwords. We recommend that you be particularly vigilant," the firm told customers. </p><p>"Never share your usernames and passwords. Be particularly wary of calls from fake bank advisors who may try to gain your trust by giving your name or account number. If in doubt, end the call and call your bank or bank advisor back at their usual number."</p><p>While the leaked IBAN numbers aren't enough to allow attackers to carry out transactions such as direct debits or transfers, the company is warning customers to check withdrawals and be wary of <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>attempts citing their bank and account number.</p><p>The company said it has notified France’s data protection authority, the CNIL, and national <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>agency the Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI). </p><h2 id="bouygues-telecom-the-latest-french-carrier-hit">Bouygues Telecom the latest French carrier hit</h2><p>Bouygues Telecom is the latest french telecoms company to be hit with a data breach in recent weeks. Late last month, Orange announced that it had fallen victim to a cyber attack. </p><p>In this case, personal data doesn't appear to have been stolen, although the company was forced to warn its customers worldwide that service disruptions were likely as it worked to fix the issue. </p><p>It's not known who was responsible, or whether the two incidents were the work of the same hackers. However, similar attacks on US phone providers have been attributed to the China-linked Salt Typhoon hacking group.</p><p>Earlier this year, ANSSI issued a <a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2025-CTI-004/uv.fr/en/publications/cyber-threat-overview-2024"><u>warning</u></a> that the telecoms sector was under what it described as an 'intense' threat, citing incidents including a DDoS attack on OVH and suggesting that they were the work of Chinese groups.</p><p>"Cyber attacks are very common and affect any company, despite all existing security tools and procedures. We are constantly evolving our security procedures to address the constantly evolving attackers' methods," said Bouygues Telecom.</p><p>"Thanks to the responsiveness of our technical teams, we were able to resolve this incident and notify our customers as quickly as possible. Protecting our customers' data is a priority at Bouygues Telecom."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/air-france-and-klm-confirm-customer-data-stolen-in-third-party-breach">Air France and KLM confirm customer data stolen in third-party breach</a></li><li><a href="https://www.itpro.com/business/a-cybersecurity-researcher-just-discovered-a-treasure-trove-of-leaked-accounts-more-than-184-million-logins-were-readily-available-online-with-google-meta-and-apple-users-affected">A cybersecurity researcher just discovered a treasure trove of leaked accounts</a></li><li><a href="https://www.itpro.com/security/data-breaches/26-million-cvs-were-exposed-when-a-recruiting-software-firm-left-a-misconfigured-azure-container-open-cybersecurity-experts-warn-its-an-easy-mistake-thats-becoming-far-too-common">26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Air France and KLM confirm customer data stolen in third-party breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/air-france-and-klm-confirm-customer-data-stolen-in-third-party-breach</link>
                                                                            <description>
                            <![CDATA[ A spokesperson told ITPro the airlines are investigating "fraudulent access" to customer data following a third-party breach. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4Xj3Bq8KyfRD7z3m6dHm4A</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2CHFFFUyRYobEkt6tf4UdM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 07 Aug 2025 10:32:00 +0000</pubDate>                                                                                                                                <updated>Thu, 07 Aug 2025 14:14:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2CHFFFUyRYobEkt6tf4UdM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Air France-KLM Group logo pictured on the nose of an airplane at Schiphol Airport, Netherlands. ]]></media:description>                                                            <media:text><![CDATA[Air France-KLM Group logo pictured on the nose of an airplane at Schiphol Airport, Netherlands. ]]></media:text>
                                <media:title type="plain"><![CDATA[Air France-KLM Group logo pictured on the nose of an airplane at Schiphol Airport, Netherlands. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2CHFFFUyRYobEkt6tf4UdM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have gained access to the personal data of potentially hundreds of KLM and Air France customers following a supply chain attack.</p><p>News of the breach first appeared on the KLM website in Dutch, and an Air France-KLM spokesperson confirmed the situation, saying the intrusion happened last week (week commencing 28 July 2025).</p><p>In a statement to <em>ITPro</em>, a spokesperson said: “Air France and KLM confirm that they are investigating a fraudulent access to the data of some of our customers. </p><p>“An unusual activity was detected on a third-party platform used by our contact centers, which led our IT security team, together with the third-party system involved, to swiftly implement corrective measures to put an end to the incident.”</p><p>Protective measures have been taken to stop the same thing happening again, the spokesperson confirmed, adding that “no sensitive data such as password, travel data, Flying Blue Miles balance, passport or credit card numbers were disclosed”.</p><p>The breach only affects Air France and KLM customers, and both airlines are in the process of contacting these individuals. Customers are advised to be mindful of suspicious emails and phone calls in the wake of the incident. </p><p>The affected supplier has not been named for security reasons. However, KLM has reported the incident to the Dutch data protection regulator (Autoriteit Persoonsgegevens), while Air France has contacted the French equivalent (CNIL).</p><p>In a statement given to ITPro, a spokesperson for CNIL confirmed it has been notified of the breach and that affected individuals have been contacted. </p><p>"The CNIL is in the process of analyzing the notification," the spokesperson said. "The data involved are: Name, surname, contact information, Flying Blue membership number and status, and the subject of questions sent to the company by email."</p><h2 id="the-latest-in-a-long-line-of-supply-chain-attacks">The latest in a long-line of supply chain attacks</h2><p>Supply chain attacks have become <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-rife-this-is-what-developers-need-to-watch-out-for"><u>an increasingly popular method of compromise</u></a> for cyber criminals. </p><p>In 2024, <a href="https://www.itpro.com/software/software-supply-chain-attacks-are-soaring-and-security-leaders-are-sluggish-to-react"><u>security firm Checkmarx revealed</u></a> that 63% of companies had been the victim of a supply chain attack in the previous two years, while 75% of organizations using open source code packages said they were concerned or very concerned about software supply chain security.</p><p>Research also revealed in 2024 that nearly all (97%) of the top 100 US banks were <a href="https://www.itpro.com/security/nearly-all-of-the-top-us-banks-were-impacted-by-third-party-breaches-last-year"><u>hit by third party data breaches</u></a> such as the one affecting Air France-KLM, with a similar number subject to fourth-party breaches (suppliers to their suppliers).</p><p>SecurityScorecard’s <em>2025 Global Third-Party Breach Report</em> meanwhile found that the Netherlands – home to KLM – was one of the countries where <a href="https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics"><u>businesses were most likely to suffer a third-party breach</u></a>, coming in second after Singapore.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">The Scattered Spider hacker group has a new industry in its crosshairs</a></li><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li><li><a href="https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life">AI breaches aren’t just a scare story any more – they’re happening in real life</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI breaches aren’t just a scare story any more – they’re happening in real life ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/ai-breaches-arent-just-a-scare-story-any-more-theyre-happening-in-real-life</link>
                                                                            <description>
                            <![CDATA[ IBM research shows proper AI access controls are leading to costly data leaks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ukUefLgFA5dmDtYxMuMb9L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2VsMkEfJHEjz2ckAcEMvKJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 04 Aug 2025 13:03:25 +0000</pubDate>                                                                                                                                <updated>Mon, 04 Aug 2025 13:03:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2VsMkEfJHEjz2ckAcEMvKJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach costs concept image showing a red alert symbol pictured on a digitized circuit board.]]></media:description>                                                            <media:text><![CDATA[Data breach costs concept image showing a red alert symbol pictured on a digitized circuit board.]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach costs concept image showing a red alert symbol pictured on a digitized circuit board.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2VsMkEfJHEjz2ckAcEMvKJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI adoption is greatly outpacing <a href="https://www.itpro.com/security/ai-security-blunders-have-cyber-professionals-scrambling">AI security</a> and governance – that’s the message being sent by IBM following the release of its latest <em>Cost of Data Breach</em> report.</p><p>According to the company, 20% of the 600 organizations it surveyed had suffered a breach “due to security incidents involving <a href="https://www.itpro.com/software/development/shadow-ai-is-creeping-its-way-into-software-development-more-than-half-of-developers-admit-to-using-unauthorized-ai-tools-at-work-and-its-putting-companies-at-risk">shadow AI</a>”.</p><p>“For organizations with high levels of shadow AI, those breaches added USD 670,000 to the average breach price tag compared to those that had low levels of shadow IT or none,” it added.</p><div class="product"><a data-dimension112="52b72c49-1639-4820-a15a-f27c8b1da11d" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="52b72c49-1639-4820-a15a-f27c8b1da11d" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="52b72c49-1639-4820-a15a-f27c8b1da11d" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>While <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">shadow AI</a> is a problem in its own right according to the IBM report, legitimate AI tools can also cause problems.</p><p>“On average, 13% of organizations reported breaches that involved their AI models  or applications,” the report reads. </p><p>Most commonly, these weren’t direct attacks, but instead took place in the supply chain, for example through <a href="https://www.itpro.com/security/ai-tools-cyber-crime-application-exploits">compromised apps</a>, APIs, or plug-ins. The knock-on effects include operational disruption (31%) and broad data compromise (60%).</p><p>The report goes on to note, however, that once again a lack of governance and oversight was a significant factor in these breaches. Indeed, only 3% of organizations affected had proper <a href="https://www.itpro.com/cloud/cloud-security/ai-is-putting-your-cloud-workloads-at-risk">AI access controls</a> in place.</p><h2 id="generative-ai-is-being-used-as-an-attack-tool">Generative AI is being used as an attack tool</h2><p>Poor internal AI governance and shadow AI aren’t the only risks the technology presents to organizations. Cyber criminals are themselves making use of <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369959/what-is-generative-ai">generative AI</a> as a new tool in their arsenal.</p><p>IBM noted that one-in-six breaches in the past year involved AI, with would-be attackers able to polish and scale phishing campaigns and other <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attacks. </p><p>“IBM previously found gen AI reduced the time needed to craft a convincing phishing email from 16 hours down to only five minutes,” the report noted. </p><p>“This year’s report shows the impact: on average, 16% of data breaches involved attackers using <a href="https://www.itpro.com/strategy/28181/what-is-ai">AI</a>, most often for AI-generated phishing (37%) and deepfake impersonation attacks (35%).”</p><h2 id="data-breach-winners-and-losers">Data breach winners and losers</h2><p>While it’s hard to claim there are any winners when it comes to being the receiving end of a data breach, some find themselves losing more than others.</p><p>IBM found that the cost of a data breach in the US had increased by just under $1 million, bringing the average cost from $9.36 million to $10.22 million in 2025. </p><p>Organizations in the Middle East, the second most expensive region in which to experience a data breach, faced an average cost of $7.29 million, down from $8.57 million in 2024. </p><p>Like the US, Benelux and Canada also experienced a rise in costs, albeit less significant, going from $5.90 million to $6.24 million and $4.66 million to $4.84 million respectively. </p><p>The remaining geographies surveyed all sat at $4.14 million or under, with Brazil coming in last at $1.22 million, a fall of $140,000 from $1.36 million in 2024.</p><p>Another loser on the data breach scene is hackers themselves. IBM cited what it calls “ransomware fatigue”, with a slight majority (63%) of organizations hit by <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attacks in 2025 saying they didn’t pay the ransom, compared to 41% that did in 2024.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li><li><a href="https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics">These five countries recorded the most third-party data breaches last year</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-cost-uk-firms-64-billion-each-year">Cyber attacks are costing UK firms billions every year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Allianz Life data breach so far ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/everything-we-know-about-the-allianz-life-data-breach-so-far</link>
                                                                            <description>
                            <![CDATA[ The company has confirmed in a filing that data was accessed earlier this month ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gbr5TMbc3t3UxQnJur4jWS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 28 Jul 2025 10:01:18 +0000</pubDate>                                                                                                                                <updated>Mon, 28 Jul 2025 10:01:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:description>                                                            <media:text><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Allianz, parent company of Allianz Life, pictured in Berlin city center.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WyQDsXrph78RGRusAv8L7g-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Insurance giant Allianz Life is investigating a breach that has reportedly seen the data of most of its North American customers stolen.</p><p>Allianz Life, a subsidiary of Germany-based financial services firm Allianz SE, sells annuities and life insurance and has around 1.4 million customers in the North America region. </p><p>The hackers are believed to have accessed personally identifiable data related to the majority of these customers, along with the data of financial professionals and some Allianz Life employees.</p><div class="product"><a data-dimension112="acf934c2-6089-4039-93ab-e35de2df12af" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="acf934c2-6089-4039-93ab-e35de2df12af" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<br><a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="acf934c2-6089-4039-93ab-e35de2df12af" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>Customer data from other geographical regions is believed to be unaffected, and the company's core network and policy administration systems don't appear to have been accessed.</p><p>According to a <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/0446bff3-a013-43ed-82fa-bca6bb157de1.html" target="_blank"><u>filing</u></a> with the attorney general in Maine, the attack took place on July 16 and was discovered a day later. Allianz Life said it would provide a full consumer notice once it has finished identifying and contacting the individuals who have been affected.</p><p>The company also stated that it has notified the FBI, and said that affected individuals will be given 24 months of credit monitoring and identity theft protection.</p><h2 id="who-s-behind-the-allianz-life-breach">Who’s behind the Allianz Life breach?</h2><p>The attack is believed to have taken place through a third-party provider, with the company telling <a href="https://techcrunch.com/2025/07/26/allianz-life-says-majority-of-customers-personal-data-stolen-in-cyberattack/" target="_blank"><u><em>TechCrunch</em></u></a><em> </em>that this was a cloud-based customer relationship management (CRM) system. </p><p>Similarly, the breach is believed to have been carried out via a <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">social engineering</a> attack.</p><p>Tarun Desikan, zero trust evangelist and EVP of cloud edge security at leading <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>firm SonicWall, said the incident once again highlights long-running problems with social engineering and <a href="https://www.itpro.com/strategy/28935/what-is-identity-management-and-what-role-does-it-play-in-security-strategy">identity management</a>. </p><p>“While <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication</a> is critical, it’s not bulletproof. Attackers now bypass MFA with sophisticated social engineering techniques," said Desikan</p><p>"Attack vectors are constantly evolving and cyber criminals are relentless in developing new tactics, techniques, and procedures. This necessitates a proactive and flexible approach to cybersecurity, which includes adopting protocols and security architectures like <a href="https://www.itpro.com/security/network-security/358282/what-is-zero-trust">Zero Trust</a>.”</p><p>According to <a href="https://www.bleepingcomputer.com/news/security/allianz-life-confirms-data-breach-impacts-majority-of-14-million-customers/" target="_blank"><u><em>BleepingComputer</em></u></a>, the attack may have been carried out by the ShinyHunters threat group. The claims follow a warning last month from Mandiant that the group had started to target Salesforce CRM customers in social engineering attacks.</p><p>The hackers were reported to be impersonating IT support staff and asking employees to accept a connection to Salesforce Data Loader, which they are then using to exfiltrate data from Salesforce and extort the company.</p><p>ShinyHunters, which first emerged in 2020, does have a track record of similar attacks, and has targeted dozens of major organizations, including Microsoft, Santander, Ticketmaster, Tokopedia and AT&T. </p><p>In the case of AT&T, the data of 110 million users was accessed, with <a href="https://www.itpro.com/security/cyber-attacks/atandt-hacker-says-firm-paid-nearly-dollar400000-to-have-stolen-data-deleted">AT&T reportedly paying a $370,000 ransom</a>. </p><p><em>ITPro </em>has approached Allianz Life for clarification.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/average-brit-hit-by-five-data-breaches-since-2004">Average Brit hit by five data breaches since 2004</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/all-us-forces-must-now-assume-their-networks-are-compromised-after-salt-typhoon-breach">‘All US forces must now assume their networks are compromised’ after Salt Typhoon breach</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/cyber-attacks-cost-uk-firms-64-billion-each-year">Cyber attacks are costing UK firms billions every year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open – cybersecurity experts warn it's an easy mistake that's becoming far too common ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/26-million-cvs-were-exposed-when-a-recruiting-software-firm-left-a-misconfigured-azure-container-open-cybersecurity-experts-warn-its-an-easy-mistake-thats-becoming-far-too-common</link>
                                                                            <description>
                            <![CDATA[ TalentHook left a misconfigured Azure Blob storage container open, researchers said, leaving jobseekers open to phishing attempts ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yzWzsAmPaEP747QAbnqSSZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pfftm3kbsf6RpxZ6fmMoPf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Jul 2025 10:01:09 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Jul 2025 10:01:27 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pfftm3kbsf6RpxZ6fmMoPf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software security concept image showing binary code snippets with some highlighted on a digital interface. ]]></media:description>                                                            <media:text><![CDATA[Software security concept image showing binary code snippets with some highlighted on a digital interface. ]]></media:text>
                                <media:title type="plain"><![CDATA[Software security concept image showing binary code snippets with some highlighted on a digital interface. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pfftm3kbsf6RpxZ6fmMoPf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have uncovered a misconfigured recruitment database leaking almost 26 million files, and security experts have warned it's a trend that's becoming far too common.</p><p>According to analysis from <a href="https://cybernews.com/security/talenthook-data-leak-exposes-millions/" target="_blank"><u><em>Cybernews</em></u></a><em>, </em>TalentHook, an online applicant tracking platform connecting HR departments with people looking for work, had left a misconfigured Azure Blob storage container open.</p><p>As a result, the resumes of millions of US citizens, including their full names, email addresses, phone numbers, education details, professional details, and employment history were exposed.</p><div class="product"><a data-dimension112="60123408-6afa-486e-94fb-5c6c1402a7c7" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:310px;"><p class="vanilla-image-block" style="padding-top:52.58%;"><img id="VVXzWjJJrXo7mwL5n5f4mf" name="Keeper Security logo.png" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/VVXzWjJJrXo7mwL5n5f4mf.png" mos="" align="middle" fullscreen="" width="310" height="163" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/en_GB/affiliate/business/" data-dimension112="60123408-6afa-486e-94fb-5c6c1402a7c7" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25=""><strong>30% off Keeper Security's Business Starter and Business plans</strong></a></p><p>Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?<a class="view-deal button" href="https://www.keepersecurity.com/en_GB/affiliate/business/" target="_blank" rel="nofollow" data-dimension112="60123408-6afa-486e-94fb-5c6c1402a7c7" data-action="Deal Block" data-label="30% off Keeper Security's Business Starter and Business plans" data-dimension48="30% off Keeper Security's Business Starter and Business plans" data-dimension25="">View Deal</a></p></div><p>“The detailed personal information in the exposed resumes enables attackers to conduct highly targeted phishing campaigns," the Cybernews team said. </p><p>"Email addresses and phone numbers can be used in phishing emails, SMS scams, or fraudulent job offers, tricking individuals into revealing sensitive information such as ID scans or banking details."</p><p>The data could be a boon for cybercriminals looking to snare unsuspecting jobseekers, researchers have warned. In recent months, groups such as the North Korean state-sponsored Lazarus group have been specifically targeting jobseekers. </p><p>Research earlier this year showed the group has <a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks">targeted victims using LinkedIn</a>, for example, or by <a href="https://www.itpro.com/security/cyber-crime/hackers-are-using-a-linkedin-recruitment-scam-to-snare-unsuspecting-jobseekers">posing as recruiters and approaching targets</a> via email and WhatsApp. </p><h2 id="sharpen-up-on-storage-configurations">Sharpen up on storage configurations</h2><p>Tim Mackey, head of software supply chain risk at Black Duck, said the incident shows the huge risks posed by easily overlooked misconfigurations and urged enterprises to sharpen up processes. </p><p>"Misconfigured systems, <a href="https://www.itpro.com/cloud/virtual-machines/355269/getting-started-with-virtual-machines">VMs</a>, containers, micro-services, and data stores are nothing new,” he said. </p><p>"For example, the sample of the exposed data for this breach masks key identifiable information, such as email addresses and cell phone numbers, indicating that encryption of those elements wasn’t a priority or that an unsecured API was also part of the breach."</p><p>Dray Agha, senior manager of security operations at Huntress, echoed Mackey’s comments, noting that incidents like these are becoming increasingly common. </p><p>"Misconfigured cloud storage (like the unsecured <a href="https://www.itpro.com/data-centers/18008/introducing-windows-azure">Azure </a>container in this case) remains an alarmingly common yet preventable issue, especially in sectors handling highly personal information," said Agha. </p><p>"Organizations must implement rigorous configuration audits, enforce least-privilege access controls, and conduct continuous monitoring to prevent such massive exposures of stored personal data."</p><p>The <em>Cybernews </em>researchers said they have contacted TalentHook, and advised the company to change the access controls to restrict public access and secure the container, and to update permissions to ensure that only authorized users or services have the necessary access.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/phishing/employee-phishing-training-is-working-but-dont-get-complacent">Employee phishing training is working – but don’t get complacent</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/phishing-tactics-the-top-attacks-trends-in-year">Phishing tactics: The top attack trends</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/hackers-are-using-pdfs-to-impersonate-big-brands-like-microsoft-and-docusign-in-a-new-threat-campaign">Hackers are using PDFs to impersonate big brands in a new threat campaign</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ European financial firms are battling a huge rise in third-party breaches ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/financial-services-europe-third-party-data-breaches</link>
                                                                            <description>
                            <![CDATA[ Growing vendor dependency has contributed to a marked rise in third-party breaches ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Vfy2cB9tvmmohyGDSijSf8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wkCqibXhGoyJEHWfs3i35Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 11 Jun 2025 15:45:10 +0000</pubDate>                                                                                                                                <updated>Wed, 11 Jun 2025 15:45:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wkCqibXhGoyJEHWfs3i35Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Third-party data breach concept image showing a computer chip on a circuit board with unlocked padlock symbol. ]]></media:description>                                                            <media:text><![CDATA[Third-party data breach concept image showing a computer chip on a circuit board with unlocked padlock symbol. ]]></media:text>
                                <media:title type="plain"><![CDATA[Third-party data breach concept image showing a computer chip on a circuit board with unlocked padlock symbol. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wkCqibXhGoyJEHWfs3i35Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Financial services firms across Europe are contending with a sharp rise in third-party and fourth-party breaches, new research shows, with nearly every major financial institution across the region hit during the last year.</p><p>Breaches of these kinds increased by a quarter compared to the year prior, according to <a href="https://securityscorecard.com/research/the-cybersecurity-of-europes-top-100-financial-institutions-2025/" target="_blank"><u>SecurityScorecard</u></a>. Indeed, 96% experienced at least one <a href="https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics">third-party breach</a> in the past year, and 97% at least one fourth-party breach.</p><p>Financial services firms in the UK reported the highest number of third-party breaches, followed by Germany and Switzerland, while Malta, Luxembourg, and Portugal had the lowest exposure and highest average <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>grades.</p><p>On an individual basis, Switzerland has the most third-party breaches per institution, the study found, followed by the Netherlands and UK. Researchers noted that these findings highlight an increasingly complex vendor ecosystem alongside glaring gaps in risk oversight. </p><p>"A 25% surge in third-party breaches among Europe’s top financial institutions is more than a warning, it is a call to action," said Corian Kennedy, senior manager of threat insights and attribution at SecurityScorecard. </p><p>"Cyber threats are no longer confined to the perimeter. They are embedded deep within supply chains. Institutions must evolve from reactive to proactive defense strategies to meet the escalating challenge."</p><p>Only 7% of financial institutions suffered a direct breach, down from 8% the year before, with <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and <a href="https://www.itpro.com/security/why-you-should-always-be-wary-of-insider-threats-a-disgruntled-employee-at-a-us-industrial-firm-deleted-backups-and-locked-it-admins-out-of-workstations-in-a-failed-data-extortion-attempt">insider threats</a> remaining key culprits. However, even without direct breaches, supplier vulnerabilities impacted nearly all the institutions surveyed. </p><p>Incidents such as the <a href="https://www.itpro.com/security/why-the-moveit-breach-still-lives-rent-free-in-the-minds-of-it-leaders">MOVEit vulnerability</a>, which led to over $65 billion in damages, show just how bad the effects of third-party breaches can be, researchers warned. </p><p>In Europe, notable cyber attacks over the last year included the breach of Zürcher Kantonalbank, which saw customer account balances and personal information exposed via its mobile app.</p><p>In the same month, Credit Suisse - now UBS - reported a cyber attack affecting 19,000 Indian employees, compromising a raft of sensitive personal data.</p><p>According to SecurityScorecard's data, just ten threat actor groups were responsible for 44% of global cyber incidents, with Cl0p, APT28, and Cobalt Group the main culprits in third-party exploitation.</p><h2 id="vendor-dependency-is-a-big-problem">Vendor dependency is a big problem</h2><p>Crucially, the report from SecurityScorecard noted that a growing dependence on a small group of vendors continues to amplify risk. </p><p>Just 15 companies now represent 62% of the global tech market, researchers found, underlining the grave risks faced by organizations if just one were to be compromised. </p><p>As a result, the company called for a more harmonized approach to third-party risk governance across Europe, particularly in high-exposure jurisdictions which are all subject to regulation under the Digital Operational Resilience Act (DORA). </p><p>Organizations should continuously monitor third- and fourth-party vendor networks and improve application and network security capabilities, researchers said. </p><p>Efforts to strengthen DNS health, endpoint security, and patching cadence in high-risk environments were also highlighted by researchers. </p><p>Similarly, SecurityScorecard advised organizations to align with DORA requirements by integrating continuous, evidence-based oversight into procurement and vendor management, it said.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/cyber-attacks-against-uk-firms-dropped-by-10-percent-last-year-but-experts-say-dont-get-complacent">Cyber attacks against UK firms dropped by 10% last year, but experts say don't get complacent</a></li><li><a href="https://www.itpro.com/security/data-breaches/us-healthcare-data-breaches-are-out-of-control-over-400-million-patient-records-have-been-exposed-in-the-last-two-years">US healthcare data breaches are out of control</a></li><li><a href="https://www.itpro.com/security/nearly-all-of-the-top-us-banks-were-impacted-by-third-party-breaches-last-year">Nearly all of the top US banks were impacted by third party breaches last year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Breach at data analytics firm impacts 364,000 people ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/lexisnexis-data-breach-disclosure</link>
                                                                            <description>
                            <![CDATA[ Hackers used company GitHub account to steal software bits and personal information, company admits ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">amdK7FLeXThQa3yzkQ2iQW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cMk7gF27pKwDfggpZvPnVc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 29 May 2025 14:33:29 +0000</pubDate>                                                                                                                                <updated>Thu, 29 May 2025 14:33:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/cMk7gF27pKwDfggpZvPnVc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[LexisNexis logo and branding pictured on a building front in downtown Toronto, Canada.]]></media:description>                                                            <media:text><![CDATA[LexisNexis logo and branding pictured on a building front in downtown Toronto, Canada.]]></media:text>
                                <media:title type="plain"><![CDATA[LexisNexis logo and branding pictured on a building front in downtown Toronto, Canada.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cMk7gF27pKwDfggpZvPnVc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have nabbed LexisNexis data belonging to more than 360,000 people via <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub</a>. </p><p>LexisNexis Risk Solutions (LNRS) began sending data breach notifications to impacted individuals last week, but admitted it was told about the leak at the beginning of April — and that the actual breach had occurred in December of last year. </p><p>The data broker said that its own systems weren't breached, explaining that the data was taken from GitHub by an "unknown threat actor" using a compromised company account, according to a company statement. </p><p>The company's investigation revealed that "<a href="https://www.itpro.com/software">software </a>artifacts" were accessed in the breach, as well as personal information. </p><p>According to a <a href="https://www.maine.gov/cgi-bin/agviewerad/ret?loc=2634" target="_blank"><u>letter</u></a> sent by LNRS to affected individuals, that included names, phone numbers, postal and email addresses, social security numbers, driver's license numbers, and dates of birth. </p><p>"No financial or credit card information was affected," the letter notes. "We have no evidence that your data has been further misused."</p><p>A government <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/782e2159-f2d4-4394-8d03-51bf08a6b3e5.html"><u>filing</u></a> shows that 364,333 people were affected by the break. </p><p>LNRS said in the data breach notice sent to customers that it was working with law enforcement on the incident. </p><p>In a statement given to <em>ITPro</em>, the company said: "On Tuesday, April 1, 2025, LexisNexis Risk Solutions (LNRS) received a report from an unknown third party claiming to have accessed certain information belonging to LNRS. </p><p>"Our Information Security team, in consultation with a forensic firm, immediately began investigating and confirmed that some data which was held in GitHub, a third-party platform used by LNRS for software development purposes, was acquired by an unknown third party."</p><p>The statement added: "There was no compromise of our own systems, infrastructure, or products. We are notifying approximately 360,000 individuals and appropriate regulators. We have also reported this incident to law enforcement."</p><h2 id="questionable-timeline">Questionable timeline? </h2><p>One security expert criticised the delay between the incident happening, LNRS being informed, and the subsequent disclosure. </p><p>Ilya Kolochenko, CEO at ImmuniWeb and a Fellow at the British Computer Society (BCS), said informing affected individuals in the wake of a breach should be of paramount importance to any organization.</p><p>"The timeline of the incident detection and disclosure is a bit surprising for a company offering legal and other comparatively sensitive services: the incident reportedly happened in December 2024, was detected in April 2025 after receiving information from the attackers, while disclosed only in May," Kolochenko said.</p><p>“Given that a lot of personal data was reportedly compromised, the incident detection and response timeline is pretty far from being perfect, to put it mildly."</p><p>That said, Kolochenko admitted that spotting such issues with partner platforms wasn't easy. </p><p>"Incidents stemming from compromised third-party repositories, like GitHub, are not trivial to detect and may even remain totally undetected," he said. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/legal-aid-agency-cyber-attack-breach">Criminal records, financial data exposed in cyber attack on Legal Aid Agency</a></li><li><a href="https://www.itpro.com/security/data-breaches/us-healthcare-data-breaches-are-out-of-control-over-400-million-patient-records-have-been-exposed-in-the-last-two-years">US healthcare data breaches are out of control</a></li><li><a href="https://www.itpro.com/business/hacked-law-firm-didnt-think-it-was-a-data-breach-the-ico-disagreed">Hacked law firm 'didn't think it was a data breach' – the ICO disagreed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A cybersecurity researcher just discovered a treasure trove of leaked accounts: More than 184 million logins were readily available online, with Google, Meta, and Apple users affected ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/business/a-cybersecurity-researcher-just-discovered-a-treasure-trove-of-leaked-accounts-more-than-184-million-logins-were-readily-available-online-with-google-meta-and-apple-users-affected</link>
                                                                            <description>
                            <![CDATA[ The mysterious database contains highly sensitive data that appears to have been harvested by infostealer malware ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">toeeDpatuh8s5KnujYVJ8J</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 27 May 2025 09:35:00 +0000</pubDate>                                                                                                                                <updated>Tue, 27 May 2025 10:50:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:description>                                                            <media:text><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> researcher has uncovered a mysterious, publicly accessible database containing millions of login credentials from services including Facebook, Apple, and Microsoft.</p><p>The publicly exposed database was not password-protected or <a href="https://www.itpro.com/security/encryption/359167/how-to-encrypt-files-and-folders-in-windows-10">encrypted</a>, and contained more than 184 million unique logins and passwords, adding up to 47.42GB of raw credential data.</p><p>The data included emails, usernames, passwords, and the URL links to the login or authorization for the accounts. </p><p>"The database contained login and password credentials for a wide range of services, applications, and accounts, including email providers, Microsoft products, Facebook, Instagram, Snapchat, Roblox, and many more," said cybersecurity researcher Jeremiah Fowler. </p><p>"I also saw credentials for bank and financial accounts, health platforms, and government portals from numerous countries that could put exposed individuals at significant risk."</p><p>The origin of the database is something of a mystery. The IP address linked the database to two domain names. One was parked and unavailable while the other was apparently unregistered and available to purchase. </p><p>Fowler contacted the <a href="https://www.itpro.com/network-internet/web-hosting/368170/best-web-hosting-services-in-2022">hosting provider</a>, which took the database down, but didn't reveal the customer's identity. One hint may be the fact that, while most text was in English, the files were listed as 'senha' - Portuguese for password. </p><p>He also messaged multiple email addresses listed in the database and was able to validate several records, with the victims confirming that they contained their accurate and valid passwords. </p><p>It's not known how long the database was exposed. However, Fowler said there are clear signs that the exposed data has been harvested by some type of <a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">infostealer malware</a>. </p><p>"It is not known exactly how this specific data was collected, but cybercriminals use a range of methods to deploy <a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">infostealers</a>," said Fowler. </p><p>"For instance, they often conceal malware within phishing emails, malicious websites, or cracked software. Once the infostealer is active, the stolen data is often either circulated on <a href="https://www.itpro.com/security/identity-theft/356578/a-simple-guide-to-the-dark-web">dark web</a> marketplaces and Telegram channels or used directly to commit fraud, attempt identity theft, or launch further cyber attacks."</p><p>Fowler advises users to change passwords and to delete sensitive documents, such as tax forms, medical records, contracts, and passwords from their emails. They should only share data like this through encrypted <a href="https://www.itpro.com/cloud/cloud-storage/362576/top-ten-cloud-storage-tips-and-tricks">cloud storage</a> systems, rather than email, he said. </p><p>"Databases like this are regularly bought, sold, and repackaged on dark web forums like BreachForums. Massive credential dumps are part of an ongoing black market where breached data is commoditized and often aggregated from multiple incidents over time," commented Cory Michal, chief security officer at AppOmni. </p><p>"What’s new isn’t the existence of the data, but the scale, the recency of some credentials, and the targeting of identity providers that are widely used to access SaaS and cloud services — making this breach especially potent for enabling downstream account takeovers."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/legal-aid-agency-cyber-attack-breach">Criminal records, financial data exposed in cyber attack on Legal Aid Agency</a></li><li><a href="https://www.itpro.com/security/data-breaches/cyber-attacks-against-uk-firms-dropped-by-10-percent-last-year-but-experts-say-dont-get-complacent">Cyber attacks against UK firms dropped by 10% last year, but experts say don't get complacent</a></li><li><a href="https://www.itpro.com/security/data-breaches/us-healthcare-data-breaches-are-out-of-control-over-400-million-patient-records-have-been-exposed-in-the-last-two-years">US healthcare data breaches are out of control</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US healthcare data breaches are out of control – over 400 million patient records have been exposed in the last two years ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/us-healthcare-data-breaches-are-out-of-control-over-400-million-patient-records-have-been-exposed-in-the-last-two-years</link>
                                                                            <description>
                            <![CDATA[ There's been a huge surge in the number of healthcare data breaches in recent years ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4TgKG5cMixQVC3rukyvz4W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 16 May 2025 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image showing digitized padlock with data points flowing out from behind.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WpWQgus5fSc7duCTbNXWAm-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two new reports have highlighted the immense scale of US healthcare data breaches, with 409 million personal records exposed over the last two years.</p><p>According to research from application security firm Indusface, there were 1,200 breaches in the US healthcare sector in the last 24 months, with 83% of incidents leaving patient records exposed.</p><p>Texas recorded 66 data breaches, the most of any state, as well as the most people affected, at 14,371,828. The state’s biggest breach was that of Concentra Health Services in January 2024, which saw data belonging to nearly four million people accessed or stolen.  </p><p>California had the second-highest number of individuals affected by data breaches, at 9,218,788. Notably, it also experienced the largest healthcare data breach in the study, affecting 4,700,000 people, when Blue Shield of California’s member data was shared with Google for advertising.</p><p>At the other end of the scale, Ohio saw 45 incidents affecting the data of 3,767,504 people, and Massachusetts just 28, exposing data belonging to 3,743,999.</p><p>"The <a href="https://www.itpro.com/security/cyber-attacks-on-healthcare-organizations-are-surging-heres-why">healthcare sector</a> is vulnerable to these breaches due to both the vast amount of sensitive patient data, which is often sold to third parties for a high price, and weak or outdated software and systems," said Venky Sundar, founder and president of Indusface. </p><p>"According to Verizon’s latest DBIR, vulnerability exploits have now overtaken phishing as a leading cause of data breaches. What is particularly concerning is how patching an average vulnerability takes 200-plus days."</p><h2 id="ransomware-contributing-to-healthcare-data-breaches">Ransomware contributing to healthcare data breaches</h2><p>The figures come after a <a href="https://jamanetwork.com/journals/jamanetworkopen/fullarticle/2833984?guestAccessKey=5d6e82f6-71fb-4684-8113-d15b3d3ce0da&utm_source=for_the_media&utm_medium=referral&utm_campaign=ftm_links&utm_content=tfl&utm_term=051425"><u>study </u></a>from Michigan State University, Yale University, and Johns Hopkins University found that ransomware-related breaches have become a key issue for healthcare providers. </p><p>Researchers found that although ransomware accounted for just 11% of breaches in 2024 by number, those attacks alone were responsible for 69% of all patient records compromised that year. </p><p>The number of attacks has also been rising steadily over the last decade. While in 2010 there were no ransomware breaches, there were 222 in 2021, accounting for nearly a third of all major healthcare breaches that year. </p><p>Similarly, the overall share of breaches caused by hacking or IT incidents surged from 4% in 2010 to 81% in 2024.</p><p>Researchers said these numbers probably underestimate the true extent of the problem thanks to underreporting, reluctance to disclose ransom payments, and the fact that the study didn't look at smaller breaches affecting fewer than 500 individuals.</p><p>"<a href="https://www.itpro.com/security/28084/what-is-ransomware">Ransomware </a>has become the most disruptive force in healthcare cybersecurity,” said John Jiang, Eli Broad endowed professor of accounting and information systems in the MSU Broad College of Business and lead author of the study.</p><p>"Healthcare providers have limited <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>resources, so it’s essential to focus protection on the most sensitive types of information. The solutions are within reach — what we need now is coordination, transparency and urgency."</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/ransomware-healthcare-vulnerabilities">Healthcare systems are rife with exploits — and ransomware gangs have noticed</a></li><li><a href="https://www.itpro.com/security/five-ways-cyber-criminals-target-healthcare-and-how-to-stop-them">Five ways cyber criminals target healthcare and how to stop them</a></li><li><a href="https://www.itpro.com/security/data-breaches/yale-new-haven-health-breach">More than 5 million Americans just had their personal information exposed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ More than 5 million Americans just had their personal information exposed in the Yale New Haven Health data breach – and lawsuits are already rolling in ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/yale-new-haven-health-breach</link>
                                                                            <description>
                            <![CDATA[ A data breach at Yale New Haven Health has exposed data belonging to millions of people – and lawsuits have already been filed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CyA5XhKU2PphyYnQw4mjfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2qM5pommjojvtwUM8YQUM9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 25 Apr 2025 11:34:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2qM5pommjojvtwUM8YQUM9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Yale New Haven Health sign pictured at New Haven Hospital in Connecticut, USA.]]></media:description>                                                            <media:text><![CDATA[Yale New Haven Health sign pictured at New Haven Hospital in Connecticut, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Yale New Haven Health sign pictured at New Haven Hospital in Connecticut, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2qM5pommjojvtwUM8YQUM9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A <a href="https://www.itpro.com/security/data-breaches">data breach</a> at Yale New Haven Health (YNHHS) has exposed data belonging to millions of people – and lawsuits have already been filed.</p><p>YNHHS runs more than 360 locations across Connecticut, New York, and Rhode Island, and is notifying patients that their personal data might have been affected.</p><p>According to an entry on the US Department of Health and Human Services breach portal, the data breach impacted 5,556,702 patients.</p><p>"The information involved varied by patient, but may have included demographic information (such as name, date of birth, address, telephone number, email address, race or ethnicity), Social Security number, patient type, and/or medical record number," said YNHHS.</p><p>"YNHHS’ electronic medical record and treatment information were not involved or accessed, and no financial account or payment information was involved in this incident."</p><p>The breach was first discovered on March 8th when YNHHS spotted unusual activity affecting its IT systems. The organization took steps immediately to contain the incident and began an investigation with the help of external cybersecurity experts from <a href="https://www.itpro.com/business/careers-and-training/mandiant-exec-thinks-ai-could-boost-diversity-in-cybersecurity">Mandiant</a>. </p><p>It also reported the incident to law enforcement. However, patients weren't notified of the breach until late April.</p><p>It's now offering complimentary credit monitoring and identity protection services, but only to those whose Social Security number was involved.</p><h2 id="yale-new-haven-health-faces-legal-action">Yale New Haven Health faces legal action</h2><p>Legal action has already been launched. Hartford law firm Cicchiello & Cicchiello has filed <a href="https://dockets.justia.com/docket/connecticut/ctdce/3:2025cv00610/164535"><u>two identical lawsuits</u></a> in the Connecticut District Court on behalf of Michael Liparulo of New London and Jon Nathanson of Fairfield.</p><p>The lawsuits allege YNHHS failed to protect personally identifiable and health information, and took too long to notify patients.</p><p>Similarly, the cases claim IT practitioners failed to encrypt files, train employees on data security, or implement basic security measures such as multi-factor authentication. </p><p>They’re calling for damages, free lifetime identity protection, and major changes to the health system’s cybersecurity practices.</p><h2 id="healthcare-in-the-crosshairs">Healthcare in the crosshairs</h2><p>Healthcare organizations are a prime target for hackers thanks to the vast amount of highly personal data that they hold. According to recent <a href="https://www.trustwave.com/en-us/resources/library/documents/trustwave-spiderlabs-research-cybersecurity-challenges-for-healthcare-in-2025/"><u>research</u></a> from Trustwave, for example, 21% of all ransomware attacks worldwide are targeted at public health and government healthcare organizations.</p><p>The study found that 45% of attacks exploited public-facing applications and 56% of public-facing applications exploited were against <a href="https://www.itpro.com/security/vulnerability/362100/log4j-vulnerability-continues-to-stress-cisos">Log4j</a>, with 9% of all attacks coming from the threat group <a href="https://www.itpro.com/security/cyber-crime/everything-you-need-to-know-about-ransomhub-the-new-force-in-the-digital-extortion-industry">RansomHub</a>.</p><p>Third-party threats within supply chains continue to pose 'significant' risks, the researchers found.</p><p>"Healthcare artificial intelligence and technology adoption presents a spectrum of risks that few other industries need to navigate. The risk is not just incredibly sensitive data privacy, but human life and quality of patient care," said Kory Daniels, CISO at Trustwave.</p><p>"Complex supply chains, lapses in patches and credential management all have consequences too serious for anyone in the healthcare industry to ignore".</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/ransomware-healthcare-vulnerabilities">Healthcare systems are rife with exploits — and ransomware gangs have noticed</a></li><li><a href="https://www.itpro.com/security/healthcare-organizations-need-to-shake-up-email-security-practices">Healthcare organizations need to shake up email security practices</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/us-healthcare-cyber-attacks-sunflower-medical-group">More than 300,000 US healthcare patients impacted in suspected Rhysida cyber attacks</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won't be the last ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/hertz-data-breach-cleo-flaw</link>
                                                                            <description>
                            <![CDATA[ Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rdCm85c6xW9QBe93hSCccW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yiQbL5Dqruj4EkQsVDJ3rF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Apr 2025 15:58:37 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Apr 2025 16:01:48 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yiQbL5Dqruj4EkQsVDJ3rF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hertz logo and branding pictured outside a rental shop on North Main Street, Walnut Creek, California.]]></media:description>                                                            <media:text><![CDATA[Hertz logo and branding pictured outside a rental shop on North Main Street, Walnut Creek, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Hertz logo and branding pictured outside a rental shop on North Main Street, Walnut Creek, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yiQbL5Dqruj4EkQsVDJ3rF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen. </p><p>In a <a href="https://www.hertz.com/content/dam/hertz/global/resources/Notice_of_Data_Incident-United_States.pdf" target="_blank"><u>statement confirming the incident</u></a>, the firm said customer data was “acquired by an unauthorized party that we understand exploited zero-day vulnerabilities within Cleo's platform in October 2024 and December 2024”.</p><p>“Hertz immediately began analyzing the data to determine the scope of the event and to identify individuals whose personal information may have been impacted,” the statement added. </p><p>Customer data exposed in the breach may vary, the company said, but is believed to include customer names, contact information, dates of birth, credit card details, and information pertaining to driver’s licenses. </p><p>Similarly, a limited number of customers may have had US social security numbers or government ID information stolen in the breach. </p><p>"A very small number of individuals may have had their Social Security or other government identification numbers, passport information, Medicare or Medicaid ID (associated with workers' compensation claims), or injury-related information associated with vehicle accident claims impacted by the event," the company warned.</p><p>Hertz said it is yet to observe any “misuse of personal information” linked to the breach, but is offering customers two years of identity monitoring services. The company also advised customers to remain vigilant for potential fraudulent activity.</p><h2 id="hertz-the-latest-to-disclose-cleo-vulnerability-impact">Hertz the latest to disclose Cleo vulnerability impact</h2><p>Hertz’ confirmation makes it the latest in a string of companies to have fallen victim to the Cleo breach. First disclosed last year, a <a href="https://www.itpro.com/security/everything-you-need-to-know-about-the-cleo-file-transfer-vulnerability-including-affected-products-patches-and-temporary-mitigations">vulnerability in the popular managed file transfer (MFT) service</a> was pounced on by the <a href="https://www.itpro.com/security/ransomware/ransomware-attacks-worst-month-ever">Clop ransomware group</a>. </p><p>The threat group initially claimed it had stolen data belonging to more than 60 companies as a result of the zero-day. This list has since grown, and earlier this year <a href="https://www.itpro.com/security/data-breaches/western-alliance-bank-admits-cyber-attack-exposed-22-000-customers"><u>Western Alliance Bank confirmed it was among the growing list of victims</u></a>. </p><p>Other confirmed victims include Chicago Public Schools, Champion Home Builders, and WK Kellogg. </p><p>Fresh research from ReliaQuest shows the impact of the Cleo breach will continue to grow for enterprises globally. Indeed, analysis by the security firm found the incident fueled a 23% increase in overall <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>activity between Q4 and Q1 2025. </p><p>“Clop’s exploitation of Cleo highlights how weaknesses in systems can ripple across interconnected industries, disrupting supply chains, halting operations, and impacting countless businesses simultaneously,” the firm said in a <a href="https://reliaquest.com/blog/threat-spotlight-ransomware-cyber-extortion-q1-2025/" target="_blank"><u>blog post</u></a>. </p><p>Rebecca Moody, head of data research at Comparitech, echoed this warning, noting that there’s likely to be “many more breach notifications from this exploit” as Clop has since added over 350 victims to its data leak site.</p><p>Dray Agha, senior manager of security operations at Huntress, said the incident underlines the “significant risks” posed by vulnerabilities in third-party platforms like Cleo. </p><p>“This highlights the importance of maintaining robust vulnerability management programs to identify and address security gaps in software promptly, especially those used for sensitive data transfer.”</p><p>Agha added the incident reflects a growing trend of cyber criminals targeting secure file transfer platforms. 2023, for example, saw a number of high-profile organizations impacted by the <a href="https://www.itpro.com/security/data-breaches/amazon-confirms-employee-data-compromised-in-2023-moveit-breach-but-the-hacker-behind-the-leak-claims-a-host-of-other-big-tech-names-are-also-implicated"><u>MOVEit data breach</u></a>. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers">The new ransomware groups worrying security researchers in 2025</a></li><li><a href="https://www.itpro.com/security/cyber-crime/blacklock-ransomware-group-reliaquest">The ‘BlackLock’ group has become one of the most prolific operators in the cyber crime industry</a></li><li><a href="https://www.itpro.com/security/ransomware/warning-issued-over-prolific-ghost-ransomware-group">Warning issued over prolific 'Ghost' ransomware group</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber attacks against UK firms dropped by 10% last year, but experts say don't get complacent ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/cyber-attacks-against-uk-firms-dropped-by-10-percent-last-year-but-experts-say-dont-get-complacent</link>
                                                                            <description>
                            <![CDATA[ More than four-in-ten UK businesses were hit by a cyber attack last year, marking a decrease on the year prior – but security experts have warned enterprises to still remain vigilant. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">t37FefatuH4oKHBXJPo5de</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Apr 2025 09:39:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing a warning symbol in red with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LrXBU2G7X45b6NeaQsxQsN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than four-in-ten UK businesses were hit by a cyber attack last year, marking a decrease on the year prior – but security experts have warned enterprises to still remain vigilant. </p><p>The government's latest <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025" target="_blank"><u><em>Cybersecurity Data Breaches Survey</em></u></a><em> </em>revealed that 43% of businesses were affected, with a total of 612,000 cyber attacks or breaches recorded across the year. That's noticeably fewer than in the previous year, when the figure was 50%.</p><p>There were 61,000 attacks against charities, affecting three-in-ten, down from 32% in the previous year. </p><p>But the fall wasn't spread evenly across the board. While micro and small businesses fell victim to fewer phishing attacks, the figures for medium and large businesses were pretty much the same as in 2024.</p><p>Small businesses in particular showed the most improvement in several cyber hygiene practices, with nearly half using cybersecurity risk assessments, up from 41% in 2024. </p><p>More than six-in-ten revealed they now have cyber insurance, up from 49% in 2024, and the proportion with a formal cybersecurity policy rose slightly. Meanwhile, 53% now have a business continuity plan, up from 44% in 2024.</p><p>High-income charities, though, got worse. Only three-quarters now carry out activities to identify cybersecurity risks, down from 86% in 2024. </p><p>Similarly, just one-in-five said they review immediate supplier risks, down from 36% in 2024, and the proportion having a formal <a href="https://www.itpro.com/enterprise-security/34017/who-should-take-ownership-of-your-cyber-security-strategy">cybersecurity strategy</a> in place fell from 47% to 39%.</p><h2 id="cybersecurity-is-improving-but-don-t-get-complacent">Cybersecurity is improving, but don’t get complacent</h2><p>Jonathan Gill, CEO of Panaseer, said that while the survey showed positive signs, complacency could cause bigger problems down the line. </p><p>"Most breaches don’t happen because organizations ignored security, but because they believed they were secure when, in reality, they weren’t,” he said. </p><p>"They assume they’re covered, but blind spots in visibility mean critical assets go unpatched, misconfigurations slip through the cracks, and security gaps persist without anyone realizing it," Gill added. </p><p>The most common type of breach involved phishing attacks, which affected 85% of businesses and 86% of charities.</p><p>Matt Cooke, cybersecurity strategist for EMEA at Proofpoint, said this was unsurprising given the continued success of phishing attacks by cyber criminals globally. </p><p>"Email has been the number one threat vector for many years now – why? Because it continues to work."</p><p>The effects of these breaches included a near-doubling in temporary loss of access to files or networks - 7%, up from 4% in 2024 - while charities reported an increase in loss of access to third-party services at 5%, up from 1% in 2024.</p><p>The resulting costs were significant, the survey found, standing at around £1,600 for businesses and £3,240 for charities on average.</p><p>Both businesses and charities appear to be pretty poor at dealing with supply chain risks, the survey warned. Only 14% of businesses said they reviewed the risks posed by their immediate suppliers,  and only 7% looked at their wider supply chain. </p><p>These figures were even worse for charities, at 9% and 4% respectively. </p><h2 id="board-level-cybersecurity-focus-is-dwindling">Board-level cybersecurity focus is dwindling</h2><p>A concerning trend highlighted in the survey centered around board-level responsibility for cybersecurity, which has steadily declined among businesses since 2021. </p><p>Just over one-third (38%) of businesses had a board member with responsibility for cybersecurity in 2021 - this has since dropped to 27%.</p><p>Cooke noted that this is a “worrying development” and further highlights a degree of complacency among organizations of all sizes. </p><p>"Cybersecurity can’t be treated as an after-thought by anyone in an organization - particularly those at board level, who control the purse strings and business priorities." </p><p>The findings are expected to inform the upcoming Cyber Security and Resilience Bill, which is set to introduce sweeping changes to shore up national cybersecurity capabilities and impose stricter requirements on businesses. </p><p>Etay Maor, chief security strategist at Cato Networks, said the growing threats posed by cyber criminals, and the increased use of AI tools by sophisticated threat groups, poses questions for lawmakers. </p><p>"The bill should incorporate measures to address the growing threat of AI-powered attacks, ensuring businesses and consumers are adequately protected from increasingly sophisticated cyber criminals,” he said. </p><p>"A holistic approach, encompassing proactive threat prevention, robust incident response, and mandatory reporting of AI-driven attacks, is crucial to effectively mitigate the evolving cyber landscape," Maor added.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/the-role-of-cyber-security-in-the-uks-tech-renaissance">The role of cyber security in the UK’s tech renaissance</a></li><li><a href="https://www.itpro.com/security/uk-cybersecurity-sector-economic-value">The UK cybersecurity sector is worth over £13 billion, but experts say there’s huge untapped potential if it can overcome these hurdles</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/uk-underestimates-threat-from-hostile-states-says-new-ncsc-head">UK underestimates threat from hostile states, says new NCSC head</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europcar data breach could affect up to 200,000 customers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/europcar-data-breach-gitlab</link>
                                                                            <description>
                            <![CDATA[ Europcar has reportedly suffered a massive data breach affecting as many as 200,000 customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UWkSMncCELrUAPqqMWUY3f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UxxaDtFLYe68RxatShoX4B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Apr 2025 10:36:50 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UxxaDtFLYe68RxatShoX4B-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Europcar logo and branding pictured on a store front in Porto, Portugal.]]></media:description>                                                            <media:text><![CDATA[Europcar logo and branding pictured on a store front in Porto, Portugal.]]></media:text>
                                <media:title type="plain"><![CDATA[Europcar logo and branding pictured on a store front in Porto, Portugal.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UxxaDtFLYe68RxatShoX4B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Europcar has reportedly suffered a massive data breach affecting as many as 200,000 customers.</p><p>The car rental firm has confirmed the hack to <a href="https://www.bleepingcomputer.com/news/security/europcar-gitlab-breach-exposes-data-of-up-to-200-000-customers/" target="_blank"><u><em>BleepingComputer</em></u></a>, adding that it's assessing the damage and notifying affected individuals. </p><p>The statement follows a post in an underground forum from a hacker claiming to have obtained all the firm's <a href="https://www.itpro.com/technology/artificial-intelligence/under-the-hood-of-gitlab-duo-chat-what-can-users-expect">GitLab</a> repositories, accessing more than 9,000 SQL files with backups that contain personal data. </p><p>Similarly, the threat actor claimed to have gained access to at least 269 .ENV files used to store configuration settings for applications, environment variables, and sensitive information. </p><p>The hackers in question have threatened to publish 37GB of data, including backups and details about the company’s cloud infrastructure and internal applications.</p><p>Europcar has denied that the full repositories were stolen, however. Exposed data included only the names and email addresses of Goldcar and Ubeeqo users, with bank and card details and passwords not exposed.</p><h2 id="source-of-europcar-data-breach-still-unknown">Source of Europcar data breach still unknown</h2><p>It's not known how the hackers were able to compromise Europcar’s GitLab account. </p><p>However, Martin Reynolds, field CTO at security firm Harness, said one of the most common ways cybercriminals compromise systems such as these is to spoof a <a href="https://www.itpro.com/security/hackers-are-abusing-githubs-search-function-to-spread-malware">popular code repository</a> infected with an <a href="https://www.itpro.com/security/malware/infostealer-malware-threat-to-businesses">infostealer malware</a>, then trick developers into downloading it.</p><p>To protect themselves from these threats, Reynolds advised organizations to make sure their repositories are protected by minimal token permissions, so only users who should have access can perform actions such as editing or downloading new code.</p><p>They should also automate scans at the moment developers add to source code repositories, so that company data won't be exposed in the event of a breach.</p><p>"This should be combined with <a href="https://www.itpro.com/development/devops/354215/what-is-devsecops-and-why-is-it-important">DevSecOps</a> best practices such as automated governance and security checks to scan new code for <a href="https://www.itpro.com/security/hackers-are-taking-advantage-of-ai-hallucinations-to-sneak-malicious-software-packages-onto-enterprise-repositories">malicious code</a> – like infostealer malware – before it is introduced," he said.</p><p>"These approaches make it more difficult for spoofed code repositories to make it through to live environments where they can be used to gain access to other systems.</p><p>"By embedding these types of controls early in the software lifecycle, security stays a priority, not an afterthought, and ensures that company secrets are kept under lock and key."</p><p>This attack has been confirmed - unlike an alleged intrusion last year, in which a hacker forum member claimed to have accessed the personal information of nearly 50 million customers. Europcar denied the claims.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/software/development/everything-you-need-to-know-about-gitlab-duo-enterprise">Everything you need to know about GitLab Duo Enterprise</a></li><li><a href="https://www.itpro.com/security/hackers-are-exploiting-critical-gitlab-password-reset-vulnerability-heres-what-you-need-to-know">Hackers are exploiting critical GitLab password reset vulnerability</a></li><li><a href="https://www.itpro.com/security/malware/infostealer-malware-exposed-credentials">A ‘significant increase’ in infostealer malware attacks left 3.9 billion credentials exposed to cyber criminals last year</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NHS supplier hit with £3m fine for security failings that led to attack ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/advanced-computer-software-group-ico-fine</link>
                                                                            <description>
                            <![CDATA[ The Information Commissioner's Office (ICO) said Advanced Computer Software Group failed to use appropriate security measures before the 2022 attack, which put the personal information of tens of thousands of NHS patients at risk.  ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Zj3WaEijCs9axt3qppvMmH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Mar 2025 10:22:35 +0000</pubDate>                                                                                                                                <updated>Thu, 27 Mar 2025 10:53:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:description>                                                            <media:text><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[NHS logo displayed on a smartphone screen in white lettering on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zoxC2QCJSmiHZA84Xve6qE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A Birmingham-based software provider has been handed a £3 million fine for security failings that led to a <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>attack on the NHS.</p><p>The <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> said Advanced Computer Software Group failed to use appropriate security measures before the 2022 attack, which put the personal information of tens of thousands of NHS patients at risk. </p><p>Advanced provided the NHS with a range of patient management and health-related products, including Adastra, Caresys, Carenotes, Odyssey, Crosscare, Staffplan, and eFinancials.</p><p>But there were gaps in its use of <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>, a lack of comprehensive vulnerability scanning, and inadequate patch management, according to the <a href="https://www.itpro.com/security/data-protection">data protection</a> watchdog.</p><p>"The security measures of Advanced’s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information," said information commissioner John Edwards. </p><p>"While Advanced had installed multi-factor authentication across many of its systems, the lack of complete coverage meant hackers could gain access, putting thousands of people’s sensitive personal information at risk."   </p><p>The hackers, believed to be the <a href="https://www.itpro.com/security/ransomware/368418/latest-lockbit-ransomware-strain-strikingly-similar-to-blackmatter">LockBit ransomware group</a>, accessed certain systems of Advanced’s health and care subsidiary via a customer account that lacked MFA. </p><p>Personal information belonging to 79,404 people was taken in the attack, including details of how to gain entry into the properties of 890 people who were receiving care at home.  </p><p>Emergency prescription services, ambulance dispatching systems, and the non-emergency 111 phone line were affected, with some healthcare staff unable to access patient records.</p><p>"People should never have to think twice about whether their medical records are in safe hands," said Edwards. </p><p>"To use services with confidence, they must be able to trust that every organisation coming into contact with their personal information – whether that’s using it, sharing it or storing it on behalf of others – is meeting its legal obligations to protect it."</p><p>The fine forms part of a voluntary settlement. And while very large, it's less than Advanced might have been facing - the ICO warned last summer in its provisional findings that it planned to hit the company with a £6.09 million penalty.</p><p>What's changed since then is the company's proactive engagement with the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a>, the National Crime Agency (NCA) and the NHS, and the steps it's taken to mitigate the risk to those impacted by the attack.  </p><p>However, the ICO said the fine sends a salutary message to other organizations that may be a bit slapdash about the security of personal data.</p><p>"With cyber incidents increasing across all sectors, my decision today is a stark reminder that organisations risk becoming the next target without robust security measures in place," said Edwards. </p><p>"I urge all organisations to ensure that every external connection is secured with MFA today to protect the public and their personal information - there is no excuse for leaving any part of your system vulnerable." </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/us-healthcare-cyber-attacks-sunflower-medical-group">More than 300,000 US healthcare patients impacted in suspected Rhysida cyber attacks</a></li><li><a href="https://www.itpro.com/security/cyber-attacks-on-healthcare-organizations-are-surging-heres-why">Cyber attacks on healthcare organizations are surging</a></li><li><a href="https://www.itpro.com/security/healthcare-organizations-need-to-shake-up-email-security-practices">Healthcare organizations need to shake up email security practices</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ These five countries recorded the most third-party data breaches last year ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/third-party-data-breaches-global-statistics</link>
                                                                            <description>
                            <![CDATA[ Singapore and the Netherlands are the world's leading hotspots for third-party data breaches, with more than seven-in-ten organizations falling victim last year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wazjsTvAZjcNL4V6qRSWp7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Mar 2025 11:26:18 +0000</pubDate>                                                                                                                                <updated>Wed, 26 Mar 2025 11:43:35 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Singapore and the Netherlands are the world's leading hotspots for third-party data breaches, with more than seven-in-ten organizations falling victim last year.</p><p>Figures from SecurityScorecard’s <a href="https://securityscorecard.com/resource/global-third-party-breach-report/?utm_medium=owned_email&utm_source=mkto&utm_campaign=20250313-gl-re-global-third-party-breach-report&utm_content=research-report&utm_term=" target="_blank"><u>2025 </u><u><em>Global Third-Party Breach Report</em></u></a> show third-party breaches are on the rise, accounting for a third of all breaches globally. However, the number is probably higher than that due to a combination of under-reporting and misclassification. </p><p>More than four-in-ten ransomware attacks now start through third parties, the study found, with the ransomware group <a href="https://www.itpro.com/security/ransomware/the-big-three-ransomware-groups-are-losing-their-grip-on-the-industry-as-gangs-begin-to-fracture-study-shows">Cl0p </a>the most prolific offender.</p><p>"Threat actors are prioritizing third-party access for its scalability. Our research shows <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>groups and state-sponsored attackers increasingly leveraging supply chains as entry points," said Ryan Sherstobitoff, senior vice president of SecurityScorecard’s Strike Threat Research and Intelligence. </p><p>But there's huge national variation, the company noted. For example, Singapore had the highest third-party breach rate at 71.4%, despite relatively few total breaches. </p><p>"With its significant overseas Chinese population and strategic position in China’s economic and naval power projection, it’s a prime target," points out the firm.</p><p>The Netherlands ranked second, at 70.4%, although this figure was skewed by a major breach at a communications firm that hit a number of utilities. </p><p>Japan was third, at 60%, followed by Taiwan at 57.1% and Australia at 50%.</p><h2 id="who-s-behind-the-rise-in-third-party-data-breaches">Who’s behind the rise in third-party data breaches?</h2><p>The main culprit is China, according to SecurityScorecard, with Japan subjected to the most Chinese state-sponsored attacks. Taiwan, meanwhile, was also a key focus for <a href="https://www.itpro.com/security/cyber-warfare/368769/should-your-business-worry-about-chinese-cyber-attacks">Chinese cyber espionage</a>.</p><p>At the other end of the scale, the US has a supply chain attack rate of 30.9%, with the Philippines at 31%, India at 35%, and the UK at 37.2%.  </p><p>Retail and hospitality was the hardest-hit sector, with a third-party breach rate of 52.4%.</p><p>The tech industry was also a leading target for threat actors alongside critical infrastructure sectors such as energy and utilities and the healthcare industry. </p><h2 id="varied-attack-vectors-raising-the-stakes">Varied attack vectors raising the stakes</h2><p>In terms of attack vectors, the risks faced by organisations globally are expanding, according to SecurityScorecard. File transfer software topped the list, accounting for 14% of attacks, followed closely by cloud products and services at 8.3%. </p><p>"To stay ahead of these threats, security leaders must move from periodic vendor reviews to real-time monitoring to contain these risks before they escalate throughout their supply chain." said Sherstobitof.</p><p>Organizations should tailor their security strategies to their particular industry, geography, technology and organizational structure, advised the researchers.</p><p>They should mitigate fourth-party risk by requiring vendors to maintain strong third-party risk management programs themselves; and Secure by Design technology should be a must.</p><p>Protection of file transfer software, cloud infrastructure, industry-specific services and VPNs should be a priority, with speedy patching, multi-factor authentication (MFA) and continuous security assessments.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/nearly-all-of-the-top-us-banks-were-impacted-by-third-party-breaches-last-year">Nearly all of the top US banks were impacted by third party breaches last year</a></li><li><a href="https://www.itpro.com/security/insurance-sector-urged-to-sharpen-up-third-party-risk-management-as-attacks-surge">Insurance sector urged to sharpen up third-party risk management as attacks surge</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/third-party-ai-tools-are-muddying-sustainability-metrics">Third-party AI tools are muddying sustainability metrics</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Oracle breach claims spark war of words with security researchers ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/oracle-breach-cloudsek</link>
                                                                            <description>
                            <![CDATA[ A war of words has erupted between Oracle and cybersecurity researchers following claims the company suffered a security breach. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">95VhWDPig8Y8QCvyMGyLQS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qb3GhyQ7x66PFWYRicmN5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Mar 2025 09:43:01 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qb3GhyQ7x66PFWYRicmN5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Oracle logo pictured on the front of the company headquarters in Redwood City, California.]]></media:description>                                                            <media:text><![CDATA[Oracle logo pictured on the front of the company headquarters in Redwood City, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Oracle logo pictured on the front of the company headquarters in Redwood City, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qb3GhyQ7x66PFWYRicmN5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A war of words has erupted between Oracle and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>researchers following claims the company suffered a security breach. </p><p>In mid-March, a threat actor by the name ‘rose87168’ published six million records, claiming the data was stolen from Oracle’s Cloud federated <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">Single Sign-On (SSO)</a> login service and demanding payment from affected customers.</p><p>Posted to the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>, the sample database allegedly included a list of affected companies, encrypted SSO passwords, Java KeyStore (JKS) files, LDAP information, and more. </p><p>“The SSO passwords are encrypted, they can be decrypted with the available files, also LDAP hashed passwords can be cracked,” the threat actor said.  </p><p>"I'll list the domains of all the companies in this leak. Companies can pay a specific amount to remove their employees' information from the list before it's sold."</p><p><a href="https://www.cloudsek.com/blog/the-biggest-supply-chain-hack-of-2025-6m-records-for-sale-exfiltrated-from-oracle-cloud-affecting-over-140k-tenants" target="_blank"><u>Initial analysis from researchers at CloudSEK </u></a>suggested the root cause of the breach appears to have been a failure to patch a server affected by a critical vulnerability. </p><p>“The threat actor has demonstrated sophisticated capabilities by targeting a critical authentication infrastructure,” CloudSEK said in its report. “They’re not only selling the data but also actively recruiting assistance to decrypt the stolen passwords, suggesting an organized and persistent threat operation.”</p><h2 id="oracle-hits-back-at-data-breach-claims">Oracle hits back at data breach claims</h2><p>Oracle strongly denied the claims by both the threat actor and CloudSEK, insisting no customers have been impacted.</p><p>“There has been no breach of Oracle Cloud,” a spokesperson for the firm told <a href="https://www.bleepingcomputer.com/news/security/oracle-denies-data-breach-after-hacker-claims-theft-of-6-million-data-records/" target="_blank"><u><em>BleepingComputer</em></u></a>. “The published credentials are not for Oracle Cloud. No Oracle Cloud customer experienced a breach or lost any data.”</p><p>Researchers at CloudSEK have hit back, however, publishing a <a href="https://www.cloudsek.com/blog/part-2-validating-the-breach-oracle-cloud-denied-cloudseks-follow-up-analysis" target="_blank"><u>follow-up report</u></a> which claims their investigation “paints a different picture”. </p><p>CloudSEK said the threat actor provided a sample of customer data and a text file created on <em>login.us2.oraclecloud.com</em> – which researchers said equates to “evidence aligning with their claim that the SSO server was active weeks before the breach surfaced”. </p><p>In a comprehensive rebuttal to Oracle’s claims, CloudSEK said its investigation centers around a series of key findings. </p><p>This includes the fact that an archived <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>repository from Oracle’s official “oracle-quickstart” account features a script (mpapihelper.py) using login.us2.oraclecloud.com for OAuth2 token generation.</p><p>“This endpoint authenticated API requests for the Oracle Cloud Marketplace, proving its production use,” researchers said. “OneLogin and Rainfocus documentation further validate its role in live SSO setups.”</p><p>Similarly, the security firm pointed to what it described as “real users’ exposure” as a sign the claims are legitimate. A host of domains found in public GitHub repositories and Oracle partner guides allegedly match the attacker’s leaked tenant list, CloudSEK noted. </p><p>“These are not dummy accounts but Oracle Cloud users, underscoring the breach’s scope.”</p><p>Rahul Sasi, CEO and co-founder of CloudSEK, said the firm is “driven by transparency and evidence, not speculation” in response to Oracle’s denial. </p><p>“This follow-up report equips the community and Oracle with facts to investigate and mitigate this threat responsibly.”</p><h2 id="the-potential-impact-of-the-oracle-breach">The potential impact of the Oracle breach</h2><p>CloudSEK said the alleged breach could have profound implications for Oracle and its customers. </p><p>The company said six million records, including sensitive authentication data, could be at risk, thereby resulting in “heightened risks of authorized access and espionage”. </p><p>The risk posed by encrypted SSO and LDAP passwords could also “unlock further breaches if cracked,” CloudSEK warned. </p><p>Similarly, the supply chain fallout of the incident as a result of exposed JKS files is a serious cause for concern, enabling downstream attacks on interconnected systems. </p><p>“A suspected unpatched vulnerability suggests deeper security flaws,” CloudSEK added. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/cloud/cloud-computing/oracle-multi-cloud-adoption-drive">Say goodbye to walled gardens, Oracle is doubling down on multi-cloud</a></li><li><a href="https://www.itpro.com/technology/artificial-intelligence/ai-agent-announcements-are-a-dime-a-dozen-right-now-heres-what-oracle-thinks-its-doing-differently">Why Oracle thinks its agents service is the gold standard</a></li><li><a href="https://www.itpro.com/cloud/367935/best-cloud-computing-services-in-2022">Take a look at the best cloud computing services for business</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Western Alliance Bank admits cyber attack exposed 22,000 customers  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/western-alliance-bank-admits-cyber-attack-exposed-22-000-customers</link>
                                                                            <description>
                            <![CDATA[ An American bank has admitted nearly 22,000 customers had their accounts compromised following an attack that targeted a zero-day flaw in a third-party file-transfer tool. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iAcMsTowmWYz7tgzEi8Cam</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LbVUdSTaprZiuxA9RW6Z3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Mar 2025 10:57:13 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Mar 2025 12:13:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LbVUdSTaprZiuxA9RW6Z3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security tools concept image showing multiple locked padlocks with one opened padlock placed in middle. ]]></media:description>                                                            <media:text><![CDATA[Security tools concept image showing multiple locked padlocks with one opened padlock placed in middle. ]]></media:text>
                                <media:title type="plain"><![CDATA[Security tools concept image showing multiple locked padlocks with one opened padlock placed in middle. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LbVUdSTaprZiuxA9RW6Z3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>An American bank has admitted nearly 22,000 customers had their accounts compromised following an attack that targeted a zero-day flaw in a third-party file-transfer tool. </p><p>In a regulatory filing, Arizona-based Western Alliance Bank said attackers had access between 12 and 24 October last year, though the bank reportedly only became aware of the attack in January. </p><p>Hackers accessed customers' names, social security numbers, birthdates, drivers license details, tax numbers, passport information, and account numbers. The company has begun notifying those impacted by the incident. </p><p>The filing didn't detail which software was targeted, but Western Alliance Bank was one of dozens of companies named in by the Cl0p <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>group in January after a series of attacks using the Cleo file transfer zero-day flaw last year. </p><p><a href="https://www.securityweek.com/western-alliance-bank-discloses-data-breach-linked-to-cleo-hack/" target="_blank"><u>Reports online</u></a> this week also suggested the source of the incident was the Cleo flaw. </p><p>Clop claimed to have accessed data by breaching the file transfer program late last year, warning that named companies had days to begin ransom negotiations before data would be published. </p><p>Other companies named included Blue Yonder and Datatrac, though some on the list have denied they were actually hacked, and Western Alliance hasn't confirmed that its attack was part of the Clop attack. </p><p>Clop has previously targeted other file-sharing products, including <a href="https://www.itpro.com/security/why-the-moveit-breach-still-lives-rent-free-in-the-minds-of-it-leaders"><u>Progress Software's MOVEit Transfer</u></a> and <a href="https://www.itpro.com/security/data-breaches/370409/the-goanywhere-data-breach-explained"><u>Fortra's GOAnywhere</u></a>. </p><h2 id="what-happened-with-the-cleo-flaw">What happened with the Cleo flaw?</h2><p>The Cleo attack is ranked among one of the most devastating cybersecurity incidents in recent years, affecting a host of organisations globally. </p><p>The company first warned that hackers were making use of the zero-day flaw in October, issuing a patch to mitigate the attacks. </p><p>However, a month later, security firm <a href="https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild" target="_blank"><u>Huntress said</u></a> attacks were continuing because the first patch didn't fully fix the flaw, advising those at risk to move any exposed systems behind a firewall. </p><p>Cleo <a href="https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update-CVE-2024-55956" target="_blank"><u>published a subsequent patch</u></a> to fix the flaw in December and advised all customers to upgrade their version of the software, though only specific editions were affected. </p><h2 id="incident-highlights-continued-financial-services-risks">Incident highlights continued financial services risks</h2><p>Akhil Mittal, senior security consulting manager at Black Duck, said the incident highlights the continued threats faced by financial services firms. </p><p>"Customers aren’t shocked when financial institutions get hacked; they expect it," Mittal said. "It’s essential for financial institutions to detect and notify their customers of any data loss as soon as possible to prevent further loss and ensure the right next steps are taken quickly."</p><p>Mittal added that a widespread overreliance on third-party software suppliers also exacerbates the issue, with many institutions having fallen victim to supply chain breaches in recent years. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="eXeUqaohp4XQakUTnFozQZ" name="Security operations use case guide.jpg" caption="" alt="Security operations use case guide" src="https://cdn.mos.cms.futurecdn.net/eXeUqaohp4XQakUTnFozQZ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/security-operations-use-case-guide"><em>Improve the effectiveness of your security team</em></a></p></div></div><p>"Organizations continue to trust third-party software without enough oversight, and every few months, the same scenario plays out—a vendor gets breached, sensitive data is stolen, and customers get offered a year of credit monitoring that does little to fix the real issue," he said.</p><p>"This isn’t just about Western Alliance — it’s a systemic problem with third-party risk," Mittal added. </p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/business/policy-and-legislation/uk-financial-services-firms-are-scrambling-to-comply-with-dora-regulations">UK financial services firms are scrambling to comply with DORA regulations</a></li><li><a href="https://www.itpro.com/security/financial-services-firms-urged-to-bolster-security-capabilities-amid-surging-threats">Financial services firms urged to bolster security capabilities amid surging threats</a></li><li><a href="https://www.itpro.com/security/ransomware/uk-finance-firms-faced-a-surge-in-ransomware-attacks-in-2023-as-threat-actors-ramped-up-activities">UK finance firms facing a torrent of threats</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘It’s your worst nightmare’: A batch of €5 hard drives found at a flea market held 15GB of Dutch medical records – and experts warn it could’ve caused a disastrous data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/its-your-worst-nightmare-a-batch-of-eur5-hard-drives-found-at-a-flea-market-held-15gb-of-dutch-medical-records-and-experts-warn-it-couldve-caused-a-disastrous-data-breach</link>
                                                                            <description>
                            <![CDATA[ Robert Polet made a startling discovery after finding hard drives on sale for €5 each in a flea market. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dRucJ2kP5kKMNkPwuKp52n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dKf5WtwB6mHpPCk5XnrqeR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Mar 2025 16:30:00 +0000</pubDate>                                                                                                                                <updated>Wed, 05 Mar 2025 12:27:14 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dKf5WtwB6mHpPCk5XnrqeR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Man browsing through items for sale at a flea market stand. ]]></media:description>                                                            <media:text><![CDATA[Man browsing through items for sale at a flea market stand. ]]></media:text>
                                <media:title type="plain"><![CDATA[Man browsing through items for sale at a flea market stand. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dKf5WtwB6mHpPCk5XnrqeR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A Dutch IT company has demonstrated exactly how not to handle <a href="https://www.itpro.com/security/data-protection">data protection</a> after a number of <a href="https://www.itpro.com/server-storage/flash-storage/367837/10-things-to-consider-when-buying-an-external-hard-disk-based">hard drives</a> containing sensitive medical data were found for sale at a Belgian flea market.</p><p>First reported in Dutch broadcaster <a href="https://www.omroepbrabant.nl/nieuws/4643495/harde-schijven-vol-medische-data-verkocht-op-rommelmarkt" target="_blank"><em>Omroep Brabant</em></a><em>, </em>62-year-old Robert Polet from Breda found the hard drives on sale for roughly €5 each in a flea market after taking a pit stop on his way back from Belgium.</p><p>Polet, a computer-crazy camera enthusiast, said that on returning to his home in Breda and inspecting the hard drives, he was shocked to find they were full of medical data from the period between 2011 and 2019.</p><p>The hard drives contained the Dutch citizen service numbers (BSN), dates of birth, addresses, prescriptions, and other medical information linked to individuals from the Utrecht, Delft, and Houten regions.</p><p>After contacting the affected healthcare organisation, based in Utrecht, Polet said he was informed the data originated from an IT company that no longer exists.</p><p>Nortade ICT Solutions used to develop <a href="https://www.itpro.com/software">software </a>for the healthcare sector but exactly how the hard drives ended up at a flea market in Belgium is still unclear.</p><p>Polet told <em>Omroep Brabant</em> that once he had made the discovery he returned to the flea market to buy the rest of the hard drives, but could not ascertain where the seller had acquired them due to a language barrier.</p><h2 id="nightmare-breach-as-painful-as-anyone-can-imagine">“Nightmare” breach as “painful as anyone can imagine”</h2><p>Speaking to <em>ITPro </em>Rick Goud, CIO and co-founder at <a href="https://www.itpro.com/security/four-in-ten-employees-sacked-over-email-security-breaches-as-firms-tackle-truly-staggering-increase-in-attacks">email security</a> and file transfer platform Zivver, described the incident as a business’ ‘worst nightmare’, but noted he was not totally surprised by the incident.</p><p>“It’s your worst nightmare right? If the company wasn’t already bankrupt they probably would be by now… It is not a surprise, but of course as painful as anyone can imagine a data leak to be.”</p><p>Elaborating on this, Goud said he feels the fact that this data managed to leak via improperly handled hardware was indicative of a period where data protection was not front of mind for some organizations working with healthcare data.</p><p>“What is interesting about this case is that it’s quite old data. I think it fits the mindset of how healthcare data was treated ten years ago,” he explained.</p><p>“It’s certainly not an excuse but it is something I do recognize from the early days when I started in healthcare. Around 20 years ago you could still walk around with DVDs inside a hospital and ask the administrator to install it and put it on the mainframe and they would just do it.”</p><p>He said that thankfully the risk profile attached to data leaks, especially those affecting health data, has meant businesses take <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> and data protection more seriously over the last 10 years. </p><h2 id="attitudes-around-safeguarding-data-are-changing">Attitudes around safeguarding data are changing</h2><p>Goud attributed this improvement to a higher risk awareness driven by legislation and standards such as <a href="https://www.itpro.com/it-governance/31712/what-is-iso-27001">ISO 27001</a> and the NEN 7510 which set out procedures and best practices for data protection and deprecating old <a href="https://www.itpro.com/server-storage/flash-storage/360883/the-benefits-and-drawbacks-of-flash-storage-today">storage devices</a>.</p><p>But he warned some businesses will run into this type of security weakness on a day-to-day basis, particularly when they have handed off the problem to a third party.</p><p>“They do not ask the vendor the right questions to ensure that a) as a healthcare provider they are sure that the vendor treats the data as well as they do it themselves but also think that basically by hiring somebody else to process your data that you are not responsible anymore and of course that is not true.”</p><p>Victoria Hordern, partner and data protection specialist at global law firm Taylor Wessing, told <em>ITPro </em>that as well as Nortade itself the healthcare organization that contracted it could be subject to investigation.</p><p>"The health organizations that engaged Nortrade ICT Solutions would be required to carry out appropriate due diligence before appointing a third party provider and ensuring that data security to protect the data is adequate," Horden said. </p><p>"Therefore, to the extent this incident reveals a failure to do this, they could also be subject to investigation and enforcement action from the data protection authority."</p><p>Goud added that regulations like ISO 27001 and NEN 7510 have been around for some time but only became legally enforceable on healthcare organizations roughly four years ago, noting that he feels there has been a ‘mindset shift’ in data protection since then.</p><p>“So that has significantly changed practices, until then it was something that the early adopters that had the intrinsic motivation to adequately protect healthcare pursued because, of course, it's costly to go through that kind of certification process. Nowadays it is a must have,” he said.</p><p>“In 2011 to 2019 where this data is from you would see probably 2 – 3% of suppliers and healthcare organizations had that type of certification, nowadays I would say that it’s closer to 70 or 80% in the Netherlands at least.”</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/malware-free-attacks-surged-in-2024-as-attackers-drop-malicious-software-for-legitimate-tools">Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools</a></li><li><a href="https://www.itpro.com/security/nakivo-backup-flaw-still-present-on-some-systems-months-after-firms-silent-patch-researchers-claim">Nakivo backup flaw still present on some systems months after firms’ ‘silent patch’, researchers claim</a></li><li><a href="">Why government email servers are top targets for state-backed hackers</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 3.3 million people were exposed in the DISA data breach – it took the firm 10 months to disclose the incident ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/disa-data-breach</link>
                                                                            <description>
                            <![CDATA[ Background check firm DISA Global Solutions has revealed it suffered a data breach exposing millions of sensitive records. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nKioWTH3FZgAFBBhpL9KLc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Feb 2025 11:44:52 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Feb 2025 09:15:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:description>                                                            <media:text><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach concept image showing a red-colored warning symbol imposed over glowing binary code.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XwakieduPCLvHtxVTJnG7b-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Background check firm DISA Global Solutions has revealed it suffered a data breach exposing millions of sensitive records – nearly a year after the incident first occurred.</p><p>The breach, first discovered on April 22, 2024, had been allowing an unauthorized third-party to access data on around 3.3 million people since February 9th. </p><p>"Although our forensics investigation could not definitively conclude the specific information procured, the affected files contained individuals’ personal information, which came into our possession due to the employment screening services we provide employers and prospective employers," said the firm. </p><p>"Presently, we are unaware of any attempted or actual misuse of any information involved in this incident."</p><p>However, it said, it had not been able to definitively establish exactly what data had been accessed. </p><p>The company is contacting people whose personal information was accessed - personal information that may have included name, social security number, driver’s license number, other government ID numbers, financial account information, and other data.</p><p>It's also offering those affected access to credit monitoring and identity restoration services through <a href="https://www.itpro.com/policy-legislation/general-data-protection-regulation-gdpr/357564/experian-faces-gdpr-action">Experian</a>.  </p><p>"We take this incident seriously and sincerely regret any inconvenience this incident may cause affected individuals," said DISA.  </p><p>"Upon discovery, we secured our network, notified law enforcement authorities, safely restored our systems and operations, and implemented additional security measures. We also offer affected individuals access to credit monitoring and identity restoration services through Experian."</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/a696c78c-0d94-4bc0-b1cf-106e70c68480/"></iframe><h2 id="disa-data-breach-a-wake-up-call-for-background-check-firms">DISA data breach a wake up call for background check firms</h2><p>Background check companies are prime targets for cyber criminals because of their long-term <a href="https://www.itpro.com/infrastructure/backup/why-long-term-data-storage-continues-to-challenge-businesses">storage</a> of vast amounts of highly sensitive personal data – and this isn't always as well protected as it should be, said Cory Michal, CSO at security company AppOmni.</p><p>"Unlike financial institutions, which must adhere to strict <a href="https://www.itpro.com/security/why-the-uks-outdated-cybersecurity-legislation-needs-an-urgent-refresh">cybersecurity regulations</a>, these companies often operate with less security budget and weaker security controls, making them more vulnerable to attacks," he said.</p><p>"Additionally, many background check firms lack advanced monitoring and forensic capabilities, leading to prolonged undetected breaches, as seen in the DISA Global Solutions breach where attackers had access for over two months before detection."</p><p>Michal said he'd like to see background check companies made subject to stricter <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> laws and standards, similar to those imposed on institutions under HIPAA or PCI-DSS. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pZaGNpX3LUhenAApm8Je2k" name="pZaGNpX3LUhenAApm8Je2k.jpg" caption="" alt="IBM" src="https://cdn.mos.cms.futurecdn.net/pZaGNpX3LUhenAApm8Je2k.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/technology/artificial-intelligence/maximizing-contact-center-operations-with-generative-ai-assistants-backed-by-responsible-ai-principles"><em>Develop a comprehensive GenAI strategy</em></a></p></div></div><p>This would mandate encryption, continuous monitoring and breach detection measures. </p><p>"Additionally, they should face clear liability for data breaches, with financial penalties and mandatory compensation for affected individuals. Stronger data retention policies should also be enforced, preventing unnecessary long-term storage of sensitive information," he said. </p><p>"Without robust federal regulations and industry-specific security mandates, these breaches will continue to expose millions to identity theft, fraud, and financial loss."</p><p>The breach has already mobilized several US law firms to launch class action lawsuits.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/the-national-public-data-breach-exposed-nearly-three-billion-users-now-the-company-has-filed-for-bankruptcy">The National Public Data breach exposed 270 million users</a></li><li><a href="https://www.itpro.com/security/ransomware/cisco-kraken-breach-claims">Cisco hits back at Kraken group data breach claims</a></li><li><a href="https://www.itpro.com/security/data-breaches/800-000-users-exposed-in-landmark-admin-data-breach">800,000 users exposed in Landmark Admin data breach</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zacks Investment breach could leave 12 million customer accounts exposed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/zacks-investment-breach-could-leave-12-million-customer-accounts-exposed</link>
                                                                            <description>
                            <![CDATA[ A threat actor claims to have seized data belonging to 12 million Zacks Investment customer accounts. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kizMChGSHiVggYJ7ixkX3h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zuZMUhWSyJW7AkqFr5VBi8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Feb 2025 11:13:25 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Feb 2025 16:25:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a Staff Writer at ITPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zuZMUhWSyJW7AkqFr5VBi8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[line graph in green and red on blue background representing fluctuating prices]]></media:description>                                                            <media:text><![CDATA[line graph in green and red on blue background representing fluctuating prices]]></media:text>
                                <media:title type="plain"><![CDATA[line graph in green and red on blue background representing fluctuating prices]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zuZMUhWSyJW7AkqFr5VBi8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zacks Investment, a leading investment research company, has allegedly suffered a <a href="https://www.itpro.com/security/data-breaches">data breach</a> that could see roughly 15 million customer records exposed.</p><p>A threat actor under the name Jurak posted on the dark web hacking forum BreachForums on 24 January 2025, claiming to have breached Zacks Investment in June last year.</p><p>Zacks is a major financial analysis provider best known for its Zacks Ranks platform used to assess stock performance. The post alleges that the stolen information contains source code as well as Zacks’ database, “containing 15 million customer lines of their customers and clients”.</p><p>This includes usernames, emails, passwords, addresses, full names, and phone numbers, according to the poster, who provided a sample of the customer data as proof.</p><p>Jurak added that they considered releasing the source code publicly but opted against it, stating trustworthy users with a ‘high reputation’ could request the <a href="https://www.itpro.com/security/ransomware/364177/conti-source-code-leaked-by-ukrainian-researcher">source code</a> by contacting them directly.</p><p>According to <em>Have I Been Pwned</em>, the stolen customer information is said to affect 12 million unique email addresses, stating the number of compromised accounts was 11,994,223.</p><p>It notes the customer information included unsalted SHA-256 password hashes, which raises serious concerns as they are vulnerable to cracking via <a href="https://www.itpro.com/security/cyber-security/354320/the-next-wave-of-bot-driven-brute-force-attacks">brute force</a> methods.</p><p>The threat actor, who spoke to <a href="https://www.bleepingcomputer.com/news/security/hacker-leaks-account-data-of-12-million-zacks-investment-users/" target="_blank"><em>BleepingComputer</em></a>, said they used privileges of a domain admin to gain access to the company’s active directory and stole the source code for its primary domain (zacks.com) as well as 16 other sites.</p><p><em>ITPro</em> has approached Zacks Investment Research but did not receive a response by the time of publishing.</p><h2 id="incident-marks-third-zacks-investment-security-breach">Incident marks third Zacks Investment security breach</h2><p>In its post announcing the breach, the user referred to a previous breach that took place in late 2022 and exposed sensitive information relating to 820,000 customers.</p><p>In a post acknowledging the incident, the firm stated that its team had identified that an unknown actor had gained unauthorized access to customer records.</p><p>The firm initially stated the exposed customer information was limited to those who had signed up for its Zacks Elite product between 1999 and February 2005.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="NXn2qgxxjYJYQmYBjrWLBA" name="Zero to hero_ A blueprint for establishing a security champions program" caption="" alt="Zero to hero: A blueprint for establishing a security champions program" src="https://cdn.mos.cms.futurecdn.net/NXn2qgxxjYJYQmYBjrWLBA.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/zero-to-hero-a-blueprint-for-establishing-a-security-champions-program"><em>Security shouldn't be an afterthought in the development process</em></a></p></div></div><p>However, the company later clarified that it had found the attackers had gained access to encrypted passwords of ‘zacks.com’ customers up to May 2020 in a second breach that took place in June 2023.</p><p>This database contained information such as the full names, emails, usernames, unsalted SH-256 passwords, addresses, and phone numbers of 8.8 million Zacks users.</p><p>This would take the total number of exposed users to over 21 million in the last four years.</p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/data-breaches/hpe-midnight-blizzard-data-breach-notification">HPE alerts affected staff after Midnight Blizzard breach</a></li><li><a href="https://www.itpro.com/security/data-breaches/850-000-patients-may-have-been-affected-in-the-globe-life-breach-after-firm-revises-victim-list">850,000 patients may have been affected in the Globe Life breach after firm revises victim list</a></li><li><a href="https://www.itpro.com/security/data-breaches/wholly-inaccurate-and-very-significantly-overstated-talktalk-confirms-data-breach-probe-but-says-its-not-as-bad-as-claimed">TalkTalk confirms data breach probe – but says it's not as bad as claimed</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HPE alerts affected staff after Midnight Blizzard breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/hpe-midnight-blizzard-data-breach-notification</link>
                                                                            <description>
                            <![CDATA[ HPE has notified staff affected in a data breach that sensitive personal information, including credit card details, may have been exposed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MFSPwpwKVw9ttsn9iebvvH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hVuCS4QNbUCw7UYrVhDLBY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Feb 2025 11:13:09 +0000</pubDate>                                                                                                                                <updated>Mon, 10 Feb 2025 16:15:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hVuCS4QNbUCw7UYrVhDLBY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[HPE logo and branding pictured on the company headquarters in Spring, Texas, United States.]]></media:description>                                                            <media:text><![CDATA[HPE logo and branding pictured on the company headquarters in Spring, Texas, United States.]]></media:text>
                                <media:title type="plain"><![CDATA[HPE logo and branding pictured on the company headquarters in Spring, Texas, United States.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hVuCS4QNbUCw7UYrVhDLBY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/strategy/28233/everything-you-need-to-know-about-hpe">Hewlett Packard Enterprise (HPE)</a> is notifying staff whose personal data was accessed by Russian state-sponsored hackers back in May 2023.  </p><p>According to filings with the attorney general offices in New Hampshire and Massachusetts, the company has written to at least 16 people, notifying them that their driver's licenses, credit card numbers, and Social Security numbers may have been stolen in the attack.</p><p>"HPE’s forensic investigation determined that certain individuals’ personal information may have been subject to unauthorized access. With the assistance of e-discovery specialists, HPE conducted a thorough review of the data at issue to identify the types of information that may have been subject to unauthorized access and determine to whom this information relates," the <a href="https://mm.nh.gov/files/uploads/doj/remote-docs/hewlett-packard-enterprise-20250205.pdf" target="_blank"><u>filing</u></a> reads.</p><p>"On January 29, 2025, HPE began providing notice of this event to impacted individuals, in accordance with applicable law."</p><p>Since the attack, HPE said it has taken a series of remediation actions, such as strengthening network security by <a href="https://www.itpro.com/cloud/cloud-security/the-biggest-cloud-security-risk-in-2024-will-be-stolen-and-exposed-credentials">rotating passwords</a>, tokens and keys, expanding its monitoring and logging measures, and adding extra controls and requirements for privileged account logins.</p><p>The firm has also expanded internal communication on security measures.</p><p>In the wake of the incident, HPE is offering affected staff free memberships for Equifax Complete Premier, which provides information on changes to victims’ credit reports, as well as WebScan notifications when financial details are found on fraudulent trading platforms.</p><p>The package also includes identity restoration services and up to $1,000,000 of identity theft insurance coverage for out of pocket expenses.</p><p>"In addition to enrolling in credit monitoring, we recommend that you remain vigilant against incidents of identity theft and fraud by reviewing your account statements and monitoring your free credit reports for suspicious activity and to detect errors,” the firm said. </p><h2 id="what-happened-in-the-hpe-attack">What happened in the HPE attack?</h2><p>The <a href="https://www.itpro.com/security/midnight-blizzard-claims-another-big-tech-scalp-with-hpe-hack-just-days-after-microsoft-breach-and-more-victims-could-be-coming">HPE breach was first disclosed in January 2024</a> after Microsoft issued a warning that the Midnight Blizzard hacking group had breached its <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Office 365</a> email environment.</p><p>The attackers targeted several email accounts within HPE’s <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a>, marketing, and business teams, using a compromised account to gain access to email mailboxes and steal sensitive data. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="84892qDZefKbnxBU3cakAC" name="Six steps to a stronger security posture through automation_email.jpg" caption="" alt="A whitepaper from ServiceNow on steps to a stronger security posture through automation, with image of businessman" src="https://cdn.mos.cms.futurecdn.net/84892qDZefKbnxBU3cakAC.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: ServiceNow)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/six-steps-to-a-stronger-security-posture-through-automation"><em>Efficient and effective attack surface hardening</em></a></p></div></div><p>Midnight Blizzard is believed to have ties to Russia's Foreign Intelligence Service (SVR), and are best-known for the infamous <a href="https://www.itpro.com/security/cyber-attacks/358738/intern-blamed-for-weak-password-that-may-have-sparked-solarwinds">SolarWinds attack</a> in 2019, which impacted several US governmental bodies, including the department of commerce and the treasury.  </p><p>HPE has also said it believed that the hack was related to another attack in May 2023, in which Midnight Blizzard gained unauthorized access to several <a href="https://www.itpro.com/security/cyber-attacks/warning-issued-after-sharepoint-flaw-puts-entire-corporate-networks-at-risk">SharePoint</a> files on the HPE system. </p><p>However, the firm said this attack had not materially impacted the company.</p><p><em>ITPro has approached HPE for comment.</em></p><h3 class="article-body__section" id="section-more-from-itpro"><span>MORE FROM ITPRO</span></h3><ul><li><a href="https://www.itpro.com/security/cyber-attacks/2024-was-a-record-year-for-commercial-cyber-attacks">2024 was a record year for commercial cyber attacks</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/linkedin-social-engineering-attacks">LinkedIn has become a prime hunting ground for cyber criminals</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/how-russia-linked-hackers-launched-their-latest-using-microsoft-teams">How Russian hackers launched their latest attack using Microsoft Teams</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 850,000 patients may have been affected in the Globe Life breach after firm revises victim list  ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/850-000-patients-may-have-been-affected-in-the-globe-life-breach-after-firm-revises-victim-list</link>
                                                                            <description>
                            <![CDATA[ US insurer Globe Life has revealed more than 850,000 patients may have been impacted in a data breach after initially believing only around 5,000 were impacted. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">mR9L69dba2M5RriMxQ7RPo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Feb 2025 08:05:49 +0000</pubDate>                                                                                                                                <updated>Wed, 05 Feb 2025 14:37:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:description>                                                            <media:text><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:text>
                                <media:title type="plain"><![CDATA[Ransomware concept image showing digitized padlock pictured on a laptop screen on red background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/bBfHCREVCzyehuRCbKWheD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>American insurance firm Globe Life has warned that another 855,000 people were potentially impacted by a <a href="https://www.itpro.com/security/cyber-attacks">cyber attack</a> last summer — not the original 5,000 initially reported.</p><p>Last summer, Globe Life spotted that cyber criminals had accessed customer data, reportedly via an online portal. </p><p>The insurance company — one of the biggest and oldest in the US — filed a report with the <a href="https://www.itpro.com/business/policy-and-legislation/new-sec-rules-around-data-breach-disclosures-arrive-on-monday-heres-what-you-need-to-know">SEC</a> on the attack, saying that details had been accessed on 5,000 individuals, but promised to update that figure after an internal investigation. </p><p>In October, Globe Life revealed that cyber criminals had contacted the insurer attempting to extort money in exchange for not leaking data. </p><p>Now, Globe Life has revealed further details of the attack, saying the initial 5,000 confirmed victims were traced to a set of specific databases maintained by third parties, or as the company put it: "a small number of independent agency owners." </p><p>The details taken were from customers of Globe Life subsidiary American Income Life Company. Those databases also included details on the additional 850,000 people, and while there's no evidence their information was leaked, the company is writing to potential victims as a precaution. <br></p><p>"Out of an abundance of caution, the company has also initiated the process to provide voluntary notifications to, and credit monitoring services for, approximately 850,000 additional individuals whose information was also stored in the relevant databases, even though the company has not been able to confirm if the threat actor acquired these additional individuals’ data," the company said in an <a href="https://www.bamsec.com/filing/32033525000004?cik=320335" target="_blank"><u>SEC filing</u></a>. </p><h2 id="globe-life-insists-no-ransom-was-paid">Globe Life insists no ransom was paid</h2><p>Globe Life added that it didn't pay the ransom, and stressed the extortion attempt didn't use ransomware or impact business operations at the time. </p><p>According to the most recent filing, the data accessed includes names, email addresses, phone numbers, and addresses, as well as insurance policy information, health data, social security numbers, and date of birth, but no financial information. </p><p>Thomas Richards, principal consultant at security firm Black Duck, said the incident will still be a cause for serious concern among customers. </p><p>“The uncertainty regarding the number of individuals affected and data accessed in this breach should be concerning, especially since this is a pretty substantial breach with almost one million policyholders affected,” he said. </p><p>"Without having this information, the affected individuals may not have clarity on the best ways to protect themselves and their personal information.</p><p>“Although it is fortunate that no financial information was accessed, financial information is often the easiest to change in this kind of scenario," Richards noted.</p><p>"However, one cannot change their health-related data, date of birth, or social security number so it’s imperative that the affected individuals are notified as soon as possible to begin taking the necessary steps to protect themselves and their data."</p><p>Globe Life was one of several high-profile insurers hit by cyber criminals last year, with a spate of attacks targeting organizations operating in the industry. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ePGeT9Vj5VgJGsfVqWuxTS" name="Powering productive work (1)" caption="" alt="Powering productive work" src="https://cdn.mos.cms.futurecdn.net/ePGeT9Vj5VgJGsfVqWuxTS.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CDW | Microsoft)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/hardware/powering-productive-work"><em>Device strategies that empower today’s workforce</em></a></p></div></div><p>The <a href="https://www.itpro.com/security/ransomware/unitedhealth-group-admits-to-paying-ransom-after-change-healthcare-cyber-attack">Change Healthcare cyber attack</a>, for example, <a href="https://www.itpro.com/security/cyber-attacks/unitedhealth-reveals-190-million-us-citizens-were-impacted-by-the-change-healthcare-breach"><u>impacted around 190 million US citizens</u></a>, with parent company UnitedHealth having recently revised its numbers following an investigation. </p><p>Elsewhere, a <a href="https://www.itpro.com/security/data-breaches/800-000-users-exposed-in-landmark-admin-data-breach"><u>data breach at Landmark Admin saw 800,000 users exposed</u></a>. A filing with the Attorney General of Maine revealed the breach exposed a broad range of personal data, including full names and addresses, social security numbers, tax ID numbers, and drivers’ license numbers. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Wholly inaccurate and very significantly overstated’: TalkTalk confirms data breach probe – but says it's not as bad as claimed ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/wholly-inaccurate-and-very-significantly-overstated-talktalk-confirms-data-breach-probe-but-says-its-not-as-bad-as-claimed</link>
                                                                            <description>
                            <![CDATA[ UK telecoms firm TalkTalk has launched a data breach probe following reports a threat actor has stolen customer information. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BxhRrw6rC4xFrfdnfHkKvY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/g26qRbzHwrxrGDKfph63yM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 28 Jan 2025 10:29:00 +0000</pubDate>                                                                                                                                <updated>Tue, 28 Jan 2025 14:34:43 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/g26qRbzHwrxrGDKfph63yM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[TalkTalk logo and branding pictured on a smartphone with binary code in background.]]></media:description>                                                            <media:text><![CDATA[TalkTalk logo and branding pictured on a smartphone with binary code in background.]]></media:text>
                                <media:title type="plain"><![CDATA[TalkTalk logo and branding pictured on a smartphone with binary code in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/g26qRbzHwrxrGDKfph63yM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>UK telecoms firm TalkTalk has confirmed that it's suffered a data breach, with a hacker known as b0nd claiming responsibility. </p><p>According to reports from <a href="https://techcrunch.com/2025/01/27/talktalk-investigating-data-breach-after-hacker-claims-theft-of-customer-data/" target="_blank"><em>TechCrunch</em></a>, b0nd is offering the personal data of more than 18.8 million current and former TalkTalk subscribers for sale on a popular cyber crime forum. </p><p>The data is claimed to include customer names, email addresses, IP addresses, phone numbers and subscriber PINs. </p><p>The threat actor is believed to have accessed the data via the systems of a third party supplier. While the supplier remains unnamed, it appears from screenshots shared by b0nd to be CSG’s Ascendon platform, which TalkTalk uses for subscription management. </p><p>TalkTalk confirmed the probe in a statement given to <em>ITPro</em>.</p><p>"As part of our regular security monitoring, given our ongoing focus on protecting customers’ personal data, we were made aware of unexpected access to, and misuse of, one of our third-party supplier's systems, however, no billing or financial information was stored on this system," a spokesperson told <em>ITPro</em>. </p><p>"Our Security Incident Response team is continuing to work with the supplier regarding this matter, and protective containment steps were taken immediately."</p><p>The spokesperson added that the claims about the number of people affected were "wholly inaccurate and very significantly overstated".</p><p>TalkTalk currently boasts around 2.4 million customers, vastly fewer than the number claimed by b0nd. The third party supplier also manages a smaller number than that.  </p><p>Meanwhile, many records are duplicated.</p><p>"Based on various dark web forum postings, it appears the threat actor has gained access to one or multiple CSG Ascendon subscription management platform tenants, some of which provide reports showing stored PINs in plain text - best practice dictates these be encrypted," said Cory Michal, chief security officer at SaaS security company, AppOmni.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LwJQUwZFb66w8TQNw3yMh7" name="2024 Cloud Security Report" caption="" alt="2024 Cloud Security Report" src="https://cdn.mos.cms.futurecdn.net/LwJQUwZFb66w8TQNw3yMh7.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/2024-cloud-security-report"><em>The latest insights on the trends driving cloud security</em></a></p></div></div><p>Michal added that b0nd appears to have only around four million data records, including PIN, name, email, IP address, and subscriber phone, in various combinations.</p><p>"b0nd is a relatively new account on the forum where the sale was posted, with the first post being on January 19 offering a Rust-based RAT for $30,000. The actor is now reposting full breach dumps from previous attacks to try and gain credibility on the account," he said.</p><p>"Additionally, one of the screenshots b0nd posted also claims to have data from 'Netflix Bundle Activations', which is something else to watch for."</p><p>It's not the first time that <a href="https://www.itpro.com/data-breaches/33701/fresh-talktalk-customer-data-found-publicly-available-online">TalkTalk has suffered a data breach</a>. In 2015, it revealed that personal data belonging to around four million people had been accessed in a cyber attack. </p><p>The telecoms firm was hit with a £400,000 fine from the <a href="https://www.itpro.com/information-commissioner/31751/what-is-the-information-commissioner-s-office-ico">Information Commissioner's Office (ICO)</a> as a result.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ HPE confirms data breach probe after IntelBroker claims ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/hpe-confirms-data-breach-probe-after-intelbroker-claims</link>
                                                                            <description>
                            <![CDATA[ IntelBroker claims to have stolen HPE source code in the breach ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iyz2ry5k6U878cRDDTkpSH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jan 2025 12:16:40 +0000</pubDate>                                                                                                                                <updated>Tue, 21 Jan 2025 15:07:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:description>                                                            <media:text><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:text>
                                <media:title type="plain"><![CDATA[Hewlett Packard Enterprise (HPE) corporate headquarters located in Palo Alto, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/99q8FYxWZfyGywAkTPij5i-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hewlett Packard Enterprise (HPE) has confirmed it is investigating data breach claims made by the IntelBroker threat group. </p><p>Last week, IntelBroker published a statement on a data breach forum saying it had successfully breached HPE's network and nabbed information, offering it for sale on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/hewlett-packard-enterprise-investigates-new-breach-claims/" target="_blank"><u>reports</u></a>, the hackers claimed to have successfully snuck into parts of HPE's network for two days, accessing HPE's private GitHub repositories, APIs, and WePay service while managing to steal certificates, source code for Zerto and iLO, Docker builds, and personal data relating to deliveries. </p><p><a href="https://www.itpro.com/strategy/28233/everything-you-need-to-know-about-hpe"><u>HPE</u></a> said the apparent hack was still being investigated, but stressed there was no customer data lost and the company was operating as normal. </p><p>"HPE became aware on January 16 of claims being made by a group called IntelBroker that it was in possession of information belonging to HPE," a company spokesperson said in a statement to <em>ITPro</em>. </p><p>"HPE immediately activated our cyber response protocols, disabled related credentials, and launched an investigation to evaluate the validity of the claims.</p><p>"There is no operational impact to our business at this time, nor evidence that customer information is involved."</p><h2 id="hpe-isn-t-the-only-big-tech-firm-targeted-by-intelbroker">HPE isn't the only big tech firm targeted by IntelBroker</h2><p>Other attacks have been attributed to IntelBroker — believed to be led by a Serbian operating out of Russia — including breaches that leaked internal Apple tools and data from Europol, as well a health care provider used by American politicians. </p><p>Indeed, HPE was hit by similar data leak claims by IntelBroker this time last year; as with this latest incident, HPE said it <a href="https://www.bleepingcomputer.com/news/security/hpe-investigates-new-breach-after-data-for-sale-on-hacking-forum/"><u>hadn't found</u></a> any evidence of a security breach. </p><p>That is a common pattern with IntelBroker claims. Companies find out via a statement on a hacking forum, investigate the incident, and then claim the intrusion wasn't serious and the data taken wasn't of any importance. </p><p>Companies targeted by IntelBroker have repeatedly disputed claims about the seriousness of the incident, saying any access was limited to small amounts of unimportant data, suggesting the hacks listed on dark-web forums were exaggerated. </p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="qQyHwhHoccvsxdAQrEgLgJ" name="Fortinet’s tested and validated architectures for cloud network security" caption="" alt="Fortinet’s tested and validated architectures for cloud network security" src="https://cdn.mos.cms.futurecdn.net/qQyHwhHoccvsxdAQrEgLgJ.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Fortinet)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/cloud/cloud-security/fortinets-tested-and-validated-architectures-for-cloud-network-security"><em>Speed up cloud deployment and improve security</em></a></p></div></div><p>Indeed, the hacker <a href="https://sec.cloudapps.cisco.com/security/center/resources/october_15_2024"><u>breached Cisco's systems in October</u></a>, listing <a href="https://www.itpro.com/security/cyber-attacks/intelbroker-leaks-2-9-tb-of-exposed-cisco-records-and-theres-more-to-come"><u>2.9 terabytes of information</u></a> on the dark web. But while Cisco admitted the incident, the company has stressed that the <a href="https://www.itpro.com/security/cyber-attacks/cisco-confirms-attackers-stole-non-public-data-shuts-down-access-to-compromised-devhub-environment"><u>data wasn't confidential or sensitive in nature</u></a>. </p><p>That was echoed in a subsequent breach at Nokia. IntelBroker released a cache of <a href="https://www.itpro.com/security/cyber-attacks/nokia-waves-off-intelbroker-breach-claims-says-leaked-source-code-came-from-a-third-party-application"><u>data stolen from the telco in November</u></a>, but Nokia downplayed the incident, stressing that no company or customer data was actually leaked.</p><p>IntelBroker responded to such claims by releasing more data from the Cisco breach at the end of last year, and earlier this month <a href="https://x.com/IntelBrokerBF/status/1877488620791029973" target="_blank"><u>said</u></a>: "I promise you all some HQ leaks soon."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Threat of personal liability has CISOs sweating ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/threat-of-personal-liability-has-cisos-sweating</link>
                                                                            <description>
                            <![CDATA[ With increased scrutiny, boards need to ramp up support for CISOs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yfEYTTgZJYyJC66PSNtdxJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 13 Dec 2024 11:23:12 +0000</pubDate>                                                                                                                                <updated>Fri, 13 Dec 2024 15:55:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Tired man working on computer laptop late at night]]></media:description>                                                            <media:text><![CDATA[Tired man working on computer laptop late at night]]></media:text>
                                <media:title type="plain"><![CDATA[Tired man working on computer laptop late at night]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qpJGqTkPZFmEASg2V62UvN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>CISOs are feeling the pressure over stories of their peers being held <a href="https://www.itpro.com/security/data-breaches/sec-data-breach-rules-branded-worryingly-vague-by-industry-body">personally liable for cybersecurity incidents</a>.</p><p>In the most notorious example, the US Securities and Exchange Commission (SEC) last year announced that it was <a href="https://www.itpro.com/security/solarwinds-claims-the-sec-is-spinning-a-false-narrative-over-sunburst-response">filing charges against both SolarWinds and its CISO, Tim Brown</a>, amid allegations of "fraud and internal control failures relating to allegedly known cybersecurity risks and vulnerabilities".</p><p>While Brown beat the charges earlier this year, others haven’t been quite as lucky. </p><p>Uber CSO Joe Sullivan, for example, was given a three-year probation sentence and a $50,000 fine for covering up a 2016 data breach. And CISOs fear such charges could potentially be filed against them. </p><p>Seven-in-ten told security firm BlackFog in a new survey that incidents like this had negatively affected their opinion of the job. Around a third said the trend was a no-win situation for security leaders, leaving them facing internal consequences if they report failings and prosecuted if they don’t.</p><p>"The role of the <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO</a> is all about managing risk for the organization but, as regulations tighten, security leaders increasingly need to consider their own personal risk," said BlackFog founder and CEO Dr Darren Williams.</p><p>Increased accountability has, at least, led to internal changes to improve <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> practices within their organisation. Nearly half (44%) of respondents said their company had already put processes in place to reduce their cyber exposure as a result.</p><p>Nearly half of all respondents believe that the potential for an individual to be prosecuted following a cyber attack would improve accountability and transparency amongst cyber professionals. </p><p>This was higher for respondents in the US, at 55%, compared with those in the UK at 43%.</p><p>When asked about the impact on the cybersecurity leaders of the future, only 15% believed that it would be a deterrent for IT professionals to become CISOs.</p><p>Meanwhile, four-in-ten said the increased scrutiny and potential of personal liability has made the board take cybersecurity more seriously. This was higher in the UK, with 47% of security leaders agreeing, compared with just 35% in the US.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="ayY2eqwwgoPAZnhjhJrwDa" name="Bridging the gap_ How security teams can engage developers in security programs.jpg" caption="" alt="Bridging the gap: How security teams can engage developers in security programs" src="https://cdn.mos.cms.futurecdn.net/ayY2eqwwgoPAZnhjhJrwDa.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Snyk)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/bridging-the-gap-how-security-teams-can-engage-developers-in-security-programs"><em>Engage developers in security programs</em></a></p></div></div><p>This has yet to translate into more resources, though, with just 10% of all respondents saying such concerns had translated to any rise in security budget. </p><p>"High profile instances of individuals being charged will no doubt add to the pressures they feel but could also be a catalyst for boards to support their leaders," said Williams. </p><p>"Improvements to governance, clear lines of reporting and incident response procedures are vital, but this must be supported by allocated resources so that security leaders can implement the security measures they need."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Amazon confirms employee data compromised amid 2023 MOVEit breach claims – but the hacker behind the leak says a host of other big tech names are also implicated ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/amazon-confirms-employee-data-compromised-in-2023-moveit-breach-but-the-hacker-behind-the-leak-claims-a-host-of-other-big-tech-names-are-also-implicated</link>
                                                                            <description>
                            <![CDATA[ Millions of records stolen during the 2023 MOVEit data breach have been leaked ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ANVeZ6FHbouwebjwMHCzK6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2B9Jf7dfcUvu2kKmsDvM3S-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 12 Nov 2024 10:38:59 +0000</pubDate>                                                                                                                                <updated>Tue, 12 Nov 2024 15:04:38 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ solomon.klappholz@futurenet.com (Solomon Klappholz) ]]></author>                    <dc:creator><![CDATA[ Solomon Klappholz ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pjZQRW2qWqQNjxubC6SUQ5.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Solomon Klappholz is a former Staff Writer at ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing which led to him developing a particular interest in IT regulation, industrial infrastructure applications, and machine learning.&lt;/p&gt;&lt;p&gt;Before he joined ITPro, Solomon graduated from the University of Warwick in 2021 with a BA (Hons) in Philosophy, Politics, and Economics which included an intercalated year studying Philosophy at the Erasmus University, Rotterdam.&lt;/p&gt;&lt;p&gt;Outside of the office, Solomon enjoys reading, visiting new art exhibitions, and playing football.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2B9Jf7dfcUvu2kKmsDvM3S-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon logo and branding pictured on a logistics facility in Velizy-Villacoublay, France.]]></media:description>                                                            <media:text><![CDATA[Amazon logo and branding pictured on a logistics facility in Velizy-Villacoublay, France.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon logo and branding pictured on a logistics facility in Velizy-Villacoublay, France.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2B9Jf7dfcUvu2kKmsDvM3S-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/tag/amazon">Amazon</a> has confirmed that a security incident affecting a third-party vendor has exposed employee information.</p><p>The incident saw data allegedly belonging to employees at a host of major tech firms leaked, with the data believed to have been stolen during the 2023 <a href="https://www.itpro.com/security/why-the-moveit-breach-still-lives-rent-free-in-the-minds-of-it-leaders">MOVEit breach</a>. </p><p>An Amazon spokesperson told <em>ITPro</em> its internal systems remain secure, insisting the incident was isolated to one of its <a href="https://www.itpro.com/security/data-breaches/358864/third-party-attacks-expose-12m-health-care-records">third-party</a> property management systems. </p><p>“Amazon and <a href="https://www.itpro.com/amazon-web-services">AWS</a> systems remain secure, and we have not experienced a security event. We were notified about a security event at one of our property management vendors that impacted several of its customers including Amazon.”</p><p>The statement added that the published information was limited to employee contact information, as well as some <a href="https://www.itpro.com/security/privacy/355211/google-releases-location-data-to-showcase-effectiveness-of-coronavirus">location data</a>.</p><p>“The only Amazon information involved was employee work contact information, for example work email addresses, desk phone numbers, and building locations.”</p><p>Amazon did not confirm how many employees were impacted by the breach.</p><p>The tech giant isn’t the only major organization impacted in the data dump. <a href="https://www.itpro.com/hardware/laptops/hp-omnibook-x-14-review-incredible-battery-life-meets-copilot-ai">HP</a>, <a href="https://www.itpro.com/tag/lenovo">Lenovo</a>, and other parties including HSBC and MetLife have allegedly been impacted in the breach. </p><p><em>ITPro </em>has contacted the organizations for confirmation.</p><p>Leaked by a cyber criminal using the moniker ‘Nam3L3ss’, the cache is said to include a variety of employee data including names, email addresses, <a href="https://www.itpro.com/security/privacy/356000/whatsapp-exposed-users-phone-numbers-in-google-search-results">phone numbers</a>, cost center codes, and, in some cases, entire organizational structures of the affected parties.</p><p>Nam3L3ss claims to have over 2.8 million records stolen from Amazon in particular, as well as half a million taken from life <a href="https://www.itpro.com/security/cyber-security/361099/cyber-security-and-insurance-companies-evolving-with-the-threat-of-ransomware">insurance company</a> MetLife. </p><p>The total number of records published in the initial release was nearly five million lines of data, affecting 25 large organizations.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x7QkfYAMgcrBoSUayNJ4aV" name="Living off The Land Attacks.jpg" caption="" alt="Living off The Land Attacks" src="https://cdn.mos.cms.futurecdn.net/x7QkfYAMgcrBoSUayNJ4aV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/living-off-the-land-attacks"><em>Hackers are using native system files against you</em></a></p></div></div><p>Nam3L3ss claimed that what they have released so far is less than 0.001% of the data they have in their possession, alleging they have 1,000 releases coming with data that has never been seen before.</p><p>The threat actor, who claims not to be a hacker, said the information was taken during the May 2023 <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack">MOVEit attacks</a>.</p><p>Hackers affiliated with the Cl0p threat collective exploited a zero-day vulnerability in Progress’s <a href="https://www.itpro.com/security/a-new-critical-moveit-vulnerability-is-being-exploited-by-hackers-heres-what-you-need-to-know">MOVEit file transfer protocol</a>, used by thousands of large organizations around the world.</p><p>The vulnerability, tracked as CVE-2023-34362, was an SQL injection flaw identified in the MOVEit Transfer web application that was leveraged by the threat actors to gain access to MOVEit Tranfer’s database.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Halloween special: Cybersecurity horror stories ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/halloween-special-cybersecurity-horror-stories</link>
                                                                            <description>
                            <![CDATA[ Join us for three terrifying tales sure to chill any IT professional to the core ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jbvxcfHWyvndcNdBoy9cfc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uaGVzyweTprBMoMMMtdtoR-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 01 Nov 2024 09:07:56 +0000</pubDate>                                                                                                                                <updated>Fri, 01 Nov 2024 15:09:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uaGVzyweTprBMoMMMtdtoR-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A skeletal hand typing on a keyboard with &quot;Cybersecurity horror stories&quot; superimposed on it]]></media:description>                                                            <media:text><![CDATA[A skeletal hand typing on a keyboard with &quot;Cybersecurity horror stories&quot; superimposed on it]]></media:text>
                                <media:title type="plain"><![CDATA[A skeletal hand typing on a keyboard with &quot;Cybersecurity horror stories&quot; superimposed on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uaGVzyweTprBMoMMMtdtoR-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="" height="200px" width="100%" data-lazy-priority="low" data-lazy-src="https://widget.spreaker.com/player?episode_id=62579532&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="x7QkfYAMgcrBoSUayNJ4aV" name="Living off The Land Attacks.jpg" caption="" alt="Living off The Land Attacks" src="https://cdn.mos.cms.futurecdn.net/x7QkfYAMgcrBoSUayNJ4aV.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/living-off-the-land-attacks"><em>Adversaries are using native system files against you</em></a></p></div></div><p>It’s All Hallows’ Day, and we’ve still got Halloween on the brain. It’s that time of year when we tell the scariest stories we can – and for those in tech, there are none scarier than that of major cybersecurity incidents.</p><p>In this episode, Rory and Jane talk to <a href="https://www.itpro.com/author/solomon-klappholz"><u>Solomon Klappholz</u></a>, <em>ITPro</em>’s cybersecurity reporter, about some of the spookiest cyber incidents of 2024 and what businesses can learn from these ghoulish tales.</p><p><strong>Footnotes</strong></p><ul><li><a href="https://www.itpro.com/software/global-it-outage-crowdstrike-falcon-believed-to-be-source-of-mass-disruption"><u>CrowdStrike CEO confirms update "defect" as the source of mass disruption</u></a></li><li><a href="https://www.itpro.com/software/millions-of-devices-bricked-and-dollar54-billion-in-losses-the-cost-of-the-crowdstrike-outage-continues-to-mount"><u>Millions of devices bricked and $5.4 billion in losses: The cost of the CrowdStrike outage continues to mount</u></a></li><li><a href="https://www.itpro.com/security/data-breaches/the-national-public-data-breach-exposed-nearly-three-billion-users-now-the-company-has-filed-for-bankruptcy"><u>The National Public Data breach exposed nearly three billion users – now the company has filed for bankruptcy</u></a></li><li><a href="https://www.itpro.com/security/data-breaches/national-public-data-breach-lawsuit-claims-nearly-three-billion-people-had-personal-data-exposed"><u>National Public Data breach: Lawsuit claims failed to protect billions of personal records</u></a></li><li><a href="https://www.itpro.com/security/data-breaches/23andmes-disastrous-data-breach-just-landed-it-a-regulatory-probe"><u>23andMe's disastrous data breach just landed it a regulatory probe</u></a></li><li><a href="https://www.itpro.com/security/data-breaches/23andme-risks-public-relations-disaster-as-it-blames-customers-for-data-breach"><u>23andMe data breach response has been a public relations disaster as it blames customers for data breach</u></a></li><li><a href="https://www.itpro.com/security/data-breaches/the-23andme-data-breach-is-getting-messier-by-the-day"><u>The 23andMe data breach is getting messier by the day</u></a></li><li><a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape"><u>World Economic Forum warns of growing ‘cyber insecurity’ amid heightened threat landscape</u></a></li></ul><p><strong>Subscribe</strong></p><ul><li><a href="https://apple.sjv.io/c/221109/473657/7613?subId1=itpro-gb-1243831151189624600&sharedId=itpro-gb&u=https%3A%2F%2Fpodcasts.apple.com%2Fgb%2Fpodcast%2Fthe-itpro-podcast%2Fid1483810154"><u>Subscribe to The IT Pro Podcast on Apple Podcasts</u></a></li><li><a href="https://open.spotify.com/show/7HpYehTy752KmtbwpOAgRZ"><u>Subscribe to The IT Pro Podcast on Spotify</u></a></li><li><a href="https://www.itpro.co.uk/newsletter-signup"><u>Subscribe to the IT Pro newsletter</u></a></li><li><a href="https://uk.linkedin.com/company/itpro-uk"><u>Join us on LinkedIn</u></a></li><li><a href="https://www.youtube.com/@itpro"><u>Follow us on YouTube</u></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 800,000 users exposed in Landmark Admin data breach ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/data-breaches/800-000-users-exposed-in-landmark-admin-data-breach</link>
                                                                            <description>
                            <![CDATA[ The hack is just the latest third party attack on an insurance firm, with attackers stealing huge amounts of personal data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qfUzmVAgJJ3TtS3we3KpDC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 30 Oct 2024 11:51:04 +0000</pubDate>                                                                                                                                <updated>Wed, 30 Oct 2024 14:45:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:description>                                                            <media:text><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Insurance administrative services company Landmark Admin is warning 800,000 people that their sensitive data has been exposed, following a <a href="https://www.itpro.com/security/cyber-attacks">cyber attack</a> earlier this year.</p><p>According to the firm's filing with the Attorney General of Maine, the breach involved an extremely broad range of personal data, including full names and addresses, Social Security numbers, tax identification numbers, drivers’ license numbers, and state-issued identification card numbers.</p><p>Similarly, passport numbers, bank account and routing numbers, medical information, health insurance policy numbers, dates of birth, and life and annuity policy information were all exposed in the incident. </p><p>The breach was discovered in May, and the company's systems were secured with the help of an external security firm until the attackers again gained access to Landmark's <a href="https://www.itpro.com/business-operations/30840/university-of-winchester-upgrades-it-network-for-predictive-maintenance">IT network</a> in June, accessing more sensitive information. </p><p>Once again, the company's systems were secured, with Landmark saying it's now tightened up <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> practices.</p><p>"As a result of the data breach, these individuals’ personal and highly sensitive information may be in the hands of cyber criminals who can place the information for sale on the dark web or use the information to perpetrate identity theft," said Murphy Law Firm, which is planning a class action lawsuit.</p><p>Several other law firms are considering the same.</p><p>Landmark is now contacting those whose data may have been leaked, offering them credit monitoring and identity theft protection services. </p><p>There's currently no indication of who was behind the attack, nor any information on ransom demands. </p><p>"The breach at Landmark Admin highlights a growing issue —third-party vendors are becoming easy targets for cyberattacks. This isn’t just a one-off; it’s part of a clear trend. As organizations rely more on outside partners, they expose themselves to more significant risks," said Akhil Mittal, senior security consulting manager at Black Duck. </p><p>"With personal and financial data now exposed, the immediate concern is identity theft, but the bigger issue is losing trust between insurers, their customers, and partners. Landmark’s security team needs to move quickly, not just by explaining what happened, but by actively helping partners strengthen security across the board."</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="LjWdHEMBU3LCLK4bVET7Rg" name="Understanding Least Privileges.jpg" caption="" alt="Understanding Least Privileges" src="https://cdn.mos.cms.futurecdn.net/LjWdHEMBU3LCLK4bVET7Rg.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: CyberFox)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/understanding-least-privileges"><em>Protect your company from ransomware attacks</em></a></p></div></div><p><a href="https://www.itpro.com/ransomware/34396/ex-white-house-cio-attacks-insurance-firms-for-fuelling-ransomware-industry">Insurance companies</a>, along with their partners or subsidiaries, represent a lucrative target for hackers thanks to the large amounts of highly-sensitive data that they hold.</p><p>Just last week, a third-party breach was reported by Brighthouse Life Insurance, for example, while insurance firm Globe Life reported that it's being <a href="https://www.itpro.com/security/ransomware/367624/the-rise-of-double-extortion-ransomware">extorted by hackers</a> after data on more than 5,000 people was stolen from a subsidiary.</p><p>Meanwhile, health insurance firm UnitedHealth has told the US Department of Health and Human Services Office for Civil Rights that the data breach it suffered earlier this year affected 100 million people.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>