Hawaiian Airlines experienced a cybersecurity breach affecting some of its IT systems but assured that flights are operating safely and on schedule, with ongoing investigations and system restoration efforts.
Aflac disclosed a cybersecurity breach likely caused by the Scattered Spider group, targeting insurance companies across the U.S., potentially exposing sensitive personal and health information. The company responded quickly, confirming no ransomware impact and continuing normal operations, while external experts investigate the incident.
A security breach at Xfinity, affecting nearly 36 million customers, has exposed personal data including usernames, passwords, and security questions. The breach was caused by a vulnerability in Citrix software, and unauthorized users gained access to Xfinity's internal systems between October 16 and October 19. Xfinity customers are advised to reset their usernames and passwords, use two-factor authentication, and change passwords for other accounts with the same credentials. The breach likely affected all Xfinity customers, and more information can be found on Xfinity's website.
VF Corp. has reported a cybersecurity breach in its systems that is expected to have a material impact on its business operations. The breach, which occurred on December 13, has disrupted the company's ability to fulfill online orders and resulted in the theft of personal data. VF Corp. is still assessing the potential financial impact of the incident. The company's stock fell 5.1% in premarket trading following the announcement.
A Russian cyber-extortion gang's hack of a file-transfer program called MOVEit has affected over 1 million people in Maine, potentially exposing their personal information such as Social Security numbers and dates of birth. The breach, which occurred in May, impacted various state agencies and industries including insurance, finance, education, health, and government. This is the latest in a string of cyber breaches in Maine, with over 3,000 entries in the Office of the Maine Attorney General's log of data breach notifications since June 2020. The average cost of a data breach has reached an all-time high of $4.5 million, with the healthcare industry reporting the most expensive breaches. Maine officials have taken measures to address the breach, including blocking internet access to the affected server and hiring external cybersecurity professionals.
McLaren Health Care has acknowledged that the ransomware attack on its computer network in August and September may have resulted in the leak of patient data on the dark web. The cyberattack, claimed by the BlackCat/AlphV gang, reportedly stole 6 terabytes of data, including personal information of 2.5 million patients. McLaren is currently investigating the extent of the data exposure and plans to notify affected individuals. The healthcare provider has also taken measures to strengthen its cybersecurity and ensure continuity of care. The claims made by the cybercriminals regarding a backdoor into McLaren's network have not been corroborated.
Chinese hackers, suspected to be state-backed, breached hundreds of public and private sector organizations globally, including nearly a third of government agencies, using a security hole in a popular email security appliance. The cybersecurity firm Mandiant identified the group as UNC4841 and said they engaged in espionage activity in support of the People’s Republic of China. The hackers sent emails containing malicious file attachments to gain access to targeted organizations’ devices and data. The breach impacted organizations in the Americas, Asia Pacific, and Europe, the Middle East, and Africa. Barracuda Networks’ Email Security Gateway was compromised, and the California company recommended fully replacing the appliances.
Chinese hackers, suspected to be state-backed, used a security hole in Barracuda Networks' Email Security Gateway to breach hundreds of public and private sector organizations globally, including nearly a third of government agencies. The hackers sent emails containing malicious file attachments to gain access to targeted organizations' devices and data. The majority of the impact was in the Americas, reflecting the geography of Barracuda's customer base. The breach was discovered in June, and Barracuda recommended fully replacing the appliances. The U.S. government has accused Beijing of being its principal cyberespionage threat.