Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Data Breach. Show all posts

Supreme Court to Hear Case Over 1.5 Lakh Medical Records Breach





The Supreme Court has issued notice on a petition seeking a Central Bureau of Investigation (CBI) probe into an alleged cyberattack that Vitraya Technologies claims resulted in the theft of medical, insurance and other sensitive personal information belonging to nearly 1.5 lakh Indian citizens.

A three-judge bench comprising Chief Justice of India Surya Kant and Justices Joymalya Bagchi and V Mohana agreed to examine the petition filed by Vitraya Technologies Pvt Ltd, a health-tech company that operates a technology platform for automating and settling health insurance claims.

The case places the alleged compromise of highly sensitive healthcare information alongside questions about the adequacy of the police investigation and the protection of informational privacy. The company has approached the court under Article 32 of the Constitution, arguing that the alleged breach has implications for the fundamental right to privacy protected under Article 21.

During the hearing, senior advocate K Parameshwar, appearing for Vitraya, told the court that the alleged intrusion affected data across six states and that the company had been approaching authorities since the incident was reported in 2025.

Parameshwar said Vitraya submitted its initial complaint in March 2025 but that an FIR was not registered until August 29, 2025. He also questioned why the case continued to name unknown persons despite the company claiming that it had supplied investigators with technical information concerning the suspected intrusion.

The counsel told the bench that Vitraya had also provided information concerning a server in Singapore to which the company's investigation allegedly traced medical records belonging to almost 1.5 lakh Indians.

The petition seeks transfer of the investigation to the CBI. In the alternative, Vitraya has asked the Supreme Court to order a court-monitored Special Investigation Team (SIT).


Alleged attack began with unauthorised access

According to the petition, Vitraya detected what it described as a coordinated cyberattack in February 2025.

The alleged activity included repeated brute-force login attempts against the company's systems, unauthorised access to its digital infrastructure, bulk downloading of confidential records and the extraction of sensitive customer information.

The data allegedly exposed in the incident includes medical records, health insurance claim information, Aadhaar-linked details and other personally identifiable information.

The combination of medical information with identity and insurance data makes the alleged incident particularly sensitive. Medical records can contain information about an individual's diagnoses, treatment history and health conditions, while Aadhaar-linked information can connect those records to an identifiable individual.

Vitraya's own platform is designed to handle this type of information. The company says its technology automates health insurance claims using artificial intelligence, machine learning, medical natural-language processing and blockchain-based smart contracts. It describes its platform as being used by more than 6,000 hospitals and says it processes approximately 10 million claims worth around $2 billion annually.

The company's technology infrastructure therefore sits within a data-intensive part of the healthcare and insurance ecosystem, where information can move between healthcare providers, insurers and technology platforms during the claims process.


Vitraya alleges attack was linked to rival companies

Following an internal forensic investigation, Vitraya claims that its security team identified suspicious IP addresses, server activity and other digital footprints that it says were associated with Remedinet Technologies Pvt Ltd and IHX Pvt Ltd.

The petition further alleges that these entities were connected to Bessemer Venture Partners and that the alleged activity involved Bessemer, Medi Assist, Perfios Software Solutions Pvt Ltd and other entities described by Vitraya as competitors.

These allegations have not been established by the Supreme Court. The companies named in the petition should not be treated as responsible for the breach unless an investigation establishes their involvement.

Vitraya says its forensic examination produced technical material that it subsequently supplied to investigators. The company claims this included server information, IP addresses, technical logs, details concerning the alleged actors and other documentary evidence.

The company approached Punjab's cybercrime authorities on March 5, 2025, according to the petition.

However, Vitraya alleges that its repeated representations and cooperation during the preliminary inquiry did not result in an FIR for almost six months.

The FIR was ultimately registered on August 29, 2025, at the Punjab State Cyber Crime Police Station in SAS Nagar. According to the petition, the case was registered under Sections 66 and 66B of the Information Technology Act and against unknown persons.

Under the IT Act, Section 66 addresses computer-related offences committed dishonestly or fraudulently, while Section 66B deals with dishonestly receiving or retaining stolen computer resources or communication devices while knowing, or having reason to believe, that they are stolen.

Vitraya has argued that the provisions used in the FIR do not adequately reflect the scale and complexity of the alleged incident. The company has also questioned why the FIR continued to identify the suspects as unknown despite the technical material it says had already been provided to police.


Company questions progress of investigation

The petition alleges that the investigation has not involved sufficient forensic examination or preservation of the digital evidence relevant to the alleged attack.

Vitraya claims that investigators have not undertaken substantial measures such as examining or seizing relevant digital infrastructure, preserving electronic evidence or conducting custodial interrogation of suspected individuals.

The company argues that these alleged shortcomings are particularly important because the incident involves systems and entities operating across multiple jurisdictions.

According to Vitraya, the alleged breach spans six states, involves multiple corporate entities and includes digital infrastructure located outside India. The company has specifically referred to a Singapore-based server where it alleges that the compromised medical information was transferred.

The cross-border element could complicate an investigation because digital evidence may be distributed across different jurisdictions, requiring investigators to establish where systems and data were located, identify the parties controlling those systems and preserve evidence before it can be deleted, altered or moved.

The company therefore argues that the investigation requires an agency with the technical capacity and jurisdictional reach to examine the alleged attack.


Privacy concerns form central part of petition

Vitraya has also framed the alleged breach as a constitutional privacy issue rather than solely a dispute between competing businesses.

The petition relies on the Supreme Court's 2017 judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, in which a nine-judge Constitution Bench recognised privacy as a fundamental right protected under Article 21. The court held that privacy is intrinsic to the protection of life and personal liberty.

That constitutional framework is relevant to a case involving medical information because the alleged data does not merely concern commercial records. It potentially connects individuals with information about their health, treatment and insurance claims.

The petition consequently argues that the alleged unauthorised disclosure of such information affects citizens' informational privacy and digital autonomy.


India's data protection framework adds another layer

The case also arrives as India moves toward implementing its newer personal-data protection regime.

The Digital Personal Data Protection Act, 2023 establishes a framework governing the processing of digital personal data and creates obligations for organisations handling such information. The Act also provides for a Data Protection Board of India and includes provisions addressing data-fiduciary obligations, individual rights, grievance redressal and penalties.

However, the timing matters. The DPDP framework is being implemented in phases. The government notified the DPDP Rules in November 2025, while several substantive provisions of the Act and Rules are scheduled to take effect 18 months after the notification.

The alleged Vitraya intrusion was identified in February 2025, before those later implementation stages. The investigation therefore cannot simply be described as a test of the fully operational DPDP regime. Instead, the case sits at the intersection of India's existing cybercrime laws, constitutional privacy protections and the country's transition toward a dedicated personal-data protection framework.

Separately, CERT-In's directions under the Information Technology Act identify unauthorised access to IT systems or data, data breaches and data leaks among cybersecurity incidents that covered organisations are required to report.


Supreme Court seeks response on proposed CBI investigation

The Supreme Court's immediate action is limited to issuing notice on the petition. The court has not made a finding that the alleged breach occurred in the manner claimed by Vitraya, nor has it established the involvement of the companies named in the petition.

The petitioner is asking the court to transfer the investigation to the CBI because it considers the existing police investigation inadequate.

Alternatively, Vitraya has proposed a court-monitored SIT involving agencies with relevant cybersecurity expertise, including the CBI and CERT-In.

The company's argument is that the combination of alleged cross-state activity, foreign-hosted infrastructure, sensitive medical information, multiple corporate entities and digital forensic evidence makes the case unsuitable for a routine investigation.

The Supreme Court's notice now places the investigation and the requested transfer before the respondents, including the Union government, the CBI and the Punjab government.

The case could therefore become an important test of how Indian authorities investigate alleged large-scale breaches involving healthcare data, cross-border infrastructure and competing corporate entities, particularly when the affected information includes medical records and government-linked identifiers.

For now, however, the allegations remain subject to investigation and judicial consideration.

Microsoft Copilot Flaws Could Expose User Data With One Click

 


Microsoft Copilot Personal contains three vulnerabilities that could allow an attacker to execute a malicious prompt with one click and exfiltrate data from connected applications, according to Varonis Threat Labs.

The researchers collectively named the flaws CoSnitch and reported them to Microsoft in December 2025. Microsoft patched the vulnerabilities on August 18, 2026, with the issue tracked as CVE-2026-24301. Varonis said it found no evidence of exploitation in the wild. The research concerns the consumer Copilot service at copilot.microsoft.com and does not establish that the same behavior affected Microsoft 365 Copilot.


Copilot Revealed Its Own Attack Path

Varonis discovered the vulnerability through what it calls "meta-hacking," repeatedly asking Copilot why a prompt could not execute without user interaction. After several refusals containing technical explanations, Copilot eventually disclosed an undocumented "autorun=1" URL parameter, including the conditions and safeguards associated with it.

Researchers constructed the URL as described and found that the supposedly disabled parameter still executed. They combined "autorun=1" with Copilot's existing "q" parameter, which pre-fills the prompt. While "q" alone requires user interaction, the combination automatically triggered the prompt when the page loaded.

Varonis said the prompt then continued executing even if the victim immediately closed the Copilot tab. Its earlier Reprompt research had also used "q" as a one-click Parameter-to-Prompt mechanism.


Existing Permissions Enable Data Theft

The first two CoSnitch flaws form the one-click exfiltration chain. The injected instruction operates with the same capabilities available to a legitimate user prompt and does not grant Copilot additional permissions.

Researchers demonstrated access to connected mail messages, subject lines and sender and recipient metadata; calendar titles, attendees, times and locations; Google Drive filenames and metadata summaries; previous Copilot conversations; and stored memory instructions and user-defined rules.

The retrieved information could be encoded, including with Base64, and transmitted through Copilot's built-in URL-fetching capability to an attacker-controlled webhook. Varonis said the resulting request could resemble Copilot's ordinary web retrieval traffic, potentially making network-level detection difficult.


Separate Memory Poisoning Path

The third vulnerability involves indirect prompt injection through web summarization. A malicious webpage could contain attacker-controlled instructions that Copilot processed and wrote into its persistent memory.

Varonis said such injected memories could survive password changes, session revocation and device re-enrollment until manually removed. The modification reportedly generated no process, file or network activity that conventional security tooling would necessarily flag, although the change remained visible in Copilot's memory interface.

The finding follows earlier Microsoft 365 Copilot memory research by Håkon Måløy and Johann Rehberger. Microsoft has separately said M365 Copilot applies sanitization and prompt-injection checks to memory writes, performs Task Adherence checks on explicit memory updates, and records those changes for security monitoring through audit data and the "MemoryUpdated" field.

Varonis recommends reviewing connected applications, disconnecting unnecessary services, monitoring AI assistants as privileged systems and exercising caution with links that open AI assistants.

The disclosure follows Varonis's RovoBlast research, which identified another one-click attack involving Atlassian's Rovo assistant. Together, the findings demonstrate how URL handling, authorized application access, external content and persistent AI memory can combine into an attack chain without directly compromising the victim's underlying accounts.

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

 

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability, CVE-2026-12569, affecting PTC Windchill. 

According to the researchers, the attackers did not use a traditional web shell to gain persistent access to the targeted servers. Instead, they used a custom component that demonstrated an in-depth understanding of the target application’s internal API, database schema, keystore, and file-vault structure. ReliaQuest notes that the discovered resource is an application-specific variation of the Clop ransomware group’s known mass exploitation framework. The web shell was linked to the Clop ransomware group because of extortion e-mails sent by the threat actors using the e-mail addresses associated with the data-leakage web site operated by Clop. 

In addition, the researchers identified X-windchill-req headers used by the web shell, which were also used by the Clop ransomware group in the past, as well as similar tactics, techniques, and procedures (TTPs). Earlier this year, Clop ransomware group’s infrastructure was found to target enterprise business software solutions such as Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. This campaign, which affected the MOVEit Transfer application, compromised more than 2,770 organizations worldwide. 

The web shell is implemented as JavaServer Pages (JSP), which directly imports the PTC Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, giving the threat actors’ access to PTC Windchill’s native functions, including the database, encrypted credentials decryption, and locating files stored in the application’s vaults. The web shell’s command execution capability was established using the custom protocol that utilizes the HTTP X-windchill-req header. 

Overall, the custom component allowed the attackers to achieve multiple malicious objectives, including Windchill secrets and configuration data theft, file vault discovery and enumeration, directory listing, file retrieval and deletion, executing additional Java classes, and identifying the server’s operating system. Besides that, ReliaQuest reports that the web shell’s implementation contains the Windchill vault enumeration code that queries multiple Windchill database tables, namely ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem. 

The PTC released a set of security updates to address CVE-2026-12569 on June 17. Additionally, the vulnerability was included in the CISA’s Known Exploited Vulnerabilities catalog earlier this week after the PTC reported active exploitation attempts in the wild. Ransom-ISAC confirmed that ransomware group Clop was behind the attacks by sending extortion emails to the employees of the targeted organizations. ReliaQuest recommends that all the JSP files found in the PTC Windchill directories should be investigated for any suspicious content and that the researchers should look for the X-windchill-req string. 

Moreover, the organizations that determined that their Windchill servers were compromised by the ransomware group should change the LDAP manager’s password and other user credentials because they are considered insecure and may have been leaked.

Amgen Data Breach Exposes Patient Health and Proprietary Cloud Data

 

Amgen has disclosed a serious cloud-related data breach that exposed patient health information and proprietary company data, highlighting how third-party cloud services can become a weak point even for large biopharmaceutical firms. The company said it detected unauthorized activity in July 2026 and immediately activated its cybersecurity response plan, contained the incident, and brought in independent forensic experts to investigate. 

According to Amgen’s filing, attackers exfiltrated data from cloud environments operated by third-party service providers. The stolen information reportedly included proprietary data, protected health information, and other records, while the company continues to determine whether confidential business information, intellectual property, research and development data, or additional patient data was also accessed. 

Amgen has not identified which cloud providers were involved, how the compromise happened, or whether a known threat actor was responsible. It has also not disclosed how many people may be affected, but said the incident was considered material on July 29 after reviewing the volume of impacted files and the possibility that sensitive information was among them. 

The company said it does not currently believe the breach is likely to materially affect its financial condition or operating results, and it has not seen an impact on products, manufacturing, financial reporting systems, or its ability to meet patient needs. Even so, the exposure of protected health information creates long-term privacy and compliance concerns, especially if personal medical or insurance details were included in the stolen files. 

Amgen is still working with third-party cybersecurity experts and reviewing legal and regulatory notification requirements, including obligations under health privacy rules. The case is another reminder that cloud security is only as strong as the controls, monitoring, and vendor oversight behind it, and that incidents involving patient data can carry consequences long after the initial breach is contained.

RingCentral Breach Exposes Personal Data of 1.6 Million Accounts


 

An attack on RingCentral, which was targeted at social engineering, has led to a data breach that could have exposed personal information of around 1.6 million individuals. In July, RingCentral detected the unauthorized activity during a campaign. The company said it immediately responded to the incident and launched an investigation with the assistance of an external forensic firm in order to contain the unauthorized activity. 

In light of the remediation measures implemented, RingCentral has not detected any further unauthorized activity. In addition, RingCentral clarified that only a limited number of its customers were affected by the incident and that those who were potentially affected were contacted directly. Furthermore, the company clarified that its services remain operational, and that its core platform was unharmed. 

Despite the lack of identification of the threat actor by the company, the ShinyHunters extortion group reportedly listed RingCentral on its Tor-based leak site in late July. As a result of the group's claim that they obtained over 623GB of data, there is further concern about the size of the attack. After investigating the leaked data, Have I Been Pwned confirmed that the dataset contains information associated with approximately 1.6 million accounts, including names, email addresses, telephone numbers, and physical addresses. 

The disclosure supports ShinyHunters' claims, even though RingCentral has not publicly attributed the incident to the group or provided details concerning how the attackers gained access to their system. A broader pattern of data theft attacks has been claimed by ShinyHunters against customers of major cloud and SaaS providers, including Salesforce and Snowflake, as well as the incident described above. This group has targeted third-party platforms and integrations increasingly, using stolen corporate data to extort companies. 

A recent lawsuit against Oracle PeopleSoft underscores the extent and persistence of the data theft operations of the organization. It has been possible for independent researchers to assess the scope of the exposure after publishing the 280GB archive. Has I Been Pwned reported approximately 1.6 million unique email addresses in the leaked data, along with names, telephone numbers, and physical addresses. 

A RingCentral representative has not independently verified the attacker's claims or disclosed the number of people affected. The incident also illustrates the effectiveness of voice-based social engineering, a strategy increasingly associated with ShinyHunters. Threat actors conduct these attacks by impersonating IT personnel and leading employees to a convincing login page with the intent of capturing passwords and authentication codes. It is possible that conventional one-time-password MFA will not be sufficient to prevent account compromise due to the attack's reliance on manipulating the employee rather than breaking the underlying security technology. 

As a result, security experts are increasingly recommending phishing-resistant methods, such as FIDO2 passkeys. These passkeys bind authentication to a legitimate website, preventing credentials from being regenerated through a fraudulent website. 

The details of the authentication method used by the compromised account have not been disclosed, nor have any controls been implemented to prevent phishing attacks. It is imperative to note that exposing names, phone numbers and physical addresses poses a risk beyond the initial compromise. These disclosures can provide attackers with sufficient context to carry out further impersonations and phishing attempts in a convincing manner. 

ShinyHunters has continued to focus on data theft and extortion rather than traditional ransomware, as demonstrated by the RingCentral incident, which illustrates how a single successful social engineering attack can lead to a much larger privacy and security issue as it progresses. 

The RingCentral incident has raised several questions, primarily regarding the extent of the exposure and the means by which the accounts were compromised. Have I Been Pwned has identified approximately 1.6 million email addresses in the leaked dataset, whereas RingCentral has described the customer base as limited. 

To determine the full impact of this incident, it is critical to reconcile those figures, along with more information about the compromised accounts, in order to determine the full extent. In organizations using RingCentral or similar cloud communication platforms, it is critical to establish strong defenses against social engineering at the earliest opportunity. During security awareness training, attention should be paid to suspicious calls, credential-harvesting websites, and requests for authentication codes. 

Organizations handling sensitive or regulated information should assess notification and compliance requirements for phishing attacks, multiple factor authentication, credential resets for potentially compromised accounts, and monitoring for follow-up phishing attacks and business email compromises. A wider question is raised by the incident about security at the intersection of technology and individuals. 

Even organizations with well-established security controls can be exposed if an attacker convinces an employee to bypass these controls. The breach thus serves as a reminder to RingCentral customers that safeguarding communication systems requires not only strong technical controls, but also preparation for social engineering tactics that are becoming increasingly convincing in order to target employees.

Trezor Data Breach Exposes Personal Information of Nearly 14,000 Customers

 

Hardware cryptocurrency wallet maker Trezor has disclosed a data breach involving the personal information of nearly 14,000 customers, after an unauthorized party gained access to data held by its third-party fulfillment provider, ShipMonk.

Trezor said its own infrastructure was not compromised and that the incident was discovered after the company was informed of the attack on August 10. The affected customers are located in the US, UK, Sweden, Colombia, Brazil, Italy and Portugal and placed orders between May 10 and August 8.

According to Trezor, the breach exposed the names, phone numbers, email addresses and shipping addresses of 11,742 customers. Information belonging to another 1,947 customers included their names, cities and email addresses. The data had been provided to ShipMonk solely to facilitate order fulfillment and delivery.

“We’re extremely sorry to inform our community that customer personal information, including full names, phone numbers, email addresses, and shipping addresses, has been accessed by an unauthorized actor during this breach,” Trezor said in its security notice.

The company attributed the limited scope of the exposure to its 90-day data retention policy, which it said is also followed by its fulfillment partners. However, Trezor warned that older orders may have been accessible for some of the customers whose information was partially exposed.

Trezor stressed that the incident did not affect its internal systems or the security of its hardware wallets. “To be clear, our systems were not compromised, and your Trezor device is secure, but the affected customers might be targeted by more sophisticated phishing attempts,” the company said.

All customers believed to be affected have been contacted directly by email. Trezor urged them to remain cautious of unexpected messages, particularly those asking for personal details, cryptocurrency information or immediate action.

The company is working with ShipMonk to establish when the compromise occurred and determine the complete extent of the incident.

Reports indicate that ShipMonk informed customers that the attackers gained access to its systems by exploiting a vulnerability in Metabase, a data analytics platform. The incident may be connected to a recently patched SQL injection zero-day affecting Metabase.

The cybercrime group ShinyHunters has also claimed responsibility for an attack on Metabase and subsequently published data it alleged was stolen from the analytics provider. However, the connection between that incident and the ShipMonk breach has not been independently established.

ShipMonk has not publicly confirmed the breach. It also remains unclear whether other organizations or individuals were affected, how much information may have been accessed, and who was ultimately responsible for the attack.

Hackers Steal 607,000 Records in Cyber-Attack on UK Department for Education

 



Hackers have stolen around 607,000 records from England's Department for Education (DfE) after compromising systems used to handle enquiries and administer international education funding.

The department confirmed the cyber incident after attackers accessed data held through the DfE's online help desk and the portal supporting the Turing Scheme. The compromised information includes telephone numbers and email addresses associated with individuals and organisations that had interacted with the department.

Reports have also identified names and job titles among the exposed information, including details belonging to school leaders, university staff and government officials. However, the DfE said the affected information was limited to customer-service contact details and that bank details and other sensitive information were not accessed.

The department has stressed that the figure of 607,000 refers to records rather than the number of individuals affected. A single person or organisation may therefore account for multiple records across the affected systems.


Social Engineering Reportedly Used Against DfE Helpdesk

The breach reportedly involved a social-engineering attack against an external-facing DfE helpdesk used by education-sector organisations and local authorities.

Computer Weekly reported that the attackers targeted the department's helpdesk and obtained more than 600,000 records containing personally identifiable information, while the affected systems were taken offline as the department investigated the incident. The Times also reported that it had verified the authenticity of some of the leaked information.

The incident illustrates why customer-facing systems can represent an attractive target. Helpdesks routinely process legitimate requests from large numbers of users and may contain historical enquiries and account-linked information. If an attacker can manipulate a support process or gain access to an account with sufficient privileges, information held outside an organisation's core systems can become exposed.

The DfE has not publicly disclosed a complete technical account of how the attackers gained access or which specific vulnerability was exploited. It would therefore be premature to attribute the breach to a particular software flaw or compromised credential without further evidence.

A group calling itself ExfilSquad has claimed responsibility for the attack and has reportedly published or advertised stolen information online. The group's claims should be treated as claims by the alleged attackers, although multiple reports have examined samples of the data and reported that some information was authentic.


DfE Moves to Contain the Incident

The DfE said it acted quickly after identifying the incident and has been working with the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA) to establish what happened and assess the impact.

The department has also referred itself to the Information Commissioner's Office (ICO), the UK's data protection regulator.

A DfE spokesperson said the department had "robust processes" to protect information and had taken swift action to contain the incident. The department maintained that the information involved was restricted to customer-service contact details and that no other data had been accessed.

The NCA separately confirmed that it was aware of the incident and was working with partners to understand the circumstances and its impact.

The DfE has also temporarily affected the operation of the services involved while remediation work is carried out. Reports said the department switched to telephone support while the affected systems were being addressed, with normal operation expected to resume after the disruption.

The department has assessed the data-protection risk to affected individuals as low. However, the exposure of professional contact information can still create opportunities for follow-on attacks, particularly phishing and impersonation campaigns that use legitimate names, job titles, organisations or previous interactions to make fraudulent communications appear credible.


Education Sector Continues Being Prime Target

The DfE breach comes as education organisations across the UK continue to report high levels of cyber incidents.

The latest UK government's Cyber Security Breaches Survey 2025/26 found that 49% of primary schools, 73% of secondary schools, 88% of further-education colleges and 98% of higher-education institutions had identified a breach or cyber attack during the previous 12 months. The comparable figure for UK businesses was 43%.

The frequency of attacks was also high among colleges and universities. Around 24% of further-education colleges and 29% of higher-education institutions reported experiencing a breach or attack at least weekly. The survey found that 14% of primary schools and 20% of secondary schools experienced attacks at least weekly.

Phishing remained the dominant threat. Among institutions that had identified a breach or attack, 90% of primary schools and 96% of secondary schools reported phishing incidents. The same figure was 96% for further- and higher-education institutions combined.

The government survey also identified higher levels of other attack types across further and higher education. These included impersonation, reported by 79% of affected further- and higher-education institutions, viruses, spyware or malware at 51%, and denial-of-service attacks at 49%. Unauthorised access to files or networks by staff was reported by 29%, while 23% reported unauthorised access by students.

The consequences extend beyond the initial compromise. Almost half, or 49%, of further- and higher-education institutions that identified a breach or attack reported at least one negative outcome for their systems. Compromised accounts or systems being used for illicit purposes accounted for 23%, while 16% reported websites, applications or online services being slowed or taken down and 14% reported losing access to files or networks.


Contact Data Can Become a Launchpad for Further Attacks

Although the DfE maintains that highly sensitive information was not accessed, the exposed records still have security implications.

Names, job titles, work email addresses and telephone numbers can provide attackers with the information required to make subsequent phishing or impersonation attempts appear legitimate. A message addressed to a known employee, referencing their role or organisation, can be considerably more convincing than an unsolicited generic email.

This risk is particularly relevant in education, where senior school leaders, university staff and government officials may have access to wider organisational systems or sensitive information.

The latest government survey indicates that impersonation is already a recurring problem in the sector. Among further- and higher-education institutions that identified breaches or attacks, 79% reported attempts involving people impersonating their organisation or staff.

The DfE incident therefore demonstrates that the consequences of a data breach do not necessarily end when the initial intrusion is contained. Exposed contact information can potentially become useful in later social-engineering campaigns, while disruption to public-facing services can continue during investigation and recovery.

For organisations handling large volumes of education-sector data, securing customer support infrastructure is therefore part of protecting the wider attack surface. Access controls, strong identity verification, monitoring and rapid incident response can limit how far an attacker can move after compromising an externally accessible service.

The DfE investigation remains ongoing, with the department working alongside the NCSC and NCA and having notified the ICO. The full circumstances of the intrusion, including how the attackers gained access and the precise extent of the exposed information, are expected to become clearer as the investigation progresses.

Tanaka Emerges as Leading Data Leak Broker as Stolen Information Fuels Cybercrime

 

Ransomware attacks are undoubtedly one of the most notorious security threats today. Yet it seems that information itself has become a very popular target among cybercriminals. Particularly, the threat actor called Tanaka has appeared to be the most successful data dealer during the first half of 2026, according to the research conducted by Cyble. Overall, 367 confirmed cases of corporate data leaks or breaches happened worldwide during the first half of 2026, the experts from Cyble have found. 

While the activity of Tanaka appeared to be less prominent than that of many well-known ransomware groups, he has been the most active data dealer according to Cyble research. His activity has resulted in 25 leak posts, which is more than double than the number of posts of other famous data-leak organizations. The threat actor has been targeting organizations in various fields, pursuing different goals. While the Banking, Financial Services and Insurance sector remained the most attractive for criminals with 38 data breach incidents recorded, governments and technology companies have also been frequently targeted by Tanaka. 

It implies that data theft is no more limited by regional or economic factors and can happen to organizations of any size or any industry. In particular, Tanaka has been very active in North America, where 7 leak posts related to the criminal have been discovered this year. Meanwhile, Europe and the UK have witnessed 6 leak posts related to Tanaka, as well. In these regions, financial services, telecom, and retail companies have experienced the most significant challenges, as customer and financial data of these organizations are highly attractive to data prospectors. 

In general, data prospecting has become a significant threat to organizations worldwide, as there are now more opportunities to benefit from the data belonging to other organizations. It is a part of the ransomware attack chain, as ransomware criminals can use the data belonging to the victim as leverage to demand more significant ransoms. However, data extortion is not the only way to monetize data theft, as leaked databases can be further sold on dark web forums and marketplaces. 

In addition, the stolen data can be used for extortion, reconnaissance, and other nefarious purposes. It is necessary for companies to realize that the detection of one’s data being sold or showcased on underground forums should be treated as a serious security incident. It can be a sign of the potential ransomware attack, which should be responded to accordingly. Monitoring the dark web for signs of reconnaissance activities is one of the essential aspects of cybersecurity, which is why professionals may want to consider detecting their organization’s potential exposure to ransomware attackers.

Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack

Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the company's systems and exfiltrate corporate information from the systems of three employees. The clothing giant disclosed the incident in its filing with the U.S Securities and Exchange Commission (SEC). According to the SEC's investigation, certain corporate information was accessed and exfiltrated during the attack. 

Several employees were targeted by the attackers through social engineering, which gave them access to their systems without their consent. Levi Strauss has not disclosed the precise social engineering technique used by the threat actor, or whether the threat actor made any extortion demands, but this incident specifically affected three company-provided computers. Levi Strauss stated that its security teams responded quickly to contain and terminate the unauthorized access. 

According to Levi Strauss' preliminary investigation, it is not believed that customer information has been stolen. In addition, the company stated that the incident did not disrupt operations for the company. Levi Strauss stated in its SEC filing that, based on preliminary findings from the Company's investigation, it believes that some corporate information has been accessed and exfiltrated as a result of the incident. Levi Strauss expects the incident to have no material impact on the company's financial position or business based on its preliminary findings so far. Levi Strauss will provide additional notifications as additional information becomes available. 

The Levi Strauss & Co. (Levi’s) apparel company, one of the world's most recognizable companies, employs approximately 19,000 people and operates over 3,300 stores. The products are also available through third parties and online platforms. Levi Strauss has not identified the threat actor responsible for the intrusion or revealed whether the company received any extortion demands from the attacker. Unconfirmed reports suggest that the hacker may have been associated with UNC6671, a hacking group that has been associated with recent voice phishing attacks. 

According to Levi Strauss, the attribution has not been confirmed, and it remains unclear what tactics were employed in the attack. There is a general indication that the Levi Strauss incident occurred at the same time as a broader wave of voice phishing and social engineering attacks targeting major organizations. 

According to Google and other internet intelligence sources consulted by Reuters, ransom-seeking attackers were attempting to compromise victims through phone calls in recent weeks by targeting dozens of prominent financial institutions and other organizations in the United States. Levi Strauss was among more than 200 companies targeted with digital traps over the course of five weeks with the same intelligence. Levi Strauss has not confirmed the possible connection, and the attackers, the specific corporate information stolen, and the method of targeting employees are still under investigation. 

Despite the company's assertion that customer information was not compromised, the incident demonstrates the continuing threat posed by social engineering and phishing attacks. Organizations continue to be vulnerable when attackers can manipulate employees into providing access to corporate systems and information. 

In response to the attackers' attempt to gain access to the compromised computers, the company immediately responded and contained them. Levi Strauss has not reported any interruption to its business operations and does not believe the incident has, or is reasonably likely to have, a material impact on its financial or business position at this time. 

Despite the breach, Levi Strauss has not reported any operational impacts and continues to investigate the incident. Levi Strauss' incident illustrates the growing threat of voice-phishing and social engineering attacks against large corporations. Although the company has indicated that the customer data was not compromised, the ongoing investigation emphasizes the need for employee awareness, access controls, and rapid response to targeted cyberattacks to limit their impact.

Bank of Baroda Data Breach: What We Know About the Alleged 1TB Dark Web Leak

 



Bank of Baroda has confirmed a cybersecurity incident involving a compromised employee email account after reports emerged that nearly 1TB of data allegedly linked to the state-owned lender had been published on the Dark Web.

The bank said the compromised account resulted in unauthorised access to certain data, but clarified that its core banking systems were not accessed and continue to remain secure. It said the incident was identified promptly, containment measures were implemented, and a comprehensive forensic investigation has been launched in coordination with relevant authorities.

The confirmation followed reports from the X account DailyDarkWeb and cybersecurity researcher Srikanth Lakshmanan, founder of CashlessConsumer, who flagged an alleged large-scale data dump connected to Bank of Baroda.

According to the claims, the dataset contains personal and corporate banking records, including savings and current account information, loan records, NetBanking users, NRI and corporate banking services, customer-support documents, and records linked to branches and ATMs. Reports from researchers also said the material included customer details, identification documents and internal audit records.

Samples and download links were reportedly shared alongside the threat actor's claim of possessing approximately 1TB of data.

However, the size of the alleged dataset has not been independently established by Bank of Baroda. Reuters reported that the Dark Web listing was advertised as a cache exceeding 700GB based on metadata analysis conducted by Lakshmanan. The number of customers whose information may have been exposed also remains unknown.

This distinction is important. The appearance of a large archive online does not, by itself, establish that every file originated from Bank of Baroda or that the entire advertised volume was successfully exfiltrated from the bank.


What allegedly appeared in the data dump?

The initial claims described a wide range of banking information. This reportedly included savings and current account records, loan-related documents, NetBanking information, NRI and corporate banking records, customer-support material, and branch and ATM data.

Other reports said samples contained highly sensitive information such as Aadhaar details, customer names, loan documents and other identity-related records. Some reports citing the claims placed the number of customer application forms potentially involved between 100,000 and 300,000. These figures remain allegations and have not been confirmed by Bank of Baroda.

Lakshmanan also shared screenshots that he said showed the root folder of the alleged data dump and reported that the download link was active. He described the incident as a "cyber disaster" and called for the Reserve Bank of India (RBI) and National Payments Corporation of India (NPCI) to consider disconnecting the bank's systems while the extent of the compromise was investigated.

At the time of those warnings, the source and method of the alleged data theft were unclear.

Bank of Baroda's subsequent statement has now provided an important piece of that picture.


Employee email account was the confirmed entry point

According to the bank, the confirmed incident involved the compromise of an employee's email account. The account was then used to obtain unauthorised access to certain data.

Bank of Baroda has not disclosed how the email account was compromised, what specific files were accessed, or whether all of the data advertised on the Dark Web originated through that account.

The lender has, however, clearly stated that its core banking systems were not accessed and remain secure.

That distinction matters because compromising an employee's email account is not the same as compromising the systems that process customer transactions.

At the same time, an email account inside a large financial institution can provide access to highly sensitive material. Depending on the employee's role and permissions, an account may contain customer correspondence, loan documents, identity records, internal reports or links to shared resources.

The incident therefore demonstrates how an attacker may be able to obtain valuable financial information without directly breaching the core platform responsible for banking transactions.


Customer risk extends beyond stolen funds

There is currently no public evidence that the alleged incident allowed attackers to directly access customer balances or manipulate transactions. Bank of Baroda has specifically said that its core banking systems were not accessed.

The potential exposure of personal and financial records nevertheless creates a separate risk.

Information such as customer names, identity documents, account-related details and loan records could give criminals material for highly targeted phishing and impersonation attempts. A scammer with genuine information about a customer's banking relationship can make fraudulent calls, emails or messages appear far more credible.

Customers should therefore be particularly cautious of communications claiming to originate from Bank of Baroda and requesting OTPs, passwords, PINs, card information or remote access to devices.

The reported leak should not automatically be interpreted as evidence that customer funds have been compromised. The more immediate concern, if the exposed records are genuine, is the possibility of follow-on fraud using information that customers would normally expect their bank to protect.


Forensic investigation now underway

Bank of Baroda said it has initiated a comprehensive forensic investigation to establish the nature and extent of the incident. The bank also said it is working with relevant authorities in accordance with applicable regulatory requirements.

Several key questions remain unanswered.

Investigators will need to determine how the employee's email account was compromised, what information was accessible through it, how much data was actually accessed or exfiltrated, and whether the Dark Web archive corresponds to the confirmed incident.

The investigation will also need to establish how many customers, if any, were affected.

The incident has already generated financial implications for the lender. The Economic Times reported that Bank of Baroda notified a preliminary cyber-insurance claim under a programme with total coverage of approximately ₹750 crore, with National Insurance Company serving as the lead insurer. The notification is an intimation of loss while the forensic investigation continues and does not represent a confirmed ₹750 crore loss.

The financial consequences of a data breach can extend beyond direct theft. Forensic investigations, remediation, legal costs, regulatory responses, customer support and other incident-response expenses can all contribute to the eventual cost.


Regulatory questions remain

The incident also places renewed attention on cybersecurity controls within India's banking sector.

CERT-In's directions under Section 70B of the Information Technology Act establish requirements for information-security practices, incident response and cyber-incident reporting.

Bank of Baroda has said it is cooperating with relevant authorities, although the public details of its regulatory notifications have not been disclosed.

For now, the most important distinction is between what has been confirmed and what remains alleged.

Bank of Baroda has confirmed that an employee's email account was compromised and that the incident resulted in unauthorised access to certain data. It has also confirmed that its core banking systems were not accessed.

The claim that approximately 1TB of Bank of Baroda information was leaked, the precise contents of the Dark Web archive, and the number of customers potentially affected remain subject to investigation.

What began as an alarming Dark Web claim has therefore evolved into a confirmed security incident with an unresolved scope. The forensic investigation will determine whether the reported hundreds of gigabytes of banking information represent the full extent of the compromise, a smaller subset of genuine Bank of Baroda data, or a mixture of both.

ShinyHunters Data Leaks Fuel $2,000 Sextortion Email Scam

 

Cybercriminals are exploiting email addresses exposed in previous ShinyHunters data leaks to conduct a new sextortion campaign demanding $2,000 in Bitcoin. The fraudulent messages falsely claim that ShinyHunters compromised victims’ phones and computers, accessed their cameras and microphones, and recorded them visiting adult websites. However, the campaign appears to involve unrelated scammers who downloaded previously leaked information and are using it to make their threats appear credible. 

The emails reportedly use random sender addresses and names such as “ShinyHunters” or “You’ve Been HACKED.” Their subject line commonly reads “Information about your online security.” In the messages, attackers mention companies whose databases were previously exposed, including Amtrak, Hallmark, Substack, Betterment, CarGurus, ADT, Panera Bread, and McGraw Hill. By identifying a company connected to the recipient’s email address, scammers attempt to create the impression that they specifically targeted the victim. 

The scam messages claim that attackers installed malware capable of accessing a victim’s microphone, camera, keyboard, photographs, browsing history, conversations, and contact list. They then threaten to send allegedly recorded intimate videos to the recipient’s family, friends, colleagues, and business contacts unless payment is made within 48 hours. The emails also instruct recipients not to contact law enforcement, reply, or reset their devices, claiming that stolen data is stored on remote servers. These warnings are intimidation tactics rather than evidence of a genuine device compromise. 

According to the report, the campaign may have begun in April, with victims and organizations sharing similar warnings online. Betterment acknowledged that some customers received threatening emails and described them as a common extortion scam. The company emphasized that knowing someone’s email address does not give criminals the ability to install malware or access that person’s device. It advised recipients not to reply, pay, click links, or open attachments, while asking anyone who interacted with the message to contact its fraud team. 

People receiving these emails should remain calm and avoid paying the Bitcoin demand, because payment does not guarantee that scammers will stop contacting them. Recipients should preserve the message as evidence, report it to their email provider and relevant cybercrime authorities, then delete it after checking for suspicious account activity. They should also use unique passwords, enable multifactor authentication, update devices, and monitor accounts associated with the exposed email address. The campaign demonstrates how data stolen in one breach can later be reused by unrelated criminals to support convincing but false threats.

South Korean Military Medical System Breached, 1.15 Million Records at Risk

 

South Korea’s military has reported unauthorized access to a medical imaging system containing sensitive records linked to approximately 1.15 million people. The incident involved the Armed Forces Medical Command’s mobile Picture Archiving and Communication System, commonly known as PACS, which enables medical staff to view X-rays, CT scans and MRI images. Although investigators have not confirmed that information was stolen, the breach has raised serious concerns about the security of military healthcare data. 

According to the Defense Ministry, the intrusion took place between November and December 2025 and may have involved approximately 8 gigabytes of medical information. This estimate was based on network traffic, rather than a confirmed list of downloaded files. Officials said the amount could be equivalent to nearly 1,000 X-ray images, but they have not identified the exact records that may have been viewed or accessed. 

The potentially exposed information includes patients’ names, sex, ages, medical imaging dates and diagnostic images. The system was used by six military hospitals located in Goyang, Yangju, Pocheon, Gangneung, Guri and Daegu. However, authorities emphasized that the figure of 1.15 million represents all individuals whose records were stored in the system, not the number of people whose information was definitely accessed or copied. 

The breach was discovered in April during a security inspection led by the Defense Counterintelligence Command. In June, the Defense Ministry, Defense Cyber Command, Defense Counterintelligence Command and Armed Forces Medical Command formed a joint investigation team to determine how the unauthorized access occurred and assess its full impact. Investigators reportedly found that an open network communications port allowed the intruder to enter the system, and that the port remained exposed from November 2025 until March 2026. 

The military suspended the medical imaging system immediately after identifying the incident. Officials have not disclosed the identity or origin of the intruder, nor have they confirmed whether any medical information was transferred outside the network. The case highlights the risks created by exposed network ports and insufficient access controls, particularly in systems containing health and military data. South Korea’s Defense Ministry said it would correct the identified weaknesses and strengthen cybersecurity measures to prevent similar incidents in the future.

Chick-fil-A Warns Customers After Credential Stuffing Attack Compromises User Accounts

 

Chick-fil-A notifies customer about personal information exposure after data breach occurred due to credential stuffing attack Chick-fil-A company has announced that personal and account information about some of its customers may have been exposed due to a data breach. This breach occurred through the use of credential stuffing, which is not a vulnerability within the corporation’s website or mobile application.

As explained in the company note to customers, unauthorized access attempts came from bad actors using credentials stolen elsewhere. The company discovered unauthorized access attempts to customer accounts after noticing anomalous activity in the login database, and the phishing campaign occurred between June 17-19, 2026, targeting Chick-fil-A One loyalty program accounts. The corporation concluded its investigation on July 13 th and established that attackers had used compromised credentials to access the account information of some customers. 

The information available to bad actors and potentially at risk of being misused varies depending on the customer’s account. It may include names, contact information, mailing addresses, phone numbers, dates of birth, and Chick-fil-A One account information like ID or QR code and mobile payment credentials. Moreover, attackers may have gained access to reward balances, gift card balances, and the last four digits of payment cards. Although the corporation has not revealed the number of affected clients, the number exceeds several thousand. 

According to the documents filed with the state, 2,182 Texas residents and 39 Massachusetts residents were impacted by the breach. However, there are also other states affected, as notifications to state attorney generals in charge of consumer protection have also been filed, including the District of Columbia. After discovering the issue, the corporation remediated the security risks and notified the affected clients. 

Moreover, Chick-fil-A took measures to enhance account security for all customers, including allowing password reset, account logout, and removing payment methods in the application. Some customers also received bonus points on their accounts as compensation for the issues experienced. Chick-fil-A corporation acknowledges the concern caused by the data breach and assures clients that it takes customer account security seriously. Moreover, the company has recommended that customers change passwords to strong and unique words or phrases not used for other accounts. 

Credential stuffing works only when the same or similar passwords are used across different accounts, so changing them to unique ones decreases the chances of experiencing another breach. Chick-fil-A data breach demonstrates once more that it is crucial to make sure that each online account, including email, banking, and social media accounts, uses a unique and strong password. 

If one suspects that an account may have been compromised, it should be changed to a strong password immediately. Also, it is essential to use multi-factor authentication when available and to monitor account activity regularly for unauthorized transactions or unauthorized access attempts.

Hugging Face Breach Raises Concerns Over AI-Driven Attacks

 



Hugging Face is investigating a security incident after its production infrastructure was compromised in an intrusion the company says involved an autonomous AI agent, raising fresh concerns about how artificial intelligence could reshape offensive cyber operations.

In a security disclosure published on July 16, the open-source AI platform said the attack leveraged an autonomous agent framework built on top of an agentic security research environment powered by a large language model (LLM). According to the company, the system executed thousands of actions across multiple sandboxed environments, allowing the attackers to move through internal infrastructure and obtain unauthorized access to datasets and service credentials.

The company said the intrusion began when a malicious dataset exploited two separate code execution paths on a processing worker. After establishing an initial foothold, the attacker reportedly escalated privileges to node-level access before collecting cloud and cluster credentials and moving laterally into several internal clusters.

Hugging Face has not yet confirmed whether customer or partner information was affected and said its investigation remains ongoing.

The incident has attracted attention across the cybersecurity community because it suggests that AI systems may now be capable of carrying out increasingly complex intrusion workflows with limited human intervention. Unlike traditional automated malware or scripts that perform predefined tasks, autonomous AI agents can adapt to changing environments, plan sequences of actions and make decisions throughout an attack.

Researchers have long warned that advances in generative AI could lower the barrier for sophisticated cyberattacks by accelerating vulnerability discovery, reconnaissance, privilege escalation and post-compromise activities. While many of these scenarios have remained largely theoretical, Hugging Face's disclosure indicates that elements of these capabilities may already be appearing in real-world operations.

According to the company's investigation, the attacking system generated thousands of individual actions during the compromise, demonstrating a level of operational scale that would normally require substantial manual effort.

Hugging Face co-founder and CEO Clément Delangue said the incident reinforces the view that threat actors are already adopting AI agents in offensive operations. He also argued that restricting advanced AI models behind commercial APIs alone is unlikely to prevent misuse because determined attackers can often circumvent safety controls, while defenders may lose valuable access to tools needed for security research and incident response.

The company encountered another challenge during its investigation when content moderation mechanisms on a frontier AI model reportedly prevented analysts from processing portions of the attack data. To continue the forensic investigation, the security team instead relied on GLM-5.2, an open-weight language model that was deployed within Hugging Face's own infrastructure.

Using the model, investigators reconstructed the attack timeline, identified indicators of compromise, mapped affected credentials and accelerated forensic analysis that would otherwise have required significantly more manual effort. The company also revoked compromised credentials, rotated authentication tokens and remediated the exploited vulnerability.

Security researchers say the incident highlights both the opportunities and limitations of AI-assisted security operations. While AI can substantially reduce investigation time by processing large volumes of telemetry, organizations may encounter operational constraints if externally hosted models refuse to analyze sensitive security artifacts because of built-in safety guardrails.

Industry experts increasingly argue that enterprises should maintain trusted self-hosted AI models that can support internal incident response without exposing sensitive forensic data to external services.

The disclosure comes amid bigger concerns about the growing availability of permissive AI models that operate with fewer content restrictions. Recent threat intelligence research has identified thousands of publicly accessible models advertised as uncensored or unrestricted, raising concerns that malicious actors have expanding access to AI systems capable of assisting offensive cyber activities.

Cybersecurity professionals caution that AI is changing the economics of cybercrime by enabling attackers to automate portions of reconnaissance, exploitation, credential harvesting and post-compromise operations. As these technologies continue to mature, sophisticated attack capabilities may become accessible to a broader range of threat actors.

For defenders, the incident reinforces the need to integrate AI into security operations rather than relying solely on conventional manual workflows. AI-assisted detection, forensic analysis and incident response are increasingly becoming essential capabilities as organizations attempt to match the speed and scale of modern attacks.

Although the investigation into the Hugging Face breach remains ongoing, the incident serves as another indication that autonomous AI systems are beginning to influence both offensive and defensive cybersecurity strategies. As organizations continue adopting AI throughout their technology environments, security teams will need to prepare for a future in which machine-speed attacks are met with equally intelligent defensive capabilities.

Third-Party Cloud Breach Exposes Patient Data at Amgen


 

The global biotechnology company Amgen has disclosed a significant data breach resulting from unauthorized access to cloud environments operated by third-party service providers, leading to the theft of sensitive patient and corporate information. According to a filing with the Securities and Exchange Commission (SEC), the pharmaceutical company, based in California, discovered the incident in July 2026 and initiated its cybersecurity incident response process immediately. 

Several containment measures were implemented by the company and independent forensic experts were engaged in an investigation into the breach. As a result of assessing the volume of files that appeared affected and determining that the compromised data could contain sensitive information, Amgen formally classified the incident as material on July 29, 2017. 

As part of the legal requirement to inform investors of significant cybersecurity incidents, the company made the disclosure in a regulatory filing with the Securities and Exchange Commission. Upon preliminary investigation, it was determined that hackers successfully exfiltrated data from a number of cloud-based systems. 

In addition to proprietary corporate data, protected health information (PHI) belonging to patients, and other sensitive records, this information has been compromised. Despite not identifying the vendors involved or revealing how the attackers gained access to the stolen data, Amgen claims that the stolen data originated from cloud storage environments managed by third-party service providers. Additionally, Amgen is assessing whether confidential business information, intellectual property, research and development data, and additional patient information was compromised. 

During the ongoing forensic investigation, the company is continuing to determine if patient records, confidential business information, intellectual property, research and development data, or other sensitive information was accessed or stolen during the incident. 

Upon completion of the forensic investigation, the full scope of the compromise is anticipated. There has been no disclosure by the company as to identification of the third-party cloud providers, attack vectors used by threat actors, or number of individuals affected. No known cybercriminal organization has been attributed to the incident.

Following an evaluation of the number of potentially affected files and the likelihood that they contained highly sensitive information, Amgen determined that the breach was material on July 29. Even though the breach is serious, the company stated that it does not anticipate that the breach will adversely affect its financial condition or operating results in the near future. 

In addition to the assistance of external cybersecurity experts, the investigation is currently ongoing. Considering its legal and regulatory obligations, Amgen stated that it would notify affected patients where required under applicable data protection laws. According to Amgen's current assessment, the cybersecurity incident has not adversely affected its products, manufacturing operations, financial reporting systems, or its ability to continue supplying medicines and meeting the needs of patients. 

There has been an increase in cyberattacks targeting healthcare and pharmaceutical organizations, whose cloud-hosted patient records and valuable research data have made these organizations attractive targets for cybercriminals. In addition to highlighting the increasing cybersecurity risks associated with third-party cloud infrastructure, the incident highlights the importance of securing sensitive healthcare data throughout the supply chain as a whole. 

Amgen stated its response was to activate its cybersecurity incident response plan immediately after detecting the unauthorized activity, implement containment measures in order to limit exposure, and continue to work with independent forensic experts to determine the extent and impact of the incident. There has been an increase in cybersecurity incidents impacting the healthcare and pharmaceutical sectors in recent months. 

The breach is another in a string of recent cybersecurity incidents. The industry has also experienced numerous cyber incidents, including Abbott Laboratories, Clover Health, Stryker, Medtronic, Novo Nordisk, and West Pharmaceutical Services, which illustrates the increasing vulnerability of medical and corporate data to cyberattacks. 

Amgen has not yet disclosed whether it has received any extortion demands or whether the attackers have attempted to take advantage of the stolen data for ransom or another malicious purpose. It is anticipated that additional details will be released once the forensic investigation has been completed. 

Privacy-preserving technologies are reshaping digital identity verification as governments enforce age verification requirements. It is anticipated that solutions that minimize biometric data collection while maintaining security and regulatory compliance will play an important role in the future of online security.

Estée Lauder Discloses HR Data Breach Linked to Oracle E-Business Suite Vulnerability

 

Estee Lauder announced that their Oracle E-Business Suite (EBS) system that manages human capital operations was targeted by cyber criminals who managed to steal personal data of some of the company’s employees. The company confirmed that some of the information on the intranet belonged to third parties who were not authorized to access it. 

According to the company’s statement, Estee Lauder learned about the breach following an internal investigation into the cybersecurity incident. Specifically, investigators discovered on June 19, 2026, that unauthorized users accessed the Oracle EBS system on or around August 9, 2025. The data exfiltrated by the hackers varied depending on the individual’s details but generally included names, addresses, and email, birth dates, social security numbers, passport numbers, bank information, medical data, and records of payroll and performance reviews. 

Since the breach involved PII, financial information, and employment data, there is a risk of identity theft and financial fraud for the affected employees. After detecting the anomaly, Estee Lauder contracted cybersecurity experts to conduct a forensic audit, report the pertinent information to the relevant law enforcement agencies, and take additional measures to secure the site. The company is offering 24 months of identity and restoration services through Kroll to all the affected parties free of charge, and the services will be available until October 31, 2026. All the affected employees should remain on the lookout for possible suspicious activities, including monitoring financial accounts, credit reports, and other relevant personal information. 

Even though Estee Lauder did not disclose the identity of the perpetrators, in the context of the discovered timeline, it is plausible to assume that the threat actors who targeted the company are part of the Cl0p extortion group. According to reports by Google and Mandiant, the hacking group utilized several Oracle EBS vulnerabilities, including the zero-day flaw with the reference number CVE-2025-61882, to initiate attacks against other companies. 

The vulnerability that was most likely used in the attack allowed malicious cyber actors to deploy arbitrary code via an unauthenticated HTTP request and affected all Oracle EBS versions from 12.2.3 to 12.2.14. Notably, Oracle released a security patch on October 4, 2025, after detecting that the vulnerability was being actively exploited. The latest breach serves as a reminder of the potential risks associated with the use of enterprise resource planning software that has the capability to store PII and other sensitive information about employees. 

It is strongly advised that organizations that use similar systems remain wary of the threats and make sure that all the relevant software has been updated with the latest security patches while also configuring the tools in a manner that minimizes the attack surface. In addition, enterprise systems should be constantly monitored for any suspicious activities that could indicate possible threats to data security.