Data Breach News, Vendor News
September 02, 2025
883 views 2 mins 0

Supply-chain attack hits Zscaler via Salesloft Drift, leaking customer info

Another Salesloft Drift-related breach has been disclosed. Seucrity Affairs reports: Zscaler discloses a data breach that is linked to the recent Salesloft Drift attack. The cybersecurity vendor confirmed it was affected by a campaign targeting Salesloft Drift, a marketing SaaS integrated with Salesforce. Threat actors stole OAuth tokens from the company, the incident impacted multiple Salesforce […]

Data Breach News, New Threats, News, Vendor News
August 29, 2025
984 views 2 mins 0

Warning issued after hackers stole Salesloft Drift data

Customers are targeted through compromised OAuth access tokens from Salesloft Drift integrations. IT Pro reports: Google’s Threat Intelligence Group (GTIG) has revealed that hackers harvested user credentials from Salesforce customers in a widespread campaign during the first half of this month. The attacker, tracked as UNC6395, targeted Salesforce customer instances through compromised OAuth tokens associated […]

Insurance News, News, Vendor News
August 26, 2025
1126 views 6 secs 0

Farmers Insurance breach impacts over 1 million customers

Cybernews reports: The Farmers Insurance Group is notifying 1,111,386 people that their personal information was exposed in a recent cyberattack earlier this year. The American insurance giant said it began sending breach notification letters about the May 29th “security incident” out of an “abundance of caution” on August 22nd. The breach may have involved the […]

Data Breach News, Vendor News
August 23, 2025
1138 views 12 secs 0

U.K. criminal background check firm APCS discloses breach

A provider of criminal background checks in the U.K. is dealing with a breach at a third-party developer. The Register reports: A leading UK provider of criminal record checks for employers is handling a data breach stemming from a third-party development company. Access Personal Checking Services (APCS) has written to customers to notify them that […]

Legal News, Data Breach News, Vendor News
August 19, 2025
1058 views 32 secs 0

Microsoft’s Nuance coughs up $8.5M to rid itself of MOVEit breach suit

The Register reports: Microsoft-owned talk-to-text outfit Nuance has agreed to cough up $8.5 million to settle a class action lawsuit over the sprawling MOVEit Transfer mega-breach – although it admits no liability. The proposed deal [PDF], filed in a Massachusetts federal court last week, would draw a line under litigation brought by individuals who claimed that the company failed […]

Data Breach News, Vendor News
August 18, 2025
1037 views 50 secs 0

Georgia SNAP call center cyberattack tied to incidents in 6 states: USDA

FOX 5 in Atlanta reports: A cyberattack that shut down Georgia’s SNAP (Supplemental Nutrition Assistance Program) call center may not have been an isolated incident. Officials with the United States Department of Agriculture tell FOX 5 that similar attacks have happened in six other states recently. The backstory: On July 28, the Georgia Department of […]

Data Breach News, Vendor News
August 16, 2025
1007 views 3 secs 0

Afghans resettled in UK hit by new data breach

BBC reports: Thousands of Afghans brought to safety in the UK have had their personal data exposed, after a Ministry of Defence (MoD) sub-contractor suffered a data breach. The names, passport information and Afghan Relocations and Assistance Policy (Arap) details of up to 3,700 Afghans have potentially been compromised after Inflite The Jet Centre, which […]

Vendor News, Data Breach News, Education Sector
August 10, 2025
1071 views 24 secs 0

Kokomo24/7, a Vendor for the Los Angeles Unified School District Hit by a Cyber Attack, Network Files Likely Compromised

TechNadu reports: A vendor that serves the Los Angeles Unified School District, Kokomo24/7, has notified authorities about a network file exposure on its internal systems and data storage environment. Investigators determined that the suspicious activity discovered on December 11, 2024, allowed cybercriminals to access sensitive personal information. Since Kokomo24/7 is a vendor for the Los Angeles Unified […]

Data Breach News, News, Vendor News
August 06, 2025
1017 views 50 secs 0

Google reveals it became one of the Salesforce attack victims in June

Google’s Intelligence Threat Group (GITG) has been tracking various threat actor groups under tracking labels such as UNC 6040, UNC 6240, and UNC 3944. The first two overlap with threat actors known as ShinyHunters, while the third overlaps with Scattered Spider. The ShinyHunters group has been linked to attacks on customers of Salesforce. Google itself […]