Such an incident has stemmed from Internet Archive's failure to rotate its authentication tokens, as initially asserted by the hacker, according to a Zendesk spokesperson.
Infiltration of a laptop enabled attacker access to Transak's third-party know-your-customer vendor, facilitating the exposure of clients' names, birthdates, driver's license data, passports, and selfies, but not their financially sensitive details.
Also included in the data purportedly stolen from Country Inn & Suites were credit card information, billing details, internal emails, messages, incidents, and calendar details of previous and upcoming bookings.
Attackers leveraged a Nidec Precision employee's valid VPN account credentials to infiltrate the firm's server, enabling the exfiltration of more than 50,000 files, all of which remain unencrypted, including internal files, green procurement-related documents, communications from business partners, contracts, business documents, and labor safety and health policies.
Internet Archive's latest breach was noted by the threat actor to have stemmed from the digital library nonprofit's failure to rotate its authentication tokens.
Information compromised as a result of the incident included individuals' names, addresses, Social Security numbers, and health-related details, among others although a probe into the total extent of stolen data continues, said Globe Life in a filing with the Securities and Exchange Commission.
Finally, in the enterprise security news, HUMAN, Relyance AI, and watchTowr raise funding this week, Alternative paths to becoming a CISO, Vendor booths don’t have to suck (for vendors or conference attendees!), Budget planning guidance for 2025, CISOs might not be that great at predicting their own future needs, Use this one easy trick to bypass E...
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.