Information compromised due to the intrusion included employees' contact details and certain encrypted and hashed credentials but no evidence indicated the theft of any customer or supplier data, said Microchip in a new filing with the Securities and Exchange Commission.
Immediate incident response protocol adoption and network section takedowns were conducted following the discovery of the intrusion on Aug. 28, according to Planned Parenthood of Montana President and CEO Martha Fuller.
Included in the leaked 27.6 GB archive belonging to VK — which was co-founded by recently arrested Telegram CEO Pavel Durov before being relinquished to Russian state-owned firms in December 2021 — were individuals' names, sex, ID numbers, profile pictures, and location information.
Such a development comes after the emergence of a ransom note from RansomHub said to be related to the incident although Halliburton has not yet been added to the ransomware gang's leak site.
Infiltration of certain CBIZ databases through the exploitation of a web page vulnerability enabled the theft of individuals' names, birth/death dates, Social Security numbers, contact details, retiree health information, and welfare plan details between June 2 and June 21.
Data leaked by the threat actor "Satanic" was divided into three CSV files, the first of which contained the full names, phone numbers, phone carriers, country, city, and timezone details, and unique record identifiers for 646,442 individuals around the world who may have had their locations tracked by Tracelo.
Such an intrusion was noted by Halliburton in an email to suppliers to have involved the "maintenance.exe" file, which was confirmed to be an encryptor leveraged by the ransomware gang.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.