Aside from deferring the delivery of breach notifications two months later, Visionworks also did not sufficiently defend its systems, resulting in the exfiltration of customers' names, birthdates, Social Security numbers, home and email addresses, financial details, and medical information, alleged the lawsuit.
Cybernews reports that MetLife was claimed to have been compromised by the RansomHub ransomware-as-a-service operation, which alleged the theft of 1 TB of data from the major global insurance company's systems. The insurance company, however, denied that its systems were compromised, saying an Ecuador-based subsidiary was impacted by a "cyber incident."
While Google Groups and LinkedIn reports noted the campaign to have commenced in early December, such an attack may have been tested since March as evidenced by command-and-control subdomains discovered by BleepingComputer.
U.S. Army soldier Cameron John Wagenius has been apprehended and charged by federal authorities over suspicion of exposing stolen AT&T and Verizon customer call records as the threat actor "Kiberphant0m," KrebsOnSecurity reports.
Malicious job offers purporting to be from widely known companies have been leveraged by threat actors to facilitate the distribution of cryptocurrency-stealing malware, reports Cybernews.