Infiltration of AnnieMac's systems between Aug. 21 and 23 resulted in the potential copying of individuals' names and Social Security numbers, said the New Jersey-based mortgage lender in breach notification letters, which noted the lack of evidence suggesting the dissemination of the exposed data on the dark web.
In a post on its leak site on Friday, RansomHub disclosed that it was able to exfiltrate files relating to contracts, financials, insurance, and confidential data while sharing a data sample that included Mexican government employees' names, job titles, workplaces, phone number extensions, email addresses, and ID reference numbers.
Information compromised in the breach has been obtained from a system that had been inactive for nearly two years, noted DemandScience in an email sent to an individual who inquired the firm after seeing his data in the leak.
U.S. telecommunications firms were confirmed by the FBI and Cybersecurity and Infrastructure Security Agency to have had customer call records, private communications of a few individuals, most of whom are in the government, and sensitive information that require law enforcement requests to have been exfiltrated by Chinese state-sponsored threat actors.
More than 100 records shared by the hacker revealed the scraping of usernames, names, email addresses, biographies, follower and following counts, external URLs, and locations, as well as targeted usernames, user IDs and scrape IDs, account creation dates, and account categories.
Included in the data exfiltrated from Thompson Coburn's systems were individuals' names, birthdates, Social Security numbers, medical record and patient account numbers, treatment or prescription details, clinical information, medical provider details, and health insurance information, said the law firm in a disclosure to the Department of Health and Human Services.
Such a disclosure comes after Satanic admitted to having stolen a database from Hot Topic, Torrid, and Box Lunch containing 350 million user records following a breach, which is believed by Hudson Rock to have been conducted through an information-stealing malware attack against Hot Topic's data unification service.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.