Attackers who infiltrated its systems from June 29 to July 18 were able to compromise some system files, which included individuals' names, financial details, and Social Security numbers, with the stolen data differing from person to person.
Included in the leaked files were data for Cisco clients and other DevHub users, as well as certain CX Professional Services customers, who have already been informed about the breach.
Infiltration of systems belonging to a third-party contractor for internal tool development enabled the exfiltration of Nokia's source code, RSA and SSH keys, SMTP accounts, Bitbucket logins, hardcoded credentials, and webhooks, but not its customer data, said IntelBroker in a post on BreachForums.
HellCat alleged that nearly 40 GB of project data and user details have been exfiltrated as a result of the breach while threatening the French multinational energy management and automation manufacturer of exposing the compromised information should it refuse to pay the $125,000 ransom.
Aside from detailing data protection measures and data identification, definition, and categorization techniques, the guidance also emphasizes cybersecurity threats, data storage failure, and other security risks associated with data, as well as provides insights on best data practices.
Infiltration of systems belonging to Mystic Valley, which caters to older adults and people with disabilities, have enabled the exfiltration of names, birthdates, Social Security numbers, payment card and financial account numbers, passport numbers, driver's license numbers, online passwords, medical details, and health insurance data.
Attacks by EmeraldWhale involved the utilization of the 'httpx' and 'Masscan' open-source tools to scan websites and determine exposure of the /.git/config file and environment files in Laravel apps.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.