Data security incident impacted records dating back to 1997 @ Eastern Washington University

In December 2024, Eastern Washington University (EWU) discovered a data breach affecting former student and temporary employees dating back to 1997. An unauthorized individual gained access to an electronic folder containing sensitive employee informa...

User and driver Information exposed via vulnerable feedback form @ Rapido

A significant data breach recently affected Rapido, a major ride-hailing service in India. The breach originated from a vulnerability in their online feedback form, which exposed sensitive user and driver data. This vulnerability, discovered by a secu...

Conferencing business division shut down some servers following Black Basta ransomware breach @ BT

BT Group, a multinational telecommunications company, experienced a cybersecurity breach impacting its BT Conferencing division. The Black Basta ransomware group claims responsibility for the attack and alleges to have exfiltrated 500 GB of data, incl...

Cybercriminals compromised files containing the sensitive personal information of 240,742 individuals @ SRP Federal Credit Union

SRP Federal Credit Union (SRPFCU), headquartered in North Augusta, South Carolina, experienced a cybersecurity breach between September 5, 2024, and November 4, 2024. The credit union, which serves approximately 200,000 individuals in Georgia and Sou...

Council lacked a valid legal basis for processing personal data from CCTV and Automated Number Plate Recognition cameras @ Sligo County Council

Sligo County Council in Ireland was fined €29,500 after an inquiry by the Data Protection Commission (DPC) found multiple breaches of the General Data Protection Regulation (GDPR). The inquiry, focused on the Council's use of CCTV and Automatic Number...

Ransomware attack blocked access to servers which impacted functions at sheriff’s office, jail, common pleas court and other county offices @ Wood County

A ransomware attack on Wood County computer systems was detected on December 10, 2024. The attack impacted numerous county offices, including the sheriff's office, jail, and common pleas court. While emergency services have not been disrupted, many of...

Data breach compromised 370,000 individuals' sensitive personal data @ Duke Energy

In May 2024, Duke Energy, a utility company serving over 2 million customers in Florida, experienced a cyber security breach. The breach exposed customer data including names, birth dates, the last four digits of Social Security numbers, account numbe...

Vendor experienced security breach which impacted some patients @ Boston Medical Center and 2 more...

On February 17, 2024, Change Healthcare, a vendor used by BMC, experienced a data security breach. The breach potentially impacted some BMC patients' information. Change Healthcare is in the process of notifying individuals whose personal information...

Russian hackers reportedly attempted to seize control of the its broadcasting in order to broadcast pro-Russian propaganda @ Espreso TV and Expresso

On December 16, 2024, the Ukrainian TV channel Espreso was targeted in a cyberattack aimed at seizing control of its broadcasting capabilities. The attackers, identified as Russian hackers based on the content they attempted to broadcast, sought to sp...

Unauthorised access to company’s IT network @ Carriage Purchaser, Inc.

PS Logistics, a transportation and logistics company specializing in flatbed trucking solutions, recently announced a data breach stemming from a cyberattack that occurred in February 2024. The breach was discovered on February 20, 2024, when an unaut...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...