Here’s your weekly #databreach news roundup:
Angel One, DISA, Orange, and Hipshipper.
Angel One
Listed broking firm Angel One suffered a data leak, which it attributed to unauthorised access to its Amazon Web Services (AWS) resources. https://t.co/3W7zdoVYum
— DevaOnBreaches (@DevaOnBreaches) March 1, 2025
Angel One, a listed broking firm, experienced a data breach due to unauthorized access to its Amazon Web Services (AWS) resources. The breach was detected on February 27, 2025, after alerts from its dark-web monitoring partner. The company promptly changed all relevant credentials and engaged an external forensic team to investigate the incident. Angel One confirmed that no client securities, funds, or credentials were impacted, and all client accounts remained secure. Despite this reassurance, the company’s shares fell by nearly 5% before recovering slightly. This breach follows a similar incident in April 2023, which also involved unauthorized access to client data.
DISA
DISA Global Solutions, a U.S.-based provider of employee screening services, has said it suffered a #databreach that affects more than 3.3 million people.https://t.co/hAdr3xb8Xw
— DevaOnBreaches (@DevaOnBreaches) February 25, 2025
DISA Global Solutions, a U.S.-based employee screening provider, announced a data breach affecting over 3.3 million people. The breach, which went undetected for over two months, was discovered on April 22, 2024, after a hacker infiltrated the company’s network in February 2024. Stolen data included Social Security numbers, financial information, and government-issued IDs, with more than 360,000 residents in Massachusetts affected. DISA has stated it cannot confirm the exact data accessed due to a lack of technical means to track the breach. The company has not disclosed the perpetrators or the exact cause of the breach, and the delay in notifying affected individuals remains unclear.
Orange
A hacker claims to have stolen thousands of internal documents with user records and employee data after breaching the systems of Orange Group, a leading French telecommunications operator and digital service provider. #databreach https://t.co/5tMSVJTBBx
— DevaOnBreaches (@DevaOnBreaches) February 25, 2025
A hacker, using the alias Rey and linked to the HellCat ransomware group, claims to have stolen thousands of documents containing user records and employee data from Orange Group, a major French telecommunications provider. The breach, affecting mostly Orange’s Romanian branch, exposed 380,000 email addresses, invoices, contracts, and sensitive customer and employee data. Rey accessed Orange’s systems through compromised credentials and vulnerabilities in Jira software, exfiltrating nearly 12,000 files totaling 6.5GB. The hacker attempted to extort the company but was unsuccessful. Orange confirmed the breach occurred on a non-critical application, stating it had taken immediate action to minimize the impact and ensure no customer operations were affected. The company is investigating the incident and cooperating with authorities.
Hipshipper
A data leak from Hipshipper, a third-party international shipping service used by Amazon, Shopify, and eBay, exposed the shipping records of over 14 million customers due to a misconfigured cloud database. The exposed data, which included shipping labels, customs forms, and personal details like names, addresses, and phone numbers, could be exploited for phishing attacks, scams, or malware infections. The leak, discovered in December 2024, was not addressed until January 8, 2025, nearly a month later. Although there’s no evidence of misuse, researchers warned that the breach posed risks to customers and advised organizations to implement better security practices, including tightening access controls and using encryption.