Breach Roundups

Weekly Databreaches Roundup Week 09-2025

March 5, 2025
week09-2025

Here’s your weekly #databreach news roundup:

Angel One, DISA, Orange, and Hipshipper.

Angel One

Angel One

Angel One, a listed broking firm, experienced a data breach due to unauthorized access to its Amazon Web Services (AWS) resources. The breach was detected on February 27, 2025, after alerts from its dark-web monitoring partner. The company promptly changed all relevant credentials and engaged an external forensic team to investigate the incident. Angel One confirmed that no client securities, funds, or credentials were impacted, and all client accounts remained secure. Despite this reassurance, the company’s shares fell by nearly 5% before recovering slightly. This breach follows a similar incident in April 2023, which also involved unauthorized access to client data.

DISA

DISA

DISA Global Solutions, a U.S.-based employee screening provider, announced a data breach affecting over 3.3 million people. The breach, which went undetected for over two months, was discovered on April 22, 2024, after a hacker infiltrated the company’s network in February 2024. Stolen data included Social Security numbers, financial information, and government-issued IDs, with more than 360,000 residents in Massachusetts affected. DISA has stated it cannot confirm the exact data accessed due to a lack of technical means to track the breach. The company has not disclosed the perpetrators or the exact cause of the breach, and the delay in notifying affected individuals remains unclear.

Orange

Orange

A hacker, using the alias Rey and linked to the HellCat ransomware group, claims to have stolen thousands of documents containing user records and employee data from Orange Group, a major French telecommunications provider. The breach, affecting mostly Orange’s Romanian branch, exposed 380,000 email addresses, invoices, contracts, and sensitive customer and employee data. Rey accessed Orange’s systems through compromised credentials and vulnerabilities in Jira software, exfiltrating nearly 12,000 files totaling 6.5GB. The hacker attempted to extort the company but was unsuccessful. Orange confirmed the breach occurred on a non-critical application, stating it had taken immediate action to minimize the impact and ensure no customer operations were affected. The company is investigating the incident and cooperating with authorities.

 

Hipshipper

Hipshipper

A data leak from Hipshipper, a third-party international shipping service used by Amazon, Shopify, and eBay, exposed the shipping records of over 14 million customers due to a misconfigured cloud database. The exposed data, which included shipping labels, customs forms, and personal details like names, addresses, and phone numbers, could be exploited for phishing attacks, scams, or malware infections. The leak, discovered in December 2024, was not addressed until January 8, 2025, nearly a month later. Although there’s no evidence of misuse, researchers warned that the breach posed risks to customers and advised organizations to implement better security practices, including tightening access controls and using encryption.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading