Breach Roundups

Weekly Databreaches Roundup Week 17-2025

April 28, 2025
Data Breaches-w16-2025

Here’s your weekly #databreach news roundup:

Baltimore City Public Schools, MTN, Frederick Health, WorkComposer, and Blue Shield of California.

Baltimore City Public Schools

Baltimore City Public Schools

In February 2025, Baltimore City Public Schools suffered a data breach when unknown attackers infiltrated its network, compromising sensitive information of current and former employees, volunteers, contractors, and a small portion of students (around 1,150). The breach exposed personal details like Social Security numbers, driver’s licenses, and student records. While the district did not attribute the attack to a specific group, it was linked to the Cloak ransomware, which has targeted several small to medium-sized organizations since 2022. The breach impacted over 31,000 individuals, prompting the district to offer credit monitoring services and advise affected individuals to monitor their financial accounts. This follows a history of cybersecurity incidents in Baltimore, including previous breaches at both city schools and government systems.

MTN

MTN

MTN Group, Africa’s largest mobile operator, announced a cybersecurity breach that compromised the personal information of some of its customers in certain markets. The attack did not affect the company’s core network, billing systems, or financial services infrastructure. While the exact scope of the breach is still under investigation, MTN confirmed that an “unknown third-party” claimed to have accessed customer data, though there is no evidence of a compromise to customer accounts or wallets. MTN has informed relevant authorities and is advising affected customers to take precautions, such as placing fraud alerts, updating passwords, and enabling multi-factor authentication. The company has yet to specify which markets were impacted.

Frederick Health

In January 2025, Frederick Health Medical Group, a major healthcare provider in Maryland, experienced a ransomware attack that led to a data breach affecting nearly one million patients. The attack, detected on January 27, allowed unauthorized access to sensitive personal and health information, including names, Social Security numbers, medical records, and insurance details. While the health system notified law enforcement and engaged a forensic firm to investigate, it did not specify the number of individuals impacted until March, when it reported 934,326 patients to the U.S. Department of Health and Human Services. No ransomware group has claimed responsibility, suggesting Frederick Health may have paid the ransom. The breach follows several other major healthcare data incidents, including Blue Shield of California and Yale New Haven Health.

WorkComposer

WorkComposer

A major security lapse involving WorkComposer, a time-tracking and productivity monitoring tool, has exposed millions of sensitive screenshots on the open internet, potentially risking identity theft, data breaches, and fraud. Cybersecurity researchers discovered more than 21 million real-time screenshots stored in an unsecured Amazon S3 bucket, capturing employees’ activities, emails, passwords, and proprietary data. WorkComposer, used by over 200,000 active users, logs hours and takes screenshots every 20 seconds to monitor remote workers. Although there is no evidence that cybercriminals accessed the data, the incident highlights the risks of poorly protected cloud databases and the importance of securing sensitive information.

Blue Shield of California

Blue Shield of California

Blue Shield of California revealed a data breach exposing the protected health information of 4.7 million members due to a misconfigured Google Analytics setup. Between April 2021 and January 2024, certain member data, including insurance details, medical claim information, and search queries, were inadvertently shared with Google’s advertising platforms. The breach did not expose sensitive personal data like Social Security numbers or financial information, but members are advised to monitor their accounts for suspicious activity. This follows a previous breach in 2024, where nearly one million members’ data was stolen in a ransomware attack. Despite the breach, Blue Shield has not offered identity theft protection or indicated whether affected individuals will receive direct notifications.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading