Here’s your weekly #databreach news roundup:
Baltimore City Public Schools, MTN, Frederick Health, WorkComposer, and Blue Shield of California.
Baltimore City Public Schools
Baltimore City Public Schools was hit by a #databreach affecting over 31,000 people, including employees, volunteers, and students. Sensitive info compromised.https://t.co/CzP3RTrrMP
— DevaOnBreaches (@DevaOnBreaches) April 26, 2025
In February 2025, Baltimore City Public Schools suffered a data breach when unknown attackers infiltrated its network, compromising sensitive information of current and former employees, volunteers, contractors, and a small portion of students (around 1,150). The breach exposed personal details like Social Security numbers, driver’s licenses, and student records. While the district did not attribute the attack to a specific group, it was linked to the Cloak ransomware, which has targeted several small to medium-sized organizations since 2022. The breach impacted over 31,000 individuals, prompting the district to offer credit monitoring services and advise affected individuals to monitor their financial accounts. This follows a history of cybersecurity incidents in Baltimore, including previous breaches at both city schools and government systems.
MTN
MTN Group reveals a cybersecurity incident compromising the personal info of some subscribers in certain markets. Network & billing systems are unaffected, investigation is ongoing. Affected customers will be notified soon. #databreach https://t.co/KHxrmnVcHf
— DevaOnBreaches (@DevaOnBreaches) April 26, 2025
MTN Group, Africa’s largest mobile operator, announced a cybersecurity breach that compromised the personal information of some of its customers in certain markets. The attack did not affect the company’s core network, billing systems, or financial services infrastructure. While the exact scope of the breach is still under investigation, MTN confirmed that an “unknown third-party” claimed to have accessed customer data, though there is no evidence of a compromise to customer accounts or wallets. MTN has informed relevant authorities and is advising affected customers to take precautions, such as placing fraud alerts, updating passwords, and enabling multi-factor authentication. The company has yet to specify which markets were impacted.
Frederick Health
A January ransomware attack at Frederick Health Medical Group has compromised the data of nearly 1 million patients, exposing sensitive personal and health information. #databreachhttps://t.co/82FJGk93N8
— DevaOnBreaches (@DevaOnBreaches) April 26, 2025
In January 2025, Frederick Health Medical Group, a major healthcare provider in Maryland, experienced a ransomware attack that led to a data breach affecting nearly one million patients. The attack, detected on January 27, allowed unauthorized access to sensitive personal and health information, including names, Social Security numbers, medical records, and insurance details. While the health system notified law enforcement and engaged a forensic firm to investigate, it did not specify the number of individuals impacted until March, when it reported 934,326 patients to the U.S. Department of Health and Human Services. No ransomware group has claimed responsibility, suggesting Frederick Health may have paid the ransom. The breach follows several other major healthcare data incidents, including Blue Shield of California and Yale New Haven Health.
WorkComposer
WorkComposer, a popular employee monitoring tool, leaked 21M+ real-time screenshots via an unsecured cloud bucket exposing sensitive data like passwords, emails, and IPs exposing 200K+ users. #databreachhttps://t.co/wg9mGAoget
— DevaOnBreaches (@DevaOnBreaches) April 25, 2025
A major security lapse involving WorkComposer, a time-tracking and productivity monitoring tool, has exposed millions of sensitive screenshots on the open internet, potentially risking identity theft, data breaches, and fraud. Cybersecurity researchers discovered more than 21 million real-time screenshots stored in an unsecured Amazon S3 bucket, capturing employees’ activities, emails, passwords, and proprietary data. WorkComposer, used by over 200,000 active users, logs hours and takes screenshots every 20 seconds to monitor remote workers. Although there is no evidence that cybercriminals accessed the data, the incident highlights the risks of poorly protected cloud databases and the importance of securing sensitive information.
Blue Shield of California
Blue Shield of California exposed the protected health info of 4.7M members to Google Ads via misconfigured Google Analytics (April 2021–Jan 2024). Data includes claims, plan details, and more—SSNs & financials are unaffected. #databreachhttps://t.co/jrM4XenkUm
— DevaOnBreaches (@DevaOnBreaches) April 25, 2025
Blue Shield of California revealed a data breach exposing the protected health information of 4.7 million members due to a misconfigured Google Analytics setup. Between April 2021 and January 2024, certain member data, including insurance details, medical claim information, and search queries, were inadvertently shared with Google’s advertising platforms. The breach did not expose sensitive personal data like Social Security numbers or financial information, but members are advised to monitor their accounts for suspicious activity. This follows a previous breach in 2024, where nearly one million members’ data was stolen in a ransomware attack. Despite the breach, Blue Shield has not offered identity theft protection or indicated whether affected individuals will receive direct notifications.