Here’s your weekly #databreach news roundup:
Toyota
Toyota Financial Services (TFS) has confirmed that it detected unauthorized access on some of its systems in Europe and Africa after Medusa ransomware claimed an attack on the company. @databreach @billtoulas @BleepinComputer https://t.co/NMObWUkDAe
— DevaOnBreaches (@DevaOnBreaches) November 18, 2023
- Toyota Financial Services (TFS), a subsidiary of Toyota Motor Corporation, confirmed unauthorized access to some of its systems in Europe and Africa. The Medusa ransomware group claimed responsibility for the attack.
- TFS is a global entity, involved in auto financing, with a presence in 90% of markets where Toyota vehicles are sold.
- Medusa ransomware listed TFS on its data leak site, demanding a ransom of $8,000,000. The group provided Toyota a 10-day response deadline, with an option to extend for $10,000 per day.
- While TFS did not confirm data theft, Medusa claims to have exfiltrated files and threatens a data leak if the ransom is not paid.
- To substantiate their claim, the hackers released sample data including financial documents, spreadsheets, purchase invoices, hashed account passwords, cleartext user IDs and passwords, passport scans, internal organization charts, financial reports, staff email addresses, etc.
- The majority of the documents are in German, suggesting that the breach primarily affected Toyota’s Central European operations.
- The current status of the investigation into the full extent of the breach or Toyota’s response to the ransom demand remains unclear.
Samsung
Samsung has admitted that hackers accessed the personal data of U.K.-based customers during a year-long breach of its systems. @CarlyPage_ @TechCrunch #databreach https://t.co/c9bCnablrQ
— DevaOnBreaches (@DevaOnBreaches) November 18, 2023
- Samsung acknowledged a breach in its systems, leading to unauthorized access to the personal data of its U.K. e-store customers.
- The breach occurred over a year-long period, specifically affecting transactions made between July 1, 2019, and June 30, 2020.
- Samsung did not discover the compromise until November 13, 2023, more than three years after the initial breach.
- Attackers exploited a vulnerability in an unnamed third-party business application to gain access to customer information.
- The exposed data includes customers’ names, phone numbers, postal addresses, and email addresses. Samsung confirmed that no financial data or passwords were impacted.
- Samsung reported the issue to the U.K.’s Information Commissioner’s Office (ICO) and informed affected customers about the breach.
- The ICO, represented by spokesperson Adele Burns, confirmed awareness of the incident and plans to make enquiries.
- This incident marks the third data breach disclosed by Samsung in the past two years. Previous incidents include an attack on its U.S. systems in September 2022 and a breach in March 2022, where Lapsus$ hackers leaked confidential data, including source code and biometric unlock algorithms.
Perry Johnson & Associates(PJ&A)
Nine million patients had highly sensitive personal and health information stolen on a medical transcription service (Perry Johnson & Associates, or PJ&A), representing one of the worst medical-related data breaches in recent times. #databreach https://t.co/Jr4KEtcZHE
— DevaOnBreaches (@DevaOnBreaches) November 17, 2023
- Perry Johnson & Associates (PJ&A), a U.S.-based medical transcription service, experienced a cyberattack resulting in the theft of sensitive information from nearly nine million patients.
- PJ&A, located in Henderson, Nevada, provides transcription services for healthcare organizations and physicians, converting dictated patient notes into written records.
- The data breach, affecting more than 8.95 million individuals, began as early as March 2023. PJ&A started notifying affected patients on October 31, six months later.
- The stolen data includes patient names, dates of birth, addresses, medical and hospital account numbers, admission diagnoses, service dates and times, and some Social Security numbers. It also encompasses insurance details, clinical information, laboratory and diagnostic test results, medications, treatment facility names, and healthcare provider identities.
- The exact nature of the cyberattack is not yet clear, and PJ&A’s chief executive Jeffrey Hubbard has not responded to requests for comment.
- At least two PJ&A customers have confirmed their patients’ data was involved:
- Northwell Health (New York State): 3.89 million patients affected. This is Northwell Health’s second patient data breach in 2023.
- Cook County Health (Illinois): 1.2 million patients affected, including records of 2,600 patients with Social Security numbers.
- As of now, data pertaining to approximately four million patients remains unaccounted for.
Truepill
Postmeds, doing business as ‘Truepill,’ is sending notifications of a #databreach informing recipients that threat actors accessed their sensitive personal information. @billtoulas https://t.co/nUgrOVEaSU
— DevaOnBreaches (@DevaOnBreaches) November 16, 2023
- Truepill, operating as Postmeds, is notifying individuals of a data breach in which threat actors accessed sensitive personal information.
- Truepill is a B2B pharmacy platform offering order fulfillment and delivery services, serving D2C brands, digital health companies, and healthcare organizations across the U.S.
- The breach impacts 2,364,359 people, as reported by the U.S. Department of Health and Human Services Office for Civil Rights breach portal.
- The unauthorized network access was discovered on August 31, 2023, with the intrusion occurring a day earlier.
- Data potentially accessed includes full names, medication types, demographic information, and names of prescribing physicians. Social Security numbers were not part of the exposed data.
- Some recipients of the breach notifications reported never having heard of Truepill, causing confusion about how their data was obtained by the company.
- The breach may lead to multiple class action lawsuits. The lawsuits are likely to argue that the breach could have been prevented with better security practices, including encryption of sensitive healthcare data on servers.
- Postmeds took over two months to notify affected individuals, a delay that may be highlighted in lawsuits. During this period, some impacted individuals noticed suspicious activity on their Venmo accounts and later found their personal data on the dark web.
- The breach notices have been criticized for being vague, lacking details on how the breach occurred, and not offering guidance or identity theft protection services.
- A law firm involved in litigation against Postmeds reports that leaked data also includes addresses, dates of birth, medical treatment and diagnosis information, and health insurance details, which were not mentioned in the company’s notice.
Courts
Furniture and appliance retailer Courts has confirmed that there was a #databreach on its recently abandoned e-commerce platform, but says customers' payment methods and password information were not exposed in the incident.https://t.co/zYg8tH5X32
— DevaOnBreaches (@DevaOnBreaches) November 15, 2023
- In September, Courts replaced its e-commerce platform with a new, more secure website: www.courts.com.
- Courts assured its e-commerce customers that their payment methods and password information were not exposed in any recent incident.
- The data leakage incident did not affect customers who made purchases in Courts’ physical stores.
- Courts emphasized the importance of data security and apologized for any inconvenience caused by the incident. They are aligning their practices with the incoming Data Protection Act, effective December 1, 2023.
Coin Cloud
The defunct Bitcoin ATM provider, Coin Cloud, has reportedly fallen victim to a massive #databreach.
— DevaOnBreaches (@DevaOnBreaches) November 15, 2023
Unidentified hackers have allegedly infiltrated the company's security infrastructure, compromising the personal information of over 300,000 users and pilfering the entire…
- Coin Cloud, a now-defunct Bitcoin ATM provider, experienced a significant data breach where hackers infiltrated its security infrastructure.
- The breach compromised personal information of over 300,000 users, including 70,000 customer selfies taken by ATM cameras. Additionally, sensitive data like social security numbers, dates of birth, names, email addresses, phone numbers, occupations, and physical addresses were stolen.
- The breach has severe implications for users in both the United States and Brazil, raising concerns of identity theft and other cybercrimes.
- The hackers also claimed to have stolen the entire source code of Coin Cloud’s backend, encompassing proprietary technology essential for cryptocurrency ATM operations.
- With access to Coin Cloud’s systems, users face risks of misuse and exploitation due to the hackers’ detailed understanding of the company’s infrastructure.
- Coin Cloud had filed for bankruptcy in February, indicating financial troubles with liabilities between $100 million and $500 million and assets ranging from $50 million to $100 million. This financial instability may have contributed to the security vulnerabilities exploited in the breach.
Plume
Plume, a smart WiFi services provider, was posted on a popular data leak forum, with attackers claiming that they’ve downloaded gigabytes of user data. The company is investigating the claims. #databreach https://t.co/7lJKY8pjhJ
— DevaOnBreaches (@DevaOnBreaches) November 15, 2023
- Plume, a smart WiFi services provider, is currently under scrutiny after claims of a data breach were posted on a popular data leak forum.
- Attackers allege they have stolen over 20GB of Plume’s WiFi database, containing more than 15 million lines of user data.
- Plume is investigating these claims. A representative from the company acknowledged awareness of the breach claim and stated that their teams are examining the situation.
- The dataset reportedly includes information of mobile app users, customers, and staff members of Plume. It is claimed to contain email addresses, device details, carriers, names, iOS and Android versions, among other data.
- The Cybernews research team confirmed that the data sample provided by the attackers seems to match their statements. However, without the full dataset, it remains uncertain if the data truly belongs to Plume or is sourced from elsewhere.
- Notably, the attackers publicly announced the leak on social media through an X account, deviating from the typical covert methods of disseminating such information.
Read more at :
https://cybernews.com/news/plume-data-breach/