#WeeklyRoundup

Weekly Databreaches Roundup Week 46-2025

November 19, 2025
week46-2025

Here’s your weekly #databreach news roundup:

Washington Post, Logitech, Somalia’s electronic visa, Synnovis, DoorDash, Checkout, and GlobalLogic.

Somalia's electronic visa

A data breach in Somalia’s electronic visa system may have exposed personal information of tens of thousands of applicants, including US citizens. The breach, caused by hackers, could affect at least 35,000 people, with leaked documents containing sensitive data like names, photos, and addresses. The US embassy has warned travelers to consider the risks before applying for a Somali e-visa. Somali authorities have not commented on the breach but have moved the visa service to a new platform. The breach adds to tensions between Somalia and Somaliland, which has disputed control of Somali airspace and its own visa policies.

Logitech

Logitech

Logitech has confirmed it was the target of a data breach caused by a cyberattack from the Clop extortion gang, who previously exploited vulnerabilities in Oracle’s E-Business Suite. The breach resulted in the theft of data, although Logitech asserts that it did not include sensitive information such as national IDs or credit card details. The company has stated that the incident did not impact its products, operations, or manufacturing and that the vulnerability was quickly patched. The stolen data, which was leaked by Clop, includes limited information about employees, customers, and suppliers. The breach occurred through a third-party vulnerability, likely related to a zero-day flaw in Oracle’s software. Clop, known for targeting zero-day vulnerabilities, has previously exploited similar flaws to steal large amounts of data from multiple organizations.

Washington Post

The Washington Post has informed nearly 10,000 employees and contractors that their personal and financial data was exposed in the recent Oracle data breach. Between July 10 and August 22, hackers exploited a zero-day vulnerability in Oracle E-Business Suite software, which the newspaper used internally, to access sensitive information. The breach was discovered after the attackers attempted to extort the Washington Post in late September. Data compromised in the attack includes full names, bank account details, Social Security numbers, and tax IDs. Affected individuals are being offered identity protection services. This attack is linked to the Clop ransomware group, which has exploited similar vulnerabilities in other organizations, including Harvard and Envoy Air. The Washington Post has launched an investigation and is advising those impacted to take steps to secure their information.

Synnovis

Logitech

Synnovis, a UK pathology services provider, has confirmed a data breach following a ransomware attack in June 2024. The attack, which affected multiple NHS hospitals, led to the theft of sensitive patient data, including NHS numbers, names, birth dates, and some test results. The stolen data was fragmented and incomplete, requiring extensive investigation over a year by forensic experts. The breach was linked to the Qilin ransomware group, which is known for targeting critical infrastructure. Although no ransom was paid, the stolen data was later leaked by the attackers. Synnovis is notifying affected organizations, but patients will be contacted by the NHS institutions directly, as required by UK data protection laws. The incident caused significant disruption, with many planned medical procedures canceled and hospitals facing operational challenges.

DoorDash

DoorDash has confirmed a data breach that occurred in October 2025, involving unauthorized access to user contact information, including names, addresses, phone numbers, and email addresses. The breach was traced to a DoorDash employee falling victim to a social engineering scam. The company has started notifying impacted users, primarily in Canada, but the breach may also affect users in the U.S. and other regions where DoorDash operates. This marks DoorDash’s third significant security incident, following breaches in 2019 and 2022. Some users have criticized the company for the delay in notifying them, pointing out the breach’s impact on personal data. DoorDash has since enhanced its security measures, launched further employee training, and referred the matter to law enforcement. Users are advised to remain cautious of phishing attempts or suspicious communications.

Checkout

Checkout

Checkout.com, a UK-based financial technology company, has confirmed a data breach by the ShinyHunters threat group, which accessed a legacy cloud storage system containing merchant data from 2020 and earlier. The stolen data includes internal documents and onboarding materials from some of Checkout.com’s past and current customers, though the breach affects less than 25% of its current merchant base. The company has refused to pay the ransom demanded by ShinyHunters, opting instead to invest in enhanced security measures and donate the ransom amount to cybercrime research at Carnegie Mellon University and the University of Oxford. ShinyHunters, known for exploiting vulnerabilities via phishing and social engineering, has also been linked to attacks on Oracle and Salesforce systems. Checkout.com has committed to strengthening its security protocols but has not disclosed the specific third-party system involved in the breach.

GlobalLogic

GlobalLogic

GlobalLogic, a digital engineering services provider, has confirmed a data breach involving personal information from over 10,000 current and former employees. The breach, which occurred between July and August 2025, was caused by a zero-day vulnerability in Oracle E-Business Suite (EBS) that attackers exploited to access and steal sensitive data. The stolen information includes names, contact details, emergency contacts, national identifiers (e.g., Social Security Numbers), salary details, and bank account information.

While GlobalLogic has not directly attributed the attack to a specific threat group, the breach bears similarities to the recent extortion campaign by the Clop ransomware gang, which has targeted multiple organizations using the same Oracle EBS vulnerability. Clop has taken credit for the attack, and while the company has not yet been added to Clop’s leak site, this suggests ongoing negotiations or that a ransom may have been paid. GlobalLogic has confirmed that the breach did not impact other systems outside its Oracle platform.

Clop’s cybercrime activities have impacted a range of organizations, including major firms like Harvard, The Washington Post, and Envoy Air. The U.S. State Department has offered a $10 million reward for information linking Clop’s activities to a foreign government.

Discover more from Data Breach Insights

Subscribe now to keep reading and get access to the full archive.

Continue reading