breach – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 02 Sep 2025 21:07:53 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 breach – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Cloudflare hit by data breach in Salesloft Drift supply chain attack https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/ https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/#respond Tue, 02 Sep 2025 21:07:53 +0000 https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/

Cloudflare

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week.

The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens.

Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens.

“Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer’s configuration and could contain sensitive information like access tokens,” Cloudflare said.

“Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel.”

The company’s investigation found that the threat actors stole only the text contained within the Salesforce case objects (including customer support tickets and their associated data, but no attachments) between August 12 and August 17, after an initial reconnaissance stage on August 9.

These exfiltrated case objects contained only text-based data, including:

  • The subject line of the Salesforce case
  • The body of the case (which may include keys, secrets, etc., if provided by the customer to Cloudflare)
  • Customer contact information (for example, company name, requester’s email address and phone number, company domain name, and company country)

“We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” Cloudflare added.

“Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

Wave of Salesforce data breaches

Since the start of the year, the ShinyHunters extortion group has been targeting Salesforce customers in data theft attacks, using voice phishing (vishing) to trick employees into linking malicious OAuth apps with their company’s Salesforce instances. This tactic enabled the attackers to steal databases, which were later used to extort victims.

Since Google first wrote about these attacks in June, numerous data breaches have been linked to ShinyHunters’ social engineering tactics, including those targeting Google itself, Cisco, Qantas, Allianz Life, Farmers Insurance, Workday, Adidas, as well as LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

While some security researchers have told BleepingComputer that the Salesloft supply chain attacks involve the same threat actors, Google has found no conclusive evidence linking them.

Palo Alto Networks also confirmed over the weekend that the threat actors behind the Salesloft Drift breaches stole some support data submitted by customers, including contact info and text comments.

The Palo Alto Networks incident was also limited to its Salesforce CRM and, as the company told BleepingComputer, it did not affect any of its products, systems, or services.

The cybersecurity company observed the attackers searching for secrets, including AWS access keys (AKIA), VPN and SSO login strings, Snowflake tokens, as well as generic keywords such as “secret,” “password,” or “key,” which could be used to breach more cloud platforms to steal data in other extortion attacks.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/feed/ 0 56444
Farmers Insurance data breach impacts 1.1M people after Salesforce attack https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/ https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/#respond Mon, 25 Aug 2025 19:29:05 +0000 https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/

Farmers Insurance sign

U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with BleepingComputer learning that the data was stolen in the widespread Salesforce attacks.

Farmers Insurance is a U.S.-based insurer that provides auto, home, life, and business insurance products. It operates through a network of agents and subsidiaries, serving more than 10 million households nationwide.

The company disclosed the data breach in an advisory on its website, saying that its database at a third-party vendor was breached on May 29, 2025.

“On May 30, 2025, one of Farmers’ third-party vendors alerted Farmers to suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing Farmers customer information (the “Incident”),” reads the data breach notification on its website.

“The third-party vendor had monitoring tools in place, which allowed the vendor to quickly detect the activity and take appropriate containment measures, including blocking the unauthorized actor. After learning of the activity, Farmers immediately launched a comprehensive investigation to determine the nature and scope of the Incident and notified appropriate law enforcement authorities.”

The company says that its investigation determined that customers’ names, addresses, dates of birth, driver’s license numbers, and/or last four digits of Social Security numbers were stolen during the breach.

Farmers began sending data breach notifications to impacted individuals on August 22, with a sample notification [1, 2] shared with the Maine Attorney General’s Office, stating that a combined total of 1,111,386 customers were impacted.

While Farmers did not disclose the name of the third-party vendor, BleepingComputer has learned that the data was stolen in the widespread Salesforce data theft attacks that have impacted numerous organizations this year.

BleepingComputer contacted Farmers with additional questions about the breach and will update the story if we receive a response.

The Salesforce data theft attacks

Since the beginning of the year, threat actors classified as ‘UNC6040’ or ‘UNC6240’ have been conducting social engineering attacks on Salesforce customers.

During these attacks, threat actors conduct voice phishing (vishing) to trick employees into linking a malicious OAuth app with their company’s Salesforce instances.

Once linked, the threat actors used the connection to download and steal the databases, which were then used to extort the company through email.

The extortion demands come from the ShinyHunters cybercrime group, who told BleepingComputer that the attacks involve multiple overlapping threat groups, with each group handling specific tasks to breach Salesforce instances and steal data.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

Other companies impacted in these attacks include Google, Cisco, Workday, Adidas, Qantas, Allianz Life, and the LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

 

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/feed/ 0 55095
BtcTurk Freezes Crypto Withdrawals After $48 Million Hot Wallet Breach https://earlybirdsinvest.com/btcturk-freezes-crypto-withdrawals-after-48-million-hot-wallet-breach/ https://earlybirdsinvest.com/btcturk-freezes-crypto-withdrawals-after-48-million-hot-wallet-breach/#respond Sat, 16 Aug 2025 20:44:48 +0000 https://earlybirdsinvest.com/btcturk-freezes-crypto-withdrawals-after-48-million-hot-wallet-breach/

BtcTurk, a Turkish cryptocurrency exchange, has paused cryptocurrency withdrawals after detecting suspicious transactions in its hot wallets.

The exchange said trading and local currency operations are still available, but all crypto deposits and withdrawals are on hold.

Cyvers, a blockchain security company, reported on August 14 that about $48 million in digital assets was being moved in an unusual pattern. The transfers, which involved Ethereum
ETH


$4,413.16

, Avalanche
AVAX


$24.14

, Arbitrum
ARB


$0.4928

, Optimism
OP


$0.7336

, Polygon
MATIC


$0.2368

, Mantle, and Base networks, were sent to two wallets before being swapped.

Harmony ONE Explained (Beginner-Friendly Animation)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

BtcTurk explained that the activity was found during routine checks. The exchange said:

During inspections conducted on August 14, 2025, unusual activity was detected in our hot wallets. As a precautionary measure, cryptocurrency deposits and withdrawals have been temporarily suspended.

Cyvers stated that most of its reserves are held in cold wallets, which are offline and not affected by the suspected breach. It also confirmed that law enforcement has been notified and that additional security steps are in progress.

Lookonchain reported that at least $23 million was taken, while CertiK put the number at no less than $50 million.

Lookonchain added that the attacker has started converting part of the stolen tokens into Ethereum. CertiK identified three wallets linked to the stolen funds: two Ethereum addresses, 0x7D91D1 and 0xA041Fe, and one Solana address, 9sjdD9Xg.

The crypto exchange Coinbase recently confirmed losing around $300,000 in tokens. What happened? Read the full story.

]]>
https://earlybirdsinvest.com/btcturk-freezes-crypto-withdrawals-after-48-million-hot-wallet-breach/feed/ 0 53544
North Korean Kimsuky hackers exposed in alleged data breach https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/ https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/#respond Tue, 12 Aug 2025 09:30:51 +0000 https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/

North Korea

The North Korean state-sponsored hackers known as Kimsuky has reportedly suffered a data breach after two hackers, who describe themselves as the opposite of Kimsuky’s values, stole the group’s data and leaked it publicly online.

The two hackers, named ‘Saber’ and ‘cyb0rg,’ cited ethical reasons for their actions, saying Kimsuky is “hacking for all the wrong reasons,” claiming they’re driven by political agendas and follow regime orders instead of practicing the art of hacking independently.

“Kimsuky, you are not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda,” reads the hackers’ address to Kimsuky published in the latest issue of Phrack, which was distributed at the DEF CON 33 conference.

“You steal from others and favour your own. You value yourself above the others: You are morally perverted.”

The hackers dumped a portion of Kimsuky’s backend, exposing both their tooling and some of their stolen data that could provide insight into unknown campaigns and undocumented compromises.

The 8.9GB dump currently hosted on the ‘Distributed Denial of Secrets” website contains, among others:

  • Phishing logs with multiple dcc.mil.kr (Defense Counterintelligence Command) email accounts.
  • Other targeted domains: spo.go.kr, korea.kr, daum.net, kakao.com, naver.com.
  • .7z archive containing the complete source code of South Korea’s Ministry of Foreign Affairs email platform (“Kebi”), including webmail, admin, and archive modules.
  • References to South Korean citizen certificates and curated lists of university professors.
  • PHP “Generator” toolkit for building phishing sites with detection evasion and redirection tricks.
  • Live phishing kits.
  • Unknown binary archives (voS9AyMZ.tar.gz, Black.x64.tar.gz) and executables (payload.bin, payload_test.bin, s.x64.bin) not flagged in VirusTotal.
  • Cobalt Strike loaders, reverse shells, and Onnara proxy modules found in VMware drag-and-drop cache.
  • Chrome history and configs linking to suspicious GitHub accounts (wwh1004.github.io, etc.), VPN purchases (PureVPN, ZoogVPN) via Google Pay, and frequent use of hacking forums (freebuf.com, xaker.ru).
  • Google Translate use for Chinese error messages and visits to Taiwan government and military sites.
  • Bash history with SSH connections to internal systems.

The hackers note that some of the above are already known or previously documented, at least partially.

However, the dump gives a new dimension to the data and provides interlinking between Kimsuky’s tools and activities, exposing and effectively “burning” the APT’s infrastructure and methods.

BleepingComputer has contacted various security researchers to confirm the veracity of the leaked documents and its value and will update the story if we receive a response.

While the breach will likely not have long-term impact on Kimsuky’s operations, it could lead to operational difficulties for Kimsuky and disruptions to ongoing campaigns.

The latest issue of Phrack (#72) is currently only available in a limited physical copy, but the online version should be ready for people to read for free in the following days from here.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/feed/ 0 52797
Google confirms data breach exposed potential Google Ads customers’ info https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/ https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/#respond Mon, 11 Aug 2025 01:20:14 +0000 https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/

Google Ads

Google has confirmed that a recently disclosed data breach of one of its Salesforce CRM instances involved the information of potential Google Ads customers.

“We’re writing to let you know about an event that affected a limited set of data in one of Google’s corporate Salesforce instances used to communicate with prospective Ads customers,” reads a data breach notification shared with BleepingComputer.

“Our records indicate basic business contact information and related notes were impacted by this event.”

Google says the exposed information includes business names, phone numbers, and “related notes” for a Google sales agent to contact them again.

The company says that payment information was not exposed and that there is no impact on Ads data in Google Ads Account, Merchant Center, Google Analytics, and other Ads products.

The breach was conducted by threat actors known as ShinyHunters, who have been behind an ongoing wave of data theft attacks targeting Salesforce customers.

While Google has not shared how many individuals were impacted, ShinyHunters says the stolen information contains approximately 2.55 million data records. It is unclear if there are duplicates within these records.

ShinyHunters further told BleepingComputer that they are also working with threat actors associated with “Scattered Spider, who are responsible for first gaining initial access to targeted systems.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

The threat actors are now referring to themselves as “Sp1d3rHunters,” to illustrate the overlapping group of people who are involved in these attacks.

As part of these attacks, the threat actors conduct social engineering attacks against employees to gain access to credentials or trick them into linking a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

The threat actors then download the entire Salesforce database and extort the companies via email, threatening to release the stolen data if a ransom is not paid.

These Salesforce attacks were first reported by the Google Threat Intelligence Group (GTIG) in June, with the company suffering the same fate a month later.

Databreaches.net reported that the threat actors have already sent an extortion demand to Google. After publishing the story, ShinyHunters told BleepingComputer that they demanded 20 Bitcoins, or approximately $2.3 million, from Google to not leak the data.

“I don’t care about ransoming Google anyway, I just sent them a bogus email for the lulz of it,” said the threat actor.

ShinyHunters says they have since switched to a new custom tool that makes it easier and quicker to steal data from compromised Salesforce instances.

In an update, Google recently acknowledged the new tooling, stating that they have seen Python scripts used in the attacks instead of the Salesforce Data Loader.

Update 8/9/25: Added further information about the extortion demand.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/google-confirms-data-breach-exposed-potential-google-ads-customers-info/feed/ 0 52579
Columbia University data breach impacts nearly 870,000 individuals https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/ https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/#respond Fri, 08 Aug 2025 08:58:24 +0000 https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/

Columbia University

​An unknown threat actor has stolen the sensitive personal, financial, and health information of nearly 870,000 Columbia University current and former students and employees after breaching the university’s network in May.

Established in 1767 as King’s College, Columbia University is a private Ivy League research university with a budget of $6.6 billion in 2024, over 20,000 employees, including 4,700 academic staff, and over 35,000 enrolled students across 19 schools and special programs.

The breach was discovered and reported to law enforcement authorities following an outage that affected some of its systems on June 24, following an investigation with support from external cybersecurity experts.

In notification letters filed with the office of Maine’s Attorney General on Thursday, August 7, the university said that the data breach affects 868,969 individuals, including employees, applicants, current and former students, and family members.

“Our investigation determined that, on or about May 16, 2025, an unauthorized third-party gained access to Columbia’s network and subsequently took certain files from our system,” Columbia University said. “To date, we have no evidence that any Columbia University Irving Medical Center patient records were affected.”

The university first confirmed the data theft last week in a statement, following reports that the alleged hacker claimed to have stolen 460 gigabytes of data from the compromised systems.

On Wednesday, the university issued another statement, confirming that the stolen data belongs to current and former students, applicants, and some Columbia employees.

According to the letters sent to affected individuals via the U.S. Postal Service, the stolen data includes a combination of personal, financial, and health information.

“The affected data included your name, date of birth, and Social Security number, as well as any personal information that you provided in connection with your application to Columbia, or that we collected during your studies if you enrolled,” the university added.

“This included your contact details, demographic information, academic history, financial aid-related information, and any insurance-related information and health information that you shared with us.”

While Columbia University has no evidence that the data has been misused in identity theft or fraud attempts, it will provide two years of free credit monitoring, fraud consultation, and identity theft restoration services through Kroll to those impacted by this data breach.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/feed/ 0 52124
Pi-hole discloses data breach via GiveWp WordPress plugin flaw https://earlybirdsinvest.com/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/ https://earlybirdsinvest.com/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/#respond Fri, 01 Aug 2025 16:18:43 +0000 https://earlybirdsinvest.com/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/

Pi-hole

Pi-hole, a popular network-level ad-blocker, has disclosed that donor names and email addresses were exposed through a security vulnerability in the GiveWP WordPress donation plugin.

Pi-hole acts as a DNS sinkhole, filtering out unwanted content before it reaches the users’ devices. While initially designed to run on Raspberry Pi single-board computers, it now supports various Linux systems on dedicated hardware or virtual machines.

The organization stated that they first learned of the incident on Monday, July 28, after donors began reporting that they were receiving suspicious emails at addresses used exclusively for donations.

As explained in a Friday post-mortem, the breach affected users who donated through the Pi-hole website’s donation form to support development, exposing personal information that was visible to anyone who viewed the webpage’s source code due to a GiveWP security flaw.

The vulnerability stemmed from GiveWP, a WordPress plugin used to process donations on the Pi-hole website. The plugin inadvertently made donor information publicly accessible without requiring authentication or special access privileges.

While Pi-hole didn’t disclose the number of affected customers, the ‘Have I Been Pwned’ data breach notification service added the Pi-hole breach, saying that it impacted almost 30,000 donors, with 73% of the exposed records already in its database.

https://bsky.app/profile/haveibeenpwned.com/post/3lvca3viu322x

No financial information exposed

Pi-hole added that no donor financial data was compromised, as credit card information and other payment details are handled directly by Stripe and PayPal. It also clarified that the Pi-hole software product itself was not affected in any way.

“We make it clear in the donation form that we don’t even require a valid name or email address, it’s purely for users to see and manage their donations,” Pi-hole said. “It is also important to note that Pi-hole the product is categorically not the subject of this breach. There is no action needed from users with a Pi-hole installed on their network.”

Although GiveWP released a patch within hours of the vulnerability being reported on GitHub, Pi-hole criticized the plugin developer’s response, citing a 17.5-hour delay before notifying users and what it described as insufficient acknowledgment of the security flaw’s potential impact on donor names and email addresses.

Pi-hole apologized to affected donors and acknowledged potential reputation damage stemming from this security incident, saying that while the vulnerability was unforeseeable, they accept accountability for the resulting data breach.

“The names and email addresses of anyone that had ever donated via our donation page was there for the entire world to see (provided they were savvy enough to right click->View page source). Within a couple of hours of this report, they had patched the bad code and released 4.6.1,” Pi-hole added in a blog post analyzing the incident.

“We take full responsibility for the software we deploy. We placed our trust in a widely-used plugin, and that trust was broken.”

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/pi-hole-discloses-data-breach-via-givewp-wordpress-plugin-flaw/feed/ 0 50899
Major Breach Study Reveals Widespread Leaks of Bank Statements, SSNs, and Crypto Keys https://earlybirdsinvest.com/major-breach-study-reveals-widespread-leaks-of-bank-statements-ssns-and-crypto-keys/ https://earlybirdsinvest.com/major-breach-study-reveals-widespread-leaks-of-bank-statements-ssns-and-crypto-keys/#respond Tue, 29 Jul 2025 12:15:17 +0000 https://earlybirdsinvest.com/major-breach-study-reveals-widespread-leaks-of-bank-statements-ssns-and-crypto-keys/

Crypto Journalist

Amin Ayan

Crypto Journalist

Amin Ayan

About Author

Amin Ayan is a crypto journalist with over four years of experience in the industry. He has contributed to leading publications such as Cryptonews, Investing.com, 99Bitcoins, and 24/7 Wall St. He has…

Last updated: 


Why Trust Cryptonews

Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas – from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

A new study has revealed the extent of sensitive information leaked through ransomware attacks and data breaches, including key financial documents and crypto keys.

Key Takeaways:

  • Unstructured files like financial documents and crypto keys are being widely exposed in breaches.
  • Cryptographic keys were found in 18% of incidents, posing serious security risks.
  • Cybercriminals are mining breached data like data scientists, targeting high-value information.

The report, published by cybersecurity firm Lab 1, analyzed over 141 million records from 1,297 breach incidents.

Unlike most breach assessments that focus on structured data like usernames and passwords, Lab 1’s analysis targeted unstructured files, the type often overlooked but potentially more damaging.

Hidden Dangers: Financial Docs, Crypto Keys, and Emails Exposed

The breaches include financial documents, cryptographic keys, email archives, and internal business records.

According to Lab 1 CEO Robin Brattel, the goal was to expose the risks hidden in everyday files that rarely draw attention.

“We focused on the huge risks associated with unstructured files that often hold high-value information, such as cryptographic keys, customer account data, or sensitive commercial contracts,” he said.

The findings are alarming. Financial documents appeared in 93% of the breach incidents studied, accounting for 41% of all analyzed files.

Nearly half included bank statements, and over a third contained International Bank Account Numbers.

In 82% of the cases, customer or corporate personally identifiable information (PII) was exposed, much of it originating from customer service interactions.

A staggering 51% of incidents included emails containing U.S. Social Security numbers.

Perhaps most concerning was the discovery of cryptographic keys in 18% of the breaches.

These keys can be used to bypass authentication systems, giving attackers a powerful advantage in future cyber intrusions. Source code and internal scripts were also widely leaked, appearing in 17% of the analyzed data sets.

The study underscores a shift in cybercriminal tactics. Hackers are increasingly operating like data scientists, mining stolen data for high-value assets to use in fraud, identity theft, or ransomware follow-ups.

“With cybercriminals now behaving like data scientists to unearth these valuable insights to fuel cyberattacks and fraud, unstructured data cannot be ignored,” Brattel warned.

16 Billion Logins Leaked: New Mega Breach Puts Crypto Users at Risk

Last month, a massive data breach exposed more than 16 billion login credentials from platforms like Apple, Google, Facebook, Telegram, and GitHub, according to cybersecurity researchers at Cybernews.

The breach, among the largest ever recorded, is not a single leak but a combination of datasets gathered through infostealer malware, credential stuffing attacks, and undisclosed breaches tracked since early 2024. Some individual sets held as many as 3.5 billion entries.

Researchers warned the leaked credentials—many recently harvested—pose a severe threat to users, especially those in crypto, due to the inclusion of sensitive login details, cookies, and tokens.

The structure of the data suggests it was harvested by modern malware, making it far more dangerous than older, recycled leaks.

One dataset tied to Telegram included 60 million records, while another, allegedly linked to Russia, had over 455 million.

Much of the data was found in unsecured Elasticsearch databases and object storage systems, briefly exposed but long enough to be copied.

Although the exact source remains unclear, cybersecurity experts suspect criminal actors compiled the records.

With such a vast trove of credentials, attackers now have tools for phishing, ransomware, and unauthorized access to crypto wallets, especially for users lacking multi-factor authentication.


]]>
https://earlybirdsinvest.com/major-breach-study-reveals-widespread-leaks-of-bank-statements-ssns-and-crypto-keys/feed/ 0 50305
Allianz Life confirms data breach impacts majority of 1.4 million customers https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/ https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/#respond Sun, 27 Jul 2025 07:36:22 +0000 https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/

Allianz logo

Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

“The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life’s customers, financial professionals, and select Allianz Life employees, using a social engineering technique.”

“We took immediate action to contain and mitigate the issue and notified the FBI. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed, including our policy administration system.”

“Our investigation is ongoing and we began the process of reaching out to individuals impacted with dedicated resources to assist them. This incident is related only to Allianz Life, which currently has 1.4 million customers.”

Allianz Life is a US-based provider of annuities and life insurance for over 1.4 million Americans. The company is owned by Allianz SE, a global financial services group headquartered in Germany, serving more than 128 million customers.

The company first revealed the breach in a mandatory filing with Maine’s Attorney General’s Office on Saturday, issuing a placeholder notification alerting of the breach.

“The consumer notice will be provided once Allianz has identified the affected individuals,” reads the placeholder notification.

While Allianz Life declined to answer questions about the threat actor and whether they were being extorted, BleepingComputer has learned that the attack is believed to have been conducted by the ShinyHunters extortion group.

ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against PowerSchool and the SnowFlake attacks, which impacted Santander, Ticketmaster, AT&T, Advance Auto Parts, Neiman Marcus, and Cylance.

While multiple ShinyHunters members have been arrested over the past few years, including a recent arrest in France, the hacking group continues to conduct attacks.

Last month, Mandiant warned that ShinyHunters had begun to target Salesforce CRM customers in social engineering attacks.

During these attacks, the hackers impersonate IT support personnel, requesting the targeted employee accept a connection to Salesforce Data Loader, a client application that allows users to import, export, update, or delete data within Salesforce environments.

Once the connection is accepted, the threat actors use Salesforce Data Loader to exfiltrate data from Salesforce, which is then used to extort the company.

BleepingComputer asked Allianz Life if the CRM is Salesforce, but the spokesperson declined to comment.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/feed/ 0 49912
$10,000 To Be Handed To US Bank’s Customers After ‘Extraordinary Losses’ Allegedly Triggered by Data Breach https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/ https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/#respond Sat, 26 Jul 2025 02:10:33 +0000 https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/

A US bank has agreed to pay up to $10,000 to customers affected by an alleged data breach that exposed personally identifying information.

According to a settlement administrator’s portal, The Bank of Canton will pay $300,000 to settle a lawsuit accusing the Canton, Massachusetts-based lender of negligent data security practices.

Class members in the lawsuit, defined as the existing, former and prospective clients of The Bank of Canton in the US impacted by the cybersecurity incident, will receive up to $2,500 for ordinary losses and up to $10,000 for extraordinary losses.

Claimants must provide documentation to prove the losses they suffered as a result of the data breach. Class members who choose not to file documentary evidence can opt for an alternative cash payment of $100.

Claims must be submitted by October 9th, with a final approval hearing for the settlement scheduled to be held in a Massachusetts court on October 21st. Payments will be made once the settlement is approved by a judge.

The Bank of Canton is settling the lawsuit a little over a year after the incident occurred. On or around May 27th of 2023, cybercriminals allegedly gained access to MOVEit Transfer, a file transfer software system used by a third-party service provider of the bank.

The lawsuit alleged the incident led to the sensitive data of the Bank of Canton’s customers, potentially including, account name, account number(s), and Social Security numbers being exposed. The lawsuit was subsequently filed in November of 2023.

Despite agreeing to settle, The Bank of Canton denies the allegations made in the lawsuit.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/10000-to-be-handed-to-us-banks-customers-after-extraordinary-losses-allegedly-triggered-by-data-breach/feed/ 0 49703