Impacts – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 25 Aug 2025 19:29:05 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Impacts – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Farmers Insurance data breach impacts 1.1M people after Salesforce attack https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/ https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/#respond Mon, 25 Aug 2025 19:29:05 +0000 https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/

Farmers Insurance sign

U.S. insurance giant Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with BleepingComputer learning that the data was stolen in the widespread Salesforce attacks.

Farmers Insurance is a U.S.-based insurer that provides auto, home, life, and business insurance products. It operates through a network of agents and subsidiaries, serving more than 10 million households nationwide.

The company disclosed the data breach in an advisory on its website, saying that its database at a third-party vendor was breached on May 29, 2025.

“On May 30, 2025, one of Farmers’ third-party vendors alerted Farmers to suspicious activity involving an unauthorized actor accessing one of the vendor’s databases containing Farmers customer information (the “Incident”),” reads the data breach notification on its website.

“The third-party vendor had monitoring tools in place, which allowed the vendor to quickly detect the activity and take appropriate containment measures, including blocking the unauthorized actor. After learning of the activity, Farmers immediately launched a comprehensive investigation to determine the nature and scope of the Incident and notified appropriate law enforcement authorities.”

The company says that its investigation determined that customers’ names, addresses, dates of birth, driver’s license numbers, and/or last four digits of Social Security numbers were stolen during the breach.

Farmers began sending data breach notifications to impacted individuals on August 22, with a sample notification [1, 2] shared with the Maine Attorney General’s Office, stating that a combined total of 1,111,386 customers were impacted.

While Farmers did not disclose the name of the third-party vendor, BleepingComputer has learned that the data was stolen in the widespread Salesforce data theft attacks that have impacted numerous organizations this year.

BleepingComputer contacted Farmers with additional questions about the breach and will update the story if we receive a response.

The Salesforce data theft attacks

Since the beginning of the year, threat actors classified as ‘UNC6040’ or ‘UNC6240’ have been conducting social engineering attacks on Salesforce customers.

During these attacks, threat actors conduct voice phishing (vishing) to trick employees into linking a malicious OAuth app with their company’s Salesforce instances.

Once linked, the threat actors used the connection to download and steal the databases, which were then used to extort the company through email.

The extortion demands come from the ShinyHunters cybercrime group, who told BleepingComputer that the attacks involve multiple overlapping threat groups, with each group handling specific tasks to breach Salesforce instances and steal data.

“Like we have said repeatedly already, ShinyHunters and Scattered Spider are one and the same,” ShinyHunters told BleepingComputer.

“They provide us with initial access and we conduct the dump and exfiltration of the Salesforce CRM instances. Just like we did with Snowflake.”

Other companies impacted in these attacks include Google, Cisco, Workday, Adidas, Qantas, Allianz Life, and the LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

 

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/farmers-insurance-data-breach-impacts-1-1m-people-after-salesforce-attack/feed/ 0 55095
Columbia University data breach impacts nearly 870,000 individuals https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/ https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/#respond Fri, 08 Aug 2025 08:58:24 +0000 https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/

Columbia University

​An unknown threat actor has stolen the sensitive personal, financial, and health information of nearly 870,000 Columbia University current and former students and employees after breaching the university’s network in May.

Established in 1767 as King’s College, Columbia University is a private Ivy League research university with a budget of $6.6 billion in 2024, over 20,000 employees, including 4,700 academic staff, and over 35,000 enrolled students across 19 schools and special programs.

The breach was discovered and reported to law enforcement authorities following an outage that affected some of its systems on June 24, following an investigation with support from external cybersecurity experts.

In notification letters filed with the office of Maine’s Attorney General on Thursday, August 7, the university said that the data breach affects 868,969 individuals, including employees, applicants, current and former students, and family members.

“Our investigation determined that, on or about May 16, 2025, an unauthorized third-party gained access to Columbia’s network and subsequently took certain files from our system,” Columbia University said. “To date, we have no evidence that any Columbia University Irving Medical Center patient records were affected.”

The university first confirmed the data theft last week in a statement, following reports that the alleged hacker claimed to have stolen 460 gigabytes of data from the compromised systems.

On Wednesday, the university issued another statement, confirming that the stolen data belongs to current and former students, applicants, and some Columbia employees.

According to the letters sent to affected individuals via the U.S. Postal Service, the stolen data includes a combination of personal, financial, and health information.

“The affected data included your name, date of birth, and Social Security number, as well as any personal information that you provided in connection with your application to Columbia, or that we collected during your studies if you enrolled,” the university added.

“This included your contact details, demographic information, academic history, financial aid-related information, and any insurance-related information and health information that you shared with us.”

While Columbia University has no evidence that the data has been misused in identity theft or fraud attempts, it will provide two years of free credit monitoring, fraud consultation, and identity theft restoration services through Kroll to those impacted by this data breach.

Picus Red Report 2025

Malware targeting password stores surged 3X as attackers executed stealthy Perfect Heist scenarios, infiltrating and exploiting critical systems.

Discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/columbia-university-data-breach-impacts-nearly-870000-individuals/feed/ 0 52124
Allianz Life confirms data breach impacts majority of 1.4 million customers https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/ https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/#respond Sun, 27 Jul 2025 07:36:22 +0000 https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/

Allianz logo

Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

“The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life’s customers, financial professionals, and select Allianz Life employees, using a social engineering technique.”

“We took immediate action to contain and mitigate the issue and notified the FBI. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed, including our policy administration system.”

“Our investigation is ongoing and we began the process of reaching out to individuals impacted with dedicated resources to assist them. This incident is related only to Allianz Life, which currently has 1.4 million customers.”

Allianz Life is a US-based provider of annuities and life insurance for over 1.4 million Americans. The company is owned by Allianz SE, a global financial services group headquartered in Germany, serving more than 128 million customers.

The company first revealed the breach in a mandatory filing with Maine’s Attorney General’s Office on Saturday, issuing a placeholder notification alerting of the breach.

“The consumer notice will be provided once Allianz has identified the affected individuals,” reads the placeholder notification.

While Allianz Life declined to answer questions about the threat actor and whether they were being extorted, BleepingComputer has learned that the attack is believed to have been conducted by the ShinyHunters extortion group.

ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against PowerSchool and the SnowFlake attacks, which impacted Santander, Ticketmaster, AT&T, Advance Auto Parts, Neiman Marcus, and Cylance.

While multiple ShinyHunters members have been arrested over the past few years, including a recent arrest in France, the hacking group continues to conduct attacks.

Last month, Mandiant warned that ShinyHunters had begun to target Salesforce CRM customers in social engineering attacks.

During these attacks, the hackers impersonate IT support personnel, requesting the targeted employee accept a connection to Salesforce Data Loader, a client application that allows users to import, export, update, or delete data within Salesforce environments.

Once the connection is accepted, the threat actors use Salesforce Data Loader to exfiltrate data from Salesforce, which is then used to extort the company.

BleepingComputer asked Allianz Life if the CRM is Salesforce, but the spokesperson declined to comment.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/feed/ 0 49912
How The Merge Impacts Ethereum’s Application Layer https://earlybirdsinvest.com/how-the-merge-impacts-ethereums-application-layer/ https://earlybirdsinvest.com/how-the-merge-impacts-ethereums-application-layer/#respond Wed, 28 May 2025 17:26:57 +0000 https://earlybirdsinvest.com/how-the-merge-impacts-ethereums-application-layer/

Ethereum’s transition to proof of stake — The Merge — is near: devnets are being stood up, specifications are being finalized and community outreach has begun in earnest. The Merge is designed to have minimal impact on how Ethereum operates for end users, smart contracts and dapps. That said, there are some minor changes worth highlighting. Before we dive into them, here are a few links to provide context about the overall Merge architecture:


The rest of this post will assume the reader is familiar with the above. For those wanting to dig even deeper, the full specifications for The Merge are available here:


Block structure

After The Merge, proof of work blocks will no longer exist on the network. Instead, the former contents of proof of work blocks become a component of blocks created on the Beacon Chain. You can then think of the Beacon Chain as becoming the new proof of stake consensus layer of Ethereum, superseding the previous proof of work consensus layer. Beacon chain blocks will contain ExecutionPayloads, which are the post-merge equivalent of blocks on the current proof of work chain. The image below shows this relationship:

For end users and application developers, these ExecutionPayloads are where interactions with Ethereum happen. Transactions on this layer will still be processed by execution layer clients (Besu, Erigon, Geth, Nethermind, etc.). Fortunately, due to the stability of the execution layer, The Merge introduces only minimal breaking changes.

Mining & Ommer Block Fields

Post-merge, several fields previously contained in proof of work block headers become unused as they are irrelevant to proof of stake. In order to minimize disruption to tooling and infrastructure, these fields are set to 0, or their data structure’s equivalent, rather than being entirely removed from the data structure. The full changes to block fields can be found in EIP-3675.

Field Constant value Comment
ommers [] RLP([]) = 0xc0
ommersHash 0x1dcc4de8dec75d7aab85b567b6ccd41ad312451b948a7413f0a142fd40d49347 = Keccak256(RLP([]))
difficulty 0
nonce 0x0000000000000000

Because proof of stake does not naturally produce ommers (a.k.a. uncle blocks) like proof of work, the list of these in each block (ommers) will be empty, and the hash of this list (ommersHash) will become the RLP-encoded hash of an empty list. Similarly, because difficulty and nonce are features of proof of work, these will be set to 0, while respecting their byte-size values.

mixHash, another mining-related field, won’t be set to 0 but will instead contain the beacon chain’s RANDAO value. More on this below.

BLOCKHASH & DIFFICULTY opcodes changes

Post-merge, the BLOCKHASH opcode will still be available for use, but given that it will no longer be forged through the proof of work hashing process, the pseudorandomness provided by this opcode will be much weaker.

Relatedly, the DIFFICULTY opcode (0x44) will be updated and renamed to PREVRANDAO. Post-merge, it will return the output of the randomness beacon provided by the beacon chain. This opcode will thus be a stronger, albeit still biasable, source of randomness for application developers to use than BLOCKHASH.

The value exposed by PREVRANDAO will be stored in the ExecutionPayload where mixHash, a value associated with proof of work computation, was stored. The payload’s mixHash field will also be renamed prevRandao.

Here is an illustration of how the DIFFICULTY & PREVRANDAO opcodes work pre and post-merge:

Pre-merge, we see the 0x44 opcode returns the difficulty field in the block header. Post-merge, the opcode, renamed to PREVRANDAO, points to the header field which previously contained mixHash and now stores the prevRandao value from the beacon chain state.

This change, formalized in EIP-4399, also provides on-chain applications a way to assess whether The Merge has happened. From the EIP:

Additionally, changes proposed by this EIP allow for smart contracts to determine whether the upgrade to the PoS has already happened. This can be done by analyzing the return value of the DIFFICULTY opcode. A value greater than 2**64 indicates that the transaction is being executed in the PoS block.

Block time

The Merge will impact the average block time on Ethereum. Currently under proof of work, blocks come in on average every ~13 seconds with a fair amount of variance in actual block times. Under proof of stake, blocks come in exactly each 12 seconds except when a slot is missed either because a validator is offline or because they do not submit a block in time. In practice, this currently happens in <1% of slots.

This implies a ~1 second reduction of average block times on the network. Smart contracts which assume a particular average block time in their calculations will need to take this into account.

Finalized Blocks & Safe Head

Under proof of work there is always the potential for reorgs. Applications usually wait for several blocks to be mined on top of a new head before treating it as unlikely to be removed from the canonical chain, or “confirmed”. After The Merge, we instead have the concepts of finalized blocks and safe head exposed on the execution layer. These blocks can be used more reliably than the “confirmed” proof of work blocks but require a shift in understanding to use correctly.

A finalized block is one which has been accepted as canonical by >2/3 of validators. To create a conflicting block, an attacker would have to burn at least 1/3 of the total staked ether. While stake amounts may vary, such an attack is always expected to cost the attacker millions of ETH.

A safe head block is one which has been justified by the Beacon Chain, meaning that >2/3 of validators have attested to it. Under normal network conditions, we expect it to be included in the canonical chain and eventually finalized. For this block to not be part of the canonical chain, a majority of validators would need to be colluding to attack the network, or the network would have to be experiencing extreme levels of latency in block propagation. Post-merge, execution layer APIs (e.g. JSON RPC) will expose the safe head using a safe tag.

Finalized blocks will also be exposed via JSON RPC, via a new finalized flag. These can then serve as a stronger substitute for proof of work confirmations. The table below summarizes this:

Block Type Consensus Mechanism JSON RPC Conditions for reorg
head Proof of Work latest To be expected, must be used with care.
safe head Proof of Stake safe Possible, requires either large network delay or attack on network.
confirmed Proof of Work N/A Unlikely, requires a majority of hashrate to mine a competing chain of depth > # of confirmations.
finalized Proof of Stake finalized Extremely unlikely, requires >2/3 of validators to finalize a competing chain, requiring at least 1/3 to be slashed.

Note: the JSON RPC specification is still under active development. Naming changes should still be expected.

Next Steps

We hope this post helps application developers prepare for the much-anticipated transition to proof of stake. In the next few weeks, a long-lived testnet will be made available for testing by the broader community. There is also an upcoming Merge community call for infrastructure, tooling and application developers to ask questions and hear the latest technical updates about The Merge. See you there 👋🏻


Thank you to Mikhail Kalinin, Danny Ryan & Matt Garnett for reviewing drafts of this post.

]]>
https://earlybirdsinvest.com/how-the-merge-impacts-ethereums-application-layer/feed/ 0 38807
Port of Seattle says ransomware breach impacts 90,000 people https://earlybirdsinvest.com/port-of-seattle-says-ransomware-breach-impacts-90000-people/ https://earlybirdsinvest.com/port-of-seattle-says-ransomware-breach-impacts-90000-people/#respond Sat, 05 Apr 2025 08:46:51 +0000 https://earlybirdsinvest.com/port-of-seattle-says-ransomware-breach-impacts-90000-people/

Port of Seattle

​Port of Seattle, the U.S. government agency overseeing Seattle’s seaport and airport, is notifying roughly 90,000 individuals of a data breach after their personal information was stolen in an August 2024 ransomware attack.

The agency disclosed the attack on August 24, saying the resulting IT outage disrupted multiple services and systems, including reservation check-in systems, passenger display boards, the Port of Seattle website, the flySEA app, and delayed flights at Seattle-Tacoma International Airport.

Three weeks after the initial disclosure, the Port confirmed that the Rhysida ransomware operation was behind the August 2024 breach.

After the incident, the Port also decided not to give in to the cybercriminals’ demands to pay for a decryptor even though they threatened to publish stolen data on their dark web leak site.

“We have refused to pay the ransom demanded, and as a result, the actor may respond by posting data they claim to have stolen on their darkweb site,” the Port of Seattle said on September 13, 2024.

“Our investigation of what data the actor took is ongoing, but it does appear that some Port data was obtained by the actor in mid-to-late August. Assessment of the data taken is complex and takes time.”

SEA tweet

​Data breach impacts roughly 90,000 people

On Thursday, April 3, 2025, the Port announced that it’s now sending approximately 90,000 notification letters to individuals impacted by the resulting data breach who had a mailing address. According to the agency, roughly 71,000 of those affected by this data breach are from Washington state.

According to a copy of the breach notification letters, the attackers stole employee, contractor, and parking data in various combinations, including names, dates of birth, Social Security numbers (or last four digits of Social Security number), driver’s license or other government identification card numbers, and some medical information.

The Port also said that it stores “very little information” on airport or maritime passengers and that its payment processing systems were unaffected by the attack.

“At no point did this incident affect the ability to safely travel to or from SEA Airport or use the Port’s maritime facilities,” the Port added this week. “The proprietary systems of major airline and cruise partners were not affected, nor were the systems of federal partners like the Federal Aviation Administration, Transportation Security Administration, and U.S. Customs and Border Protection.”

Rhysida, the ransomware-as-a-service (RaaS) operation behind the Port of Seattle attack, surfaced in May 2023 and quickly gained notoriety after breaching the British Library, the Chilean Army (Ejército de Chile), the City of Columbus, Ohio, Sony subsidiary Insomniac Games, and MarineMax (the world’s largest recreational boat and yacht retailer).

Its affiliates also breached Singing River Health System, which warned almost 900,000 people that their personal and health information had been stolen in an August 2023 Rhysida ransomware attack.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/port-of-seattle-says-ransomware-breach-impacts-90000-people/feed/ 0 29115
Potential Impacts of a Trump Presidency on the Web3 Gaming Industry https://earlybirdsinvest.com/potential-impacts-of-a-trump-presidency-on-the-web3-gaming-industry/ https://earlybirdsinvest.com/potential-impacts-of-a-trump-presidency-on-the-web3-gaming-industry/#respond Sat, 01 Mar 2025 22:15:17 +0000 https://earlybirdsinvest.com/potential-impacts-of-a-trump-presidency-on-the-web3-gaming-industry/

The Trump election victory has caused a stir across many industries, and Web3 is no exception. With a history of policy changes and evolving views on digital assets, a Trump presidency could have a big impact on Web3 gaming, which is the epicenter of innovation, community building and digital ownership.

Trump’s Web3 views

Donald Trump’s views on Web3 have changed. Back in 2021, he initially called Bitcoin a “scam” and worried about it disrupting the US dollar. However, his stance has changed drastically since then, and his administration is getting more crypto-friendly. This aligns with the global trend of blockchain integration and crypto-friendly laws in many countries. By relaxing regulations, Trump’s administration might look to encourage more innovation in Web3 gaming, which relies on blockchain and cryptocurrencies for digital ownership and in-game economies.

The Trump administration has promised to look at policies that support the blockchain industry. Web3 gaming would benefit greatly from this recognition, especially as regulatory clarity is key to innovation. As Web3 gaming relies on tokenized economies, less restrictions will allow developers and players to engage more freely without fear of legal consequences or regulatory barriers.

Trump’s Web3 History

During Trump’s first term, the crypto market went through growth, correction and growth again:

2017: Bitcoin went from around $1,000 to nearly $20,000, and Ethereum from $8 to over $700. Market cap went from $17 billion to over $600 billion.

2018: A big correction, Bitcoin went to $3,200 and Ethereum to $130 and market cap went to around $130 billion.

2019: The market stabilized, Bitcoin ranged from $3,000 to $13,000 and Ethereum from $100 to $350. Market cap ranged from $100 billion to $300 billion.

2020: Despite the COVID pandemic, Bitcoin and Ethereum went up, closing at over $29,000 and $700 respectively and market cap went over $750 billion.

Trump’s views on SEC Chair Gary Gensler

One of Trump’s recent attacks was on SEC Chair Gary Gensler and his views on crypto regulation. Trump has said he will replace Gensler and appoint someone more crypto-friendly. For Web3 gaming, this will have big implications. With a more crypto-friendly SEC chair, gaming platforms that use cryptocurrency will have fewer regulatory hurdles, especially on token issuance and trading.

A pro-crypto SEC will also attract bigger investors to Web3 gaming, a space that has grown fast but has yet to gain mainstream acceptance. Reducing these regulatory hurdles will legitimize Web3 gaming’s in-game assets and create a path for Web3 games to reach new users and expand their digital economies.

Investment and Development

If Trump’s administration continues the pro-crypto approach, Web3 gaming will see a big surge in investment. As blockchain gaming is growing and has millions of users globally, having an administration that supports cryptocurrency development will mean a good investment climate. For example, more venture capital will accelerate the development of decentralized gaming platforms and create an environment for innovation.

A pro-crypto Trump administration might also encourage traditional gaming companies to explore blockchain integration and create collaborations that will bring Web3 gaming to the mainstream.

As the US shapes its crypto policy, other countries usually follow or take cues to shape their own regulatory approach. A US-friendly blockchain policy will make the country a digital innovation leader and will create international collaborations in Web3 gaming or conflicts in regulatory policies.

Conclusion

Trump back in the White House could be big for Web3 gaming. His administration is warming up to crypto and blockchain so a more friendly regulatory environment for digital assets is expected. That could mean more innovation and investment in Web3 gaming and growth in the space. New leadership at the SEC could also mean clearer guidelines and less uncertainty for devs and investors. As the US figures out its crypto policies, the global Web3 gaming landscape will likely shift, too, with international collaborations and market dynamics adjusting to the changes.

Editor’s note: This article was written with the assistance of AI. Edited and fact-checked by Owen Skelton.

]]>
https://earlybirdsinvest.com/potential-impacts-of-a-trump-presidency-on-the-web3-gaming-industry/feed/ 0 22709