Sensitive – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 22 Aug 2025 11:21:00 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Sensitive – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 FTX creditors sue Kroll for mishandling claims, exposing sensitive data https://earlybirdsinvest.com/ftx-creditors-sue-kroll-for-mishandling-claims-exposing-sensitive-data/ https://earlybirdsinvest.com/ftx-creditors-sue-kroll-for-mishandling-claims-exposing-sensitive-data/#respond Fri, 22 Aug 2025 11:20:59 +0000 https://earlybirdsinvest.com/ftx-creditors-sue-kroll-for-mishandling-claims-exposing-sensitive-data/

FTX creditors have launched a class action lawsuit against Kroll Restructuring Administration, the firm managing claims for the bankrupt crypto exchange.

The suit, filed on Aug. 20 by US-based Hall Attorneys, alleged that Kroll’s handling of claims for FTX, BlockFi, and Genesis customers caused financial harm and exposed sensitive information to cybercriminals.

According to the lawsuit, Kroll knew emails were unsafe, as it consistently warned about phishing risks after it suffered a data breach incident in August 2023.

At the time, an unauthorized party gained access to a Kroll employee’s mobile number, which allowed entry into Kroll’s systems and exposure of creditor data, including names, addresses, email contacts, and some FTX account balances.

However, the firm reportedly continued to send critical notices solely via email, leaving claimants vulnerable to scams and phishing attacks.

Notably, Sunil Kavuri, a prominent FTX creditor, confirmed that phishing emails have become a daily concern for the defunct exchange’s users. He noted receiving a fraudulent message containing his full name just hours before posting about it on X.

Meanwhile, the lawsuit claims Kroll’s approach also caused verification delays, lockouts, and, in certain cases, the loss of claims by FTX creditors.

Considering this, Nicholas Hall, the lead counsel on the case, urged FTX creditors to join the legal battle. According to him:

“All creditors are encouraged to participate; it’s for both US and Bahamas customer-creditors.”

He also pointed out that the suit seeks compensation for losses related to phishing attacks, delayed claims, and expunged filings. Hall said:

“[FTX creditors could get] monetary relief for eligible class members (for example, up to $750 or actual damages for California victims, but depends on class, residency, etc.).”

Beyond monetary relief, plaintiffs are demanding practical reforms, including multi-channel communications through both email and First-Class Mail, status-change notifications with mandatory response periods, a manual tax-form option, and stricter security controls for account changes, such as mailing verification codes before permitting updates.

Additional demands include deliverability safeguards and independent audits to strengthen data protection.

Mentioned in this article
]]>
https://earlybirdsinvest.com/ftx-creditors-sue-kroll-for-mishandling-claims-exposing-sensitive-data/feed/ 0 54531
Hackers Hit Centers for Medicare & Medicaid Services – 103,000 Americans Warned Names, Addresses, Provider Records and Other Sensitive Data at Risk https://earlybirdsinvest.com/hackers-hit-centers-for-medicare-medicaid-services-103000-americans-warned-names-addresses-provider-records-and-other-sensitive-data-at-risk/ https://earlybirdsinvest.com/hackers-hit-centers-for-medicare-medicaid-services-103000-americans-warned-names-addresses-provider-records-and-other-sensitive-data-at-risk/#respond Sun, 20 Jul 2025 11:09:13 +0000 https://earlybirdsinvest.com/hackers-hit-centers-for-medicare-medicaid-services-103000-americans-warned-names-addresses-provider-records-and-other-sensitive-data-at-risk/

A major cybersecurity incident has exposed sensitive personal and health records of tens of thousands of Americans.

In a notice, the Centers for Medicare & Medicaid Services (CMS) says 103,000 individuals across the United States with accounts on Medicare.gov are impacted by a data breach.

CMS says it discovered that user data had been compromised after receiving multiple complaints through its call center. According to the federal agency, hackers may have used information from external sources to collect data such as names, dates of birth, Medicare Beneficiary Identifiers, coverage start dates and ZIP codes to fraudulently create Medicare.gov accounts.

Once inside, the thieves gained access to more sensitive data, including provider details, mailing addresses, dates of service, diagnosis codes, services received and plan premiums.

“On May 2, 2025, representatives at our 1-800-MEDICARE call center flagged complaints from people with Medicare who had received a letter through the mail about the creation of a Medicare.gov account. However, these callers hadn’t created the accounts or asked anyone else to do it for them.

Noticing the similarities in the reports, we investigated further and discovered more cases of accounts created between 2023 and 2025 that matched this pattern. We quickly deactivated those accounts, while also launching a larger effort to find the bad actors who created them.”

The CMS is a federal agency under the U.S. Department of Health and Human Services tasked with overseeing the country’s healthcare programs, including Medicare, Medicaid, the Children’s Health Insurance Program and Health Insurance Marketplace.

The CMS is encouraging affected individuals to get a free credit report from each of the three major nationwide credit reporting companies. The agency also says that it hasn’t received any reports of identity fraud or improper use of personal information as a result of the incident.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/hackers-hit-centers-for-medicare-medicaid-services-103000-americans-warned-names-addresses-provider-records-and-other-sensitive-data-at-risk/feed/ 0 48690
Hackers Hit Krispy Kreme – 161,676 Americans Warned Social Security Numbers, Names, Drivers Licenses and Other Sensitive Data At Risk https://earlybirdsinvest.com/hackers-hit-krispy-kreme-161676-americans-warned-social-security-numbers-names-drivers-licenses-and-other-sensitive-data-at-risk/ https://earlybirdsinvest.com/hackers-hit-krispy-kreme-161676-americans-warned-social-security-numbers-names-drivers-licenses-and-other-sensitive-data-at-risk/#respond Sun, 29 Jun 2025 05:03:57 +0000 https://earlybirdsinvest.com/hackers-hit-krispy-kreme-161676-americans-warned-social-security-numbers-names-drivers-licenses-and-other-sensitive-data-at-risk/

Krispy Kreme is warning tens of thousands of Americans that they are now at risk of identity theft and fraud following a major cybersecurity incident.

In a new filing with the Office of the Maine Attorney General, the doughnut and coffeehouse giant says it has discovered a computer hack affecting 161,676 employees, former employees and members of their families.

In a statement, the firm says that an unknown actor gained unauthorized access to the retailer’s information technology systems, stealing multiple types of data.

According to Krispy Kreme, the attacker may have siphoned sensitive personal information, including names, Social Security numbers, dates of birth and driver’s license or state ID numbers. The thief may have also copied financial data such as financial account access records, credit or debit card entries, along with security codes, as well as usernames and passwords to financial accounts.

Other customer data that might have been seized include digital signatures, usernames and passwords, email addresses and passwords, biometric records, USCIS or Alien Registration Numbers, US military ID numbers, medical or health records and health insurance entries.

“On November 29, 2024, Krispy Kreme became aware of unauthorized activity on a portion of its information technology systems. Upon learning of the unauthorized activity, we immediately began taking steps to investigate, contain, and remediate the incident with the assistance of leading cybersecurity experts.

On May 22, 2025, our investigation into the incident determined that certain personal information was affected. There is no evidence that the information has been misused, and we are not aware of any reports of identity theft or fraud as a direct result of this incident.”

Krispy Kreme says it abruptly sent letters of notification to affected customers to provide more information about the cybersecurity incident, while offering free credit monitoring and identity protection services.

The firm says it is revamping its security protocols “to further protect the privacy of the data entrusted to us.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/hackers-hit-krispy-kreme-161676-americans-warned-social-security-numbers-names-drivers-licenses-and-other-sensitive-data-at-risk/feed/ 0 44742
64,000,000 T-Mobile Records Containing Highly Sensitive Customer Data Allegedly Leaked Online As Mobile Giant Refutes Attackers’ Claims https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/ https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/#respond Sat, 14 Jun 2025 11:24:15 +0000 https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/

Hackers say they just posted a massive new trove of T-Mobile customer data online – but the details of the data dump are in question.

Cyber thieves uploaded the data to a popular dark web forum, according to Cybernews.

The outlet’s researchers say a sample of the data appears to contain some emails linked to prior T-Mobile breaches, along with “some new data points not seen in previous T-Mobile attacks.”

But the mobile giant says the malicious actors are flat-out lying.

“Any reports of a T-Mobile data breach are inaccurate. We have reviewed the sample data provided and can confirm the data does not relate to T-Mobile or our customers.”

Researchers say the data contains full names, dates of birth, tax IDs, addresses, phone numbers, email addresses, device IDs, cookie IDs and IP addresses.

“If this data is legitimate, exposing 64M lines of highly sensitive information poses a serious threat of identity theft/fraud, surveillance, and further, better-targeted attacks on customers.”

The alleged data dump comes as 76 million T-Mobile customers begin to receive their share of a $350 million payout following a 2021 data breach and class action settlement.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/64000000-t-mobile-records-containing-highly-sensitive-customer-data-allegedly-leaked-online-as-mobile-giant-refutes-attackers-claims/feed/ 0 41975
364,333 Americans At Risk As Data Giant Discovers Breach – Social Security Numbers, Names and Other Sensitive Info Stolen https://earlybirdsinvest.com/364333-americans-at-risk-as-data-giant-discovers-breach-social-security-numbers-names-and-other-sensitive-info-stolen/ https://earlybirdsinvest.com/364333-americans-at-risk-as-data-giant-discovers-breach-social-security-numbers-names-and-other-sensitive-info-stolen/#respond Fri, 30 May 2025 08:39:02 +0000 https://earlybirdsinvest.com/364333-americans-at-risk-as-data-giant-discovers-breach-social-security-numbers-names-and-other-sensitive-info-stolen/

Sensitive personal and financial information of hundreds of thousands of Americans has been stolen in a newly reported cybersecurity incident.

In a filing with the Office of the Maine Attorney General, Georgia-based data broker giant LexisNexis Risk Solutions (LNRS) says that it discovered a breach affecting 364,333 people.

“We learned that on December 25, 2024, an unauthorized third party acquired certain LNRS data from a third-party platform used for software development. The issue did not affect LNRS?s own networks or systems…

The types of impacted personal information varied by affected individual, and could have included name, contact information (such as phone number, postal or email address), Social Security number, driver’s license number or date of birth. No financial or credit card information was affected.”

LNRS says it immediately sent letters to affected customers to inform them of the breach, while offering free identity monitoring services to affected individuals for two years.

LNRS also says it has not yet detected any instance involving the misuse of the stolen customer data.

The firm is urging customers to stay vigilant and report any suspicious activity related to their financial accounts.

LNRS says it has “launched an investigation with the assistance of leading external cybersecurity experts, notified law enforcement and took steps to review and further enhance our security controls.”

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/364333-americans-at-risk-as-data-giant-discovers-breach-social-security-numbers-names-and-other-sensitive-info-stolen/feed/ 0 39114
Google rolls out sensitive content warnings for nudes in Messages- Android Authority https://earlybirdsinvest.com/google-rolls-out-sensitive-content-warnings-for-nudes-in-messages-android-authority/ https://earlybirdsinvest.com/google-rolls-out-sensitive-content-warnings-for-nudes-in-messages-android-authority/#respond Mon, 21 Apr 2025 23:32:51 +0000 https://earlybirdsinvest.com/google-rolls-out-sensitive-content-warnings-for-nudes-in-messages-android-authority/
Google Messages in rolling out Sensitive Content Warnings.

Edgar Cervantes / Android Authority

TL;DR

  • Google Messages is rolling out sensitive content warnings, which can detect and blur images that may contain nudity.
  • Adults can opt in, but the feature is on by default for teens and supervised users.
  • All detection happens on-device via SafetyCore, with no image data sent to Google.

After being in the works for several months, Google is finally starting to roll out sensitive content warnings in Messages. The long-awaited feature is designed to detect and blur nude images before users see them, and prevent accidental sharing.

The update was spotted by 9to5Google, with the controls appearing under Protection & Safety > Manage sensitive content warnings within the app’s settings menu. While this system was announced last year and Google claimed it started rolling out in February, it’s only now showing up on some devices, and the rollout appears limited to the beta version so far.

When active, the feature automatically blurs images that may contain nudity, gives you the choice to view, block the sender, or learn more about the risks. There’s also an option to reblur the image after previewing. A separate warning appears when you try to send or forward potentially nude images, reminding you of the risks and requiring confirmation before proceeding.

No images are sent to Google’s servers.

Sensitive content warnings are opt-in for adults, but they’re enabled by default for teenagers. For supervised accounts, the setting can’t be turned off at all, though parents can control it via Google’s Family Link. Unsupervised teens from ages 13 to 17 can disable it manually through their Google Account settings.

Importantly, all content detection happens on-device through Android’s SafetyCore system, meaning none of the images or classification results are sent to Google’s servers. The feature doesn’t currently apply to videos and will only function when an app like Messages actively calls the SafetyCore service.

Got a tip? Talk to us! Email our staff at news@androidauthority.com. You can stay anonymous or get credit for the info, it’s your choice.
]]>
https://earlybirdsinvest.com/google-rolls-out-sensitive-content-warnings-for-nudes-in-messages-android-authority/feed/ 0 32109
New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/ https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/#respond Mon, 31 Mar 2025 08:29:04 +0000 https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/

A new “highly capable” mobile banking malware dubbed “Crocodilus,” targets Android devices, extorting sensitive crypto wallet credentials using social engineering tactics.

A recent research by cybersecurity firm Threat Fabric found the emergence of a new malware family Crocodilus. The malware is reportedly distributed through a proprietary dropper that bypasses Android 13+ restrictions.

“Despite being new, it already includes all the necessary features of modern banking malware: overlay attacks, keylogging, remote access, and ‘hidden’ remote control capabilities,” analysts noted.

Sophisticated Android malware designed to steal cryptocurrency private keys isn’t new. In October 2024, the FBI issued a warning about a similar malware called SpyAgent, which was linked to North Korean hackers.

However, what differs in the new mobile banking Trojan Crocodilus is the “device takeover and advanced credential theft,” Threat Fabric wrote on X.

Crocodilus Displays Overlays to Target Banks and Cryptos

Crocodilus malware works on a modus operandi similar to modern “Device Takeover banking Trojan,” analysts noted. After initial installation via a proprietary dropper, the malware requests “Accessibility Service” to be enabled, they added.

In order to intercept credentials, Crocodilus connects to the command-and-control (C2) server for instructions such as overlays to be used.

Further, the threat initially appeared in Spain and Turkey, targeting several crypto wallets, the Mobile Threat Intelligence team revealed.

“We expect this scope to broaden globally as the malware evolves,” the team noted.

Additionally, the two-factor authentication (2FA) is bypassed by the malware using RAT command that triggers a screen capture on the content of the Google Authenticator application. Crocodilus captures the code displayed on the screen in the Google Authenticator app, and sends to the C2.

Malware Instructs Victims to Do the Job

Unlike other Trojans, Crocodilus overlays target crypto wallet by asking victims to take a backup of their wallet keys.

“Back up your wallet key in the settings within 12 hours. Otherwise, the app will be reset, and you may lose access to your wallet,” the overlay text reads.

This social engineering hack guides victims to navigate to their seed phrase. This inturn allows Crocodilus to extract the text using its Accessibility Logger.

“With this information, attackers can seize full control of the wallet and drain it completely,” Threat Fabric analysts said.

The post New ‘Crocodilus’ Android Malware Steals Sensitive Crypto Wallet Credentials: Research appeared first on Cryptonews.

]]>
https://earlybirdsinvest.com/new-crocodilus-android-malware-steals-sensitive-crypto-wallet-credentials-research/feed/ 0 28185
21,899 Bank Customers Affected As US Lender Suffers Cybersecurity Breach, Hacker Taps Social Security Numbers and Other Sensitive Information https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/ https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/#respond Sat, 22 Mar 2025 04:26:39 +0000 https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/

A billion-dollar bank is warning customers after a cybersecurity breach affecting thousands of customers.

In a filing with the Office of the Maine Attorney General, Western Alliance Bank says an unauthorized actor exploited a vulnerability in a third-party file transfer software system it uses.

The breach, which was discovered in late January and happened in October, impacts 21,899 customers, according to the filing.

“Western Alliance learned that an unauthorized actor had potentially accessed some of Western Alliance’s data on January 27, 2025. Our investigation determined that the unauthorized actor acquired certain files from the systems from October 12, 2024, to October 24, 2024…

On February 21, 2025, we determined that the files contained some of your personal information, including your name and Social Security number. The files may have also contained your date of birth, financial account number, driver’s license number, tax identification number, and/or passport, if you provided it to Western Alliance.”

The bank says it has informed law enforcement about the data breach and is offering customers a 12-month complimentary membership to an identity-theft protection service.

Western Alliance Bank currently has approximately $81 billion in total assets, according to the Federal Reserve.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/21899-bank-customers-affected-as-us-lender-suffers-cybersecurity-breach-hacker-taps-social-security-numbers-and-other-sensitive-information/feed/ 0 26513