The Week in Cyber Security and Data Privacy: 18 – 24 March 2024

134,503,937 known records breached in 1,091 newly disclosed incidents

Welcome to this week’s global round-up of the biggest and most interesting news stories.

At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks.


Publicly disclosed data breaches and cyber attacks: in the spotlight

Misconfigured Google Firebase instances expose almost 125 million user records

On 10 January, a security researcher known as ‘MrBruh’ reported on vulnerabilities in the AI hiring system Chattr.ai, which is used by many US fast food chains.

According to MrBruh, attackers could register profiles with full privileges by exploiting misconfigurations in Google Firebase – a Cloud-based mobile application platform.

This gave them access to names, phone numbers, emails, plaintext passwords, branch locations, confidential messages and shift information for Chattr employees, franchisee managers and job applicants.

MrBruh, alongside two other researchers who go by the names ‘Logykk’ and ‘xyzeva’/’Eva’, then scanned more than 5 million domains for personally identifiable information exposed via other misconfigured Firebase instances.

They discovered 916 misconfigured websites, exposing 124,605,664 million users’ records, including names, emails, phone numbers, passwords and financial data.

The researchers then alerted all affected organisations, sending 842 emails over 13 days. Only 24% of site owners fixed the misconfiguration.

Data breached: 124,605,664 records.

Multiple Indian brands affected by Gamooga misconfiguration

A misconfigured Apache Kafka broker belonging to the Indian marketing analytics company Gamooga exposed sensitive data relating to numerous organisations in India for over a year, “including banking service providers, insurance agencies, e-commerce stores, entertainment apps, and educational institutions”.

At least 1 million customers of well-known brands, including Swiggy, Redbus, Nykaa, BigBasket, TataMotors, ICICIPruLife and Axis Direct, are known to be affected, but the actual scale of the breach is potentially vast: Gamooga claims to track more than 1 billion users – two thirds of India’s population, or one eighth of the world’s.

Publicly accessible information included names, dates of birth, phone numbers, email addresses, IP addresses, purchase history, insurance information, payment information, and more.

Data breached: at least 1 million people’s data.

Chinese APT group compromises 70 organisations, including 48 government agencies

The Chinese advanced persistent threat group Earth Krahang is known to have targeted at least 116 organisations in 45 countries, and has successfully breached 70 organisations in 23 countries. These include 48 government agencies, 10 of which are foreign affairs ministries.

According to Trend Micro, which has been tracking the group since early 2022, the group “exploits public-facing servers and sends spear phishing emails to deliver previously unseen backdoors”.

It then uses “its malicious access to government infrastructure to attack other government entities, abusing the infrastructure to host malicious payloads, proxy attack traffic, and send spear-phishing emails to government-related targets using compromised government email accounts”.

Data breached: unknown.


Publicly disclosed data breaches and cyber attacks: full list

This week, we found 134,503,937 records known to be compromised, and 1,091 organisations suffering a newly disclosed incident. 916 of those incidents are linked to Google Firebase misconfigurations, as explained above.

This week, 1,076 organisations are known to have had data exfiltrated, exposed or otherwise breached. Only 5 definitely haven’t had data breached.

We also found 6 organisations providing a significant update on a previously disclosed incident.

Organisation(s)SectorLocationData breached?Known data breached
916 Google Firebase websites (via Chattr)
Source 1; source 2; source 3
(New)
Retail and hospitalityUSAYes124,605,664
eClinical Solutions
Source
(New)
SoftwareUSAYes3 TB
Kelson
Source
(New)
ConstructionCanadaYes1.5 TB
Gamooga, Swiggy, bigbasket.com, redBus, Nykaa, CaratLane, TataMotors, ICICI Prudential Life Insurance Company Limited and Axis Bank
Source
(New)
IT services, retail, manufacturing, insurance and financeIndiaYes>1,000,000
International Luxury Group
Source
(New)
RetailSwitzerlandYes1 TB
Grupa Topex
Source
(New)
ManufacturingPolandYes638 GB
Philips Respironics
Source 1; source 2; source 3; source 4
(New)
ManufacturingUSAYes457,152
NewAgeSys, Inc
Source
(New)
Professional servicesUSAYes319 GB
V12Software
Source 1; source 2
(New)
SoftwareUSAYes286,396
Sting AD
Source
(New)
ManufacturingBulgariaYes235,585
Therapeutic Health Services
Source
(New)
HealthcareUSAYes218,940
Sun Holdings
Source
(New)
HospitalityUSAYes182,756
3Delectronics
Source
(New)
RetailRussiaYes133,000
University of Wisconsin Hospitals and Clinics
Source 1; source 2
(New)
HealthcareUSAYes85,902
South China Athletic Association
Source 1; source 2
(New)
Non-profitHong KongYes70,000
Select Education Group
Source
(New)
Professional servicesUSAYes67,097
PyLC
Source
(New)
InsuranceMexicoYes63,000
El Ezaby Pharmacy
Source 1; source 2
(New)
ManufacturingEgyptYes62.4 GB
Hallesche Kraftverkehrs-& Speditions-GmbH
Source
(New)
TransportGermanyYes54,547
Valley Oaks Health
Source
(New)
HealthcareUSAYes50,352
City of Jacksonville Beach
Source
(New)
PublicUSAYes48,949
Kirkland & Ellis
Source 1; source 2
(New)
LegalUSAYes48,802
Monmouth College
Source 1; source 2
(New)
EducationUSAYes44,737
England & Wales Cricket Board (ECB)
Source
(New)
LeisureUKYes43,000
GardaWorld
Source
(New)
Professional servicesUSAYes39,928
Citizens Bank of West Virginia
Source 1; source 2
(Update)
FinanceUSAYes35,105
Podemos
Source
(New)
PublicSpainYes30 GB
Fidelity Investments Life Insurance
Source 1; source 2
(Update)
InsuranceUSAYes29,073
Bethel School District
Source
(New)
EducationUSAYes28,844
Weirton Medical Center
Source
(New)
HealthcareUSAYes26,793
American Renal Associates
Source
(New)
HealthcareUSAYesAt least 19,295
Tiegerman
Source 1; source 2
(New)
EducationUSAYes19,000
R1 RCM
Source 1; source 2; source 3
(Update)
SoftwareUSAYes16,121
Newton Public Schools
Source
(New)
EducationUSAYes10,545
Healthfirst
Source 1; source 2
(New)
InsuranceUSAYes6,836
Johnson Matthey
Source
(New)
ManufacturingUSAYes6,095
St. Mary’s Healthcare System for Children
Source
(New)
HealthcareUSAYes5,650
Simpson Strong-Tie
Source
(New)
RetailUSAYes5,570
Victory Bank
Source 1; source 2
(New)
FinanceUSAYes4,292
Dental Group of Amarillo
Source 1; source 2
(New)
HealthcareUSAYes3,821
Eastside Union School District
Source
(New)
EducationUSAYes3,592
Schuster Co
Source
(New)
TransportUSAYes3,532
Dedicated Senior Medical Centers
Source 1; source 2
(New)
HealthcareUSAYes3,441
Sycamore Rehabilitation Services, Inc.
Source
(New)
HealthcareUSAYes3,414
A5 Pharmacy Inc.
Source 1; source 2
(New)
HealthcareUSAYes3,000
Plymouth Tube Company Employee Benefit Plan
Source 1; source 2; source 3
(Update)
InsuranceUSAYes2,652
Shimon Peres Negev Nuclear Research Center
Source
(New)
DefenceIsraelYes“thousands”
Orthopedics Associates of Flower Mound
Source 1; source 2; source 3
(Update)
HealthcareUSAYes1,759
UC San Diego Health
Source 1; source 2
(New)
HealthcareUSAYes1,642
Homeaglow
Source
(New)
IT servicesUSAYes1,556
California Correctional Health Care Services
Source 1; source 2
(New)
HealthcareUSAYes1,348
Ascend Healthcare Inc
Source 1; source 2
(New)
HealthcareUSAYes791
Cypress Capital Group, Inc.
Source
(New)
FinanceUSAYes756
Community Health Group Partnership Plan
Source 1; source 2
(New)
InsuranceUSAYes708
Seaglass Chiropractic
Source 1; source 2
(New)
HealthcareUSAYes650
Lindsay Municipal Hospital
Source 1; source 2
(New)
HealthcareUSAYes500
Massachusetts Department of Developmental Services
Source 1; source 2
(New)
PublicUSAYes500
Mercy Home for Children
Source
(New)
HealthcareUSAYes356
Gnome Landscapes & Design
Source 1; source 2
(Update)
Professional servicesUSAYes356
Mintlify
Source
(New)
SoftwareUSAYes91
TD
Source
(New)
FinanceUSAYes4
Goed
Source
(New)
HealthcareBelgiumYesUnknown
Spa Gran Prix
Source
(New)
LeisureBelgiumYesUnknown
Grupo Equatorial Energia
Source
(New)
UtilitiesBrazilYesUnknown
Giant Tiger
Source
(New)
RetailCanadaYesUnknown
Radiant Logistics Inc.
Source
(New)
TransportCanadaYesUnknown
Dongguan Southstar Electronics Limited
Source
(New)
ManufacturingChinaYesUnknown
SCHOKINAG-Schokolade-Industrie GmbH
Source
(New)
ManufacturingGermanyYesUnknown
The Railways of Islamic Republic of Iran (RAI)
Source
(New)
TransportIranYesUnknown
IronRock Insurance Company Limited
Source
(New)
InsuranceJamaicaYesUnknown
The Pokémon Company
Source
(New)
LeisureJapanYesUnknown
The London Clinic
Source 1; source 2
(New)
HealthcareUKYesUnknown
Ultra Electronics Group
Source
(New)
ManufacturingUKYesUnknown
Kolbe Striping, Inc
Source
(New)
ConstructionUSAYesUnknown
Dolomite
Source
(New)
CryptoUSAYesUnknown
Lewis & Clark College
Source
(New)
EducationUSAYesUnknown
St. Mary Parish School Board
Source
(New)
EducationUSAYesUnknown
Fiduciary Outsourcing, LLC
Source
(New)
FinanceUSAYesUnknown
M&D Capital
Source 1; source 2
(New)
FinanceUSAYesUnknown
Aveanna Healthcare
Source 1; source 2
(New)
HealthcareUSAYesUnknown
Commonwealth Healthcare Corporation
Source
(New)
HealthcareUSAYesUnknown
EMSA (Emergency Medical Services Authority)
Source
(New)
HealthcareUSAYesUnknown
Jordano’s Inc.
Source 1; source 2
(New)
HospitalityUSAYesUnknown
BioLife Plasma Services
Source
(New)
ManufacturingUSAYesUnknown
Crinetics Pharmaceuticals
Source 1; source 2
(New)
ManufacturingUSAYesUnknown
I.A.T.S.E. National Benefit Funds
Source
(New)
Non-profitUSAYesUnknown
Ampersand
Source 1; source 2
(New)
Professional servicesUSAYesUnknown
Henry County, VA
Source
(New)
PublicUSAYesUnknown
Arx Capital
Source 1; source 2
(New)
Real estateUSAYesUnknown
MarineMax
Source 1; source 2; source 3
(Update)
RetailUSAYesUnknown
70 organisations, including 48 government organisations
Source
(New)
Public and unknownMultipleYesUnknown
Bundeskriminalamt
Source
(New)
LegalGermanyUnknownUnknown
Polycab India Limited
Source
(New)
ManufacturingIndiaUnknownUnknown
REG.RU
Source
(New)
IT servicesRussiaUnknownUnknown
Pension Fund of Ukraine
Source
(New)
PublicUkraineUnknownUnknown
KIM (Kaluska informatsiyna merezha LLC)
Source 1; source 2
(New)
TelecomsUkraineUnknownUnknown
Linktelecom
Source
(New)
TelecomsUkraineUnknownUnknown
Мисто-ТВ
Source
(New)
TelecomsUkraineUnknownUnknown
Triacom
Source 1; source 2
(New)
TelecomsUkraineUnknownUnknown
Apex Legends Global Series
Source
(New)
LeisureUSAUnknownUnknown
City of Pensacola Government
Source
(New)
PublicUSAUnknownUnknown
Giorgia Meloni’s Instagram account
Source
(New)
PublicItalyNo0
gouvernement.lu
Source 1; source 2
(New)
PublicLuxembourgNo0
MyGuichet.lu
Source 1; source 2
(New)
PublicLuxembourgNo0
dormakaba
Source
(New)
RetailSwitzerlandNo0
Rt Hon. Grant Shapps MP’s RAF Dassault Falcon 900 jet
Source
(New)
TransportUKNo0

Note 1: ‘New’/‘Update’ in the first column refers to whether this breach was first publicly disclosed this week, or whether a significant update was released this week. The updated data point is italicised in the table.

Note 2: For incidents where we only know the file size of the data breached, we use the formula 1 MB = 1 record. Given that we can’t know the exact numbers, as it depends on the types of records included (e.g. pictures and medical histories are considerably larger files than just names and addresses), we err on the side of caution by using this formula. We believe that this underestimates the records breached in most cases, but it is more accurate than not providing a number at all.


AI

Microsoft research finds 87% of UK organisations vulnerable to cyber attacks in the age of AI

A new report by Microsoft, in collaboration with Dr Chris Brauer of Goldsmiths, University of London classed 87% of UK organisations as vulnerable to cyber attacks. Mission Critical: Unlocking the UK AI Opportunity Through Cybersecurity states that the UK must cement its position as a “cybersecurity superpower” in order to realise its ambition of becoming a global “AI superpower”.

Google VLOGGER generates video from photos, raising security concerns

Google researchers have unveiled VLOGGER, an AI model that can generate photorealistic videos of people from photographs and audio samples. However, security professionals have expressed concern about the technology’s potential misuse to create deepfakes that could be used for social engineering attacks.


Enforcement

Nemesis Market darknet marketplace shut down

The Office of the Public Prosecutor General in Frankfurt am Main – Central Office for Combating Cybercrime – and the German Federal Criminal Police Office have seized the server infrastructure of the darknet marketplace Nemesis Market, along with €94,000 in cryptocurrency.

US House of Representatives passes bill to block sale of US data to foreign adversaries

The House of Representatives has unanimously voted in favour of a bill to block data brokers from selling US citizens’ data to foreign adversaries.

“Today’s overwhelming vote sends a clear message that we will not allow our adversaries to undermine American national security and individual privacy by purchasing people’s personally identifiable sensitive information from data brokers,” said House Energy and Commerce Committee leaders Cathy McMorris Rodgers and Frank Pallone in a joint statement. 


Other news

UK accuses China of two malicious cyber campaigns

The UK’s deputy prime minister, Oliver Dowden, has officially blamed the 2021–22 attacks on the UK’s Electoral Commission and parliamentarians on “China state-affiliated actors”.

ICO publishes new fining guidance

The UK’s data protection authority, the ICO (Information Commissioner’s Office), has published new data protection fining guidance, setting out how it calculates fines.

The ICO’s director of legal service, Tim Capel, said: “We believe the guidance will provide certainty and clarity for organisations. It shows how we reach one of our most important decisions as a regulator by explaining when, how and why we would issue a fine for a breach of the UK General Data Protection Regulation or Data Protection Act 2018.”

ISACA® qualification chosen by NCSC as part of GovAssure

ISACA’s® CISA (Certified Information Security Auditor) qualification has been chosen by the NCSC as an industry-leading standard and qualifying criterion for companies licensed to conduct assurance reviews of government organisations, as part of its new cyber assurance regime for government systems, GovAssure.


Recently published reports


Key dates

21 March 2024 – Old EU Standard Contractual Clauses expired

If you transfer data using old EU standard contractual clauses issued under the Data Protection Directive 1995, the deadline to replace them was 21 March 2024. The ICO website provides further information.

31 March 2024 – PCI DSS v4.0 transitioning deadline

Version 3.2.1 of the PCI DSS (Payment Card Industry Data Security Standard) is being retired on 31 March, to be replaced by version 4.0 of the Standard. There are more than 50 new requirements in PCI DSS v4.0. You can find out more about them on the PCI Security Standards Council’s website.

30 April 2024 – ISO/IEC 27001:2013 certification unavailable

Certification bodies must stop offering (re)certification to ISO 27001:2013 by 30 April. The new iteration of the Standard, ISO 27001:2022, isn’t significantly different from ISO 27001:2013, but there are some notable changes. Learn more about complying with ISO 27001:2022.


That’s it for this week’s round-up. We hope you found it useful.

We’ll be back next week Tuesday with the biggest and most interesting news stories, all rounded up in one place. Until then, have a good Easter.

In the meantime, if you missed it, check out last week’s round-up. Alternatively, you can view our full archive.


Security Spotlight

To get news of the latest data breaches and cyber attacks straight to your inbox, subscribe to our weekly newsletter: the Security Spotlight.

Every Wednesday, you’ll get a 4-minute email with:

  • Industry news, including this weekly round-up;
  • Our latest research and statistics;
  • Interviews with our experts, sharing their insights and expertise;
  • Free useful resources; and
  • Upcoming webinars.