Editor's Message

Welcome to DBD. On March 8th, DBD celebrated it's 5th anniversary and PRiSM celebrated it's 2nd anniversary. Little did I know when I started both of these ventures just how much an impact they would have on my life and I'd like to thank each and everyone of you who have supported me over the years, with a special thanks to those individuals who have kindly shared their knowledge with me, and continue to do so. Thanks again for your support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington DC



Monday, 26 May 2025

Data Breaches Digest - Week 22 2025

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 26th May and 1st June 2025.


27th May

4.5% of breaches now extend to fourth parties

5 Largest Ransomware Attacks Ever Recorded

8.75 million hit by online threats in South Africa in Q1

94 billion browser cookies are being sold to hackers on Telegram

840k-patient per year hospital empire fights ransomware attack

67,947 Americans Warned as US City Data Breach May Have Exposed Names, Dates of Birth, Social Security Numbers and More

Adidas become latest victims of cyber attack as customers warned of data breach

Adidas confirms customer data stolen in cyber attack

Adidas Confirms Cyber Attack, Customer Data Stolen

Adidas Data Breach - Customer Data Exposed Via Third-Party Service Provider

Adidas Data Breach Exposes Customer Contact Info

Adidas Discloses Cyber-Attack, Customer Data Compromised

Adidas hit by major cyber attack as customer details exposed

Adidas loses customer data in latest cyber attack

Adidas says customer data stolen in cyber attack

Adidas Says Cyberattack Targeted Customers’ Personal Information, Credit Card Data Marked ‘Safe’ From Breach

Adidas warns cyber attack stole customer data

Adidas warns of data breach after customer service provider hack

Africa faces rising ransomware threat, warns Kaspersky

After Pahalgam Attack, How Pakistan Unleashed Cyber Terrorism On India

AI is perfecting scam emails, making phishing hard to catch

Akira Ransomware Group Claims Breach of Laboratorios Belloch, Exposing Sensitive Data

Alleged Data Breach at Bangladesh Road Ministry

Anti-Corruption Platform Ipaidabribe.com Allegedly Suffers Major Data Breach

Cash-strapped university facing a class action lawsuit over data breach

China accuses Taiwan-linked group of cyberattack on local tech company

China, Taiwan trade accusations over cyberattacks

Coca-Cola Denies Ultimatum: Everest Ransomware Group Dumps Employee Data Due to Unpaid Ransom

Coca-Cola Europacific Partners targeted in major data breach

Coca-Cola ignores ransom demand, hackers dump employee data

Coinbase Data Breach Exposes Crypto Founders: Security Risks and Trading Implications in 2025

Coinbase faces legal action following data breach impacting more than 69k customers

Cooper Health System data breach affects nearly 60,000 individuals

Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets

Data Breach at Alera Exposed Data of More Than 10,000 Individuals

Data breach at KBC Securities Services: financial information leaked to thousands of customers

DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers

DragonForce looking to usurp other ransomware gangs

DragonForce Ransomware Leveraged in MSP Attack Using RMM Tool

Dutch intelligence unmasks previously unknown Russian hacking group 'Laundry Bear'

Elit Avia allegedly targeted by ransomware gang, crew data leaked

Employees Searching Payroll Portals on Google Tricked Into Sending Paychecks to Hackers

Europol, as part of Operation Endgame 2.0, destroyed the infrastructure of hacker groups and paralyzed their operations

Everest Ransomware Leaks Coca-Cola Employee Data Online

FBI Warns about Silent Ransom Group Targeting Law Firms

FBI warns legal firms of Luna Moth extortion attacks where hackers will call their office

French ISP ‘Free’ 2024 Data Breach Exposed Almost 14 Million User Accounts

Germany raises alarm over Windows Server 2025 flaw rated 9.9/10

GitLab ‘Vulnerability Highlights the Double-Edged Nature of AI Assistants’

Global Cyber Raid: ₹190 Crore Ransomware Network Crushed Were You A Target?

Global data breach affects 184 million users, no damage reported in Pakistan

Governments Urge Organizations to Prioritize SIEM/SOAR Adoption

Guangzhou police attribute cyberattack on tech company to hacker group allegedly linked to Taiwan’s Democratic Progressive Party (DPP)

Hackers Are Calling Your Office: FBI Alerts Law Firms to Luna Moth's Stealth Phishing Campaign

Hackers Mimic OneNote Login to Steal Office365 & Outlook Credentials

Hackers steal Adidas customer data in cyber attack

Hackers Use Fake OneNote Login to Capture Office365 and Outlook Credentials

Hong Kong Monetary Authority (HKMA) Warns Public About Fraudulent Banking Websites and Phishing Scams

How CISOs can defend against Scattered Spider ransomware attacks

How Does External Attack Surface Management (EASM) Go Beyond Vulnerability Management?

How well do you know your remote IT worker?

Iranian Man Pleads Guilty to Role in Baltimore Ransomware Attack

Iranian national admits to Greenville City Hall ransomware attack

Kettering Health radiation oncology back to treating patients after cyber attack

Kettering Health says radiation oncology is back online after ransomware attack

'Kisses from Prague': The fall of a Russian ransomware giant

Law Firms Warned of Silent Ransom Group Attacks

Legal Practice Board of Western Australia confirms Dire Wolf ransomware attack

Major hack exposes 184 million Apple and Google accounts: Change your passwords NOW

Malicious Machine Learning Model Attack Discovered on PyPI

Marks & Spencer (M&S) cyber attack latest as customers warned of scam emails

Marks & Spencer (M&S) cyber attack probe looks at possible IT helpdesk hack, online fashion still 'weeks away' from return

Massive 47GB Data Breach Exposes Millions Of Passwords For Google, Netflix And More

MathWorks, Creator of MATLAB, Confirms Ransomware Attack

MATLAB developer bringing systems back online following ransomware attack

MATLAB developer confirms ransomware attack behind service outage

Meta wants to use your content to train its AI, and no GDPR will stop it

Microsoft, Dutch security agencies lift veil on Laundry Bear cyber espionage group

More than 184 million passwords exposed in massive data breach - Apple, Google, Microsoft and more

Nationwide Recovery Service Data Breach Victim List Grows

Nearly 70,000 impacted by ransomware attack on Sheboygan, Wisconsin

Nearly 280,000 impacted by Nova Scotia Power ransomware hack

New Jersey hospital hack exposes patients’ personal details

New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency

New York Department of Motor Vehicles (DMV) warns of latest fraudulent text message scam. What to do if you're targeted

Nova Scotia Power confirms it was hit by ransomware attack but hasn’t paid the ransom

Operation ENDGAME cracks down on ransomware

Pakistan’s National Cyber Emergency Response Team (CERT) warns after massive global data breach affecting 180 million users

Pakistanis Asked to Change All Social Media Passwords after Data Theft

Pakistanis Urged To Immediately Change All Passwords After Massive Global Data Breach

Palo Alto Networks Report Identifies Evolving Ransomware Tactics in Asia Pacific

Planned Parenthood Patients File Lawsuits Over Laboratory Services Cooperative Data Breach

Preparing for the UK's Cyber Security and Resilience Bill

Preparing your organisation for a potential ransomware payment ban

Ransomware attack on MATLAB developer MathWorks - licensing center still locked down

Ransomware attacks on banks: trends and prevention strategies

Regulator has closed case in fundraising platform after data breach

Russia-Affiliated Void Blizzard Impersonates European Defense & Security Summit in Phishing Emails

Russia-Linked Hackers Target Tajikistan Government with Weaponized Word Documents

Russian hackers behind attacks on police, NATO, Dutch intelligence says

Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages

Russian hospital programmer gets 14 years for leaking soldier data to Ukraine

Russian Laundry Bear cyberspies linked to Dutch Police hack

SafePay ransomware hits over 235K Marlboro-Chesterfield Pathology patients

Scam email imitating Dallas’ planning department asks for thousands of dollars in fees

Securing Healthcare: Safeguarding Patient Care and Privacy Through Agile Cyber Strategies

South Korea expands data breach investigation to KT and LG Uplus

Taiwan's Democratic Progressive Party (DPP) authorities found organizing cyberattacks against Guangzhou tech company

Threat Actors Use Fake DocuSign Notifications to Steal Corporate Data

United Airlines Faces Alleged Data Breach 272 Million Records Exposed

Unsophisticated Actors, Poor Hygiene Prompt Critical Infrastructure (CI) Alert for Oil & Gas

US Government Launches Audit of NIST’s National Vulnerability Database

US law firms facing Luna Moth ransomware threat

Vulnerabilities found in NASA’s open source software

Warning issued to anyone who gets Marks and Spencer (M&S) e-mails after cyber attack

What Is Anti-Ransomware? Why Detection Alone Won’t Stop the Next Attack

What will be the impact of Operation Endgame?

Why app modernization can leave you less secure

Why Quiet Expertise No Longer Wins Cybersecurity Clients

Word to the wise: Beware of fake Docusign emails

26th May

$2.5M Gone in Hours - Victim Hit Twice in Sophisticated Stablecoin Phishing Scam

$2.5 Million Vanishes in Double Crypto Phishing Scam

$4.4 Million Settlement Agreed to Resolve WellNow Urgent Care Data Breach Litigation

52% of Security Operations Center (SOC) Teams Are Overworked, New Report Shows

Adidas confirms customers data breach

Adidas Confirms Data Breach Impacting Customers Who Interacted with Help Desk in Turkiye

Adidas Confirms Data Breach of Customer Information

Adidas next retailer hit by cyber attack

AI forces security leaders to rethink hybrid cloud strategies

AI, Ransomware, and IoT Dominate Kaspersky’s Cybersecurity Outlook for META Region

Alleged 500GB Data Leak Impacts Chinese Industrial Gas Giant Messer Group

Asia-Pacific region experiences 13% growth in cyber-attacks

BIOS under attack: hackers increasingly focus on boot threats

Cellcom hit by major cyber attack, disrupting voice and text services

Chevrolet retailer in Brazil allegedly hit by cyberattack

Chinese Hackers Exploit Cityworks 0-Day to Hit US Local Governments

Chinese Hackers Exploit Cityworks Flaw to Target US Local Governments

Coinbase Breach Explained: Bribed Support Agents, Stolen Data and a $20M Bounty

Coinbase faces another data breach lawsuit claiming stock drop damages

Coinbase Faces Class Action Lawsuit Over Data Breach and UK Regulatory Violations

Cooper Health System Data Breach Affects Almost 60,000 Individuals

Crypto investor loses $2.6M in stablecoins in double phishing scam

Crypto Investor Suffers $2.6 Million Loss in Stablecoins Through Sophisticated Double Phishing Scam

Cyber attack to cost Marks & Spencer (M&S) £300 million, operations disrupted through July

Data Breach Fallout: Coinbase Sued Over Hidden UK Regulator Deal

Data breach hits over 180 million users globally, including Pakistan

Electricity supply emerges as prime cyber attack target

Energy provider confirms ransomware attack and data breach

EsSalud Peruvian Health Insurance Data Allegedly Leaked Online

Europol, as part of Operation Endgame 2.0, destroyed the infrastructure of hacker groups and paralyzed their work

FBI warns law firms they’re being targeted by hackers

Former employees pursue class action over ‘concealed’ data breach at Interior Health

Fraud conviction overturned for DeFi exploiter behind $114M Mango Markets manipulation

Global Law Enforcement Cripples Ransomware Infrastructure

Hacker Steals $223 Million From Crypto Platform Cetus

Hackers Breach Indonesia's Perludem Site to Promote Online Gambling

Hackers just hit a $5 Billion hospital empire, demand ransom

Hackers steal $2.6M in double crypto phishing scam

Hacktivism Reborn: How a Fading Cyber Threat Has Become a Modern Battleground

Here’s how you can protect yourself from being scammed with deepfakes

How to Avoid Common Crypto Scams and Phishing Attacks in 2025

Hundreds demand compensation following SK Telecom data breach that affected millions

Impersonating Meta, Powered by AppSheet: A Rising Phishing Campaign Exploits Trusted Platforms to Evade Detection

India Meteorological Department (IMD) restricts access to weather data over fear of cyber attack

Investigation into SK Telecom data breach expands to KT, LG Uplus

Investor Sues Coinbase Over Stock Slide Tied to Data Breach and $4.5 Million Financial Conduct Authority (FCA) Fine

Kaspersky Identifies Evolving Ransomware and Cybersecurity Trends in META Region

Luxury aviation services firm allegedly breached, staff details leaked

Major AT&T leak exposed 31 Million records, hackers claim

Major data breach as 184 million Apple, Netflix, Google logins leaked

Marks & Spencer (M&S) boss issues major cyber attack update after online orders paused

Marks & Spencer (M&S) hack may have been caused by security issues at Indian IT giant Tata Consultancy Services

Marks and Spencer chief gives online ordering update after 'cyber incident'

Marlboro-Chesterfield Pathology data breach impacted 235,911 individuals

Massive Data Breach Exposes 184 Million Login Credentials

Massive Global Data Breach Compromises 184 Million Google, Microsoft, and Social Media Accounts

Massive global data breach exposes over 180 million user accounts

Mumbai Advertising Firm Hit by Ransomware Attack, Hackers Demand Bitcoin

National Institute of Standards and Technology (NIST) Introduces New Metric to Measure Likelihood of Vulnerability Exploits

National Institute of Standards and Technology (NIST) proposes new metric to gauge exploited vulnerabilities

Nigeria, South Africa among countries with escalated online threats in Q1 2025

No Power Outage, Just a Data One: Nova Scotia Hit by Ransomware Surge

Nova Scotia Power confirms data breach, customer information compromised

Nova Scotia Power Confirms Ransomware Attack - 280k Customers Affected

Nova Scotia Power Confirms Ransomware Attack, 280k Notified of Data Breach

Nova Scotia Power confirms 'sophisticated' ransomware attack

Over 70 Malicious npm and VS Code Packages Found Stealing Data and Crypto

Over 180 million users’ passwords, login credentials stolen in massive data breach, says national cyber security body

Pakistan: National Cyber Emergency Response Team (PKCERT) issues urgent warning following massive social media data breach

Phishing attacks exploit AppSheet to mimic Meta & evade defences

Phishing Tactics Are Evolving - Here’s How Cybercriminals Are Getting Smarter

Probe into SK Telecom data breach expands to KT, LG Uplus

Ransomware a leading cause of U.S. health data breaches

“Reject all” cookies button must be present and visible, German court says

Researchers Drop Proof-of-Concept (PoC) for Fortinet CVE-2025-32756, Urging Quick Patching

Salesforce hack at largest Coca-Cola bottler

Scammers Use Fake Ledger Letters to Steal Crypto Wallet Info

SilverRAT Source Code Leaked Online: Here’s What You Need to Know

Sophisticated Hacker Group TA-ShadowCricket Attacking Government & Enterprise Networks

Staying one step ahead of ransomware attacks in 2025

Street-Level QR Phishing: Cybercriminals Take Social Engineering to the Real World

TA-ShadowCricket: Sophisticated Hacker Group Targeting Government and Enterprise Networks

This dangerous new phishing scam spoofs a top Google program to try and hack Facebook accounts

Tiffany confirms data breach in South Korea following Dior incident

Trojanized Version of Popular Password Manager KeePass Distributed Via Malicious Search Ads, Fueled Extended Campaign of Ransomware Attacks

U.S. Banking Associations Petition Securities and Exchange Commission (SEC) to Rescind Cyber Breach Reporting Mandate

UK, US Police Target Ransomware Gangs In Latest Action

Unsecured database leak exposes 184 million login records from major technology platforms

What happens when a business is targeted by a cyber attack?

Why layoffs increase cybersecurity risks

Zscaler ThreatLabz 2025 Phishing Report: Phishing Evolves With GenAI