Hunters International has added a property management firm in Kentucky to their leak site. They provide a description of what they claim to have acquired from Homeland, Inc.: Over 200Gb of data – tenants info (ssn, income, family members, phone numbers, etc) – service management info (move-in/move-out files, agreements, expenses, etc) – financial data (payments,…
Category: Business Sector
It’s Still Easy for Anyone to Become You at Experian
Brian Krebs reports: In the summer of 2022, KrebsOnSecurity documented the plight of several readers who had their accounts at big-three consumer credit reporting bureau Experian hijacked after identity thieves simply re-registered the accounts using a different email address. Sixteen months later, Experian clearly has not addressed this gaping lack of security. I know that because my account at…
Hackers swipe Booking.com, damage from attack is global
Tatsuya Sudo reports: Hackers breached Booking.com, one of the world’s largest online accommodation reservation sites, by posing as hotel staff to steal credit card information from travelers making bookings. Phishing scams like this have plagued Japan since May. The headquarters of Booking.com in the Netherlands conceded the damage is occurring on a global scale. Read more about this current…
Optus loses court bid to keep report into cause of cyber-attack secret
Josh Taylor reports a win for transparency: Optus has lost a bid in the federal court to keep secret a report on the cause of the 2022 cyber-attack – which resulted in the personal information of about 10 million customers being exposed – after a judge rejected the telco’s legal privilege claim. After the hack, the company announced…
UK: Nearly £2 million of stolen cryptocurrency to be paid back to victims
An interesting press release from the South East Regional Organised Crime Unit (SEROCU): Around £1.9 million worth of stolen cryptocurrency is to be paid back to victims of theft as a result of work by the South East Regional Organised Crime Unit (SEROCU). On 27 January this year, 40-year-old Wybo Wiersma, of Het Weike, Goredijk,…
MOVEit hackers leverage new zero-day bug to breach organizations (CVE-2023-47246)
Helga Labus reports: A critical zero-day vulnerability (CVE-2023-47246) in the SysAid IT support and management software solution is being exploited by Lace Tempest, a ransomware affiliate known for deploying Cl0p ransomware. […] The (limited) attacks were first spotted by the Microsoft Threat Intelligence team, and they notified Israeli software maker SysAid about them on November…