UK retailer Harrods is the most recent victim of a cyber attack, hot on the heels of similar cybersecurity incidents affecting Marks & Spencer and the Co-op, prompting an NSCS advisory.
Harvard University and Envoy, an American Airlines subsidiary, have confirmed data breaches linked to a zero-day vulnerability CVE-2025-61882 in Oracle’s E-Business Suite software.
Have I Been Pwned? (HIPB) has added 244 million freshly stolen passwords compromised via infostealer malware to an already existing list of 199 million, impacting 284 million unique user accounts.
A hacker has stolen the patient info records of at least 11 million individuals in a massive HCA Healthcare data breach and leaked samples on an underground hacking forum.
A health data breach appears to have exposed the sensitive personal information of members of Congress and their employees. DC Health Link is used by many (but not all) members and their assorted staff.
A major data breach at health insurance giant Blue Shield of California appears to be a case of misconfiguring advertising analytics tools. Between April 2021 and January 2024, Google Analytics was misconfigured causing some personal information and potentially sensitive health data related to claims and searches to be available to Google’s ad network.
Brazil's Health Ministry is looking at extended downtime for the system that processes Covid-19 vaccination data as it attempts to recover from two ransomware attacks that came just four days apart.
By and large, the companies that Epic is suing seemed to be seeking medical data to sell to attorneys looking to establish mass tort cases involving many patients suffering similar injuries or conditions. In total the companies accessed 300,000 medical records under these alleged false pretenses.
It's not a surprise that there has been a significant increase in healthcare cyber attacks, but the numbers revealed by a new Bitglass study are nevertheless eye-popping: an increase of over 55% in 2020.
Healthcare giant CVS exposed over a billion health records through a misconfigured cloud database leak, including visitor and session IDs, device information and multiple records for medications.










