18,267,244 known records breached in 94 newly disclosed incidents

Welcome to this week’s global round-up of the biggest and most interesting news stories.

At the end of each month, these incidents – and any others that we find – will be used to inform our monthly analysis of data breaches and cyber attacks.

Publicly disclosed data breaches and cyber attacks: in the spotlight

loanDepot reports an extra 324,071 victims

In January, the mortgage lender loanDepot announced in an SEC filing that an unauthorised third party had gained access to the sensitive personal information of about 16.6 million individuals in its systems.

In a new breach notification to the Maine Attorney General this week, it reported that an extra 324,071 individuals were affected. The breached data includes names, addresses, emails, phone numbers, dates of birth, and financial account and Social Security numbers.

Data breached: 16,924,071 individuals’ data.

The Colorado Department of Health Care Policy & Financing reports a further 473,936 victims

Last October, the Colorado Department of Health Care Policy & Financing notified the Maine Attorney General of a breach affecting 4,187,732 people. The incident was caused by the MOVEit Transfer vulnerability.

This week, the Department informed the Maine regulator that an additional 474,936 individuals were impacted. The breached data may include names, Social Security numbers and health insurance information.

Data breached: 4,662,668 individuals’ data.

2,350,236 individuals’ health data compromised in American Vision Partners breach

Medical Management Resource Group, L.L.C. (doing business as American Vision Partners), an eye care practitioner with more than 100 eye care centres across the US, reported a data breach affecting 2,350,236 people.

For all individuals, the breached data included names, contact details, dates of birth and medical information. For some victims, the stolen data also included Social Security numbers and health insurance information.

Data breached: 2,350,236 individuals’ data.

Publicly disclosed data breaches and cyber attacks: full list

This week, we found 18,267,244 records known to be compromised, and 94 organisations suffering a newly disclosed incident. 86 of them are known to have had data exfiltrated, exposed or otherwise breached. None definitely haven’t had data breached.

We also found 4 organisations providing a significant update on a previously disclosed incident.

Organisation(s)SectorLocationData breached?Known data breached
loanDepot
Source 1; source 2
(Update)
FinanceUSAYes16,924,071
Colorado Department of Health Care Policy & Financing
Source 1; Source 2
(Update)
PublicUSAYes4,662,668
Medical Management Resource Group, L.L.C. (American Vision Partners)
Source 1; source 2; source 3
(New)
HealthcareUSAYes2,350,236
March Construction
Source
(New)
ConstructionUSAYes1.8 TB
Roncelli Plastics
Source
(New)
ManufacturingUSAYes1.6 TB
The Peddie School
Source
(New)
EducationUSAYes1.2 TB
Newman Ferrara
Source
(New)
LegalUSAYes835 GB
UNITE HERE
Source
(Update)
Professional servicesUSAYes791,273
First Professional Services
Source
(New)
HealthcareUSAYes755 GB
BS&B Safety Systems
Source
(New)
ManufacturingUSAYes714.9 GB
Grand Paris Aménagement
Source
(New)
ConstructionFranceYes653.8 GB
Climatech
Source
(New)
ManufacturingUSAYes550 GB
VSP Dental
Source
(New)
HealthcareUSAYes543 GB
Human Resources Technologies
Source
(New)
IT servicesUSAYes500 GB
Dilweg
Source
(New)
FinanceUSAYes453 GB
Spine West
Source
(New)
HealthcareUSAYes450 GB
Wapiti Energy
Source
(New)
EnergyUSAYes436.3 GB
Birchall Foodservice
Source
(New)
HospitalityUKYes405 GB
Zircodata
Source
(New)
IT servicesAustraliaYes395 GB
Wangkanai Group
Source
(New)
ManufacturingThailandYes350 GB
Family Health Center
Source
(New)
HealthcareUSAYes327 GB
US Merchants
Source
(New)
ManufacturingUSAYes245 GB
Tangerine
Source
New
TelecomsAustraliaYes232,000
Remkes Poultry
Source
(New)
ManufacturingNetherlandsYes190 GB
Hardeman County Community Health Center
Source
(New)
HealthcareUSAYes169 GB
CarePro
Source 1; source 2
(New)
HealthcareUSAYes151,499
Farmacia al Shefa
Source
(New)
HealthcareRomaniaYes150 GB
Quik Pawn Shop
Source
(New)
FinanceUSAYes140 GB
Bucher and Strauss
Source
(New)
FinanceSwitzerlandYes140 GB
Prime Healthcare Employee Health Plan
Source 1; source 2
(New)
HealthcareUSAYes101,135
Apex Internationale Spedition
Source
(New)
TransportGermanyYes100 GB
Bram Auto Group
Source
(New)
ManufacturingUSAYes85 GB
Town of Greater Napanee
Source
(New)
PublicCanadaYes82.9 GB
Tiete Automobile
Source
(New)
RetailBrazilYes68.5 GB
Delia Cosmetics
Source
(New)
ManufacturingPolandYes64 GB
Rapid Granulator
Source
(New)
ManufacturingSwedenYes60 GB
medQ, Inc.
Source
(New)
HealthcareUSAYes54,353
Advanced Project Solutions
Source
(New)
IT servicesUSAYes54 GB
Greater Cincinnati Behavioral Health Services
Source 1; source 2
(Update)
HealthcareUSAYes50,000
Compression Leasing Services
Source
(New)
ManufacturingUSAYes41.11 GB
Washington County Hospital and Nursing Home
Source
(New)
HealthcareUSAYes31,125
Crossroads Equipment Lease & Finance, LLC
Source
(New)
FinanceUSAYes24,182
EdisonLearning, Inc.
Source
(New)
EducationUSAYes23,922
DTS (Desarrollo de Tecnologia y Sistemas)
Source
New
IT servicesChileYes20 GB
Peer Consultants
Source
(New)
Professional servicesUSAYes20 GB
Wyze
Source
(New)
IT servicesUSAYes13,000
Bay Area Heart Center
Source 1; source 2
(New)
HealthcareUSAYes11,709
Westward360
Source
(New)
Real estateUSAYes11 GB
Greylock McKinnon Associates, Inc.
Source
(New)
LegalUSAYes5,465
Bacon-Universal Holdings, LLC
Source
(New)
ConstructionUSAYes3,561
T.Y. Lin International Group Ltd.
Source
(New)
EngineeringUSAYes3,398
GC Services
Source
(New)
FinanceUSAYes3,043
CVS Pharmacy, Inc.
Source 1; source 2
(New)
HealthcareUSAYes1,896
Matthews International
Source
(New)
ManufacturingUSAYes1,846
Pond & Company
Source
(New)
EngineeringUSAYes1,495
Brazee & Huban CPAs
Source
(New)
FinanceUSAYes1,119
BlueCross BlueShield of Tennessee, Inc. and Volunteer State Health Plan, Inc. d/b/a BlueCare Plus Tennessee
Source 1; source 2
(New)
HealthcareUSAYes790
Roswell Park Comprehensive Cancer Center
Source 1; source 2
(New)
HealthcareUSAYes755
Capital Health system, Inc.
Source 1; source 2
(New)
HealthcareUSAYes501
Harris Beach PLLC
Source
(New)
LegalUSAYes486
Beauty Essence, Inc.
Source
(New)
LeisureUSAYes409
Walmart, Inc.
Source
(New)
RetailUSAYes204
Xerox Corporation
Source
(New)
Professional servicesUSAYes181
HematoLogics, Inc.
Source
(New)
HealthcareUSAYes99
torchbyte
Source
(New)
TelecomsRomaniaYes45
Australian Department of Finance
Source
(New)
PublicAustraliaYesUnknown
Anxun Information Technology
Source
(New)
Cyber securityChinaYesUnknown
PSI Software
Source
(New)
SoftwareGermanyYesUnknown
Acies SRL
Source
(New)
HealthcareItalyYesUnknown
Grupo Bimbo
Source
(New)
ManufacturingMexicoYesUnknown
Axel Johnson
Source
(New)
ManufacturingSwedenYesUnknown
dasteam ag
Source
(New)
Professional servicesSwitzerlandYesUnknown
Acorn Property Group
Source
(New)
ConstructionUKYesUnknown
Multiple universities using the Janet Network, including Cambridge and Manchester
Source
(New)
EducationUKYesUnknown
Helical Technology
Source
(New)
ManufacturingUKYesUnknown
The Chas. E. Phipps Co
Source
(New)
ConstructionUSAYesUnknown
FixedFloat
Source
(New)
CryptoUSAYesUnknown
Aeromech
Source
New
EngineeringUSAYesUnknown
Bradshaw Medical (intech)
Source
(New)
HealthcareUSAYesUnknown
Maryville Addiction Treatment Center
Source 1; source 2
(New)
HealthcareUSAYesUnknown
Radiology Associates of Ocala
Source
(New)
HealthcareUSAYesUnknown
Infiniti USA
Source
(New)
ManufacturingUSAYesUnknown
Pressco Technology
Source
(New)
ManufacturingUSAYesUnknown
Welch’s
Source
(New)
ManufacturingUSAYesUnknown
C&J Industries
Source
(New)
Professional servicesUSAYesUnknown
Carl Fischer Music Publishing
Source
(New)
RetailUSAYesUnknown
Lancaster
Source
(New)
RetailUSAYesUnknown
U-Haul
Source
(New)
RetailUSAYesUnknown
Andfla
Source
(New)
AgricultureRomaniaUnknownUnknown
CRB Group
Source
(New)
ConstructionUSAUnknownUnknown
KHS&S Contractors
Source
(New)
ConstructionUSAUnknownUnknown
Dunaway
Source
(New)
EngineeringUSAUnknownUnknown
Change Healthcare
Source
(New)
HealthcareUSAUnknownUnknown
Ernest Health
Source
(New)
HealthcareUSAUnknownUnknown
National Dentex Labs
Source
(New)
HealthcareUSAUnknownUnknown
Silgan Holdings
Source
(New)
ManufacturingUSAUnknownUnknown

Note 1: ‘New’/‘Update’ in the first column refers to whether this breach was first publicly disclosed this week, or whether a significant update was released this week. The updated data point is italicised in the table.

Note 2: For incidents where we only know the file size of the data breached, we use the formula 1 MB = 1 record. Given that we can’t know the exact numbers, as it depends on the types of records included (e.g. pictures and medical histories are considerably larger files than just names and addresses), we err on the side of caution by using this formula. We believe that this underestimates the records breached in most cases, but it is more accurate than not providing a number at all.

Enforcement

ICO orders leisure centre to stop using facial recognition technology to monitor staff

The ICO (Information Commissioner’s Office) has ordered Serco Leisure and several associated community leisure trusts to stop using facial recognition technology to monitor employee attendance as this is “neither fair nor proportionate under data protection law”, according to the UK Information Commissioner.

On the same day the ICO issued this enforcement notice, it published new guidance for using biometric data.

New US Executive Order issued to strengthen US port security

The Biden-Harris administration is issuing an Executive Order to strengthen the security of US ports. Cyber incidents that endanger “any vessel, harbor, port, or waterfront facility” must be reported. The US Coast Guard is also given the authority to respond to “malicious cyber activity”.

Other news

LockBit ransomware group recovers from law enforcement disruption

Last week, we reported that law enforcers disrupted the LockBit ransomware group. Four days later, the group recovered. Its blog has now reappeared, as well as a leak page containing folders for “dozens” of victims.

NSA announces retirement of director of cyber security

The US NSA (National Security Agency) has announced the retirement of its director of cyber security, Rob Joyce. He’ll be succeeded by David Luber.

Key date

31 March 2024 – PCI DSS v4.0 transitioning deadline 

Version 3.2.1 of the PCI DSS (Payment Card Industry Data Security Standard) is being retired on 31 March, to be replaced by version 4.0 of the Standard. There are more than 50 new requirements in PCI DSS v4.0. You can find out more about them on the PCI Security Standards Council’s website.

That’s it for this week’s round-up. We hope you found it useful.

We’ll be back next week with the biggest and most interesting news stories, all rounded up in one place.

In the meantime, if you missed it, check out last week’s round-up. Alternatively, you can view our full archive.

Security Spotlight

To get news of the latest data breaches and cyber attacks straight to your inbox, subscribe to our weekly newsletter: the Security Spotlight.

Every Wednesday, you’ll get a 4-minute email with:

  • Industry news, including this weekly round-up;
  • Our latest research and statistics;
  • Interviews with our experts, sharing their insights and expertise;
  • Free useful resources; and
  • Upcoming webinars.