Two-day cyberattack impacted 1,547,169 customers @ Flagstar Bank

In June 2022 the company disclosed it had suffered a major breach the previous year that impacted 1.54 million customers....

Data breach affected up to 914,138 individuals @ ConnectOnCall.com

ConnectOnCall, a telehealth platform and subsidiary of Phreesia, experienced a data breach between February 16, 2024, and May 12, 2024, impacting over 900,000 individuals. The breach exposed personal and medical information, including names, phone num...

Sensitive consumer information compromised, including Social Security numbers and financial account information @ API Financial Solutions

API Financial Solutions, a financial services company specializing in payroll and human services, has reached a $457,500 settlement in a class action lawsuit stemming from a data breach that occurred around June 28, 2023. The lawsuit alleged that API ...

Personal information compromised in data breach @ Loren D. Stark Co. Inc.

In October 2022, Loren D. Stark Co., a retirement plan consulting firm operating in Texas, Louisiana, and Oklahoma, experienced a data breach that compromised the sensitive personal information of an undisclosed number of individuals. The firm has agr...

Resident discovered other people's personal details online @ Cornwall Council

A woman attempting to schedule an appointment at a Cornwall Council waste and recycling center discovered a data breach that exposed the personal information of other users. The woman encountered pre-populated fields containing names, addresses, phone...

GitLab vulnerability and led to 58,000 users' data exposure @ Byte Federal

A cybersecurity incident impacting US Bitcoin ATM operator Byte Federal has potentially exposed the personal information of 58,000 customers. On November 18, 2024, Byte Federal discovered unauthorized access to one of their servers. The intrusion, wh...

Customers' data leaked onto dark web @ Telecom Namibia

In December 2024, a significant cyberattack targeted Telecom Namibia and various Namibian government institutions. The attack, attributed to cyber terrorists, exploited vulnerabilities in remote access systems used by Telecom Namibia employees. This b...

Unauthorised third party accessed and acquired some files @ Regional Care, Inc.

Regional Care, Inc. (RCI), a large third-party administrator, experienced a data breach on September 18, 2024. Unusual activity on their network prompted an internal investigation which revealed that an unauthorized third party had accessed and poten...

StealthMole claimed 17 million Malaysians' data had been leaked and sold on the dark web @ JPN and National Registration Department

In December 2024, allegations surfaced on social media claiming that the MyKad data of 17 million Malaysians had been leaked and was being sold on the dark web. As evidence, samples of Malaysian identification cards were shared online. The alleged lea...

Cyber security attack impacted patients and students @ Texas Tech University and Texas Tech University Health Sciences Center

The Texas Tech University Health Sciences Center experienced a cyberattack on September 26th, which is causing ongoing disruptions for both students and patients. The attack has impacted various systems within the Health Sciences Center, leading to ca...

Lead by example in cyber

Premier risk-driven analysis

All our analysis is overseen some of the leading members of the risk community and includes lessons learnt, controls environment and root cause analysis. Learn more...

High-quality structured cyber dataset

Key attributes of each case - such as threat actor, costs incurred, failed controls etc. - are captured through the Global Cyber Event Taxonomy Learn more...

Consulting & training services

Our case studies have provided us with unique insights into the challenges faced and strategies implemented by organisations countering cyber security threats. Learn more...