Visualização de leitura

Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers

Hardware wallet maker Trezor has confirmed that a data breach at logistics partner ShipMonk is substantially larger than first reported, after older U.S. order records that should have been deleted remained in the leaked dataset.

On September 4, 2026, Trezor said it was told two days earlier that the incident also included order data from a prior ShipMonk partnership between November 2019 and August 2021, fully exposing about 67,000 additional U.S. customers.

Trezor first disclosed the incident on August 13 after ShipMonk reported unauthorized access on August 10. That notice covered 11,742 customers whose names, emails, phone numbers and shipping addresses were fully exposed, plus 1,947 with partial exposure of name, city and email, totaling about 13,689 people.

Those records were linked to orders in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy and Portugal between May 10 and August 8, 2026. An August 14 update already admitted that some partial-exposure records included older orders.

ShipMonk told customers that attackers exploited a vulnerability in the analytics platform Metabase. Metabase notified the logistics firm on August 6 that an unauthorized party used a software flaw to reach account and customer data. Later reporting tied the campaign to a critical SQL injection zero-day that yielded administrator access on compromised instances. Trezor’s own systems were not breached, its devices remain secure, and wallet backups were not leaked. Parcel contents were not exposed.

The latest update undercuts the retention argument Trezor used to bound the first disclosure. The company requires fulfillment partners to delete or anonymize order data 90 days after delivery. Trezor said it repeatedly requested and received written assurance that ShipMonk had deleted the older records, yet the data was still in ShipMonk’s systems.

The newly acknowledged U.S. files include name, email, phone number, shipping address, and order number, bringing the overall impact above 80,000 customers.

That combination of home addresses, phone numbers and hardware-wallet purchase history is useful for phishing and, Trezor now warns, physical security risk.

Scammers can impersonate Trezor, banks, or exchanges by email, call, or letter and push victims to enter a recovery seed. Affected customers have been emailed from help@trezor.io; anyone who did not receive that message is not in the leaked set.

Recipients should treat urgent requests for personal data as hostile, verify claims only through official Trezor channels, and never type a wallet backup into a website or share it with anyone.

Trezor said this is the first incident since its 2013 founding to expose customer phone numbers and shipping addresses, and it is preparing an Anonymous Delivery option with locker pickup and automatic deletion of shipping identifiers.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post Trezor Confirms ShipMonk Data Breach Exposed 67,000 Additional US Customers appeared first on Cyber Security News.

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London Stansted Airport.

The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes and vehicle registration details. The attackers also demanded a ransom for the stolen data, but MAG said it refused to pay.

MAG stated that passenger safety, airport operations and aviation security were not affected by the breach. The compromised system did not contain customer bank account details or payment-card information, according to the group.

Most of the exposed data reportedly came from passengers who registered for WiFi services in airport terminals. The stolen information primarily included email addresses associated with WiFi sign-ups.

Hackers Steal Data From Three UK Airports

Additional customer records were accessed through services linked to airport travel, including car-park reservations, lounge bookings and fast-track access. These records may have contained more detailed information, such as vehicle registration numbers and postcodes.

The airport operator said it identified the incident on Tuesday and acted quickly to stop further unauthorized access. MAG said it contained the breach, engaged specialist cybersecurity advisors and began notifying customers whose data may have been affected.

“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,” MAG said in a statement.

The company said it had informed the relevant authorities and was cooperating with them, while MAG told the BBC that it knows the identity of the threat actors involved but did not publicly name the hacking group or disclose the ransom amount demanded.

The UK Information Commissioner’s Office confirmed that it had received a breach notification from Manchester Airports Group and was assessing the information supplied by the company.

The regulator may determine whether MAG met its data-protection obligations and whether further action is required. The incident highlights the risks associated with customer-facing digital services, especially WiFi portals, parking platforms, and online booking systems.

While the compromised records did not include payment data, attackers can use email addresses, names, postcodes, and vehicle information to build convincing phishing and social engineering campaigns.

Affected customers may receive fake airport notifications, fraudulent baggage or flight alerts, malicious parking-payment messages, or scam calls claiming to offer compensation.

The combination of travel-related information and contact details can make such attacks appear legitimate. MAG has urged customers to remain alert for suspicious emails, text messages and phone calls.

Users should avoid opening unexpected attachments, clicking links in unsolicited messages or sharing personal information with unverified callers. Customers should independently visit official airport websites rather than following links in breach-related messages.

They should also enable multi-factor authentication on email accounts, use unique passwords, and monitor inboxes for phishing attempts that impersonate Manchester Airport, East Midlands Airport, London Stansted Airport, or customer-support teams.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports appeared first on Cyber Security News.

Nutex Health Data Breach – Hackers Gained Access to Network and Exfiltrated Data

Nutex Health has disclosed a cybersecurity incident involving unauthorized activity on its computer network, with preliminary findings indicating that an unknown third party accessed and exfiltrated information stored on company servers.

The Houston, Texas-based healthcare company revealed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated August 24, 2026.

Nutex Health said it recently became aware of suspicious activity affecting data maintained within its network environment. The company has launched an investigation with support from an independent third-party incident response team and forensic experts.

It also activated its cybersecurity response plan, deployed containment measures, and notified law enforcement authorities. According to the filing, the unauthorized party accessed and removed certain data from Nutex Health servers.

The company said the affected information may include private or confidential records. However, the full scope of the data exposure has not yet been determined.

Nutex Health is assessing whether patient information, employee records, credentialed provider data, confidential business information, financial data, intellectual property, or other sensitive records were accessed, acquired, or exfiltrated during the intrusion.

Nutex Health Data Breach

The disclosure does not identify the initial access vector, the date of intrusion, the threat actor, malware used, or whether the incident involved ransomware.

The company also did not confirm the volume of data allegedly taken from its systems or whether stolen information has been published, sold, or otherwise misused.

At the time of the filing, Nutex Health said it had not identified a material impact on its business operations or financial reporting systems.

The organization further stated that it does not currently believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operational performance, financial condition, or results of operations. However, the investigation remains ongoing, and the assessment could change as forensic analysis develops.

Healthcare-sector breaches can create significant exposure because affected environments may hold protected health information, personally identifiable information, employment records, provider credentials, billing data, and internal business documents.

Nutex Health said it is evaluating its legal and regulatory notification obligations. If the investigation determines that patient information was involved, the company intends to issue required notifications to impacted individuals and other relevant parties.

The filing also warns that the incident may result in legal, financial, operational, reputational, and regulatory risks. These could include data disclosure, fraudulent use of stolen information, loss or destruction of company data, regulatory scrutiny, litigation, remediation expenses, and disruption caused by management’s diversion of attention to incident response.

Organizations handling healthcare data remain attractive targets for financially motivated threat actors because medical and business records can be monetized through identity fraud, extortion, phishing, and resale on criminal marketplaces.

The Nutex Health incident highlights the importance of rapid containment, forensic evidence preservation, privileged-access monitoring, network segmentation, and timely notification procedures following suspected data exfiltration.

Nutex Health has not yet disclosed whether it will provide additional technical details, indicators of compromise, or a final count of the number of impacted individuals.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Nutex Health Data Breach – Hackers Gained Access to Network and Exfiltrated Data appeared first on Cyber Security News.

US Bank Investigating Data Breach Following LockBit Ransomware Claim

US Bank is investigating LockBit’s claims of a breach and data theft, with the ransomware group threatening to publish the alleged stolen files on September 3 unless an undisclosed ransom is paid.

Lee Henderson, US Bank vice president of public affairs, confirmed that the company is aware of the claims. In a statement, Henderson said the bank is examining whether a cybersecurity incident occurred.

Lee Henderson said in an emailed statement to The Register: “At this time, there is no indication that our internal systems are impacted or evidence of unauthorized access to our network. US Bank takes the security and privacy of our clients’ and employees’ information very seriously.”

The bank has not disclosed whether it has contacted LockBit, whether any data was taken, or how much money the ransomware group allegedly demanded.

US Bank Investigates LockBit Data Breach Claim

LockBit added US Bank to its data leak site late Wednesday and gave the organization 14 days to meet its ransom demand. The group did not provide details about the number of files it claims to possess or the type of information that may have been stolen.

The incident highlights the continuing risk of ransomware-based data extortion against financial institutions. In these attacks, threat actors may steal data before encrypting systems or without deploying ransomware at all.

They then pressure victims to pay by threatening to release customer records, employee information, internal documents, or financial data.

Security researchers and law enforcement agencies have repeatedly warned that paying ransom does not guarantee stolen data will be deleted.

During the 2024 Operation Cronos disruption of LockBit infrastructure, investigators found evidence that the group retained victim data even after organizations made extortion payments.

International law enforcement agencies seized LockBit servers, domains, and decryption keys in February 2024. Authorities later identified alleged LockBit operator Dmitry Yuryevich Khoroshev, also known as LockBitSupp.

However, the group continued operating and resurfaced with a LockBit 5.0 ransomware variant in 2025. The latest LockBit claim comes after earlier incidents involving US Bank customer data through third-party vendors.

In a recent vendor-related incident linked to Fidelity National Information Services, US Bank reportedly began notifying 537 Massachusetts customers that their names, mailing addresses, and credit card numbers may have been exposed.

The bank said Social Security numbers, online banking credentials, and account balances were not accessed in that incident. A law firm is reportedly considering a class-action lawsuit related to the vendor breach.

US Bank also experienced a larger third-party data exposure in 2022. That incident reportedly affected about 11,000 customers after a vendor accidentally shared a file containing information on closed credit card accounts.

The exposed data included names, addresses, Social Security numbers, dates of birth, account numbers, and outstanding balances. US Bank continues to monitor the LockBit claim while its investigation remains ongoing.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post US Bank Investigating Data Breach Following LockBit Ransomware Claim appeared first on Cyber Security News.

Shell Investigating Data Breach Following Cl0p Ransomware Group Claim

Multinational energy giant Shell has launched an active investigation after the notorious Cl0p ransomware syndicate claimed responsibility for exfiltrating sensitive internal data.

Security researchers and enterprise defenders are closely monitoring the situation as forensic teams work to assess the legitimacy and operational scope of the cyberattack.

The extortion collective listed Shell on its dark web leak portal, alleging the theft of approximately 89 gigabytes of proprietary corporate data. According to statements published on the cybercrime group’s site, the compromised files purportedly include engineering drawings, facility photographs, project roadmaps, and testing reports. Threat actors typically deploy these preview listings to exert maximum pressure on enterprise victims before leaking full datasets.

Corporate espionage and extortion attempts targeting energy infrastructure carry severe operational and supply chain implications. While Cl0p has historically focused on extortion via data exfiltration rather than deploying encryptors on operational technology networks, the exposure of engineering blueprints and facility audits introduces significant safety and counterparty security risks. Analysts emphasize that verifying file authenticity remains standard procedure during extortion incidents.

Shell acknowledged the claims and activated internal cyber incident response protocols to evaluate the integrity of its networks. Company representatives noted that investigations remain ongoing alongside third-party digital forensics firms to determine whether production environments or employee assets suffered unauthorized access.

“We are working with our security teams and relevant experts to investigate the situation,” a Shell spokesperson said.

The company has not confirmed any operational disruption to its refineries, drilling operations, or core IT infrastructure. Incident responders continue analyzing boundary telemetry, identity logs, and third-party software deployments to identify possible initial access vectors.

Cl0p, also tracked as TA505 or FIN11 affiliates, has a long history of carrying out automated, mass-exploitation campaigns against enterprise software. The syndicate previously executed zero-day supply chain attacks against managed file transfer platforms, including MOVEit Transfer and Accellion FTA, compromising hundreds of organizations worldwide.

Recent threat intelligence reports also connect the group to campaigns targeting exposed enterprise web platforms and product lifecycle management tools.

Rather than utilizing traditional ransomware encryption, the group frequently relies on pure extortion. Threat actors exfiltrate structured databases and unencrypted files using custom web shells, demanding multi-million-dollar ransoms in exchange for non-publication.

This approach complicates enterprise incident triage, as file systems operate normally while confidential data remains compromised.

Security teams handling critical infrastructure assets must enforce robust perimeter controls and strict vendor access policies. Organizations should identify all internet-facing management appliances, audit external-facing dependencies, and promptly patch edge appliances against known vulnerabilities.

Enterprises are advised to enforce centralized log aggregation across authentication gateways, deploy multi-factor authentication on all administrative services, and review outbound traffic for anomalous exfiltration spikes.

As forensic investigations into Shell’s environment proceed, organizations across the energy sector should review their exposure to known threat actor infrastructure and maintain tested incident communication plans.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Shell Investigating Data Breach Following Cl0p Ransomware Group Claim appeared first on Cyber Security News.

Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems

Levi Strauss & Co., the denim giant, reported a cybersecurity incident where an unauthorized third party accessed the company’s internal systems via a targeted social engineering attack.

According to a regulatory filing submitted to the U.S. Securities and Exchange Commission, the attackers manipulated three employees into surrendering access to their company-issued computers, ultimately allowing the intruders to reach and extract certain corporate files.

Levi Strauss said the unauthorized party used social engineering techniques, a method that relies on psychological manipulation rather than technical exploits, to trick employees into granting access to their devices.

The San Francisco-based apparel maker has not disclosed the exact tactic used, whether phishing emails, deceptive phone calls, or impersonation, but industry reports note that many similar recent attacks have relied on vishing, or voice-based phishing calls impersonating IT staff or help-desk personnel.

Levi Strauss Data Breach

Once inside, the attackers accessed company files stored on the three compromised machines and exfiltrated a portion of that corporate information before the intrusion was detected and shut down.

Upon discovering the breach, Levi Strauss activated its incident response protocols, isolated the affected systems, and brought in third-party cybersecurity experts to investigate the scope of the compromise.

The company stated that its rapid containment measures successfully terminated the unauthorized access, and preliminary findings from the ongoing investigation indicate that no consumer data was affected.

Levi Strauss also confirmed that the incident did not disrupt any business operations, and the company continues to notify affected parties and relevant regulators in line with applicable data protection laws.

In its SEC filing, signed by senior vice president and general counsel David Jedrzejek, Levi Strauss said it does not currently believe the breach will have a material effect on its business strategy, financial condition, or operating results.

The company, which carries a market capitalization of roughly $9.35 billion, emphasized that the investigation remains active and that further details could emerge as the probe progresses.

Levi Strauss now joins a growing roster of major global companies hit by a surge in social engineering-driven cyberattacks and ransomware campaigns over the past several months.

Data reviewed by Reuters shows that threat actors using ransom demands and phone-based social engineering tactics have targeted dozens of prominent U.S. financial institutions and corporations in recent weeks, with more than 200 companies caught in these digital traps over just five weeks.

Just days earlier, a Dutch luxury retail chain also disclosed a cyberattack affecting one of its logistics providers, underscoring how attackers are increasingly exploiting human trust rather than software vulnerabilities to breach enterprise networks [web:8].

The Levi Strauss incident is a reminder that even well-resourced corporations remain vulnerable to low-tech, high-impact tactics like social engineering.

Security experts continue to stress that employee awareness training, multi-factor authentication, and strict verification protocols for IT support requests are critical defenses, especially as AI tools make impersonation and deception campaigns cheaper and more convincing for attackers to execute at scale.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems appeared first on Cyber Security News.

Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT).

The incident resulted in the compromise of login credentials linked to approximately 200 user and technical accounts. BIT detected unusual activity on its SharePoint environment on Tuesday, July 28.

Security specialists quickly investigated the anomalies and confirmed that the servers may have been targeted through recently disclosed Microsoft SharePoint vulnerabilities.

The agency immediately blocked internet access to the affected SharePoint systems and applied the required security fixes. Microsoft disclosed multiple SharePoint vulnerabilities in mid-July.

Organizations widely use SharePoint for document storage, collaboration, internal communication, and file sharing. BIT operates several SharePoint servers in Swiss federal data centers to support government services and employee workflows.

Hackers Breach Swiss SharePoint

After Microsoft released security updates, BIT began installing the patches on its systems. However, investigators believe unknown threat actors may have exploited the vulnerabilities before all defensive actions were completed.

The exact identity, origin, and motives of the attackers remain unknown. During the ongoing forensic investigation, security teams discovered on Friday, July 31, that several login credentials had been compromised.

The affected accounts included both standard user accounts and technical accounts used by systems or applications. BIT responded by resetting passwords for all impacted accounts.

Authorities said current analysis has not identified evidence that files, documents, or other data were exfiltrated from the SharePoint platform. The compromise appears to be limited to credentials associated with around 200 accounts.

Investigators also noted that confidential government information and highly sensitive personal data are not permitted to be stored on the affected SharePoint environment.

BIT is working with the Federal Office for Cyber Security (BACS) and Microsoft to investigate the intrusion and determine the full scope of the attack. The technical investigation remains active, and authorities have not ruled out further findings as forensic work continues.

As a precaution, BIT is reinstalling the affected SharePoint servers. External internet access to the platform will remain blocked until the recovery work is completed and officials confirm that the environment is secure.

Federal administration employees can still access documents internally and use alternative methods to share information with external personnel.

The incident highlights the ongoing risks facing organizations that run internet-facing collaboration platforms. SharePoint systems can become attractive targets because they often hold business documents, provide access to internal users, and integrate with other Microsoft services.

Prompt patching, credential monitoring, network restrictions, and server rebuilding remain important response measures after suspected exploitation.

BIT reported the incident to BACS and the State Secretariat for Security Policy, or SEPOS, within the required timeframe under Switzerland’s Information Security Act.

The agency also shared relevant technical indicators from the attack on critical infrastructure with operators via the BACS platform, helping other organizations identify potential signs of related intrusion activity.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts appeared first on Cyber Security News.

❌