Week in Breach from Excel Office Services

This week, Dunkin’ faces a 2nd credential stuffing attack, a Canadian photo-sharing platform discovers hack, a French cybersecurity society is compromised and Australian property data is leaked.

Dark Web ID Trends:
Top Source Hits: ID Theft Forums (99%) 
Top Compromise Type: Domain (99%)
Top Industry: Medical and Healthcare
Top Employee Count: 1 – 10 Employees (94%)

United States – Dunkin’ Donuts

Exploit: Credential stuffing attack
Dunkin’ Donuts: One of the world’s leading baked goods and coffee chains
>> Read full details on our blog.


United States – Truluck’s Seafood, Steak & Crab House 

Exploit: Malware injection into point-of-sale (POS) systems
Truluck’s: Houston-based chain restaurant.
>> Read full details on our blog. 


United States – DataCamp

Exploit: Unauthorized system access
DataCamp: Online learning platform for data science
>> Read full details on our blog. 


Canada – 500px

Exploit: Server hack
500px: Photo-sharing platform 
>> Read full details on our blog. 


Canada – College of Physicians and Surgeons of Saskatchewan

Exploit: Employee breach
eHealth Saskatchewan: Electronic health record system
>> Read full details on our blog. 


France – CLUSIF

Exploit: Human error resulting in data leak
CLUSIF: Paris-based information security society
>> Read full details on our blog. 


Australia – LandMark White

Exploit: Database leak
LandMark White: Large property evaluation firm
>> Read full details on our blog. 

 

Australia – Optus

Exploit: Website glitch and phishing
Optus: Telecommunications company seeking to be first-in-market with 5G home broadband service
>> Read full details on our blog. 

 

In Other News:

MyFitnessPal and CoffeeMeetsBagel data go for sale on the Dark Web

After the breach of MyFitnessPal last year involving 150M user accounts, the data has finally been packaged up along with stolen credentials from 15 other websites to be sold on the Dark Web. The asking price? Less than $20,000 in Bitcoin…

Read more