Cyber Crime and Data Breach Round Up 2023

Find out about some of the biggest cyber crimes and data breaches of 2023 as we take you on a month by month journey below!

January saw Royal Mail hit by a ransomware attack, preventing customers from sending out letters and parcels overseas until it was resolved.  The ransomware attack affected computer systems that Royal Mail used to despatch deliveries abroad, with speculation that the ransomware used was “LockBit”.

Usually, a favourite for serving burgers and fries, in February, Five Guys were served with a lawsuit after a data breach impacting job applicants.  It was revealed that the incident exposed sensitive information including, names and driver’s license numbers.

The ongoing development of AI, saw ChatGPT introduced, but with increased popularity comes a bigger target on your back.  After a 9-hour outage, users saw others’ billing information, including address, card type and expiration date.  Chat history was also leaked – let’s hope you were all just asking for cake recipes!

Nearly 300 UK restaurants that are part of the Yum! Brand (Pizza Hut, KFC and Taco Bell) were forced to close after a ransomware attack that affected their IT systems.  Employees were told that their names, driver’s license numbers and other ID card numbers were among the data that was taken by the attackers.

Nearly 7,000 employees of Sony’s gaming branch, Sony Interactive Entertainment, were affected by a ransomware attack.  The ransomware group “C1op” were responsible for exploiting a vulnerability within the division’s file transfer software and stealing data, however, the nature of the data was not specified.

MOVEit, a type of software designed to move sensitive files around securely was hacked.  This has impacted a number of companies, including: the BBC, British Airways and Boots.  Staff from companies were warned that personal data may have been stolen, including bank details and national insurance numbers, however, they have stated that a ransom has not been demanded.

Over 34 million Indonesian passports were leaked in mass data breach impacting the country’s Immigration Directorate General at the Ministry of Law and Human Rights.  The exposed data included full names, passport numbers, dates of issue, expiry dates and dates of birth of all 34 million passport holders.  Those affected were told that this puts them at risk of being victims of identity theft.

Japanese watchmaker Seiko has confirmed it suffered a Black Cat ransomware attack and warned the incident has led to a data breach.  Seiko have confirmed that 60,000 items of personal data from customers and partners were compromised by the attacker.  Data included names, addresses, phone numbers and email addresses, although they have stated that the cybercriminals did not access credit card information.

Millions of golf fans have been affected by a breach to the American sports gear giant Topgolf Callaway.  The company distributed an email to all known victims stating that an unknown third party had hacked into company systems and impacted the availability of some of its e-commerce services.  Attackers stole sensitive data including full names, shipping addresses, phone numbers and account passwords.

The genetic testing company 23andMe were at the centre of attention in October, when a hacker stole millions of user records.  The hacker, who goes by Golem, then leaked the records on the cybercrime forum BreachForums.  23andMe have blamed the incident on customers reusing passwords and the opt-in feature called DNA Relatives.

The British Library, a research library in London and the national library of the UK, stated they have evidence that user data was hacked in a cyber-attack and offered for sale on the dark web.  The ransomware group Rhysida have taken responsibility for the attack and have said they will auction off the stolen data.

The videogame studio behind Spider-Man, Spyro the Dragon and Ratchet & Clank, have been victims of a huge hack.  It is believed that the data includes private employee data, internal company emails and unreleased game footage.  Hackers have demanded $2 million to keep the stolen information private but leaks of their upcoming “Wolverine” game have already been released.

Leave a Reply

Your email address will not be published. Required fields are marked *