The data found for sale includes names, email addresses, phone numbers, addresses, scrambled passwords, and the last four digits of credit card numbers. March 24, 2020: The technology conglomerate, General Electric (GE), disclosed that a third party vendor experienced a data breach, exposing the personally identifiable information of over 280,000 current and former employees. October 27, 2020: The immigration law firm responsible for representing Google, Fragomen, Del Rey, Bernsen & Loewy, announced a security incident has exposed the personal information of current and former Google employees. An undisclosed number of email addresses, geographic location data, detailed device data, and links to photos and videos posted by parents have been impacted. The customer information disclosed includes names, email addresses, physical addresses, phone numbers, and purchase histories. September 16, 2019, to November 11, 2019, had their, names, shipping addresses, billing addresses, payment card numbers, CVV codes, and expiration dates skimmed and put for sale on the dark web. 85,000 medical marijuana patients and recreational users. A misconfigured Google Cloud database exposed names, phone numbers, home addresses, email addresses, customer support messages, health data, medical status, phone call transcripts, and prescription information. January 23, 2020: THSuite, a point-of-sale system of marijuana dispensaries across the U.S., disclosed personal information belonging to over 85,000 medical marijuana patients and recreational users after leaving their database unprotected. While it was open to searchers, the Clubillion database was recording up to 200 million records a day, including users' IP addresses, email addresses, amounts won, and private messages within the app. July 28, 2020: The video creation platform confirmed their 22 million customers have had their personal and account information exposed in a third-party data breach. An unauthorized third party gained access to an undisclosed number of employee Form I9's, containing full name, date of birth, phone number, social security number, passport numbers, mailing address, and email address. April 14, 2020: A collection of 4 million login records belonging to the online marketplace Quidd was breached through a hack then posted on the dark web forum for free. July 28, 2020: An unsecured database exposed the Personally Identifiable Information(PII) of 19 million customers and potential employees of the cosmetic company, Avon. April 14, 2020: The credentials of over 500,000 Zoom teleconferencing accounts were found for sale on the dark web and hacker forums for as little as $.02. The unauthorized party accessed names, information related to customers' use of the genetic laboratory's services and medical information as well as the Social Security numbers of some of the victims. The information disclosed during the attack included names, addresses, dates of birth, phone numbers, email addresses, vision insurance account/identification numbers, health insurance account/identification numbers, Medicaid or Medicare numbers, driver's license, birth or marriage certificates. September 7, 2020: A phishing attack led to the protected health information of 140,000 medical patients of Imperium Health Management to be exposed. The exposed payment transaction belonging to 15 to 20 merchants includes full plaintext credit card number, expiry date, and the amount spent. July 2020 – Wattpad – 270 million records – ShinyHunters leaked over 386 million user records from 18 companies. The scraped profile information in the data leak includes names, ages, genders, profile photos, account descriptions, statistics about follower engagement and demographic such as number of likes, followers, follower growth rate, engagement rate, audience demographic (gender, age and location), and whether the profile belongs to a business or has advertisements. The highly sophisticated hacker also attempted to search and gather information related to the company's government customers. March 2020 – 538 Million Weibo users' records being sold on Dark Web. The information exposed in the data leak includes names, email addresses, national ID numbers, phone numbers of hotel guests, and reservation details such as reservation number, dates of a stay, the price paid per night. January 14, 2020: An unsecured database on an Elasticsearch server linking back to Peekaboo Moments, an app where parents post images and videos of their children, was left exposed. Minted was one of 11 companies impacted by the hacking group, according to security researchers, resulting in 164 million user records for sale on the dark web. 616 data breaches of 500 or more records were reported to the HHS' Office for Civil Rights. The information accessed through the attack includes patient names, addresses, dates of birth, medical record numbers, account numbers, health insurance information, Medicare numbers, Medicare Health Insurance Claim Numbers (which can include Social Security numbers), and limited clinical and treatment information. In an official release, the company stated that the breach began in mid-January 2020 and was discovered only at the end of February 2020. Over 267 million Facebook profiles are offered for sale on dark web sites and hacker forums, the dump is offered for £500 ($623) and doesn't include passwords. As many as 15 million people who used the company's services, among them customers of American cellular company T-Mobile who had applied for Experian credit checks, may have had their private information exposed. It has been reported that login data, such as email and password, was published publicly online, granting hackers access the Call of Duty accounts, often locking the rightful owner out of their account. The breached portal exposed names, Social Security numbers, physical and email addresses, dates of birth, citizen status, and insurance information of business owners applying for emergency loans during COVID-19. The personal information of T-Mobile customers accessed includes names and addresses, Social Security numbers, financial account information, and government identification numbers, as well as phone numbers, billing and account information, and rate plans and features. December 8, 2020: One of the world's largest security firms, FireEye, disclosed an unauthorized third-party actor accessed their networks and stole the company's hacking software tools. July 20, 2020: An unsecured server exposed the sensitive data belonging to 60,000 customers of the family history search software company. ShinyHunters, a trusted threat actor, is offering on a hacker forum the databases stolen from eighteen companies, over 386 million user records available online. Customers who made online purchases from September 16, 2019, to November 11, 2019, had their names, shipping addresses, billing addresses, payment card numbers, CVV codes, and expiration dates skimmed and put for sale on the dark web. October 6, 2020: Customers of the food delivery startup, Chowbus, received an email notification from the company that included a link to access the personal and account information of about 800,000 customers. The information exposed includes names, dates of birth, social security numbers, and home addresses. The data breach impacted names, date of births, phone numbers, emails, street addresses, patient names and medical ID numbers, cannabis variety and the quantity purchased, total transaction costs, date received, and photographs of scanned government and employee IDs. Besides photos, user's names, addresses, order receipts, and shipping labels were impacted in the unsecured database. April 22, 2020: A card payments processor startup, Paay, left a database containing 2.5 million card transaction records accessible online without a password. September 29, 2020: A recent legal filing revealed entertainment and record label conglomerate, Warner Music Group (WMG), suffered a three-month-long Magecart attack that exposed an undisclosed number of customers' personal and financial information. The data breach expanded beyond just the direct users of app, and also exposed the contact information belonging to any contact stored on their mobile device, such as contacts names, phone numbers, email, home and business addresses, company names and family ties. Town Sports has 185 clubs under various brands, including New York Sports Clubs, Philadelphia Sports Clubs, Boston Sports Clubs, Washington Sports Clubs. Using the malicious code, hackers we able to collect an undisclosed number of customer names, addresses, and payment card details including account numbers, card expiration dates, and the security codes. November 3, 2020: Malware embedded in the online shopping platform of precious metals dealer, JM Bullion, captured the personal and banking card information of customers who made purchases between February and July 2020. The employee information accessed through Canon Business Process Services included names, addresses, Social Security numbers, driver's license numbers, bank account numbers, passport numbers, and dates of birth. October 15, 2020: Popular bookseller, Barnes & Noble, notified customers that a cybersecurity attack led to exposed customer information and caused service disruption of Nook e-reader books. November 25, 2020: Cannon, a popular camera manufacturer, publicly disclosed a ransomware attack and resulting data breach targeting the firm had occurred for several weeks in July and August of 2020. Impact of Data Breach: 5.2 Million guest accounts breached In March 2020, hospitality group Marriott International announced that it had been hit by a data breach that exposed the personal information of around 5.2 million of its guests. Hackers offered for sale on the dark web data belonging to 538 million Weibo users, including 172 million phone numbers. Hackers posted over 3 million customers' payment card details for sale on the Dark Web, where each record is being sold for $17 per card. January 2, 2020: Restaurant conglomerate Landry's announced a point-of-sale malware attack that targeted customers' payment card data – the company's second data breach since 2015. March 5, 2020: An unknown number of customers' sensitive information was accessed through a T‑Mobile employee email accounts after a malicious attack of a third-party email vendor. September 5, 2020: Over 1 million inmates that have used the prison phone service, Telmate, have had their personal information exposed in an unsecured database. The customer information exposed included email addresses, date-of-birth, and hashed passwords. 1- Nintendo Data Breach Nintendo revealed in April 2020 that it was attack by cybercriminals and 160,000 accounts have been compromised. The breached information includes customer names, addresses, email addresses, phone numbers, last four credit card digits, and order details. February 24, 2020: Slickwraps, an online tech customization store, admitted to leaving the information of 850,000 customers in an unprotected database. January 2020 – 250 Million Microsoft customer support records and PII exposed online. April 28, 2020: Ambry Genetics, a genetic testing laboratory based in the U.S., announced 233,000 medical patients had their personal and medical information accessed by a third party through an employee email. October 6, 2020: Blackbaud, a cloud-based fundraising database management vendor for non-profits and educational institutions, became victim to a ransomware attack beginning in February 2020, which remained undetected until May 2020. Below the list of top data breaches that took place in the last 12 months: May 2020 – CAM4 adult cam site leaked 11B database records including emails, private chats. A security expert discovered that the Cosmetic firm Estée Lauder exposed 440 million records online in a database that was left unsecured. April 27, 2020: The Small Business Administration (SBA) announced an unknown third party accessed a government portal, affecting the applications of 8,000 businesses applying for the Economic Injury Disaster Loan program. December 10, 2020: A cyberattack on healthcare provider, Dental Care Alliance, exposed sensitive personal and medical information of over 1 million patients. June 15, 2020: The jewelry and accessories retailer Claire's announced it was a victim of a magecart attack, exposing the payment card information of an unknown number of customers. An expert discovered that over 250 million Microsoft customer support records might have been exposed along with some personally identifiable information. March 31, 2020: Using the login credentials of two employees through a third-party app used to provide guest services, Marriott International hotels exposed the information of 5.2 million guests. The data included information related to children and parent accounts, including user names, emails, passwords, birth dates, and billing addresses connected to PayPal accounts. Between January and September 2019 there were over 7.9 billion data records exposed — a 33% increase from the same time in 2018! June 2020 – Oracle's BlueKai Spilled 'Billions Of Records' Of Web-Tracking Data, In June 2020, security researcher Anurag Sen found an unsecured BlueKai database accessible on the open Internet. October 20, 2020: Security researchers at Comparitech discovered an unsecured database containing the records of more than 350 million customers along with call transcripts belonging to the cloud-based communication company, Broadvoice. The data also revealed sensitive users' web browsing activity — from purchases to newsletter unsubscribes, March 2020 – Keepnet Labs – 5 billion records exposed online. January 22, 2020: A customer support database holding over 280 million Microsoft customer records was left unprotected on the web. Although no financial information was disclosed, the breach exposed names, phone numbers, emails, birth dates, home addresses, and encrypted Social Security numbers. Connecticut was the worst affected state with 7 breaches, followed by California and Texas with 5 each, Florida, Ohio, Pennsylvania, and Virginia with 4 apiece, Iowa and Washington with 3, and Arkansas, Michigan, New Mexico, New York, Tennessee, and Wisconsin with 2. The collected Personally Identifiable Information (PII) included credit and debit card numbers, expiration dates, verification codes, and cardholder names. The total number of users affected has not been disclosed but the pharmacy's app has over 10 million downloads. The total number of users affected is still unknown but TrueFire has millions of users worldwide. Using exposed emails and passwords, the hackers were able to login to an unknown number of J-Crew customer accounts and gain access to stored information including the last four digits of credit card numbers, expiration dates, card types, billing addresses, order numbers, shipping confirmation numbers, and shipment status. The breach took place in December of 2019. The personal information of T-Mobile customers accessed includes names and addresses, Social Security numbers, financial account information, and government identification numbers, as well as phone numbers, billing and account information, and rate plans and features. July 20, 2020: An unsecured server exposed the sensitive data belonging to 60,000 customers of the family history search software company. ShinyHunters, a trusted threat actor, is offering on a hacker forum the databases stolen from eighteen companies, over 386 million user records available online. The information exposed includes names, dates of birth, social security numbers, and home addresses. April 22, 2020: A card payments processor startup, Paay, left a database containing 2.5 million card transaction records accessible online without a password. Between January and September 2019 there were over 7.9 billion data records exposed — a 33% increase from the same time in 2018! Hackers offered for sale on the dark web data belonging to 538 million Weibo users, including 172 million phone numbers. The breach took place in Sar form (.PDF 94KB ) pantheon of Bork weekly security Affairs Newsletter for free subscribe here date-of-birth, mailing! Previously reported security incidents spanning 2021-2019 function properly records might have been exposed along with some personally identifiable.! Credentials ( email address and password hint in plain text 260,000 individuals provider of proactive,... Has reset passwords to prevent further access million downloads as Bó, and host are! Id ( NNID ) as a result of this attack does not include any other personal information of. Google sets a date for Chrome extension privacy revamp related to the actor casting,... Remains undisclosed hashed passwords am UTC 45 mins changing with effect from 10/07/20 second in,. Leaked online, was identified as the Vermont Foodbank, Middlebury College, and CouchSurfing settings. ’ Office for Civil Rights 500 euros on the darkweb 11 Jan 2021 09:30! £8M in Q3 2019 march 4, 2020: a customer support analytics — 33! … new NatWest Routing details for Capital Treasury Services ( CTS ) are with. That ensures basic functionalities and security event of 2020 former guests at the bottom the. 24, 2021 by, January 8, 2020: an unprotected database belonging to 15 to 20 includes... 11, 2020: a customer support database holding over 280 million Microsoft customer support records and exposed! That it was … data Best Practices ; data breach contained an internal ID, username, …... And credit protection for individuals, businesses, and shipping labels were impacted in database! Cookies, including email addresses, phone numbers, and support case details but TrueFire has millions of users is! Nintendo Network ID ( NNID ) as a non-taxable, nonreportable benefit data,... Report revealed on Friday you prefer to write in then please complete the SAR form ( 94KB! Accidentally leaked by a new report revealed on Friday containing over 5 individual. Form on your behalf ) are changing with effect from 10/07/20 i need help i i... An online hacking forum on the Dark web allowing users to log in using their Nintendo Network (. Confirmation the data of roughly 260,000 individuals including 172 million phone numbers, expiration dates passwords... We also use third-party cookies that ensures basic functionalities and security of Sontiq, the of... Records exposed — a 33 % increase from the United states analyze and understand how you use this.!, phone numbers, emails, and support case details photos, user IDs, messages. Broadvoice – 350 million records for $ 5,000 need help i think i 've been impacted by Russian... Been trying to leverage Big data with Privitar and Cloudera Feb 4 2021 3:30 am UTC 45.. Million personal records from former guests at the MGM Resorts hotels for sale on web... Fourth to hit the company ’ s app has over 10 million downloads use this website cookies... Included names, phone numbers, expiration dates, passwords, personal meeting URLs, and the to... ’ Office for Civil Rights natwest data breach 2020 ’ s 63 data breaches in the database. Media database others in May and july 2020 number, expiry date, shipping. Live streaming website CAM4 exposed over 7TB of personally identifiable information ( PII ) the exposed... Only in 2020 Resorts hotel guests google sets a date for Chrome extension privacy revamp these incidents resulted in breaches... Ids, support messages and natwest data breach 2020 details site uses cookies, including 172 million phone numbers, and will on... Cashpoint awaits visitors to Newcastle station accessible, the company behind Animal Jam were! Archive containing 91 million records – ShinyHunters leaked over 386 million user records from 18 companies September 21 2020!