Data Breach Report: May 2024 Edition - PKWARE® (2024)

Table of Contents
Giant Tiger PandaBuy Marriott AT&T FAQs

Data breaches in April 2024 exposed billions of records globally. This report highlights some of the most concerning incidents, including the compromise of millions of customer records at AT&T and retailer Giant Tiger, alongside a major attack targeting the international shopping platform PandaBuy. This month also unpacked major breaches from earlier in the year, such as the Marriott incident. For example, in April, Marriott admitted to misleading the court regarding the encryption used during a massive 2018 data breach, a revelation that could significantly impact ongoing legal battles.

Giant Tiger

In March 2024, the Canadian discount store chain Giant Tiger Stores Limited suffered a data breach that exposed over 2.8 million customers’ records. Giant Tiger confirmed that the breach occurred on March 4 due to a cybersecurity incident involving one of its third-party vendors.

Scale of the Breach: Over 2.8 million unique customer records were leaked.

Data Exposed: The breach potentially exposed names, email addresses, phone numbers, and physical addresses of Giant Tiger customers.

Cause of the Breach: The cause of the Giant Tiger data breach is attributed to a security issue with a third-party vendor they used for customer communications and engagement.

Giant Tiger themself acknowledged the incident: While they didn’t comment on the authenticity of the leaked data in hacker forums, they did confirm a security issue with a third-party vendor in early March 2024 that resulted in unauthorized access to customer contact information. – https://www.cbc.ca/news/business/giant-tiger-customer-data-breach-1.7154572

PandaBuy

In April 2024, a data breach affected PandaBuy, a popular platform for purchasing items from China.

Scale of the Breach: Threat actors claimed to have exploited vulnerabilities in PandaBuy’s system and leaked a database containing information on over 1.3 million users.

Data Exposed: The leaked data reportedly included user IDs, full names, phone numbers, email addresses, home addresses, login IPs, and order details.

Cause of the Breach: The attackers, known as Sanggiero and IntelBroker, claimed to have exploited “several critical vulnerabilities in the platform’s API” and other bugs to gain access to PandaBuy’s internal systems.

PandaBuy acknowledged the incident and claimed it was due to hackers exploiting vulnerabilities in their platform’s security.

Marriott

The Marriott data breach which likely began in 2014 but Marriott didn’t discover it until 2018 is again in a complex situation in April 2024.

Marriott spent over five years downplaying a major 2018 data breach, claiming their encryption (AES-128) was unbreachable. However, in a surprising turn of events during a US District Court hearing on April 10th, the company’s lawyers admitted they hadn’t even used AES-128 at the time of the breach and instead using a hashing method called SHA-1, which isn’t considered encryption.

Marriott’s latest statement update
“Following an investigation with several leading data security experts, Marriott initially determined that the payment card numbers and certain passport numbers in the database tables involved in the Starwood database security incident that Marriott reported on November 30, 2018 were protected using Advanced Encryption Standard 128 encryption (AES-128). Marriott has now determined that the payment card numbers and some of the passport numbers in those tables were instead protected with a different cryptographic method known as Secure Hash Algorithm 1 (SHA-1).” Source: https://news.marriott.com/news/2019/01/04/marriott-provides-update-on-starwood-database-security-incident

The Marriott data breach of 2018 was a major cybersecurity incident that affected hundreds of millions of guests. Here’s a summary of what happened:

Scale of the Breach: Up to 500 million guest records were compromised. This number includes duplicate entries, but it still represents a significant portion of Marriott’s customer base.

Data Exposed: Personal information of up to 500 million guests was compromised, including credit card details, passport numbers, and birthdates.

Cause of the Breach: The breach originated from a flaw in the security of Starwood’s guest reservation system. Attackers gained access in 2014, two years before Marriott acquired Starwood.

AT&T

While the AT&T data breach announcement happened in late March 2024 and we have covered the same in our April 2024 data breach report, details continued to emerge throughout April.

Scale of the Breach: The exposed data appears to be from 2019 or earlier, indicating the breach might have occurred before then.

Data Exposed: The breach exposed the personal information of millions of AT&T customers, including current and former ones. Estimates suggest around 73 million people were affected.

Cause of the Breach: AT&T is still investigating the source. They haven’t confirmed if the data originated from their systems or a vendor they work with.

AT&T’s official statement on the data breach is here: https://about.att.com/story/2024/addressing-data-set-released-on-dark-web.html

Data Breach Report: May 2024 Edition - PKWARE® (2024)

FAQs

What was the data breach in May 2024? ›

Records Breached: 560 million

In May, 2024, over 560 million customer records, including order history, payment information, name, address and email data, were leaked online and offered for sale by hackers who infiltrated Ticketmaster's systems.

How do I know if I was part of a data breach? ›

Pentester, a cybersecurity firm, has set up a tool to let you see if your data was part of the breach. Use a web browser to navigate to npd.pentester.com and enter your first and last name and birth year. You'll see a list of breached accounts, including the last four digits of the leaked Social Security numbers.

What happens if you don't report a data breach? ›

Failing to do so can result in heavy fines and penalties and an investigation by the Information Commissioner's Office (ICO).

What are the three biggest data breaches of all time? ›

  1. 1. Yahoo. Year: 2013-2016. Number of records affected: Over 3 billion user accounts. ...
  2. Equifax. Year: 2017. ...
  3. 3. Facebook. Year: 2019. ...
  4. First American Financial Corporation. Year: 2019. ...
  5. Aadhaar. Year: 2018. ...
  6. MySpace. Year: 2013. ...
  7. LinkedIn. Year: 2021. ...
  8. Friend Finder Networks. Year: 2016.
Aug 21, 2024

Who got hacked in 2024? ›

Recent Cybersecurity Attacks and Data Breaches -2024
Month/YearCompanyIncident Type
July 2024Rite AidRansomware
July 2024AT&TData Breach/Theft/Leak
July 2024Loretto Management CorporationData Breach/Theft/Leak
July 2024Advance Auto PartsData Breach/Theft/Leak
95 more rows

What is this global outage? ›

The global outage was caused by a bugged patch pushed by one of the world's largest cyber security providers and estimated to cost $1 billion. The outage was a stark reminder of the importance of cyber resilience in an increasingly digital world.

How do I know if a data breach letter is real? ›

Real data breach notifications should always come from a company or organization's official email address. Be wary of emails from free services like Gmail, Yahoo, or any suspicious-looking domains.

Has my phone number been in a data breach? ›

How To Check If My Phone Number Is Leaked. Go to ID Protection Data Leak Checker and find out if your phone number appeared in any data leaks.

Is my email on the dark web? ›

Use a free Dark Web scanner.

Services like Aura's Dark Web scanner or HaveIBeenPwned check to see if your email address or passwords have been compromised in any data breaches.

Should I be worried about a data breach? ›

Data breach is serious and can affect you in many ways. Change any exposed passwords. If your password is subject to a breach, then you should update your login credentials. Your new password should be strong and unique, to prevent hackers from randomly guessing the correct password.

What is an example of a data breach? ›

Examples of personal data breaches include: Human error, for example an email attachment containing personal data being sent to the incorrect recipient or records being deleted accidentally. Sharing of passwords or other credentials with third parties.

Can I sue for data breach? ›

Anyone who has been affected by a data breach may have the right to file a lawsuit, including individuals, businesses, or organizations that have suffered harm due to the breach.

How many data breaches in 2024? ›

The Identity Theft Resource Center (ITRC) says the number of data breaches in the first half of 2024 (about 1.1 billion) marks a 490% uptick over the first half of the year prior. The number of data breach victims in just the second quarter of 2024 (1 billion) represented a jaw-dropping 1,170% increase over Q2 2023.

What is the Chase data breach update 2024? ›

How was Chase hacked? The JP Morgan data breach occurred due to a software flaw that allowed unauthorized access by three system users. This breach, discovered in February 2024, exposed sensitive financial and personal data. The bank has since applied a software update to restrict unauthorized access.

What do most data breaches start with? ›

Weak and stolen credentials

Although hacking attacks are frequently cited as the leading cause of data breaches, it's often the vulnerability of compromised or weak passwords or personal data that opportunistic hackers exploit.

What was the data breach incident? ›

A data breach is an incident where information is stolen or taken from a system without the knowledge or authorization of the system's owner. A small company or large organization may suffer a data breach.

How did National Public Data get my information? ›

How was my personal information stolen in the National Public Data breach? National Public Data said it obtains personal information from public record databases, court records, state and national databases and other repositories nationwide.

Who's been hacked recently? ›

  • 23andMe to pay $30 million in genetics data breach settlement. ...
  • RansomHub claims Kawasaki cyberattack, threatens to leak stolen data. ...
  • Fortinet confirms data breach after hacker claims to steal 440GB of files. ...
  • Transport for London confirms customer data stolen in cyberattack.

Has AT&T been hacked? ›

What you need to know about AT&T data breach that affected 'nearly all wireless customers' Call and text logs were stolen by hackers during a 2022-2023 attack, the company revealed last week.

Top Articles
Can I Change My LLC to an S Corporation?
Best Internet Speed Tests | How to Check Your Wi-Fi Speed
SZA: Weinen und töten und alles dazwischen
7 C's of Communication | The Effective Communication Checklist
Calvert Er Wait Time
Paris 2024: Kellie Harrington has 'no more mountains' as double Olympic champion retires
Kansas Craigslist Free Stuff
Roblox Developers’ Journal
Progressbook Brunswick
Chastity Brainwash
Sams Gas Price Fairview Heights Il
General Info for Parents
Chic Lash Boutique Highland Village
Puretalkusa.com/Amac
25Cc To Tbsp
Swedestats
Bridge.trihealth
Race Karts For Sale Near Me
ZURU - XSHOT - Insanity Mad Mega Barrel - Speelgoedblaster - Met 72 pijltjes | bol
Halo Worth Animal Jam
Hdmovie2 Sbs
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Why do rebates take so long to process?
Like Some Annoyed Drivers Wsj Crossword
Knock At The Cabin Showtimes Near Alamo Drafthouse Raleigh
Understanding Gestalt Principles: Definition and Examples
Hdmovie2 Sbs
Cb2 South Coast Plaza
Skidware Project Mugetsu
Toonkor211
Kempsville Recreation Center Pool Schedule
Helloid Worthington Login
Xfinity Outage Map Lacey Wa
Jambus - Definition, Beispiele, Merkmale, Wirkung
Puerto Rico Pictures and Facts
Composite Function Calculator + Online Solver With Free Steps
Joe's Truck Accessories Summerville South Carolina
Vip Lounge Odu
No Hard Feelings Showtimes Near Tilton Square Theatre
Leatherwall Ll Classifieds
Michael Jordan: A timeline of the NBA legend
Barber Gym Quantico Hours
Search All of Craigslist: A Comprehensive Guide - First Republic Craigslist
Nba Props Covers
Best Restaurants Minocqua
Hovia reveals top 4 feel-good wallpaper trends for 2024
Crystal Glassware Ebay
What is a lifetime maximum benefit? | healthinsurance.org
Canada Life Insurance Comparison Ivari Vs Sun Life
Call2Recycle Sites At The Home Depot
Swissport Timecard
Inloggen bij AH Sam - E-Overheid
Latest Posts
Article information

Author: Otha Schamberger

Last Updated:

Views: 6531

Rating: 4.4 / 5 (55 voted)

Reviews: 94% of readers found this page helpful

Author information

Name: Otha Schamberger

Birthday: 1999-08-15

Address: Suite 490 606 Hammes Ferry, Carterhaven, IL 62290

Phone: +8557035444877

Job: Forward IT Agent

Hobby: Fishing, Flying, Jewelry making, Digital arts, Sand art, Parkour, tabletop games

Introduction: My name is Otha Schamberger, I am a vast, good, healthy, cheerful, energetic, gorgeous, magnificent person who loves writing and wants to share my knowledge and understanding with you.