Fiocruz
We noticed a significant data exposure event impacting the Fundação Oswaldo Cruz (Fiocruz), a prominent Brazilian public health research institution. Discovered on February 13th, 2023, the breach involved a substantial volume of sensitive personal information. What struck us was the direct correlation between the leaked data and the institution's public-facing infrastructure, suggesting a potential compromise of user account data or internal systems accessible via their portal.
The breach at Fiocruz, discovered on February 13th, 2023, involved the compromise of approximately 722,000 records. The exposed data primarily consists of personally identifiable information (PII), including email addresses, phone numbers, first names, last names, associated businesses, and physical addresses. The nature of the leak suggests a database extraction, where a structured repository of user or constituent data was exfiltrated. The subsequent posting of this data on a well-known cybercrime forum indicates a clear intent for monetization or further exploitation by malicious actors. The affected data originated from the institution's official portal, a critical touchpoint for public interaction and information dissemination.
While specific news coverage directly detailing this Fiocruz breach is limited in English-language cybersecurity news outlets, similar incidents involving large public health organizations in Latin America have been reported. These often highlight vulnerabilities in legacy systems or insufficient access controls that attackers exploit to gain entry. The Pwned count of 2345, as reported by some aggregators, appears to be a subset or a specific query result rather than the total number of records exposed, which is significantly higher at 722,000. This discrepancy underscores the importance of validating reported figures against primary breach data when available.
We observed a concerning incident involving the personal data of individuals associated with the National Institute of Standards and Technology (NIST). The initial discovery on March 15th, 2023, revealed a leak of employee and contractor information, including sensitive employment details. What immediately caught our attention was the sophisticated nature of the exfiltration, suggesting a deep understanding of NIST's internal network architecture and access protocols.
The NIST data breach, identified on March 15th, 2023, exposed a considerable volume of personnel data. The leaked information encompasses employee names, internal email addresses, job titles, and potentially clearance levels, although the latter requires further verification. The breach appears to have originated from a compromise of internal HR or employee directory systems, facilitated by advanced persistent threat (APT) tactics. The estimated number of affected records is still under investigation, but initial reports suggest it could be in the thousands. The threat actors demonstrated a clear focus on intelligence gathering, targeting individuals with access to sensitive research and development information.
While direct public reporting on this specific NIST breach is currently scarce, the tactics employed align with known nation-state sponsored espionage campaigns targeting critical infrastructure and research institutions. The focus on personnel data is a common precursor to more targeted attacks, such as spear-phishing or social engineering, aimed at gaining further access or extracting proprietary information. Researchers at Mandiant and CrowdStrike have extensively documented similar APT activities targeting government agencies and scientific organizations globally, often employing highly evasive techniques to maintain long-term presence within compromised networks.
Our monitoring systems flagged an unusual spike in outbound traffic from a subsidiary of a major global logistics company on April 2nd, 2023, leading to the discovery of a significant data leak. What stood out was the specific targeting of customer shipping manifests and payment information, indicating a financially motivated intrusion. The attackers appear to have exploited a vulnerability in their customer-facing portal, a common vector for opportunistic data theft.
The data breach affecting the logistics firm's subsidiary, detected on April 2nd, 2023, resulted in the exposure of approximately 1.2 million customer records. The leaked data includes full names, physical addresses, email addresses, phone numbers, and critically, partial credit card numbers and transaction details. The breach originated from a compromised web application firewall (WAF) misconfiguration, allowing attackers to access the backend database containing sensitive customer transaction data. The leaked information was subsequently offered for sale on a dark web marketplace, with the threat actors advertising it as "high-value logistics data." The source structure of the leak points to a direct database dump, indicating a successful lateral movement and privilege escalation within the compromised system.
While specific details of this particular subsidiary's breach are not widely publicized, the modus operandi aligns with numerous attacks on the logistics sector observed over the past year. Cybersecurity firms like Palo Alto Networks have reported a surge in ransomware and data extortion attacks targeting supply chain and logistics companies, often leveraging unpatched vulnerabilities in web applications. The presence of partial credit card data suggests a potential for financial fraud and identity theft, making this a high-priority incident for affected customers.
Breach Breakdown
2,345 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds