24
Total linked signals
Linked through an affected location, company headquarters, or both.
Geographic intelligence
Follow 24 current cybersecurity signals linked to United States through an affected location, a profiled company's country, or both, with source reporting.
Affected-country links use structured victim-country data. Company-country links use a reviewed profile based on the organisation's headquarters or the local operating entity represented by its domain. A signal linked in both ways is counted once in the total; actor origin and locations inferred from prose remain excluded.
Country context
Reference details that help place the cybersecurity reporting in its geographic and economic context.
24
Linked through an affected location, company headquarters, or both.
Not classified
Victim-country data is unavailable in this reporting window.
24
Based on reviewed company headquarters.
16
Severity classifications among linked signals.
Explore related intelligence
Based on all published signals currently linked to United States through an affected location, a profiled company's country, or both. Counts describe this reporting set, not overall incident prevalence.
Company-linked signals
Jamf, a company specializing in Apple device management, was among roughly two dozen Klue customers impacted by a data incident. The incident, which became active on July 26, 2026, involved the Icarus threat group claiming responsibility for an attack. Further reports indicated that another hacking group might have obtained samples of the stolen Klue customer data and attempted to extort affected companies directly. While the full extent of Jamf's specific exposure through this third-party incident is not detailed, the broader event highlights the risks associated with supply chain compromises. Jamf's security efforts include initiatives like its Beacon threat-hunting service, which focuses on proactive detection and analysis of Mac threats, and its annual Security 360 report, which addresses key threats to Apple endpoints.
South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.
Infoblox Threat Intel has identified a sophisticated adversary-in-the-middle (AiTM) phishing campaign that began in May 2026 and was publicly reported on July 22, 2026. This campaign targets global organizations, including agencies associated with the European Union and the United Nations, as well as universities and commercial enterprises. The attackers utilize procurement-themed emails sent from previously compromised organizational accounts to bypass multi-factor authentication (MFA) and hijack authenticated sessions. These emails are designed to appear credible, mimicking routine business workflows such as bid invitations, shared project files, or requests for information, often incorporating false deadlines and confidentiality language to create urgency. When a recipient clicks an embedded link, the AiTM infrastructure intercepts credentials and session tokens in real-time, allowing attackers to gain access to the organization's account and network. The campaign leverages various Phishing-as-a-Service kits, including EvilProxy, FlowerStorm, and Kali365, and hosts fake download pages on compromised, often dormant, websites to enhance their apparent legitimacy. Infoblox emphasizes that this type of phishing scenario is not typically covered in standard security training, highlighting the need for organizations to combine user awareness with early visibility into phishing infrastructure through DNS-based threat intelligence.
Amazon Web Services (AWS) experienced a billing console glitch that caused customers worldwide to receive erroneous, astronomically high billing estimates, some reaching trillions of dollars. The issue, which began on July 16, 2026, at 7:38 PM PDT (July 17, 2026, 3:38 AM UK time), affected the display of estimated charges and alerts in the AWS Billing and Cost Management Console and Cost Explorer tools, rather than actual charges. AWS acknowledged the bug, disabled the faulty estimation subsystem, and worked on a fix, advising customers not to treat the inflated totals as real charges.
A widespread security incident affecting Canvas, a learning management system by Instructure, impacted thousands of institutions, including Rutgers University, which utilizes the Qualtrics survey tool. Instructure notified Rutgers that while there was no indication of passwords, dates of birth, government identifiers, or financial information being involved, the specific Rutgers data compromised remains unclear. Instructure reportedly reached an agreement with the unauthorized threat actor, and the stolen data was returned and destroyed. Canvas remained operational throughout the incident.
Glendale Community College (GCC) is actively investigating a cybersecurity incident that occurred on June 16, 2026. The college is working with third-party specialists to address the incident and provide updates to the public. This ongoing disclosure was prominently featured on the college's website on July 14, 2026.
A data leak at the AI music generator Suno, which occurred in November 2025, became public in July 2026. The breach exposed data from over 55 million unique email addresses and, for users who registered with their phone numbers, those numbers as well. A small portion of the dataset also included payment processor Stripe data, leading to the leak of names, physical addresses, purchase amounts, and certain credit card details (card type, expiration date, and last four digits) for tens of thousands of users. Suno confirmed it does not have access to full credit card numbers via Stripe.
U.S. insurance provider AssuranceAmerica confirmed a data breach affecting the personal information and driver's license numbers of 6.9 million people. The company discovered hackers in its computer systems on March 17, 2026, and concluded its investigation on June 15, 2026, with notification letters scheduled to be sent out on July 10, 2026.
Leaked internal documents, reportedly shared by 'Serenity on X,' indicate that Anthropic plans to secure approximately 1.4 GW of data center power capacity in Australia, representing an estimated $21.6 billion investment. This leak reveals sensitive internal business strategies and infrastructure expansion plans.
The 'FortiBleed' cyber campaign, which previously exposed login credentials for thousands of Fortinet firewalls, has now been linked to the ransomware groups INC and Lynx. Forensic investigations revealed evidence on a Windows server used in the attack infrastructure, showing administrators had access to negotiation portals of both ransomware groups. This suggests a strong connection between the credential theft and subsequent extortion campaigns. Researchers estimate that over 430,000 FortiGate firewalls worldwide were targeted, with sniffers installed on approximately 19,000 systems to intercept network traffic.
A targeted phishing attack on healthcare AI company Xsolis has exposed the data of at least 1.4 million patients across eight U.S. health systems. Xsolis develops utilization management and care coordination technology widely used by hospitals and health systems. This breach now ranks among the most significant healthcare vendor cyberattacks of 2026. The U.S. Department of Health and Human Services (HHS) confirmed the patient impact figure on June 22, after Xsolis filed its breach report on June 5. Moreover, legal action over the incident has already been filed in at least one case, signaling growing accountability pressure on AI vendors handling sensitive patient data. The breach did not begin with the disclosure. Instead, the unauthorized access occurred months earlier. On January 20, 2026, an unidentified actor accessed portions of Xsolisâs IT environment. The attacker then acquired a limited number of files from within the system. Xsolis did not report the incident to HHS until June 5 â roughly four and a half months after the initial intrusion. This delay has drawn scrutiny. Furthermore, Hendrick Health in Abilene, Texas, faced a separate lawsuit specifically citing delayed patient notification as a key concern. Xsolis has stated the company is not currently aware of any misuse of the stolen data. However, the company has declined to specify which types of patient information were exposed. A spokesperson confirmed Xsolis is notifying affected individuals but is not commenting beyond its June 5 public statement. The following health systems have confirmed involvement in the Xsolis data breach : Rochester Regional Health â Rochester, N.Y. Together, these eight organizations collectively serve patients across six states. Consequently, the breach spans a wide geographic footprint â from the Pacific Northwest to the Southeast and Midwest. Xsolis took several steps after discovering the breach . First, the company reported the incident to HHS on June 5. Next, it began notifying affected patients directly. Additionally, Xsolis released a formal public statement through PR Newswire acknowledging the security incident. However, critics note that the five-month gap between the January intrusion and the June disclosure raises serious questions. Under HIPAA, covered entities and business associates generally must report breaches within 60 days of discovery. Health systems and regulators are now examining whether this timeline met legal standards. Why This Breach Matters for Healthcare AI This incident highlights a critical vulnerability in modern healthcare operations. Health systems increasingly rely on third-party AI vendors for functions like utilization management and care coordination. As a result, these vendors hold highly sensitive patient records â making them attractive targets for cybercriminals. Phishing attacks remain the leading method hackers use to gain unauthorized access. Notably, a single successful phishing email at a vendor like Xsolis can cascade into a breach affecting millions of patients at multiple health systems simultaneously. Third-Party Risk in Healthcare Is Growing Third-party vendor breaches now account for a rising share of healthcare data incidents. Therefore, health systems that outsource clinical and operational functions to AI companies must treat vendor cybersecurity as a direct extension of their own risk management. Regulators, including HHSâs Office for Civil Rights, actively scrutinize business associate agreements (BAAs) and breach timelines. Health systems found to lack adequate vendor oversight face fines and reputational harm alongside their vendors. Health system leaders should act quickly when a vendor breach occurs. First, they must verify whether their organization was part of the affected vendorâs client base. Next, they should request a full incident report from the vendor, including the timeline and scope of data access. Additionally, health systems must assess their own HIPAA obligations independently. Even when a vendor like Xsolis handles patient notifications, the covered health system retains compliance responsibility. Going forward, health systems should strengthen third-party risk programs. Key actions include conducting annual security assessments of all AI and health IT vendors, requiring vendors to carry cyber liability insurance, and including clear breach notification timelines in every BAA. Furthermore, phishing awareness training must extend beyond a health systemâs own staff. Health systems should require vendors to demonstrate regular employee security training as a contract condition. Ultimately, a vendorâs security posture directly affects every patient record that vendor touches. Vendor breaches, regulatory shifts, and the governance gaps in between. Here's what happened this month in third-party risk management news. Financial institutions are legally accountable for what their vendors do with customer data. Outsourcing a function doesn't outsource the liability that comes with it â a principle that runs through GLBA Safeguards Rule requirements, state privacy laws, and open banking obligations under Part 1033. Vendor contracts need to do more than check a compliance box: they should specify permitted data uses, require breach notification within 24â48 hours, include audit rights, and address AI governance for any vendor using automated decision-making. Fourth-party risk also warrants explicit contract language requiring vendors to disclose and flow down obligations to their own subcontractors. A phishing attack on a healthcare AI vendor exposed 1.4 million patient records. Xsolis, which provides AI-powered utilization management to hospitals and health insurers, was breached through a single phishing email, exposing Social Security numbers, health insurance details, and medical treatment records across seven major hospital systems including Mayo Clinic. At least one organization â Rochester Regional Health â had ended its relationship with Xsolis in 2021, yet its patient data was still in scope at the time of the breach. Most of the 1.4 million affected had no idea the vendor held their information at all. Third-party vendor incidents now account for 58% of all healthcare data breaches, and this case is a concrete reminder that data deletion at offboarding is a risk control, not an administrative afterthought. The Klue breach reached LastPass customer data. Attackers used OAuth tokens stolen from Klue to access LastPass's Salesforce environment, exposing customer names, contact details, and support case records. Password vaults were unaffected, but the stolen data is enough to fuel targeted phishing. Fourth-party risk in practice: a vendor relationship several steps removed still produced direct customer harm. How to Avoid Common Third-Party Risk Management Mistakes
Healthcare technology company Xsolis, Inc. has disclosed a data breach affecting nearly 1.4 million individuals. Tennessee-based Xsolis provides utilization management and revenue cycle solutions for hospitals, health systems, and payers. The company published a data security notice in early June, revealing that unauthorized activity was detected on its systems on January 22. The intrusion resulted from a targeted phishing attack carried out two days earlier. According to Xsolis, the hackers gained access to files storing personal and protected health information received by the company from its clients, including names, dates of birth, addresses, SSNs, health insurance information, and medical treatment information. While the data breach was disclosed two weeks ago, the US Department of Health and Human Services (HHS) has now disclosed the number of affected individuals. The Xsolis cybersecurity incident was added to the HHS data breach tracker on Monday, with the number of affected individuals listed as 1,396,519. Advertisement. Scroll to continue reading. No known ransomware group appears to have taken credit for the attack on the healthcare tech company. SecurityWeek has asked Xsolis whether it was targeted in an extortion attempt and, if so, whether a ransom has been paid. The companyâs disclosure indicates that itâs ânot aware of any actual or attempted misuse of information because of this incidentâ. Itâs not uncommon for healthcare-related data breaches to affect millions of people. One recent example is the incident involving the dental benefits administrator DentaQuest , in which hackers stole information from 2.6 million accounts. Related : Millions Impacted Across Several US Healthcare Data Breaches Related : 266,000 Affected by Data Breach at Radiology Associates of Richmond Related : Oncology Institute Discloses Data Breach Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelorâs degree in industrial informatics and a masterâs degree in computer techniques applied in electrical engineering. Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch New Index Tracks Material Breaches â And Refuses to Add Up the Losses WP2Shell WordPress Vulnerabilities Exploited in the Wild Two Scattered Spider Hackers Sentenced to Jail in UK âClickLock Stealerâ Bypasses macOS Security With Social Engineering, Process Killing Chinaâs Top Cybersecurity Firms Hit by Mounting Military Procurement Bans Fourth SharePoint Vulnerability Exploited in Past Monthâs Wave of Attacks Endpoint Security Firm Glow Launches With $180M in Funding at $1.2B Valuation Oracle Patches Over 1,400 Vulnerabilities With Quarterly Security Updates Ransomware Group Threatening to Leak Data Stolen From Coca-Colaâs Fairlife OpenAI Says Its AI Models Broke Loose and Hacked Hugging Face Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains Cisco Launches Low-Cost AI Models for Source Code Security Empirical Security Raises $25 Million in Series A Funding Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Xsolis breach exposes personal and health data of 1.4 million people Healthcare technology company Xsolis has disclosed a data breach impacting nearly 1.4 million individuals following a phishing attack. The Tennessee-based firm, which provides utilization management and revenue cycle solutions for healthcare providers, became aware of unauthorized access on January 22, 2026, after a phishing attack two days prior. The breach exposed personal and protected health information received from Xsolisâs hospital and payer clients, as reported by Security Affairs. The security incident, which occurred on January 20, 2026, allowed an unauthorized actor to acquire files containing sensitive information. This data may include names, addresses, dates of birth, Social Security numbers, health insurance details, and medical treatment information. Xsolis has launched an investigation, reported the incident to law enforcement, and is implementing enhanced security measures. Affected individuals are being notified by mail and offered free credit monitoring and identity protection services, along with access to a toll-free call center. The U.S. Department of Health and Human Services reported that 1,396,519 individuals were affected. No ransomware group has claimed responsibility for the attack at this time.
Security researchers reported on June 25, 2026, the discovery of a new malware campaign dubbed 'Edgecution,' which utilizes a malicious Microsoft Edge extension to deploy ransomware and a Python-based backdoor. The extension abuses the Native Messaging API to escape the browser sandbox and establish a persistent system-level executor. Attackers are reportedly using Microsoft Teams for social engineering, directing victims to fake 'Outlook Updates Management Console' websites to trick them into installing the malicious extension. This campaign is believed to be operated by an Initial Access Broker (IAB) linked to the 'Payout Kings' ransomware operation.
A Russian-speaking cybercriminal group exposed credentials for approximately 74,000 to 86,644 Fortinet FortiGate firewalls and VPN gateways across 194 countries. The incident, dubbed 'FortiBleed', involved leaked administrative and SSL VPN credentials, prompting CISA to issue a hardening alert. The exposure was publicly reported on June 22, 2026, following discovery on June 13, 2026.
AssuranceAmerica Managing General Agency, LLC, an Atlanta-based nonstandard auto insurance provider, reported a data breach to the South Carolina Department of Consumer Affairs on June 18, 2026. The breach, detected on March 17, 2026, involved an unauthorized third party accessing and copying files from its computer systems after targeting a single employee. A review completed on June 15, 2026, identified that names, contact details, insurance policy information, driver/vehicle information, claims data, driver's license numbers, tax ID information, and potentially Social Security numbers were exposed.
Microsoft has been accused of leaking data belonging to Dutch civil servants, specifically those working for the Authority for Consumers and Markets (ACM) and the Dutch Data Protection Authority (AP), to the US House of Representatives. The leaked data includes emails, minutes, and invitations with unredacted names.
Anthropic, het bedrijf achter Claude Mythos AI, onderzoekt ongeautoriseerde toegang tot zijn AI-model via de omgeving van een externe leverancier. Dit incident vond plaats slechts twee weken na de introductie van Mythos. Een kleine groep gebruikers op een Discord-kanaal heeft naar verluidt toegang verkregen tot Mythos, met als primair doel het verzamelen van gegevens.
Threat actors are actively exploiting critical vulnerabilities in Fortinet FortiClient Endpoint Management Server (EMS), including CVE-2026-35616 and CVE-2026-21643. CVE-2026-35616, a critical security flaw, was actively exploited in the wild to deploy credential-stealing malware (EKZ Infostealer), prompting an emergency patch in April 2026. CVE-2026-21643 is also mentioned in active exploitation campaigns.
Anthropic, an AI startup, experienced a data leak on March 27, 2026, where nearly 3,000 unpublished assets, including draft blog posts, images, and PDFs related to their upcoming 'Claude Mythos' AI model, were inadvertently left accessible in a public data cache. The leak was attributed to human error in configuring the company's content management system (CMS). Anthropic clarified that no core infrastructure, customer data, or security architecture was involved.
Multiple critical authentication bypass vulnerabilities related to FortiCloud Single Sign-On (SSO) have been actively exploited in Fortinet products. CVE-2026-24858, disclosed in January 2026, allowed malicious actors with a FortiCloud account to log in to devices registered to other users if FortiCloud SSO was enabled. This led to unauthorized firewall configuration changes, account creation, and VPN configuration changes. Earlier, CVE-2025-59718 and CVE-2025-59719 (December 2025) allowed unauthenticated attackers to bypass SSO login via crafted SAML messages. Attacks exploiting these flaws have been observed creating rogue accounts and stealing firewall configuration data.
South Korean e-commerce giant Coupang disclosed a significant data breach affecting approximately 33.7 million customers. On December 8, 2025, Seoul Police reportedly raided Coupang Headquarters as part of a probe into the data breach. Exposed data included names, email addresses, phone numbers, and shipping addresses.
South Korea's largest e-commerce platform, Coupang, disclosed a data breach that exposed personal information of approximately 33.7 million user accounts. The breach, attributed to a former employee who exploited unrevoked authentication keys, involved names, email and postal addresses, phone numbers, and order histories. No financial information or passwords were compromised. The incident led to a record fine from the Korean Personal Information Protection Commission (PIPC) and an investigation by South Korean authorities. Coupang initially released a statement on November 29, 2025, confirming unauthorized exposure of approximately 4,500 accounts, with a broader admission of 33.7 million accounts on November 30, 2025.
Class action will target âReal-Time Biddingâ (RTB) data breach in Microsoftâs advertising system, and is anticipated to affect Microsoftâs operations across the EU 26 May 2025 -Â In the first action of its kind in Ireland, the Irish Council for Civil Liberties (ICCL) will today apply to the High Court to launch a class action lawsuit against Microsoft. The case is intended to target the very large âReal-Time Biddingâ (RTB) data breach within Microsoftâs advertising system. ICCL is taking the legal action on behalf of all affected people in Ireland under the new EU Collective Redress Directive. The organisation hopes to force Microsoft to bring its systems into compliance with the EUâs General Data Protection Regulation (GDPR). This application comes on the seven year anniversary of the GDPR's introduction on 25 May 2018. The outcome of this litigation is anticipated to affect Microsoftâs operations across the European Economic Area as the companyâs European headquarters are based in Ireland. Users of Office, Windows, Xbox and the general internet are affected Microsoftâs RTB system operates behind the scenes on websites and apps to match advertising to specific people. Users of popular Microsoft products and services, including Windows, Xbox, web-based Office (Word, Excel and Outlook), the Edge web browser that is pre-installed with Windows, and websites and apps that use Microsoftâs Xandr advertising technology, are affected. Dr Johnny Ryan, Director of ICCLâs Enforce unit, is leading the case and said: âPeopleâs intimate secrets such as their relationship, work and financial status are broadcast by Microsoft into the Real-Time Bidding advertising system. That system is a black hole of data open to any malicious actor and represents a huge data breach of millions of peopleâs informationâ. Very sensitive data about people exposed, including national security personnel ICCL Enforce investigations have revealed the extraordinary sensitivity of the data that Microsoft exposes. Posing as a data buyer, ICCL Enforce obtained thousands of RTB data âsegmentsâ about Irish people. These include information such as whether a person gambles, their finances and debt, and even such sensitive information as whether the person works in a sensitive national security role. âMicrosoft has no way of knowing what happens to the personal data after it broadcasts. This a data breach, pure and simple. Microsoft is exposing us all individually to malicious profiling and discrimination, and in doing so it is also undermining European securityâ. ICCL is represented by James Doherty SC, Sean OâSullivan BL and Ahern Rudden Quigley. See explainers about RTB at https://iccl.ie/rtb/ The Irish High Court granted permission on May 26, 2025 for the country's first class action lawsuit, marking a significant milestone in European data protection enforcement six days after the seventh anniversary of GDPR implementation. The Irish Council for Civil Liberties (ICCL) secured approval to launch proceedings against Microsoft under the EU Collective Redress Directive. The case targets alleged violations within Microsoft's Real-Time Bidding (RTB) advertising system, which the organization characterizes as constituting a massive data breach affecting millions of users across Europe. According to ICCL's application, the lawsuit focuses on Microsoft's RTB operations that process data from users across multiple platforms. Users of popular Microsoft products and services, including Windows, Xbox, web-based Office (Word, Excel and Outlook), the Edge web browser that is pre-installed with Windows, and websites and apps that use Microsoft's Xandr advertising technology, are affected, the organization stated. The case emerges from ICCL's investigation into RTB data practices, which revealed extensive categorization of sensitive personnel. The organization's research identified thousands of RTB data "segments" about Irish people obtained through posing as a data buyer. These segments included information about gambling habits, financial status, and employment in sensitive national security roles. Dr Johnny Ryan , Director of ICCL's Enforce unit, leads the case. "People's intimate secrets such as their relationship, work and financial status are broadcast by Microsoft into the Real-Time Bidding advertising system. That system is a black hole of data open to any malicious actor and represents a huge data breach of millions of people's information", Ryan stated. Microsoft's controversial Xandr acquisition and sunset The timing of this legal action coincides with Microsoft's decision to discontinue its demand-side platform (DSP), Microsoft Invest (formerly Xandr, formerly AppNexus) . According to Microsoft Advertising Corporate Vice President Kya Sainsbury-Carter, the company announced on May 14, 2025 that it will discontinue Microsoft Invest effective February 28, 2026. Microsoft acquired Xandr from AT&T in June 2022 , completing a deal first announced in December 2021. AT&T had previously acquired AppNexus in 2018 for a reported $1.6 billion. The original AppNexus platform, founded in 2007 by Brian O'Kelley and Mike Nolet, was widely recognized for providing unprecedented transparency into fee structures and money flows throughout the advertising supply chain. According to Sainsbury-Carter's announcement, Microsoft is "exclusively focusing our buy-side advertising technology investments on the Microsoft Advertising Platform" starting in 2026. The company stated its commitment to "more private and personalized advertising experiences for a more agentic and conversational world is not achievable with the industry's current DSP model." This strategic shift away from traditional DSP operations removes one of the most transparent options in the programmatic ecosystem. AppNexus had established itself as a champion of transparency, with co-founder Brian O'Kelley positioning the company as providing advertisers with visibility into fee structures long before it became an industry priority. Announcement from Kya Sainsbury-Carter, Corporate Vice President at Microsoft Advertising - May 14, 2025 At Microsoft Advertising, we believe that the future of digital engagement is conversational, personalized, and agentic. Our strategic vision is rooted in the transformative power of generative AI to create entirely new possibilities in advertising, unlocking better outcomes between people, brands, publishers, and ad platforms. We are entering a new eraâone defined by conversational AI experiences, agentic systems that simplify decision making and bring brands closer to people, and predictive design models that fundamentally reshape what people expect from digital services. This new era will be enabled by purpose-built AI-powered advertising platforms that make personalized advertising simple.
Amazon confirmed that employee data was compromised through a third-party property management vendor due to the lasting impact of the 2023 MOVEit vulnerability. The breach, revealed by a threat actor known as "Nam3L3ss," exposed approximately 2.8 million lines of employee data, including work contact information, email addresses, desk phone numbers, and building locations. The disclosure occurred on November 11, 2024.
FAQ
This page brings together current signals connected to United States through an affected location, a reviewed company profile, or both.
No. The country connection describes affected locations or profiled company locations. It does not claim actor origin unless a source explicitly establishes that separately.
The page follows the rolling current-reporting window. Counts change as new incidents are added, evidence is reviewed, and older signals leave that window.