Volkswagen leak exposed location data for 800,000 electric cars - The Verge

https://www.theverge.com/2024/12/30/24332181/volkswagen-data-leak-exposed-location-evs

The leak also included the emails, addresses, and phone numbers of drivers in some cases, Der Spiegel reports.

If anything, this leak serves as yet another reminder of the immense amount of data collected by modern-day vehicles, which Mozilla has called a “privacy nightmare.”

Anyone Can Buy Data Tracking US Soldiers and Spies to Nuclear Vaults and Brothels in Germany - Wired

https://www.wired.com/story/phone-data-us-soldiers-spies-nuclear-germany/

More than 3 billion phone coordinates collected by a US data broker expose the detailed movements of US military and intelligence workers in Germany—and the Pentagon is powerless to stop it.

Apple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up. | Ars Technica

https://arstechnica.com/security/2024/01/hackers-can-id-unique-apple-airdrop-users-chinese-authorities-claim-to-do-just-that/

Chinese authorities recently said they’re using an advanced encryption attack to de-anonymize users of AirDrop in an effort to crack down on citizens who use the Apple file-sharing feature to mass-distribute content that’s outlawed in that country.

23andMe confirms hackers stole ancestry data on 6.9 million users | TechCrunch

https://techcrunch.com/2023/12/04/23andme-confirms-hackers-stole-ancestry-data-on-6-9-million-users/

On Friday, genetic testing company 23andMe announced that hackers accessed the personal data of 0.1% of customers, or about 14,000 individuals. The company also said that by accessing those accounts, hackers were also able to access “a significant number of files containing profile information about other users’ ancestry.” But 23andMe would not say how many “other users” were impacted by the breach that the company initially disclosed in early October.

As it turns out, there were a lot of “other users” who were victims of this data breach: 6.9 million affected individuals in total.

In an email sent to TechCrunch late on Saturday, 23andMe spokesperson Katie Watson confirmed that hackers accessed the personal information of about 5.5 million people who opted-in to 23andMe’s DNA Relatives feature, which allows customers to automatically share some of their data with others. The stolen data included the person’s name, birth year, relationship labels, the percentage of DNA shared with relatives, ancestry reports and self-reported location.

Genetics firm 23andMe says user data stolen in credential stuffing attack – BleepingComputer

https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/

The initial data leak was limited, with the threat actor releasing 1 million lines of data for Ashkenazi people. However, on October 4, the threat actor offered to sell data profiles in bulk for $1-$10 per 23andMe account, depending on how many were purchased.

A 23andMe spokesperson confirmed the data is legitimate and told BleepingComputer that the threat actors used exposed credentials from other breaches to access 23andMe accounts and steal the sensitive data.

https://arstechnica.com/security/2023/10/private-23andme-user-data-is-up-for-sale-after-online-scraping-spree/

The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location.

While there are benefits to storing genetic information online so people can trace their heritage and track down relatives, there are clear privacy threats. Even if a user chooses a strong password and uses two-factor authentication as 23andMe has long urged, their data can still be swept up in scraping incidents like the one recently confirmed. The only sure way to protect it from online theft is to not store it there in the first place.

NHS data breach: trusts shared patient details with Facebook without consent | The Guardian

https://www.theguardian.com/society/2023/may/27/nhs-data-breach-trusts-shared-patient-details-with-facebook-meta-without-consent

Observer investigation reveals Meta Pixel tool passed on private details of web browsing on medical sites

Report: ‘massive’ Tesla leak reveals data breaches, thousands of safety complaints | The Guardian

https://www.theguardian.com/technology/2023/may/26/tesla-data-leak-customers-employees-safety-complaints

Tesla has failed to adequately protect data from customers, employees and business partners and has received thousands of customer complaints regarding the carmaker’s driver assistance system, Germany’s Handelsblatt has reported, citing 100 gigabytes of confidential data leaked by a whistleblower.

The Handelsblatt report said customer data could be found “in abundance” in a data set labelled “Tesla Files”.

Advarer mot skreddersydd svindel etter datalekkasje – NRK

https://www.nrk.no/norge/advarer-mot-skreddersydd-svindel-etter-datalekkasje-1.15963551

Personopplysningene som er på avveie etter det store datainnbruddet mot Norkart, kan åpne for mer utspekulerte former for svindel, tror ekspert.

[…]

De neste månedene anbefaler han å være ekstra varsom for spesielle brev, e-poster og telefoner.

– Bruk god dømmekraft, og være skeptisk – hver eneste gang du får en henvendelse, hvor du ikke enkelt kan identifisere hvem som står bak, påpeker Jøsang.

Dataangrep mot Norkart: 3,3 millioner kan være berørt – NRK

https://www.nrk.no/norge/dataangrep-mot-norkart_-3_3-millioner-kan-vaere-berort-1.15962268

Selskapet Norkart, som leverer IT-systemer for kart- og eiendomsinformasjon, er utsatt for et dataangrep. Persondata for opp mot 3,3 millioner innbyggere er på avveier.

Selskapet varslet om dataangrepet tirsdag. Alle som eier eiendom i Norge kan være berørt.

[…]

– Det vi ønsker nå er at alle som er eiere eller festere er ekstra årvåkne når det gjelder forsøk på svindel. Et godt råd er å sperre seg for sjekk av kredittopplysninger og følge med på hva som skjer i postkassen din.

Helseopplysninger om norske utøvere på avveie i OL: – Helt Texas – NRK Sport

https://www.nrk.no/sport/helseopplysninger-om-norske-utovere-pa-avveie-i-ol_-_-helt-texas-1.15839426

Olympiatoppens sjef, Tore Øvrebø, er kraftig oppgitt over OL-arrangørens håndtering av norske helseopplysninger. Direktøren på et av hotellene som huser norsk støttepersonell visste om smitte før den norske leiren.

– Han er en grei kar, men han skulle ikke hatt disse opplysningene før oss, sier Tore Øvrebø da han møter pressen i Zhangjikou – et par timer unna Beijing.

– Det er helt Texas, konkluderer Øvrebø.

Hotelldirektøren på Eagle Nest, der flere medlemmer av det norske støtteapparatet bor, er stadig i forkant når det kommer til koronastatus på utøverne.

1.8 TB of Police Helicopter Surveillance Footage Leaks Online - WIRED

https://www.wired.com/story/ddosecrets-police-helicopter-data-leak/

The leak illustrates the inherent risk of collecting and retaining sensitive footage that could be breached.

FT editor among 180 journalists identified by clients of spyware firm - Surveillance - The Guardian

https://www.theguardian.com/world/2021/jul/18/ft-editor-roula-khalaf-among-180-journalists-targeted-nso-spyware

Data leak and forensics suggest NSO’s surveillance tool used against journalists at some of world’s top media companies

A successful Pegasus infection gives NSO customers access to all data stored on the device. An attack on a journalist could expose a reporter’s confidential sources as well as allowing NSO’s government client to read their chat messages, harvest their address book, listen to their calls, track their precise movements and even record their conversations by activating the device’s microphone.

Huge data leak shatters the lie that the innocent need not fear surveillance - The Guardian

https://www.theguardian.com/news/2021/jul/18/huge-data-leak-shatters-lie-innocent-need-not-fear-surveillance

Our investigation shows how repressive regimes can buy and use the kind of spying tools Edward Snowden warned us about

Law-abiding people – including citizens and residents of democracies such as the UK, such as editors-in-chief of leading newspapers – are not immune from unwarranted surveillance. And western countries do not have a monopoly on the most invasive surveillance technologies. We’re entering a new surveillance era, and unless protections are put in place, none of us are safe.

Revealed: leak uncovers global abuse of cyber-surveillance weapon - Surveillance - The Guardian

https://www.theguardian.com/world/2021/jul/18/revealed-leak-uncovers-global-abuse-of-cyber-surveillance-weapon-nso-group-pegasus

Human rights activists, journalists and lawyers across the world have been targeted by authoritarian governments using hacking software sold by the Israeli surveillance company NSO Group, according to an investigation into a massive data leak.

The investigation by the Guardian and 16 other media organisations suggests widespread and continuing abuse of NSO’s hacking spyware, Pegasus, which the company insists is only intended for use against criminals and terrorists.

Pegasus is a malware that infects iPhones and Android devices to enable operators of the tool to extract messages, photos and emails, record calls and secretly activate microphones.

Ransomware gang threatens to expose police informants if ransom is not paid - The Record

https://therecord.media/ransomware-gang-threatens-to-expose-police-informants-if-ransom-is-not-paid/

Avinor: Forretningskritisk informasjon kan ha kommet på avveie – E24

https://e24.no/teknologi/i/wenm8M/avinor-forretningskritisk-informasjon-kan-ha-kommet-paa-avveie

Avinor har avdekket innbrudd i e-postkontoen til en av sine ansatte. Analyser viser at data har blitt hentet ut av kontoen, skriver Avinor i en pressemelding.

«Angrepet innebærer at en inntrenger har kopiert informasjon fra den ansattes e-postkonto. Forretningskritisk og personsensitiv informasjon kan derfor ha kommet på avveie,» skriver Avinor.

Selskapet understreker at det ikke finnes indikasjoner på at Avinors operative systemer er berørt, «flysikkerheten er derfor ikke påvirket av hendelsen».

Fødselsnumre og sykemeldinger til ansatte i Hurtigruten stjålet og lagt ut på det mørke nettet – NRK

https://www.nrk.no/trondelag/dataangrep-mot-hurtigruten_-sensitive-opplysninger-om-ansatte-i-hurtigruten-er-publisert-pa-dark-web-1.15404764

Opplysninger fra fem skip har havnet på avveie. Hurtigruten har sendt brev til gjester og ansatte som er rammet av dataangrepet.

[D]e som brøt seg inn fikk tilgang til fullt navn, fødselsnumre og info om ansettelsesforhold til medlemmer av besetningen.

Det inkluderer arbeidsavtaler, sykemeldinger, dokumentasjon til Nav og andre HR-relaterte forhold.

Informasjonen var lagret på servere om bord på skipet.

Utsatt for hackerangrep - Drammen kommune

https://www.drammen.kommune.no/om-kommunen/aktuelt/hackerangrep/

Drammen kommune har vært utsatt for et hackerangrep på en mindre del av infrastrukturen for vann og avløp.
Kommunen har kontroll på situasjonen, og alle vann- og avløpssystemer fungerer som normalt. Ingen av kommunens innbyggere er berørt av situasjonen, og ingen personopplysninger er på avveie.

Kan ta et halvt år for Østre Toten å rette opp dataangrep – NRK

https://www.nrk.no/innlandet/kan-ta-et-halvt-ar-for-ostre-toten-a-rette-opp-dataangrep-1.15364106

Den første uka var mange helt uten e-post.

Sosialhjelpsmottakere måtte skrive søknader på nytt.

Alle PC-er måtte formateres og få lagt til ny programvare.

Det er stor fare for at sensitive data er kommet på avveie.

Også sikkerhetskopier ble slettet av angriperne.

Ansatte måtte jobbe med penn og papir i starten.

Angrepet vil trolig koste minst 10 millioner kroner.

Hacking-skandale ryster Finland - pasienter presset for penger – NRK

https://www.nrk.no/urix/hacking-skandale-ryster-finland---pasienter-presset-for-penger-1.15214710

Pasientopplysninger fra et finsk psykoterapisenter er på avveie etter hacking, og flere pasienter er blitt presset for penger.

Utpresseren skal ha presset selskapets ledelse for 40 bitcoin, tilsvarende nesten 5 millioner kroner, for ikke å publisere pasientjournalene på det mørke nettet.

Utpresseren skal ha truet med å publisere 100 journaler på det mørke nettet per dag.

Kravet ble avvist, dermed begynte lekkasjene. Etter dette begynte det å dukke opp trusselmeldinger til hver enkelt pasient.

– Nå må vi ordne krisehjelp til ofrene, sier Ohisalo.