April 2025: Major Data Breaches and Cyber Attacks

Ransomware surge: Sensata Technologies, US state agencies targeted in widespread cyber incidents

Industrial technology company Sensata Technologies disclosed that the company experienced a ransomware attack that encrypted parts of its network. The company took its systems offline, initiated response protocols, and launched an investigation with third-party cybersecurity experts. Law enforcement has been notified and is involved. This comes as several U.S. states have recently disclosed cyber incidents affecting critical government services, including Arizona, Arkansas, Idaho, Nebraska, and Oregon.

“On April 6, 2025, Sensata Technologies Holding plc (the “Company”) experienced a ransomware incident that has encrypted certain devices in the Company’s network,” Richard Siedel, vice president and chief accounting officer at the Massachusetts headquartered company, detailed in a Securities and Exchange Commission (SEC) filing on Wednesday. “Upon discovery, Sensata immediately activated its response protocols, implemented containment measures, including proactively taking its network offline, and launched an investigation with the assistance of third-party cybersecurity professionals. In coordination with legal counsel, the Company has notified law enforcement about the matter and is supporting its investigation.”

Hackers Allegedly Leaked 1.59 Million Rows of Indian Insurance User’s Sensitive Data

Hackers allegedly claim that a software company based in India was compromised on December 19, 2024, by a hacker identified as @303. The breach exposed approximately 1,590,798 rows of sensitive data, including customer information and administrative credentials.

The dataset, initially leaked on the dark web forum by a user known as “frog,” contains email addresses from major Indian insurance providers, mobile numbers, and potentially confidential administrative access credentials.

The Sample data analyzed by Cyber Security News contains information about employees of prominent insurance companies, including HDFC Ergo, Bajaj Allianz, ICICI Lombard, and others.

Cyberattack Hits British Retailer Marks & Spencer

Iconic British retailer Marks & Spencer (M&S) is scrambling to restore services impacted by a cybersecurity incident that occurred over the Easter holiday.

While the company’s online services remained operational, the incident impacted certain store operations, causing delays and frustration among customers.

“As soon as we became aware of the incident, it was necessary to make some minor, temporary changes to our store operations to protect customers and the business and we are sorry for any inconvenience experienced,” M&S said in a filing with the London Stock Exchange.

The company says it has engaged with cybersecurity experts to investigate the incident and relevant authorities have been notified.

“We are taking actions to further protect our network and ensure we can continue to maintain customer service,” M&S also said, without providing further details on the impacted services.

Western Sydney University discloses security breaches, data leak

Western Sydney University (WSU) announced two security incidents that exposed personal information belonging to members of its community.

WSU is a prominent Australian institution offering various undergraduate, postgraduate, and research programs across multiple disciplines.

It serves a student body of 47,000 and employs over 4,500 permanent and seasonal staff, operating with an annual budget of approximately $600 million.

One of the incidents disclosed concerns the compromise of one of the University’s single sign-on (SSO) systems between January and February 2025.

This breach has reportedly led to the unauthorized access of demographic, enrollment, and progression information for approximately 10,000 current and former students.

DOGE breach sparks cybersecurity crisis as Russian IP tries to access Federal Labor Systems

A looming national cybersecurity emergency is being witnessed following a whistleblower’s disclosure that an IP address registered in Russia tried to access sensitive federal labor databases mere minutes following a contentious data scraping by the agency led by Elon Musk, Department of Government Efficiency (DOGE), as per a report.

The breach attempt was directed at the National Labor Relations Board (NLRB), by using credentials associated with a recently created DOGE email address, as per Nextgov report.

County Data Breach Also Affected City of Chattanooga, Tenn.

The cybersecurity incident, which dates to July, stemmed to an agency that “provides debt collection services to city government,” a city spokesperson said in a news release, noting there’s “no indication that anything other than debt collection services data was affected.”

(TNS) — The city of Chattanooga was also affected by a data breach that Hamilton County officials have recently disclosed, officials said Friday.

Both incidents stem from Nationwide Recovery Services, a collection agency based in Cleveland, Tennessee.

Nationwide Recovery Services provides debt collection services to city government,” city spokesperson Eric Holl said in a news release. “There is no indication that anything other than debt collection services data was affected.”

Hackers Allegedly Breach TikTok, Exposing Over 900,000 Usernames & Passwords

A hacking collective identifying itself as R00TK1T has claimed responsibility for a massive data breach affecting TikTok, allegedly exposing the credentials of more than 900,000 users. 

According to the group’s statements, they have released a sample of 927,000 TikTok user records into the wild, describing it as “proof of their vulnerabilities”.

R00TK1T stated they had previously warned ByteDance and TikTok about security vulnerabilities but were ignored.

“We warned ByteDance and TikTok, but their silence speaks volumes. Despite our clear message, they’ve ignored the cries of users locked out, suspended, or erased from the platform,” the group declared.

Western Sydney University student data stolen again, posted on dark web

The details of more than 10,000 students have been stolen from one of Australia’s largest universities.

Western Sydney University has again been targeted in a cyber breach. In a statement released on Thursday, the university said demographic, enrolment and course progress information had been taken.

In a separate incident, “personal information belonging to the university community” was discovered on the dark web in late March – the information had been online for almost five months.

It is unclear if the information was for sale or posted as a whole.

A university spokesperson said the matter was under police investigation and could not be elaborated on.

Microsoft Defender XDR False Positive Leads to Massive Data Leak of 1,700+ Sensitive Documents

ANY.RUN research identified a large-scale data leak event triggered by a false positive in Microsoft Defender XDR. The security platform incorrectly flagged benign files as malicious, leading to their automatic submission to ANY.RUN’s public sandbox for analysis. As a result, over 1,700 sensitive documents were uploaded and indexed publicly.

The leak, which involved corporate data from hundreds of companies, has raised alarm bells about the risks of misclassification in threat detection systems and the unintended consequences of user behavior in response to such errors.

More than 11,000 DBS, Bank of China customers’ information compromised after data attack on vendor

Customer data from two banks here was stolen in a ransomware attack on a printing vendor, though no login information was compromised.

In a joint statement late on April 7, the Cyber Security Agency of Singapore (CSA) and Monetary Authority of Singapore (MAS) said the two banks were DBS Bank and Bank of China, Singapore (BOC).

DBS said the customer statements of around 8,200 customers were potentially compromised, while BOC separately said that the breach affected around 3,000 customers, whose paper letters were printed and distributed by Toppan Next Tech.

Both banks added that their respective systems had not been compromised, and customer monies remained safe. DBS added that there was no evidence of unauthorised transactions resulting from the incident so far.

According to DBS, the affected customers are mainly users of brokerage DBS Vickers and short-term loan service Cashline.

The potentially compromised information came from statements or letters sent to individual customers between December 2024 and February 2025.

Customer data exposed in these statements includes names, postal addresses and details relating to equities held under DBS Vickers and Cashline loans, said DBS, adding that the documents do not contain login credentials, passwords, NRIC details, deposit balances or total wealth holdings.


Discover more from Information Security Blogs

Subscribe to get the latest posts sent to your email.

Leave a Reply

Discover more from Information Security Blogs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Information Security Blogs

Subscribe now to keep reading and get access to the full archive.

Continue reading