Berlin refuses to be blackmailed after network breach
Berlin's state government confirmed it suffered a data breach of its administrative network in August followed by an extortion attempt by the attackers. Governing officials publicly stated the city will not comply with the blackmailers' demands, characterizing the incident as a serious crime. The breach prompted an emergency Senate session where leadership addressed both the security incident and the extortion threat.
Aesto Health experienced a data breach affecting 9.5 million individuals, with attackers gaining unauthorized access to personal and health information stored in the company's AWS infrastructure. The incident highlights ongoing security challenges in healthcare technology environments and the sensitive nature of data at risk when cloud infrastructure is compromised.
METR disclosed two security incidents involving unauthorized access attempts to its systems, with attackers successfully stealing an API key and consuming approximately $600,000 worth of AI credits. The incidents highlight the value and accessibility of compromised API credentials in the AI services ecosystem, where stolen keys can be rapidly exploited for resource consumption before detection. No sensitive information was believed to have been compromised in the breaches.
Healthcare distributor McKesson is investigating a claimed data breach involving threat actor ShinyHunters, who allege they have stolen 284 million records from the company. The scale of the incident—affecting hundreds of millions of records—presents significant risk to patients and healthcare organizations that depend on McKesson's services.
McKesson has disclosed a breach affecting millions of patient records, with the threat actor ShinyHunters demanding a $55.2 million ransom. The incident highlights vulnerability in healthcare infrastructure, with reports indicating that pacemakers and other critical medical devices may have been targeted in the broader attack campaign.