The week in breach news

This week: Microsoft disclosed details of a large-scale credential theft campaign targeting more than 35,000 users across 13,000 organizations in 26 countries. Meanwhile, an insider attack involving a software provider handling sensitive U.S. federal agency data has come to light, while major breaches in the hospitality and health care sectors continue to expose sensitive customer and patient information.

The week in breach news

North America

Microsoft users

Industry: Technology Exploit: Phishing

Microsoft disclosed details of a large-scale credential theft campaign that targeted more than 35,000 users across 13,000 organizations in 26 countries.

The campaign used code-of-conduct-themed phishing lures, combined with legitimate email services, to redirect users to attacker-controlled domains and steal authentication tokens. The phishing emails featured polished, enterprise-style HTML templates with structured layouts and authenticity statements, making them appear more credible and convincing than typical phishing attempts.

Most of the phishing emails targeted organizations in the health care and life sciences, financial services, professional services and technology sectors. The disclosure comes just a month after Microsoft revealed another large-scale phishing campaign using device code authentication flows to compromise organizations worldwide.

Source

How it could affect your business

Today's phishing campaigns are becoming increasingly sophisticated, blending seamlessly into everyday business communications and making them harder for users to identify. Organizations should prioritize continuous user awareness training and leverage advanced technologies, such as GenAI, to detect and stop evolving phishing threats.

United States

Opexus

Industry: Government & Public Sector Exploit: Malicious Insider

A software company that handles sensitive data for nearly every U.S. federal agency was reportedly the victim of an insider threat earlier this year.

Opexus, a software services provider used for processing U.S. government records, disclosed that two employees improperly accessed sensitive documents and compromised or deleted dozens of databases, including systems containing data from the Internal Revenue Service and the General Services Administration. The incident is now under investigation by the FBI and other federal law enforcement agencies.

According to reports, the two individuals, identified as twin brothers Muneeb and Suhaib Akhter, allegedly destroyed more than 30 databases and removed over 1,800 files tied to a government project. The incident also reportedly caused outages in key government software systems and, in some cases, permanent data loss.

Source

How it could affect your business

Incidents like this are a reminder that some of the most damaging cyberthreats can come from within an organization, with insider threats capable of causing severe operational disruption and data loss. Organizations should enforce strict access controls, continuously monitor privileged activity and implement role-based permissions to reduce the risk of unauthorized access or misuse of sensitive systems.

North America

BWH Hotels

Industry: Hospitality & Leisure Exploit: Hacking

BWH Hotels, the parent company of Best Western, WorldHotels and SureStay, confirmed a major data breach that exposed sensitive customer information.

The global hospitality company, which operates more than 4,500 hotels across 100 countries, detected unauthorized activity in a web application containing guest reservation data on April 22. The company acknowledged that attackers had maintained access to the network for more than six months. Thousands of reservations tied to Best Western and other BWH brands may have been exposed, raising concerns over targeted phishing attacks against travelers.

The company has begun notifying affected guests and is warning them to remain cautious of fake booking pages, suspicious communications and urgent payment requests.

Source

How it could affect your business

Breaches involving reservation and travel data can lead to highly targeted phishing attempts that appear legitimate and personalized. Organizations and individuals should stay alert to suspicious emails, fake booking links and urgent payment requests that attempt to exploit exposed customer information.

United States

West Pharmaceutical Services

Industry: Healthcare Exploit: Ransomware & Malware

West Pharmaceutical Services, a manufacturer of pharmaceutical packaging and drug delivery systems, experienced a ransomware attack on May 4 that prompted the company to proactively shut down and isolate portions of its on-premise infrastructure.

The Pennsylvania-based company, one of the world's leading providers of drug-delivery technologies, detected unusual activity on its network and took systems offline as a precautionary measure. The shutdown disrupted access to enterprise systems and temporarily affected global business operations.

According to the latest updates, the company has made significant progress in restoring operations globally, including restarting critical manufacturing and receiving and shipping systems at certain locations.

Source

How it could affect your business

Ransomware attacks continue to disrupt organizations across sectors. To reduce risk and recover quickly, organizations should maintain a robust business continuity and disaster recovery (BCDR) strategy, along with immutable, ransomware-protected backups that cannot be altered or deleted by attackers.

United States

NYC Health + Hospitals Corporation

Industry: Healthcare Exploit: Third-Party Data Breach

A data breach at NYC Health + Hospitals Corporation in late March may have affected more than 1.8 million individuals.

NYC Health + Hospitals is the largest public health system in the U.S. and serves more than 1 million New Yorkers. The Department of Health and Human Services Office for Civil Rights breach portal was updated to show that personal and protected health information belonging to approximately 1.8 million current and former patients and employees was compromised in the incident.

Investigators found that attackers had access to the network for 11 weeks, with the breach reportedly originating from a security incident involving one of the organization's vendors.

Source

How it could affect your business

Exposure of personally identifiable information and protected health information can create serious risks, including identity theft, insurance fraud and highly targeted phishing attacks. Health care organizations should strengthen third-party security oversight, enforce strict access controls, continuously monitor networks for suspicious activity and maintain strong incident response processes to reduce the impact of breaches involving sensitive patient data.

Like what you're reading?

Subscribe now to get security news and information in your inbox every week

Upcoming Webinars

Join other IT professionals to connect, learn and level up. Get insights into the latest cybersecurity trends and technologies.

Autotask quarterly product innovation update

Autotask quarterly product innovation update

Read more
Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Autotask Tech Jam: Master the Accounting Hub for QuickBooks Online

Read more
Compliance as a Service: The MSP revenue stream clients can't opt out of

Compliance as a Service: The MSP revenue stream clients can't opt out of

Read more