Australian consumer-credit lender Latitude Financial disclosed that attackers had exfiltrated 14 million records β including 7.9 million driver's licence numbers and 53,000 passport numbers β via credentials stolen from a service provider.
- Victim
- Latitude Financial Services
- Loss
- $50.0M
- Records
- 14.0M
Russian-speaking attackers exfiltrated full health-claim records on 9.7 million current and former Medibank customers, then released them in tranches on the dark web after the Australian insurer refused to pay.
- Victim
- Medibank Private
- Loss
- $250.0M
- Records
- 9.7M
An unauthenticated API endpoint exposed personal data of 9.8 million current and former Optus customers β names, dates of birth, passport and driver's licence numbers β to a single anonymous attacker.
- Victim
- Optus (Singtel)
- Loss
- $140.0M
- Records
- 9.8M
REvil affiliates encrypted the world's largest meat processor, shutting down beef and pork plants across the U.S., Canada, and Australia. JBS paid an $11 million ransom β one of the largest publicly-confirmed ransomware payments at the time.
- Victim
- JBS S.A. / JBS USA
- Loss
- $100.0M