Accounts of more than three million users of US-based appointment scheduling service FlexBooker have been stolen in an attack that took place before the holidays and are now being sold on malicious forums.

See also: Have I Been Pwned: DatPiff warns of data breach of millions of members
The same attackers are also offering databases claiming to come from two other entities: racing media organization Racing.com and Redbourne Group 's rediCASE case management software , both from Australia.
All three breaches allegedly occurred just days before Christmas.
The most recent breach appears to have occurred on FlexBooker, a popular tool for scheduling appointments and syncing employee calendars.
FlexBooker's customers include owners of any business that needs to schedule appointments, such as accountants, barbers, doctors, engineers, lawyers, dentists, gyms, beauty salons, therapists, trainers, spas, etc.
See also: Broward Health: Data breach affects 1.3 million people
The attack appears to be carried out by a group calling itself Uawrongteam, which shared links and files containing sensitive information, including photos, driver's licenses, and other identifiers.

According to Uawrongteam, the database contains a table with 10 million rows of customer information ranging from payment forms and charges to driver's license photos.
The actor notes that some "juicy columns" in the database are names, emails, phone numbers, password fragments, and hashed passwords.
FlexBooker sent a data breach notification to customers, confirming the attack and that the attackers had “accessed and downloaded” data on the Amazon cloud storage system.
See also: Chinese hackers hack data for future quantum decryption
FlexBooker advised users to remain vigilant and check account statements and credit reports for suspicious or fraudulent activity.
According to data breach notification service Have I Been Pwned, the FlexBooker attack affected data from more than 3.7 million accounts (3,756,794) consisting of email addresses, names, some credit card data, passwords, and phone numbers.
