California-based company OmniVision announced that it suffered a data breach following a ransomware attack (Cactus) that took place last year.

OmniVision, a subsidiary of Chinese Will Semiconductor, designs and develops imaging sensors for smartphones, laptops ,webcams, automobiles, medical imaging systems and more.
On Friday, the company notified local authorities of a security that took place between September 4 and September 30, 2023.
See also: Australia: MediSecure suffers data breach
“ On September 30, 2023, OVT was notified of a security that resulted in the encryption of certain systems by an unauthorized third party incident ,” the statement said . “ In response to this incident, we immediately launched a comprehensive investigation with the assistance of third-party cybersecurity experts and notified law enforcement .”
Now, OmniVision says the investigation was completed on April 3, 2024, and revealed that there was also a data breach, with attackers stealing some personal information from the company, although it did not disclose how many people were affected.
However, in mid-October 2023, the Cactus ransomware gang claimed responsibility for the attack and data breach at OmniVision and leaked samples of the following data:
- Passport scans
- Non-disclosure agreements
- Contracts
- Confidential documents
The attackers eventually published all the data they had stolen, in a ZIP file available for free download.
Currently, OmniVision has been removed from the Cactus Gang's extortion page.
See also: Nissan North America: Data breach affects 53,000 employees
In response to this security and data breach , OmniVision has taken steps to secure its environment and more quickly detect suspicious activity. It also offers 24-month credit monitoring and identity theft recovery services to recipients of alerts.

Affected individuals are urged to register for the service, remain vigilant against unsolicited and suspicious communications, regularly review credit reports and accounts , and report unusual activity to their financial institution.
Attacks and data breaches
The OmniVision ransomware attack highlights the need for increased vigilance and preparedness against cyber threats. Companies must take proactive measures to protect their sensitive data and maintain customer trust.
Therefore, it is important for businesses to regularly review and update their security measures to stay ahead of potential cyber attacks
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Santander: Customer and employee data breach
Additionally, partnering with cybersecurity experts and investing in robust security solutions can help mitigate risks and prevent devastating consequences from a data breach.
As technology continues to advance, companies (like OmniVision) must ensure they don’t fall victim to data breaches and constantly adapt to the evolving threat landscape . Overall, cybersecurity should be a top priority for businesses of all sizes to protect their reputations, avoid financial losses, and maintain the trust of their customers, partners, and investors.
Source: www.bleepingcomputer.com
