The records of more than 760,000 employees of several major companies appeared online Monday morning after a malicious actor leaked them to a popular hacking forum.
See also: Korea: CEO arrested for adding DDoS capability to satellite receivers

The data apparently comes from last year's massive MOVEit , in which a zero-day in Progress Software's file transfer software was used to steal sensitive information from thousands of organizations.
Around 2,800 organizations and nearly 100 million people were affected by the attack, which is believed to have been carried out by the Russian-linked Cl0p ransomware gang
The newly leaked data was posted on Monday on the BreachForums cybercrime forum by a threat actor named Nam3l3ss, who has previously been linked to other data leaks linked to the MOVEit hack.
See also: FTC: Changes telemarketing rules to protect against "tech support scammers"
The leaked employee records belong to major companies Bank of America, Koch, Nokia, JLL, Xerox, Morgan Stanley and Bridgewater and mainly include names, employee emails, phone numbers, work ID numbers, job titles and manager names.

Atlas Privacy 's data breach reporting service DataBreach , which added the data to its database to help individuals discover if they were affected, believes the information likely came from Cl0p, but was filtered to extract relevant details.
Atlas carefully reviewed the records and estimates that they belong to 288,297 people working at Bank of America, 237,487 employees from Koch, 94,253 from Nokia, 62,349 from JLL, 42,735 from Xerox, 32,861 from Morgan Stanley114 and 2,141 from Bridgewater.
See also: Operation Serengeti: 1000 people arrested in Africa for cybercrimes
There are several steps we can take to reduce the risk of data leaks. First, using strong and unique passwords for our accounts can make it more difficult for malicious actors to gain access. Also, enabling two-factor authentication (2FA) provides an extra layer of protection. Second, it is important to be cautious of the emails and links we receive, as phishing attacks are a common method of data breach. Finally, regularly updating our software and using secure networks, such as VPNs, can help maintain our privacy and the security of our data. With small but meaningful steps, we can strengthen our protection against such threats.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
