Featured Article

The biggest data breaches in 2024: 1 billion stolen records and rising

Comment

Image Credits: Bryce Durbin (opens in a new window)

We’re over halfway through 2024, and already this year we have seen some of the biggest, most damaging data breaches in recent history. And just when you think that some of these hacks can’t get any worse, they do.

From huge stores of customers’ personal information getting scraped, stolen and posted online, to reams of medical data covering most people in the United States getting stolen, the worst data breaches of 2024 to date have already surpassed at least 1 billion stolen records and rising. These breaches not only affect the individuals whose data was irretrievably exposed, but also embolden the criminals who profit from their malicious cyberattacks.

Travel with us to the not-so-distant past to look at how some of the biggest security incidents of 2024 went down, their impact, and in some cases, how they could have been stopped. 

Mystery AT&T data leak exposed 73 million customer accounts

Some three years after a hacker teased a published sample of allegedly stolen AT&T customer data, a data breach broker in March dumped the full cache of 73 million customer records online to a known cybercrime forum for anyone to see. The published data included customers’ personal information, including names, phone numbers and postal addresses, with some customers confirming their data was accurate

But it wasn’t until a security researcher discovered that the exposed data contained encrypted passcodes used for accessing a customer’s AT&T account that the telecoms giant took action. The security researcher told TechCrunch at the time that the encrypted passcodes could be easily unscrambled, putting some 7.6 million existing AT&T customer accounts at risk of hijacks. AT&T force-reset its customers’ account passcodes after TechCrunch alerted the company to the researcher’s findings. 

One big mystery remains: AT&T still doesn’t know how the data leaked or where it came from

Change Healthcare hackers stole medical data on “substantial proportion” of people in America

In 2022, the U.S. Justice Department sued health insurance giant UnitedHealth Group to block its attempted acquisition of health tech giant Change Healthcare, fearing that the deal would give the healthcare conglomerate broad access to about “half of all Americans’ health insurance claims” each year. The bid to block the deal ultimately failed. Then, two years later, something far worse happened: Change Healthcare was hacked by a prolific ransomware gang; its almighty banks of sensitive health data were stolen because one of the company’s critical systems was not protected with multi-factor authentication.

The lengthy downtime caused by the cyberattack dragged on for weeks, causing widespread outages at hospitals, pharmacies and healthcare practices across the United States. But the aftermath of the data breach has yet to be fully realized, though the consequences for those affected are likely to be irreversible. UnitedHealth says the stolen data — which it paid the hackers to obtain a copy — includes the personal, medical and billing information on a “substantial proportion” of people in the United States. 

UnitedHealth has yet to attach a number to how many individuals were affected by the breach. The health giant’s chief executive, Andrew Witty, told lawmakers that the breach may affect around one-third of Americans, and potentially more. For now, it’s a question of just how many hundreds of millions of people in the U.S. are affected. 

Synnovis ransomware attack sparked widespread outages at hospitals across London 

A June cyberattack on U.K. pathology lab Synnovis — a blood and tissue testing lab for hospitals and health services across the U.K. capital — caused ongoing widespread disruption to patient services for weeks. The local National Health Service trusts that rely on the lab postponed thousands of operations and procedures following the hack, prompting the declaration of a critical incident across the U.K. health sector.

A Russia-based ransomware gang was blamed for the cyberattack, which saw the theft of data related to some 300 million patient interactions dating back a “significant number” of years. Much like the data breach at Change Healthcare, the ramifications for those affected are likely to be significant and life-lasting. 

Some of the data was already published online in an effort to extort the lab into paying a ransom. Synnovis reportedly refused to pay the hackers’ $50 million ransom, preventing the gang from profiting from the hack but leaving the U.K. government scrambling for a plan in case the hackers posted millions of health records online. 

One of the NHS trusts that runs five hospitals across London affected by the outages reportedly failed to meet the data security standards as required by the U.K. health service in the years that ran up to the June cyberattack on Synnovis.

Ticketmaster had an alleged 560 million records stolen in the Snowflake hack

A series of data thefts from cloud data giant Snowflake quickly snowballed into one of the biggest breaches of the year, thanks to the vast amounts of data stolen from its corporate customers. 

Cybercriminals swiped hundreds of millions of customer data from some of the world’s biggest companies — including an alleged 560 million records from Ticketmaster, 79 million records from Advance Auto Parts and some 30 million records from TEG — by using stolen credentials of data engineers with access to their employer’s Snowflake environments. For its part, Snowflake does not require (or enforce) its customers to use the security feature, which protects against intrusions that rely on stolen or reused passwords. 

Incident response firm Mandiant said around 165 Snowflake customers had data stolen from their accounts, in some cases a “significant volume of customer data.” Only a handful of the 165 companies have so far confirmed their environments were compromised, which also includes tens of thousands of employee records from Neiman Marcus and Santander Bank, and millions of records of students at Los Angeles Unified School District. Expect many Snowflake customers to come forward. 

More TechCrunch

The new bylines go beyond the typical @username references that often accompany link posts from news publications and those pointing to other written content, like a WordPress blog or Substack

Twitter/X alternative Mastodon appeals to journalists with new ‘byline’ feature

code references found in the X iOS app indicate that the company could be considering adding downvotes for replies only to improve how they’re ranked.

X weighs adding a downvote button to replies — but it doesn’t want to emulate Reddit

Evolve, a popular financial institution for fintech startups, announced that a cyberattack affected “the data and personal information of some Evolve retail bank customers and financial technology partners’ customers.” 

Yieldstreet says some of its customers were affected by the Evolve Bank data breach

Welcome to TechCrunch Fintech! This week, we’re looking at the Evolve Bank hack, three notable acquisitions, Plaid’s enterprise customer growth and more. To get a roundup of TechCrunch’s biggest and…

Evolve hack fallout continues, fintech M&A heats up and Plaid talks enterprise push

Raising a Series A round in today’s competitive market can be a daunting task. To equip seed-stage founders with the insights and strategies needed for success, TechCrunch Disrupt 2024 will…

What You Need to Raise a Series A Today at TechCrunch Disrupt 2024

Snapchat is introducing new ways for users to personalize their accounts, the company announced on Tuesday. The updates, which are mostly available for Snapchat+ subscribers, allow users to do things…

Snapchat’s latest features help users personalize their accounts

Meta plans to bring more generative AI tech into games, specifically VR, AR and mixed reality games, as the company looks to reinvigorate its flagging metaverse strategy. According to a…

Meta plans to bring generative AI to metaverse games

Featured Article

News outlets are accusing Perplexity of plagiarism and unethical web scraping

In the age of generative AI, when chatbots can provide detailed answers to questions based on content pulled from the internet, the line between fair use and plagiarism, and between routine web scraping and unethical summarization, is a thin one.  Perplexity AI is a startup that combines a search engine…

5 hours ago
News outlets are accusing Perplexity of plagiarism and unethical web scraping

The Make Design feature is available within Figma’s software and will generate UI (user interface) layouts and components from text prompts.

Figma disables its AI design feature that appeared to be ripping off Apple’s Weather app

Sophisticated spacecraft often run on shockingly outdated computing systems: consider that the Perseverance rover runs on a PowerPC 750, the processor famous for running on iMacs in the late 1990s. …

Computing and shielding startups join forces to put AI-capable chips in space

The venture fundraising trend in 2024 is fairly clear by now: Large, established VC firms are continuing to attract capital from limited partners, while smaller, newer funds are finding it…

Industry Ventures raises a $900M fund for investing in small, early-stage VCs and their breakout startups

Samyr Laine and Ayanna Alexander-Laine now put their grit and determination to work for founders wanting to launch and scale consumer brands.

Husband-and-wife former Olympians target $50M for new fund to invest in influencer-led consumer brands

Electricity demand is booming on account of AI. In a May 2024 report, Goldman Sachs predicted that data centers will use 8% of the U.S.’s total power supply by 2030, up from…

As the AI boom gobbles up power, Phaidra is helping companies manage datacenter power more efficiently

The amount of waste produced by the construction industry adds up to more than a third of the overall waste produced each year in the European Union. And it’s no…

Sensorita uses digital twins to help waste management companies streamline construction waste

BoldHue’s device essentially scans your face and dispenses a customized foundation formula that matches your skin tone.

Beauty tech startup BoldHue raises capital to ship its ‘Keurig for makeup’

Unacademy is slashing another 250 jobs in latest round of cuts as Indian edtech sector continues to struggle.Q

Indian edtech Unacademy cuts another 250 jobs

Apple unveiled iOS 18 last month at its Worldwide Developers Conference (WWDC). Since then, the company has released two developer betas in the last few weeks with extended support for…

Apple adds support for new languages across lock screen, keyboard and search on iOS 18

Anthropic is launching a program to fund the development of new types of benchmarks capable of evaluating the performance and impact of AI models, including generative models like its own…

Anthropic looks to fund a new, more comprehensive generation of AI benchmarks

A group of senators has banded together to urge Synapse’s owners and bank and fintech partners to “immediately restore customers’ access to their money.” As part of their demands, the…

Senators urge owners, partners and VC backers of fintech Synapse to restore customers’ access to their money

Hello and welcome back to TechCrunch Space. I hope everyone has a fantastic July 4 this week. Go eat a hot dog. Read my story from last week on the…

TechCrunch Space: Star spangled

Music, podcasts, audiobooks…emergency alerts? Spotify’s latest test has the streaming app venturing into new territory with a test of an emergency alerts system in its home market of Sweden. According…

Spotify tests emergency alerts in Sweden

Simply submitting the request for a takedown doesn’t necessarily mean the content will be removed, however.

YouTube now lets you request removal of AI-generated content that simulates your face or voice

The news highlights that the fallout from the Evolve data breach on third-party companies — and their customers and users —  is still unclear.

Fintech company Wise says some customers affected by Evolve Bank data breach

The Supreme Court on Monday vacated two judicial decisions concerning Republican-backed laws from Florida and Texas aimed at limiting social media companies’ ability to moderate content on their platforms. The…

Supreme Court sends Texas and Florida social media regulation laws back to lower courts

Afloat, a gift delivery app that lets you shop from local stores and have gifts delivered to a loved one on the same day, is now available across the U.S. The…

Gifting on-demand startup Afloat goes nationwide

Exciting news for tech enthusiasts and innovators! TechCrunch Disrupt 2024 is just around the corner, and we have an incredible opportunity for you to elevate your brand’s visibility. How? By…

Drive brand impact with a Side Event at TechCrunch Disrupt

After Meta started tagging photos with a “Made with AI” label in May, photographers complained that the social networking company had been applying labels to real photos where they had…

Meta changes its label from ‘Made with AI’ to ‘AI info’ to indicate use of AI in photos

Investment app Robinhood is adding more AI features for investors with its acquisition of AI-powered research platform Pluto Capital, Inc. Announced on Monday, the company says that Pluto will allow…

Robinhood snaps up Pluto to add AI tools to its investing app

Vaire Computing, based in London and Seattle, is betting that chips that can do reversible computing are going to be the way forward for the world.

Vaire Computing raises $4.5M for ‘reversible computing’ moonshot which could drastically reduce energy needs

The EC has found that Meta’s “pay or consent” offer to Facebook and Instagram users in Europe does not comply with the bloc’s DMA.

Meta’s ‘pay or consent’ model fails EU competition rules, Commission finds