Amazon Confirms Employee Data Was Exposed Through MOVEit Breach


In a significant development that underscores the lasting impact of 2023’s MOVEit vulnerability, Amazon has confirmed that employee data was compromised through a third-party property management vendor.

The breach, revealed by a threat actor known as “Nam3L3ss,” exposes the continuing ripple effects of one of last year’s most devastating supply chain attacks. The compromise stems from the notorious MOVEit Transfer vulnerability, CVE-2023-34362, a critical SQL injection flaw that allowed unauthenticated attackers to gain unauthorized access to vulnerable systems.

Read more…
Source: Forbes News


Sign up for our Newsletter


Related:

  • Marriott hit by second data breach exposing “up to” 5.2 million people

    March 31, 2020

    Hotel chain Marriott International has today announced that it has been hit by a second data breach exposing the personal details of “up to approximately 5.2 million guests”. The breach, which began in mid-January 2020 and was discovered at the end of February 2020, saw contact details, including names, addresses, birth dates, gender, email addresses and ...

  • Data Breach Occurs at Agency in Charge of Secure White House Communications

    February 24, 2020

    Hackers have compromised the Department of Defense (DoD) agency in charge of securing and managing communications for the White House, leaking personally identifiable information (PII) of employees and leading to concerns over the safety of the communications of top-level U.S. officials in the run-up to the 2020 presidential election. Reuters first reported the data breach at the Defense Information ...

  • Details of 10.6 million MGM hotel guests posted on a hacking forum

    February 19, 2020

    The personal details of more than 10.6 million users who stayed at MGM Resorts hotels have been published on a hacking forum this week. Besides details for regular tourists and travelers, included in the leaked files are also personal and contact details for celebrities, tech CEOs, reporters, government officials, and employees at some of the world’s ...

  • Nedbank says 1.7 million customers impacted by breach at third-party provider

    February 14, 2020

    Nedbank, one of the biggest banks in the South Africa region, has disclosed a security incident yesterday that impacted the personal details of 1.7 million users. The bank says the breach occurred at Computer Facilities (Pty) Ltd, a South African company the bank was using to send out marketing and promotional campaigns. In a security notice posted on its ...

  • Misconfigured security command exposes 250 million Microsoft customer records

    January 23, 2020

    Microsoft has revealed a misconfigured security command was the culprit behind a leak of one of Microsoft’s internal customer support databases that exposed some 250 million customer records. “Our investigation has determined that a change made to the database’s network security group on December 5, 2019 contained misconfigured security rules that enabled exposure of the data,” explained the Microsoft Security ...

  • Hacker leaks passwords for more than 500,000 servers, routers, and IoT devices

    January 20, 2020

    A hacker has published this week a massive list of Telnet credentials for more than 515,000 servers, home routers, and IoT (Internet of Things) “smart” devices. The list, which was published on a popular hacking forum, includes each device’s IP address, along with a username and password for the Telnet service, a remote access protocol that can ...