Hasbro Data Breach Exposed Employee Personal Information
Notification letters filed with the Massachusetts Attorney General reveal that a cyberattack disclosed by the toy and game giant in late March also compromised employee personal data, including names, postal and email addresses, phone numbers, national ID numbers, and financial account details. The exact scope remains unclear industry-wide, though Massachusetts alone reported 436 affected residents, and the earlier network intrusion had already cost roughly 11 million dollars in cleanup and delayed 25 million dollars in sales. No cybercrime group has listed the toymaker on a leak site, and the company says it has no evidence of misuse so far.
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
A commercial phishing-as-a-service kit has been abusing legitimate Microsoft 365 login flows since 2024, funneling victims through adversary-in-the-middle proxies that capture usernames, passwords, and live two-factor codes before hijacking the resulting session cookie. Roughly 4,500 organizations across more than sixty countries have been targeted, with 48 percent of identified email addresses potentially compromised and over 9,000 suspected session-theft events recorded, concentrated in technology, manufacturing, and education. Because the attacker ends up holding a valid session rather than a password, a simple credential reset does not remove their access.
White House bans foreign-made equipment for power generation over cyber backdoor concerns
An executive order signed this week bars the acquisition of foreign-made equipment used to manage electricity transmission lines rated 69,000 volts or higher, along with substations, control rooms, and generating stations, citing fears that embedded digital backdoors could let foreign governments disrupt the grid remotely. The Defense, Commerce, and Energy Departments must now screen relevant transactions, publish a list of pre-qualified vendors, and give agencies 120 days to inventory at-risk equipment already in use. The move follows a string of recent attacks on US and UK critical infrastructure, including intrusions at water utilities in a dozen states and the shutdown of a small British power plant.
Manchester Airports Group says hackers stole travelers’ data
The operator of Manchester, London Stansted, and East Midlands airports disclosed that intruders exfiltrated customer data tied to Wi-Fi sign-ups, car park bookings, lounge access, and Fast Track passes, exposing email addresses, phone numbers, vehicle registration numbers, and postcodes, though not payment details. The company suspended its online booking management tool as a precaution and says airport operations were never disrupted. Local reporting suggests as many as 8.9 million travelers could be affected, though the airport group has not confirmed that figure, and no extortion group had claimed the attack as of publication.
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Berlin’s state government is refusing to pay a ransom after the Rhysida group claimed to have stolen 5.79 terabytes of data, roughly 1.44 million files, from the city-state’s administrative network, including personnel records, plaintext credentials, court documents, and vulnerability analyses tied to the water supply. The breach was first disclosed August 17, with forensic investigators later tracing actual data exfiltration back to August 7, a full week before the network was isolated. Officials say the timing, weeks ahead of a September 20 state election, has raised concern, though they maintain no election-related systems or data were touched.