Tricolor Holdings Targeted in Ransomware Attack Data Breach

KittyKatKrew claims to have breached Tricolor Holdings, a U.S.-based technology-enabled auto finance company serving underserved and credit-invisible consumers. The actor alleges the leaked file tree contains Active Directory exports, financial portfolio exports and master servicing tapes, archived legal and regulatory documents, marketing leads, internal chat logs, employee lists, and production SQL…

Read More
GVM Technologies Data Breach Exposes Student Passports

GVM Technologies, operating as GradSmart, reportedly suffered a data breach after a misconfigured cloud MongoDB instance without an IP whitelist and containing plaintext credentials allowed unauthorized access. The actor claims over 2,000 student records were exfiltrated, including full names, contact details, passport numbers, test scores, visa statuses, and academic and employment…

Read More
American National Standards Institute (ANSI) Suffers 3.6 TB Data Breach

A threat actor claims to have exfiltrated a massive 3.6 terabyte archive from an internal ANSI vault containing raw and classified standards data. The archive reportedly includes over 25,200 documents, unpublished drafts, full committee records, revision histories, metadata revealing pricing and access controls, and backend logs overlapping with ASTM, ISO, NIST,…

Read More