Data Breaches - W/E - 01/11/19

500K People Affected by San Diego School District Data Breach (12/26/2018)
Personal data has been breached at the San Diego Unified School District in California. The district became aware of the breach in October, but the actual compromise occurred between January and November 1, according to a statement. The data file that had been viewed by unauthorized individuals contained information on students dating back to the 2008-09 school year, or more than 500,000 individuals. The district stated that phishing techniques which gathered log-in credentials for staff members caused the breach.

Bruegger's Bagels, Caribou Coffee Impacted by Data Breach (12/26/2018)
The parent company for Bruegger's Bagels and Caribou Coffee stated that the discovery of unusual activity on its network has revealed a data breach. While working with FireEye's Mandiant division, it was determined that the breach had taken place between August 28 and December 3 and that names and payment card data had been exposed. Up to 254 Caribou Coffee locations and 157 Bruegger's Bagels stores were potentially impacted, parent company Coffee and Bagels said.

Magecart Attack Causes Breach at OXO International (01/09/2019)
Home goods company OXO International was targeted by a breach that came to light on December 17, but took place on various dates between June 9, 2017 and October 16, 2018, according to a letter submitted to California's Office of the Attorney General. Personal information that had been entered on OXO's payment site has been compromised. Bleeping Computer has reported that the breach is the result of a Magecart attack, which involves the injection of malicious script into a site's checkout page so that payment data can be siphoned.

Marriott Starwood Breach Numbers Downgraded from 500 Million to 383 Million Affected (01/08/2019)
Although it was first thought that 500 million people had been affected by the November breach that impacted Marriott customers, the hotel company has said that the number is slightly less and that 383 million guests have had their data exposed. The breach affects guests who made reservations at a Starwood property on or before September 10, 2018. After a forensics evaluation, Marriott changed its original estimate of 500 million breached customers to 383 million. Marriott also said in a January 4 statement that 5.25 million unencrypted passport numbers and 20.3 million encrypted passport numbers were included in the information accessed by an unauthorized third-party.