Service Provider

Industry

Cyberattack at LexisNexis Risk Solutions

December 25, 2024

Risk management provider, LexisNexis Risk Solutions (LNRS) suffered a cyberattack where personally identifiable information for over 360,000 customers ended up stolen.
“On April 1, 2025, we learned that on December 25, 2024, an unauthorized third party acquired certain LNRS data from a third-party platform used for software development,” the company said in a letter to victims. “The issue did not affect LNRS’s own networks or systems.
Based on LNRS’ review of the impacted data, the Alpharetta, Georgia-based company determined personal information ended up affected in the attack. There were 364,333 people affected in the attack.

read more

Automation Service Provider, Caltrol, Suffers Cyberattack

January 27, 2025

Automation services provider, Caltrol Inc. suffered a cyberattack over a six-day period at the end of January into February where a threat actor was able to exfiltrated personally identifiable information of victims.
From Monday, January 27 until Saturday, February 1, Caltrol suffered an attack that involved personal information. The company sent out letters saying “we received your information because your parent or spouse is employed by our organization.”
“On February 1, 2025, Caltrol became aware of technical issues related to our server,” the company said in a letter to victims. “Upon discovery, we took immediate action to secure our company’s systems and retained outside cyber counsel and engaged independent IT specialists (at the direction of counsel) to investigate the incident.”

read more

Ransomware Attack at Security Firm, Andy Frain Services

October 23, 2024

Security provider, Andy Frain Services (AFS) suffered an October 2024 data breach where 100,964 people fell victim to the hack.
Aurora, Illinois-based AFS said it discovered the breach on October 23, 2024. Ransomware gang Black Basta claimed responsibility for the breach in November 2024, saying it stole 750 GB of data from the private security firm.
In a letter to victims of the attack, Andy Frain did not mention if this was a ransomware attack or not. It did not verify the Black Basta claim.

read more

Cyberattack at Hyundai IT Provider

March 1, 2025

Fountain Valley, California-based information technology (IT) service provider, Hyundai AutoEver America, LLC (HAEA), suffered a cyberattack in February and is now letting victims know their personally identifiable information ended up stolen in a hack.
“On March 1, 2025, HAEA became aware of a cyber incident that impacted our information technology environment,” the company said in a letter to victims. “Upon discovery, we immediately launched an investigation with the support of external cybersecurity experts to assess the scope of the incident, confirm containment, and identify any affected information.
HAEA said it also notified law enforcement and is working with them.

read more

Cyberattack at Engineering Service Provider

January 8, 2025

Walnut, California-based RKA Consulting Group suffered a cyberattack in January and is now letting victim know their personally identifiable information ended up stolen in the hack.
That personal information may be the result of working with RKA Consulting on an engineering project.
“On or around January 8, 2025, we discovered suspicious activity on our systems,” the company said in a letter to victims just over four days ago. “We immediately disconnected these systems, began an investigation, and engaged independent computer forensic experts to assist.”

read more

Cyberattack At Power Plant, Marine Service Provider, Goltens

May 28, 2025

Marine and power plant service provider, Goltens Worldwide Management Corp. suffered a cyberattack in May after threat actors obtained access via an employee’s email account.
“On May 28, 2025, Goltens became aware of suspicious activity relating to an employee’s email account,” the company said in a letter to victims. “Goltens promptly secured the employee’s email and ensured that the activity did not extend outside of the email tenant.
With the assistance of third-party cybersecurity specialists, Manasquan, New Jersey-based Goltens also launched an investigation to determine the full scope of the incident.

read more