惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Register - Security
The Register - Security
美团技术团队
Recent Announcements
Recent Announcements
MongoDB | Blog
MongoDB | Blog
Jina AI
Jina AI
C
Check Point Blog
aimingoo的专栏
aimingoo的专栏
I
InfoQ
S
Securelist
T
Tor Project blog
GbyAI
GbyAI
L
LINUX DO - 热门话题
V
Visual Studio Blog
AWS News Blog
AWS News Blog
The Cloudflare Blog
腾讯CDC
K
Kaspersky official blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recorded Future
Recorded Future
李成银的技术随笔
W
WeLiveSecurity
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
M
Microsoft Research Blog - Microsoft Research
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Schneier on Security
Schneier on Security
B
Blog
IT之家
IT之家
爱范儿
爱范儿
H
Help Net Security
Simon Willison's Weblog
Simon Willison's Weblog
NISL@THU
NISL@THU
J
Java Code Geeks
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
Cyberwarzone
Cyberwarzone
博客园 - 叶小钗
MyScale Blog
MyScale Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Project Zero
Project Zero
F
Future of Privacy Forum
D
Darknet – Hacking Tools, Hacker News & Cyber Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hacker News: Ask HN
Hacker News: Ask HN
D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
B
Blog RSS Feed
V
Vulnerabilities – Threatpost

Comparitech

Cybercriminals say they hacked Harrison County, WV commission, demand ransom Cybercriminals say they breached AdvancedHealth, Tennessee clinic confirms Fluke Corp notifies 18,000+ people of data breach that leaked SSNs What is Token-Based Authentication? Tokens Explained Western Orthopaedics warns 113,000+ people of data breach that leaked SSNs, credit cards, and medical info What is ARP? ARP protocol explained What is symmetric encryption? Crunchyroll VPN not working? Fix buffering, errors & region blocks American Lending Center notifies 123,000+ people of data breach that leaked SSNs How to watch Oleksandr Usyk vs Rico Verhoeven online Cybercriminals say they hacked CarePoint Health, stole data Ransomware gang claims attack and data theft from UK city school Horizon Media reports data breach of SSNs, cybercriminals take credit Claude VPNs (and how to use Claude safely) What is GhostPairing on WhatsApp? What is a prompt injection attack? Where do leaked passwords end up? A statistical analysis of the dark web’s credential pipeline Ransomware roundup: April 2026 Suffolk, VA warns 157,000+ people of data breach that leaked SSNs, finances How to watch UFC 328 (Chimaev vs Strickland) from anywhere Cybercriminals say they hacked Winona County, MN (again) Keeper vs 1Password: Which password manager is best in 2026? What is F-Droid? Is it safe? Proton VPN Secure Core: What is it, and should you use it? What is an agentic browser? Features and how to use them safely Sandhills Medical Foundation warns patients of data breach Cybercriminals say they hacked Massachusetts Development Finance Agency, its second breach in 2 years STELIA Aerospace confirms cyber attack on North American systems. $2.07 million ransom issued Debt collector Rodenburg Law Firm warns 81,307 people of data breach Healthcare ransomware roundup: Q1 2026 stats on attacks, ransoms, and data breaches How to block ads on Paramount Plus A complete guide to smart speaker privacy What is the Great Firewall of China Cybercriminals say they hacked Rusk County, WI What is a decentralized VPN? Do you need a dVPN? Southern Illinois Dermatology warns patients of data breach that leaked SSNs 92,000 people notified of data breach following cyber attack at Puerto Rican hospital Cybercriminals say they hacked Minidoka Memorial Hospital, demand ransom What is sensitive data? Types and how to protect yourself Inside RAMP: What a leaked database reveals about Russia’s ransomware marketplace What is a passphrase? Are they safer than passwords? Phoenix Art Museum warns of data breach that leaked SSNs Mozilla VPN vs NordVPN – VPN Comparison Guide Cookeville Regional Medical Center warns 338,000 people of data breach Antimalware vs Antivirus: What’s the difference? What is URL phishing? Examples and how to stay safe How to use a VPN in Bhutan (and the best options) Cybercriminals give Brockton, MA hospital one week to pay ransom after hack Is Truth Social safe? Everything you need to know What is cyberwarfare? Medical implant maker TriMed warns 80,000+ people of data breach Ransomware roundup: Q1 2026 Heart South Cardiovascular Group warns 46,000+ people of data breach Cybercriminals say they hacked Community College of Beaver County Critical Infrastructure at Risk: 179 ICS Devices Exposed Online
Oregon employment firm notifies 142,000+ people of two data breaches claimed by ransomware gangs
Rebecca Mood · 2026-05-21 · via Comparitech

Oregon employment firm notifies 142,000+ people of two data breaches

Cardinal Services, Inc. has started issuing data breach notifications to 142,323 people following two separate cybersecurity incidents in 2025 — one in June and one in August. Ransomware group Rhysida claimed the first attack, issuing a $940,000 ransom demand. INC claimed the second.

In its notification, Cardinal Services states that:

On or around June 30, 2025, Cardinal became aware of unauthorized access it its systems. Upon learning of this issue, Cardinal immediately commenced an investigation into the incident and worked with external cyber security professionals experienced in handling these types of situations. During the investigation on August 8, 2025, Cardinal became aware of further unauthorized access to its systems and immediately worked with the cybersecurity professionals to secure its internal environment and continue its investigation to determine whether any personal or sensitive data was impacted as a result of the incidents.”

Exactly what data has been impacted in these incidents isn’t clear (the information is redacted in the notification) but Cardinal is offering those affected complimentary access to Epiq Privacy Solutions ID, which suggests sensitive data, such as Social Security numbers, could have been involved.

Cardinal Services is added to Rhysida's data leak site
Cardinal Services is added to Rhysida’s data leak site

Rhysida added Cardinal Services to its data leak site in mid-July 2025, issuing an 8 bitcoin ransom demand worth $940,000 at the time. Included within its proof pack were screenshots of Social Security numbers, ID cards, a tax compliance certificate, and various other documents.

In mid-September 2025, INC also added Cardinal Services to its data leak site. It said 140 GB of data had been stolen.

INC adds Cardinal Services to its data leak site

Cardinal Services hasn’t confirmed either of these ransomware claims, nor has it said whether any ransoms were demanded and/or paid. Comparitech contacted Cardinal for more information and we’ll update this article if we receive a response.

Who is Rhysida?

Rhysida is thought to have ties to the ransomware group Vice Society and first originated in May 2023. Since then, we have logged 268 attacks via this group with 112 of these attacks being confirmed by the entity involved.

Heart South Cardiovascular Group and Phoenix Art Museum recently issued data breach notifications following 2025 attacks claimed by Rhysida, with 46,666 and 1,758 people affected, respectively.

So far this year, we have noted eight attacks via Rhysida with two of these attacks being confirmed. These are German tech company Elabs AG, and Canadian manufacturer STELIA Aerospace North America Inc. 

Who is INC?

INC also emerged in 2023 (July) and has claimed 775 victims since then. Across these attacks, 188 have been confirmed by the entity involved.

Other recently confirmed attacks via the group include (all US-based):

  • Sandhills Medical Foundation, Inc. – May 2025 – 169,017 people affected
  • Cape Fear Country Club – January 2026
  • Pulpdent Corporation – March 2026
  • Central Medical Services of Westrock (CMSW) – May 2026
  • Parker Lipman LLP – March 2026 – 1,120 people affected

So far this year, we’ve recorded 195 attacks via INC with 22 of these being confirmed.

Ransomware attacks on US companies

In 2025, we tracked 755 confirmed attacks on US companies and are monitoring a further 3,121 unconfirmed attacks. Across the confirmed attacks, over 44.6 million records have been affected.

Other attacks that have been confirmed in recent weeks include:

  • American Lending Center – July 2025 – 123,158 people impacted (hackers unknown)
  • Fluke Corporation – August 2025 – 18,517 people impacted (claimed by Clop)
  • US Tiger Securities Inc. – July 2025 – 26,985 people impacted (unknown hackers)
  • Vacation Myrtle Beach – June 2025 – 10,750 people impacted (claimed by Play)

So far this year, we’ve noted 107 confirmed attacks and 1,387 unconfirmed attacks.

About Cardinal Services, Inc.

Located in Coos Bay, Oregon, Cardinal Services is an employment services firm that specializes in helping organizations with their payroll, staffing, workers’ comp, and HR needs. It was established in 1984.