PrivacySignal
Breach

Kaspersky Lab experts have discovered a new attack vector and toolkit for compromising corporate Gmail accounts

DataBreaches.net · · International · Data Breaches

Kaspersky Lab has identified a new toolkit used by the threat actor group ToddyCat that targets corporate Gmail accounts through API-based access, allowing attackers to read emails, extract calendar data, and move through connected Google services while staying hidden for long periods.

Why this matters: Corporate Gmail is not just email. It is calendars, shared documents, meeting notes, and contact histories — a detailed map of how an organization actually works. API-based access is the quiet kind of intrusion: no password reset, no obvious sign-in, nothing that triggers a standard alert. The people whose data gets read may never know it happened. If your company runs on Google Workspace, this is a reminder that account access and API permissions deserve the same scrutiny as your firewall.

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Breach
DataBreaches.net · · International

NHS admits data breach by sending patient data via pagers

The NHS has acknowledged a data breach after a BBC investigation found that sensitive personal information about transplant patients — including names, dates of birth, and organ details — was routinely transmitted over an unencrypted pager network.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

#breach#enforcement#healthcare#privacy Read original →
Breach
HIPAA Journal · · US Federal

Boston Healthcare for the Homeless Program Breach Affects At Least 185K State Residents

The Boston Healthcare for the Homeless Program has disclosed a data breach affecting at least 185,000 Massachusetts residents, according to a report that also notes breaches at Monongalia County General Hospital and other healthcare organizations.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
HIPAA Journal · · US Federal

Texas Hearing Institute Ransomware Attack Affects 30,000 Patients

Texas Hearing Institute disclosed a ransomware attack that compromised the protected health information of nearly 30,000 patients. The incident falls under HIPAA breach notification requirements, prompting the organization to go public with details of the cyberattack.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare#security Read original →
Breach
HIPAA Journal · · US Federal

Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients

Aesto Health, a healthcare technology company based in Birmingham, Alabama, has disclosed a data security incident that affected multiple healthcare provider clients. The breach was reported by The HIPAA Journal, though specific details about the number of patients affected or the nature of the compromised data have not been specified in available reporting.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →