The Week in Breach News: 04/16/25 – 04/22/25

This week: Hertz is the latest company hit in the Cleo exploit spree; the Medusa ransomware group claims victory over NASCAR; three fresh translated BullPhish ID videos; and 10 tips for securing users in a fast-moving software-as-a-Service (SaaS) world.
Read this week’s new featured blog: 10 Tips for Improving IT Security to Protect Your Users and Your Business

JPW Industries, Inc.
Exploit: Hacking
Industry: Manufacturing

JPW Industries, Inc. has confirmed a data breach that may have exposed highly sensitive personal information, including names, Social Security numbers, government-issued IDs and financial account details. The company became aware of the incident on February 3, 2025, and their investigation has revealed that a computer virus had locked parts of JPW’s systems as well as allowing bad actors to steal confidential data. JPW has not disclosed the number of people impacted but is taking steps to notify those affected.
How It Could Affect Your Customers’ Business: Speedy detection systems and excellent data breach response protocols can minimize the damage a company suffers after a cyberattack.
Kaseya to the Rescue: Explore the biggest challenges professionals contended with in 2024 and the impact of AI on cybersecurity in the Kaseya Cybersecurity Survey 2024. GET THE REPORT>>
Blue Shield of California
https://www.hipaajournal.com/blue-shield-of-california-google-ads-data-breach
Exploit: Misconfiguration
Industry: Business Services
Blue Shield of California announced a privacy breach on April 9, revealing that user data was unintentionally shared with Google Ads due to a misconfigured Google Analytics setup. The breach, which occurred between April 2021 and January 2024, may have exposed members’ sensitive information, including names, insurance details, medical service data and doctor search activity to Google’s advertising platform. The company stated the connection between Google Analytics and Google Ads was severed in January 2024, and no further data sharing has occurred since.
How It Could Affect Your Customers’ Business: Even widely used analytics tools like Google Analytics can pose serious privacy risks if not properly configured.
Kaseya to the Rescue: Maximize your security on a lean budget with the insights you’ll find in our infographic 5 Ways to Squeeze More From a Tight Security Budget. DOWNLOAD IT>>
NASCAR
https://hackread.com/medua-ransomware-claims-nascar-breach-latest-attack/
Exploit: Ransomware
Industry: Entertainment
The Medusa ransomware gang has claimed National Association for Stock Car Auto Racing (NASCAR) as its latest high-profile victim, demanding a $4 million ransom in exchange for not leaking sensitive internal data. The group released 37 images as proof of compromise. Initial analysis of the samples reveals a variety of internal materials, including corporate branding assets, raceway facility maps, employee contact spreadsheets, internal notes and photographs. The exposed data allegedly contains names, email addresses, job titles and potentially credential-related information, as well as detailed maps of race grounds. Medusa warned that the full trove of information would be published if NASCAR fails to meet the ransom demand.
How It Could Affect Your Customers’ Business: This incident highlights the importance of securing internal data to prevent data breaches from escalating into public, high-stakes ransom demands.
Kaseya to the Rescue: Get tips to strengthen a company’s defenses and bolster its cyber resilience with our Building a Cyber-Resilient Business checklist. GET THE CHECKLIST>>
United Domestic Workers of America
Exploit: Hacking
Industry: Non-Profit
United Domestic Workers (UDW) of America, American Federation of State, County and Municipal Employees (AFSCME) Local 3930 has disclosed that it has experienced a data breach. The union said that on or around January 17, 2025, UDW 3930 discovered an unauthorized third party on its IT network. They confirmed the third party accessed and possibly acquired private and confidential personal information from the UDW system. The data breach affected up to 200,000 individuals. The personal information in the compromised files may have included names, addresses and Social Security numbers.
How it Could Affect Your Customers’ Business: Organizations, especially those handling large volumes of private data, must have strong monitoring systems in place to quickly detect unauthorized access.
Kaseya to the Rescue: Our 10 Tips for Successful Employee Security Awareness Training infographic can help you maximize the effectiveness of your security awareness training efforts. DOWNLOAD IT>>
Nevro Corp.
Exploit: Hacking
Industry: Manufacturing
Nevro, a California-based medical device company known for its HFX spinal cord stimulation (SCS) platform, reported a data breach that potentially exposed sensitive personal information. The company determined that between November 21, 2024, and December 1, 2024, an unauthorized third party may have gained access to personal data. The compromised files could include names, Social Security numbers, driver’s license numbers, financial information (account or credit/debit card numbers), medical information and health insurance details. Nevro is currently working to assess the full scope of the breach and notify affected individuals.
How it Could Affect Your Customers’ Business: This incident underscores the critical importance of early detection and rapid response to suspicious network activity.
Kaseya to the Rescue: Identify the must-have features in a user protection solution and explore how to build a robust user protection strategy in our Modern User Protection Buyer’s Guide. GET IT>>
Hertz
Exploit: Hacking
Industry: Travel & Leisure
Rental car giant Hertz is the latest company to fall victim to the Cleo file transfer software exploit. The breach exposed the data of customers of Hertz and its subsidiaries Dollar and Thrifty car rental outlets in the U.S., Canada, the U.K., the E.U., and Australia. Affected information includes names, contact details, dates of birth, driver’s license and payment card details. For U.S. customers and employees, credit card data, workers’ compensation claims info, and for a small number, Social Security/government ID numbers, passport info and vehicle accident claim details were also snatched. U.K., Australian and E.U. customers may have had passport information compromised. In addition, Canadian employees may have had government ID numbers and injury or workers’ compensation claim data exposed.
How it Could Affect Your Customers’ Business: Businesses must prioritize securing third-party software, especially when relying on widely used tools like file transfer software.
Kaseya to the Rescue: Discover how Kaseya 365 User delivers comprehensive protection beyond the endpoint without breaking the bank. GET THE EBOOK>>


What challenges will IT pros face in the second half of 2024? Find out in the Mid-Year Cyber Risk Report. GET IT>>


Morocco – Caisse Nationale de Sécurité Sociale
Exploit: Hacking (Nation-State)
Industry: Government
Morocco’s Caisse Nationale de Sécurité Sociale (CNSS) confirmed a major cyberattack that exposed sensitive personal data on Telegram. Hackers bypassed security to steal internal documents, and early investigations suggest the breach was politically motivated, linked to tensions between Morocco and Algeria. Hackers claimed the attack was retaliation for alleged Moroccan “harassment” of Algeria on social media and warned of further strikes if Algerian platforms are targeted.
How it Could Affect Your Customers’ Business: Geopolitical tensions can spill into cyberspace, turning critical national infrastructure into targets.
Kaseya to the Rescue: Discover how Kaseya 365 User delivers comprehensive protection beyond the endpoint without breaking the bank. GET THE EBOOK>>


Take a deep dive into why an AI-powered anti-phishing solution is a smart financial choice. GET EBOOK>>


Read this week’s featured blog:10 Tips for Improving IT Security to Protect Your Users and Your Business
Remote or on-site, every endpoint matters. Check out these 10 practical IT security tips to help you lock down your organization’s devices, protect your users and stay one step ahead of cyberthreats. READ MORE>>


Learn how to identify and mitigate malicious and accidental insider threats before there’s trouble! GET EBOOK>>


See Our 3 New Anti-phishing Video Lessons in 3 Languages
Bad actors are constantly developing new traps to trick employees into falling for their phishing schemes. These three fresh videos, available in Portuguese, French and Spanish, can help keep spotting and reporting phishing top-of-mind for your users.
- Identificar E Denunciar Phishing VO (Portuguese)
- Repérage Et Signalement D’hameçonnage VO (French)
- Cómo Detectar Y Denunciar El Phishing VO (Spanish)
Learn more in the BullPhish ID Release Notes.


Learn how to spot today’s most dangerous cyberattack & get defensive tips in Phishing 101 GET EBOOK>>


Are You Building a Cyber-Resilient Business?
With hybrid work and cloud apps on the rise, protecting users anywhere and everywhere is critical for staying resilient against today’s sophisticated threats like phishing, BEC, ransomware and identity theft.
Download our essential checklist to discover key insights and smart actions to take that can help you protect users and strengthen your cyber defenses to build a cyber-resilient business.


Get expert advice for protecting your organization’s most vulnerable gateway in this infographic. DOWNLOAD IT>>


April 24: Microsoft 365 & Google Workspace User Health Check REGISTER NOW>>
April 24: Technical Thursday – Die neuesten Produktupdates und Feature-Releases REGISTER NOW>>
May 14: Kaseya + Datto Connect Local: Cape Town REGISTER NOW>>
May 15: Kaseya+Datto Connect Local: Sydney REGISTER NOW>>
May 20: Kaseya + Datto Connect Local: Chicago Symposium REGISTER NOW>>
May 22: Kaseya+Datto Connect Local: Detroit REGISTER NOW>>
May 22: Kaseya+Datto Connect Local: Melbourne REGISTER NOW>>
June 3: Kaseya+Datto Connect Local: New York City Symposium REGISTER NOW>>
June 17 – 19: Kaseya DattoCon Europe REGISTER NOW>>
October 6 – 8: Kaseya DattoCon REGISTER NOW>>
October 28 – 30: Kaseya DattoCon Asia-Pacific REGISTER NOW>>


Do you have comments? Requests? News tips? Complaints (or compliments)? We love to hear from our readers! Send a message to the editor.
Partners: Feel free to reuse this content. When you get a chance, email pr@kaseya.com to let us know how our content works for you!


Read our case studies and see how MSPs and businesses have benefited from using our solutions. READ NOW>