2020 Wind River Systems — HR/personnel files exfiltrated from corporate network
Data compromised
Employee PII and benefits/financial enrollment fields per Wind River disclosures
Technical writeup
Embedded-software vendor Wind River Systems told employees and press that files containing human-resources and personnel data were downloaded from its network around September 29, 2020, with public disclosure following in early 2021. Company statements cited possible exposure of SSNs, passport or visa numbers, driver licenses, national IDs, dates of birth, health or benefits data, and financial account metadata for workforce members, without a widely published headcount.
Root cause
External intrusion into corporate IT with document exfiltration (per company breach notifications)