Tag: data-breach
All entries tagged data-breach.
- Gyazo (Helpfeel): an image-upload-server vulnerability reaches arbitrary command execution, exposing 23.62 million user records and 490 million image-metadata records
- A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
- Swiss Bitcoin Pay (Neuchâtel) shuts down its servers after a suspected intrusion, saying IBANs, wallet addresses and hashed passwords may have been accessed
- Salt confirms misuse of an existing access credential to an unnamed 'peripheral system', up to 1.09 million Swiss mobile customers' records reportedly at risk
- Revolut discloses a customer KYC data breach after fulfilling a fraudulent request sent from inside a genuine government agency's own email domain
- Japan's Digital Agency: a VPN vulnerability exploited since May went undetected for a month, surfaced only by an anomalous mass file-access alert on a maintenance account, exposing ~246,000 government-personnel records
- France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool
- ChimeraZ claims France's Département de l'Aveyron employment platform, exposing 20,000+ people's data including 1,499 CVs, a customer account without MFA, an IDOR flaw and a misconfigured Odoo database, per one of two trackers who reviewed the leak
- A dark-web identity-theft storefront sells 153 million+ driver's-license scans traced to identity-verification vendor IDScan.net; FBI opens a formal investigation
- JetBrains admits its own Cadence cloud-compute service ran unpatched against a KEV-listed vulnerability it had disclosed a month earlier, and was breached through it for sixteen days
- Association des maires de France confirms a UNION-based SQL-injection breach exposing 114,000 records on mayors, municipal councillors and territorial agents, plaintext passwords included
- Thomson Reuters' C-Track court case-management platform breach reaches at least 13 US states, the US Virgin Islands and three Ontario courts
- CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account
- Dropbox account takeover via a federated Lenovo-ID trust gap: roughly 5,000 accounts accessed with no password and no 2FA bypass needed
- A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation
- ZeroBytes claims a third French government platform in three months: ~148.9M rows from Zéro Logement Vacant via a Metabase admin session and a cleartext production database password
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida
- Six Swiss cantons disclose bulk-harvesting of vehicle-owner data after an unknown actor bypassed per-person rate limits on public lookup portals, with extortion attempts against the platform operator and canton Vaud
- Troy Hunt: a 24.9M-address ShinyHunters/Carhartt breach-claim collapses to 12.9M real records once TPC-DS synthetic benchmark data and several duplicate/test-account patterns are filtered out, a reusable methodology for verifying inflated breach-claim record counts
- Nozomi Networks/CBC: Winnipeg's largest hospital network loses HVAC and door-access central monitoring to a ransomware incident with no named actor, access vector, or ransomware family disclosed 18 days later
- SUEZ Eau France notifies customers of a technical service provider's breach, identity, contract and, for some customers, bank and identity-document data exposed
- La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August
- Martigny-Combe (Valais) municipal email account compromised and used to send a fraudulent message to administration contacts, second Valais municipality hit in 2026
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector
- A 2023 ownCloud auth-bypass CVE re-enters CISA KEV because Hunt.io caught a suspected Chinese-speaking operator's open staging server using it to steal nuclear-research and naval-contractor data from two Philippine organisations
- A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list
- A Valais commune's secretariat mailbox was compromised on 10 August and sat quiet until the attacker used it on 18 August to mail roughly 450 of the commune's own contacts; the send is what triggered detection
- Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
- Spain's Castilla-La Mancha regional government confirms a cyberattack after the Panzer extortion group lists it; the government confirms the intrusion, not the group's data claims
- Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population, and the provider contractually watching its infrastructure round the clock did not notice
- StopAndProtect runs its whole operation off other people's WordPress sites, a must-use plugin that never appears in the plugin list, a hidden REST route that accepts PHP, and an installer that deletes itself
- Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself
- Arbeiterkammer Oberösterreich cannot scope its own breach because the attackers wiped the traces, so every member is being notified under Article 34 as a precaution
- Akira blinds EDR by rebooting a victim host into Safe Mode with Networking, the operator's first observed use of the technique, and the stripped-down boot starved its own encryptor
- CVE-2026-71362, Adobe Commerce and Magento Open Source: an unauthenticated attacker switches a customer session to another customer's account (CVSS 9.1), and a WAF vendor reports it is already blocking attempts
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
- NHS Blood and Transplant sent organ-offer messages naming recipients over an unencrypted pager network, and because pager broadcasts leave no receiver log, it cannot scope who received them
- France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone
- UK ICO reprimands the national criminal-records office over a seven-month website compromise; outsourced patching with no internal owner was the cause, and network segmentation is what capped the damage
- MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly
- A German federal- and state-funded memorial foundation is rebuilding its entire IT from scratch after ransomware, all seven sites offline, data assumed exfiltrated, no actor named
- One compromised contract-logistics processor put ten organisations into breach notification at once, CEVA Logistics, eight European warehouses, and a bank, a retailer and a games platform all learning from their supplier
- Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
- Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign, 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
- Żabka confirms an external service-provider account reached its ticketing system; the claimed pivot from Jira into source control and production is the seller's assertion, not the company's
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since 3 August, and no CVE was ever assigned
- Beacon CRM tells around 1,500 UK charities to assume everything they stored was taken, a compromised access key, exfiltrated backups, and encryption its experts think the attacker could undo
- A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation, one of 1,640 organisations a researcher counted from inside the actors' own servers
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- ByteToBreach hits Hungary's State Treasury after Romania's land registry; the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
- CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it
- French Éducation nationale: a hijacked staff account reached the agent-training system, exposing identity and NIR data for everyone who has worked in an académie since 2001
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
- Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
- Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion
- Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
- South Korea's Foreign Ministry: a ~10-month zero-day intrusion into the Diplomatic Academy's e-learning platform exposed records on nearly all diplomats
- Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million, the Swiss rail manufacturer refuses to pay
- Ernst & Young discloses a breach of a third-party IT support-ticket platform used by its tax practice, exposing client tax and financial documents
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
- TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers
- World Leaks posts ~858,000 files tied to India's Kudankulam nuclear-plant contractor; Reliance confirms a third-party-hosting breach
- Basel utility IWB: ~40,000 customer records exfiltrated in a breach of a third-party service provider
- Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability
- DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB; an attribution and volume IFAGE has not confirmed
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials
- Kairos data-theft-only extortion, a US county paid ~$1M with no ransomware encryptor ever recovered
- Navient discloses borrower SSN exposure from a ransomware hit on its outside law firm
- AdaptHealth breached via a social-engineered hijack of a third-party contractor's session
- Medtronic notifies ~9 million people of a ShinyHunters-claimed corporate-IT breach, 2.5 months after containment
- DHS confirms a breach of the Homeland Security Information Network (HSIN)
- MedusaLocker leak site lists the Canton of Zürich's Baudirektion, unconfirmed claim
- Blackfield ransomware demands $2M from Nidec's Taiwanese subsidiary after a 22 June server compromise
- Aflac discloses a Japan-subsidiary breach, 4.38 million policyholders and agents, ~10-day dwell before detection
- KDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs
- Island: "BadBlocker"; an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid
- ShinyHunters used a single vishing call into the company's identity platform to breach Madison Square Garden
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft
- Xsolis healthcare-AI vendor breach exposes 1.4M patients across seven US health systems, third-party processor pattern
- ShapedPlugin build pipeline compromised, three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell
- Brazil's national Cell Broadcast alert platform hijacked to push fake "Extreme Alert" messages to ~30M phones
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed
- Amazon's One Medical confirms a legacy-storage breach; ShinyHunters' 8.8TB claim is unverified and its deadline expires today
- Texas Parks & Wildlife: 3.08M licence holders exposed via an unnamed third-party vendor, with a public-vs-AG-filing SSN contradiction
- HCRG Care Group first notifies patients of a February 2025 Medusa breach, 16 months on
- UK Information Commissioner resigns with immediate effect, regulator left leaderless mid-restructure
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
- Kodak confirms breach after ShinyHunters leak-site listing; June 18 deadline passed without publication
- Nintendo employee data stolen from third-party HR-survey SaaS (TinyPulse), not Nintendo's own systems
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory
- Munich: ~120,000 student records suspected on the darknet, terminated employee under investigation
- iRhythm discloses data theft via social engineering of a third-party-hosted application (SEC 8-K)
- WordPress supply-chain compromise via Awesome Motive's CDN backdoors ~1.2M sites
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform, billing PII for ~2M customers leaked, no OT access
- Kyushu Electric subsidiary loses an unencrypted SSD with 10.9 million customer records, reportedly Japan's largest personal-data breach
- South Korea fines Coupang a record ₩624.7 bn over an unrevoked signing key held by a former employee
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- Maine's breach-notification portal abused for fraudulent filings against VRChat and Discord, both companies deny any breach
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- EDPB adopts a harmonised GDPR Article 33 breach-notification template; consultation open to 5 August
- ServiceNow unauthenticated REST endpoint queried customer instance tables before a silent 5 June patch
- Meta discloses 20,225 Instagram account takeovers via an AI support-tool logic flaw; Maine AG notification filed 8 June
- France's Tchap government messenger breached via account takeover, 73,467 civil servants' metadata scraped, CNIL notified
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities
- ICO secures Proceeds-of-Crime confiscation from former RAC employees who sold ~30,000 customer records
- Magecart family runs its skimmer out of Stripe, payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- Hijacked polyfill[.]io domain reactivates, surfacing native browser credential prompts on sites that never removed legacy script tags
- Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional services
- UN World Food Programme breach exposes IDs and locations of ~600,000 Gaza households
- Shared booking-software breach exposes guests at 100+ Dutch, Belgian and Irish hotels; phishing wave already underway
- NCSC Switzerland: Booking.com breach feeds two-pronged WhatsApp hotel-booking phishing against Swiss travellers
- Dashlane discloses TOTP brute-force that downloaded encrypted vaults of fewer than 20 users
- Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff
- California AG sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach, bulk-enumeration coding error plus absent credential-stuffing defences
- CNIL fines IQVIA Operations France €5M for health data warehouse security failures: no MFA, no log monitoring, no network segmentation
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach, misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records
- ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- West Pharmaceutical Services; 8-K/A confirms full operational restoration, data investigation ongoing
- ICO secures £355,880 POCA confiscation against former Markerstudy Insurance employee for off-hours bulk record access and sale
- B1ack's Stash carding marketplace publicly releases 4.6M card records, SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months
- ARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
- FunnelKit "Funnel Builder for WooCommerce" actively exploited as Magecart skimmer on 40,000+ WordPress stores, no CVE assigned
- node-ipc npm package backdoored via expired-domain account takeover, 90+ credential categories exfiltrated, three malicious versions, ~3-minute window to detection
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act
- Dutch IGJ rules Clinical Diagnostics/NMDL failed NEN 7510 information-security standard at time of July 2025 ransomware breach; ~941,000 patients affected, cervical-cancer screening data exposed
- BWH Hotels (Best Western, WorldHotels, Sure Hotels), 181-day unauthorised access to a guest-reservation web application, six EU brands in scope
- Foxconn confirms Nitrogen ransomware crippled North-American manufacturing sites; 8 TB / 11M files claimed
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation
- West Pharmaceutical Services files SEC Form 8-K Item 1.05, data exfiltrated, systems encrypted, global operations partially restarted
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- ICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
- Braintrust AI evaluation platform AWS account breach, multi-tenant LLM-provider keys and SaaS credentials at risk; mandatory key rotation across customer base
- Groupe 3R (Réseau Radiologique Romand), Akira ransomware claims 48 GB; 20 imaging centres across seven Swiss cantons, second attack in twelve months
- Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
- Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)