#data-breach

[ follow ]
US politics
fromDataBreaches.Net
2 hours ago

Treasury cancels $21 million in Booz Allen contracts, blaming a breach that happened years ago - DataBreaches.Net

The Treasury Department canceled $21 million in Booz Allen contracts after a former Booz employee stole tax return data, prompting accusations of inadequate safeguards.
#ransomware
fromZDNET
4 weeks ago
Information security

Massive Aflac breach exposed millions of SSNs and other data - get free protection today

fromZDNET
4 weeks ago
Information security

Massive Aflac breach exposed millions of SSNs and other data - get free protection today

#extortion
#shinyhunters
fromDataBreaches.Net
4 days ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromDataBreaches.Net
4 days ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

Information security
fromDataBreaches.Net
3 days ago

Call-On-Doc allegedly had a breach affecting more than 1 million patients. They've yet to comment. - DataBreaches.Net

Call-On-Doc faced a reported breach exposing over one million patient records, including sensitive STD diagnoses, despite advertising state-of-the-art data security.
Privacy technologies
fromWIRED
3 days ago

DOGE May Have Misused Social Security Data, DOJ Admits

Law enforcement and immigration agencies are using warrantless data purchases, door raids, and surveillance tech to bypass Fourth Amendment protections.
Information security
fromSecurityWeek
3 days ago

Nike Probing Potential Security Incident as Hackers Threaten to Leak Data

Nike is investigating a potential cybersecurity incident after WorldLeaks listed Nike as a victim and threatened to publish alleged stolen data unless paid.
#okta
Information security
fromTechzine Global
4 days ago

149 million login details leaked via unsecured database

A publicly accessible database exposed 149 million usernames and passwords across email, social, financial, government, and streaming services, likely harvested by infostealer malware.
#cybersecurity
fromDataBreaches.Net
4 days ago
Information security

NL: Police warned about security hole used by Russian hackers in major theft of police data - DataBreaches.Net

fromTheregister
1 month ago
Higher education

Sydney Uni data goes walkabout after code repo raided

A University of Sydney code repository breach exposed historical personal data of thousands of current and former staff, affiliates, alumni, and students.
fromwww.bbc.com
1 month ago
UK politics

Government data stolen in hack, minister confirms

Government data was stolen in a hack; officials closed the vulnerability, an investigation is ongoing, the perpetrator remains unknown, and individual risk is assessed as fairly low.
fromDataBreaches.Net
4 days ago
Information security

NL: Police warned about security hole used by Russian hackers in major theft of police data - DataBreaches.Net

Information security
fromWIRED
4 days ago

149 Million Usernames and Passwords Exposed by Unsecured Database

A publicly exposed database of 149 million account credentials—including 48M Gmail, 17M Facebook, and others—was hosted and then taken down for violating host terms.
US politics
fromwww.npr.org
4 days ago

Trump administration admits even more ways DOGE accessed sensitive personal data

DOGE staff improperly accessed and shared sensitive Social Security and personal data on millions; extent, uses, and unauthorized political connections remain unclear.
#under-armour
fromTechCrunch
5 days ago
Information security

Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch

fromTechCrunch
5 days ago
Information security

Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch

Privacy professionals
fromSecuritymagazine
6 days ago

Two Unique DHS Cyber Incidents Exposed 1M People's Data

Two state DHS data incidents exposed sensitive resident information through misconfigured maps and unauthorized system access, impacting roughly 700,000 Illinois residents and Minnesota users.
Information security
fromTechCrunch
6 days ago

Exclusive: UStrive security lapse exposed personal data of its users, including children

UStrive experienced a security lapse that exposed personal data of users, including children, via a vulnerable GraphQL endpoint accessible to logged-in users.
Privacy professionals
fromSecuritymagazine
1 week ago

Lawsuit Filed After 320,000 Impacted by Monroe University Breach

Monroe University experienced a Dec. 9–23, 2024 data breach exposing sensitive personal and health information, prompting delayed notices and a class-action lawsuit.
Privacy professionals
fromDataBreaches.Net
1 week ago

SK Telecom files lawsuit to revoke record 135 bln-won fine over data breach - DataBreaches.Net

SK Telecom filed a lawsuit to overturn a 135 billion-won PIPC fine over a USIM data leak that affected 23 million users.
Privacy professionals
fromDataBreaches.Net
1 week ago

UK: North West Ambulance Service's increased breach reports may reflect better reporting - DataBreaches.Net

North West Ambulance Service recorded almost 400 data breaches in three years, with rising incidents driven by confidentiality failures and increased reporting.
Information security
fromDataBreaches.Net
1 week ago

4 in 5 small businesses had cyberscams last year, almost half were AI powered - DataBreaches.Net

Cybercrime causes small businesses to raise prices; AI increasingly enables attacks, and many small businesses suffer repeated breaches within a year.
Privacy professionals
fromDataBreaches.Net
1 week ago

Japanese nuclear regulator employee loses phone containing sensitive info in China - DataBreaches.Net

A Nuclear Regulation Authority employee lost a work smartphone in China containing confidential nuclear security staff names and contacts, risking a potential information leak.
Privacy professionals
fromDataBreaches.Net
1 week ago

A faceless hacker stole my therapy notes - now my deepest secrets are online forever - DataBreaches.Net

The theft of 33,000 Vastaamo psychotherapy records exposed victims to extortion, public disclosure of sensitive therapy details, and enduring psychological and privacy harm.
Information security
fromSecuritymagazine
1 week ago

Grubhub Data Stolen in Confirmed Hack, Questions Remain

Grubhub confirmed unauthorized data downloads from certain systems, stopped the activity, and said sensitive financial and order history information was not affected.
Information security
fromwww.housingwire.com
1 week ago

Judge consolidates SitusAMC class actions after 2025 data breach

SitusAMC experienced a Nov. 12, 2025 data incident compromising accounting records, client agreements, and possibly client-customer data; a lead lawsuit alleges negligent data protection.
US news
fromSecuritymagazine
1 week ago

This Website Exposed ICE Data - Now, It's Faced a Cyberattack

A publicly accessible ICE List database exposes PII for roughly 4,500 federal ICE agents and supervisors and recently suffered a DDoS attack reportedly originating from Russia.
Privacy professionals
fromFast Company
1 week ago

Remember that viral Tea app? The controversial 'dating safety' platform is back, this time on the web

A popular dating-safety app aimed at protecting women suffered major data breaches, legal challenges, and App Store removal but returns via a website relaunch.
UK news
fromTheregister
1 week ago

Woman bailed as cops probe doctor's surgery data breach

A 29-year-old non-surgery staff member was arrested and bailed in connection with an alleged data breach and theft at Croft Surgery.
Information security
fromTechzine Global
1 week ago

Five Belgian hospitals affected by data breach

Third-party software supplier breaches exposed 71,000 patient and provider records, highlighting supplier risk and inadequate third-party monitoring in Belgian healthcare.
EU data protection
fromTheregister
1 week ago

France fines telcos 42M for issues leading to 2024 breach

Free and Free Mobile were fined €42 million by CNIL for a breach exposing over 24 million customers' personal and financial data.
#coupang
fromDataBreaches.Net
1 week ago
Privacy professionals

Data protection agency tells Coupang to stop publishing unconfirmed information about data breach - DataBreaches.Net

fromDataBreaches.Net
4 weeks ago
E-Commerce

South Korean retail giant Coupang to compensate $1.1 billion to affected users over data breach - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Privacy professionals

Data protection agency tells Coupang to stop publishing unconfirmed information about data breach - DataBreaches.Net

fromDataBreaches.Net
4 weeks ago
E-Commerce

South Korean retail giant Coupang to compensate $1.1 billion to affected users over data breach - DataBreaches.Net

fromDataBreaches.Net
1 week ago

Victorian Department of Education says hackers stole students' data - DataBreaches.Net

The Department of Education in Victoria, Australia, notified parents that attackers accessed a database containing the personal information and email addresses of current and former students, prompting password resets. The department disclosed the breach in letters sent to parents, stating that an unauthorized third party accessed students' names, school names, year levels, and school-issued email addresses, as well as encrypted passwords for accounts that use them.
Education
fromDataBreaches.Net
1 week ago

Eurail passengers taken for a ride as data breach spills passports, bank details - DataBreaches.Net

Eurail B.V. has unfortunately experienced a security breach within our systems that resulted in unauthorized access to customer data. Following the discovery, we immediately began work to secure our systems and initiated an investigation with the support of external cybersecurity specialists and legal advisors. We take this matter very seriously and are currently conducting a thorough investigation to determine the full scope of the incident and its potential impact on customers, which includes participants of the European Commission's DiscoverEU action.
EU data protection
EU data protection
fromTheregister
1 week ago

Passports, bank details compromised in Eurail data breach

Eurail confirmed a data breach exposing customer personal and passport information, with DiscoverEU participants at higher risk of additional ID, bank, and health data exposure.
EU data protection
fromTheregister
1 week ago

Endesa probes breach after hackers claim huge data haul

Endesa suffered an unauthorized intrusion potentially exposing identifying details, national IDs, contract data and some IBANs for millions of customers, while passwords were not accessed.
US news
fromTechCrunch
1 week ago

Man to plead guilty to hacking US Supreme Court filing system | TechCrunch

Nicholas Moore is expected to plead guilty for repeatedly accessing the U.S. Supreme Court's electronic filing system on 25 days between August and October 2023.
Privacy technologies
fromDataBreaches.Net
2 weeks ago

Armenia probes alleged sale of 8 million government records on hacker forum - DataBreaches.Net

Hackers are selling an alleged Armenian government notification dataset of about 8 million records for $2,500, prompting an official investigation.
Information security
fromTechCrunch
2 weeks ago

Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users | TechCrunch

Hackers accessed some Betterment systems via social engineering through third-party platforms, exposing customer contact details and dates of birth; fraudulent crypto-solicitation messages were sent.
#cyberattack
fromTheregister
2 weeks ago

Latest BreachForums reboot spills data on 325K users

The allegedly stolen user data was later posted to shinyhunte[.]rs, alongside a message from a self-described cyber outlaw calling himself "James," who appeared keen to make sure his handiwork didn't go unnoticed. Have I Been Pwned's listing of the incident shows that the breach occurred before law enforcement's October 2025 takedown of the BreachForums domain, and that the leak comprised roughly 324,000 unique email addresses, usernames, and Argon2-hashed passwords, pulled from public posts, private messages, and other forum records.
Information security
#instagram
fromTechCrunch
2 weeks ago
Information security

Instagram says there's been 'no breach' despite password reset requests | TechCrunch

fromEngadget
2 weeks ago
Information security

An Instagram data breach reportedly exposed the personal info of 17.5 million users

fromTechCrunch
2 weeks ago
Information security

Instagram says there's been 'no breach' despite password reset requests | TechCrunch

fromEngadget
2 weeks ago
Information security

An Instagram data breach reportedly exposed the personal info of 17.5 million users

#healthcare
fromComputerWeekly.com
2 weeks ago

Personal data of thousands stolen in attack on London councils | Computer Weekly

The Royal Borough of Kensington and Chelsea (RBKC) in Greater London is in the process of contacting households across the borough after establishing in December that personal data on thousands of residents was stolen in a cyber attack on shared systems operated by the council. Over a month after the incident, several services remain disrupted or are operating in a limited capacity.
Information security
#eeoc
fromDataBreaches.Net
2 weeks ago
Information security

EEOC experienced security incident involving an Opexus employee's 'unauthorized' access, email says - DataBreaches.Net

fromNextgov.com
2 weeks ago
Information security

EEOC experienced security incident involving contractor's 'unauthorized' access, email says

fromDataBreaches.Net
2 weeks ago
Information security

EEOC experienced security incident involving an Opexus employee's 'unauthorized' access, email says - DataBreaches.Net

fromNextgov.com
2 weeks ago
Information security

EEOC experienced security incident involving contractor's 'unauthorized' access, email says

Public health
fromTechCrunch
2 weeks ago

Illinois health department exposed over 700,000 residents' personal data for years | TechCrunch

A security lapse exposed personal information of over 700,000 Illinois residents via a public internal mapping website from April 2021 to September 2025.
fromDataBreaches.Net
2 weeks ago

Methodist Homes of Alabama and Northwest Florida is notifying residents and employees of its second data breach in seven months. - DataBreaches.Net

For residents and patients, the account information included first and last name, Social Security number, date of birth, Medicare number, or medical treatment and condition information. For those individuals who were not residents, personal information involved first and last name, in combination with one or more of the following data element(s): Social Security number, passport number, driver's license or state identity card information, medical information, health insurance information, and online log-in information corresponding with the individual whose email account was compromised.
Information security
Arts
fromwww.npr.org
2 weeks ago

A 200-year-old book distributor is closing. Here's what that means for public libraries

Baker & Taylor, the nation's largest print book distributor to public libraries, is closing amid financial troubles, a 2022 data breach, and industry pressures.
#cyber-attack
Privacy professionals
fromDataBreaches.Net
3 weeks ago

NZ: High Court grants injunction over ManageMyHealth cyber breach - DataBreaches.Net

A High Court injunction bars sharing Manage My Health stolen data, but limited jurisdiction and unserved attackers make the injunction unlikely to prevent further dissemination.
#honeypot
fromDataBreaches.Net
3 weeks ago
Information security

Threat actors insisted that Resecurity's honeypot was real data. We found no evidence that it was. - DataBreaches.Net

ScatteredLapsus$Hunters alleges exfiltration of Resecurity internal chats, employee records, threat intel, client lists, and plans; Resecurity deployed a synthetic-data honeypot that captured attacker activity.
fromDataBreaches.Net
3 weeks ago
Information security

ShinyHunters claims to have compromised Resecurity, but it looks like they fell for a honeypot - DataBreaches.Net

Threat actors claim full access to REsecurity systems, exfiltrating internal chats, employee data, client lists, and plans; REsecurity says data were honeypots, no customer impact.
fromDataBreaches.Net
3 weeks ago
Information security

Threat actors insisted that Resecurity's honeypot was real data. We found no evidence that it was. - DataBreaches.Net

fromDataBreaches.Net
3 weeks ago
Information security

ShinyHunters claims to have compromised Resecurity, but it looks like they fell for a honeypot - DataBreaches.Net

Privacy professionals
fromDataBreaches.Net
3 weeks ago

Illinois Department of Human Services tightens map security after data incident - DataBreaches.Net

Internal planning maps with incorrect privacy settings exposed personal data of ~32,401 DRS customers and ~672,616 Medicaid/Medicare Savings Program recipients.
fromTheregister
3 weeks ago

Cybercrook claims to sell critical info about utilities

The crim says the haul spans more than 800 classified raw LiDAR point cloud files in .las format ranging from 100 MB to 2 GB each; full coverage of transmission line corridors and substations, which includes layers for bare earth, vegetation, conductors, and structures; high-resolution orthophotos in .ecw format; MicroStation design files and PTC settings; large vegetation feature files in .xyz format; and other files from active projects.
US news
fromDataBreaches.Net
3 weeks ago
Privacy professionals

Attorney General James Secures $500,000 from Capital Region Health Care Provider for Failing to Protect Patients' Information - DataBreaches.Net

OrthopedicsNY paid $500,000 in penalties after a cyberattack exposed sensitive data of about 656,000 patients and employees due to inadequate security.
Law
fromDataBreaches.Net
4 weeks ago

Software company lacked 'downstream' liability for data breach - DataBreaches.Net

Barracuda cannot be held downstreamly liable for Zoll's data-breach-related class-action settlement; equitable indemnification failed without a derivative or vicarious relationship.
EU data protection
fromDataBreaches.Net
4 weeks ago

French software company fined $2 million for cyber failings leading to data breach - DataBreaches.Net

Nexpublica France was fined €1.7 million by CNIL for inadequate cybersecurity after a portal exposed third-party documents and sensitive data.
Information security
fromTechzine Global
4 weeks ago

Dataset containing data from Wired circulating on hacker forums

Claimed theft of over 2.36 million Wired subscription records and additional Condé Nast publication data was offered on hacker forums and appears authentic.
Information security
fromWIRED
4 weeks ago

The Worst Hacks of 2025

Breaches exploited third-party Salesforce integrations and exposed millions of records, driven by consolidated threat actors like Scattered Lapsus$ Hunters.
Video games
fromGadgets 360
4 weeks ago

Rainbow Six Siege Servers Still Down as Ubisoft Performs Rollback

Ubisoft is rolling back player data after a large-scale breach in Rainbow Six Siege but provides no timeline for full server restoration.
Video games
fromThe Verge
4 weeks ago

Ubisoft shuts down 'Rainbow Six Siege' servers following hack

Hackers gained control of Rainbow Six Siege systems, granted players 2 billion R6 Credits, and Ubisoft shut down servers and marketplace while addressing the breach.
Information security
fromDataBreaches.Net
4 weeks ago

Coinbase Discloses Arrest Of Former Customer Agent Over Data Breach - Report - DataBreaches.Net

A former Coinbase customer service contractor was arrested in India after hackers bribed representatives or contractors to access customer data, prompting layoffs and disclosure criticism.
Information security
fromTheregister
1 month ago

21K Nissan customers' data stolen in Red Hat raid

About 21,000 Nissan customers had personal data exposed after unauthorized access to a Red Hat-managed server, including names, addresses, phone numbers, and partial emails.
fromTechCrunch
1 month ago

US insurance giant Aflac says hackers stole personal and health data of 22.6 million | TechCrunch

On Tuesday, the company confirmed it has begun notifying around 22.65 million whose data was stolen during the cyberattack. In a filing with the Texas attorney general, Aflac said that the stolen data includes customer names, dates of birth, home addresses; government-issued ID numbers (such as passports and state ID cards) and driver's license numbers, and Social Security numbers; as well as medical and health insurance information.
Information security
Music
fromTechRepublic
1 month ago

SoundCloud Cyberattack Leaves 28M Users Exposed - TechRepublic

Cybercriminals breached SoundCloud's ancillary dashboard, accessing data from about 28 million accounts, exposing emails and public profile details enabling phishing risks.
Privacy professionals
fromTechzine Global
1 month ago

Data of 21,000 Nissan customers leaked via Red Hat

Nissan customer data for about 21,000 people was exposed due to a Red Hat breach, revealing names, addresses, phones, and emails; no financial data exposed.
Privacy professionals
fromBloomberglaw
1 month ago

Horizontal Integration Evades Worker's Lawsuit Over Data Breach

A former Horizontal Integration employee lacked legal standing to sue after failing to allege that his personal information was compromised in the July 2024 data breach.
France news
fromwww.theguardian.com
1 month ago

France's national post office hit by suspected cyberattack

France's national post office and its banking service suffered a DDoS attack that disrupted online services, deliveries, and banking access ahead of Christmas.
Information security
fromTheregister
1 month ago

South Korea to require face scans to buy a SIM

South Korea will require facial-recognition verification for new mobile subscribers to prevent account registration with stolen data and reduce phone-based scams.
Information security
fromWIRED
1 month ago

Hackers Stole Millions of PornHub Users' Data for Extortion

US border and law-enforcement agencies are expanding surveillance capabilities while AI tools enable sophisticated scams and a major breach exposed PornHub user data.
fromwww.theguardian.com
1 month ago

The Com: the growing cybercrime network behind recent Pornhub hack

Ransomware hacks, data theft, crypto scams and sextortion cover a broad range of cybercrimes carried out by an equally varied list of assailants. But there is also an English-speaking criminal ecosystem carrying out these activities that defies conventional categorisation. Nonetheless, it does have a name: the Com. Short for community, the Com is a loose affiliation of cyber-criminals, largely native English language speakers typically aged from 16 to 25.
Information security
Information security
fromSecuritymagazine
1 month ago

630M Passwords Stolen, FBI Reveals: What This Says About Credential Value

A seized dataset of 630 million stolen credentials added to Have I Been Pwned included 46 million previously unseen vulnerable passwords, highlighting persistent credential risk.
#pornhub
#mixpanel
fromTechCrunch
1 month ago
Information security

Hacking group says it's extorting Pornhub after stealing users' viewing data | TechCrunch

fromTechCrunch
1 month ago
Information security

Hacking group says it's extorting Pornhub after stealing users' viewing data | TechCrunch

[ Load more ]