#data-breach

[ follow ]
Information security
fromThe Hacker News
13 hours ago

FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials

Law enforcement dismantled LeakBase, a major cybercriminal forum with 142,000 members that traded stolen data and hacking tools, seizing all content and accounts for evidence.
#cybercrime
fromDataBreaches.Net
1 day ago
EU data protection

LeakBase seized, arrests made as part of global action - DataBreaches.Net

LeakBase, a major cybercrime forum for trading stolen data and credentials, was dismantled through coordinated international law enforcement operations resulting in approximately 100 enforcement actions and arrests of key users.
fromSecurityWeek
1 week ago
Information security

Romanian Hacker Pleads Guilty to Selling Access to US State Network

Catalin Dragomir pleaded guilty to selling unauthorized access to Oregon's emergency management network, stealing personal data, agreeing to restitution, and facing prison and fines.
EU data protection
fromDataBreaches.Net
1 day ago

LeakBase seized, arrests made as part of global action - DataBreaches.Net

LeakBase, a major cybercrime forum for trading stolen data and credentials, was dismantled through coordinated international law enforcement operations resulting in approximately 100 enforcement actions and arrests of key users.
#cybersecurity
Privacy technologies
fromTheregister
6 days ago

French DIY etailer ManoMano admits customer data stolen

ManoMano customers' personal data was compromised through a cyberattack on a customer support subcontractor in January 2026, with criminals claiming the breach affected 37.8 million accounts across multiple European countries.
Information security
fromMail Online
1 week ago

'Largest breach in US history' exposes records of 26 MILLION Americans

A massive breach at Conduent exposed personal data for at least 26 million Americans, with millions in Texas and Oregon most severely affected, including addresses, Social Security numbers, and health information.
Privacy professionals
fromSecurityWeek
1 day ago

New LexisNexis Data Breach Confirmed After Hackers Leak Files

LexisNexis confirmed a data breach involving legacy data from before 2020, with hackers exfiltrating over 2GB of data through React2Shell vulnerability exploitation and improperly secured AWS instances.
Privacy professionals
fromTheregister
1 day ago

LexisNexis Legal & Professional confirms data breach

LexisNexis Legal & Professional division experienced a data breach affecting legacy servers, with Fulcrumsec claiming responsibility for exploiting a vulnerable React container to access approximately 2 GB of data.
Privacy professionals
fromTheregister
2 days ago

Brit games studio Cloud Imperium admits to data breach

Cloud Imperium Games delayed disclosure of a January 21st data breach affecting user personal data, announcing it only through a subtle popup without proactive communication to affected users.
Healthcare
fromSecuritymagazine
2 days ago

1M Impacted by University of Hawaii Cancer Center Breach

University of Hawaiʻi Cancer Center experienced a data breach exposing approximately 1.15 million individuals' Social Security numbers, driver's license numbers, and voter registration records from epidemiological studies spanning decades.
#ransomware-attack
fromTheregister
6 days ago
Information security

Dutch cops back Odido as ShinyHunters leaks continue

Dutch police support Odido's refusal to pay ransom after ShinyHunters leaked 1 million customer records for the second consecutive day, with plans for escalating daily leaks.
fromSecurityWeek
1 week ago
Information security

Medical Device Maker UFP Technologies Hit by Cyberattack

UFP Technologies detected a cybersecurity intrusion on February 14 involving file theft and IT system disruption, with operations continuing despite impacts to billing and delivery label systems.
Privacy professionals
fromSecurityWeek
2 days ago

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on University of Hawaiʻi Cancer Center compromised personal information of approximately 1.2 million people, including names, Social Security numbers, and driver's license details, though clinical operations and patient care remained unaffected.
#healthcare-security
Privacy professionals
fromDataBreaches.Net
2 days ago

Evoke Wellness at Hilliard updates its breach notification - DataBreaches.Net

An Ohio addiction treatment center discovered unauthorized patient data access by a former employee in October 2024, but delayed notifying affected individuals until August 2025, with inconsistent breach discovery dates in official notifications.
Privacy professionals
fromSecurityWeek
3 days ago

Madison Square Garden Data Breach Confirmed Months After Hacker Attack

Madison Square Garden confirmed a data breach from the Cl0p ransomware group's exploitation of Oracle EBS zero-day vulnerabilities, compromising personal information including names and Social Security numbers.
#ransomware
fromwww.housingwire.com
3 weeks ago
Privacy professionals

Anywhere Real Estate data breach exposes employee information

Anywhere Real Estate suffered a ransomware-caused breach of its Oracle EBS, exposing personal data of 17,429 individuals, including Social Security numbers.
fromSecurityWeek
3 weeks ago
Information security

Conduent Breach Hits Volvo Group: Nearly 17,000 Employees' Data Exposed

Conduent's breach exposed personal and medical data of tens of millions, including nearly 17,000 Volvo Group employees, with impact estimates rising significantly.
Privacy professionals
fromTechzine Global
3 days ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Privacy technologies
fromDataBreaches.Net
5 days ago

Leaked Odido data exposes sensitive information - DataBreaches.Net

Dutch news outlets freely reported on the Odido telecom breach affecting 6.2 million customers, exposing sensitive data including stalking victims' information and protected addresses without censorship.
#telecommunications
fromTechCrunch
2 weeks ago
EU data protection

Dutch phone giant Odido says millions of customers affected by data breach | TechCrunch

fromTechCrunch
2 weeks ago
EU data protection

Dutch phone giant Odido says millions of customers affected by data breach | TechCrunch

fromTheregister
6 days ago

AI-built app on Lovable exposed 18K users, researcher claims

The main issue, Khan said, was that all apps that are vibe-coded on Lovable's platform are shipped with their backends powered by Supabase, which handles authentication, file storage, and real-time updates through a PostgreSQL database connection. However, when the developer - in this case AI - or the human project owner fails to explicitly implement crucial security features like Supabase's row-level security and role-based access, code will be generated that looks functional but in reality is flawed.
Artificial intelligence
#ai-security
fromJezebel
6 days ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

fromJezebel
6 days ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Information security
fromSecurityWeek
6 days ago

38 Million Allegedly Impacted by ManoMano Data Breach

A data breach at European DIY retailer ManoMano compromised approximately 38 million customers' personal information through a compromised customer service subcontractor.
#cyberattack
fromDataBreaches.Net
1 week ago
Information security

Clalit probes suspected cyberattack after Iranian-linked hackers leak patient files - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Clalit probes suspected cyberattack after Iranian-linked hackers leak patient files - DataBreaches.Net

#shinyhunters
fromTechCrunch
4 weeks ago
Information security

Hackers publish personal information stolen during Harvard, UPenn data breaches | TechCrunch

fromTechCrunch
4 weeks ago
Information security

Hackers publish personal information stolen during Harvard, UPenn data breaches | TechCrunch

Information security
fromDataBreaches.Net
1 week ago

Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site - DataBreaches.Net

Wynn Resorts' data listing was removed from ShinyHunters leak site after the company reportedly paid an extortion demand, with the resort confirming deletion of stolen employee data.
fromTheregister
1 week ago

Wynn Resorts confirms data stolen after ShinyHunters threats

Trusting cybercriminals is inherently flawed; there is no honour among thieves. There is absolutely no reliable way to verify that an extortionist has permanently deleted stolen data. Copies are frequently retained, shared, or sold months down the line.
Information security
fromSecurityWeek
1 week ago

Ad Tech Company Optimizely Targeted in Cyberattack

The threat actor gained access to Optimizely's systems through a sophisticated voice-phishing attack, but was unable to escalate privileges, install software, or create any backdoors in the Optimizely environment. The incident was confined to certain internal business systems including Zendesk, records in our Salesforce CRM, and a limited set of internal documents used for back-office operations.
Information security
#paypal
#ivanti-epmm
fromDataBreaches.Net
1 week ago

The hospitality sector continues to be lucrative targets - DataBreaches.Net

Choice Hotels International disclosed a breach affecting franchisees and applicants. Its notification letter states that a "skilled person used social engineering" to gain access on January 14, 2026 to an application that contained records regarding franchisees and franchise applicants. The access occurred even though access required multifactor authentication (MFA). The information involved included names and Social Security numbers. There is no indication that any guest data was involved. No gang has publicly claimed responsibility for the attack as yet.
Information security
fromTheregister
1 week ago

Cornwall council mishandles complaints in data breach case

A UK councillor has dubbed her local authority's data breach "crazy" after the personal details of individuals behind a series of complaints were revealed to her. Dulcie Tudor, an independent councillor for the Threemilestone and Chacewater area in Cornwall, England, publicized the data protection gaffe via social media following complaints about comments she made during a November council meeting. Cllr Tudor received ten complaints after asking fellow councillor Leigh Knight whether a trans woman was a real woman.
Privacy professionals
fromTechzine Global
1 week ago

PayPal leaked sensitive data for six months due to software error

PayPal is warning customers about a data breach that leaked personal data for six months. The leaked data includes social security numbers. The software error occurred in the PayPal Working Capital application, an app that allows small businesses to easily take out a business loan. The leak occurred between July 1, 2025, and December 13, 2025. In addition to names and email addresses, phone numbers, business addresses, social security numbers, and dates of birth were also compromised.
Information security
#ficoba
fromDataBreaches.Net
1 week ago
Information security

A single compromised account gave hackers access to 1.2 million French banking records - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

A single compromised account gave hackers access to 1.2 million French banking records - DataBreaches.Net

fromDataBreaches.Net
1 week ago

San Jose slow to tell workers about data breach - DataBreaches.Net

San Jose administrators have disclosed that private information for current and former city employees may have been compromised, following a data breach last month. The incident occurred on Jan. 9 when a "workforce member" lost a USB drive that may have contained Social Security numbers, according to a letter city officials sent to people whose data may have been involved in the breach. San José officials have not said how many people were affected by the breach.
Information security
fromTheregister
1 week ago

ICO wins battle in fight to fine tech retailer 500k

The Information Commissioner's Office (ICO) originally fined DSG Retail £500,000 ($673,000) in 2020, the maximum financial penalty allowed under the Data Protection Act 1998 (DPA 1998) - the relevant legislation at the pre-GDPR time. Its monetary penalty notice (MPN) was upheld by the Court of Appeal's first-tier tribunal but later reversed by the upper tribunal [PDF], which sided with DSG Retail and, if that decision was final, would have effectively nullified the ICO's fine.
EU data protection
fromSan Jose Spotlight
1 week ago

San Jose slow to tell workers about data breach - San Jose Spotlight

when a "workforce member" lost a USB drive that may have contained Social Security numbers, according to a letter city officials sent to people whose data may have been involved in the breach. San José Spotlight spoke with three people who said they received the city's letter in recent days, including a current employee and two former employees. One of the former employees said they last worked for the city in 2000. The individuals requested anonymity to protect their privacy.
Privacy professionals
Public health
fromDataBreaches.Net
2 weeks ago

Privacy breaches following the Lapu Lapu Day Festival - DataBreaches.Net

Employees intentionally accessed patients' medical records after the Lapu Lapu Day tragedy, causing widespread privacy breaches and undermining trust in health care.
#social-engineering
Privacy professionals
fromTechCrunch
2 weeks ago

Sex toys maker Tenga says hacker stole customer information | TechCrunch

Tenga experienced an email account breach exposing approximately 600 U.S. customers' names, emails, and possibly order or customer service details.
Information security
fromSecurityWeek
2 weeks ago

Nearly 1 Million User Records Compromised in Figure Data Breach

Nearly one million Figure Technology Solutions user records, including names, birth dates, emails, addresses, and phone numbers, were exposed after a social engineering attack.
fromDataBreaches.Net
2 weeks ago

Leaked Data Raises Questions About Hackers' Claims and Moldova's Prior Denial - DataBreaches.Net

The Compensatii platform enables residents to register and apply for compensation for energy bills, including heating, natural gas, and electricity, during the colder months. To register, applicants need to provide: The name, surname, and IDNP of all persons residing in the declared household; Data from energy consumption invoices; Mortgage loan amount and cadastral number (if applicable); The monthly income of each member for the months of April-September; Personal IBAN account for transferring the compensation.
fromThe Local France
2 weeks ago

Hacker accesses info on 1.2 mn French bank accounts

Since the end of January, the hacker used the stolen credentials of an official to access and consult "parts of the file of all of the accounts open in French banks and which contains personal data such as bank account numbers, name of the account holder, address and in certain cases the account owner's tax number," the ministry said in a statement.
France news
fromTheregister
2 weeks ago

Adidas investigates third-party data breach

Allegations of an incident at Adidas emerged on February 16, when someone claiming to be the Lapsus$ Group posted on BreachForums (screenshot shared here on Daily Dark Web) that they compromised the sportswear giant's extranet. According to the crooks, the stolen files - 815,000 rows of information - allegedly include: first and last names, email addresses, passwords, birthdays, company names, and "a lot of technical data."
Information security
Information security
fromTheregister
2 weeks ago

ShinyHunters allegedly drove off with 1.7M CarGurus records

ShinyHunters claims to have stolen 1.7 million CarGurus corporate records and posted them, threatening further leaks and extortion by 20 Feb 2026.
Information security
fromTechCrunch
2 weeks ago

Data breach at fintech giant Figure affects close to a million customers | TechCrunch

A Figure data breach exposed personal information for about 967,200 customers, including names, dates of birth, addresses, phone numbers, and email addresses.
#substack
fromTechCrunch
4 weeks ago
Information security

Substack confirms data breach affecting users' email addresses and phone numbers | TechCrunch

fromTechCrunch
4 weeks ago
Information security

Substack confirms data breach affecting users' email addresses and phone numbers | TechCrunch

World news
fromSecuritymagazine
2 weeks ago

Global Leaders, Executives Exposed in Data Leak

Unprotected cloud storage linked to Abu Dhabi Finance Week exposed scans of over 700 passports and state ID cards, including documents of high-profile individuals.
fromSecuritymagazine
2 weeks ago

Conduent Data Breach: Overview and What to Know

Conduent experienced a data incident on that is proving to have widespread repercussions. The business services provider offers a range of support for organizations, including printing/mailroom services, payment integrity, document processing, and back-office aid, so this attack on its network affected more entities than itself. On Jan. 13, 2025, Conduent found a cyber incident had affected part of its network. Upon this discovery, the organization secured networks and commenced an investigation alongside third-party forensic experts.
Information security
#discord
fromZDNET
3 weeks ago
Privacy professionals

My 5 favorite Discord alternatives - no ID verification required

fromZDNET
3 weeks ago
Information security

Discord's age verification lockdown: What to know, and alternatives users are considering

fromZDNET
3 weeks ago
Privacy professionals

My 5 favorite Discord alternatives - no ID verification required

fromZDNET
3 weeks ago
Information security

Discord's age verification lockdown: What to know, and alternatives users are considering

Information security
fromArs Technica
2 weeks ago

Password managers' promise that they can't see your vaults isn't always true

Password manager “zero knowledge” assurances can be bypassed by account recovery, sharing, or group features, allowing server compromises to expose user vaults.
#eurail
fromTheregister
2 weeks ago

Dutch cops arrest man after sending him confidential files

The chain of events reads less like a breach and more like an own goal. In connection with a separate investigation, the man contacted the police on February 12 to report he had images that might be relevant. An officer responded by sending him a link so he could upload the files - except the link sent was a download link, effectively giving him access to confidential police documents.
Miscellaneous
#lvmh
fromDataBreaches.Net
2 weeks ago
Privacy professionals

Korea's Personal Information Protection Commissioner fines 3 LVMH luxury brands after Salesforce data breaches - DataBreaches.Net

fromDataBreaches.Net
2 weeks ago
Privacy professionals

Korea's Personal Information Protection Commissioner fines 3 LVMH luxury brands after Salesforce data breaches - DataBreaches.Net

fromDataBreaches.Net
2 weeks ago

He tried to extort the Dutch police. It didn't work out well for him. - DataBreaches.Net

He wanted something in return for returning files to the Dutch police. What he got in return was an arrest. A press release from Dutch police sums it up: On Thursday evening around 7:00 PM, police arrested a 40-year-old man from Ridderkerk on Prinses Beatrixstraat in Ridderkerk for computer hacking. Due to a police error, the man had inadvertently gained access to confidential police documents.
Privacy technologies
EU data protection
fromTechzine Global
2 weeks ago

Data breach at Odido: responsibility and compensation under discussion

Odido reported a data breach affecting an estimated 6.2 million customers; the company says compensation is not automatic while it assesses causes and harm.
Information security
fromwww.theguardian.com
2 weeks ago

Brushing fraud: Britons told to beware of mystery parcels as new scam soars

Unexpected cheap parcels can be part of brushing fraud where criminals use stolen delivery details to post fake verified reviews and boost their online credibility.
Privacy professionals
fromDataBreaches.Net
2 weeks ago

Dutch phone giant Odido says millions of customers affected by data breach - DataBreaches.Net

Odido suffered a breach exposing over 6.2 million customers' personal and financial data, including government ID details and IBANs.
US politics
fromDataBreaches.Net
2 weeks ago

Attorney General Ken Paxton Demands Information from Blue Cross Blue Shield of Texas and Conduent as Part of Investigation into Largest Data Breach in U.S. History - DataBreaches.Net

Texas Attorney General Ken Paxton issued Civil Investigative Demands to BCBS and Conduent over a Conduent breach exposing about four million Texans' personal health data.
Information security
fromDataBreaches.Net
2 weeks ago

South Korea blames Coupang data breach on management failure, not sophisticated attack - DataBreaches.Net

Coupang's massive data leak resulted from management failure and lax authentication oversight, with a former engineer exploiting vulnerabilities to access and leak user data.
Information security
fromSecurityWeek
2 weeks ago

Dutch Carrier Odido Discloses Data Breach Impacting 6 Million

Odido data breach exposed names, contact details, dates of birth, customer and bank account numbers, and passport/driver's license information for about 6.2 million customers.
E-Commerce
fromTechCrunch
3 weeks ago

More U.S. investors sue South Korean government over handling of Coupang data breach | TechCrunch

U.S. investors are pursuing ISDS arbitration under the Korea-U.S. FTA after Coupang's massive data breach and alleged discriminatory treatment by South Korean authorities.
Information security
fromZDNET
3 weeks ago

Can you trust LastPass in 2026? Inside the multimillion-dollar quest to rebuild its security culture

LastPass used the 2022 data breach as a catalyst to substantially strengthen security controls and prioritize consumer security beyond typical program standards.
fromBusiness Matters
3 weeks ago

NCSC reveals Budget forecasts accessed almost 25,000 times before publication

A report by the National Cyber Security Centre found that documents prepared by the Office for Budget Responsibility were downloaded on "at least" 24,701 occasions in the hour before Rachel Reeves delivered her Budget speech on 26 November. The figure is far higher than the 43 downloads cited in an initial internal review. The NCSC said the first full download of the OBR's forecasts occurred shortly after 11.35am on Budget day,
UK politics
Information security
fromTheregister
3 weeks ago

Discord puts everyone in teen mode by default

Discord will default all users to teen settings, requiring ID, video selfie, or automated age inference to restore adult access despite prior ID-data breach.
Information security
fromTechCrunch
3 weeks ago

Exclusive: Hacktivist scrapes over 500,000 stalkerware customers' payment records

More than 536,000 customer payment records from Struktura's stalkerware services were scraped, exposing emails, partial card details, and purchased surveillance app subscriptions.
fromBusiness Matters
3 weeks ago

High Court clears way for thousands to pursue Capita data breach claims

A High Court judge has ruled that thousands of people affected by a major data breach at Capita can continue with their legal action against the outsourcing group, in a decision being described as a landmark for large-scale data privacy claims in the UK. In a judgment handed down on 9 February, Master Dagnall rejected arguments from Capita's legal team that solicitors acting for more than 8,000 claimants had abused the court process.
EU data protection
Information security
fromSecurityWeek
3 weeks ago

Flickr Security Incident Tied to Third-Party Email System

Flickr experienced a third-party email service vulnerability that may have exposed users' names, email addresses, usernames, account types, IP addresses, locations, and activity data.
fromTheregister
4 weeks ago

Betterment breach scope pegged at 1.4M users

Betterment, which offers automated investment and financial planning services, first disclosed the breach in January after detecting unauthorized access to certain internal systems on January 9. Betterment said the hacker gained entry through a social engineering scheme that relied on impersonation to infiltrate third-party marketing and operations tools, then used that access to send customers a fraudulent cryptocurrency promotion disguised as an official company message.
Information security
Information security
fromTechCrunch
4 weeks ago

Data breach at govtech giant Conduent balloons, affecting millions more Americans | TechCrunch

A January 2025 ransomware attack on Conduent may have exposed personal data of potentially tens of millions of US residents across multiple states.
Canada news
fromwww.cbc.ca
4 weeks ago

Nearly 1,300 customers affected by Canada Computers data breach, company says | CBC News

Canada Computers experienced a retail website data breach affecting 1,284 customers and sent inconsistent notifications, causing customer frustration and credit card cancellations.
[ Load more ]