#data-breach

[ follow ]
fromFast Company
52 minutes ago

Moltbook, the viral social network for AI agents, has a major security problem

The rise of OpenClaw, a proactive agentic AI controlled through interfaces more familiar to the average user than tools like Anthropic's Claude Code, which enthralled early adopters over the holiday period, has been one of the most seismic shifts in the AI world since the release of ChatGPT. By piggybacking on user-friendly interfaces paired with powerful AI agent technology, OpenClaw has pushed AI further into the public eye.
Information security
fromAxios
4 hours ago

Exclusive: Sen. Maggie Hassan presses AI toy company on child data privacy

Catch up quick: Researchers reported last month that bondu, an AI-powered conversational toy company, inadvertently exposed children's chat transcripts and personal data through a publicly accessible portal. Bondu, which allows parents to check their children's conversations, said it took down the exposed portal and relaunched it the next day with authentication measures, according to Wired. Driving the news: New Hampshire Senator Maggie Hassan, the ranking member of the Senate's Joint Economic Committee, is now asking bondu to explain how the exposure occurred.
Privacy technologies
Information security
fromSecurityWeek
4 hours ago

Hackers Leak 5.1 Million Panera Bread Records

A ShinyHunters vishing-based SSO compromise exposed contact details for about 5.1 million Panera customers and claims a 14 million-record theft.
#moltbook
fromEngadget
17 hours ago
Artificial intelligence

Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw

fromFortune
21 hours ago
Information security

Top AI leaders are begging people not to use Moltbook, the AI agent social media: 'disaster waiting to happen' | Fortune

fromEngadget
17 hours ago
Artificial intelligence

Moltbook, the AI social network, exposed human credentials due to vibe-coded security flaw

fromFortune
21 hours ago
Information security

Top AI leaders are begging people not to use Moltbook, the AI agent social media: 'disaster waiting to happen' | Fortune

#cybersecurity
fromDataBreaches.Net
1 week ago
Information security

NL: Police warned about security hole used by Russian hackers in major theft of police data - DataBreaches.Net

fromTheregister
3 weeks ago
Information security

European Space Agency initiates criminal probe into breach

The European Space Agency suffered a major cyber breach exposing 500 GB of sensitive mission, operational, and contractor data, with attackers claiming continued access.
fromTheregister
1 month ago
Information security

European Space Agency hit again as crims claim 200 GB haul

European Space Agency suffered a breach of external servers, with alleged theft of source code, credentials, confidential documents, and over 200 GB of data.
fromDataBreaches.Net
1 week ago
Information security

NL: Police warned about security hole used by Russian hackers in major theft of police data - DataBreaches.Net

#ransomware
fromdatabreaches.net
1 day ago
Information security

Ransomware attack compromised 377,000 people's Social Security and driver's license numbers from Texas gas station and convenience store chain

fromZDNET
1 month ago
Information security

Massive Aflac breach exposed millions of SSNs and other data - get free protection today

fromdatabreaches.net
1 day ago
Information security

Ransomware attack compromised 377,000 people's Social Security and driver's license numbers from Texas gas station and convenience store chain

fromZDNET
1 month ago
Information security

Massive Aflac breach exposed millions of SSNs and other data - get free protection today

#comcast
fromDataBreaches.Net
2 days ago
Privacy professionals

Comcast agrees to $117.5 million settlement to resolve lawsuits over 2023 Citrix Bleed data breach - DataBreaches.Net

fromDataBreaches.Net
2 days ago
Privacy professionals

Comcast agrees to $117.5 million settlement to resolve lawsuits over 2023 Citrix Bleed data breach - DataBreaches.Net

Information security
fromDataBreaches.Net
2 days ago

RINA Accountants & Advisors is creating $400K settlement fund to settle lawsuit over 2022 data breach - DataBreaches.Net

RINA Accountants & Advisors will pay $400,000 to settle a 2022 cyberattack that exposed thousands' personally identifiable records, including Social Security Numbers.
Privacy professionals
fromDataBreaches.Net
3 days ago

BD: 14,000 journos' personal data leaked online - DataBreaches.Net

A technical failure on the Bangladesh Election Commission portal exposed sensitive personal data of about 14,000 journalists, including NID numbers and contact details.
#healthcare
fromDataBreaches.Net
4 days ago
Privacy professionals

Investigation into data breach involving Blue Cross Blue Shield members could head to court - DataBreaches.Net

fromDataBreaches.Net
4 days ago
Privacy professionals

Investigation into data breach involving Blue Cross Blue Shield members could head to court - DataBreaches.Net

#sk-telecom
fromDataBreaches.Net
4 days ago
Information security

SK Telecom rejects consumer agency's compensation settlement over personal data leak - DataBreaches.Net

fromDataBreaches.Net
4 days ago
Information security

SK Telecom rejects consumer agency's compensation settlement over personal data leak - DataBreaches.Net

fromwww.cbc.ca
4 days ago

Data breach at Canada Computers & Electronics leaks personal customer information | CBC News

The company became aware of the breach which included personal information of its website customers "including credit card information" on Friday, it told CBC News in a statement. Canada Computers & Electronics said the affected customers were informed on Monday, given recommendations about steps to take, and that the breach was reported to authorities. But neither the statement, nor the notices seen by CBC News that went out to customers, says when the breach happened, how long it lasted or how many customers were affected.
Information security
Information security
fromTheregister
5 days ago

ShinyHunters claims it stole10M records from dating apps

ShinyHunters claims to have stolen over 10 million records from Match Group affecting Hinge, Match.com, and OkCupid, potentially via AppsFlyer.
Information security
fromTechRepublic
5 days ago

ShinyHunters Claims 14M Panera Bread Records Exposed in Data Breach - TechRepublic

ShinyHunters claims it stole roughly 14 million Panera Bread customer records via a Microsoft Entra single sign-on compromise, enabling phishing, identity fraud, and account takeover risks.
#telehealth
fromDataBreaches.Net
1 week ago
Privacy professionals

Call-On-Doc allegedly had a breach affecting more than 1 million patients. They've yet to comment. - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Call-On-Doc allegedly had a breach affecting more than 1 million patients. They've yet to comment. - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Privacy professionals

Call-On-Doc allegedly had a breach affecting more than 1 million patients. They've yet to comment. - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Call-On-Doc allegedly had a breach affecting more than 1 million patients. They've yet to comment. - DataBreaches.Net

Information security
fromDataBreaches.Net
1 week ago

France's Waltio faces ransom threat from notorious hacker collective - DataBreaches.Net

Waltio faces a ShinyHunters ransom threat claiming nearly 50,000 users' data and threatening to leak 2024 tax reports, while core systems remain secure.
#fourth-amendment
fromTechzine Global
6 days ago

Nearly 30 million SoundCloud accounts affected by data breach

A data breach at SoundCloud that came to light in December 2025 is now becoming clearer. The data breach monitor Have I Been Pwned added the leaked dataset to its database this week, revealing the true extent of the impact. SoundCloud is a global audio platform where artists and listeners come together and where hundreds of millions of music and audio tracks are hosted.
Information security
#shinyhunters
fromDataBreaches.Net
1 week ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

ShinyHunters group opens new dark web leak site, claims responsibility for OKTA vishing campaign - DataBreaches.Net

#coupang
fromDataBreaches.Net
2 weeks ago
Privacy professionals

Data protection agency tells Coupang to stop publishing unconfirmed information about data breach - DataBreaches.Net

fromDataBreaches.Net
1 month ago
E-Commerce

South Korean retail giant Coupang to compensate $1.1 billion to affected users over data breach - DataBreaches.Net

fromDataBreaches.Net
2 weeks ago
Privacy professionals

Data protection agency tells Coupang to stop publishing unconfirmed information about data breach - DataBreaches.Net

fromDataBreaches.Net
1 month ago
E-Commerce

South Korean retail giant Coupang to compensate $1.1 billion to affected users over data breach - DataBreaches.Net

US politics
fromDataBreaches.Net
1 week ago

Treasury cancels $21 million in Booz Allen contracts, blaming a breach that happened years ago - DataBreaches.Net

The Treasury Department canceled $21 million in Booz Allen contracts after a former Booz employee stole tax return data, prompting accusations of inadequate safeguards.
#extortion
Information security
fromSecurityWeek
1 week ago

Nike Probing Potential Security Incident as Hackers Threaten to Leak Data

Nike is investigating a potential cybersecurity incident after WorldLeaks listed Nike as a victim and threatened to publish alleged stolen data unless paid.
#okta
Information security
fromTechzine Global
1 week ago

149 million login details leaked via unsecured database

A publicly accessible database exposed 149 million usernames and passwords across email, social, financial, government, and streaming services, likely harvested by infostealer malware.
Information security
fromWIRED
1 week ago

149 Million Usernames and Passwords Exposed by Unsecured Database

A publicly exposed database of 149 million account credentials—including 48M Gmail, 17M Facebook, and others—was hosted and then taken down for violating host terms.
US politics
fromwww.npr.org
1 week ago

Trump administration admits even more ways DOGE accessed sensitive personal data

DOGE staff improperly accessed and shared sensitive Social Security and personal data on millions; extent, uses, and unauthorized political connections remain unclear.
#under-armour
fromTechCrunch
1 week ago
Information security

Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch

fromTechCrunch
1 week ago
Information security

Under Armour says it's 'aware' of data breach claims after 72M customer records were posted online | TechCrunch

Privacy professionals
fromSecuritymagazine
1 week ago

Two Unique DHS Cyber Incidents Exposed 1M People's Data

Two state DHS data incidents exposed sensitive resident information through misconfigured maps and unauthorized system access, impacting roughly 700,000 Illinois residents and Minnesota users.
Information security
fromTechCrunch
1 week ago

Exclusive: UStrive security lapse exposed personal data of its users, including children

UStrive experienced a security lapse that exposed personal data of users, including children, via a vulnerable GraphQL endpoint accessible to logged-in users.
Privacy professionals
fromSecuritymagazine
2 weeks ago

Lawsuit Filed After 320,000 Impacted by Monroe University Breach

Monroe University experienced a Dec. 9–23, 2024 data breach exposing sensitive personal and health information, prompting delayed notices and a class-action lawsuit.
Privacy professionals
fromDataBreaches.Net
2 weeks ago

UK: North West Ambulance Service's increased breach reports may reflect better reporting - DataBreaches.Net

North West Ambulance Service recorded almost 400 data breaches in three years, with rising incidents driven by confidentiality failures and increased reporting.
Information security
fromDataBreaches.Net
2 weeks ago

4 in 5 small businesses had cyberscams last year, almost half were AI powered - DataBreaches.Net

Cybercrime causes small businesses to raise prices; AI increasingly enables attacks, and many small businesses suffer repeated breaches within a year.
Privacy professionals
fromDataBreaches.Net
2 weeks ago

Japanese nuclear regulator employee loses phone containing sensitive info in China - DataBreaches.Net

A Nuclear Regulation Authority employee lost a work smartphone in China containing confidential nuclear security staff names and contacts, risking a potential information leak.
Privacy professionals
fromDataBreaches.Net
2 weeks ago

A faceless hacker stole my therapy notes - now my deepest secrets are online forever - DataBreaches.Net

The theft of 33,000 Vastaamo psychotherapy records exposed victims to extortion, public disclosure of sensitive therapy details, and enduring psychological and privacy harm.
Information security
fromSecuritymagazine
2 weeks ago

Grubhub Data Stolen in Confirmed Hack, Questions Remain

Grubhub confirmed unauthorized data downloads from certain systems, stopped the activity, and said sensitive financial and order history information was not affected.
Information security
fromwww.housingwire.com
2 weeks ago

Judge consolidates SitusAMC class actions after 2025 data breach

SitusAMC experienced a Nov. 12, 2025 data incident compromising accounting records, client agreements, and possibly client-customer data; a lead lawsuit alleges negligent data protection.
US news
fromSecuritymagazine
2 weeks ago

This Website Exposed ICE Data - Now, It's Faced a Cyberattack

A publicly accessible ICE List database exposes PII for roughly 4,500 federal ICE agents and supervisors and recently suffered a DDoS attack reportedly originating from Russia.
Privacy professionals
fromFast Company
2 weeks ago

Remember that viral Tea app? The controversial 'dating safety' platform is back, this time on the web

A popular dating-safety app aimed at protecting women suffered major data breaches, legal challenges, and App Store removal but returns via a website relaunch.
UK news
fromTheregister
2 weeks ago

Woman bailed as cops probe doctor's surgery data breach

A 29-year-old non-surgery staff member was arrested and bailed in connection with an alleged data breach and theft at Croft Surgery.
Information security
fromTechzine Global
2 weeks ago

Five Belgian hospitals affected by data breach

Third-party software supplier breaches exposed 71,000 patient and provider records, highlighting supplier risk and inadequate third-party monitoring in Belgian healthcare.
EU data protection
fromTheregister
2 weeks ago

France fines telcos 42M for issues leading to 2024 breach

Free and Free Mobile were fined €42 million by CNIL for a breach exposing over 24 million customers' personal and financial data.
fromDataBreaches.Net
2 weeks ago

Victorian Department of Education says hackers stole students' data - DataBreaches.Net

The Department of Education in Victoria, Australia, notified parents that attackers accessed a database containing the personal information and email addresses of current and former students, prompting password resets. The department disclosed the breach in letters sent to parents, stating that an unauthorized third party accessed students' names, school names, year levels, and school-issued email addresses, as well as encrypted passwords for accounts that use them.
Education
fromDataBreaches.Net
2 weeks ago

Eurail passengers taken for a ride as data breach spills passports, bank details - DataBreaches.Net

Eurail B.V. has unfortunately experienced a security breach within our systems that resulted in unauthorized access to customer data. Following the discovery, we immediately began work to secure our systems and initiated an investigation with the support of external cybersecurity specialists and legal advisors. We take this matter very seriously and are currently conducting a thorough investigation to determine the full scope of the incident and its potential impact on customers, which includes participants of the European Commission's DiscoverEU action.
EU data protection
EU data protection
fromTheregister
2 weeks ago

Passports, bank details compromised in Eurail data breach

Eurail confirmed a data breach exposing customer personal and passport information, with DiscoverEU participants at higher risk of additional ID, bank, and health data exposure.
EU data protection
fromTheregister
2 weeks ago

Endesa probes breach after hackers claim huge data haul

Endesa suffered an unauthorized intrusion potentially exposing identifying details, national IDs, contract data and some IBANs for millions of customers, while passwords were not accessed.
US news
fromTechCrunch
2 weeks ago

Man to plead guilty to hacking US Supreme Court filing system | TechCrunch

Nicholas Moore is expected to plead guilty for repeatedly accessing the U.S. Supreme Court's electronic filing system on 25 days between August and October 2023.
Privacy technologies
fromDataBreaches.Net
3 weeks ago

Armenia probes alleged sale of 8 million government records on hacker forum - DataBreaches.Net

Hackers are selling an alleged Armenian government notification dataset of about 8 million records for $2,500, prompting an official investigation.
Information security
fromTechCrunch
3 weeks ago

Fintech firm Betterment confirms data breach after hackers send fake crypto scam notification to users | TechCrunch

Hackers accessed some Betterment systems via social engineering through third-party platforms, exposing customer contact details and dates of birth; fraudulent crypto-solicitation messages were sent.
#cyberattack
fromTheregister
3 weeks ago

Latest BreachForums reboot spills data on 325K users

The allegedly stolen user data was later posted to shinyhunte[.]rs, alongside a message from a self-described cyber outlaw calling himself "James," who appeared keen to make sure his handiwork didn't go unnoticed. Have I Been Pwned's listing of the incident shows that the breach occurred before law enforcement's October 2025 takedown of the BreachForums domain, and that the leak comprised roughly 324,000 unique email addresses, usernames, and Argon2-hashed passwords, pulled from public posts, private messages, and other forum records.
Information security
#instagram
fromTechCrunch
3 weeks ago
Information security

Instagram says there's been 'no breach' despite password reset requests | TechCrunch

fromEngadget
3 weeks ago
Information security

An Instagram data breach reportedly exposed the personal info of 17.5 million users

fromTechCrunch
3 weeks ago
Information security

Instagram says there's been 'no breach' despite password reset requests | TechCrunch

fromEngadget
3 weeks ago
Information security

An Instagram data breach reportedly exposed the personal info of 17.5 million users

fromComputerWeekly.com
3 weeks ago

Personal data of thousands stolen in attack on London councils | Computer Weekly

The Royal Borough of Kensington and Chelsea (RBKC) in Greater London is in the process of contacting households across the borough after establishing in December that personal data on thousands of residents was stolen in a cyber attack on shared systems operated by the council. Over a month after the incident, several services remain disrupted or are operating in a limited capacity.
Information security
#eeoc
fromDataBreaches.Net
3 weeks ago
Information security

EEOC experienced security incident involving an Opexus employee's 'unauthorized' access, email says - DataBreaches.Net

fromNextgov.com
3 weeks ago
Information security

EEOC experienced security incident involving contractor's 'unauthorized' access, email says

fromDataBreaches.Net
3 weeks ago
Information security

EEOC experienced security incident involving an Opexus employee's 'unauthorized' access, email says - DataBreaches.Net

fromNextgov.com
3 weeks ago
Information security

EEOC experienced security incident involving contractor's 'unauthorized' access, email says

Public health
fromTechCrunch
3 weeks ago

Illinois health department exposed over 700,000 residents' personal data for years | TechCrunch

A security lapse exposed personal information of over 700,000 Illinois residents via a public internal mapping website from April 2021 to September 2025.
fromDataBreaches.Net
3 weeks ago

Methodist Homes of Alabama and Northwest Florida is notifying residents and employees of its second data breach in seven months. - DataBreaches.Net

For residents and patients, the account information included first and last name, Social Security number, date of birth, Medicare number, or medical treatment and condition information. For those individuals who were not residents, personal information involved first and last name, in combination with one or more of the following data element(s): Social Security number, passport number, driver's license or state identity card information, medical information, health insurance information, and online log-in information corresponding with the individual whose email account was compromised.
Information security
Arts
fromwww.npr.org
3 weeks ago

A 200-year-old book distributor is closing. Here's what that means for public libraries

Baker & Taylor, the nation's largest print book distributor to public libraries, is closing amid financial troubles, a 2022 data breach, and industry pressures.
fromwww.standard.co.uk
3 weeks ago

London council warns 100,000 households' personal details could have been stolen in cyber attack

Kensington and Chelsea Council has written to 100,000 households warning their personal details may have been taken in a recent cyber attack. The town hall urged residents to follow National Cyber Security Centre advice and warned criminals could use the information to make scams seem more legitimate, according to an update on its website. The council said the attack was carried out "with criminal intent"
UK news
Privacy professionals
fromDataBreaches.Net
4 weeks ago

NZ: High Court grants injunction over ManageMyHealth cyber breach - DataBreaches.Net

A High Court injunction bars sharing Manage My Health stolen data, but limited jurisdiction and unserved attackers make the injunction unlikely to prevent further dissemination.
#honeypot
fromDataBreaches.Net
4 weeks ago
Information security

Threat actors insisted that Resecurity's honeypot was real data. We found no evidence that it was. - DataBreaches.Net

fromDataBreaches.Net
1 month ago
Information security

ShinyHunters claims to have compromised Resecurity, but it looks like they fell for a honeypot - DataBreaches.Net

fromDataBreaches.Net
4 weeks ago
Information security

Threat actors insisted that Resecurity's honeypot was real data. We found no evidence that it was. - DataBreaches.Net

fromDataBreaches.Net
1 month ago
Information security

ShinyHunters claims to have compromised Resecurity, but it looks like they fell for a honeypot - DataBreaches.Net

Privacy professionals
fromDataBreaches.Net
4 weeks ago

Illinois Department of Human Services tightens map security after data incident - DataBreaches.Net

Internal planning maps with incorrect privacy settings exposed personal data of ~32,401 DRS customers and ~672,616 Medicaid/Medicare Savings Program recipients.
fromTheregister
1 month ago

Cybercrook claims to sell critical info about utilities

The crim says the haul spans more than 800 classified raw LiDAR point cloud files in .las format ranging from 100 MB to 2 GB each; full coverage of transmission line corridors and substations, which includes layers for bare earth, vegetation, conductors, and structures; high-resolution orthophotos in .ecw format; MicroStation design files and PTC settings; large vegetation feature files in .xyz format; and other files from active projects.
US news
fromDataBreaches.Net
1 month ago
Privacy professionals

Attorney General James Secures $500,000 from Capital Region Health Care Provider for Failing to Protect Patients' Information - DataBreaches.Net

OrthopedicsNY paid $500,000 in penalties after a cyberattack exposed sensitive data of about 656,000 patients and employees due to inadequate security.
Law
fromDataBreaches.Net
1 month ago

Software company lacked 'downstream' liability for data breach - DataBreaches.Net

Barracuda cannot be held downstreamly liable for Zoll's data-breach-related class-action settlement; equitable indemnification failed without a derivative or vicarious relationship.
EU data protection
fromDataBreaches.Net
1 month ago

French software company fined $2 million for cyber failings leading to data breach - DataBreaches.Net

Nexpublica France was fined €1.7 million by CNIL for inadequate cybersecurity after a portal exposed third-party documents and sensitive data.
[ Load more ]