#data-breach

[ follow ]
#cyberattack
Information security
fromSecurityWeek
1 week ago

Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping

Iran-linked cyberattack on Stryker caused global disruption to Microsoft environment, affecting order processing, manufacturing, and shipping operations.
World news
fromwww.aljazeera.com
2 weeks ago

Iran-linked hackers hit medical giant Stryker in retaliatory cyberattack

An Iran-linked hacking group claimed responsibility for a cyberattack on Stryker, a major medical device company, citing retaliation for a US-Israeli strike on an Iranian school that killed over 170 people.
World news
fromMail Online
2 weeks ago

Iran claims cyberattack on US as retaliation for 'brutal attack'

Iranian-linked Handala group claimed responsibility for a global cyberattack on Stryker medical technology company, wiping over 200,000 systems and extracting 50 terabytes of data in retaliation for military strikes on Iran.
Information security
fromSecurityWeek
1 week ago

Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping

Iran-linked cyberattack on Stryker caused global disruption to Microsoft environment, affecting order processing, manufacturing, and shipping operations.
World news
fromwww.aljazeera.com
2 weeks ago

Iran-linked hackers hit medical giant Stryker in retaliatory cyberattack

An Iran-linked hacking group claimed responsibility for a cyberattack on Stryker, a major medical device company, citing retaliation for a US-Israeli strike on an Iranian school that killed over 170 people.
World news
fromMail Online
2 weeks ago

Iran claims cyberattack on US as retaliation for 'brutal attack'

Iranian-linked Handala group claimed responsibility for a global cyberattack on Stryker medical technology company, wiping over 200,000 systems and extracting 50 terabytes of data in retaliation for military strikes on Iran.
London politics
fromwww.standard.co.uk
21 hours ago

Victims of cyber attack on London council 'won't be told for months' that their details have been stolen

Kensington and Chelsea Council is notifying residents of a data breach, with the process expected to start by summer 2026.
#cybersecurity
Privacy professionals
fromTechRepublic
3 days ago

Navia Data Breach Hits 2.7 Million People, Exposing Sensitive Personal Data

Navia Benefit Solutions experienced a data breach affecting nearly 2.7 million individuals, with unauthorized access lasting nearly a month before detection.
Information security
fromTechRepublic
1 day ago

Nearly 7M Email Addresses Exposed in Crunchyroll Third-Party Breach

Crunchyroll was breached through a third-party vendor, compromising user data and internal systems via a support agent's account.
Privacy professionals
fromSecurityWeek
2 days ago

HackerOne Employee Data Exposed in Massive Navia Breach

Nearly 300 HackerOne employees had personal information exposed in a data breach by Navia Benefit Solutions affecting 2.7 million individuals.
Privacy professionals
fromSecurityWeek
2 days ago

Extortion Group Claims It Hacked AstraZeneca

Lapsus$ extortion group hacked AstraZeneca, stealing approximately 3GB of sensitive data including credentials, internal code, and employee information.
Privacy professionals
fromTechzine Global
2 days ago

Mazda investigates data breach following vulnerability in internal IT system

Mazda experienced a security incident leading to unauthorized access of employee and partner data, prompting enhanced security measures.
Privacy professionals
fromTechRepublic
3 days ago

Navia Data Breach Hits 2.7 Million People, Exposing Sensitive Personal Data

Navia Benefit Solutions experienced a data breach affecting nearly 2.7 million individuals, with unauthorized access lasting nearly a month before detection.
#hackerone
Privacy professionals
fromTechzine Global
1 day ago

HackerOne hit by data breach via third-party partner

HackerOne confirmed a data breach at Navia, affecting 287 employees' personal data, including sensitive information like Social Security numbers.
Privacy professionals
fromTheregister
2 days ago

HackerOne slams supplier over delayed breach notice

HackerOne employees were affected by a data breach linked to a third-party benefits provider, Navia Benefit Solutions, due to a security flaw.
#crunchyroll
Privacy professionals
fromTechCrunch
2 days ago

Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch

Crunchyroll confirmed a data breach involving customer service ticket information due to a third-party vendor incident, affecting millions of users.
Privacy professionals
fromTechCrunch
2 days ago

Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch

Crunchyroll confirmed a data breach involving customer service ticket information due to a third-party vendor incident, affecting millions of users.
Privacy professionals
fromTechRepublic
2 days ago

Millions of Anonymous Student and Crime Tips Exposed in Major Data Breach

Sensitive data from a crime tip platform was exposed, raising concerns about the safety and privacy of users relying on such systems.
Privacy professionals
fromSecurityWeek
2 days ago

Mazda Says Employee, Partner Information Stolen in Cyberattack

Mazda Motor Corporation experienced a data breach affecting personal information of 692 employees and business partners due to unauthorized access to its management system.
#ransomware
Information security
fromSecurityWeek
3 days ago

Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware

Trio-Tech's Singapore subsidiary experienced a ransomware attack, leading to file encryption and ongoing investigations into the incident.
Information security
fromTheregister
3 days ago

Chip tester shrugged off ransomware - then came the leak

Trio-Tech International reversed its initial assessment of a ransomware attack, now considering it a material cybersecurity event after data was disclosed.
Privacy professionals
fromSecurityWeek
2 weeks ago

238,000 Impacted by Bell Ambulance Data Breach

Bell Ambulance notified 237,830 individuals of a February 2025 data breach exposing personal, financial, medical, and health insurance information after the Medusa ransomware gang claimed responsibility.
Privacy professionals
fromTechzine Global
3 weeks ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Information security
fromSecurityWeek
3 days ago

Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware

Trio-Tech's Singapore subsidiary experienced a ransomware attack, leading to file encryption and ongoing investigations into the incident.
Information security
fromTheregister
3 days ago

Chip tester shrugged off ransomware - then came the leak

Trio-Tech International reversed its initial assessment of a ransomware attack, now considering it a material cybersecurity event after data was disclosed.
Privacy professionals
fromSecurityWeek
2 weeks ago

238,000 Impacted by Bell Ambulance Data Breach

Bell Ambulance notified 237,830 individuals of a February 2025 data breach exposing personal, financial, medical, and health insurance information after the Medusa ransomware gang claimed responsibility.
Privacy professionals
fromTechzine Global
3 weeks ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Privacy professionals
fromSecurityWeek
1 week ago

Marquis Data Breach Affects 672,000 Individuals

Marquis, a marketing and compliance provider for financial institutions, disclosed a data breach affecting approximately 672,000 individuals, with stolen personal and financial information including SSNs, addresses, and payment card numbers.
#phishing-attack
Privacy professionals
fromSecurityWeek
1 week ago

Security Firm Aura Discloses Data Breach Impacting 900,000 Records

Aura suffered a data breach affecting 900,000 records after a phishing attack compromised an employee account for approximately one hour, exposing names, email addresses, and contact information of roughly 35,000 customers.
Information security
fromSecuritymagazine
1 week ago

Targeted Phishing Attack Breaches Biotech Company Data

Intuitive Surgical suffered a phishing attack compromising employee credentials, exposing customer and corporate data, though operational systems and customer networks remained unaffected due to network segmentation.
Privacy professionals
fromSecurityWeek
1 week ago

Starbucks Data Breach Impacts Employees

Starbucks experienced a data breach affecting approximately 900 employees through phishing attacks that compromised Partner Central accounts, exposing names, social security numbers, dates of birth, and financial information.
Privacy professionals
fromSecurityWeek
1 week ago

Security Firm Aura Discloses Data Breach Impacting 900,000 Records

Aura suffered a data breach affecting 900,000 records after a phishing attack compromised an employee account for approximately one hour, exposing names, email addresses, and contact information of roughly 35,000 customers.
Information security
fromSecuritymagazine
1 week ago

Targeted Phishing Attack Breaches Biotech Company Data

Intuitive Surgical suffered a phishing attack compromising employee credentials, exposing customer and corporate data, though operational systems and customer networks remained unaffected due to network segmentation.
Privacy professionals
fromSecurityWeek
1 week ago

Starbucks Data Breach Impacts Employees

Starbucks experienced a data breach affecting approximately 900 employees through phishing attacks that compromised Partner Central accounts, exposing names, social security numbers, dates of birth, and financial information.
#ransomware-attack
Privacy professionals
fromTechCrunch
1 week ago

Marquis says over 672,000 people had personal and financial data stolen in ransomware attack | TechCrunch

Marquis, a fintech company serving hundreds of banks, suffered a ransomware attack in August 2025 that compromised personal and financial data of over 672,000 people, with more than half residing in Texas.
Information security
fromTheregister
2 weeks ago

Crims hit EV charger firm ELECQ, steal customer contact data

ELECQ, a smart EV charger maker, suffered a ransomware attack on March 7 that encrypted and copied customer personal data including names, email addresses, phone numbers, and home addresses from its AWS cloud systems.
Privacy professionals
fromSecurityWeek
3 weeks ago

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on University of Hawaiʻi Cancer Center compromised personal information of approximately 1.2 million people, including names, Social Security numbers, and driver's license details, though clinical operations and patient care remained unaffected.
Privacy professionals
fromTechCrunch
1 week ago

Marquis says over 672,000 people had personal and financial data stolen in ransomware attack | TechCrunch

Marquis, a fintech company serving hundreds of banks, suffered a ransomware attack in August 2025 that compromised personal and financial data of over 672,000 people, with more than half residing in Texas.
Information security
fromTheregister
2 weeks ago

Crims hit EV charger firm ELECQ, steal customer contact data

ELECQ, a smart EV charger maker, suffered a ransomware attack on March 7 that encrypted and copied customer personal data including names, email addresses, phone numbers, and home addresses from its AWS cloud systems.
Privacy professionals
fromSecurityWeek
3 weeks ago

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on University of Hawaiʻi Cancer Center compromised personal information of approximately 1.2 million people, including names, Social Security numbers, and driver's license details, though clinical operations and patient care remained unaffected.
UK politics
fromwww.independent.co.uk
1 week ago

Thousands of Afghans still in limbo over UK resettlement five years on

Nearly 30,000 Afghans await UK resettlement decisions five years after Kabul's fall, with urgent intervention needed to meet the March 2029 deadline.
Cryptocurrency
fromBitcoin Magazine
1 week ago

Bitrefill Discloses Cyberattack, Points To North Korea's Lazarus Group

Bitrefill suffered a cyberattack on March 1 originating from a compromised employee laptop, with the Lazarus Group suspected as the perpetrator, resulting in stolen cryptocurrency and exposure of approximately 18,500 customer records.
fromTheregister
1 week ago

EU sanctions Iranian cyber crew behind US election tampering

Based in Tehran, Emennet Pasargad is responsible for a variety of high-profile cyberattacks on Western organizations. Among these are attempted interference with US elections and attacks on the subscribers of French satirical magazine Charlie Hebdo, the Council stated.
France politics
UK news
fromwww.independent.co.uk
1 week ago

Lloyds faces questions over troubling' banking app glitch

Lloyds Banking Group faces parliamentary scrutiny after a data breach exposed customers' financial transactions through its banking app, prompting the Treasury Committee to demand immediate answers and compensation details.
#ai-security
Privacy professionals
fromWIRED
1 week ago

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears Home Services exposed 3.7 million chat logs and 1.4 million audio files containing customer personal information through unsecured databases housing conversations with AI chatbot Samantha.
fromJezebel
4 weeks ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Privacy professionals
fromWIRED
1 week ago

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears Home Services exposed 3.7 million chat logs and 1.4 million audio files containing customer personal information through unsecured databases housing conversations with AI chatbot Samantha.
fromJezebel
4 weeks ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Privacy professionals
fromComputerWeekly.com
1 week ago

Companies House restarts online services following cyber breach | Computer Weekly

Companies House restored its WebFiling service after discovering a security flaw that exposed personal data and allowed unauthorized actions to logged-in users with authorization codes.
#cybersecurity-vulnerability
fromBusiness Matters
1 week ago
Privacy professionals

Companies House suspends online filing service after cyber vulnerability exposes director data

Companies House suspended its WebFiling service after a security vulnerability allowed users to access and edit other companies' sensitive personal data through a browser back button exploit.
fromLawSites
3 weeks ago
Information security

LexisNexis Says Data Breach Has Been Cointained; Hackers Claim Access to Government and Law Firm User Data

Hackers exploited an unpatched React vulnerability to breach LexisNexis servers, accessing millions of records including sensitive government employee data and plaintext credentials.
Privacy professionals
fromBusiness Matters
1 week ago

Companies House suspends online filing service after cyber vulnerability exposes director data

Companies House suspended its WebFiling service after a security vulnerability allowed users to access and edit other companies' sensitive personal data through a browser back button exploit.
Information security
fromLawSites
3 weeks ago

LexisNexis Says Data Breach Has Been Cointained; Hackers Claim Access to Government and Law Firm User Data

Hackers exploited an unpatched React vulnerability to breach LexisNexis servers, accessing millions of records including sensitive government employee data and plaintext credentials.
Privacy professionals
fromWIRED
1 week ago

Do You Need an Identity Protection Service for Safe Browsing?

Identity theft protection services function as insurance products offering reactive compensation for damages rather than active prevention, with coverage details and sub-benefit caps critically affecting actual protection value.
Privacy professionals
fromwww.theguardian.com
1 week ago

Confidential health records from UK BioBank project exposed online

UK Biobank researchers have repeatedly exposed confidential health data online, creating privacy risks despite the absence of direct identifiers in the leaked files.
#salesforce-security
Information security
fromSecuritymagazine
2 weeks ago

Why Are Platform Ecosystems - Like Salesforce - Often Targeted?

Salesforce warned users of increased threat actor activity exploiting misconfigured publicly accessible sites and permissive guest user settings to gain unauthorized data access for social engineering and vishing campaigns.
Information security
fromTheregister
2 weeks ago

ShinyHunters claims yet another Salesforce customers breach

ShinyHunters claims to have stolen data from approximately 100 high-profile companies including Salesforce, Snowflake, Okta, LastPass, Sony, and AMD through exploiting overly broad guest user permissions on Salesforce Experience Cloud sites.
Information security
fromSecuritymagazine
2 weeks ago

Why Are Platform Ecosystems - Like Salesforce - Often Targeted?

Salesforce warned users of increased threat actor activity exploiting misconfigured publicly accessible sites and permissive guest user settings to gain unauthorized data access for social engineering and vishing campaigns.
Information security
fromSecurityWeek
2 weeks ago

Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign

ShinyHunters targets Salesforce instances through social engineering and misconfiguration exploitation, not platform vulnerabilities, prompting Salesforce warnings about overly permissive guest user settings.
Information security
fromTheregister
2 weeks ago

ShinyHunters claims yet another Salesforce customers breach

ShinyHunters claims to have stolen data from approximately 100 high-profile companies including Salesforce, Snowflake, Okta, LastPass, Sony, and AMD through exploiting overly broad guest user permissions on Salesforce Experience Cloud sites.
Information security
fromTechRepublic
2 weeks ago

Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk

A critical vulnerability in the Ally WordPress plugin allows unauthenticated attackers to extract sensitive database data including password hashes from hundreds of thousands of affected websites.
Information security
fromSecurityWeek
2 weeks ago

Michelin Confirms Data Breach Linked to Oracle EBS Attack

Michelin confirmed a data breach from the Cl0p ransomware group's Oracle EBS zero-day exploitation campaign affecting over 100 organizations.
Privacy professionals
fromEngadget
2 weeks ago

Social Security watchdog investigating claims that DOGE engineer copied its databases

A former software engineer associated with Elon Musk's Department of Government Efficiency is under investigation for allegedly possessing and attempting to transfer sensitive Social Security Administration databases containing personal information on over 500 million Americans.
fromTechCrunch
2 weeks ago

DOGE employee stole Social Security data and put it on a thumb drive, report says | TechCrunch

A former DOGE software engineer told co-workers at their new job that he "possessed two tightly restricted databases of U.S. citizens' information" and was planning to use the information at his new company, according to the report, which added that the Social Security Administration's inspector general is investigating the whistleblower complaint.
Privacy professionals
Privacy professionals
fromSecurityWeek
2 weeks ago

Thousands Affected by Ericsson Data Breach

Ericsson's US subsidiary disclosed a data breach at a third-party service provider affecting approximately 15,000 individuals, with unauthorized access occurring between April 17-22, 2025.
Information security
fromTechzine Global
2 weeks ago

Ericsson breach: voice phishing call exposed over 15,000 records

A vishing attack on an Ericsson vendor exposed personal data including Social Security numbers and medical information for 15,661 people after an employee was tricked into revealing account access.
#voice-phishing-attack
Privacy professionals
fromTheregister
2 weeks ago

Ericsson breach blamed on third party vendor vishing attack

A voice-phishing attack on an Ericsson service provider exposed personal data of over 15,000 individuals, including names, Social Security numbers, and government-issued IDs.
fromTechRepublic
2 weeks ago

LexisNexis Hack Exposes 3.9M Records Through Unpatched React Vulnerability

According to BleepingComputer, a recent breach on LexisNexis gave hackers access to nearly 4 million database records, thousands of accounts, password hashes, and cloud records. The company admitted the hackers gained access by exploiting an unpatched React vulnerability in its systems.
Information security
Privacy technologies
fromTheregister
2 weeks ago

Transport for London says 2024 breach affected 7M customers

Transport for London's 2024 data breach exposed over 7 million people's information, vastly exceeding the initial 5,000 customer estimate, with potential access to names, contact details, email addresses, home addresses, and bank account data.
Information security
fromThe Hacker News
3 weeks ago

FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials

Law enforcement dismantled LeakBase, a major cybercriminal forum with 142,000 members that traded stolen data and hacking tools, seizing all content and accounts for evidence.
#cybercrime
EU data protection
fromDataBreaches.Net
3 weeks ago

LeakBase seized, arrests made as part of global action - DataBreaches.Net

LeakBase, a major cybercrime forum for trading stolen data and credentials, was dismantled through coordinated international law enforcement operations resulting in approximately 100 enforcement actions and arrests of key users.
EU data protection
fromDataBreaches.Net
3 weeks ago

LeakBase seized, arrests made as part of global action - DataBreaches.Net

LeakBase, a major cybercrime forum for trading stolen data and credentials, was dismantled through coordinated international law enforcement operations resulting in approximately 100 enforcement actions and arrests of key users.
Healthcare
fromSecuritymagazine
3 weeks ago

1M Impacted by University of Hawaii Cancer Center Breach

University of Hawaiʻi Cancer Center experienced a data breach exposing approximately 1.15 million individuals' Social Security numbers, driver's license numbers, and voter registration records from epidemiological studies spanning decades.
#healthcare-security
Privacy professionals
fromDataBreaches.Net
3 weeks ago

Evoke Wellness at Hilliard updates its breach notification - DataBreaches.Net

An Ohio addiction treatment center discovered unauthorized patient data access by a former employee in October 2024, but delayed notifying affected individuals until August 2025, with inconsistent breach discovery dates in official notifications.
fromSecurityWeek
3 weeks ago

Madison Square Garden Data Breach Confirmed Months After Hacker Attack

In the Oracle EBS hacking campaign, the Cl0p ransomware and extortion group exploited zero-day vulnerabilities to gain access to data stored by more than 100 organizations in the enterprise management software. Madison Square Garden (MSG), the world-famous arena located in New York City, was named by the hackers as a victim of the campaign in November 2025.
Privacy professionals
Privacy technologies
fromDataBreaches.Net
3 weeks ago

Leaked Odido data exposes sensitive information - DataBreaches.Net

Dutch news outlets freely reported on the Odido telecom breach affecting 6.2 million customers, exposing sensitive data including stalking victims' information and protected addresses without censorship.
Privacy professionals
fromDataBreaches.Net
3 weeks ago

KT, LG Uplus face lingering fallout over hacking incidents - DataBreaches.Net

KT and LG Uplus face regulatory scrutiny and customer losses following data breaches, with LG Uplus under investigation for obstructing forensic analysis by destroying evidence.
fromTheregister
3 weeks ago

AI-built app on Lovable exposed 18K users, researcher claims

The main issue, Khan said, was that all apps that are vibe-coded on Lovable's platform are shipped with their backends powered by Supabase, which handles authentication, file storage, and real-time updates through a PostgreSQL database connection. However, when the developer - in this case AI - or the human project owner fails to explicitly implement crucial security features like Supabase's row-level security and role-based access, code will be generated that looks functional but in reality is flawed.
Artificial intelligence
Information security
fromSecurityWeek
3 weeks ago

38 Million Allegedly Impacted by ManoMano Data Breach

A data breach at European DIY retailer ManoMano compromised approximately 38 million customers' personal information through a compromised customer service subcontractor.
#shinyhunters
Information security
fromDataBreaches.Net
4 weeks ago

Wynn Resorts Confirms Data Breach After Hackers Remove It From Leak Site - DataBreaches.Net

Wynn Resorts' data listing was removed from ShinyHunters leak site after the company reportedly paid an extortion demand, with the resort confirming deletion of stolen employee data.
fromTheregister
4 weeks ago

Wynn Resorts confirms data stolen after ShinyHunters threats

Trusting cybercriminals is inherently flawed; there is no honour among thieves. There is absolutely no reliable way to verify that an extortionist has permanently deleted stolen data. Copies are frequently retained, shared, or sold months down the line.
Information security
#paypal
Information security
fromTheregister
1 month ago

Attacker gets into France's DB listing all bank accounts

A January breach exposed 1.2 million French bank account records, while attackers actively exploit two critical Ivanti EPMM zero-days targeting unpatched systems worldwide.
fromDataBreaches.Net
1 month ago

The hospitality sector continues to be lucrative targets - DataBreaches.Net

Choice Hotels International disclosed a breach affecting franchisees and applicants. Its notification letter states that a "skilled person used social engineering" to gain access on January 14, 2026 to an application that contained records regarding franchisees and franchise applicants. The access occurred even though access required multifactor authentication (MFA). The information involved included names and Social Security numbers. There is no indication that any guest data was involved. No gang has publicly claimed responsibility for the attack as yet.
Information security
fromTheregister
1 month ago

Cornwall council mishandles complaints in data breach case

A UK councillor has dubbed her local authority's data breach "crazy" after the personal details of individuals behind a series of complaints were revealed to her. Dulcie Tudor, an independent councillor for the Threemilestone and Chacewater area in Cornwall, England, publicized the data protection gaffe via social media following complaints about comments she made during a November council meeting. Cllr Tudor received ten complaints after asking fellow councillor Leigh Knight whether a trans woman was a real woman.
Privacy professionals
fromTechzine Global
1 month ago

PayPal leaked sensitive data for six months due to software error

PayPal is warning customers about a data breach that leaked personal data for six months. The leaked data includes social security numbers. The software error occurred in the PayPal Working Capital application, an app that allows small businesses to easily take out a business loan. The leak occurred between July 1, 2025, and December 13, 2025. In addition to names and email addresses, phone numbers, business addresses, social security numbers, and dates of birth were also compromised.
Information security
Information security
fromDataBreaches.Net
1 month ago

A single compromised account gave hackers access to 1.2 million French banking records - DataBreaches.Net

Stolen credentials from one government official allowed attackers to access France's FICOBA database, exposing over 1.2 million bank accounts and sensitive financial data.
[ Load more ]