#data-breach

[ follow ]
#cybersecurity
Privacy professionals
fromNextgov.com
3 days ago

Pro-Iran hackers claim breach of FBI director's email

A pro-Iran hacker group accessed FBI Director Kash Patel's email and leaked purported contents online in response to FBI actions against them.
Information security
fromSecurityWeek
3 days ago

In Other News: Palo Alto Recruiter Scam, Anti-Deepfake Chip, Google Sets 2029 Quantum Deadline

Cybersecurity incidents this week include LA Metro disruptions, a Russian phishing campaign targeting messaging apps, and a hack affecting breathalyzer ignition devices.
Healthcare
fromSecurityWeek
13 hours ago

Healthcare IT Platform CareCloud Probing Potential Data Breach

CareCloud experienced a cybersecurity incident that may have compromised patient information, but the impact is believed to be limited and manageable.
EU data protection
fromEngadget
3 days ago

European Commission confirms data breach

The European Commission experienced a cyber attack, resulting in the theft of over 350GB of data from its cloud infrastructure.
Privacy professionals
fromNextgov.com
3 days ago

Pro-Iran hackers claim breach of FBI director's email

A pro-Iran hacker group accessed FBI Director Kash Patel's email and leaked purported contents online in response to FBI actions against them.
Information security
fromSecurityWeek
3 days ago

In Other News: Palo Alto Recruiter Scam, Anti-Deepfake Chip, Google Sets 2029 Quantum Deadline

Cybersecurity incidents this week include LA Metro disruptions, a Russian phishing campaign targeting messaging apps, and a hack affecting breathalyzer ignition devices.
#cyberattack
EU data protection
fromSecurityWeek
15 hours ago

European Commission Reports Cyber Intrusion and Data Theft

The European Commission confirmed a cyberattack that compromised its cloud infrastructure, resulting in the theft of hundreds of gigabytes of data.
EU data protection
fromTechCrunch
3 days ago

European Commission confirms cyberattack after hackers claim data breach | TechCrunch

A cyberattack on the European Commission's cloud infrastructure resulted in the theft of significant data, but internal systems remain unaffected.
Information security
fromSecurityWeek
2 weeks ago

Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping

Iran-linked cyberattack on Stryker caused global disruption to Microsoft environment, affecting order processing, manufacturing, and shipping operations.
EU data protection
fromSecurityWeek
15 hours ago

European Commission Reports Cyber Intrusion and Data Theft

The European Commission confirmed a cyberattack that compromised its cloud infrastructure, resulting in the theft of hundreds of gigabytes of data.
EU data protection
fromTechCrunch
3 days ago

European Commission confirms cyberattack after hackers claim data breach | TechCrunch

A cyberattack on the European Commission's cloud infrastructure resulted in the theft of significant data, but internal systems remain unaffected.
Information security
fromSecurityWeek
2 weeks ago

Iran-Linked Hacker Attack on Stryker Disrupted Manufacturing and Shipping

Iran-linked cyberattack on Stryker caused global disruption to Microsoft environment, affecting order processing, manufacturing, and shipping operations.
EU data protection
fromTheregister
17 hours ago

European Commission admits breach of public web systems

The European Commission confirmed a data breach affecting its public web infrastructure, with details on the extent and nature of the data taken remaining unclear.
fromwww.cbc.ca
2 days ago

Settlement approved for Canadians affected by past 23andMe data breach | CBC News

The settlement will provide $3.25 million US for Canada-based victims of the breach, which saw hackers gain access to customers' data including people in Canada in 2023.
EU data protection
#lloyds-banking-group
Privacy professionals
fromTheregister
3 days ago

Lloyds app glitch exposed transactions to almost 500K users

A software update at Lloyds Banking Group exposed transaction details of up to 447,000 customers due to a defect in the API handling data.
Privacy professionals
fromTheregister
3 days ago

Lloyds app glitch exposed transactions to almost 500K users

A software update at Lloyds Banking Group exposed transaction details of up to 447,000 customers due to a defect in the API handling data.
EU data protection
fromTechzine Global
3 days ago

European Commission investigates data breach in Amazon cloud

A data breach involving Amazon's cloud infrastructure has resulted in the theft of over 350 GB of data, with threats to publish it online.
Soccer (FIFA)
fromTheregister
3 days ago

AFC Ajax drops ball as hackers transfer tickets, lift bans

AFC Ajax experienced a data breach due to vulnerabilities, exposing personal data and allowing unauthorized access to user accounts.
Privacy professionals
fromwww.bbc.com
3 days ago

Lloyds bank reveals IT glitch affected almost half a million customers

A recent IT issue affected nearly 447,936 customers of Lloyds, Halifax, and Bank of Scotland, exposing their transaction data to others.
fromTechzine Global
3 days ago

Dutch football club Ajax hid data breach after report from ethical hacker

In 2017, Rasnab gained access to the Amsterdam club's ticketing system, which was then operated in collaboration with Eventim. Through that system, he was able to view personal data of fans and employees, including data on club icon Sjaak Swart.
Privacy professionals
London politics
fromwww.standard.co.uk
4 days ago

Victims of cyber attack on London council 'won't be told for months' that their details have been stolen

Kensington and Chelsea Council is notifying residents of a data breach, with the process expected to start by summer 2026.
#hackerone
Privacy professionals
fromTheregister
6 days ago

HackerOne slams supplier over delayed breach notice

HackerOne employees were affected by a data breach linked to a third-party benefits provider, Navia Benefit Solutions, due to a security flaw.
#crunchyroll
Privacy professionals
fromTechCrunch
6 days ago

Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch

Crunchyroll confirmed a data breach involving customer service ticket information due to a third-party vendor incident, affecting millions of users.
Privacy professionals
fromTechCrunch
6 days ago

Crunchyroll confirms data breach after hacker claims unauthorized access | TechCrunch

Crunchyroll confirmed a data breach involving customer service ticket information due to a third-party vendor incident, affecting millions of users.
Privacy professionals
fromTechRepublic
6 days ago

Millions of Anonymous Student and Crime Tips Exposed in Major Data Breach

Sensitive data from a crime tip platform was exposed, raising concerns about the safety and privacy of users relying on such systems.
Privacy professionals
fromSecurityWeek
6 days ago

Mazda Says Employee, Partner Information Stolen in Cyberattack

Mazda Motor Corporation experienced a data breach affecting personal information of 692 employees and business partners due to unauthorized access to its management system.
#ransomware
Information security
fromSecurityWeek
1 week ago

Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware

Trio-Tech's Singapore subsidiary experienced a ransomware attack, leading to file encryption and ongoing investigations into the incident.
Information security
fromTheregister
1 week ago

Chip tester shrugged off ransomware - then came the leak

Trio-Tech International reversed its initial assessment of a ransomware attack, now considering it a material cybersecurity event after data was disclosed.
Privacy professionals
fromSecurityWeek
2 weeks ago

238,000 Impacted by Bell Ambulance Data Breach

Bell Ambulance notified 237,830 individuals of a February 2025 data breach exposing personal, financial, medical, and health insurance information after the Medusa ransomware gang claimed responsibility.
Privacy professionals
fromTechzine Global
4 weeks ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Information security
fromSecurityWeek
1 week ago

Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware

Trio-Tech's Singapore subsidiary experienced a ransomware attack, leading to file encryption and ongoing investigations into the incident.
Information security
fromTheregister
1 week ago

Chip tester shrugged off ransomware - then came the leak

Trio-Tech International reversed its initial assessment of a ransomware attack, now considering it a material cybersecurity event after data was disclosed.
Privacy professionals
fromSecurityWeek
2 weeks ago

238,000 Impacted by Bell Ambulance Data Breach

Bell Ambulance notified 237,830 individuals of a February 2025 data breach exposing personal, financial, medical, and health insurance information after the Medusa ransomware gang claimed responsibility.
Privacy professionals
fromTechzine Global
4 weeks ago

All data from dutch Telco Odido hack now online

ShinyHunters released all stolen data from Odido's 6.5 million customers and 600,000 companies online after the company refused ransom payment, exposing names, addresses, social security numbers, ID documents, and sensitive personal information.
Privacy professionals
fromSecurityWeek
1 week ago

Marquis Data Breach Affects 672,000 Individuals

Marquis, a marketing and compliance provider for financial institutions, disclosed a data breach affecting approximately 672,000 individuals, with stolen personal and financial information including SSNs, addresses, and payment card numbers.
#phishing-attack
Privacy professionals
fromSecurityWeek
1 week ago

Security Firm Aura Discloses Data Breach Impacting 900,000 Records

Aura suffered a data breach affecting 900,000 records after a phishing attack compromised an employee account for approximately one hour, exposing names, email addresses, and contact information of roughly 35,000 customers.
Information security
fromSecuritymagazine
2 weeks ago

Targeted Phishing Attack Breaches Biotech Company Data

Intuitive Surgical suffered a phishing attack compromising employee credentials, exposing customer and corporate data, though operational systems and customer networks remained unaffected due to network segmentation.
Privacy professionals
fromSecurityWeek
2 weeks ago

Starbucks Data Breach Impacts Employees

Starbucks experienced a data breach affecting approximately 900 employees through phishing attacks that compromised Partner Central accounts, exposing names, social security numbers, dates of birth, and financial information.
Privacy professionals
fromSecurityWeek
1 week ago

Security Firm Aura Discloses Data Breach Impacting 900,000 Records

Aura suffered a data breach affecting 900,000 records after a phishing attack compromised an employee account for approximately one hour, exposing names, email addresses, and contact information of roughly 35,000 customers.
Information security
fromSecuritymagazine
2 weeks ago

Targeted Phishing Attack Breaches Biotech Company Data

Intuitive Surgical suffered a phishing attack compromising employee credentials, exposing customer and corporate data, though operational systems and customer networks remained unaffected due to network segmentation.
Privacy professionals
fromSecurityWeek
2 weeks ago

Starbucks Data Breach Impacts Employees

Starbucks experienced a data breach affecting approximately 900 employees through phishing attacks that compromised Partner Central accounts, exposing names, social security numbers, dates of birth, and financial information.
#ransomware-attack
Privacy professionals
fromTechCrunch
1 week ago

Marquis says over 672,000 people had personal and financial data stolen in ransomware attack | TechCrunch

Marquis, a fintech company serving hundreds of banks, suffered a ransomware attack in August 2025 that compromised personal and financial data of over 672,000 people, with more than half residing in Texas.
Information security
fromTheregister
3 weeks ago

Crims hit EV charger firm ELECQ, steal customer contact data

ELECQ, a smart EV charger maker, suffered a ransomware attack on March 7 that encrypted and copied customer personal data including names, email addresses, phone numbers, and home addresses from its AWS cloud systems.
Privacy professionals
fromSecurityWeek
3 weeks ago

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on University of Hawaiʻi Cancer Center compromised personal information of approximately 1.2 million people, including names, Social Security numbers, and driver's license details, though clinical operations and patient care remained unaffected.
Privacy professionals
fromTechCrunch
1 week ago

Marquis says over 672,000 people had personal and financial data stolen in ransomware attack | TechCrunch

Marquis, a fintech company serving hundreds of banks, suffered a ransomware attack in August 2025 that compromised personal and financial data of over 672,000 people, with more than half residing in Texas.
Information security
fromTheregister
3 weeks ago

Crims hit EV charger firm ELECQ, steal customer contact data

ELECQ, a smart EV charger maker, suffered a ransomware attack on March 7 that encrypted and copied customer personal data including names, email addresses, phone numbers, and home addresses from its AWS cloud systems.
Privacy professionals
fromSecurityWeek
3 weeks ago

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on University of Hawaiʻi Cancer Center compromised personal information of approximately 1.2 million people, including names, Social Security numbers, and driver's license details, though clinical operations and patient care remained unaffected.
UK politics
fromwww.independent.co.uk
1 week ago

Thousands of Afghans still in limbo over UK resettlement five years on

Nearly 30,000 Afghans await UK resettlement decisions five years after Kabul's fall, with urgent intervention needed to meet the March 2029 deadline.
Cryptocurrency
fromBitcoin Magazine
1 week ago

Bitrefill Discloses Cyberattack, Points To North Korea's Lazarus Group

Bitrefill suffered a cyberattack on March 1 originating from a compromised employee laptop, with the Lazarus Group suspected as the perpetrator, resulting in stolen cryptocurrency and exposure of approximately 18,500 customer records.
fromTheregister
1 week ago

EU sanctions Iranian cyber crew behind US election tampering

Based in Tehran, Emennet Pasargad is responsible for a variety of high-profile cyberattacks on Western organizations. Among these are attempted interference with US elections and attacks on the subscribers of French satirical magazine Charlie Hebdo, the Council stated.
France politics
UK news
fromwww.independent.co.uk
1 week ago

Lloyds faces questions over troubling' banking app glitch

Lloyds Banking Group faces parliamentary scrutiny after a data breach exposed customers' financial transactions through its banking app, prompting the Treasury Committee to demand immediate answers and compensation details.
#ai-security
Privacy professionals
fromWIRED
1 week ago

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears Home Services exposed 3.7 million chat logs and 1.4 million audio files containing customer personal information through unsecured databases housing conversations with AI chatbot Samantha.
fromJezebel
1 month ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Privacy professionals
fromWIRED
1 week ago

Sears Exposed AI Chatbot Phone Calls and Text Chats to Anyone on the Web

Sears Home Services exposed 3.7 million chat logs and 1.4 million audio files containing customer personal information through unsecured databases housing conversations with AI chatbot Samantha.
fromJezebel
1 month ago
Artificial intelligence

Hacker Used Commercial AI Chatbots to Breach Most of the Mexican Government

Privacy professionals
fromComputerWeekly.com
2 weeks ago

Companies House restarts online services following cyber breach | Computer Weekly

Companies House restored its WebFiling service after discovering a security flaw that exposed personal data and allowed unauthorized actions to logged-in users with authorization codes.
#cybersecurity-vulnerability
fromBusiness Matters
2 weeks ago
Privacy professionals

Companies House suspends online filing service after cyber vulnerability exposes director data

Companies House suspended its WebFiling service after a security vulnerability allowed users to access and edit other companies' sensitive personal data through a browser back button exploit.
fromLawSites
3 weeks ago
Information security

LexisNexis Says Data Breach Has Been Cointained; Hackers Claim Access to Government and Law Firm User Data

Hackers exploited an unpatched React vulnerability to breach LexisNexis servers, accessing millions of records including sensitive government employee data and plaintext credentials.
Privacy professionals
fromBusiness Matters
2 weeks ago

Companies House suspends online filing service after cyber vulnerability exposes director data

Companies House suspended its WebFiling service after a security vulnerability allowed users to access and edit other companies' sensitive personal data through a browser back button exploit.
Information security
fromLawSites
3 weeks ago

LexisNexis Says Data Breach Has Been Cointained; Hackers Claim Access to Government and Law Firm User Data

Hackers exploited an unpatched React vulnerability to breach LexisNexis servers, accessing millions of records including sensitive government employee data and plaintext credentials.
Privacy professionals
fromWIRED
2 weeks ago

Do You Need an Identity Protection Service for Safe Browsing?

Identity theft protection services function as insurance products offering reactive compensation for damages rather than active prevention, with coverage details and sub-benefit caps critically affecting actual protection value.
Privacy professionals
fromwww.theguardian.com
2 weeks ago

Confidential health records from UK BioBank project exposed online

UK Biobank researchers have repeatedly exposed confidential health data online, creating privacy risks despite the absence of direct identifiers in the leaked files.
#salesforce-security
Information security
fromSecuritymagazine
2 weeks ago

Why Are Platform Ecosystems - Like Salesforce - Often Targeted?

Salesforce warned users of increased threat actor activity exploiting misconfigured publicly accessible sites and permissive guest user settings to gain unauthorized data access for social engineering and vishing campaigns.
Information security
fromTheregister
3 weeks ago

ShinyHunters claims yet another Salesforce customers breach

ShinyHunters claims to have stolen data from approximately 100 high-profile companies including Salesforce, Snowflake, Okta, LastPass, Sony, and AMD through exploiting overly broad guest user permissions on Salesforce Experience Cloud sites.
Information security
fromSecuritymagazine
2 weeks ago

Why Are Platform Ecosystems - Like Salesforce - Often Targeted?

Salesforce warned users of increased threat actor activity exploiting misconfigured publicly accessible sites and permissive guest user settings to gain unauthorized data access for social engineering and vishing campaigns.
Information security
fromSecurityWeek
2 weeks ago

Hundreds of Salesforce Customers Allegedly Targeted in New Data Theft Campaign

ShinyHunters targets Salesforce instances through social engineering and misconfiguration exploitation, not platform vulnerabilities, prompting Salesforce warnings about overly permissive guest user settings.
Information security
fromTheregister
3 weeks ago

ShinyHunters claims yet another Salesforce customers breach

ShinyHunters claims to have stolen data from approximately 100 high-profile companies including Salesforce, Snowflake, Okta, LastPass, Sony, and AMD through exploiting overly broad guest user permissions on Salesforce Experience Cloud sites.
Information security
fromTechRepublic
2 weeks ago

Security Flaw in WordPress Plugin Puts 400,000 Websites at Risk

A critical vulnerability in the Ally WordPress plugin allows unauthenticated attackers to extract sensitive database data including password hashes from hundreds of thousands of affected websites.
Information security
fromSecurityWeek
2 weeks ago

Michelin Confirms Data Breach Linked to Oracle EBS Attack

Michelin confirmed a data breach from the Cl0p ransomware group's Oracle EBS zero-day exploitation campaign affecting over 100 organizations.
Privacy professionals
fromEngadget
2 weeks ago

Social Security watchdog investigating claims that DOGE engineer copied its databases

A former software engineer associated with Elon Musk's Department of Government Efficiency is under investigation for allegedly possessing and attempting to transfer sensitive Social Security Administration databases containing personal information on over 500 million Americans.
fromTechCrunch
2 weeks ago

DOGE employee stole Social Security data and put it on a thumb drive, report says | TechCrunch

A former DOGE software engineer told co-workers at their new job that he "possessed two tightly restricted databases of U.S. citizens' information" and was planning to use the information at his new company, according to the report, which added that the Social Security Administration's inspector general is investigating the whistleblower complaint.
Privacy professionals
Privacy professionals
fromSecurityWeek
2 weeks ago

Thousands Affected by Ericsson Data Breach

Ericsson's US subsidiary disclosed a data breach at a third-party service provider affecting approximately 15,000 individuals, with unauthorized access occurring between April 17-22, 2025.
Information security
fromTechzine Global
2 weeks ago

Ericsson breach: voice phishing call exposed over 15,000 records

A vishing attack on an Ericsson vendor exposed personal data including Social Security numbers and medical information for 15,661 people after an employee was tricked into revealing account access.
Privacy professionals
fromTheregister
2 weeks ago

Ericsson breach blamed on third party vendor vishing attack

A voice-phishing attack on an Ericsson service provider exposed personal data of over 15,000 individuals, including names, Social Security numbers, and government-issued IDs.
fromTechRepublic
3 weeks ago

LexisNexis Hack Exposes 3.9M Records Through Unpatched React Vulnerability

According to BleepingComputer, a recent breach on LexisNexis gave hackers access to nearly 4 million database records, thousands of accounts, password hashes, and cloud records. The company admitted the hackers gained access by exploiting an unpatched React vulnerability in its systems.
Information security
Privacy technologies
fromTheregister
3 weeks ago

Transport for London says 2024 breach affected 7M customers

Transport for London's 2024 data breach exposed over 7 million people's information, vastly exceeding the initial 5,000 customer estimate, with potential access to names, contact details, email addresses, home addresses, and bank account data.
Information security
fromThe Hacker News
3 weeks ago

FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials

Law enforcement dismantled LeakBase, a major cybercriminal forum with 142,000 members that traded stolen data and hacking tools, seizing all content and accounts for evidence.
fromDataBreaches.Net
3 weeks ago

LeakBase seized, arrests made as part of global action - DataBreaches.Net

The forum, known as LeakBase, had established itself as a central hub in the cybercrime ecosystem, specialising in the trade of leaked databases and so-called "stealer logs" - archives of stolen credentials harvested through infostealer malware. Accessible on the open web and operating in English, the platform combined elements of a forum and discussion board, enabling cybercriminals to buy, sell and exchange compromised data.
EU data protection
Healthcare
fromSecuritymagazine
4 weeks ago

1M Impacted by University of Hawaii Cancer Center Breach

University of Hawaiʻi Cancer Center experienced a data breach exposing approximately 1.15 million individuals' Social Security numbers, driver's license numbers, and voter registration records from epidemiological studies spanning decades.
#healthcare-security
Privacy professionals
fromDataBreaches.Net
4 weeks ago

Evoke Wellness at Hilliard updates its breach notification - DataBreaches.Net

An Ohio addiction treatment center discovered unauthorized patient data access by a former employee in October 2024, but delayed notifying affected individuals until August 2025, with inconsistent breach discovery dates in official notifications.
fromSecurityWeek
4 weeks ago

Madison Square Garden Data Breach Confirmed Months After Hacker Attack

In the Oracle EBS hacking campaign, the Cl0p ransomware and extortion group exploited zero-day vulnerabilities to gain access to data stored by more than 100 organizations in the enterprise management software. Madison Square Garden (MSG), the world-famous arena located in New York City, was named by the hackers as a victim of the campaign in November 2025.
Privacy professionals
Privacy technologies
fromDataBreaches.Net
1 month ago

Leaked Odido data exposes sensitive information - DataBreaches.Net

Dutch news outlets freely reported on the Odido telecom breach affecting 6.2 million customers, exposing sensitive data including stalking victims' information and protected addresses without censorship.
Privacy professionals
fromDataBreaches.Net
1 month ago

KT, LG Uplus face lingering fallout over hacking incidents - DataBreaches.Net

KT and LG Uplus face regulatory scrutiny and customer losses following data breaches, with LG Uplus under investigation for obstructing forensic analysis by destroying evidence.
fromTheregister
1 month ago

AI-built app on Lovable exposed 18K users, researcher claims

The main issue, Khan said, was that all apps that are vibe-coded on Lovable's platform are shipped with their backends powered by Supabase, which handles authentication, file storage, and real-time updates through a PostgreSQL database connection. However, when the developer - in this case AI - or the human project owner fails to explicitly implement crucial security features like Supabase's row-level security and role-based access, code will be generated that looks functional but in reality is flawed.
Artificial intelligence
Information security
fromSecurityWeek
1 month ago

38 Million Allegedly Impacted by ManoMano Data Breach

A data breach at European DIY retailer ManoMano compromised approximately 38 million customers' personal information through a compromised customer service subcontractor.
Information security
fromTechRepublic
1 month ago

ShinyHunters Leak 12.4 Million CarGurus Records in Massive Data Dump

ShinyHunters leaked 12.4 million CarGurus records containing personal and financial data, enabling targeted social engineering and phishing attacks against users.
[ Load more ]