Data Breach
24 articles
Advertisement
Articles24
The Thomson Reuters C-Track Breach May Include Sealed Court Records
Files left C-Track in March, were found on 30 June and disclosed on 3 September. The remedy offered is credit...
PR
4 Sep
500,000 New ID Documents a Day Is Not a Historical Breach
A dark-web service advertised documents from an identity verification firm and claimed half a million new ones...
PR
3 Sep
Aesto Health Took Eight Months to Tell 9.5 Million People
A vendor that archives patient records during system migrations is notifying 9.5 million people about a Decemb...
AM
2 Sep
McKesson Will Not Be Notifying Most of These Patients. Their Doctors Will.
The rule splits the duty: the business associate tells the practices, and each practice tells its own patients...
AM
1 Sep
Attackers Phoned McKesson's Staff, and Okta Let Them Into Snowflake
McKesson has confirmed unauthorised access to third-party applications. The attackers say they got there by te...
KE
30 Aug
Half the Carhartt Breach Data Was Fabricated
ShinyHunters claimed close to 25 million records. Troy Hunt filtered the dump before loading it and found 12,9...
KE
29 Aug
ASEAN's Record $4.12m Breach Cost Comes From 26 Companies
IBM discloses the sample size and the coverage drops it. The comparisons inside the study — 123 days faster de...
KE
29 Aug
The Dangerous Part of the UK Airports Breach Is Not 8.7 Million
Most of what was taken from Manchester, Stansted and East Midlands is wifi sign-up email. The parking and loun...
PR
29 Aug
Two Incidents Account for Half of the Philippines' 335 Million Exposed Records
Credentials are not records, records are not people, and 255 incidents are not evenly distributed. Reading Vie...
SA
25 Aug
The French Education Breach Is Being Counted in Lines, Not People
A seller advertises 346 million records from France's school systems. His own deduplicated figures are 4.35 mi...
PR
24 Aug
An Extortion Group Claimed 25 Million Records. 218,000 Appeared.
ShinyHunters listed Alcon on 2 August alleging more than 25 million Salesforce records. The data later publish...
PR
21 Aug
A Ransomware Group Posted Its Demands On The Hospital's Own Facebook Page
AnMed closed 83 medical offices after a July attack, with ten still shut a week later. On 11 August the attack...
KE
21 Aug
A Poisoned JSON Feed Made Hidden Admins on WordPress Sites
No plugin update was published. Attackers reached BdThemes storage, poisoned a feed the plugins pull into the...
CY
11 Aug
A Signup Form Sent Passwords to Facebook and Google for Nearly Two Years
Klaviyo's signup form was misconfigured so third-party marketing trackers captured what users typed, including...
CY
11 Aug
The Breach Was at the Vendor. The Notification Came From Everyone Else.
Valve, Framework and a football club all told customers about a breach this week. None of them was broken into...
KE
10 Aug
A Zero-Day in a Dashboard Tool Took Framework's Entire Customer List
Framework and Tally were both breached on 3 August through a zero-day in Metabase, the business-intelligence t...
KE
9 Aug
The Snowflake Extortionist Pleaded Guilty. The Way In Was Still Just a Password.
Connor Riley Moucka, 26, pleaded guilty on 6 August over the campaign that took data from more than 165 organi...
CY
9 Aug
Japan Logged 19,417 Data-Breach Reports in FY2025 — What the Second-Highest Total on Record Does and Doesn't Tell You
Japan's privacy regulator recorded 19,417 breach notifications in FY2025, the second-highest on record but dow...
CY
20 Jul
Qantas Was Breached, but Australia's Privacy Regulator Declined a Formal Investigation — Governance Was the Deciding Factor
Australia's privacy regulator closed its inquiry into the 2025 Qantas breach on 16 July without opening a form...
CY
20 Jul
One PeopleSoft Zero-Day, 100-Plus Victims: The July Breach Disclosures Trace to a Single Oracle Flaw
Nissan, NAIC and a wave of universities are disclosing breaches that trace to one Oracle PeopleSoft zero-day,...
CY
11 Jul
Accenture Says It Remediated an 'Isolated Matter' — a Seller Claims 35GB of Source Code and Cloud Keys
A forum seller claims to have taken 35GB of Accenture source code and cloud credentials; Accenture acknowledge...
CY
11 Jul
Medtronic Is Notifying 3.8 Million People of a Data Breach — Here's What It Means for Patients
Medtronic, the world's largest medical device maker, is notifying 3,834,294 people that a data breach of its c...
AM
11 Jul
Oracle Patches Actively Exploited PeopleSoft Zero-Day (CVE-2026-35273) as Data-Theft Campaign Hits Universities
Oracle issued an out-of-band alert on 10 June for CVE-2026-35273, a CVSS 9.8 unauthenticated remote-code-execu...
CY
16 Jun
No Zero-Day Required: ShinyHunters' Salesforce Vishing Spree Snares Charter and Carnival in One Week
Two major consumer brands confirmed breaches days apart — Carnival began notifying nearly six million people,...
CY
2 Jun
Advertisement