#data-breach

[ follow ]
Information security
fromForbes
16 hours ago

4.3 Billion Work Profiles Exposed: Scammers Now Know Where You Work

A 16TB unsecured MongoDB exposed nearly 4.3 billion professional records, enabling large-scale, AI-driven social engineering and identity-targeted scams.
Privacy professionals
fromTechCrunch
1 day ago

Data breach at credit check giant 700Credit affects at least 5.6 million | TechCrunch

A 700Credit data breach exposed names, addresses, birthdates, and Social Security numbers of at least 5.6 million people, with stolen data collected May–October 2025.
Information security
fromTechCrunch
1 day ago

Flaw in photo booth maker's website exposes customers' pictures | TechCrunch

A photo-booth company exposes customers' photos and videos online due to a website storage vulnerability, allowing easy mass download.
fromwww.standard.co.uk
1 day ago

London cinema chain Curzon warns customer data including card digits may have been exposed in technical glitch

Curzon cinema has admitted a major app failure that left dozens of customers' personal details exposed to complete strangers. The upmarket cinema chain which runs 10 venues across London plus its Curzon Home Cinema streaming service said the error meant other users could see people's names, emails, phone numbers, dates of birth, profile photos and membership tiers. In some cases, even the last four digits of saved bank cards were visible.
Information security
#lastpass
fromwww.itpro.com
1 day ago
Information security

LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users here's how the incident unfolded

fromwww.itpro.com
1 day ago
Information security

LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users here's how the incident unfolded

Artificial intelligence
fromZDNET
1 day ago

OpenAI user data was breached, but changing your password won't help - here's why

Customer data from OpenAI was exfiltrated via a Mixpanel supply-chain breach that affected API documentation visitors, causing minimal but notable impact.
#coupang
fromTechCrunch
2 days ago
Information security

CEO of South Korean retail giant Coupang resigns after massive data breach | TechCrunch

fromTechCrunch
1 week ago
Information security

Korea's Coupang says data breach exposed nearly 34M customers' personal information | TechCrunch

fromTechCrunch
2 days ago
Information security

CEO of South Korean retail giant Coupang resigns after massive data breach | TechCrunch

fromTechCrunch
1 week ago
Information security

Korea's Coupang says data breach exposed nearly 34M customers' personal information | TechCrunch

#security-misconfiguration
fromTechCrunch
1 week ago
Privacy professionals

Petco confirms security lapse exposed customers' personal data | TechCrunch

fromTechCrunch
1 week ago
Privacy professionals

Petco confirms security lapse exposed customers' personal data | TechCrunch

Information security
fromTechCrunch
3 days ago

Exclusive: Petco takes down Vetco website after exposing customers' personal information

A Petco veterinary site exposed extensive customer and pet medical records and personal data accessible without login, with at least one record indexed by Google.
#ransomware
fromTechCrunch
1 week ago
Information security

Fintech firm Marquis alerts dozens of US banks and credit unions of a data breach after ransomware attack | TechCrunch

fromTechCrunch
1 week ago
Information security

Fintech firm Marquis alerts dozens of US banks and credit unions of a data breach after ransomware attack | TechCrunch

fromTechCrunch
4 days ago

FTC upholds ban on stalkerware founder Scott Zuckerman | TechCrunch

A stalkerware maker who was banned from the surveillance industry after a data breach that exposed the personal information of its customers, as well as the people they were spying on, will not be able to go back to selling the invasive software, according the U.S. Federal Trade Commission. The FTC denied a request to cancel that ban made by Scott Zuckerman, the founder of consumer spyware company Support King and its subsidiaries SpyFone and OneClickMonitor.
Privacy technologies
fromTechCrunch
5 days ago

Petco's security lapse affected customers' SSNs, drivers' licenses and more | TechCrunch

Last week, pet products and services giant Petco confirmed that it experienced a data breach involving customers' personal information, without specifying what type of data was affected. On Friday, in a legally required filing with Texas' attorney general's office, Petco reported that the affected data included: names, Social Security numbers, driver's license numbers, financial information such as account numbers, credit or debit card numbers, and dates of birth.
Privacy professionals
Information security
fromTheregister
5 days ago

Barts Health seeks legal block after Clop steals NHS data

Barts Health had patient and staff data stolen via Clop's exploitation of Oracle EBS and is seeking a High Court order to block publication.
fromWIRED
1 week ago

Security News This Week: Oh Crap, Kohler's Toilet Cameras Aren't Really End-to-End Encrypted

An AI image creator startup left its database unsecured, exposing more than a million images and videos its users had created-the "overwhelming majority" of which depicted nudes and even nude images of children. A US inspector general report released its official determination that Defense Secretary Pete Hegseth put military personnel at risk through his negligence in the SignalGate scandal, but recommended only a compliance review and consideration of new regulations.
Privacy technologies
#cybersecurity
fromNature
3 weeks ago
Information security

Cyberattacks' harm to universities is growing - and so are their effects on research

fromNature
3 weeks ago
Information security

Cyberattacks' harm to universities is growing - and so are their effects on research

Artificial intelligence
fromWIRED
1 week ago

Huge Trove of Nude Images Leaked by AI Image Generator Startup's Exposed Database

An AI image generator startup left over one million images and videos publicly accessible, exposing nonconsensual nudified images including minors' faces swapped onto adult bodies.
#cyberattack
fromIT Pro
2 weeks ago
Information security

Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed

UK news
fromwww.standard.co.uk
2 weeks ago

Major London councils initiate emergency' plans after being hit by cyber attack

Westminster and Kensington and Chelsea councils are working with the National Cyber Security Centre after a cyberattack affecting shared IT systems, phones and encrypted files.
Information security
fromIT Pro
2 weeks ago

Wall Street giants warned of data exposure following supply chain attack

SitusAMC reported a cyberattack that may have exposed corporate and client data linked to major banks including JPMorgan, Citi, and Morgan Stanley.
fromIT Pro
2 weeks ago
Information security

Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed

fromIT Pro
2 weeks ago
Information security

Wall Street giants warned of data exposure following supply chain attack

#clop
#mixpanel
fromTechCrunch
1 week ago
Information security

A data breach at analytics giant Mixpanel leaves a lot of open questions | TechCrunch

fromTechCrunch
1 week ago
Information security

A data breach at analytics giant Mixpanel leaves a lot of open questions | TechCrunch

Privacy professionals
fromTheregister
1 week ago

Kensington and Chelsea Council confirms data breach

Kensington and Chelsea Council confirmed attackers copied and removed data during a cyber incident, prompting residents to monitor accounts and communications closely.
Privacy professionals
fromTheregister
1 week ago

FTC slaps edtech vendor after breach exposes 10M students

Illuminate Education failed to secure cloud-stored records, exposing sensitive data of 10.1 million students due to lax controls, plaintext storage, and delayed breach notifications.
#cyber-attack
UK politics
fromwww.theguardian.com
2 weeks ago

Taliban used discarded UK kit to track down Afghans who worked with west, inquiry hears

The UK left sensitive technology and data in Afghanistan, enabling the Taliban to trace and endanger Afghans who assisted Western forces.
Information security
fromTheregister
2 weeks ago

Brsk confirms breach as bidding begins for 230K+ records

British telco Brsk is investigating an unauthorized database breach exposing basic customer contact information for over 230,000 records, with affected customers offered protections.
Information security
fromIT Pro
2 weeks ago

OpenAI hailed for 'swift move' in terminating Mixpanel ties after data breach hits developers

A Mixpanel security breach exposed OpenAI developer account names, emails, location details, and limited analytics; OpenAI removed Mixpanel and is notifying affected developers.
Information security
fromTheregister
2 weeks ago

OpenAI dumps Mixpanel after analytics breach hits API users

OpenAI API platform users had profile-related account data exposed in a Mixpanel breach; ChatGPT-only users are generally unaffected unless they use the API.
Information security
fromBusiness Insider
2 weeks ago

OpenAI says hackers stole data from its analytics partner

Hackers stole some developer profile data from Mixpanel, exposing names, emails, and approximate locations of certain OpenAI API users and prompting phishing warnings.
Information security
fromTheregister
2 weeks ago

US emergency alert systems down after cyberattack

A cyberattack on Crisis24's CodeRED emergency-alert platform disrupted alerts nationwide, exposed personal data, and prompted municipalities to seek replacements or temporary communication methods.
fromTheregister
2 weeks ago

Calls grow for inquiry into UK data watchdog after MoD leak

Their demand lands amid fierce criticism of the regulator's decision not to formally investigate the Ministry of Defence over what has been described as the most serious data breach in British history: the leaking of a spreadsheet revealing the identities and locations of more than 19,000 Afghans fleeing the Taliban. Information Commissioner John Edwards defended his stance at a DSIT-hosted hearing last month, insisting the incident was a "one-off" error rather than evidence of systemic non-compliance inside the MoD.
EU data protection
Information security
fromwww.bbc.com
2 weeks ago

Scammers hacked her phone and stole thousands - so how did they get her details?

Data breaches increase risk of targeted fraud such as SIM-swap attacks that let criminals control phones and seize online accounts.
#situsamc
fromTechCrunch
2 weeks ago
Information security

US banks scramble to assess data theft after hackers breach financial tech firm | TechCrunch

fromTechCrunch
2 weeks ago
Information security

US banks scramble to assess data theft after hackers breach financial tech firm | TechCrunch

Information security
fromComputerworld
2 weeks ago

How has cloud flipped the regular security narrative?

In cloud environments, compromised identity credentials and excessive permissions allow attackers to bypass defenses and exfiltrate massive sensitive data across interconnected services.
Information security
fromTechCrunch
3 weeks ago

Google says hackers stole data from 200 companies following Gainsight breach | TechCrunch

Hackers stole Salesforce-stored data from over 200 company instances via Gainsight apps in a large-scale supply-chain breach.
fromwww.bbc.com
3 weeks ago

Teens plead not guilty over TfL cyber attack

Thalha Jubair 19, from East London, and Owen Flowers, 18, from Walsall in the West Midlands spoke only to confirm their names and enter pleas at the brief hearing. They are both charged with conspiring to commit unauthorised acts against Transport for London (TfL) under the Computer Misuse Act. In addition, Mr Flowers is accused of attempting to hack computer systems belonging to California-based Sutter Health and another US company, SSM Healthcare Corporation. Mr Jubair has also been charged with failing to provide passwords for his devices.
UK news
Information security
fromSecuritymagazine
3 weeks ago

Logitech Confirms Data Breach, Security Leaders Respond

Logitech experienced a data breach via a third-party zero-day exploit; stolen data likely included limited employee, consumer, customer, and supplier information without sensitive financial identifiers.
Information security
fromTechCrunch
3 weeks ago

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

Customer data in Salesforce connected through Gainsight-published applications was compromised, prompting investigations and a claim of responsibility by the ShinyHunters hacking group.
Law
fromAbove the Law
3 weeks ago

Morning Docket: 11.19.25 - Above the Law

Meta avoids antitrust loss; whistleblower protections targeted; major data breach; custody ruling oddities; Epstein grand jury secrecy debated; law firm merger affecting Asia.
fromwww.cbc.ca
3 weeks ago

Ontario, Alberta school boards caught unprepared in mass student data breach: provincial watchdogs | CBC News

Privacy watchdogs in Ontario and Alberta issued their findings Tuesday after investigating a mass data breach of a student information system used across Canada, concluding that school boards lacked adequate breach response plans, among other issues. Ontario's privacy commissioner says PowerSchool, a software and storage company for school systems in the U.S. and Canada, was a victim of a cyberattack and ransom threat in December 2024 that compromised the data of current and former students, parents and staff.
Canada news
Information security
fromMail Online
3 weeks ago

Mother of all data breaches sees 1.3 BILLION passwords exposed

A dataset of 1.3 billion unique passwords and 1.957 billion email addresses was exposed online, putting numerous accounts at risk.
fromTheregister
3 weeks ago

Security researcher calls BS on Coinbase breach timeline

The researcher, Jonathan Clark, says he knows this for a fact because he reported the attack to Coinbase on January 7 after the criminals tried to scam him. According to Clark, Coinbase's Head of Trust and Safety Brett Farmer responded to his "comprehensive security report" the same day he emailed it to the company's security@ address. In a blog about the incident, Clark says Farmer replied: "This report is super robust and gives us a lot to look into. We are investigating this scammer now."
Information security
Information security
fromTechCrunch
3 weeks ago

DoorDash confirms data breach impacting users' phone numbers and physical addresses | TechCrunch

DoorDash suffered a data breach exposing users' names, emails, phone numbers, and addresses; no sensitive IDs or payment info were taken, and impacted users were notified.
Information security
fromTechCrunch
3 weeks ago

Surveillance tech provider Protei was hacked, its data stolen and its website defaced | TechCrunch

Protei, a Russian-founded telecom vendor of surveillance and filtering systems, was hacked, had its website defaced, and 182GB of data stolen.
#att
fromZDNET
3 weeks ago
Privacy professionals

You can still claim your AT&T data breach settlement of up to $7,500 - how to apply for free

fromZDNET
1 month ago
Privacy professionals

AT&T customers can still claim up to $7,500 from $177M data breach settlement - here's how

fromZDNET
3 weeks ago
Privacy professionals

You can still claim your AT&T data breach settlement of up to $7,500 - how to apply for free

fromZDNET
1 month ago
Privacy professionals

AT&T customers can still claim up to $7,500 from $177M data breach settlement - here's how

Information security
fromIT Pro
3 weeks ago

Logitech says zero-day attack saw hackers copy 'certain data' from internal IT systems

Logitech experienced a cyberattack exploiting a zero-day in a third-party platform, resulting in limited exfiltration of employee, customer, and supplier data while operations remain unaffected.
Information security
fromwww.aljazeera.com
3 weeks ago

Somalia confirms major data breach in electronic visa system

Hackers breached Somalia's electronic visa platform, potentially exposing sensitive personal data of at least 35,000 travellers and prompting an official investigation and security concerns.
Information security
fromWIRED
4 weeks ago

A Major Leak Spills a Chinese Hacking Contractor's Tools and Targets

Multiple major security incidents include US seizure of Starlink hardware, Google's lawsuit over Lighthouse scam, DHS data retention, and a KnownSec leak of Chinese hacking tools and stolen datasets.
Information security
fromTheregister
4 weeks ago

Parliament blasts MoD over Afghan breach reforms

The Ministry of Defence failed to improve data protection, leaving thousands of Afghan relocation applicants' sensitive information exposed and still at risk of future breaches.
#oracle-e-business-suite
US politics
fromwww.mediaite.com
1 month ago

Congressional Budget Office Reportedly Hacked By Foreign Entity

The Congressional Budget Office experienced a suspected foreign cyberattack that may have exposed lawmakers' communications and financial research used for legislation.
Information security
fromTheregister
1 month ago

What are the most common passwords? No surprises here

Predictable numeric and keyboard-sequence passwords remain extremely common, making accounts highly vulnerable to modern cracking tools and brute-force attacks.
Privacy professionals
fromTheregister
1 month ago

Malware-pwned laptop gifts cybercriminals Nikkei's Slack

Nikkei suffered a Slack breach exposing personal details of 17,368 employees and partners after malware compromised an employee device and stole credentials.
Information security
fromTechCrunch
1 month ago

University of Pennsylvania confirms hacker stole data during cyberattack | TechCrunch

A hacker breached University of Pennsylvania development and alumni systems, exfiltrating data and sending fraudulent emails from official @upenn.edu addresses.
Information security
fromSecuritymagazine
1 month ago

1.2M Individuals' Data Stolen In University Hacking

A cyber incident at the University of Pennsylvania led to mass malicious emails and alleged theft of personal data of about 1.2 million community members.
fromThe Verge
1 month ago

Alleged U Penn hacker claims they're in it for money, not 'primarily "anti-DEI"'

A person claiming to be one of the University of Pennsylvania hackers says that about "1.2 million lines of data" will be kept private for the group to sell before it is made public. The group also plans to make other documents public. In comments to The Verge, the hacker or hackers distanced themselves from earlier hacks of other private universities including Columbia - which were aimed at demonstrating colleges had maintained unlawful pro-diversity policies.
US politics
Privacy professionals
fromDataBreaches.Net
1 month ago

Veradigm's Breach Claims Under Scrutiny After Dark Web Leak - DataBreaches.Net

An unauthorized party accessed Veradigm client data on December 15, 2024, after obtaining a credential from a client breach, exposing personal and health information.
fromDataBreaches.Net
1 month ago

UK: Woman charged after NHS patients' records accessed in data breach - DataBreaches.Net

Today's reminder of the insider threat comes to us from the National Health Service in the U.K. Craig Meighan and Billy Gaddi report: A woman has been charged after Scots patients had their private medical records accessed during an NHS data breach. Reports suggest around 100 patients in NHS Lothian could have had their records accessed as a result of the incident. The health board said it discovered patients in the region may have had their information "inappropriately accessed" during routine monitoring.
Privacy professionals
fromDataBreaches.Net
1 month ago

Landmark civil penalty of AU$5.8 million issued under Australia's Privacy Act - DataBreaches.Net

On 9 October 2025 the Federal Court of Australia (the Court) imposed an AU$5.8 million civil penalty on Australian Clinical Labs Limited, one of Australia's largest private hospital pathology service providers (the Company), for systemic failures that led to the unauthorised access to and exfiltration of the sensitive personal information of more than 223,000 individuals.
Privacy professionals
Information security
fromDataBreaches.Net
1 month ago

Massive Great Firewall Leak Exposes 500GB of Censorship Data - DataBreaches.Net

A roughly 600 GB leak exposed over 100,000 internal GFW-related documents, source code, configs, and operational materials revealing censorship tool development and testing methods.
fromWIRED
1 month ago

Hundreds of People With 'Top Secret' Clearance Exposed by House Democrats' Website

While scanning for unsecured databases at the end of September, an ethical security researcher stumbled upon the exposed cache of data and discovered that it was part of a site called DomeWatch. The service is run by the House Democrats and includes videostreams of House floor sessions, calendars of congressional events, and updates on House votes. It also includes a job board and résumé bank.
Privacy professionals
Information security
fromZDNET
1 month ago

Your logins could be among 180M just added to Have I Been Pwned - how to check for free

Have I Been Pwned added two breached-account datasets — 183 million records and 3.9 million MyVidster-related accounts — exposing emails and associated passwords.
Information security
fromTheregister
1 month ago

Iran's MOIS-linked Ravin Academy hit by data breach

Ravin Academy, an Iranian cyber training school tied to intelligence, suffered a breach exposing names, phone numbers, and other personal data of associates and students.
fromSecuritymagazine
1 month ago

40B Records Exposed From Marketing and Email Data Platform

An unencrypted, non-password-protected database was discovered by Cybersecurity Researcher Jeremiah Fowler. This database contained files from an email marketing platform and held approximately 40 billion records (13 TB). The records appeared to belong to Netcore Cloud Pvt. Ltd (Netcore), an India-based company providing marketing services. Fowler sent a message to Netcore to inform them of the exposure, and the database was restricted the same day.
Privacy professionals
[ Load more ]