#data-breach

[ follow ]
Privacy professionals
fromDataBreaches.Net
2 hours ago

Flagstar Agrees to $31.5 Million Deal in Accellion-Breach Suit - DataBreaches.Net

Flagstar Bank agreed to pay $31.5 million to settle claims over breaches that exposed nearly 2.2 million individuals' personal information.
Miscellaneous
fromwww.berkeleyside.org
2 hours ago

UC Berkeley is about to go to Mars

Berkeley faces multiple local crises: data exposure of city rentals, protests over antisemitism probe, discontinued survivor hotline, new diversion program, traffic injuries.
#cybersecurity
fromDataBreaches.Net
2 weeks ago
Privacy professionals

Survival Flight reports second cybersecurity incident in less than a year - DataBreaches.Net

Survival Flight experienced a cybersecurity incident on July 17 exposing patient names, addresses, medical treatment details and health insurance information; investigation and notifications are ongoing.
fromSecuritymagazine
2 weeks ago
Information security

Security Leaders Discuss Restaurant Brands International's Vulnerabilities

RBI systems exposed drive‑through audio and employee data due to basic security failures like hardcoded/default credentials.
#extortion
fromDataBreaches.Net
3 hours ago
Information security

Hackers say they have deleted children's pictures and data after nursery attack backlash - DataBreaches.Net

fromDataBreaches.Net
3 hours ago
Information security

Hackers say they have deleted children's pictures and data after nursery attack backlash - DataBreaches.Net

#ransomware
Information security
fromTheregister
6 days ago

Volvo NA staff data stolen in third-party ransomware attack

Volvo North America employee names and social security numbers were exposed after a ransomware attack on HR system provider Miljödata.
Information security
fromwww.standard.co.uk
1 week ago

Hackers steal children's names, pictures and addresses from nursery chain with 18 branches in London

Hackers stole sensitive personal data, including photos and safeguarding details, of about 8,000 children from Kido nurseries and attempted ransomware extortion.
#red-hat
fromDataBreaches.Net
4 hours ago
Information security

Red Hat confirms security incident after hackers breach GitLab instance - DataBreaches.Net

Crimson Collective claims to have stolen nearly 570GB from a Red Hat GitLab instance, including about 800 Customer Engagement Reports with sensitive client details.
fromTechzine Global
15 hours ago
Information security

Red Hat hit by GitHub breach: 570GB stolen, including client info

Crimson Collective stole nearly 570GB from Red Hat, including data from 28,000 internal projects and about 800 Customer Engagement Reports containing sensitive credentials.
#cyberattack
fromSecurityWeek
4 days ago
EU data protection

British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach

fromSecurityWeek
4 days ago
EU data protection

British Department Store Harrods Warns Customers That Some Personal Details Taken in Data Breach

fromSecurityWeek
14 hours ago

1.2 Million Impacted by WestJet Data Breach

The stolen information includes names, addresses, dates of birth, government-issued ID details, and other information that customers shared in relation to their travel needs, including accommodation requests and complaints. For WestJet Rewards members, membership details, such as WestJet Rewards ID number and points balance, and other account information may have been compromised as well. The airline is providing the impacted individuals with 24 months of free monitoring, identity theft protection, and proactive fraud assistance services, which include up to $1 million of expense reimbursement insurance.
Canada news
fromSecurityWeek
16 hours ago

Cybercriminals Claim Theft of Data From Oracle E-Business Suite Customers

According to Google Threat Intelligence Group (GTIG) and Mandiant, the malicious activity allegedly targeting Oracle EBS appears to have started on or around September 29. The attackers have sent extortion emails to executives at "numerous" companies, claiming to be affiliated with the notorious Cl0p cybercrime group. GTIG and Mandiant researchers have described the attacks as a high-volume email campaign leveraging hundreds of compromised accounts, including ones previously linked to a profit-driven threat group named FIN11.
Information security
Information security
fromSecurityWeek
18 hours ago

1.5 Million Impacted by Allianz Life Data Breach

A July breach of a third-party CRM exposed personal data, including Social Security numbers, of about 1.497 million Allianz Life customers, professionals, and employees.
#cybercrime
#privacy
fromElectronic Frontier Foundation
1 day ago
Privacy professionals

EFF Is Standing Up for Federal Employees-Here's How You Can Stand With Us

OPM's sharing of sensitive federal employee data violated privacy protections and federal workers' safety; direct donations to EFF support privacy and free-expression defense.
fromDataBreaches.Net
1 week ago
Privacy professionals

No Need to Hack When It's Leaking: App for outing Charlie Kirk's critics leaked its users' personal data - DataBreaches.Net

Cancel the Hate, an app for reporting alleged critics of Charlie Kirk, leaked users' personal data including emails and phone numbers and was taken offline.
fromDataBreaches.Net
1 week ago
Privacy professionals

No Need to Hack When It's Leaking: App for outing Charlie Kirk's critics leaked its users' personal data - DataBreaches.Net

Information security
fromTechCrunch
1 day ago

Data breach at Canadian airline WestJet affects 1.2M passengers | TechCrunch

A cyberattack stole personal data of 1.2 million WestJet passengers, including identification and reward information, possibly linked to the Scattered Spider hacking group.
Information security
fromTheregister
1 day ago

3.7M breach letters set to flood North America's mailboxes

Approximately 3.7 million North American customers and employees had personal data exposed in breaches affecting Allianz Life, WestJet, and another US tech company.
US politics
fromNew York Post
2 days ago

NJ gov candidate Mikie Sherrill's military file release probed by watchdog after she claimed it was political hit-job

The National Archives' watchdog is investigating the unauthorized release of Mikie Sherrill's full military file containing un-redacted personal data.
fromBusiness Matters
2 days ago

HSBC warns UK business banking customers of third-party data breach

I provided passport details in good faith to HSBC as it was necessary for identification before opening up a business account. Now I'm worried that money will be taken out of the company account by crooks, with the third-party platform having been hacked. Worse, that my passport details could be sold on the dark web. I had reservations about providing ID proof in the first place because cyber attacks are now so prevalent but you put your trust in the banks to get online security right, first
Privacy professionals
#harrods
fromIT Pro
3 days ago
Information security

Harrods rejects contact with hackers, after 430,000 customer records stolen from third-party provider

fromIT Pro
3 days ago
Information security

Harrods rejects contact with hackers, after 430,000 customer records stolen from third-party provider

fromNextgov.com
3 days ago

'Widespread' breach let hackers steal employee data from FEMA and CBP

A "widespread cybersecurity incident" at the Federal Emergency Management Agency allowed hackers to make off with employee data from both the disaster management office and U.S. Customs and Border Protection, according to a screenshot of an incident overview presentation obtained by Nextgov/FCW. The hack is also suspected to have later triggered the dismissal of two dozen Federal Emergency Management Agency technology employees announced late last month, according to internal meeting notes and a person familiar with the matter.
Information security
EU data protection
fromComputerWeekly.com
3 days ago

Harrods hit by second cyber attack in six months | Computer Weekly

Harrods suffered a third-party data breach exposing over 400,000 customer records with names, contact details, and some marketing labels; passwords and payment details were not taken.
fromSecuritymagazine
4 days ago

WestJet Notifies American Consumers of Data Breach

Unfortunately, WestJet confirmed that certain data was obtained from its systems. Since making that determination, WestJet conducted an analysis of that data to identify specific data elements and locate current contact information for certain United States residents who were impacted. As of September 15, 2025, WestJet completed that analysis and as a result is providing this notice. No credit card or debit card numbers, expiry dates and CVV numbers, and no guest user passwords were obtained.
Information security
#child-privacy
fromIT Pro
3 days ago
Information security

Kido nursery hackers threaten to release more details - along with the personal data of 100 employees

fromIT Pro
3 days ago
Information security

Kido nursery hackers threaten to release more details - along with the personal data of 100 employees

Information security
fromDataBreaches.Net
5 days ago

Company that sells software for monitoring sex offenders, terrorists, and hackers was hacked - DataBreaches.Net

Spyware vendor RemoteCOM leaked sensitive data exposing nearly 6,900 corrections employees and about 14,000 monitored individuals, revealing detailed personal and officer information across 49 states.
#cyber-attack
fromDataBreaches.Net
5 days ago
Information security

Harrods warns customers their personal data could have been stolen by hackers in new cyber-attack - DataBreaches.Net

fromIT Pro
1 week ago
UK news

Co-op chief executive 'very proud' of cyber attack response despite huge financial losses

fromDataBreaches.Net
5 days ago
Information security

Harrods warns customers their personal data could have been stolen by hackers in new cyber-attack - DataBreaches.Net

fromIT Pro
1 week ago
UK news

Co-op chief executive 'very proud' of cyber attack response despite huge financial losses

#att
fromZDNET
6 days ago
US news

You can claim up to $7,500 from AT&T's $177M data breach payouts - how to qualify

fromZDNET
1 week ago
Privacy professionals

You can claim up to $7,500 from AT&T's $177M data breach payouts - but the deadline is soon

fromZDNET
6 days ago
US news

You can claim up to $7,500 from AT&T's $177M data breach payouts - how to qualify

fromZDNET
1 week ago
Privacy professionals

You can claim up to $7,500 from AT&T's $177M data breach payouts - but the deadline is soon

Information security
fromwww.theguardian.com
6 days ago

Kido nursery hackers threaten to publish more children's profiles

A cybercrime group named Radiant hacked Kido nurseries, obtained thousands of children's personal data and photos, and is extorting the company with publication threats.
Information security
fromSecurityWeek
6 days ago

In Other News: LockBit 5.0, Department of War Cybersecurity Framework, OnePlus Vulnerability

New Department of War CSRMC, Dragos Platform 3.0, a 3-million-record Lotte Card breach, and LockBit ransomware developments mark notable cybersecurity events.
#salesforce
fromZDNET
1 week ago
Information security

Battered by cyberattacks, is Salesforce facing a trust problem?

fromZDNET
1 week ago
Information security

Battered by cyberattacks, is Salesforce facing a trust problem?

Privacy professionals
fromDataBreaches.Net
6 days ago

Neon, the No. 2 social app on the Apple App Store, pays users to record their phone calls and sells data to AI firms - DataBreaches.Net

Neon Mobile paid users to record phone calls for sale to AI companies and rose to No.2 on the U.S. App Store before a security flaw exposed call data.
Information security
fromTechCrunch
6 days ago

Exclusive: Thousands of Indian bank transfer records found online

An unsecured Amazon-hosted cloud server exposed 273,000 Indian bank transfer PDFs, revealing account numbers, transaction amounts, and personal contact details across at least 38 banks.
fromFast Company
1 week ago

DOGE put your Social Security Number on a cloud server with up to a 65% risk of getting hacked: Senate report

copied Americans' sensitive Social Security and employment data into a cloud database without any verified security controls,
US politics
Healthcare
fromDataBreaches.Net
1 week ago

Verily Faces Lawsuit Over Alleged HIPAA Violations - DataBreaches.Net

Verily allegedly misused personally identifiable health information of over 25,000 patients and failed to file required HIPAA breach notifications.
fromDataBreaches.Net
1 week ago

Motility Data Breach Exposes Social Security Numbers & Affects 760,000 Consumers - DataBreaches.Net

On Aug. 19, 2025, Motility Software Solutions, a provider of dealer management software for specialty vehicle dealerships, identified suspicious activity on its network. The company quickly took the impacted server offline to contain the incident and began an investigation with the help of cybersecurity experts. According to Motility, the breach resulted in unauthorized access to the personally identifiable information (PII) of approximately 760,000 consumers in the United States.
Information security
#lotte-card
fromDataBreaches.Net
1 week ago
Information security

Lotte Card reissues 650,000 cards after data leak, protects 1.28 million customers - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Lotte Card reissues 650,000 cards after data leak, protects 1.28 million customers - DataBreaches.Net

#boyd-gaming
Information security
fromSecurityWeek
1 week ago

Automotive Titan Stellantis Discloses Data Breach

Stellantis experienced a data breach via a third-party platform that exposed North American customer contact information; no financial or sensitive personal data were accessed.
EU data protection
fromTheregister
1 week ago

EV charging biz zaps customers with data leak scare

Digital Charging Solutions reported unauthorized access to customer data by a third-party customer service provider, prompting investigations, security measures, notifications to authorities and affected customers.
#stellantis
fromTechCrunch
1 week ago
Information security

Automaker giant Stellantis says customers' personal data stolen during breach | TechCrunch

fromTechCrunch
1 week ago
Information security

Automaker giant Stellantis says customers' personal data stolen during breach | TechCrunch

Information security
fromComputerWeekly.com
1 week ago

Teen charged with Las Vegas casino cyber heist | Computer Weekly

A teenage suspect surrendered and faces multiple charges for Scattered Spider cyberattacks that disrupted MGM and Caesars, causing major losses and data theft.
#dhs
fromThe Local France
1 week ago

Data from French government ANTS website 'not for sale on the dark web'

Over the weekend it was widely reported in French media that a group of hackers had breached the government's ANTS website, stealing personal data from between 12 and 13 million people. The unidentified group posted messages online claiming that the personal data was now for sale on the dark web, offering sample data to apparently prove that their hack had been successful.
Information security
Business
fromDataBreaches.Net
1 week ago

Data Leak? Crypto.com Fires Back At 'Unfounded' Allegations - DataBreaches.Net

Crypto.com denies concealing a 2023 breach, reports it affected very few users, involved limited PII, and customer funds were not at risk.
Information security
fromWIRED
1 week ago

Security News This Week: A Dangerous Worm Is Eating Its Way Through Software Packages

Multiple serious security failures and threats emerged this week, including government data exposure, critical identity-management flaws, hypersonic missile tests, and advanced SMS-scamming techniques.
Information security
fromIT Pro
1 week ago

The Salesloft hackers claim they have 1.5 billion compromised Salesforce records

Threat actors claim theft of over 1.5 billion records via Salesloft Drift attacks using social engineering and malicious OAuth tokens to access Salesforce instances.
fromSecurityWeek
2 weeks ago

Tiffany Data Breach Impacts Thousands of Customers

According to the notification sent out to impacted individuals, a threat actor gained unauthorized access to Tiffany systems on or around May 12, 2025. An investigation revealed that the attacker obtained information associated with Tiffany gift cards, including name, email address, postal address, phone number, sales data, gift card number, and PIN. The luxury goods company informed the Maine Attorney General's Office that more than 2,500 individuals are impacted by the data breach. It's unclear if that number includes the affected Canadian customers.
Information security
Information security
fromSecurityWeek
2 weeks ago

SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations

SonicWall prompted affected customers to reset passwords after hackers accessed encrypted backup firewall preference files stored in a cloud service.
fromDataBreaches.Net
2 weeks ago

Tiffany discloses data breach involving gift cards - second breach disclosure in recent months - DataBreaches.Net

Tiffany writes that they experienced a cybersecurity incident on or around May 12, 2025. "Based on our investigation, we determined on September 9, 2025, that, in connection with this issue, an unauthorized party obtained certain information related to your Tiffany gift card(s)," the letter states, adding, "The affected information included client name, postal address, email address, phone number, sales data, internal client reference number, and Tiffany gift card number and PIN."
Information security
fromIT Pro
2 weeks ago

Nearly 700,000 customers impacted after insider attack at US fintech firm

A US-based fintech firm has warned customers their data may have been exposed following an insider attack.
Information security
fromIT Pro
2 weeks ago

Hackers behind Jaguar Land Rover announce their 'retirement' - should we believe them?

The Scattered Lapsus$ Hunters hacking group, recently linked to the attack on Jaguar Land Rover that has devastated the company, has announced that it plans to shut down.
Information security
#kering
fromSecurityWeek
2 weeks ago

689,000 Affected by Insider Breach at FinWise Bank

"FinWise contracts with AFF to offer installment loans to consumers. In this arrangement, FinWise is the lender and AFF is the technology provider. FinWise originates the loan and provides funds to the consumer. AFF is contracted to provide the application platform, facilitate the loan origination for FinWise, as well as service the loan on behalf of FinWise," FinWise explained in its notification. "Please note that you may have had, or applied for, a FinWise installment loan, a lease-to-own account, or a retail installment sales agreement account with AFF which was impacted by this security incident," impacted people have been told.
Information security
fromwww.bbc.com
2 weeks ago

Gucci, Balenciaga and Alexander McQueen private data ransomed by hackers

Cyber criminals have stolen the private details of potentially millions of Balenciaga, Gucci and Alexander McQueen customers in an attack. The stolen data includes names, email addresses, phone numbers, addresses and the total amount spent in the luxury stores around the world. Kering, the parent company of the luxury brands, has confirmed the breach and says it disclosed the incident to the relevant data protection authorities.
Information security
[ Load more ]