#data-breach

[ follow ]
#cyber-attack
Information security
fromTheregister
5 hours ago

OpenAI dumps Mixpanel after analytics breach hits API users

OpenAI API platform users had profile-related account data exposed in a Mixpanel breach; ChatGPT-only users are generally unaffected unless they use the API.
Information security
fromTechzine Global
6 hours ago

OpenAI sees API data breach via Mixpanel hack

OpenAI terminated its use of Mixpanel after a Mixpanel systems breach exported limited API customer identification and analytics data, creating phishing and social engineering risks.
#ransomware
fromDataBreaches.Net
1 month ago
Law

Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach - DataBreaches.Net

fromDataBreaches.Net
1 month ago
Law

Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach - DataBreaches.Net

Information security
fromBusiness Insider
10 hours ago

OpenAI says hackers stole data from its analytics partner

Hackers stole some developer profile data from Mixpanel, exposing names, emails, and approximate locations of certain OpenAI API users and prompting phishing warnings.
#cyberattack
fromIT Pro
10 hours ago
Information security

Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed

fromIT Pro
3 days ago
Information security

Wall Street giants warned of data exposure following supply chain attack

fromIT Pro
10 hours ago
Information security

Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposed

fromIT Pro
3 days ago
Information security

Wall Street giants warned of data exposure following supply chain attack

Information security
fromTheregister
1 day ago

US emergency alert systems down after cyberattack

A cyberattack on Crisis24's CodeRED emergency-alert platform disrupted alerts nationwide, exposed personal data, and prompted municipalities to seek replacements or temporary communication methods.
#cybersecurity
fromNature
6 days ago
Information security

Cyberattacks' harm to universities is growing - and so are their effects on research

fromNature
6 days ago
Information security

Cyberattacks' harm to universities is growing - and so are their effects on research

#clop
fromTheregister
2 days ago
Information security

Clop's Oracle EBS rampage reaches Dartmouth College

Dartmouth College suffered data theft after Clop exploited an Oracle E-Business Suite zero-day, exposing names, SSNs, and some financial account information.
fromTheregister
2 weeks ago
Information security

Allianz UK confirms Oracle EBS compromise

Clop gang exploited an Oracle E-Business Suite vulnerability to compromise Allianz UK customer data, affecting 80 current and 670 former customers while LV systems remained unaffected.
fromTheregister
2 days ago

Calls grow for inquiry into UK data watchdog after MoD leak

Their demand lands amid fierce criticism of the regulator's decision not to formally investigate the Ministry of Defence over what has been described as the most serious data breach in British history: the leaking of a spreadsheet revealing the identities and locations of more than 19,000 Afghans fleeing the Taliban. Information Commissioner John Edwards defended his stance at a DSIT-hosted hearing last month, insisting the incident was a "one-off" error rather than evidence of systemic non-compliance inside the MoD.
EU data protection
Information security
fromwww.bbc.com
2 days ago

Scammers hacked her phone and stole thousands - so how did they get her details?

Data breaches increase risk of targeted fraud such as SIM-swap attacks that let criminals control phones and seize online accounts.
#situsamc
fromTechCrunch
3 days ago
Information security

US banks scramble to assess data theft after hackers breach financial tech firm | TechCrunch

fromTechCrunch
3 days ago
Information security

US banks scramble to assess data theft after hackers breach financial tech firm | TechCrunch

Information security
fromComputerworld
3 days ago

How has cloud flipped the regular security narrative?

In cloud environments, compromised identity credentials and excessive permissions allow attackers to bypass defenses and exfiltrate massive sensitive data across interconnected services.
Information security
fromTechCrunch
6 days ago

Google says hackers stole data from 200 companies following Gainsight breach | TechCrunch

Hackers stole Salesforce-stored data from over 200 company instances via Gainsight apps in a large-scale supply-chain breach.
fromwww.bbc.com
6 days ago

Teens plead not guilty over TfL cyber attack

Thalha Jubair 19, from East London, and Owen Flowers, 18, from Walsall in the West Midlands spoke only to confirm their names and enter pleas at the brief hearing. They are both charged with conspiring to commit unauthorised acts against Transport for London (TfL) under the Computer Misuse Act. In addition, Mr Flowers is accused of attempting to hack computer systems belonging to California-based Sutter Health and another US company, SSM Healthcare Corporation. Mr Jubair has also been charged with failing to provide passwords for his devices.
UK news
Information security
fromSecuritymagazine
6 days ago

Logitech Confirms Data Breach, Security Leaders Respond

Logitech experienced a data breach via a third-party zero-day exploit; stolen data likely included limited employee, consumer, customer, and supplier information without sensitive financial identifiers.
#salesforce
fromTechCrunch
1 week ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

fromDataBreaches.Net
1 month ago
Information security

Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials - DataBreaches.Net

fromTechCrunch
1 week ago
Information security

Salesforce says some of its customers' data was accessed after Gainsight breach | TechCrunch

fromDataBreaches.Net
1 month ago
Information security

Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials - DataBreaches.Net

Law
fromAbove the Law
1 week ago

Morning Docket: 11.19.25 - Above the Law

Meta avoids antitrust loss; whistleblower protections targeted; major data breach; custody ruling oddities; Epstein grand jury secrecy debated; law firm merger affecting Asia.
fromwww.cbc.ca
1 week ago

Ontario, Alberta school boards caught unprepared in mass student data breach: provincial watchdogs | CBC News

Privacy watchdogs in Ontario and Alberta issued their findings Tuesday after investigating a mass data breach of a student information system used across Canada, concluding that school boards lacked adequate breach response plans, among other issues. Ontario's privacy commissioner says PowerSchool, a software and storage company for school systems in the U.S. and Canada, was a victim of a cyberattack and ransom threat in December 2024 that compromised the data of current and former students, parents and staff.
Canada news
Information security
fromMail Online
1 week ago

Mother of all data breaches sees 1.3 BILLION passwords exposed

A dataset of 1.3 billion unique passwords and 1.957 billion email addresses was exposed online, putting numerous accounts at risk.
fromTheregister
1 week ago

Security researcher calls BS on Coinbase breach timeline

The researcher, Jonathan Clark, says he knows this for a fact because he reported the attack to Coinbase on January 7 after the criminals tried to scam him. According to Clark, Coinbase's Head of Trust and Safety Brett Farmer responded to his "comprehensive security report" the same day he emailed it to the company's security@ address. In a blog about the incident, Clark says Farmer replied: "This report is super robust and gives us a lot to look into. We are investigating this scammer now."
Information security
Information security
fromTechCrunch
1 week ago

DoorDash confirms data breach impacting users' phone numbers and physical addresses | TechCrunch

DoorDash suffered a data breach exposing users' names, emails, phone numbers, and addresses; no sensitive IDs or payment info were taken, and impacted users were notified.
Information security
fromTechCrunch
1 week ago

Surveillance tech provider Protei was hacked, its data stolen and its website defaced | TechCrunch

Protei, a Russian-founded telecom vendor of surveillance and filtering systems, was hacked, had its website defaced, and 182GB of data stolen.
#att
fromZDNET
1 week ago
Privacy professionals

You can still claim your AT&T data breach settlement of up to $7,500 - how to apply for free

fromZDNET
3 weeks ago
Privacy professionals

AT&T customers can still claim up to $7,500 from $177M data breach settlement - here's how

fromZDNET
1 month ago
Privacy professionals

AT&T customer? Claim up to $7,500 from $177M data breach settlement - don't miss the new deadline

fromZDNET
1 week ago
Privacy professionals

You can still claim your AT&T data breach settlement of up to $7,500 - how to apply for free

fromZDNET
3 weeks ago
Privacy professionals

AT&T customers can still claim up to $7,500 from $177M data breach settlement - here's how

fromZDNET
1 month ago
Privacy professionals

AT&T customer? Claim up to $7,500 from $177M data breach settlement - don't miss the new deadline

Information security
fromIT Pro
1 week ago

Logitech says zero-day attack saw hackers copy 'certain data' from internal IT systems

Logitech experienced a cyberattack exploiting a zero-day in a third-party platform, resulting in limited exfiltration of employee, customer, and supplier data while operations remain unaffected.
Information security
fromwww.aljazeera.com
1 week ago

Somalia confirms major data breach in electronic visa system

Hackers breached Somalia's electronic visa platform, potentially exposing sensitive personal data of at least 35,000 travellers and prompting an official investigation and security concerns.
Information security
fromWIRED
1 week ago

A Major Leak Spills a Chinese Hacking Contractor's Tools and Targets

Multiple major security incidents include US seizure of Starlink hardware, Google's lawsuit over Lighthouse scam, DHS data retention, and a KnownSec leak of Chinese hacking tools and stolen datasets.
Privacy professionals
fromwww.theguardian.com
1 week ago

Personal details of Tate galleries job applicants leaked online

Personal details of 111 applicants to a Tate website developer role were leaked online, exposing addresses, salaries, referees' mobile numbers and emails.
#ministry-of-defence
#oracle-e-business-suite
fromTechCrunch
2 weeks ago
Information security

Washington Post confirms data breach linked to Oracle hacks | TechCrunch

The Washington Post was affected by a breach of the Oracle E-Business Suite tied to the Clop ransomware campaign.
fromTheregister
1 month ago
Information security

Envoy caught in Clop's Oracle EBS raid

Envoy Air's Oracle E-Business Suite was compromised, exposing limited business contact data while customer data and American Airlines systems remained unaffected.
US politics
fromwww.mediaite.com
2 weeks ago

Congressional Budget Office Reportedly Hacked By Foreign Entity

The Congressional Budget Office experienced a suspected foreign cyberattack that may have exposed lawmakers' communications and financial research used for legislation.
Information security
fromTheregister
3 weeks ago

What are the most common passwords? No surprises here

Predictable numeric and keyboard-sequence passwords remain extremely common, making accounts highly vulnerable to modern cracking tools and brute-force attacks.
Privacy professionals
fromTheregister
3 weeks ago

Malware-pwned laptop gifts cybercriminals Nikkei's Slack

Nikkei suffered a Slack breach exposing personal details of 17,368 employees and partners after malware compromised an employee device and stole credentials.
Information security
fromTechCrunch
3 weeks ago

University of Pennsylvania confirms hacker stole data during cyberattack | TechCrunch

A hacker breached University of Pennsylvania development and alumni systems, exfiltrating data and sending fraudulent emails from official @upenn.edu addresses.
Information security
fromSecuritymagazine
3 weeks ago

1.2M Individuals' Data Stolen In University Hacking

A cyber incident at the University of Pennsylvania led to mass malicious emails and alleged theft of personal data of about 1.2 million community members.
fromThe Verge
3 weeks ago

Alleged U Penn hacker claims they're in it for money, not 'primarily "anti-DEI"'

A person claiming to be one of the University of Pennsylvania hackers says that about "1.2 million lines of data" will be kept private for the group to sell before it is made public. The group also plans to make other documents public. In comments to The Verge, the hacker or hackers distanced themselves from earlier hacks of other private universities including Columbia - which were aimed at demonstrating colleges had maintained unlawful pro-diversity policies.
US politics
Privacy professionals
fromDataBreaches.Net
3 weeks ago

Veradigm's Breach Claims Under Scrutiny After Dark Web Leak - DataBreaches.Net

An unauthorized party accessed Veradigm client data on December 15, 2024, after obtaining a credential from a client breach, exposing personal and health information.
fromDataBreaches.Net
3 weeks ago

UK: Woman charged after NHS patients' records accessed in data breach - DataBreaches.Net

Today's reminder of the insider threat comes to us from the National Health Service in the U.K. Craig Meighan and Billy Gaddi report: A woman has been charged after Scots patients had their private medical records accessed during an NHS data breach. Reports suggest around 100 patients in NHS Lothian could have had their records accessed as a result of the incident. The health board said it discovered patients in the region may have had their information "inappropriately accessed" during routine monitoring.
Privacy professionals
fromDataBreaches.Net
3 weeks ago

Landmark civil penalty of AU$5.8 million issued under Australia's Privacy Act - DataBreaches.Net

On 9 October 2025 the Federal Court of Australia (the Court) imposed an AU$5.8 million civil penalty on Australian Clinical Labs Limited, one of Australia's largest private hospital pathology service providers (the Company), for systemic failures that led to the unauthorised access to and exfiltration of the sensitive personal information of more than 223,000 individuals.
Privacy professionals
Information security
fromDataBreaches.Net
3 weeks ago

Massive Great Firewall Leak Exposes 500GB of Censorship Data - DataBreaches.Net

A roughly 600 GB leak exposed over 100,000 internal GFW-related documents, source code, configs, and operational materials revealing censorship tool development and testing methods.
fromWIRED
1 month ago

Hundreds of People With 'Top Secret' Clearance Exposed by House Democrats' Website

While scanning for unsecured databases at the end of September, an ethical security researcher stumbled upon the exposed cache of data and discovered that it was part of a site called DomeWatch. The service is run by the House Democrats and includes videostreams of House floor sessions, calendars of congressional events, and updates on House votes. It also includes a job board and résumé bank.
Privacy professionals
Information security
fromZDNET
3 weeks ago

Your logins could be among 180M just added to Have I Been Pwned - how to check for free

Have I Been Pwned added two breached-account datasets — 183 million records and 3.9 million MyVidster-related accounts — exposing emails and associated passwords.
Information security
fromTheregister
1 month ago

Iran's MOIS-linked Ravin Academy hit by data breach

Ravin Academy, an Iranian cyber training school tied to intelligence, suffered a breach exposing names, phone numbers, and other personal data of associates and students.
fromSecuritymagazine
1 month ago

40B Records Exposed From Marketing and Email Data Platform

An unencrypted, non-password-protected database was discovered by Cybersecurity Researcher Jeremiah Fowler. This database contained files from an email marketing platform and held approximately 40 billion records (13 TB). The records appeared to belong to Netcore Cloud Pvt. Ltd (Netcore), an India-based company providing marketing services. Fowler sent a message to Netcore to inform them of the exposure, and the database was restricted the same day.
Privacy professionals
Information security
fromTechCrunch
4 weeks ago

Tata Motors confirms it fixed security flaws, which exposed company and customer data | TechCrunch

Tata Motors' E-Dukaan portal exposed AWS private keys and sensitive data, granting access to customer information, internal reports, dealer data, and over 70 TB files.
Information security
fromTechCrunch
4 weeks ago

LG Uplus is latest South Korean telco to confirm cybersecurity incident | TechCrunch

LG Uplus reported a suspected data breach to KISA amid multiple South Korean telecom cyberattacks, with investigations ongoing and national cybersecurity capacity strained.
Privacy technologies
fromIT Pro
4 weeks ago

Google says reports of a 'huge' Gmail breach affecting millions of users are false, again

Google says reports of a massive Gmail breach are inaccurate and result from misunderstanding of aggregated infostealer databases, with user protections intact.
fromTheregister
4 weeks ago

EY exposed 4TB SQL backup file to open web, researchers say

"Finding a 4TB SQL backup exposed to the public internet is like finding the master blueprint and the physical keys to a vault, just sitting there," it said. "With a note that says 'free to a good home.' [The lead researcher had] investigated breaches that started with less. Way less. He once traced an entire ransomware incident back to a single web.config file that leaked a connection string. That was 8 kilobytes. This was four terabytes.
Information security
Information security
fromIT Pro
3 weeks ago

US telco confirms hackers breached systems in stealthy state-backed cyber campaign - and remained undetected for nearly a year

State-sponsored hackers breached Ribbon Communications' networks in December 2024 and remained undetected for nearly a year, affecting customer files on two laptops.
East Bay real estate
fromwww.berkeleyside.org
3 weeks ago

Pacific Steel site sold in step toward major new life sciences campus

Berkeley experienced major development proposals, infrastructure improvements, campus controversies and data breaches, public safety and community events affecting residents across housing, transit, and university spheres.
Canada news
fromwww.cbc.ca
1 month ago

Toys 'R' Us Canada notifies customers that personal information might have been compromised in breach | CBC News

Toys "R" Us Canada experienced a customer data breach exposing names, addresses, emails and phone numbers, but not passwords or payment details.
Privacy professionals
fromDataBreaches.Net
1 month ago

Kaufman County's data breach was their second one in three weeks - DataBreaches.Net

Kaufman County experienced two data breaches in October that may have exposed residents' personal information, including Social Security numbers.
fromBusiness Insider
1 month ago

Apple is cracking down on those viral 'Tea' apps, citing persistent privacy concerns

A spokesperson for Apple told Business Insider that both apps were removed for not meeting "requirements around content moderation and user privacy, in addition to receiving an excessive number of user complaints and negative reviews - including complaints of minors' personal information being posted in the apps." The spokesperson added that for Apple, the general approach after discovering a violation is to communicate with the app developer to bring the platform up to standard.
Apple
fromTheregister
1 month ago

Cifas exposes dozens of email addresses in invite mishap

Anti-fraud nonprofit Cifas was left red-faced after sending out a calendar invite that exposed the email addresses of dozens of individuals working across the fraud space. The invite was sent in August to a session scheduled for October 16 about the organization's JustMe app, which allows individuals to confirm if applications made in their name are genuine. Over a dozen addresses were exposed in the To field, with another 45 in the CC field, according to the message.
EU data protection
fromDataBreaches.Net
1 month ago

Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees - DataBreaches.Net

On October 16 and 17, the ScatteredLAPSUS$Hunters Telegram channel repeatedly violated Telegram's TOS by leaking personal information on people - and in this case, information on employees of the Department of Justice (DOJ/FBI), U.S. Attorneys Office (DOJ/USAO), the Department of Homeland Security (DHS), and the Federal Aviation Authority (FAA). DataBreaches did not report on it at the time precisely because the files were still exposed. Instead, DataBreaches contacted Telegram to inquire why the channel hadn't been banned again for leaking sensitive information about government employees.
Information security
fromDataBreaches.Net
1 month ago

Data BreachesProsper Data Breach Impacts 17.6 Million Accounts - DataBreaches.Net

More than 17 million individuals were likely impacted by a data breach at peer-to-peer lending marketplace Prosper, data breach notification service Have I Been Pwned warns.Prosper disclosed the incident last month, noting that hackers accessed its network and stole confidential, proprietary, and personal information from its systems. According to the US-based company, the attackers queried its database containing customer information and applicant data to exfiltrate the information, but did not access user accounts.
Information security
Information security
fromTheregister
1 month ago

Have I Been Pwned logs 17.6M victims in Prosper breach

A September cyberattack on Prosper allegedly exposed personal data for about 17.6 million people, including Social Security numbers and various identity and contact details.
fromwww.amny.com
1 month ago

Column | Final Phase for NY Cybersecurity Regulation: Is Your Financial Institution in Compliance? | amNewYork

In August, the New York State Department of Financial Services reached agreement with Healthplex, Inc., a licensed insurance agent and independent adjuster, to pay a $2 million civil penalty after a hacker executed a phishing attack on an employee's email and gained access to the private health data and sensitive nonpublic information of tens of thousands of Healthplex consumers. Eight years in the making, the final phase of New York's groundbreaking Cybersecurity Regulation Part 500 takes effect Nov. 1.
Information security
Information security
fromWordtothewise
1 month ago

B2B Spam: Strapi, Unstructured and Reo

A unique email given to Strapi for a demo later received unsolicited promotional mail from an unrelated company, indicating a possible unauthorized exposure of Strapi customer contact data.
fromZDNET
1 month ago

New deadline: Claim up to $7,500 from AT&T's $177M data breach payouts - here's how

If you're a current or former AT&T customer, the deadline to file a claim to be part of the $177 million class-action settlement over two major data breaches has been extended. The breaches -- one dating back to 2019 and a second in 2024 -- exposed Social Security numbers, call and text records, names, addresses, dates of birth, and more.
US news
Privacy professionals
fromDataBreaches.Net
1 month ago

Integris Health Agrees to $30 Million Settlement Over 2023 Data Breach - DataBreaches.Net

Integris Health agreed to a $30 million settlement after a November 2023 breach exposed over two million patients' sensitive data, creating substantial fraud and identity theft risk.
Information security
fromDataBreaches.Net
1 month ago

Gov't seeks police probe of KT for allegedly obstructing data breach investigation - DataBreaches.Net

KT allegedly obstructed a government probe into unauthorized mobile-payment breaches by submitting false server disposal timing information and concealing backup logs and evidence.
Information security
fromTheregister
1 month ago

Sotheby's finds its data on the block after cyberattack

Sotheby's disclosed a July 24 cyber breach exposing sensitive data, including Social Security numbers and financial account information, affecting at least two Maine residents.
[ Load more ]