❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 25 September 2026Security/Privacy

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

By: Dissent
24 September 2026 at 12:35
Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,...

Source

Before yesterdaySecurity/Privacy

FBI Hack Exposed FBI’s Own Hacking Unit

By: Dissent
23 September 2026 at 19:52
Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and...

Source

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

By: Dissent
23 September 2026 at 16:59
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Latvia arrests suspected hacker for electronics repair company breach

By: Dissent
23 September 2026 at 11:51
Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair...

Source

Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign

By: Dissent
22 September 2026 at 17:30
Sorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursing and medical students locked out of exams and simulation charting, the real blast radius...

Source

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)

By: Dissent
22 September 2026 at 14:43
Joseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. The data breach could be massively...

Source

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang (1)

By: Dissent
19 September 2026 at 10:04
Lawrence Abrams reports: The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which...

Source

Gemini Hacked Three Companies in First Known Breakout by Google’s AI

By: Dissent
19 September 2026 at 07:13
Erin Woo and Robert McMillan report: Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. The hacks, which the company confirmed on Friday, occurred in May as part of a test run by the...

Source

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

By: Dissent
17 September 2026 at 07:40
Swati Khandelwal reports: A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up...

Source

Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack

By: Dissent
15 September 2026 at 07:48
Emma Kirk reports: A school in Perth’s north has been targeted in a cyber attack, with hackers stealing students and families’ personal information. St James Anglican School, in Perth’s north, identified a cyber breach involving unauthorised access into its computer systems. Parents were advised the school immediately contained the cyber security incident and secured its...

Source

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected? (1)

By: Dissent
14 September 2026 at 09:03
Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law firm listings on Silent Ransom Group’s (SRG’s) leak site. As...

Source

ShinyHunters expose 6.4M in attack on medical supplier McKesson

By: Dissent
10 September 2026 at 09:31
Connor Jones reports: McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply...

Source

Hackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guys

By: Dissent
7 September 2026 at 12:37
Carly Page reports: Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sunday that around 4,000 BTC had been withdrawn from...

Source

Personal Data of Approximately 220,000 Domestic and International Gangnam Unni Users Leaked

By: Dissent
7 September 2026 at 08:31
Lee Seunghyeong reports: Personal information of approximately 220,000 domestic and international users has been leaked from Gangnam Unni, a beauty medical platform operated by Healing Paper. On September 7, Healing Paper announced through a public notice that on September 4, there was abnormal access to the integration feature (API) used to view consultation records, resulting...

Source

US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure

By: Dissent
6 September 2026 at 07:11
Jonathan Greig reports: A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accused Yaryab of directing multiple Iranian hacking groups that have targeted “critical infrastructure sectors including defense, news, shipping,...

Source

French Police Arrest Suspected ZeroBytes Hacker Over Tax Data Theft

By: Dissent
5 September 2026 at 14:10
Waqas reports: French authorities have detained an 18-year-old man suspected of belonging to ZeroBytes, a hacking group that claimed responsibility for several attacks targeting French government services and companies. The Paris prosecutor’s office disclosed the case on September 4, according to reports from French media. However, the suspect was arrested on August 18, formally placed...

Source

TR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ data

By: Dissent
4 September 2026 at 07:17
The Turkish Data Protection Authority (KVKK) investigation into the data breach at the famous restaurant chain Baydöner, where the full names, phone numbers, emails, and city information of 505,337 customers were compromised, has been completed. The investigation found that there was no alarm mechanism to detect unusual system activity, and Baydöner was fined a total...

Source

CNIL: Health data breach: €500,000 fine imposed on the Loire Private Hospital

By: Dissent
3 September 2026 at 19:45
On September 3, 2026, the CNIL issued a €500,000 fine against the Loire Private Hospital, for not having taken appropriate measures to ensure the security of the data of its patients and some of their relatives. During the summer of 2025, an attacker managed to connect to the  electronic patient record (EPR) of the Loire Private...

Source

Two “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it.

By: Dissent
3 September 2026 at 17:44
Sometimes, first impressions are wrong. And in the case of “Nephrology Associates,” DataBreaches mistakenly thought one victim was attacked by two different groups. But no, there are actually two unrelated entities with the same name that suffered attacks this year. And only one of them has disclosed it. The Kansas Incident On March 7, The...

Source

Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners

By: Dissent
2 September 2026 at 16:23
Daryna Antoniuk reports: Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, which raises money for civilians in Ukraine affected by Russia’s invasion, and You Are Not Alone, a project supporting...

Source

❌
❌