❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayDataBreaches.Net

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

By: Dissent
23 September 2026 at 16:59
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Latvia arrests suspected hacker for electronics repair company breach

By: Dissent
23 September 2026 at 11:51
Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — using similar methods — was discovered in early September at TSC, an electronics repair...

Source

Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?

By: Dissent
17 September 2026 at 08:07
Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affected by the breach STILL haven’t been notified.  Since April, DataBreaches has reported Navigate360’s lack of public transparency about the...

Source

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

By: Dissent
17 September 2026 at 07:40
Swati Khandelwal reports: A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up...

Source

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected? (1)

By: Dissent
14 September 2026 at 09:03
Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law firm listings on Silent Ransom Group’s (SRG’s) leak site. As...

Source

AT&T store worker gets 16 months inside for SIM-swap side hustle

By: Dissent
13 September 2026 at 10:50
Connor Jones reports: A former AT&T retail worker who used his system access to hijack customers’ phone numbers for cybercriminals has been sentenced to 16 months in federal prison. Kenneth Carter, 44, carried out the SIM swaps at a store in Portland, Oregon, , allowing the criminals to intercept authentication codes and raid victims’ bank accounts....

Source

Not just Korea: Google leaked identifying info for sex crime victims across the world

By: Dissent
12 September 2026 at 18:29
Shin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hankyoreh has confirmed. “Photos of me from when I was a minor were distributed without my consent. They were posted on an...

Source

Weverse Data Leak Affects More Than 422,000 K-Pop Fan Accounts

By: Dissent
7 September 2026 at 08:30
kbizoom reports: Weverse, the fan platform operated by HYBE-affiliated Weverse Company, has confirmed a security incident that affected 422,584 user accounts. The company said the exposed information consisted mainly of internal identifiers that cannot be used outside the platform. “We received a notification from the Korea Internet & Security Agency (KISA) on September 3 that...

Source

Ledger faces $500 million class action over data breaches

By: Dissent
4 September 2026 at 07:17
Pavlo Kot reports: ​Hardware crypto wallet maker Ledger is facing a class action seeking at least $500 million over a series of customer data breaches. The plaintiff claims the company failed to adequately protect customers’ personal information and did not take sufficient measures following previous incidents. The lawsuit was filed on August 27 by Ledger user Douglas...

Source

FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans

By: Dissent
4 September 2026 at 07:17
Pierluigi Paganini reports: A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New Orleans field office opened a formal investigation the same day. Brian Krebs at KrebsOnSecurity, who broke the story, traced...

Source

TR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ data

By: Dissent
4 September 2026 at 07:17
The Turkish Data Protection Authority (KVKK) investigation into the data breach at the famous restaurant chain Baydöner, where the full names, phone numbers, emails, and city information of 505,337 customers were compromised, has been completed. The investigation found that there was no alarm mechanism to detect unusual system activity, and Baydöner was fined a total...

Source

A massive cache of Valve data has reportedly leaked online, appearing to include Portal 2’s elusive beta build and a potential weapon from Half-Life 2: Episode 3

By: Dissent
30 August 2026 at 11:26
Rick Lane reports: A massive cache of internal builds from Valve has reportedly leaked online, including beta builds of several classic Valve titles and possible weapons from Half-Life 2’s cancelled third episode. The leak, which began circulating on Saturday and comes from an unknown source, includes 12 terabytes of data currently being sifted through by data miners. The...

Source

SCOOP: Some Click2Mail customers will soon be receiving notification of a data security incident

By: Dissent
29 August 2026 at 10:03
On August 27, DataBreaches woke up to a message request on Signal that read, “Click2mail.com checkout with a debit card, website is actively hijacked. Card gets sold to fraudsters. It’s happened twice.” DataBreaches accepted the request, and learned that the customer who contacted us first experienced a problem on June 2, and then again the...

Source

Manchester Airports Group confirms cyber attack exposed customer emails, phone numbers and vehicle details

By: Dissent
27 August 2026 at 11:22
Gabriel Higgins reports: Manchester Airports Group (MAG) has confirmed that it has been the target of a cybersecurity incident carried out by an unauthorised third party, resulting in the exposure of a quantity of customer data. The group operates Manchester, London Stansted and East Midlands airports, and said the breach relates to information gathered through car...

Source

ShinyHunters provided no real proof they hacked ReliaQuest– because they didn’t get anywhere: ReliaQuest

By: Dissent
24 August 2026 at 07:36
Yesterday, DataBreaches reported that ShinyHunters had added ReliaQuest to its dedicated leak site, but without any substantive proof — only a few screenshots showing access to a user account on reliaquest.okta[.]com/enduser/settings. ReliaQuest did not reply to DataBreaches’ email inquiry, but they have published an entire blog post responding to the claims. Without naming ShinyHunters, they write, in...

Source

ShinyHunters claims hack of ReliaQuest; no confirmation by ReliaQuest (1)

By: Dissent
23 August 2026 at 11:07
Cybersecurity firm ReliaQuest has reported its research findings about ShinyHunters multiple times recently. On August 17,  @ReliaQuestTR tweeted that they were tracking yet another ShinyHunters campaign. But after another forum user replied on August 23 with some screenshots and a pithy “Who’s hunting who?” ReliaQuestTR deleted their tweet and hasn’t posted anything on that account...

Source

Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNs

By: Dissent
21 August 2026 at 12:28
In April, Silent Ransom Group’s (SRG)* leak site listed 38 law firms that had not paid them and whose data was leaked. By June 29, there were 48 law firms. Now there are 64, and, in somewhat surprising claims, SRG says a recent attack was actually its second on one law firm, and they will...

Source

Largest Applebee’s franchisee says hackers stole sensitive data

By: Dissent
20 August 2026 at 09:17
Amar Ćemanović reports: Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident. The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, and biometric information. The total number of affected people remains unclear, but state filings indicate that at...

Source

Prison for data analyst who tried to extort $2.5 million from his employer

By: Dissent
19 August 2026 at 10:04
There’s an update to a previously reported case of a disgruntled former employee who tried to extort his employer, Brightly Software.  Graham Cluley reports: When Cameron Curry discovered that his contract as a data analyst wasn’t going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume....

Source

More than 2 million user records from TaxAct allegedly acquired; 450k already leaked (with correction)

By: Dissent
17 August 2026 at 09:23
On August 13, DataBreaches was contacted anonymously on Signal by someone reporting that they had acquired more than 2 million records with clients’ phone numbers, usernames, and email addresses from TaxAct, which is owned by Cinven. TaxAct operates under its parent company and holding entity, Taxwell. Not all the phone numbers were real, they reported,...

Source

❌
❌