❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 26 June 2026DataBreaches.Net

Third Defendant Sentenced To Prison For Hacking DraftKings

By: Dissent
25 June 2026 at 17:04
NATHAN AUSTAD, one of three people indicted for hacking DraftKings in 2022 has now been sentenced to 18 months in prison. In April, a second man, KAMERIN STOKES, a/k/a β€œTheMFNPlug,” was sentenced to 30 months in prison for his role, while JOSEPH GARRISON was sentenced in 2024 to 18 months: United States Attorney for the...

Source

Yesterday β€” 25 June 2026DataBreaches.Net

How Hackers Broke into Madison Square Garden

By: Dissent
24 June 2026 at 09:50
Joseph Cox reports: The hackers that stole a large cache of data from Madison Square Garden called a low level employee and tricked them into letting the hackers into MSG’s systems, according to the hackers and 404 Media’s review of the stolen data. …  404 Media downloaded the full 45GB data dump and found the...

Source

Tata Electronics confirms cyberattack as hackers leak data

By: Dissent
24 June 2026 at 09:17
Bill Toulas reports: Tata Electronics has confirmed in a statement to BleepingComputer that it was the target of a cyberattack that impacted parts of its IT infrastructure. The company emphasizes that its operations continued to run normally and were not affected by the incident. […] While Tata Electronics has not disclosed the threat actor’s identity,...

Source

LastPass says hackers stole customer support case data during Klue breach

By: Dissent
24 June 2026 at 09:16
Password manager LastPass is still dealing with the settlement from its 2022 data breach (see Related Posts, below, for background on that), but now it has another breach to disclose. Zack Whittaker reports: Password manager maker LastPass is notifying customers that their personal information and customer support case records were stolen during a recent hack...

Source

Before yesterdayDataBreaches.Net

Two men, believed to part of Scattered Spiders, plead guilty over Β£39m TfL cyber attack

By: Dissent
22 June 2026 at 15:17
Two members of Scattered Spider, who were arrested in 2024 and 2025, have reportedly changed their pleas to guilty just before their trials were set to begin. Victoria Collins reports: Two men have pleaded guilty to offences in connection with a massive cyber attack which caused Transport for London (TfL) months of disruption and cost...

Source

Xsolis breach affected 1,396,519 of its clients’ patients

By: Dissent
22 June 2026 at 12:04
Xsolis, Inc. is a business associate in the healthcare sector, providing utilization and case management services. They describe themselves as applying β€œindustry-leading AI and automation to ensure appropriate care settings and accelerate collaboration across a connected network of providers and payers.” On June 19, California Attorney General’s Office posted a copy of a breach notification...

Source

Brazil’s Civil Defense suffers a cyberattack on its official alert network

By: Dissent
21 June 2026 at 15:13
This is the kind of cyberattack that can put lives at risk and makes me want to wring some necks if I wasn’t so old and feeble. DemΓ³crata reports: Brazil’s Civil Defense has reported this Saturday that its official alert system has been the target of a cyberattack, an incident that is already being investigated...

Source

Klue OAuth breach victim list grows as Icarus hackers claim attack

By: Dissent
21 June 2026 at 11:01
Lawrence Abrams reports: Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce environments, as the new β€œIcarus” extortion group publicly claims the attack. The disclosure comes after cybersecurity firmsΒ HuntressΒ andΒ ReliaQuestΒ detailed how attackers abused compromised Klue Battlecards integrations to steal Salesforce...

Source

Global Schools Group Obtained Two Court Injunctions That Didn’t Seem to Change Muchβ€”and Might Backfire (1)

By: Dissent
20 June 2026 at 09:01
Following a major data security incident involving sensitive student and parent information, Global Schools Group sought court injunctions prohibiting the publication of data acquired by FulcrumSec. They obtained the injunctions, but once again, injunctions do not affect threat actors β€” or at least, not in the way the plaintiffs hoped.Β  Yesterday, DataBreaches reported that Global...

Source

Texas government data breach allowed hackers to steal 3 million driver’s licenses and passports

By: Dissent
18 June 2026 at 20:57
Zack Whittaker reports: A data breach at a Texas state government department allowed hackers to take the driver’s license information and passport numbers of more than 3 million people,Β according toΒ the state’s attorney general. The incident is one of the largest data breaches to affect the state this year. In a data breach notice on theΒ Texas...

Source

Data analysis of the Global Schools Group breach, Part 2

By: Dissent
18 June 2026 at 12:59
In Part 1,Β  DataBreaches published some totals and aggregate data from the recent Global Schools Group data breach. All analyses and statistics were provided to this site by FulcrumSec, who had attacked Global Schools Group (GSG) and exfiltrated the data. Data from three of GSG’s school brands were included in Part 1. Data for the...

Source

Data analysis of the Global Schools Group breach, Part 1

By: Dissent
18 June 2026 at 10:46
This is the first part of a two-part report of findings from the Global Schools Group data breach. All statistical analyses and findings were provided to DataBreaches by FulcrumSec, and are presented to assist those investigating the breach as well as parents and employees who might be concerned as to what types of data were...

Source

Cybercriminals Are Targeting EdTech: Data Breaches and Ransomware Attacks on the Rise

By: Dissent
17 June 2026 at 07:48
Resecurity writes: The education technology (EdTech) sector has become a prime target for cybercriminals as attacks against educational institutions and related platforms continue to escalate. With sensitive data, including student records, employee information, and payment data, stored on EdTech systems, the sector has become an appealing target for cybercriminals seeking financial gain, data exploitation, and...

Source

JLR ordered 30,000 staff to reset passwords in person after cyberattack

By: Dissent
15 June 2026 at 07:31
Aimee Turner reports: Jaguar Land Rover ordered all 30,000 employees to reset their passwords in person following a cyberattack that raised concerns staff credentials had been compromised. Speaking at Infosecurity Europe, former Jaguar Land Rover chief information security officer Ashish Shrestha revealed the company required employees to physically verify their identity before resetting passwords after...

Source

AU: American Express ordered to fix security gaps after customer was spied on

By: Dissent
15 June 2026 at 07:03
Harriet Alexander and Julie Lewis report: The privacy watchdog has ordered American Express to rectify security flaws in five of its data systems to guard against β€œinsider threats” and to restrict employee access to specific customer information to protect vulnerable and high-profile customers. Privacy Commissioner Carly Kind found the payments giant had β€œfailed to implement...

Source

UK: Hotel guests issued urgent β€˜check’ alert as personal details stolen from major chain

By: Dissent
14 June 2026 at 09:51
Elaine Blackburne reports: Hotel guests have been warned to stay alert for convincing fraudulent messages following a data breach at a major hotel chain. Personal information belonging to individuals with reservations at one of the chain’s properties was compromised over a six-month period. BWH Hotels, the parent company behind WorldHotels, Best Western Hotels & Resorts,...

Source

South Korea Hands Coupang a Record-Breaking $409 Million Data Privacy Fine

By: Dissent
13 June 2026 at 09:20
DataBreaches has been impressed by South Korea’s response to data breaches ever since reading about how its financial regulator responded to three credit card companies whose customers suffered a major data leak. Unlike any enforcement action DataBreaches had ever seen levied here in the U.S., the firms had their ability to enroll new customers suspended...

Source

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

By: Dissent
12 June 2026 at 12:30
From Mandiant and Google Threat Intelligence Group, an advisory: Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation ofΒ CVE-2026-35273, a critical remote...

Source

Former Saydel schools IT worker sentenced for Iowa cyber sabotage

By: Dissent
12 June 2026 at 07:53
Today’s reminder of the insider threat is brought to us by DysruptionHub: A former Saydel Community School District information technology worker in Iowa was sentenced June 11 after prosecutors said he disrupted school technology systems used by students and staff. The disruptions affected classroom technology, staff accounts and district-managed devices after Ezekiel Dean Potter left...

Source

WA: Chelan County enters third week of disruptions with no recovery timeline

By: Dissent
10 June 2026 at 19:42
On June 8, Andrew Simpson reported: Β Chelan County entered its third week of system-wide disruptions Monday following a malware incident discovered over Memorial Day weekend, with officials saying they still do not have a timeline for restoring affected systems. According to a June 8 update, county officials became aware of malware affecting the county network...

Source

❌
❌