Normal view

There are new articles available, click to refresh the page.
Yesterday — 10 August 2026Main stream

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

By: Dissent
9 August 2026 at 08:24
Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’s according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data...

Source

Before yesterdayMain stream

Boston Children’s Hospital named in North Korean hacking operation

By: Dissent
7 August 2026 at 13:37
Naomi Diaz reports: Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired reported Aug. 5. The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device. Mr. Stykas, chief technology officer at...

Source

What Canvas learned from a massive cyberattack

By: Dissent
7 August 2026 at 09:39
Alcino Donadel reports: …. Instructure, the edtech company behind learning management system Canvas, suffered one of the largest data breaches in the U.S. this year after cybercriminals gained access through a third-party vendor—an increasingly common occurrence in higher ed. Higher education’s more meditative, governed approach to technological change is useful for reviewing rigor and long-term quality assurance, Pendleton...

Source

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

By: Dissent
3 August 2026 at 08:33
The Herald Business reports: Seoul Facilities Corp. has drawn criticism over its plan to offer 5,000 won [$3.50 USD] per affected user in response to a personal data breach involving about 4.62 million people, with questions mounting over whether the compensation is adequate. Seoul Metropolitan Council member Im Gyu-ho of the Democratic Party of Korea...

Source

Weaponizing Exposed Data

By: Dissent
31 July 2026 at 12:48
Lab-1 Dark-web Research Team Contributors:Alex Necula, Anastasia Sentasnova, Ellis Stannard, Jeffrey Bell, Manuel Boll, Valéry Rieß-Marchive Mannie W writes: Ransomware and data-extortion groups are moving beyond bulk dumps to analyze, index and price stolen data before it is published or sold — removing the “weaponization tax” and turning breaches into searchable, tranched and targetable assets....

Source

Ransomware in Italy: RedACT report sheds light on an evolving threat environment

By: Dissent
31 July 2026 at 12:44
SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report, published by ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the collection, verification, and analysis...

Source

Crime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent Vector

By: Dissent
30 July 2026 at 10:15
Crime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to accelerate the arrest of cybercriminals in the INC Ransomware Cybercrime-as-a-Service group as well as...

Source

Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. (Corrected)

By: Dissent
27 July 2026 at 15:20
Three times may be a charm for some things, but not for data security incidents. Frontier Airlines allegedly has had a third data security incident this year. First, it was BobDaHacker publishing a blog post on June 16 titled “Your Boarding Pass Is a Skeleton Key.” Frontier Airlines Doesn’t Care. According to the post, Frontier...

Source

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

By: Dissent
24 July 2026 at 08:49
Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on this breach are at the end of this article.  Background In 1976, an Albuquerque detective had...

Source

Greedy ransomware crews return for seconds after victims cough up first extortion payments

By: Dissent
22 July 2026 at 10:34
Connor Jones reports: Authorities have long warned organizations not to pay ransoms, and fresh figures underline why: handing over the money doesn’t mean the crooks leave you alone. Proofpoint survey data suggests that 58 percent of affected UK organizations paid a ransom. Worse, 22 percent of those who pay get extorted again anyway. The UK...

Source

Milford, New Hampshire Confirms Unauthorized Activity, Withholds Details of Suspected Cyberattack (1)

By: Dissent
21 July 2026 at 20:01
Milford, New Hampshire is a quintessential New England town. But charm is no defense against cyberattackers, and it appears that the town may have been attacked last week. As DysruptionHub was the first to report, the town began experiencing problems early on July 15.  Town email alerts, shared with DataBreaches by a town resident, reveal...

Source

Pay up or not? Ransomware surge has victims facing tough choices.

By: Dissent
21 July 2026 at 18:02
Hannah Murphy reports: Nearly half of companies that are targets of a ransomware cyber attack end up paying a ransom to release their data or systems, according to 2025 research from cybersecurity group Sophos, while the median amount demanded is rising. Globally, some jurisdictions are responding by banning payments to hackers. In the UK, for...

Source

Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.

By: Dissent
20 July 2026 at 07:36
On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators. A DataBreaches.net Editorial In March 2026, the world learned that a hacktivist had acquired 8.3 million...

Source

The Breach That Won’t End: An Update on Canvas, and how they created an EdTech’s Vendor Trust Problem

By: Dissent
16 July 2026 at 16:46
Jeff Piontek comments on the Instructure breach: The forensic review has taken far longer than anyone expected. Through June, Instructure was still finalizing customer-specific findings and asking institutions to designate a security contact to receive them. In early July, the company began delivering the first wave of institution-specific data packets, through a permissioned file-sharing link...

Source

Italy fines WINDTRE €1.7 million over data breaches

By: Dissent
16 July 2026 at 12:53
Gianluca Semeraro reports:  Italy’s data protection authority has fined telecoms operator WINDTRE €1.7 million ($1.94 million) for “serious shortcomings” in ​its data security systems, leading ‌to two unauthorised breaches and the exposure of personal information belonging to more than 365,000 customers. • The investigation was prompted by the CK ‌Hutchison ​owned company’s notification of ⁠the...

Source

AU: Regulator’s preliminary findings did not indicate Qantas breached privacy obligations

By: Dissent
16 July 2026 at 07:55
Vlad Constantinescu reports that the Office of the Australian Information Commissioner has determined that although the Qantas data breach of 2025 resulted in 5.67 million customer records being compromised and leaked, the regulator’s preliminary inquiry did not indicate that Qantas was likely to have breached the country’s privacy rules. The attack began when an attacker...

Source

Finland issues wanted notice for hacker behind massive psychotherapy data breach

By: Dissent
14 July 2026 at 17:12
I was really unpleasantly surprised when they let him out while on appeal, and now they may not be able to return him to prison?  Did no one foresee that he might not stick around to be sent back to prison? Daryna Antoniuk reports: Finnish police have reportedly issued a wanted notice for convicted hacker Aleksanteri...

Source

Rewards For Justice offers reward for info on Media Land, ML.Cloud, and three individuals associated with it

By: Dissent
14 July 2026 at 16:54
Rewards for Justice announced a $10M reward for information on the Russian-based bulletproof hosting (BPH) services company Media Land, its associated company ML.Cloud, and associated staff Aleksandr Alexandrovich Volosovik, Kirill Andreevich Zatolokin, and Yuliya Vladimirovna Pankova: Media Land offers BPH services such as hosting illicit and illegal content, registering private domains on behalf of customers,...

Source

Defending SaaS-based applications against ShinyHunters OAuth abuse

By: Dissent
14 July 2026 at 14:53
From Microsoft Security Research and Microsoft Defender Security Research Team: In a series of campaigns observed between mid-2025 and mid-2026, Microsoft identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply chain compromise, and misconfigured guest access to target customer SaaS-based applications such as Salesforce instances. The threat actors...

Source

Uniondale Union Free School District – Audit Follow-Up by New York State Comptroller (2023M-61-F)

By: Dissent
8 July 2026 at 15:27
In October 2023, NYS Comptroller Thomas DiNapoli released an IT audit of the Uniondale Union Free School District on Long Island. The purpose of the audit was to examine management of non-student user network controls.  The audit report found, in part: District officials did not adequately manage nonstudent network user accounts and permissions. As a...

Source

❌
❌