Reading view

There are new articles available, click to refresh the page.

Data BreachesProsper Data Breach Impacts 17.6 Million Accounts

Ionut Arghire reports: More than 17 million individuals were likely impacted by a data breach at peer-to-peer lending marketplace Prosper, data breach notification service Have I Been Pwned warns. Prosper disclosed the incident last month, noting that hackers accessed its network and stole confidential, proprietary, and personal information from its systems. According to the US-based...

Source

Gov’t seeks police probe of KT for allegedly obstructing data breach investigation

Yonhap News reports: The Ministry of Science and ICT said Monday it has asked the police to investigate allegations that KT obstructed a government probe into the company’s unauthorized mobile payment breaches. In late August, unauthorized mobile payments worth a combined 240 million won ($168,000) were reported in Seoul and nearby areas after the personal...

Source

Oracle silently fixes zero-day exploit leaked by ShinyHunters

Lawrence Abrams reports: Oracle has silently fixed an Oracle E-Business Suite vulnerability (CVE-2025-61884) that was actively exploited to breach servers, with a proof-of-concept exploit publicly leaked by the ShinyHunters extortion group. The flaw was addressed with an out-of-band security update released over the weekend, which Oracle said could be used to access “sensitive resources.” “This...

Source

Discord blamed a vendor for its data breach — now the vendor says it was ‘not hacked’

Jay Peters reports: 5CA is a customer service support company that works with Discord. Recently, the chat platform said the vendor had been breached as part of a “security incident” where 70,000 government ID photos may have leaked. Now, 5CA says in a post on its website that it was “not hacked.” According to Discord, “this incident impacted a...

Source

From sizzle to drizzle to fizzle: The massive data leak that wasn’t (1)

After days of endlessly urging Salesforce or companies to pay them so that their data would not be leaked, the deadline for Salesforce to pay came and went. And as it went, ScatteredLAPSUS$Hunters leaked data from six of the 39 companies listed on its dark web leak site. But that’s where the massive leak that...

Source

In a few days, the PowerSchool hacker will learn his sentence, and his life as he has known it will end. (1)1)

In November 2021, when “g0retrance” defaced the website of the Massachusetts Interscholastic Athletic Association (MIAA) with a message saying “PWNED,” the hacker, who also used the moniker “netsaosa,” left a message under it “should have listened to my emails instead of ignoring me … don’t worry, this is harmless. just to get ur attention :)” Boston.com...

Source

Telstra Denies Scattered Spider Data Breach Claims Amid Ransom Threats

IT Security News reports: Telstra, one of Australia’s leading telecommunications companies, has denied claims made by the hacker group Scattered Spider that it suffered a massive data breach compromising nearly 19 million personal records. The company issued a statement clarifying that its internal systems remain secure and that the data in question was scraped from...

Source

SonicWall Says All Firewall Backups Were Accessed by Hackers

Waqas reports: In September 2025, SonicWall reported a data breach of its cloud backup service, stating that fewer than 5% of its customers were affected. At the time, the issue appeared contained and under investigation. That changed today after SonicWall and incident response firm Mandiant confirmed that the attackers had accessed backup configuration files for...

Source

Discord Confirms 70,000 Government IDs Exposed in Third-Party Breach

Divya reports: The popular communication platform Discord is confronting a major extortion attempt after cybercriminals breached one of its third-party customer service providers, compromising sensitive user data including government identification photos used for age verification. Threat actors claim to have exfiltrated 1.5 terabytes of sensitive information, including over 2.1 million government-issued identification photos. However, Discord disputes these figures, stating that...

Source

Qantas says ‘legal protections in place’ as ScatteredLAPSUS$Hunters group threatens to release personal data

NOTE from DataBreaches.net: The injunction Qantas obtained is limited in terms of who it covers. It does NOT cover all journalists and media. It only covers those who are under the jurisdiction of the NSW Supreme Court. Most journalists and media are not covered by the injunction, such as DataBreaches, and many may decide to...

Source

US law firm with major political clients hacked in spying spree linked to China

Sean Lyngaas of CNN reports: Suspected Chinese government-backed hackers have breached computer systems of U.S. law firm Williams & Connolly, which has represented some of America’s most powerful politicians, as part of a larger spying campaign against multiple law firms, according to a letter the firm sent clients and a source familiar with the hack....

Source

Clop extortion emails claim theft of Oracle E-Business Suite data

Lawrence Abrams reports: Mandiant and Google are tracking a new extortion campaign where executives at multiple companies received emails claiming that sensitive data was stolen from their Oracle E-Business Suite systems. According to Genevieve Stark, Head of Cybercrime and Information Operations Intelligence Analysis at GTIG, the campaign began in late September. “This activity began on...

Source

Company that sells software for monitoring sex offenders, terrorists, and hackers was hacked

Mikael Thalen reports: A company that sells spyware that monitors individuals on parole and probation had its data leaked to a cybercrime forum this week. The leak, according to an analysis by Straight Arrow News, exposed highly sensitive information regarding employees of the corrections system and those under court-ordered supervision. The affected company, RemoteCOM, describes itself...

Source

Harrods warns customers their personal data could have been stolen by hackers in new cyber-attack

Aidan Radnedge reports: Harrods has warned some customers that their personal data could have been taken in an IT systems breach – in the latest cyber-attack to hit a major UK firm. The luxury department store based in London’s Knightsbridge said information, such as names and contact details, of its e-commerce customers was taken after...

Source

Neon, the No. 2 social app on the Apple App Store, pays users to record their phone calls and sells data to AI firms

Great investigative journalism by Zack Whittaker on TechCrunch. First, he reports: A new app offering to record your phone calls and pay you for the audio so it can sell the data to AI companies is, unbelievably, the No. 2 app in Apple’s U.S. App Store’s Social Networking section. The app, Neon Mobile, pitches itself as...

Source

ClaimPix Data Leak Exposes 5 Million Customer Records

And if there haven’t been enough recent data incidents involving car manufacturers and their vendors, here’s a leak to give wannabe criminals some additional details that they might be able to use in a phishing or social engineering campaign. WebsitePlanet reports: Cybersecurity Researcher Jeremiah Fowler discovered and reported to Website Planet about an unencrypted and non-password-protected database...

Source

Volvo Group Data Breach Affects Workforce PII

And ANOTHER automotive-related one, as reported by Claim Depot: Volvo Group North America LLC recently experienced a data breach impacting current and former employees. The cybersecurity incident involved Miljödata, a third-party supplier of human resources software used by Volvo. On Aug. 23, 2025, Miljödata discovered it had suffered a suffered a ransomware attack on Aug....

Source

Motility Data Breach Exposes Social Security Numbers & Affects 760,000 Consumers

Another hack involving the automotive sector? Claim Depot writes: On Aug. 19, 2025, Motility Software Solutions, a provider of dealer management software for specialty vehicle dealerships, identified suspicious activity on its network. The company quickly took the impacted server offline to contain the incident and began an investigation with the help of cybersecurity experts. According...

Source

❌