❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 25 September 2026DataBreaches.Net

OpenAI agent breached Australian government health website, Albanese says

By: Dissent
24 September 2026 at 17:07
Alexander Martin reports: An OpenAI agent gained β€œunauthorized access” to β€œnon-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said Wednesday. The agent β€” an AI system designed to carry out tasks autonomously β€” accessed a public portal for Medicare statistics, Albanese said at a press conference in New York...

Source

Stevens Point servers go offline, city officials not sure if caused by a cyberattack

By: Dissent
24 September 2026 at 13:30
Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after several city computer servers went offline early Wednesday, disrupting municipal phone and email services and leaving employees unable to access some city systems. District 4 Councilwoman Andrea Olson said city IT employees notified staff and council members of a cyberattack in a 6:51...

Source

Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals

By: Dissent
24 September 2026 at 13:30
From the DOJ: Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creation and operation of Rydox, an illicit website and marketplace for cybercriminals to buy, sell and trade stolen personal information, and to access devices and other tools for carrying out cybercrime and fraud. β€œThe guilty plea of Ardit Kutleshi...

Source

Two Maryland hospitals still dealing with system issues after cyberattack

By: Dissent
24 September 2026 at 12:35
On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring systems at two Maryland hospitals after they were hit by a cyberattack earlier this month. The company said in an online update that its telephone capabilities at Anne Arundel Medical Center and Doctors Community Medical Center in Lanham have been restored...

Source

Wyoming courts investigate extent of personal data exposed in cybersecurity breach

By: Dissent
24 September 2026 at 12:35
Maggie Mullen reports: The Wyoming Judicial Branch says it’s awaiting more details regarding the scope of a cybersecurity breach of a third-party software company that may have included a decade’s worth of data from the state’s court system. West Publishing Corporation, which the Wyoming Supreme Court and Wyoming district courts previously used for case management,...

Source

Error on North Carolina jury duty website exposed people’s social security numbers, medical records, more

By: Dissent
24 September 2026 at 12:33
Kudos to WBTV for following up on an astute observer’s vulnerability report. David Hodges reports: North Carolina residents summoned for jury duty received notice through a letter in the mail but to request an exemption from jury duty in North Carolina, a person can go online and fill out a jury excuse form. Zach Duda...

Source

Yesterday β€” 24 September 2026DataBreaches.Net

FBI Hack Exposed FBI’s Own Hacking Unit

By: Dissent
23 September 2026 at 19:52
Joseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and...

Source

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

By: Dissent
23 September 2026 at 16:59
A new dedicated leak site by threat actors calling themselves β€œThe Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Ryuk Ransomware Operator Sentenced to 24 Months in Prison

By: Dissent
23 September 2026 at 12:00
Abinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal prison sentence followed by 3 years of supervised release, according to the U.S. Attorney’s...

Source

Latvia arrests suspected hacker for electronics repair company breach

By: Dissent
23 September 2026 at 11:51
Daryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second β€” using similar methods β€” was discovered in early September at TSC, an electronics repair...

Source

The EU spent billions on a cyberattack shield β€” nobody checked if it worked

By: Dissent
23 September 2026 at 10:10
The EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on. Jonathan Bent reports: Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own auditors found that when that funding is passed on to third...

Source

Before yesterdayDataBreaches.Net

Elsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect Campaign

By: Dissent
22 September 2026 at 17:30
Sorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit is dominated by nursing and medical students locked out of exams and simulation charting, the real blast radius...

Source

ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1)

By: Dissent
22 September 2026 at 14:43
Joseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data β€œon all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse. The data breach could be massively...

Source

Israeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companies

By: Dissent
22 September 2026 at 11:21
Amir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael β€œMiki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The group itself has no connection to the charges. According to the indictment, Bar...

Source

Spokane Public Schools takes some systems offline after β€˜network security incident’

By: Dissent
22 September 2026 at 09:05
Shannon Moudy reports: Some systems are offline Monday after Spokane Public Schools says it experienced an overnight β€˜network security incident.’ In an email sent to families Monday, the district says the situation is being investigated. β€œOut of an abundance of caution, we have chosen to take several of our systems offline. As a result, families...

Source

Early Scattered Spider member pleads guilty to cybercrime spree

By: Dissent
22 September 2026 at 09:05
Matt Kapko reports: Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy...

Source

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang (1)

By: Dissent
19 September 2026 at 10:04
Lawrence Abrams reports: The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. The attack began Friday night when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which...

Source

National Cancer Centre e-mail lapse allegedly exposes patients’ details

By: Dissent
19 September 2026 at 08:45
The mistaken cc: breach still happens.Β  Ann Neo reports: An invitation to an event sent by the National Cancer Centre Singapore (NCCS) has sparked privacy concerns after a mailing list exposed the identities, contact details and, in some instances, workplaces of individuals with a genetic cancer condition. The e-mail, an invitation to a Living with...

Source

Gemini Hacked Three Companies in First Known Breakout by Google’s AI

By: Dissent
19 September 2026 at 07:13
Erin Woo and Robert McMillan report: Google’sΒ Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. The hacks, which the company confirmed on Friday, occurred in May as part of a test run by the...

Source

HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics for Security Rule Violations

By: Dissent
18 September 2026 at 20:47
WASHINGTON β€” September 17, 2026 β€” The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity...

Source

❌
❌