❌

Normal view

There are new articles available, click to refresh the page.
Yesterday — 24 September 2026Main stream

Canva hacked via vendor’s Salesforce instance; Other customers affected as well

By: Dissent
23 September 2026 at 16:59
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked...

Source

Before yesterdayMain stream

The U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?

By: Dissent
18 September 2026 at 15:56
As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to the breach?  When the Navigate360 breach first broke, DDoSecrets.org called it “BlueLeaks 2.0” because of the...

Source

Port of LA Fended Off 120 Million Cyberattacks in August

By: Dissent
17 September 2026 at 11:48
PYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by Bloomberg News, which notes that these attacks on America’s busiest container hub for global trade represent an ongoing operational threat amid shifting tariff policies. Gene Seroka, the port’s executive director, told the news...

Source

EU chief wants joint response to cyberattacks, sabotage

By: Dissent
17 September 2026 at 11:48
Alexander Martin reports: European Commission President Ursula von der Leyen proposed on Wednesday an emergency mechanism allowing any EU country to summon the bloc’s governments in response to security threats including sabotage, cyberattacks and drone incursions. Delivering her annual State of the Union address in Strasbourg, Von der Leyen said threats were “mounting on our...

Source

Navigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?

By: Dissent
17 September 2026 at 08:07
Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affected by the breach STILL haven’t been notified.  Since April, DataBreaches has reported Navigate360’s lack of public transparency about the...

Source

Revolut’s paperwork breach shows why insurers are rethinking what counts as a ‘cyber attack’

By: Dissent
15 September 2026 at 07:49
Matthew Sellers reports: Revolut wasn’t hacked in the usual sense. No one broke into its servers or slipped malware past its defences. Someone asked for customer data, from what looked like a genuine government email address, and Revolut handed it over. That email is now behind one of the stranger data incidents to hit a...

Source

Silent Ransom Group Hacked Greenberg Traurig; Who notifies the 126k Affected? (1)

By: Dissent
14 September 2026 at 09:03
Silent Ransom Group added Greenberg Traurig to its list of prominent law firms it attacked and leaked. DataBreaches.net has exclusive details on the incident. On August 21, when DataBreaches reported on a data breach affecting Troutman Pepper Locke, the firm was one of 64 law firm listings on Silent Ransom Group’s (SRG’s) leak site. As...

Source

Six in 10 Cyberattacks in Colombia Target Hospitals

By: Dissent
13 September 2026 at 18:33
Joseph Freixes reports: Six in 10 cyberattacks recorded in Colombia target health sector institutions, a figure that highlights the growing exposure of hospitals and clinics to digital threats. The figure, included in a Biofile report based on a measurement analyzed from IBM’s X-Force Index, shows that medical information has become one of the main targets...

Source

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

By: Dissent
7 September 2026 at 13:24
Bill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as...

Source

Japan’s Health Ministry to Strengthen Cybersecurity Measures at Hospitals

By: Dissent
7 September 2026 at 08:41
The  Yomiuri Shimbun reports: The Health, Labor and Welfare Ministry is set to strengthen cybersecurity measures at hospitals to counter a surging number of cyberattacks on medical institutions. The ministry has included ¥13.7 billion in its budget request for fiscal 2027 to implement the measures for protecting networks and deploying cybersecurity specialists. The request will...

Source

NYS Comptroller DiNapoli releases more municipal cybersecurity audits

By: Dissent
6 September 2026 at 07:54
New York State Comptroller DiNapoli recently released some municipal audits, three of which concerned cybersecurity. The following are excerpts from the public versions of the audits. Town of Wilton – Cybersecurity (2026M-48) Audit Period January 1, 2024 – August 8, 2025 Understanding the Audit Area The Town had 56 full-time and 13 part-time employees during...

Source

Two “Nephrology Associates” suffered cyberattacks. Only one of them has disclosed it.

By: Dissent
3 September 2026 at 17:44
Sometimes, first impressions are wrong. And in the case of “Nephrology Associates,” DataBreaches mistakenly thought one victim was attacked by two different groups. But no, there are actually two unrelated entities with the same name that suffered attacks this year. And only one of them has disclosed it. The Kansas Incident On March 7, The...

Source

The New School Safety Perimeter: Where Cybersecurity Meets Physical Security

By: Dissent
3 September 2026 at 16:27
Kumar Sokka reports: At many institutions, the student ID number exposed in a data breach is the same number that unlocks dorm doors, sits behind classroom badge readers, controls laboratory access, and authenticates into building automation systems. The badge in a student’s wallet is keyed to that database. When that database is compromised, every physical...

Source

Agentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80-Page Audit

By: Dissent
3 September 2026 at 12:51
Roger Satterfield reports: An attacker handed an unknown corporate victim a comprehensive, 80-page security audit on Wednesday — not as a service, but as a postscript to the ransomware attack that had just consumed the victim’s enterprise. According to Palo Alto Networks’ threat intelligence unit Unit 42, whose researchers documented the September 2 incident, the...

Source

IE: HSE fined €645,000 over data breach affecting Westmeath hospital

By: Dissent
1 September 2026 at 08:08
Adrian Cusack reports: The Data Protection Commission has fined the HSE [Health, Safety, and Environment] more than €600,000 over the mismanagement of historical records held at St Loman’s hospital, Mullingar, and St Conal’s Hospital, Letterkenny. The fine was issued at the conclusion of an inquiry into the handling of paper records at the two facilities...

Source

Santa Fe Schools Move Forward With New Cybersecurity Policy

By: Dissent
1 September 2026 at 08:08
André Salkin reports:  The Santa Fe school board approved a new cybersecurity policy this week but delayed a vote on a separate policy governing student data privacy, with most board members calling it too broad and too important to rush through. The delayed measure, Draft Policy 357, would govern how the district treats student data...

Source

Cybercriminals build fake school websites as education attacks hit record high

By: Dissent
30 August 2026 at 11:26
Joy Agwunobi reports: Cybercriminals are ramping up preparations for the new academic year by creating thousands of education-themed websites and phishing campaigns designed to steal personal and financial information from students, parents and educators, as the education sector remains the world’s most targeted industry for cyberattacks. New research by Check Point Research, the threat intelligence...

Source

Two different groups have recently attacked Interim HealthCare entities. Should other franchises be concerned?

By: Dissent
29 August 2026 at 09:45
In April, Interim HealthCare of West Texas LLC (Lubbock, Amarillo, and Pampa) and Interim HealthCare of Amarillo notified the U.S. Department of Health and Human Services of a breach. West Texas notified HHS that 2,071 patients were affected, while the Amarillo franchise notified HHS that 666 patients were affected. In closing its investigation into Interim...

Source

Star Health’s public record: A data breach, a ₹3.39-crore fine, 13,000 ombudsman complaints — and still no accounting for the policyholder

By: Dissent
29 August 2026 at 07:47
Nitin Naresh revisits the significant Star Health breach of 2024. Previous coverage of the hack-and-leak incident can be found linked in the Related section below this post, which includes coverage of threats made to the insurance firm’s executives, court injunctions that, of course, did not stop a threat actor from leaking data, and lawsuits against...

Source

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

By: Dissent
27 August 2026 at 08:17
Brian Krebs reports: Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection...

Source

❌
❌