Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Cybersecurity Stolen ChipSoft claims patient data confirmed destroyed following cyberattack

By: Dissent
7 May 2026 at 07:25
There’s an update to the ChipSoft ransomware attack.  DigitalShield reports that although ChipSoft hasn’t revealed whether it paid Embargo ransom, it did disclose that some negotiations had occurred. One of the most striking elements of the case is the company’s claim about the deletion of the stolen data. According to the company, the destruction has been...

Source

NYSDFS Secures $2.25 Million Cybersecurity Settlement with Delta Dental

By: Dissent
1 May 2026 at 12:20
There is an update regarding the 2023 Delta Dental breach involving MOVEit software. Delta Dental was one of many customers whose patient data was exposed after Clop exploited a zero-day vulnerability to attack MOVEit and acquire its clients’ data. More than 7 million patients were reportedly affected by the breach, although the number specific to New...

Source

Two Americans Sentenced to Prison for Using BlackCat Ransomware to Attack Multiple Entities

By: Dissent
30 April 2026 at 18:59
There is an update on the criminal cases against Ryan Goldberg and Kevin Martin, security professionals who turned to the dark side and cut a deal with ALPHV/BlackCat operators to use their ransomware and pay BlackCat 20% of whatever they collected in ransom. From the DOJ’s press release today: Two American cybersecurity professionals were sentenced...

Source

OCR Announces Settlements of Four Ransomware Investigations that Affected Over 427,000 Individuals

By: Dissent
24 April 2026 at 07:59
Yesterday, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced settlements with four regulated entities following separate ransomware investigations under HIPAA’S Security Rule. For those keeping count: the resolutions announced mark 19 completed investigations from ransomware breaches and 13 completed investigations in OCR’s Risk Analysis Initiative. The settlements follow...

Source

NOT for Sale! BlueLeaks 2.0 Hacktivist decides not to sell dataset with sensitive data

By: Dissent
22 April 2026 at 18:39
Just when I thought I might be done with work for the day, DataBreaches received an email from “Internet Yiff Machine” (IYM),  the hacktivist responsible for hacking P3 Global Intel in what has been called the “Blue Leaks 2.0” breach. As most readers know by now, IYM provided a dataset of 8.3 million tips that...

Source

BlueLeaks 2.0: 7,300+ Schools, Referral Systems Reported, and a Breach Navigate360 Still Hasn’t Publicly Confirmed

By: Dissent
22 April 2026 at 10:14
Overview and Background This is the first of what will likely be several updates to this site’s exclusive reporting on the “BlueLeaks 2.0” incident that exposed anonymous and sensitive tips by and about students on a platform that promised them anonymity and security.  DDoSecrets.org named the incident “Blue Leaks 2.0” because, like a previous leak...

Source

Qilin’s 2024 attack on NHS vendor continues to impact patient care for one NHS Trust

By: Dissent
19 April 2026 at 10:27
Long-term follow-ups are important, and DataBreaches is glad that Alexander Martin points out that at least one NHS Trust is still impacted by the Qilin ransomware attack on Synnovis in 2024. From his reporting: At South London and Maudsley NHS Foundation Trust (SLaM), pathology systems have not been restored as of publication, with the trust...

Source

P3 Advertised 20+ Years and 0 Security Breaches. You Can Guess What Happened Next.

By: Dissent
16 April 2026 at 07:00
Introduction P3 Global Intel advertises itself as a “fully integrated and state-of-the-art tip acquisition and tip management solution that has quickly become the leading choice of Crime Stoppers Programs, Law Enforcement Agencies, Campus Safety Programs, and Federal Agency Initiatives.”  35,000 U.S. schools use P3 Campus, which partners with “safer school” initiatives such as Sandy Hook...

Source

California’s cybersecurity audit rule is now in effect: its impact for class litigation

By: Dissent
14 April 2026 at 13:10
The IAPP writes: Last year, the California Privacy Protection Agency adopted a major new rule requiring certain businesses to conduct an annual cybersecurity audit. The rule went into effect 1 Jan. 2026. This pioneering requirement, the first of its kind among state data privacy laws of general applicability, may entail substantial compliance efforts for affected companies to...

Source

City of Anthony, NM, public records have been suspiciously disappeared, locked, or wiped

By: Dissent
13 April 2026 at 14:46
There are insider breaches, and then there are fourth-degree felonies and other possible charges if public records are destroyed improperly or without a lawful purpose. KVIA in New Mexico reports: The City of Anthony released a letter to KVIA on Saturday stating that the previous administration had allegedly committed several wrong-doings and the City is...

Source

Iowa AG files lawsuit against Change Healthcare over 2024 data breach

By: Dissent
8 April 2026 at 09:27
Naomi Diaz reports: Iowa Attorney General Brenna Bird has filed a lawsuit against Change Healthcare, alleging the company violated state consumer protection and data security laws in connection with a 2024 data breach that affected nearly 2.2 million Iowa residents. Filed March 31, the lawsuit claims the breach exposed sensitive personal and medical information and caused widespread...

Source

Act-of-War Clauses Cloud Cyber Insurance Coverage

By: Dissent
8 April 2026 at 09:09
Angus Loten reports: From Europe to the Middle East, geopolitical conflicts have companies rereading the fine print on insurance policies that deny coverage for wartime cyberattacks. Act-of-war exclusions—a common provision in homeowners, life and travel insurance—are largely untested in the cyber market, where the line between cybercrime and nation-state warfare is unclear. That can leave...

Source

Who really runs your VPN — and what that may mean for your privacy

By: Dissent
8 April 2026 at 08:24
Over on Codamail (fka Cotse.net), Steve Gielda has updated his research on VPN infrastructure and its implications for your privacy. From that article: The Question VPN providers market themselves as independent services in diverse jurisdictions. This investigation asks a structural question: does the global VPN industry’s physical infrastructure actually reflect that diversity, or does it...

Source

1 Billion Microsoft Users Warned As Angry Hacker Drops 0-Day Exploit

By: Dissent
7 April 2026 at 10:38
Davey Winder reports: Usually, when I report zero-day exploits, it’s because attacks by threat actors are already underway or a vendor has released a patch after becoming aware of the vulnerability. BlueHammer, however, is different. This time, it’s a security researcher who has released the Windows attack exploit code; there is no patch available, and...

Source

How often do threat actors default on promises to delete data?

By: Dissent
5 April 2026 at 10:02
We have probably all read recommendations that cyberattack victims should not pay ransom demands because it encourages more crime, and because criminals can’t be trusted to delete data they promise to delete. But what evidence have we seen supporting a claim that criminals default on data deletion? Law enforcement made a point of reporting that...

Source

BakerHostetler’s 2026 report: Findings from 1,250 clients’ breach experiences in 2025

By: Dissent
3 April 2026 at 18:10
BakerHostetler’s annual report, which shares their experiences as a law firm representing data breach clients, is always one of my favorite reads, and their 2026 Data Security Incident Response Report does not disappoint. As always, it is chock-full of interesting statistics and commentary. In 2025, they represented 1,250 clients:  27% were from Healthcare (including pharma...

Source

Attack on axios software developer tool threatens widespread compromises

By: Dissent
31 March 2026 at 14:27
Tim Starks and Derek B. Johnson report: A hacker briefly delivered malware this week through a popular open-source project for software developers that has an estimated 100 million weekly downloads, raising the possibility of compromises spreading widely through a supply-chain attack. Axios is a JavaScript client library used in web requests. The unknown attacker hijacked...

Source

Ransomware Attack Totally Cripples Jackson County Sheriff’s Office in Indiana

By: Dissent
27 March 2026 at 13:48
From a report on cyber.netsecops.io: Executive Summary A debilitating ransomware attack has completely crippled the IT operations of the Jackson County Sheriff’s Office in Indiana. The attack, which struck last week, has rendered the department’s entire computer network, including all PCs, Wi-Fi, and critical reporting systems, unusable. […] Technical Analysis Initial Access Vector: The likely initial access vector...

Source

Delaware Supreme Court Reverses, Holds Cyber Insurers Sufficiently Pled Collective Subrogation Claim Resulting from Blackbaud Data Breach

By: Dissent
25 March 2026 at 08:29
The fallout from the massive Blackbaud breach is not over, it seems. Lydia Mills of Wiley Rein writes: Reversing the decision below, the Delaware Supreme Court held that a group of cyber liability insurers sufficiently pled a complaint for subrogation based on breach of contract. Travelers Cas. & Sur. Co. of Am. v. Blackbaud, Inc., 2026...

Source

TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign

By: Dissent
25 March 2026 at 08:18
Deeba Ahmed reports on some of TeamPCP’s dangerously effective recent activities: What Happened? The trouble began on 19 March 2026, when a hacking group calling themselves TeamPCP managed to break into Trivy, a popular tool used by developers to scan their code for security vulnerabilities. This was a supply chain attack, which occurs when hackers sneak malicious code...

Source

❌
❌