Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities

By: Dissent
30 July 2026 at 07:26
In June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reported on that, too, commenting that we did not find their incident response timely...

Source

KR: KT Fined 54 Billion Won Over Data Breach via Illegal Base Stations

By: Dissent
30 July 2026 at 07:21
Two years after a malware incident that was not handled in accordance with South Korea’s requirements, KT has been fined. Lee Jin-seok reports: KT has been fined more than 53.9 billion won [USD $37,630,484.43] over a personal data breach and unauthorized micropayment damages caused by the exploitation of illegal small base stations (femtocells). The government...

Source

US House Votes to Extend Cyber Sharing Law for 10 Years

By: Dissent
25 July 2026 at 10:25
Chris Liotta reports: Lawmakers voted to extend a key cyberthreat sharing law for another decade, attaching the long-stalled reauthorization to Washington’s annual defense policy bill. The U.S. House of Representatives narrowly approved its $1.15 trillion fiscal year 2027 national defense authorization act in a 216-212 vote Wednesday, including a provision that would reauthorize the Cybersecurity Information...

Source

Crime Stoppers assured people their tips would be anonymous. Then more than 1 million tips leaked.

By: Dissent
24 July 2026 at 08:49
Previous reporting about the Navigate360 breach focused on tips submitted by students, teachers, and parents. In this article, we focus on tips submitted to Crime Stoppers and law enforcement-related programs that use Navigate360’s software. Links to previous articles on this breach are at the end of this article.  Background In 1976, an Albuquerque detective had...

Source

Clop gang targets Windchill, FlexPLM in data theft attacks

By: Dissent
24 July 2026 at 08:06
Sergiu Gatlan reports: The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. As cybersecurity company...

Source

Instructure Incident Driving 58 Percent of Breach Notices in 2026

By: Dissent
22 July 2026 at 19:12
GovTech reports: The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident —...

Source

OpenAI Models Escaped Containment and Hacked Hugging Face

By: Dissent
22 July 2026 at 17:47
It’s happened. The nightmare of the future is now in our present. Or was this just old-fashioned negligence? Lily Hay Newman and Dell Cameron report: OpenAI disclosed on Tuesday that it lost control of two AI models during a security test that ended in a breach of the open AI research platform Hugging Face. Describing the incident as...

Source

Broken Promises of Anonymity: Four Months Later, Still No Transparency. Now We’re Seeking Accountability.

By: Dissent
20 July 2026 at 07:36
On March 18, 2026, Navigate360 learned that 8.3 million anonymous tips had been exposed. The company’s response—and the silence of the programs that depend on its platform—has persisted for months. We’re now seeking accountability through state and federal regulators. A DataBreaches.net Editorial In March 2026, the world learned that a hacktivist had acquired 8.3 million...

Source

NY Attorney General James Secures $18 Million From 23andMe for Failing to Protect Customers’ Genetic Data

By: Dissent
18 July 2026 at 08:13
There’s another update in the litigation involving 23andMe, below, but this won’t be the last update, as California’s Attorney General has also recently sued them under California’s privacy laws.  New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general today secured $18 million from genetic testing company 23andMe for failing to...

Source

Armenian National Extradited to the United States Pleads Guilty to Ransomware Extortion Conspiracy

By: Dissent
11 July 2026 at 09:06
PORTLAND, Ore.— An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon. Karen Serobovich Vardanyan, 34, pleaded guilty to conspiracy and computer fraud. According to court documents, between...

Source

Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison

By: Dissent
11 July 2026 at 09:06
Jon Brodkin reports that a third co-conspirator who helped BlackCat attackers by giving them inside information on victims’ defense strategies has now been sentenced. A former ransomware negotiator was sentenced to 70 months in prison yesterday after colluding with BlackCat scammers to extort the victims he was hired to protect. As a ransomware negotiator for the company DigitalMint,...

Source

The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?

By: Dissent
6 July 2026 at 19:05
Trigger Warning: This post includes content from tips submitted to anonymous tiplines by or about students. While identity information is redacted, tips may include obscenities and explicit references to sexual abuse, rape, assault, self-harm, violence, suicidal ideation, pornography, and pedophilia.  Overview On March 18, 2026, DDoSecrets and Straight Arrow News reported on a dataset provided...

Source

An AI just carried out a cyber attack without any human oversight for the first time

By: Dissent
3 July 2026 at 16:15
Anthony Cuthbertson reports: Security researchers have uncovered what they believe to be the first ever instance of an artificial intelligence agent executing a cyber attack from start to finish without human assistance. The AI-powered attack marks a major milestone for both artificial intelligence and cyber security, raising concerns that AI is lowering the barrier for cyber criminals. The fully automated campaign involved...

Source

MOVEit Breach Defendants Lose 2nd Bid to Toss Negligence Claims

By: Dissent
29 June 2026 at 13:56
Christopher Brown reports: Bellwether defendants in multi-district litigation over a massive data breach of Progress Software’s MOVEit file-transfer application failed to convince a federal court to toss negligence claims against them under the laws of California, Indiana, Michigan, and Ohio. The defendants—Progress and several of its customers—argued that the claims were barred under the economic-loss...

Source

Data analysis of the Global Schools Group breach, Part 1

By: Dissent
18 June 2026 at 10:46
This is the first part of a two-part report of findings from the Global Schools Group data breach. All statistical analyses and findings were provided to DataBreaches by FulcrumSec, and are presented to assist those investigating the breach as well as parents and employees who might be concerned as to what types of data were...

Source

Scoop: FulcrumSec Leaks Novo Nordisk Data After $25M Demand Goes Unpaid (2)

By: Dissent
15 June 2026 at 20:51
Danish pharma giant Novo Nordisk disclosed a cybersecurity incident last week, and although the firm’s name may not be familiar to everyone, they are a major producer of insulin and semaglutide. Semaglutide is marketed as Wegovy for weight loss and Ozempic for Type 2 diabetes. In its June 11 update, the firm stated that the...

Source

South Korea Hands Coupang a Record-Breaking $409 Million Data Privacy Fine

By: Dissent
13 June 2026 at 09:20
DataBreaches has been impressed by South Korea’s response to data breaches ever since reading about how its financial regulator responded to three credit card companies whose customers suffered a major data leak. Unlike any enforcement action DataBreaches had ever seen levied here in the U.S., the firms had their ability to enroll new customers suspended...

Source

Essex NHS hospitals records compromised in cyber attack

By: Dissent
8 June 2026 at 08:38
Mason Lewsey reports: Thousands of Essex patient records were compromised in a cyber attack linked to a major NHS data breach, MSE has confirmed. Mid and South Essex NHS Foundation Trust revealed that around 2,380 patient test records were stolen in the attack, which affected data held by third-party provider Synnovis. The trust operates Southend...

Source

FTC Gives Final Approval to Order Against Illuminate Settling Allegations It Failed to Secure Students’ Personal Data

By: Dissent
8 June 2026 at 08:30
From an FTC press release of June 5: Following a public comment period, the Federal Trade Commission finalized a modified order requiring Illuminate Education Inc. to implement a data security program, limit collection and retention of consumer data, and delete unnecessary data to settle charges that the company’s data security failures led to a major...

Source

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

By: Dissent
2 June 2026 at 08:24
Jason Koebler reports: Hackers say that they used Meta’s AI support chatbot to break into a host of high-profile Instagram profiles by asking the support bot to change the email address associated with the target account. The claims coincide with a series of high-profile Instagram account takeovers, including the Barack Obama White House account, the Chief Master...

Source

❌
❌