#data-breach

[ follow ]
fromWIRED
5 days ago

Hundreds of People With 'Top Secret' Clearance Exposed by House Democrats' Website

While scanning for unsecured databases at the end of September, an ethical security researcher stumbled upon the exposed cache of data and discovered that it was part of a site called DomeWatch. The service is run by the House Democrats and includes videostreams of House floor sessions, calendars of congressional events, and updates on House votes. It also includes a job board and résumé bank.
Privacy professionals
Information security
fromZDNET
1 hour ago

Your logins could be among 180M just added to Have I Been Pwned - how to check for free

Have I Been Pwned added two breached-account datasets — 183 million records and 3.9 million MyVidster-related accounts — exposing emails and associated passwords.
Information security
fromTheregister
5 days ago

Iran's MOIS-linked Ravin Academy hit by data breach

Ravin Academy, an Iranian cyber training school tied to intelligence, suffered a breach exposing names, phone numbers, and other personal data of associates and students.
fromSecuritymagazine
5 days ago

40B Records Exposed From Marketing and Email Data Platform

An unencrypted, non-password-protected database was discovered by Cybersecurity Researcher Jeremiah Fowler. This database contained files from an email marketing platform and held approximately 40 billion records (13 TB). The records appeared to belong to Netcore Cloud Pvt. Ltd (Netcore), an India-based company providing marketing services. Fowler sent a message to Netcore to inform them of the exposure, and the database was restricted the same day.
Privacy professionals
#cybersecurity
fromTechCrunch
1 day ago
Information security

Government hackers breached telecom giant Ribbon for months before getting caught | TechCrunch

fromTechCrunch
1 day ago
Information security

Government hackers breached telecom giant Ribbon for months before getting caught | TechCrunch

Information security
fromTechCrunch
4 days ago

Tata Motors confirms it fixed security flaws, which exposed company and customer data | TechCrunch

Tata Motors' E-Dukaan portal exposed AWS private keys and sensitive data, granting access to customer information, internal reports, dealer data, and over 70 TB files.
Information security
fromTechCrunch
4 days ago

LG Uplus is latest South Korean telco to confirm cybersecurity incident | TechCrunch

LG Uplus reported a suspected data breach to KISA amid multiple South Korean telecom cyberattacks, with investigations ongoing and national cybersecurity capacity strained.
Privacy technologies
fromIT Pro
3 days ago

Google says reports of a 'huge' Gmail breach affecting millions of users are false, again

Google says reports of a massive Gmail breach are inaccurate and result from misunderstanding of aggregated infostealer databases, with user protections intact.
#cyberattack
fromDataBreaches.Net
1 week ago
UK news

UK: 'Catastrophic' attack as Russians hack files on EIGHT MoD bases and post them on the dark web - DataBreaches.Net

fromDataBreaches.Net
1 week ago
UK news

UK: 'Catastrophic' attack as Russians hack files on EIGHT MoD bases and post them on the dark web - DataBreaches.Net

Information security
fromTheregister
3 days ago

EY exposed 4TB SQL backup file to open web, researchers say

A publicly exposed 4TB unencrypted EY SQL Server backup leaked API keys, tokens, passwords, and credentials via a cloud bucket misconfiguration.
Information security
fromIT Pro
1 day ago

US telco confirms hackers breached systems in stealthy state-backed cyber campaign - and remained undetected for nearly a year

State-sponsored hackers breached Ribbon Communications' networks in December 2024 and remained undetected for nearly a year, affecting customer files on two laptops.
East Bay real estate
fromwww.berkeleyside.org
2 days ago

Pacific Steel site sold in step toward major new life sciences campus

Berkeley experienced major development proposals, infrastructure improvements, campus controversies and data breaches, public safety and community events affecting residents across housing, transit, and university spheres.
Canada news
fromwww.cbc.ca
1 week ago

Toys 'R' Us Canada notifies customers that personal information might have been compromised in breach | CBC News

Toys "R" Us Canada experienced a customer data breach exposing names, addresses, emails and phone numbers, but not passwords or payment details.
Privacy professionals
fromDataBreaches.Net
1 week ago

Kaufman County's data breach was their second one in three weeks - DataBreaches.Net

Kaufman County experienced two data breaches in October that may have exposed residents' personal information, including Social Security numbers.
fromBusiness Insider
1 week ago

Apple is cracking down on those viral 'Tea' apps, citing persistent privacy concerns

A spokesperson for Apple told Business Insider that both apps were removed for not meeting "requirements around content moderation and user privacy, in addition to receiving an excessive number of user complaints and negative reviews - including complaints of minors' personal information being posted in the apps." The spokesperson added that for Apple, the general approach after discovering a violation is to communicate with the app developer to bring the platform up to standard.
Apple
#ransomware
fromDataBreaches.Net
1 week ago
Law

Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Attorney General James Announces Settlement with Wojeski & Company Accounting Firm - DataBreaches.Net

fromIT Pro
1 week ago
Information security

Volkswagen confirms security 'incident' amid ransomware breach claims

fromThe Walrus
2 weeks ago
Information security

The Cyberattack That Stole 280,000 Identities-and Showed How Easily We Can Be Duped | The Walrus

fromIT Pro
2 weeks ago
EU data protection

Capita fined 14 million after it 'failed to ensure the security' of of personal data

fromDataBreaches.Net
1 week ago
Law

Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Attorney General James Announces Settlement with Wojeski & Company Accounting Firm - DataBreaches.Net

fromIT Pro
1 week ago
Information security

Volkswagen confirms security 'incident' amid ransomware breach claims

fromThe Walrus
2 weeks ago
Information security

The Cyberattack That Stole 280,000 Identities-and Showed How Easily We Can Be Duped | The Walrus

fromIT Pro
2 weeks ago
EU data protection

Capita fined 14 million after it 'failed to ensure the security' of of personal data

fromTheregister
1 week ago

ICO defends decision not to investigate MoD Afghan data leak

The MoD was responsible for the accidental data breach, which took place in February 2022 and is likely to have cost more than £850 million. Evidence of the breach only came to light in July this year after a government superinjunction, imposed in August 2023, was lifted. According to a report [PDF] from the National Audit Office (NAO), the MoD first became aware of the data breach in August 2023 when personal details of ten individuals from the dataset were posted to Facebook.
Information security
Privacy professionals
fromZDNET
1 week ago

AT&T customer? Claim up to $7,500 from $177M data breach settlement - don't miss the new deadline

AT&T's $177 million settlement for 2019 and 2024 data breaches lets affected customers claim up to $7,500 by Dec. 18, 2025.
UK news
fromdatabreaches.net
1 week ago

Cyber-Attack On Bectu's Parent Union Sparks UK National Security Concerns DataBreaches.Net

A June cyber-attack on Prospect exposed data of most of its 150,000 members, including sensitive information with potential national security implications.
fromTheregister
1 week ago

Cifas exposes dozens of email addresses in invite mishap

Anti-fraud nonprofit Cifas was left red-faced after sending out a calendar invite that exposed the email addresses of dozens of individuals working across the fraud space. The invite was sent in August to a session scheduled for October 16 about the organization's JustMe app, which allows individuals to confirm if applications made in their name are genuine. Over a dozen addresses were exposed in the To field, with another 45 in the CC field, according to the message.
EU data protection
#salesforce
fromDataBreaches.Net
1 week ago
Information security

Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials - DataBreaches.Net

fromDataBreaches.Net
1 week ago
Information security

Hackers Say They Have Personal Data of Thousands of NSA and Other Government Officials - DataBreaches.Net

fromDataBreaches.Net
2 weeks ago

Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees - DataBreaches.Net

On October 16 and 17, the ScatteredLAPSUS$Hunters Telegram channel repeatedly violated Telegram's TOS by leaking personal information on people - and in this case, information on employees of the Department of Justice (DOJ/FBI), U.S. Attorneys Office (DOJ/USAO), the Department of Homeland Security (DHS), and the Federal Aviation Authority (FAA). DataBreaches did not report on it at the time precisely because the files were still exposed. Instead, DataBreaches contacted Telegram to inquire why the channel hadn't been banned again for leaking sensitive information about government employees.
Information security
fromDataBreaches.Net
2 weeks ago

Data BreachesProsper Data Breach Impacts 17.6 Million Accounts - DataBreaches.Net

More than 17 million individuals were likely impacted by a data breach at peer-to-peer lending marketplace Prosper, data breach notification service Have I Been Pwned warns.Prosper disclosed the incident last month, noting that hackers accessed its network and stole confidential, proprietary, and personal information from its systems. According to the US-based company, the attackers queried its database containing customer information and applicant data to exfiltrate the information, but did not access user accounts.
Information security
#oracle-e-business-suite
Information security
fromTheregister
2 weeks ago

Have I Been Pwned logs 17.6M victims in Prosper breach

A September cyberattack on Prosper allegedly exposed personal data for about 17.6 million people, including Social Security numbers and various identity and contact details.
fromwww.amny.com
2 weeks ago

Column | Final Phase for NY Cybersecurity Regulation: Is Your Financial Institution in Compliance? | amNewYork

In August, the New York State Department of Financial Services reached agreement with Healthplex, Inc., a licensed insurance agent and independent adjuster, to pay a $2 million civil penalty after a hacker executed a phishing attack on an employee's email and gained access to the private health data and sensitive nonpublic information of tens of thousands of Healthplex consumers. Eight years in the making, the final phase of New York's groundbreaking Cybersecurity Regulation Part 500 takes effect Nov. 1.
Information security
Information security
fromWordtothewise
2 weeks ago

B2B Spam: Strapi, Unstructured and Reo

A unique email given to Strapi for a demo later received unsolicited promotional mail from an unrelated company, indicating a possible unauthorized exposure of Strapi customer contact data.
fromZDNET
2 weeks ago

New deadline: Claim up to $7,500 from AT&T's $177M data breach payouts - here's how

If you're a current or former AT&T customer, the deadline to file a claim to be part of the $177 million class-action settlement over two major data breaches has been extended. The breaches -- one dating back to 2019 and a second in 2024 -- exposed Social Security numbers, call and text records, names, addresses, dates of birth, and more.
US news
Privacy professionals
fromDataBreaches.Net
2 weeks ago

Integris Health Agrees to $30 Million Settlement Over 2023 Data Breach - DataBreaches.Net

Integris Health agreed to a $30 million settlement after a November 2023 breach exposed over two million patients' sensitive data, creating substantial fraud and identity theft risk.
Information security
fromDataBreaches.Net
2 weeks ago

Gov't seeks police probe of KT for allegedly obstructing data breach investigation - DataBreaches.Net

KT allegedly obstructed a government probe into unauthorized mobile-payment breaches by submitting false server disposal timing information and concealing backup logs and evidence.
Information security
fromTheregister
2 weeks ago

Sotheby's finds its data on the block after cyberattack

Sotheby's disclosed a July 24 cyber breach exposing sensitive data, including Social Security numbers and financial account information, affecting at least two Maine residents.
Privacy professionals
fromDataBreaches.Net
2 weeks ago

Heritage Provider Network $49.99M Class Action Settlement - DataBreaches.Net

Eligible Heritage Provider Network patients may claim cash payments and medical monitoring from a $49,995,000 class-action settlement over a December 2022 data breach.
Information security
fromBusiness Matters
2 weeks ago

Capita fined 14 Million over 2023 cyber-attack that exposed data of 6.6 Million people

Capita was fined £14 million by the ICO for serious data protection failures after a March 2023 cyber-attack that exposed 6.6 million people's personal data.
Digital life
fromMashable
2 weeks ago

4 big tech settlements you might be eligible for in 2025

Consumers may be eligible for settlement payouts from AT&T, Facebook, and Amazon; check eligibility, deadlines, and claim procedures to recover owed funds.
US news
fromwww.housingwire.com
2 weeks ago

loanDepot sues WCL, alleging illegal practices

loanDepot alleges West Capital Lending and associates stole confidential customer data, poached employees, misclassified about 600 loan officers, and will pursue legal remedies.
fromDataBreaches.Net
2 weeks ago

Attorney General James Secures $14.2 Million from Car Insurance Companies Over Data Breaches - DataBreaches.Net

NEW YORK - New York Attorney General Letitia James today secured $14.2 million from eight car insurance companies for failing to protect the private information of more than 825,000 New Yorkers. The data breaches were part of a hacking campaign that targeted car insurance companies' quoting tools and stole people's personal information, including driver's license numbers and dates of birth. The hackers later used some of the stolen driver's license information to file fraudulent unemployment claims at the height of the COVID-19 pandemic.
#discord
fromDataBreaches.Net
2 weeks ago
Information security

Discord blamed a vendor for its data breach - now the vendor says it was 'not hacked' - DataBreaches.Net

fromZDNET
3 weeks ago
Information security

70,000 government IDs were exposed in a Discord breach - could yours be next?

fromDataBreaches.Net
2 weeks ago
Information security

Discord blamed a vendor for its data breach - now the vendor says it was 'not hacked' - DataBreaches.Net

fromZDNET
3 weeks ago
Information security

70,000 government IDs were exposed in a Discord breach - could yours be next?

fromSecuritymagazine
2 weeks ago

180,000 Records of PII and Payment Information Exposed

A database was found to be without password protection or encryption, exposing approximately 180,000 records (178,519 files) containing PII and payment data. This database was discovered by Jeremiah Fowler, a Cybersecurity Researcher and was initially reported to Website Planet . In an examination of the exposed files, Fowler identified invoices that contained personally identifiable information (PII). Sensitive data in these invoices included, but was not limited to: These invoices belonged to employees, customers, service providers and partners globally.
Information security
Information security
fromThe Verge
2 weeks ago

Discord blamed a vendor for its data breach - now the vendor says it was 'not hacked'

None of 5CA's systems were involved in the breach; platforms remain secure, and forensic findings indicate the incident occurred outside 5CA.
#identity-theft
fromwww.theguardian.com
3 weeks ago

Hackers leak Qantas data containing 5 million customer records after ransom deadline passes

The Qantas data, which was stolen from a Salesforce database in a major cyber-attack in June, included customers' email addresses, phone numbers, birth dates and frequent flyer numbers. It did not contain credit card details, financial information or passport details. On Saturday the group marked the data as leaked, writing: Don't be the next headline, should have paid the ransom.
Information security
Information security
fromDataBreaches.Net
3 weeks ago

Telstra Denies Scattered Spider Data Breach Claims Amid Ransom Threats - DataBreaches.Net

Telstra denies a claimed breach of nearly 19 million records, saying data was scraped publicly and no sensitive credentials were exposed.
fromwww.esquire.com
3 weeks ago

There's a Shady Conservative Coven Influencing Oklahoma State Politics

State Rep. Josh Schriver, R-Oxford, who has called porn a scourge and compared it to heroin, introduced legislation in September to ban online pornography statewide. But data reviewed by Metro Times show that an account linked to his personal AOL email address appeared in a data breach from Fling.com, a pornographic dating site that features live web cams and promised users they could find sex and get laid tonight.
US politics
Privacy professionals
fromTheregister
3 weeks ago

Prospect union tells members their data was breached in June

UK trade union Prospect suffered a June 2025 IT security breach exposing members' personal data including sexual orientation and disabilities.
#sonicwall
Information security
fromComputerworld
3 weeks ago

Major Discord hack exposes the real risks of digital ID

Mandatory government ID requirements make third-party verification services attractive targets, creating predictable risks of sensitive user data exposure.
Information security
fromIT Pro
3 weeks ago

Teens arrested over nursery chain Kido hack

Two 17-year-olds were arrested in Bishop's Stortford on suspicion of computer misuse and blackmail over a Kido nursery data breach affecting about 8,000 children.
Information security
fromSecurityWeek
3 weeks ago

Ransomware Group Claims Attack on Beer Giant Asahi

Qilin ransomware claimed responsibility for a cyberattack on Asahi, stealing 27 GB and disrupting orders, shipments, and call center operations in Japan.
fromwww.independent.co.uk
3 weeks ago

Two men arrested over cyber attack on nurseries in London

Since these attacks took place, specialist Met investigators have been working at pace to identify those responsible. We understand reports of this nature can cause considerable concern, especially to those parents and carers who may be worried about the impact of such an incident on them and their families. We want to reassure the community and anyone affected that this matter continues to be taken extremely seriously.
UK news
Privacy professionals
fromDataBreaches.Net
3 weeks ago

California hospitals can escape fines if workers expose patient info - DataBreaches.Net

Hospitals are not liable for employee disclosures of patient information when appropriate privacy policies existed and the employee knowingly violated them.
Information security
fromComputerWeekly.com
3 weeks ago

The Security Interviews: David Bradbury, CSO, Okta | Computer Weekly

Okta suspended development after an October 2023 helpdesk breach and launched a Secure Identity Commitment to improve products, customer practices, industry protection, and corporate hardening.
Information security
fromTechzine Global
3 weeks ago

Red Hat leak escalates: ShinyHunters demands money after GitLab breach

ShinyHunters joined Crimson Collective's extortion, publishing stolen Red Hat customer data and threatening full release if negotiations don't begin by October 10.
Information security
fromTheregister
3 weeks ago

Red Hat breach escalates as Crimson Collective recruits help

Criminal groups exfiltrated Red Hat consulting GitLab data, including thousands of repositories and secrets, and are conducting a joint extortion campaign.
fromZDNET
3 weeks ago

ParkMobile might owe you money from its data breach settlement - but there's a small catch

If you used the ParkMobile app to pay for parking at a meter several years ago, you might be getting a payment as a result of a data breach. Unfortunately, it's probably not an amount you'd expect for the inconvenience of having your data exposed. And while it's a comically low amount, don't spend it all in one place, because, well.... You're literally not allowed to.
Information security
[ Load more ]