Skip to main content

Data Breaches

University campus setting with laptop, papers, and books, hinting at disruption.

ShinyHunters Breach Exposes Educational SaaS Canvas

ShinyHunters hackers have claimed responsibility for taking down educational software platform Canvas in a cyberattack that left users offline. The group didn't hold back, giving the developer a scathing "F for security" in their criticism of the breach.

Analyst 207
Blurred computer screen looms behind brightly-lit customer service desk in retail store.

Zara Breach Exposes Data of 197,000 Customers Worldwide

A recent data breach at a former technology provider exposed the sensitive information of 197,400 Zara customers worldwide, including email addresses, product details, and order IDs. The breach, revealed by data-breach notification service Have I Been Pwned, highlights the importance of securing customer data.

Analyst 207
Laptop on a cluttered student desk with a blurred screen.

ShinyHunters Breach Educational SaaS Canvas

A recent cyberattack has left Canvas, a popular educational software-as-a-service platform, offline, with hackers group ShinyHunters taking credit for the breach and raising serious concerns about the platform's security. The incident has disrupted learning and left many wondering about the safety of sensitive data.

Analyst 207
Blurred laptop screen shows Canvas login page in bright college library setting.

ShinyHunters Breach Exposes 330 Colleges in Canvas Hack

The notorious ShinyHunters gang has breached Instructure's Canvas, exposing a staggering 330 colleges to a devastating hack, and issued a chilling ultimatum with a May 2026 deadline to negotiate. The attackers replaced login pages with an extortion message, demanding schools seek cyber advisory help and secretly reach out to settle.

Analyst 207
Sensitive voter data scattered across a government office workspace, highlighting potential risks of misuse.

Voter Data Exposes Sensitive Information to Potential Misuse

A simple experiment by Noah M. Kenney revealed alarming privacy risks when he linked publicly available voter data from two counties with other public records, highlighting the sensitive information at risk of misuse. By analyzing voter files from Texas and North Carolina, Kenney showed just how easily voter data can be exploited.

Analyst 207
Brightly-lit video editing workspace with equipment and subtle hints of email materials.

ShinyHunters Leak Exposes 119K Vimeo Emails

A massive data leak, allegedly perpetrated by the threat actor group ShinyHunters, has put 119,000 Vimeo email addresses at risk, according to a recent report. This alarming breach raises serious concerns about online data security and user privacy.

Analyst 207
Brightly-lit school hallway with computers and students in background.

Instructure Breach Exposes 280 Million Records from 8,800 Educational Institutions

A massive data breach at Instructure has put the sensitive information of 280 million students, teachers, and staff from 8,800 educational institutions at risk, with the ShinyHunters extortion gang claiming responsibility for the attack. The stolen records include data from colleges, school districts, and online education platforms that use Canvas.

Analyst 207
Dimly lit room with scattered papers, laptop, and personal notes, conveying unease and vulnerability.

Stalkerware Breach Exposes Risks for Executives

A shocking stalkerware breach has exposed a treasure trove of sensitive information, including 86,859 images - seemingly screenshots from a single victim's device - used to secretly stalk a high-profile European entrepreneur and media personality. The alarming leak highlights the very real risks executives face in the digital age.

Analyst 207
Server room with laptop screen blurred, hinting at a security breach.

Vimeo Breach Exposes 119,000 in Data Heist by ShinyHunters Gang

A recent data breach at Vimeo exposed the email addresses and names of over 119,000 users, thanks to a hack by the notorious ShinyHunters extortion gang, which gained access through a vulnerability at data anomaly detection company Anodot. The breach highlights the importance of securing third-party integrations to protect sensitive user data.

Analyst 207
Person sits at cluttered desk with laptop in dimly lit home office.

Vimeo Breach Exposes 119,000 Email Addresses

A data breach at Vimeo has compromised the email addresses of over 119,000 users, with hackers also accessing some metadata and technical data from a third-party analytics vendor. Fortunately, no video content, login credentials, or payment card information was stolen.

Analyst 207
Rows of computer servers in a dimly-lit data center represent a vulnerable cybersecurity setting.

Trellix Breach Exposes Source Code to Threat Actors

Trellix has confirmed a breach of its internal development assets, revealing that threat actors gained unauthorized access to a portion of its source code repository. The company is working with experts to investigate and has found no evidence that its source code has been exploited so far.

Analyst 207
University campus workstation with laptop screen blurred, surrounded by ordinary indoor lighting.

Instructure Data Breach Exposes Sensitive Information

A massive data breach at Instructure has potentially exposed the sensitive information of 275 million individuals, making it one of the largest breaches in recent weeks. The incident, which was disclosed on May 1, is still under investigation, with the company working closely with experts to contain the damage and keep users informed.

Analyst 207
Dental office with scattered files and subtle server room hint.

New York Fines Delta Dental $2.25M for MOVEit Hack Violations

Delta Dental of New York has been fined $2.25 million by the New York Department of Financial Services for its handling of a massive data breach involving hackers stealing around 60,000 files from its MOVEit servers in 2023. The hefty penalty highlights the importance of robust cybersecurity measures to protect sensitive information.

Analyst 207
Brightly-lit data center with rows of servers and workstations in the background.

Trellix Source Code Repository Breached

Trellix revealed a breach of its source-code repository over the weekend, but fortunately found no signs of exploitation or compromise to its code release process. The company is still investigating and has promised to share more details once it's completed.

Analyst 207
Technicians inspect servers in a secure data center with a concerned expression.

Trellix Breach Exposes Source Code Repository

Trellix has confirmed a security incident involving unauthorized access to part of its source code repository, and is working closely with forensic experts and law enforcement to investigate. The company is reviewing the breach and will share updates as more information becomes available.

Analyst 207
Voter registration document with redacted fields on a plain surface in a public office setting.

Voter Data Exposes Personal Info to Potential Abuse

Your voter data is at risk of being exposed and used against you, with publicly available registration files potentially revealing sensitive information about you and your family. Even redacted files can be easily linked to other public datasets, making it simple for employers, fraud rings, or others to access your personal info.

Analyst 207
Laptop on a college campus table with a subtle hint of a data breach.

Instructure Breach Exposes Data of 275 Million Users

A recent data breach at Instructure, the company behind Canvas, has compromised the sensitive information of 275 million users, including names, email addresses, student ID numbers, and private messages. The company is actively investigating the incident with cybersecurity experts and law enforcement.

Analyst 207
Rows of computer servers and coding workstations in a brightly-lit, neutral-colored software development environment.

Trellix Source Code Breach Exposes Repository Vulnerability

Trellix recently identified a security breach that compromised a portion of its source code repository, prompting an immediate investigation with leading forensic experts and notification of law enforcement. The company has assured that there's no evidence its source code release process was affected or exploited - yet.

Analyst 207
Medical device in a clinical setting shows subtle signs of concern.

Medtronic Faces Federal Lawsuits Over Recent Hack

Medtronic is facing a wave of federal lawsuits after a massive data breach exposed over 9 million records containing sensitive personal information, sparking concerns about the company's handling of customer data. The breach, attributed to the ransomware gang ShinyHunters, has left many questioning the vulnerability of medical device manufacturers to cyber threats.

Analyst 207
Natural light pours into a French government agency's interior, highlighting institutional elements amidst a scene of…

French Teen Detained for Breach of Gov't Agency Data

A massive data breach at a French government agency has led to the detention of a 15-year-old suspect, with 11.7 million accounts impacted, prompting a swift investigation and criminal probe. The breach was detected on April 13, and authorities were notified just a few days later.

Analyst 207
A cluttered journalist's workspace with scattered notes and a laptop displaying a blank screen.

Researchers Warn of Emerging Exploit Threats After AI-Enabled Zero-Day Discovery

BleepingComputer issued a swift correction, retracting a report of a new data breach at Instructure due to reliance on outdated information from a prior incident, and expressed regret for the error. The incorrect story was pulled shortly after publication.

Analyst 207
French government officials gather around a table with documents in a dimly lit office.

French Teen Suspected in Mega-Breach at Secure Document Agency

A massive cyber security breach at France's secure document agency, ANTS, has led to the theft of 12-18 million lines of sensitive data, which was then offered for sale online. A 15-year-old French teen has been detained in connection with the leak, prompting the Paris Public Prosecutor's Office to launch a judicial investigation.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit, neutral server room.

Brazilian DDoS Firm Exposes Own Security Breach

A Brazilian firm's bold admission about notifying major internet providers of massive DDoS attacks against small ISPs took an unexpected turn when evidence revealed a shocking security breach of its own. The company's CEO, Erick Nascimento, revealed that an intrusion in January 2026 compromised key servers and his personal security codes.

Analyst 207
Cluttered home office setup with gaming console and laptop surrounded by papers and snack packaging.

Ukraine Arrests Hackers Behind 610,000 Roblox Account Breach

Ukrainian authorities have cracked down on a group of hackers responsible for breaching over 610,000 Roblox accounts in a months-long phishing scam that harvested credentials and tokens. The stolen access was used to snag in-game items and Robux, Roblox's virtual currency.

Analyst 207