
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
In a massive €30M heist, hackers exploited a vulnerability in a service provider's software, making unauthorized direct debits from Commerzbank customer accounts in 2023, but fortunately, no customers suffered financial losses. The incident highlights the risks of relying on third-party services and the importance of robust security measures.

A massive data breach at RingCentral has exposed the sensitive information of 1.6 million customers, including names, addresses, phone numbers, and email addresses, which have been posted online by the hacker group ShinyHunters. This breach was discovered on July 28, and although RingCentral took swift action to stop the unauthorized activity, the damage has already been done.

Data breaches are surging out of control, with 1,803 compromises reported in the first half of 2026 alone, putting the year on track to shatter the 2025 record of 3,321 breaches. If this pace continues, 2026 could see a staggering 3,600 data compromises.

The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

Meet ExfilSquad, a notorious data-extortion group that's made off with a whopping 27 million records and 382.64 GB of sensitive data from 13 major organizations across government, education, finance, and manufacturing. The stolen treasure trove was dumped online for all to see, courtesy of a simple misconfiguration in Microsoft Power Pages.

Shell is investigating a potential data breach after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive information from the energy giant. The company is working closely with its security teams and experts to get to the bottom of the incident.

RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

A security breach at Trezor's logistics partner has compromised the personal data of over 13,000 customers, including names, email addresses, phone numbers, and shipping addresses, with the exposure window potentially stretching back 90 days. Trezor has confirmed the breach, which affects customers in several countries who ordered products between May and August.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
A data security breach has hit a Scottish Government partner, compromising sensitive information of around 300 Crown Office and Procurator Fiscal Service (COPFS) staff who took part in a public sector survey. The incident is under investigation, but COPFS confirms its own systems remain secure.

A contractor's six-week extortion scheme against Brightly Software ended with a guilty verdict, after he threatened to expose sensitive payroll and personnel records unless he received a whopping $2.5 million - ultimately settling for a significantly smaller sum of $7,540.92. The 27-year-old data analyst had been quietly siphoning off corporate data from the Siemens-owned company's network for months.

Uber Freight is investigating claims that a hacking group called Helix has stolen nearly 1 million files from the company, posting them online as evidence. The breach has sparked an urgent probe into unauthorized access to Uber Freight's systems and data repositories.

Over 1,500 UK charities are reeling after a data breach at CRM provider Beacon exposed their personal information, likely due to a compromised AWS access key. This devastating cyber-attack has left countless organizations vulnerable, sparking urgent concerns about data security.

Trezor revealed that its shipping partner, ShipMonk, suffered a security breach, exposing a whopping 14,000 customer records, and fortunately confirmed that its own systems and devices remain secure. The breach, which occurred between May 10 and August 8, 2026, was discovered on August 10, 2026.
A security breach at Beacon compromised customer data, including attachment files, after an AWS access key was potentially exposed in public JavaScript build artifacts, allowing attackers to retrieve encrypted data in readable form. The breach, which started on July 27-28, 2026, may have resulted in a downloadable copy of the database.

A major security blunder at the Criminal Records Office (ACRO) left 10,920 people vulnerable to a data breach after a hacker gained unauthorized access to its website and content management system for a staggering eight months. The Information Commissioner's Office (ICO) has now reprimanded ACRO for its failings in preventing this massive breach.

A simple Google search led to a major security slip-up when a developer stumbled upon a publicly indexed Google Doc containing sensitive staging server credentials. A careless mistake by an outside contractor had left the confidential info exposed, and a curious autocomplete suggestion revealed it all.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Uber Freight is investigating a data security incident after a hacktivist group claimed to have breached its systems, but fortunately, the issue has been identified, contained, and resolved, with operations now secure and running smoothly. The breach hasn't disrupted daily operations, and the company is working to put customers' minds at ease.

A shocking data breach at the UK's Criminal Records Office has left 11,000 individuals vulnerable after sensitive information was exposed due to basic cyber security failings. The breach went undetected for seven months, highlighting the devastating consequences of neglecting online security.

The Tribeca Film Festival recently suffered a data leak, exposing a whopping 666,369 records, including sensitive celebrity information, after a cybersecurity researcher discovered three unsecured databases left vulnerable to public access. The festival has since taken swift action, assuring the researcher that they are actively investigating and taking data security very seriously.

Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.

A data breach at Ceva Logistics has compromised sensitive information of European clients, affecting eight warehouses and disrupting contract logistics operations. The breach, described as a "textbook supply chain breach," was contained within European operations, with no impact on global systems.

Levi's is investigating a data breach after a sneaky social engineering attack tricked three employees into giving hackers access to their work computers, compromising certain corporate information. Fortunately, the company says consumer data appears to be safe and operations are running smoothly.

LexisNexis swiftly pulled the plug on three key services - Nexis Diligence, Metabase API, and Newsdesk - after detecting suspicious activity on servers managed by a third-party vendor, taking swift action to safeguard customers and contain the breach. The move comes as the company investigates the unusual server activity.