Skip to main content

Data Breaches

Rows of shelving and shipping containers in a brightly-lit logistics warehouse with crates and a shipping label printer on…

Valve Exposes Steam Hardware Customer Data Breach

A recent cyberattack on CEVA Logistics, a shipping partner for Steam hardware in Europe, exposed sensitive customer data, including names, addresses, phone numbers, emails, and order details, between July 29 and August 1, 2026. Valve has notified affected customers about the breach, which may have compromised their personal information.

Analyst 207
Laptop on cluttered desk with blurred login screen, surrounded by papers and coffee cups in modern office.

Metabase Zero-Day Exploited to Breach Framework Customer Data

A zero-day exploit in analytics provider Metabase has led to a data breach at laptop maker Framework, exposing personal customer information, and prompting a review of its data storage methods with external vendors. Metabase has since patched the bug, blocked attack endpoints, and deployed a fix across its cloud service to prevent further exploitation.

Analyst 207
Laptop screen on a plain desk in a blurred office setting with a faint shadow.

Metabase Zero-Day Exploited in Data-Theft Attacks

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.

Analyst 207
Rows of computer servers and storage equipment in a data center with some servers having open panels, and a single…

Unlimited Technology Systems Breach Exposes 3.8 Million People

A shocking data breach at Unlimited Technology Systems has put the personal information of 3.8 million people at risk, after a server hack exposed sensitive data for a five-day window in October 2025. The breach was only detected on October 19, 2025, and it took until July 2026 for the company to notify authorities and affected individuals.

Analyst 207
Busy port facility with cranes, shipping containers, and workers, featuring a partially visible gate with a blank…

US Coast Guard Monitors Cyberattack Disrupting North Carolina Ports

A cyberattack brought North Carolina's ports to a grinding halt, forcing delays and manual processing at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The U.S. Coast Guard is now monitoring the situation and coordinating a response with partner agencies to get operations back on track.

Analyst 207
A laptop sits on a minimalist desk in a brightly-lit corporate office setting.

Levi Strauss & Co. Breach Exposes Corporate Data

Levi Strauss & Co. recently suffered a cybersecurity breach, but fortunately, it was quickly contained and terminated, protecting consumer data from exposure. The incident did, however, involve the unauthorized access and exfiltration of certain corporate information.

Analyst 207
Hospital corridor with muted colors and ambient daylight, featuring a blurred patient information terminal and hospital…

NHS Trust Probes Unauthorized Access to Girl's Medical Records

NHS Tayside is launching an investigation into a disturbing data breach at Ninewells Hospital, where a nine-year-old girl's medical records were allegedly accessed without authorization by staff. The incident has triggered a probe into how sensitive patient information was compromised.

Analyst 207
Busy port terminal with shipping containers, trucks, and a worker in a high-visibility vest on a sunny day.

Cyberattack Disrupts North Carolina Ports Operations

A cyberattack has brought North Carolina's ports to a grinding halt, causing a systems-wide outage that has delayed operations and truckers at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. Gates at all three locations are now back to a normal operating schedule, but the impact of the disruption is still being felt.

Analyst 207
Softly lit office scene with people working at desks, computer screen and printer in foreground, cityscape visible through…

Beacon Cyber Incident Exposes Data of 1500 UK Charities

A cyber incident at CRM provider Beacon has potentially exposed the sensitive data of 1,500 UK charities, prompting swift notification and containment efforts by the company. Beacon is now working closely with its customers to help them communicate with those potentially affected.

Analyst 207
Blurred office workstation with scattered papers and a small potted plant nearby.

Phisher Breaches US Defense Supplier's Microsoft 365 Account

A phishing scam led to a breach of a US defense supplier's Microsoft 365 account, exposing sensitive data including customer communications, engineering docs, and potentially export-controlled tech info. The intruder gained access to mailbox contents, but the company found no evidence that the data was copied or exfiltrated.

Analyst 207
Young man sits in courtroom with somber expression, hands clasped together.

Canadian Hacker Pleads Guilty to Snowflake Extortion Scheme

A 26-year-old Canadian hacker has pleaded guilty to masterminding a massive Snowflake extortion scheme that compromised over 100 million AT&T customers' sensitive call and text history records. Connor Riley Moucka faces up to 30 years in prison for his role in the cross-border hacking and extortion operation.

Analyst 207
Security personnel investigate a server room with a slightly ajar door, surrounded by computer workstations and a large…

Swiss Government SharePoint Breach Exposes 200 Accounts

The Swiss government's Microsoft SharePoint system was breached, compromising the login credentials of around 200 accounts, after security specialists detected unusual activity on July 28. The breach was quickly contained and remediated, with external internet access to the SharePoint environment blocked and patches applied.

Analyst 207
Law enforcement officer walks past blurred computer equipment outside a courthouse.

Snowflake hacker pleads guilty to massive data extortion scheme

In a major win for justice, Connor Moucka, a Canadian national, has pleaded guilty to masterminding a massive data extortion scheme targeting Snowflake customer environments, a case that could put him behind bars for up to 32 years. The guilty plea marks a significant milestone in one of the most expansive data-theft-and-extortion campaigns of 2024.

Analyst 207
Defendant sits in federal courtroom with lawyer, hands restrained.

Snowflake Breaches Expose 100 Million People as Hacker Pleads Guilty

A massive data breach at Snowflake has left a staggering 100 million people vulnerable, after hackers exploited stolen credentials to access sensitive records at over 165 organizations. The mastermind behind the breach, Connor Riley Moucka, has pleaded guilty to multiple charges, including computer fraud and identity theft.

Analyst 207
Empty chair faces blurred podium in a neutral-colored courtroom or briefing room.

Canadian Hacker Pleads Guilty to Snowflake Data Theft Extortion Scheme

A Canadian hacker has pleaded guilty to stealing sensitive data and extorting victims, including one instance where he re-extorted a victim by threatening to disclose their stolen information. The 26-year-old faces up to 32 years in prison when sentenced on October 27.

Analyst 207
Police station interior with blurred logo, chairs, counter, and window.

UK Police Expose Victim Data to Stalker, Regulator Warns

When victims share their most sensitive information with the police, they trust that it will be kept safe - but in two shocking data breaches, the Metropolitan Police Service let that trust down, putting a stalking victim's new address and number at risk. The incidents have sparked a stern warning from regulators about the force's handling of sensitive information.

Analyst 207
GitHub code repository terminal with multiple windows and code snippets on a clean desk surrounded by notebooks and a laptop.

Leaked n8n API Tokens Compromise Thousands of Instances

Thousands of n8n instances are at risk after GitGuardian researchers discovered 321 live instances accepting leaked API tokens, allowing attackers to steal raw credentials without exploiting software vulnerabilities. A staggering 4,576 credentials tied to 1,255 hostnames were compromised, putting countless users at risk of data breaches.

Analyst 207
Blurred computer screen and scattered papers in a charity office with staff working in the background.

Beacon CRM Breach Exposes UK Charity Data

A cyberattack on Beacon CRM has compromised the data of a UK charity, with the company confirming that an unauthorized third-party likely downloaded copies of its database backups. If you're a Beacon CRM user, it's best to assume that all your stored data, including files, may have been accessed.

Analyst 207
Blurred laptop screen on a table in a government-style hallway with people in the distance.

Lawmakers Push to Extend ID Theft Services for OPM Breach Victims

Lawmakers are pushing for a bill that would provide lifetime identity protection for the 4.2 million federal employees and contractors affected by the 2015 Office of Personnel Management breach, giving them the peace of mind they deserve. The proposed RECOVER PII Act aims to make the currently expiring protection program permanent, ensuring victims are safeguarded against ID theft for life.

Analyst 207
Person sits in quiet room, holding folder, with laptop and identity protection brochure nearby, conveying vigilance and…

Breach Victims Set for Lifetime Identity Protection

With the federal government's identity protection services set to expire on September 30, 22.1 million breach victims from the 2015 China-linked breaches face a looming gap in lifetime protection. Will they be left vulnerable after a decade of coverage?

Analyst 207
Dimly lit police station interior with scattered papers and a blurred computer screen.

UK Police Database Breach Exposes Officer Data on Dark Web

A sensitive police database has been breached, putting the personal details of police officers, staff, and justice professionals at risk after being published on the dark web. The breach, detected on July 26, exposed names, work email addresses, and organizations, but thankfully, no passwords or security credentials were compromised.

Analyst 207
Dimly lit police station interior with scattered papers and files, suggesting disarray.

ExfilSquad Breach Exposes Data of 100,000 UK Police Officers

A massive data breach has hit the UK police force, with a hacking group claiming to have stolen sensitive information from over 100,000 officers, including names, organizations, and email addresses. The breach, attributed to ExfilSquad, has left thousands of police personnel and government partners vulnerable to potential identity theft and harassment.

Analyst 207
Blurred police station lobby with out-of-focus interior details.

PNLD Breach Reveals U.K. Police and Government Contacts on Dark Web

A recent PNLD data breach has exposed sensitive contact information of U.K. police, government officials, and customers on the dark web, including names, work email addresses, and organisation details. The breach could make it easier for scammers to craft convincing phishing messages targeting law enforcement officers.

Analyst 207
Close-up of partially disassembled small cellular base station on a surface.

KT's Lax Security Exposes 16,647 Users to $175,000 in Unauthorized Micropayments

A shocking security lapse at KT has left 16,647 users vulnerable to unauthorized micropayments totaling $175,000, after a hacker exploited a lost femtocell to breach the company's mobile network. This costly breach has resulted in stolen identities and a hefty penalty for South Korea's largest telecommunications company.

Analyst 207