Skip to main content

Data Breaches

UK government office with papers scattered, slightly ajar file cabinet, and blurred computer screen in background.

UK Government Investments Exposes Official Contact Data in 40-Hour Breach

A simple mistake by a staff member at UK Government Investments left sensitive contact information of 51 government officials exposed to the public for a staggering 40 hours. The breach, revealed in the organization's annual report, highlights the importance of following basic security protocols to protect official data.

Analyst 207
Medical office setting with scattered records and equipment, laptop on desk in foreground.

Amgen Discloses Cloud Data Breach Exposing Patient Health Info

Amgen recently discovered a cloud data breach that compromised patient health information, prompting immediate action to contain and investigate the incident. The breach, detected in July 2026, involved unauthorized access to multiple cloud systems operated by third-party service providers, resulting in the theft of sensitive data, including proprietary information and protected health records.

Analyst 207
Rows of equipment racks and monitors in a modern server room with a single blurred workstation in the foreground.

Hugging Face Breach Exposes Defense Gaps in AI Age

In a shocking revelation, Hugging Face fell victim to a breach that exposed vulnerabilities in AI-powered defenses, with over 17,000 attack events detected across its sandboxes. The incident was linked to a sophisticated attack chain involving OpenAI's models, highlighting the need for stronger security measures in the AI age.

Analyst 207
Well-lit security storefront with slightly askew camera panel.

ShinyHunters Breach Famous Physical Security Brand

The notorious hacking group ShinyHunters has breached the most iconic brand in physical security, sending shockwaves through the industry. This high-profile hack has left many wondering about the vulnerability of even the most trusted names in security.

Analyst 207
Charity office staff work amidst scattered papers and concerned expressions.

CAF Bank Outage Persists, Charities Struggle with Disrupted Payments

Thousands of UK charities are still reeling from a week-long online banking outage at CAF Bank, with £1.45 billion in customer deposits stuck in limbo and no end in sight for a resolution. The disruption has left 14,000 charity customers scrambling to manage their day-to-day transactions.

Analyst 207
Formal government setting with documents and blurred telecom logo behind somber-toned individual.

South Korea Slaps KT with $39 Million Fine for 11-Month Data Breach

South Korea's Personal Information Protection Commission has slapped KT Corporation with a hefty $39 million fine for a data breach that went undetected for a staggering 11 months, exposing sensitive info of over 16,647 customers. The penalty, equivalent to KRW 53.979 billion, is a stern reminder of the importance of robust cybersecurity measures.

Analyst 207
Clean home security system control panel on a residential hallway wall.

ShinyHunters Breach Exposes Brinks Home Data

Brinks Home recently disclosed a security breach, with an extortion group claiming to have exposed millions of customer records, prompting the company to activate its incident response procedure and work with leading forensics experts to contain the damage. The breach, identified on July 20, thankfully didn't impact alarm monitoring and system functionality.

Analyst 207
People in business attire and lab coats gather around a table with computer equipment and papers in a secure facility's…

Analog Devices Exposes Data Breach, Probes Incident

Analog Devices recently uncovered a data breach, swiftly springing into action to contain the incident and minimize damage after detecting unauthorized access to its systems on June 23. The company has launched a thorough investigation, working with cybersecurity experts and law enforcement to understand the breach and prevent future threats.

Analyst 207
Hospital corridor with laptop and medical records on counter, hinting at potential data breach.

ShinyHunters Targets Healthcare with Rising Data Theft Attacks

ShinyHunters is on the hunt, using data theft at cloud scale to target healthcare and medical-tech organizations, leveraging stolen OAuth tokens and corporate single-sign-on accounts to wreak havoc. This notorious extortion gang has successfully breached numerous organizations in the past two years, often through clever social engineering tactics.

Analyst 207
Municipal water treatment plant in a Midwestern town with subtle digital infrastructure.

Minnesota Water Systems Hit by Coordinated Cyberattack

A coordinated cyberattack hit over 30 Minnesota community water systems, prompting a swift response from state and federal teams to contain the intrusion and mitigate immediate impacts on local water operations. The breach caused significant disruptions, with some cities like Braham forced to go offline and ask residents to conserve water.

Analyst 207
Modern office setting with blurred computer screen and cityscape background.

Data Breach Costs Soar to $5 Million Average Globally

The global average cost of a data breach has skyrocketed to a record $4.99 million, with organisations facing a daunting 602 incidents on average, and experts warn that a reactive security approach is no longer enough to keep up with today's rapid-fire cyber threats. To stay ahead, businesses must shift to a continuous, autonomous defence - or risk being left in the dust.

Analyst 207
Rows of computer servers and networking equipment in a data center with a generic computer in the foreground.

OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI researchers and publicly credited by JFrog.

Analyst 207
Control room of a municipal water treatment plant with industrial and administrative equipment.

Minnesota Water Utilities Targeted in Coordinated Cyberattack

A coordinated cyberattack has left over 30 Minnesota communities without access to water services, with officials working swiftly to contain and investigate the damage. Minnesota Information Technology Services is leading the response, sharing vital threat intelligence and guiding affected utilities through the recovery process.

Analyst 207
Bank interior with empty counter and terminals, lit by natural daylight streaming through a window.

CAF Bank Halts Online Services Over Security Vulnerability

Thousands of charities are facing disruption to their online accounts and payroll services after CAF Bank temporarily halted its online banking services due to a newly discovered security vulnerability. The suspension, which began on July 24, will remain in place until the issue is resolved.

Analyst 207
Bank branch interior with a sign reading Online Services Unavailable.

CAF Bank Halts Online Services Over Third-Party Software Vulnerability

CAF Bank has temporarily halted its online banking service due to a third-party software vulnerability, and customers are being supported while the issue is resolved with the help of external experts. The bank's CEO, Alison Taylor, has apologized for the disruption, assuring customers that access will be restored once the connection is secure.

Analyst 207
University hallway with open doors, symbolizing vulnerabilities in single sign-on security.

SSO Security Requires Proactive Defense Against Credential Attacks

A single compromised SSO account can become a master key, unlocking a vast array of sensitive services and putting millions of individuals at risk, as seen in the 2025 University of Pennsylvania breach where 1.2 million people's data was stolen. Proactive defense against credential attacks is crucial to protecting your organization's security.

Analyst 207
Bank interior with online banking workstation and concerned customers in background.

CAF Bank Halts Online Services Over Third-Party Software Flaw

CAF Bank has temporarily halted its online banking service due to a third-party software flaw that led to suspicious activity on some customer accounts. The bank assures customers that core banking services remain unaffected and that no money has been lost.

Analyst 207
Calm medical office setting with blurred patient records in background.

MCBS Data Breach Exposes 1.26 Million People's Sensitive Information

A massive data breach at Medical Computer Business Services (MCBS) has put the sensitive information of over 1.26 million people at risk, with a threat actor claiming to have stolen a staggering 3.3 terabytes of data. The breach, which occurred in September 2025, exposed personal data handled by the medical billing and practice-management company.

Analyst 207
Dairy production facility with stainless steel equipment and milk bottles on a conveyor belt.

Coca-Cola Discloses Data Theft in Fairlife Ransomware Attack

Coca-Cola has confirmed that its dairy subsidiary, Fairlife, was hit by a ransomware attack, resulting in data theft by hackers. The company is working to restore impacted systems and operations, with most US production now back online.

Analyst 207
Office workspace with desk, laptop, and scattered papers, conveying sensitive information handling.

ShinyHunters Targets Ernst & Young in Claimed Data Breach

Ernst & Young revealed that a third-party support system used by its IT team was hacked, putting client tax information at risk. The breach, detected on April 23, exposed sensitive personal and financial data.

Analyst 207
Smartphone displaying Click To Pray app in a neutral room with subtle church background.

Pope's Prayer App Leaks 700K Users' Info Amid Security Vulnerability

A shocking security breach has been uncovered in the Pope's official prayer app, Click To Pray, exposing the sensitive information of over 719,000 registered users for months due to a vulnerability that allowed anyone to access account data. The flaw, discovered by an ethical hacker, highlights the alarming risks of unsecured personal data.

Analyst 207
Parcel delivery facility with packages and equipment, laptop screen blurred in background.

OnTrac Data Breach Exposes Customer Information After Network Hack

OnTrac recently suffered a network hack, resulting in a data breach that exposed customer information, with the incident detected on March 23 after an intrusion occurred between March 20-22. Fortunately, the company has no evidence of the stolen information being misused or published.

Analyst 207
Chick-fil-A restaurant interior with a tablet login screen in the foreground.

Chick-fil-A Breach Exposes 13,000 Customers' Data

Thousands of Chick-fil-A customers are reeling after a credential stuffing attack compromised 13,322 accounts, exposing sensitive customer data over just three days in June. The breach allowed hackers to access a combination of customer info linked to Chick-fil-A One accounts, including names and more.

Analyst 207
Technicians monitor control panels in a brightly-lit utility center, with a hint of concern.

Origin Energy Data Breach Exposes Client Information

Origin Energy has confirmed a data breach, exposing customer records and sparking an immediate investigation into the incident. The breach affects some of its 4.8 million customers, and the company is taking swift action to notify and protect those impacted.

Analyst 207