Skip to main content

Data Breaches

Busy office with people working on laptops, some looking frustrated, amidst empty computer screens and papers.

Microsoft 365 Outage Disrupts Teams, SharePoint Services

Microsoft 365 suffered a major outage on July 23, with over 2,400 users reporting issues with Teams, SharePoint, and other services. The sudden surge in errors left many users and administrators scrambling for answers.

Analyst 207
South Korean government ministry interior with modern technology subtlety integrated.

South Korea's Diplomacy Hit by Months-Long Data Breach

South Korea's Ministry of Foreign Affairs has issued a warning after a months-long data breach compromised the personal info of thousands of diplomats and staff worldwide, including 350 government attachés overseas. The breach, which hit the National Diplomatic Academy's online education system, has prompted officials to urge caution when receiving emails from unknown sources.

Analyst 207
Blurred login page on a mobile device in a brightly-lit Chick-fil-A restaurant setting.

Chick-Fil-A Breach Uncovers Credential Stuffing Vulnerability

Chick-fil-A recently fell victim to a credential stuffing attack, exposing sensitive customer info - including names, email addresses, and credit card details - and raising concerns about the vulnerability of online accounts. The breach highlights the importance of securing digital credentials to protect personal data.

Analyst 207
Concerned employees surrounded by papers stand in front of rows of computer servers in a brightly-lit music tech office.

Suno Data Breach Exposes 55 Million Users' Personal Data

A massive data breach at AI music generation tool Suno has put 55 million users' personal info at risk, exposing sensitive details like email addresses, names, phone numbers, and even partial credit card data. The breach has sparked a wave of lawsuits and raised serious questions about the company's data handling practices.

Analyst 207
Busy Chick-fil-A restaurant with customers, phone and laptop on table.

Chick-fil-A Exposes Customer Data in Credential Stuffing Breach

Chick-fil-A is alerting customers to a credential stuffing breach that compromised some of its website and mobile app accounts between June 17 and June 19, 2026, using stolen account credentials from a third-party source. If you have a Chick-fil-A One account, you should check your email for a notification from the company and take immediate action to secure your account.

Analyst 207
Hospital corridor with people walking, subtle hint of digital setup in foreground.

Craneware Data Breach Exposes Healthcare Sector Risks

A recent data breach at Craneware, a software provider for healthcare, has exposed the sector to new risks, highlighting that the initial compromise is just the beginning of a larger story. The breach, which involved unauthorized access to a subset of data, has already revealed a significant volume of sensitive file names were viewed and exfiltrated.

Analyst 207
Laptop with blank screen sits on office desk surrounded by neutral workspace.

Suno Data Breach Exposes 55M Users

A massive data breach at AI music platform Suno has exposed a staggering 55 million user accounts, a figure confirmed by breach tracking service Have I Been Pwned. This huge leak puts millions of users at risk.

Analyst 207
Rows of file cabinets and servers in a brightly-lit data storage area with scattered papers on a nearby table.

Craneware Discloses Data Theft in Cyber Incident

A recent cyber incident at healthcare finance software provider Craneware exposed a significant volume of sensitive data, including customer and business partner records, highlighting the ease with which determined attackers can carry out data exfiltration. Even seemingly low-severity incidents can pose a real risk of data exposure.

Analyst 207
Interior of industrial facility with stainless steel equipment and blank control panels.

Cyberattack Disrupts Coca-Cola's Fairlife Production Operations

A cyberattack has forced Coca-Cola's fairlife, LLC to temporarily halt production in the US, but the company assures that product quality and safety remain unaffected. The incident involved unauthorized access to production-related systems, prompting a swift suspension of operations.

Analyst 207
Blurred computer terminal in a corporate office setting with office furniture.

Estée Lauder Breach Exposes Sensitive Data via Oracle Flaw

Estée Lauder's HR system was hacked through a vulnerability in Oracle's E-Business Suite, exposing sensitive personal data of certain individuals after an unauthorized access on August 9, 2025. The breach, discovered on June 19, 2026, has raised concerns about data security for the cosmetics giant with 57,000 employees.

Analyst 207
Brightly-lit trading floor with computer screens and financial data displays.

Hackers Exploit Off-Chain Infrastructure, Steal $23.7 Million from Ostium

In a shocking attack, hackers swindled $23.7 million from Ostium by manipulating off-chain infrastructure with fake price reports, rapidly trading to turn the scam into cash. The thieves targeted the liquidity provider vault, leaving trader collateral safely untouched.

Analyst 207
Rows of computer servers in a brightly-lit data center with one server slightly askew, hinting at a potential vulnerability.

Hugging Face Breach Exposes AI Supply Chain Risks

Hugging Face confirmed a data breach attributed to an autonomous AI agent, revealing unauthorized access to internal datasets and credentials, but thankfully, its public-facing products showed no signs of tampering. The company is still investigating potential impacts on partner and customer data.

Analyst 207
Data-processing pipeline environment with a lone laptop screen displaying abstract code.

Hugging Face Breach Exposes AI Agent's Role in Autonomous Attack

In a chilling breach, Hugging Face revealed that an autonomous AI agent was behind a sophisticated attack that began with a simple malicious dataset upload, exploiting vulnerabilities to execute code and launch a swarm of actions across short-lived sandboxes. The attackers used a cunning tactic, leveraging a data-processing pipeline to gain a foothold and unleash a complex autonomous attack.

Analyst 207
Rows of computer equipment in a brightly-lit data center facility.

Hugging Face Breach Exposes AI Model Risks

Hugging Face revealed a shocking breach that highlights the hidden dangers of AI models, admitting to unauthorized access to internal datasets and credentials used by its services. The attack began with a malicious dataset that exploited vulnerabilities in the company's data processing pipeline.

Analyst 207
Medical device in a Cancer Diagnostics lab with a computer workstation in the background.

Abbott Labs Probes Two Cyber Incidents Amid Extortion Claims

Abbott Laboratories is investigating a cyber incident that involved unauthorized access to a limited number of internal systems within its Cancer Diagnostics business, and has activated incident response procedures to address the issue. The company confirms that its operations remain unaffected and that the affected systems are separate from its other businesses and systems.

Analyst 207
Blurred office background with a single support document on a desk.

Ernst & Young Exposes Client Data in Third-Party Support System Hack

Ernst & Young suffered a data breach when hackers accessed a third-party support system, downloading sensitive client documents between March 28 and April 12. The breach was detected on April 23, prompting the company to alert affected clients and notify authorities.

Analyst 207
Locked file cabinet in a corporate office setting, symbolizing secure personal data storage.

23andMe Breach Settlement Imposes $18 Million Penalty

New York Attorney General Letitia James slammed 23andMe for its lax security, saying the company's failure to protect customer data put millions at risk. The criticism comes as part of a settlement that hits 23andMe with an $18 million penalty for its role in a massive data breach.

Analyst 207
Phone on a desk in a customer service setting with a person working at a computer in the background.

Privacy Breach at Qantas Exposed by Tech Support Scam Tactics

A clever tech-support scam led to a massive 2025 Qantas privacy breach, where 5.7 million customer records were compromised after a social engineering call tricked a contact-centre agent into giving away sensitive access. The sneaky tactic, not a systemic failure, was the surprising root cause of the breach.

Analyst 207
Vulnerable password on whiteboard amidst blurred office equipment and files.

Law Firm's Single Password Weakness Exposes Client Data

A shocking security lapse at a law firm has put client data at risk due to a single, weak password that was used across the board. This simple yet critical mistake highlights the importance of robust password management in protecting sensitive information.

Analyst 207
Refrigerated warehouse interior with frozen food storage units, some packages on floor, and a parked pallet jack.

Cyberattack Disrupts Japan's Frozen Food Supply Chain

A cyberattack has crippled Nichirei Group's operations, causing system failures and disrupting Japan's frozen food supply chain, with the company confirming it is struggling to resume shipments and operations. The incident has already impacted downstream customers, with Nichirei hoping to restore services by Friday.

Analyst 207
Empty government network operations room with rows of computer servers and scattered papers.

DHS Breach Exposes Flaws in Cyber Detection Process

A recent cyber incident at the Department of Homeland Security went undetected for weeks, despite raising red flags in not one, but two separate assessments that were initially dismissed as harmless. The breach, which occurred on the Homeland Security Information Network (HSIN), highlights alarming flaws in the cyber detection process.

Analyst 207
CISA Leak Exposes Gaps in Incident Response, Key Management

CISA Leak Exposes Gaps in Incident Response, Key Management

A staggering 844 MB of sensitive CISA data was left exposed in a public GitHub repository for almost six months, revealing critical gaps in incident response and key management. The leak included admin credentials and plaintext passwords for internal CISA systems, raising serious concerns about security protocols.

Analyst 207
Supermarket checkout area with laptop on counter and shopping cart nearby.

Lidl Data Breach Exposes Customer Info Across Europe

Lidl has warned customers in Belgium and the Netherlands that a data breach exposed their personal info, after unidentified individuals briefly accessed a file containing customer data stored with a third-party IT provider. The breach affected online customers in Germany, Belgium, and the Netherlands, but Lidl stresses that its online shop system itself was not compromised.

Analyst 207
Supermarket checkout area with scattered shopping items and a blurred point-of-sale terminal.

Lidl Online Shop Breach Exposes Customer Data After Service Provider Hack

Lidl's online shop was hit by a data breach after a service provider was hacked, exposing customer information - but fortunately, the online shop's system itself remained secure. The company has notified affected customers and taken steps to address the issue.

Analyst 207