Tag: data breach
827 articles

security reforms Must-Have Fixes After Risky Afghan Leak
As ministers prepare to face Parliament, a confidential review of the 2021 Afghan data leak says crucial security reforms remain unimplemented — critics warn that those delays leave vulnerable people exposed and risk turning one breach into a systemic failure.

data breach: Stunning Risky Leak Hits 4.5M
TransUnion says a vendor’s hacked app exposed data for about 4.5 million U.S. consumers — a stark reminder that third-party flaws can put your most sensitive financial information at risk. If you’re affected, check your credit, consider freezes or alerts, and watch for notifications about monitoring and identity restoration.

application breach: Exclusive Risky Data Wake-Up Call
A TransUnion support-app breach exposed personal data for about 4.5 million people, a stark reminder that trusting a handful of giant firms with your identity can amplify risk. Take it as a wake-up call to balance digital convenience with protection—consider credit freezes, monitoring, and reviewing your accounts regularly.

OAuth tokens Risky: Stunning CRM Data Breach Alert
Google says attackers stole OAuth tokens from Salesloft’s Drift app to siphon Salesforce CRM records, leaving customers scrambling as missing or altered data disrupts sales operations. It’s a sharp reminder that convenient third‑party integrations can become powerful attack vectors unless tokens, permissions and vendor vetting are tightly managed.

OAuth tokens: Stunning Risky Drift AI Data Breach
A recent campaign abused compromised OAuth and refresh tokens tied to the Drift AI chat agent to siphon data from Salesloft—potentially creating a corridor into downstream Salesforce records. If you used Salesloft–Drift integrations, assume exposure: revoke tokens, rotate credentials, enable MFA, and audit access immediately.

Farmers Insurance data breach: Stunning Critical Failure
When a vendor breach exposed personal data for more than 1.1 million Farmers customers, it proved outsourcing can make even trusted brands vulnerable — even if their own systems weren’t hit. This is a wake‑up call for stronger vendor security, smarter contracts, and practical steps customers should take now.

SIEM rules fail: Stunning Risks and Fixes
If your SIEM only spots one in seven simulated attacks, the Picus Blue Report’s 160M+ simulations are a wake‑up call that gaps in telemetry, brittle rules, and alert fatigue are creating a dangerous illusion of security. The fix is practical: treat detection as continuous measurement—improve instrumentation, run regular attack simulations, and adopt disciplined detection engineering to turn that wake‑up call into measurable improvement.

DaVita data breach: Exclusive Shocking Fallout
A ransomware attack that exposed health records, tax IDs and check images for roughly 2.4 million DaVita patients lays bare how fragile our medical data really is — and the fallout ranges from identity fraud to disrupted care for some of the most vulnerable. Now patients, providers and policymakers must act quickly to shore up defenses, demand accountability and protect both health and financial security.

APCS data breach: Exclusive Devastating Risk Exposed
APCS — a major UK criminal‑records checker — was caught up in a supply‑chain breach at a third‑party developer, raising urgent questions about which sensitive records were exposed. Employers, applicants and regulators now need clear answers and stronger vendor security to restore trust.

customer data likely stolen: Must-Have Critical Alert
Colt warns customer data was likely stolen in a recent cyberattack and is offering a filename list to help clients check exposure. If you rely on its network services, now’s the time for targeted searches, credential rotation, and coordinated incident response.

Colt data theft: Exclusive Risky Auction Shocks Customers
Colt quietly admitted what many feared: a cyberattack that began as a service disruption also led to stolen customer data — now a criminal group called Warlock is auctioning the haul on the dark web. If you rely on Colt, this shifts from an outage to a breach you should watch closely and act on fast.

SIM-swap attacks: Must-Have Urgent Defenses
A major breach exposing SIM identifiers makes SIM‑swap attacks a real and urgent risk — but you can protect yourself now by switching from SMS to app- or hardware-based MFA, adding a carrier PIN or passphrase, and watching your accounts for suspicious activity.

Aussie Telco Limited Stunning Data Leak: Risky Fallout
A stolen login at iiNet has put roughly 280,000 customers’ names, emails, phone numbers and addresses in the hands of attackers — the exact kind of info scammers use to launch convincing phishing and account-fraud attempts. If you’re affected, enable MFA, stay alert for suspicious messages, and follow any guidance from your provider.

Allianz Life data breach: Stunning Risky Fallout
About 1.1 million Allianz Life customers may have had personal data exposed in a breach tied to the ShinyHunters group — here’s what to watch for and the quick steps you can take now to protect your identity and finances.

cyber intrusion: Exclusive Risky CIRO Data Breach
CIRO, the regulator that holds sensitive data on advisors and investors, has disclosed a cyber intrusion that could have exposed personal and firm information—raising urgent questions about privacy and market trust. The organization says it’s investigating and notifying affected people, but clear timelines and concrete remediation will be essential to restore confidence.

iiNet data breach: Risky Stunning 280k Exposed
Worried about the data you hand to your ISP? A recent iiNet incident exposed over 280,000 customer records—here’s what happened, who’s at risk, and simple steps you can take to protect yourself.

Workday CRM breach: Stunning Critical Risk Revealed
Workday says attackers accessed vendor-run CRM tools that support its customers, potentially exposing contact and support data — a stark reminder that even trusted platforms can be vulnerable through third-party integrations. If you use Workday, assume elevated risk, tighten vendor controls, and watch for suspicious communications while the investigation continues.

manpower data breach: Exclusive Risky Impact Revealed
Manpower has disclosed a breach exposing personal data of nearly 145,000 registrants, putting jobseekers, contractors and clients at heightened risk of identity theft and fraud. If you applied for temp work, monitor your accounts and credit, be wary of recruitment scams, and ask Manpower what specific data was exposed.

RansomHub leak: Devastating Manpower Data Breach
A ransomware leak exposed personal data for 144,189 people tied to Manpower’s Lansing franchise — including names, SSNs, DOBs and employment details — and the company is offering credit monitoring as it scrambles to contain the fallout. This wake-up call shows how staffing firms’ troves of sensitive records make them prime targets, and why tighter vendor security and quick, transparent responses matter now more than ever.

Hackers Breach Dutch Lab: Stunning Privacy Risk
Half a million people who trusted a Dutch cancer‑screening lab with their most intimate health details have had that trust shattered after hackers stole sensitive records — a breach that threatens patient privacy, public‑health confidence, and the future of screening programs. As investigators work to pin down the scope, this crisis is a clear wake‑up call for stronger cybersecurity, better policies, and swift support for those affected.

Connex Credit Union breach: Shocking Risky Wake-Up
A recent cyber-attack at Connex Credit Union exposed the personal data of 172,000 members, leaving many understandably worried about identity theft and financial safety. While Connex notifies affected members and steps up security, now’s a good time to review your accounts and enable extra protections like monitoring and multi-factor authentication.

Cybersecurity threats: Critical Stunning Wake-Up Call
This week’s cybersecurity roundup spotlights three urgent threats—BadCam camera exploits, a critical WinRAR vulnerability, and attackers targeting EDR systems—reminding businesses and users to patch, reassess defenses, and stay vigilant.

TeleMessage vulnerabilities: Stunning Risky Data Breach
When security researcher Micah Lee exposed at DEF CON how TeleMessage — a supposedly secure app used by White House officials — leaked a massive trove of sensitive communications, it became a stark wake-up call about how fragile our digital privacy really is. Now more than ever we need stronger encryption, transparency, and user awareness to prevent another breach.

KrebsOnSecurity Featured in HBO Max’s New ‘Most Wanted’ Series
Dive into the gripping world of cybercrime with HBO Maxs new series, featuring insights from KrebsOnSecurity, as it unravels the shocking case of hacker Julius Kivimäki and the critical need to safeguard our digital lives. Discover the chilling realities of data breaches and the urgent conversations around accountability that could reshape our future!