Tag: data breach
827 articles

Azure Exfiltration Campaign Exposes 3.6 Million Records
A shocking data breach has hit major players like McDonald's and Gap Inc., with a hacker claiming to have made off with a staggering 3.6 million Azure account records, including 1.7 million sensitive employee records from McDonald's alone. The breach exposes names, emails, addresses, and more, serving as a stark reminder that traditional security perimeters just aren't enough.

Quest Breach Exposes Guests' Personal Data Through Third-Party Vulnerability
We've got some important news to share with you: Quest recently discovered a security issue with one of its third-party service providers that may have exposed some of your personal data. The company quickly sprang into action to contain the breach and is now reaching out to affected guests.

Supply Chain Hack Exposes Pokémon Center Customer Data
A recent supply chain hack exposed sensitive customer data at the Pokémon Center, but fortunately, the breach occurred through a third-party logistics partner, CEVA, and not directly through the retailer's own systems. The incident, triggered by CEVA's notification on July 30, compromised customer order details for Pokémon Center's UK and German shipments.

SafePal Data Breach Exposes 40,000 Customer Records
Good news: your SafePal wallet credentials and financial info are safe - the recent data breach exposed non-sensitive customer records, including names, email addresses, and purchase details, of around 39,798 customers.

Azure Breach Exposes 3.6 Million Records from Top Companies
A threat actor known as TheHatman is selling employee data from top companies like McDonald's and Tata Consultancy Services, allegedly stolen from Microsoft Azure tenants using compromised credentials. The stolen records total 3.6 million, with McDonald's alone accounting for 1.7 million employee records.

Pokémon Center Breach Exposes Customer Data
A recent cyberattack on CEVA Logistics, a major shipping company, has compromised customer data at the Pokémon Center, forcing the cancellation of some orders due to an unforeseen fulfilment issue. The breach, which occurred between July 29 and August 1, has disrupted operations for multiple retailers in Europe.

Azure Breach Exposes Millions of Employee Records at Top Firms
A threat actor known as TheHatman is peddling a staggering 1.7 million employee records from McDonald's, along with millions more from other top firms, allegedly stolen from Microsoft Azure environments. The breach, which Hudson Rock deems highly authentic, has left giants like Vodafone, Tata Consultancy Services, and IHG Hotels & Resorts vulnerable.

SafePal Breach Exposes 40,000 Customers to Phishing Risk
Don't worry, SafePal has confirmed that sensitive info like your seed phrase, private keys, and bank account details were not compromised in the breach that exposed the order info of 39,798 customers. The exposed data includes names, email and shipping addresses, phone numbers, and purchase details of customers who placed orders between March 2025 and April 2026.

French Tax Authority Breach Exposes 678,000 Individuals' Data
A threat actor known as ZeroBytes has claimed access to sensitive French tax authority systems, boasting on a hacking forum that they could sell stolen databases containing data on hundreds of thousands of individuals. The alarming post sparked a swift response from French authorities, who disclosed a massive breach affecting over 678,000 people.

SafePal Breach Exposes 39,798 Customer Records
Good news: SafePal's recent data breach didn't compromise wallet access or funds, but 39,798 customers had their personal info exposed, including names, emails, and shipping addresses. The breach appears to be limited, with sensitive credentials like wallet seed phrases and private keys remaining secure.

ShinyHunters Breach Exposes 1.6M RingCentral Accounts
A massive data breach at RingCentral has exposed the sensitive information of 1.6 million customers, including names, addresses, phone numbers, and email addresses, which have been posted online by the hacker group ShinyHunters. This breach was discovered on July 28, and although RingCentral took swift action to stop the unauthorized activity, the damage has already been done.

French Tax Authority Confirms Data Breach After Hacker Touts 2M Records
The French Tax Authority has confirmed a data breach after a hacker claimed to have stolen sensitive information from over 2 million taxpayers, exploiting stolen credentials and a security loophole. The breach was detected in June, and an immediate audit helped sever the unauthorized access.

ExfilSquad Breaches 13 Organizations Via Misconfigured Microsoft Power Pages
Meet ExfilSquad, a notorious data-extortion group that's made off with a whopping 27 million records and 382.64 GB of sensitive data from 13 major organizations across government, education, finance, and manufacturing. The stolen treasure trove was dumped online for all to see, courtesy of a simple misconfiguration in Microsoft Power Pages.

Shell Probes Data Breach After Clop Ransomware Gang Claims Theft
Shell is investigating a potential data breach after the notorious Clop ransomware gang claimed to have stolen 89GB of sensitive information from the energy giant. The company is working closely with its security teams and experts to get to the bottom of the incident.

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts
RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

Trezor Breach Exposes 13,000 Customers' Personal Data
A security breach at Trezor's logistics partner has compromised the personal data of over 13,000 customers, including names, email addresses, phone numbers, and shipping addresses, with the exposure window potentially stretching back 90 days. Trezor has confirmed the breach, which affects customers in several countries who ordered products between May and August.

Data Analyst Sentenced for Extorting Employer in $2.5 Million Cyber Scheme
A 27-year-old data analyst turned cyber villain, threatening to spill sensitive salary info to the SEC unless his employer paid up - in a brazen $2.5 million extortion scheme that landed him in hot water. He made his demands in chilling messages, including one that read: We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach.

Contractor Sentenced for Insider Attack on Brightly Software
A contractor's six-week extortion scheme against Brightly Software ended with a guilty verdict, after he threatened to expose sensitive payroll and personnel records unless he received a whopping $2.5 million - ultimately settling for a significantly smaller sum of $7,540.92. The 27-year-old data analyst had been quietly siphoning off corporate data from the Siemens-owned company's network for months.

Uber Freight Probes Data Breach Claims by Helix Hacking Group
Uber Freight is investigating claims that a hacking group called Helix has stolen nearly 1 million files from the company, posting them online as evidence. The breach has sparked an urgent probe into unauthorized access to Uber Freight's systems and data repositories.

Compromised AWS Key Exposes 1500+ UK Charities to Data Breach
Over 1,500 UK charities are reeling after a data breach at CRM provider Beacon exposed their personal information, likely due to a compromised AWS access key. This devastating cyber-attack has left countless organizations vulnerable, sparking urgent concerns about data security.

Trezor Breach Exposes 14,000 Customer Records
Trezor revealed that its shipping partner, ShipMonk, suffered a security breach, exposing a whopping 14,000 customer records, and fortunately confirmed that its own systems and devices remain secure. The breach, which occurred between May 10 and August 8, 2026, was discovered on August 10, 2026.
Beacon Breach Exposes Charity Data After AWS Key Compromise
A security breach at Beacon compromised customer data, including attachment files, after an AWS access key was potentially exposed in public JavaScript build artifacts, allowing attackers to retrieve encrypted data in readable form. The breach, which started on July 27-28, 2026, may have resulted in a downloadable copy of the database.

UK Watchdog Reprimands ACRO for 2023 Data Breach Failings
A major security blunder at the Criminal Records Office (ACRO) left 10,920 people vulnerable to a data breach after a hacker gained unauthorized access to its website and content management system for a staggering eight months. The Information Commissioner's Office (ICO) has now reprimanded ACRO for its failings in preventing this massive breach.

Uber Freight Probes Data Breach by Helix Extortion Group
Uber Freight is investigating a data security incident after a hacktivist group claimed to have breached its systems, but fortunately, the issue has been identified, contained, and resolved, with operations now secure and running smoothly. The breach hasn't disrupted daily operations, and the company is working to put customers' minds at ease.