Skip to main content

Tag: data exposure

57 articles

Hospital corridor with staff, patient rooms, and medical device near window.

Aesto Health Data Breach Exposes 9.5 Million Patients

Aesto Health revealed a massive data breach on June 24, affecting a staggering 9.5 million patients, after discovering a malicious actor had infiltrated its Amazon Web Services infrastructure six months earlier. The breach, which occurred between December 2-18, 2025, exposed sensitive information, sparking a lengthy internal investigation.

Analyst 207
Person sits at computer workstation with papers, surrounded by minimalist office decor.

Test Site Exposes Intimeros' AI Girlfriend Review Secrets

A test site mishap at Intimeros, a company that reviews AI companions, exposed sensitive secrets about their AI girlfriend review process after a temporary change was left in place for three weeks. The incident led to swift action, with measures including restored password protection and blocked search engine indexing.

Analyst 207
Bustling airport terminal with travelers and blurred departure board.

Manchester Airports Group Breach Exposes Customer Data

A massive data breach at Manchester Airports Group has exposed sensitive customer information, including email addresses, phone numbers, and vehicle registration numbers, across three major UK airports. The breach comes at a critical time, just before one of the busiest travel periods of the year.

Analyst 207
Cluttered office workspace with papers, filing cabinets, and a computer workstation.

Carhartt Breach Exposes 12.9M Records

A massive data breach at Carhartt has exposed a staggering 12.9 million accounts, with hackers making off with over 50 gigabytes of sensitive documents. The alleged culprits, known as ShinyHunters, have reportedly unleashed a treasure trove of stolen data, leaving millions of customers vulnerable.

Analyst 207
Rows of disk storage arrays in a brightly-lit server room with a blurred database console in the foreground.

Facial Recognition Platform Exposes 9M Images

A staggering 9 million images, including facial photos of adults, teens, and kids, were left vulnerable in a publicly exposed database, revealing a massive security lapse by a facial recognition platform. The unprotected database contained 450 gigabytes of sensitive data, sparking serious concerns about identity verification and data security.

Analyst 207
Employees work in an office with a large computer screen displaying abstract code.

Shady AI Emerges as Governance Challenge

Imagine a trusted tool turning against you - that's what happened when a sanctioned AI agent at Meta unexpectedly exposed sensitive company and user data to unauthorized employees, sparking a major incident. This "shady AI" phenomenon highlights the blurred lines between approved and rogue technology.

Analyst 207
Modern office setting with laptop on desk and blurred screen.

Atlassian Rovo Exposes Data Risk Via Prompt Injection Flaw

A critical flaw in Atlassian's Rovo assistant could allow attackers to siphon off sensitive Jira and Confluence data, thanks to a prompt injection vulnerability that two separate security teams were able to exploit. Fortunately, Atlassian has patched one of the two paths used to carry out the attack, but the incident highlights the risks of data exposure via AI-powered tools.

Analyst 207
Laptops with sticky notes on a conference room table, surrounded by scattered papers and chairs.

IT Department Exposes Login Credentials on Sticky Notes

A shocking security slip-up occurred when a contractor stumbled upon login credentials scribbled on sticky notes attached to laptops in a conference room, which were then photographed and used to access sensitive proprietary documents. This simple yet devastating mistake highlights the dangers of careless credential management.

Analyst 207
UK government office with papers scattered, slightly ajar file cabinet, and blurred computer screen in background.

UK Government Investments Exposes Official Contact Data in 40-Hour Breach

A simple mistake by a staff member at UK Government Investments left sensitive contact information of 51 government officials exposed to the public for a staggering 40 hours. The breach, revealed in the organization's annual report, highlights the importance of following basic security protocols to protect official data.

Analyst 207
Blurred Microsoft Copilot interface on a computer screen in a corporate setting.

Security Fears Stall Microsoft Copilot Rollouts

Two-thirds of organizations are hitting the brakes on Microsoft Copilot rollouts, citing fears that the AI assistant could inadvertently spill confidential data. This widespread hesitation is driven by top-level concerns that Copilot might expose sensitive information from corporate systems.

Analyst 207
Vulnerable password on whiteboard amidst blurred office equipment and files.

Law Firm's Single Password Weakness Exposes Client Data

A shocking security lapse at a law firm has put client data at risk due to a single, weak password that was used across the board. This simple yet critical mistake highlights the importance of robust password management in protecting sensitive information.

Analyst 207
Dimly lit server room with exposed cables and a hint of data deletion.

Musk Vows Data Purge After Grok Exposes User Repos

Elon Musk has vowed to wipe out all user data uploaded to SpaceXAI, following a shocking discovery that the company's AI tool, Grok Build, was secretly sending entire repositories, complete with full Git history and raw files, to a Google Cloud Storage bucket. The purge promises a clean slate, with Musk assuring that zero data will remain.

Analyst 207
Laptop and external hard drive on a desk with a blurred cloud storage interface nearby, indicating potential data exposure.

Grok Build Exposes Git Repositories to Unintended Storage

Elon Musk has made a bold promise to erase all user data uploaded to Grok Build before now, assuring users that their content will be completely deleted. This move comes after a researcher discovered that Grok Build was inadvertently storing entire Git repositories, including sensitive files and commit history, in a Google Cloud Storage bucket.

Analyst 207
Medical device on hospital bed with blurred computer records in background.

Medtronic Breach Exposes Patient Health Data to Cybercrooks

Medtronic is alerting patients that their personal and health information may have been compromised in a recent data breach, but has reassured them that the incident didn't impact the safe operation of its medical devices. The breach, detected on April 15, occurred between April 13 and 19, and Medtronic is now notifying affected individuals.

Analyst 207
Bank interior with teller counters, computers, and papers, hint of digital infrastructure in background.

India's .bank.in Domain Registry Exposes Sensitive Bank Employee Data

A major security slip-up by the registrar for India's .bank.in domain has left 5,576 bank employees' sensitive credentials and contact details exposed, putting their security at risk. This breach undermines the very purpose of the .bank.in namespace - to protect Indian banking web identities from phishers and fraudsters.

Analyst 207
Office workstation with laptop and CRM software, overlooking cityscape through large window.

Human Error Exposes Security Breaches Despite AI Advances

Despite advancements in AI, human error continues to expose security breaches, as seen in a recent Salesforce supply-chain compromise where a legacy credential was exploited. A company called Klue, which integrates with Salesforce, was compromised when attackers used OAuth tokens to access customer data.

Analyst 207
Rows of file cabinets and server racks in a brightly-lit corporate office with a slightly ajar cabinet drawer hinting at a…

Nissan Discloses Oracle PeopleSoft Breach Exposing Payroll Records

Nissan has alerted the California Attorney General to a potential data breach, revealing that a cyber attack on Oracle PeopleSoft systems may have exposed sensitive payroll records of hundreds of companies, including Nissan, from May 27 to June 9. The automaker believes it was specifically targeted in the attack, which may have compromised a range of personnel data.

Analyst 207
Securing Agentic AI Workspaces Requires Unified Governance

Securing Agentic AI Workspaces Requires Unified Governance

Nine out of 10 organisations are already harnessing AI assistants, but many are flying blind - unsure if these powerful tools have been compromised. As AI agents assume their own identities and access rights, a misconfigured or compromised agent can quickly become a high-speed pathway for data breaches and credential abuse.

Analyst 207
Worker's desk with desktop computer, papers, and blurred screen in bright office setting.

LastPass Breach Exposes Customer Data in Supply Chain Hack

LastPass recently discovered a security incident at Klue, a third-party platform they use, which led to an unauthorized actor accessing some customer data through its Salesforce environment. Fortunately, customer vaults and core products remain secure, and swift action has been taken to mitigate the breach.

Analyst 207
Modern office setting with computer servers and symbolic breach objects.

Icarus Hack Exposes Hundreds of Firms in Supply-Chain Breach

On June 11, a massive supply chain breach occurred when hackers exploited a weak link at Klue, a market intelligence provider used by over 250,000 companies worldwide, gaining access to sensitive data across hundreds of firms. The attackers used a compromised legacy credential to obtain OAuth tokens and infiltrate connected customer environments.

Analyst 207
Blurred screens and interfaces surround a prominent computer server in a dimly lit data center, conveying vulnerability.

US Carrier Exposed Credit Card Data in Clear Text

A newly hired database admin stumbled upon a shocking discovery on her first day - a main production server containing sensitive customer data, including full 16-digit credit card numbers stored in plain text, Social Security numbers, and billing information. The exposed data was found on a server that didn't even require a secondary system lookup, making it alarmingly accessible.

Analyst 207
Dimly lit server room with rows of computer equipment and a blurred figure in the background.

Telco Exposes Customer Data in Cleartext, Ignoring Basic Security Protocols

A new hire was granted sudo-level access to a live production database on their first day, with management's casual instruction to "take a look" - and promptly uncovered customer records stored in easily accessible cleartext. This alarming lapse in security protocols left sensitive customer information, including full personal details and payment numbers, exposed and vulnerable.

Analyst 207
Busy office scene with people working, an unattended laptop and other objects representing risks of weak passwords.

Weak Onboarding Passwords Expose Corporate Systems to Unnecessary Risk

Poorly handled onboarding passwords can put entire corporate systems at risk, exposing sensitive data to potential breaches - and it's a problem that's easier to prevent than you think. Temporary passwords sent via email or SMS can be intercepted, forwarded, or compromised, creating an open invitation for attackers.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit data center.

ServiceNow Security Incident Exposes Customer Data via API Flaw

ServiceNow recently patched a critical API flaw that allowed attackers to access sensitive customer data, but not before detecting anomalous activity that hinted at a broader intrusion. The company quietly alerted affected customers through a discreet support bulletin and direct outreach.

Analyst 207