Skip to main content

Tag: data leak

32 articles

Bank lobby with blurred employee in background, flooded with natural daylight through large window or glass door.

US Bank Probes LockBit Ransomware Claim, Faces Data Leak Deadline

US Bank is investigating a potential cybersecurity incident after LockBit ransomware crew claimed to have breached the institution and stolen sensitive data. The bank has assured that there's currently no indication of internal system impacts or unauthorized network access.

Analyst 207
Close-up of a computer processor in a clean-room setting with blurred background and technical equipment.

Loongson Processors Expose Data Through Leaky Caches

Researchers at Germany's Helmholtz Center for Information Security have uncovered a vulnerability in Loongson processors that allows data to leak from the L1 data cache, putting sensitive information at risk. This surprising discovery was made by fuzzing Loongson processors and tracing an "uncertain" state in a specific instruction back to its source.

Analyst 207
Server equipment sits in a brightly-lit office, symbolizing data security.

Tribeca Film Festival Data Leak Reveals Celebrity Records

The Tribeca Film Festival recently suffered a data leak, exposing a whopping 666,369 records, including sensitive celebrity information, after a cybersecurity researcher discovered three unsecured databases left vulnerable to public access. The festival has since taken swift action, assuring the researcher that they are actively investigating and taking data security very seriously.

Analyst 207
UK government office with papers scattered, slightly ajar file cabinet, and blurred computer screen in background.

UK Government Investments Exposes Official Contact Data in 40-Hour Breach

A simple mistake by a staff member at UK Government Investments left sensitive contact information of 51 government officials exposed to the public for a staggering 40 hours. The breach, revealed in the organization's annual report, highlights the importance of following basic security protocols to protect official data.

Analyst 207
Smartphone displaying Click To Pray app in a neutral room with subtle church background.

Pope's Prayer App Leaks 700K Users' Info Amid Security Vulnerability

A shocking security breach has been uncovered in the Pope's official prayer app, Click To Pray, exposing the sensitive information of over 719,000 registered users for months due to a vulnerability that allowed anyone to access account data. The flaw, discovered by an ethical hacker, highlights the alarming risks of unsecured personal data.

Analyst 207
Dairy factory computer workstation with scattered papers and industrial equipment in the background.

Anubis Ransomware Targets Coca-Cola's Fairlife, Threatens Data Leak

The Anubis ransomware gang has claimed responsibility for a cyberattack on Fairlife, a subsidiary of The Coca-Cola Company, boasting that they encrypted the company's systems and stole a whopping one terabyte of corporate data. With a deadline looming, the gang is threatening to leak the sensitive information unless Coca-Cola agrees to negotiate by the end of the week.

Analyst 207
CISA Leak Exposes Gaps in Incident Response, Key Management

CISA Leak Exposes Gaps in Incident Response, Key Management

A staggering 844 MB of sensitive CISA data was left exposed in a public GitHub repository for almost six months, revealing critical gaps in incident response and key management. The leak included admin credentials and plaintext passwords for internal CISA systems, raising serious concerns about security protocols.

Analyst 207
Government office interior with concerned officials in a public records room.

US County Pays $1M to Cyber Extortionists Amid Data Leak Threat

A US county recently made a shocking decision to pay $1 million to cyber extortionists, despite lacking concrete proof that the hackers had deleted the stolen data, after a month-long negotiation that began with a hefty demand of $3 million. The extortion group, Kairos, had threatened to leak sensitive information, prompting the county to make a counteroffer that was ultimately outweighed by the threat.

Analyst 207
GitHub issue page on laptop with public repository and subtle hint of private content exposure.

GitHub Agentic Workflows Exposed to Data Leak Threat via Public Issues

GitHub's Agentic Workflows are vulnerable to a data leak threat, as researchers have demonstrated a clever technique called GitLost that tricks AI agents into spilling private content from secure repositories into public comments. All it takes is a simple public issue to launch the attack, with no stolen credentials or special access required.

Analyst 207
Secure facility interior with a symbolic payment terminal or encrypted data storage device.

US Government Entity Pays $1 Million to Thwart Data Leak

A US government entity was forced to pay a hefty $1 million ransom to prevent a massive data leak, after a group called Kairos threatened to release 1.6 million files unless their demand was met. The payment was the culmination of a month-long negotiation that began with a $3 million opening demand.

Analyst 207
Passport lies on a plain surface surrounded by blurred cannabis dispensary items, hinting at a security breach.

Massive Passport Leak Exposes Sensitive Traveler Data

A staggering leak of almost a million passport records from around the world has put sensitive traveler data at risk. The breach, linked to a low-security ID verification system for cannabis dispensaries, exposed passports as a vulnerable weak point in authentication processes.

Analyst 207
Dimly lit office cubicle with scattered papers, open laptop, and concerned coworkers in the background.

Huntress Insider Leak Exposes Potential Security Breach

A shocking security breach at Huntress has come to light, with a former analyst claiming that a colleague may have compromised the company's integrity by passing sensitive law enforcement communications to a notorious cybercriminal. The explosive allegations have left many questions unanswered about the breach and its potential impact.

Analyst 207
Dimly lit server room with rows of computer servers and storage equipment, some screens displaying abstract interfaces.

Shadow AI Exposes 2,000 Vibe-Coded Apps with Sensitive Data

A shocking discovery by Red Access revealed over 2,000 apps with sensitive corporate, operational, or personal data exposed online, leaving countless organizations vulnerable to risk. These apps, found on popular vibe-coding platforms, were often deployed without basic security controls, granting open access to sensitive information.

Analyst 207
A somber-colored file folder lies on a desk with a blurred computer screen in the background.

US Bank Self-Reports Data Leak to Unauthorized AI App

A US bank has taken swift action, self-reporting a data leak that exposed sensitive customer information to an unauthorized AI app, sparking concerns over the volume and sensitivity of the compromised data. The bank's proactive disclosure to regulators and customers highlights its commitment to transparency in the face of a data-handling lapse.

Analyst 207
Laptop screen on a plain surface with a blurred office background and subtle cloud connection hint.

Instructure Pays Ransom to ShinyHunters to Prevent 3.65TB Canvas Data Leak

In a stunning move, Instructure paid a ransom to the notorious ShinyHunters group to prevent a massive 3.65TB data leak from its Canvas learning-management system. The Utah-based company reached a deal with the hackers, securing the safe return of stolen data and a guarantee that its customers wouldn't be extorted individually.

Analyst 207
Empty college corridor with students and faculty showing subtle concern.

Instructure Discloses Double Breach Amid ShinyHunters' Data Leak Threat

In a shocking security breach, Instructure, the creator of Canvas, revealed not one, but two separate intrusions into its system, leaving thousands of schools and students scrambling for access to crucial course materials during final exams. The breaches come as an extortion group, ShinyHunters, threatens to leak a massive 3.65 TB of stolen data.

Analyst 207
Rows of computer servers with flickering screens and dimmed lights suggest a breach or disruption in a technology company's…

RansomHouse Hackers Claim Breach of Trellix Source Code

Trellix has confirmed a breach of its source code repository, with hackers from the notorious RansomHouse group claiming to have accessed and encrypted sensitive data on April 17. The group has even posted leaked screenshots to back up its claims.

Analyst 207
Brightly-lit video editing workspace with equipment and subtle hints of email materials.

ShinyHunters Leak Exposes 119K Vimeo Emails

A massive data leak, allegedly perpetrated by the threat actor group ShinyHunters, has put 119,000 Vimeo email addresses at risk, according to a recent report. This alarming breach raises serious concerns about online data security and user privacy.

Analyst 207
Computer screen displays blurred Excel spreadsheet in brightly-lit office with DevOps folder visible in background.

Fintech Firm Exposes Database Credentials in Shared Spreadsheet

A fintech firm's most sensitive secrets were left exposed in a shared spreadsheet, with a password that was embarrassingly simple - literally a combination of the company's name and the year. The shocking discovery was made by Stanislav Kazanov during a routine compliance audit, when he stumbled upon a widely accessible SharePoint folder containing a file ominously titled Prod_DB_Root_Creds_DO_NOT_SHARE.xlsx.

Analyst 207
Large, empty development environment with rows of code on sleek computer screens against a neutral background.

Checkmarx GitHub Data Leaked by LAPSUS$ Hackers

Checkmarx confirmed that hackers from the LAPSUS$ group breached its GitHub repository on March 23, 2026, and published stolen data on April 22, after a series of supply-chain and credential-theft events. The attackers used the access to publish malicious code to certain artifacts, compromising the integrity of Checkmarx's software development process.

Analyst 207
Shattered padlock on cracked digital surface with error message and accusatory finger in background.

Lovable Disputes Data Leak, Shifts Blame to HackerOne

Lovable, a coding platform, is facing scrutiny after a security researcher uncovered a major data leak, exposing users' sensitive information, including credentials, chat history, and source code, to anyone with a free account. The company's shifting explanations have only added fuel to the fire, sparking concerns about its data handling practices.

Analyst 207
A broken padlock lies on a dark, cracked surface with scattered credentials and a laptop screen glowing in the background.

Vercel Discloses Credential Breach Tied to OAuth Mishandling

Vercel recently disclosed a credential breach affecting some customer credentials, which they attribute to an outside developer platform, Context.ai, citing an OAuth mishandling issue. The incident highlights the risks of complex authentication processes and the importance of secure credential management.

Analyst 207
Shattered padlock and scattered papers near laptop glow, cityscape visible through cracked window, conveying vulnerability.

McGraw Hill Data Leak Exposes 13.5M Records After Salesforce Misconfiguration

McGraw Hill, a leading publisher of educational materials, recently suffered a significant data leak, exposing a staggering 13.5 million records due to a misconfigured Salesforce-hosted page. This alarming breach highlights the importance of robust data security measures, even for companies with a traditional focus like textbook publishing.

Analyst 207
Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware Attacks Evolve to Exploit Stolen Data for Double Extortion

Ransomware attacks have taken a sinister turn, now using stolen data to blackmail victims into paying up - not just by encrypting their files, but by threatening to expose sensitive information to the world. This double extortion tactic adds a whole new level of pressure, forcing victims to weigh the cost of a data breach against the cost of a ransom.

Analyst 207