Tag: third party breach
10 articles

Trezor Users Targeted in Phishing Attacks After Email Breach
Beware of a phishing scam targeting Trezor users: a fake "Critical Security Alert" email is circulating, claiming to be from Trezor but is actually an attempt to steal your info. Don't click on any links - Trezor has confirmed it's a scam and is investigating.

Supply Chain Hack Exposes Pokémon Center Customer Data
A recent supply chain hack exposed sensitive customer data at the Pokémon Center, but fortunately, the breach occurred through a third-party logistics partner, CEVA, and not directly through the retailer's own systems. The incident, triggered by CEVA's notification on July 30, compromised customer order details for Pokémon Center's UK and German shipments.

Wesco Probes Data Exfiltration After ExfilSquad Leak Claim
Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.
Beacon CRM Breach Exposes UK Charity Data
A cyberattack on Beacon CRM has compromised the data of a UK charity, with the company confirming that an unauthorized third-party likely downloaded copies of its database backups. If you're a Beacon CRM user, it's best to assume that all your stored data, including files, may have been accessed.

Chick-fil-A Exposes Customer Data in Credential Stuffing Breach
Chick-fil-A is alerting customers to a credential stuffing breach that compromised some of its website and mobile app accounts between June 17 and June 19, 2026, using stolen account credentials from a third-party source. If you have a Chick-fil-A One account, you should check your email for a notification from the company and take immediate action to secure your account.

Hackers Inject Malicious Script in Polymarket Supply-Chain Attack
Polymarket has pledged to fully reimburse customers who lost around $3 million in a shocking supply-chain attack that injected malicious JavaScript into the platform's frontend via a third-party vendor breach. The incident highlights the vulnerability of even major players to these types of attacks.

Oxford University Exposes Data Breach After Career Platform Hack
The University of Oxford recently alerted users to a data breach on its CareerConnect platform, which occurred on May 28 when attackers gained access to sensitive information, including names, email addresses, and encrypted passwords. To protect users, locally set passwords have been invalidated and affected users will be prompted to reset their passwords upon next login.

GitHub Breach Exposes 3800 Internal Repositories to Malicious VS Code Extension
GitHub's security team swiftly contained a breach that exposed 3,800 internal repositories to a malicious VS Code extension, and immediately took action to prevent further damage. The company has completed critical secret rotations and is now meticulously analyzing logs to ensure the incident is fully resolved.

NVIDIA Discloses GeForce NOW Breach Affecting Armenian Users
NVIDIA recently discovered a security breach affecting users of GeForce NOW in Armenia, which was caused by a compromised system operated by a third-party partner, not by NVIDIA's own network. The company is working closely with the partner to resolve the issue and notify affected users.

Medtronic, Itron Disclose Breaches by Digital Intruders
Itron sprang into action after detecting an unauthorized break-in on April 13, swiftly notifying law enforcement, and working with cybersecurity experts to investigate and remediate the breach. The company has since confirmed that it has prevented any further unauthorized activity within its corporate systems.