Topic: customer data exposure
-
Ultrahuman hackers stole customer wellness data via internal tool
A hacker stole an employee's login credentials via malware to access Ultrahuman's internal analytics system on March 27, exposing wellness data for roughly 0.1% of users (at least 700 customers). The breach was detected within hours, leading to an immediate shutdown of the compromised system, and...
Read More » -
Ceva Logistics Data Breach Hits European Clients
A cyberattack on Ceva Logistics' European contract logistics division exposed sensitive customer data (names, addresses, phone numbers, and order details) from eight warehouses, affecting clients like Valve, Bol, De Bijenkorf, Ajax, and ING. Security experts warn that logistics firms are prime ta...
Read More » -
Basic-Fit Data Breach Impacts 1 Million Gym Members
A major data breach at European fitness chain Basic-Fit has compromised the personal information of approximately one million members across its operating regions. The exposed data likely includes sensitive details like names and contact information, prompting the company to activate its incident...
Read More » -
Colt Data Breach: Customer Information Compromised in Cyber-Attack
Colt Technology Services has confirmed a significant data breach potentially exposing sensitive customer information, revising earlier assurances that the attack was contained to internal systems. The company is urgently working to determine the full scope of the compromised data and has set up a...
Read More » -
Qantas Data Breach Exposes 5.7 Million Customers' Info
Qantas disclosed a data breach affecting 5.7 million customers, with sensitive personal information stolen via a third-party contact center platform, potentially linked to the Scattered Spider hacking group. The breach exposed basic details (e.g., names, emails) for 4 million customers, while 1.7...
Read More » -
Qantas Hit by Cyberattack in Recent Data Theft Incident
Qantas confirmed a cyberattack affecting up to 6 million customers, exposing personal data like names, emails, and frequent flyer details, but financial data remained secure. The breach, detected on July 1, involved a third-party system, and Qantas is working with authorities and cybersecurity ex...
Read More » -
Qantas hit by cyberattack amid aviation security breaches
Qantas confirmed a cybersecurity breach affecting customer data on a third-party platform, potentially exposing personal details like names, emails, and frequent flyer numbers, but no financial or login credentials. The breach shares similarities with attacks by the hacking group Scattered Spider...
Read More » -
TaskUs Staff Implicated in Coinbase Data Breach, Court Docs Claim
A TaskUs employee was identified as the central figure in a major data breach at Coinbase, involving stolen customer data and social engineering attacks. The breach compromised nearly 70,000 users' personal information, leading to a $20 million ransom demand and significant financial losses. Task...
Read More » -
Qualys, Tenable Hit in Salesloft Data Breach
Tenable and Qualys experienced unauthorized access to their Salesforce data due to stolen OAuth tokens from the Salesloft Drift application, highlighting risks from third-party integrations. Both firms confirmed their core products and services were unaffected, and they responded by disabling the...
Read More » -
Italy fined €1.7M over security flaws linked to two data breaches
Italy's data protection authority fined telecom giant WINDTRE €1.7 million for serious security failures after two cyberattacks in February 2025 compromised over 365,000 customers' personal data, with 41,359 victims also having payment information stolen. The attackers used social engineering to ...
Read More » -
Luxury Giants Louis Vuitton, Dior, Tiffany Fined $25M for Data Breaches
South Korea's Personal Information Protection Commission (PIPC) has fined Louis Vuitton, Christian Dior, and Tiffany a total of $25 million for data breaches that exposed over 5.5 million customers' personal information due to inadequate security on shared cloud platforms. The breaches occurred t...
Read More » -
Cloudflare Data Breach Linked to Salesloft Drift Supply Chain Attack
Cloudflare experienced a supply chain attack via its Salesforce customer support system, exposing API tokens and sensitive customer data, including contact details and support case information. The breach, occurring between August 12-17, is part of a broader campaign targeting multiple organizati...
Read More » -
LastPass confirms breach in Klue supply chain attack
LastPass confirmed a data breach after attackers stole OAuth tokens during the Klue supply chain attack, compromising customer data in its Salesforce environment without affecting core password vaults or master passwords. Hackers exploited vulnerabilities in the third-party platform Klue to captu...
Read More » -
Suno AI Trained on 2M+ YouTube Songs
A hacker leaked Suno's source code, revealing the AI music company scraped millions of songs and lyrics from YouTube, Deezer, Genius, and Pond5 to train its model, including over 2 million YouTube video clips and 420,000 podcasts. Suno employed targeted methods like searching for a cappella versi...
Read More » -
Odido Data Breach: ShinyHunters Gang Claims Millions Affected
The ShinyHunters extortion gang breached Dutch telecom provider Odido, potentially exposing millions of customers' sensitive personal data like names, addresses, and ID numbers, though the company states passwords and financial details were not compromised. Odido and the attackers dispute the sca...
Read More » -
SafePal data breach exposes 39,798 customers' info for sale
SafePal disclosed a data breach affecting approximately 39,798 customers who placed orders between March 2, 2025, and April 11, 2026, with exposed data including names, emails, shipping addresses, phone numbers, and purchase details,but no wallet credentials, seed phrases, or financial informatio...
Read More » -
ADT data breach exposes info of 5.5 million customers
ADT suffered a data breach by the ShinyHunters group, exposing personal data of 5.5 million individuals including names, phone numbers, addresses, and partial government IDs, but no payment information or security system data was compromised. The breach began when attackers compromised an employe...
Read More »