Topic: customer notification
-
Framework warns all customers of data breach
Framework suffered a data breach exposing customer names, emails, phone numbers, and addresses, caused by a third-party provider (Metabase) attack, not a direct breach of Framework's systems. The breach affected all customers, with the attacker exploiting a zero-day vulnerability in Metabase's cl...
Read More » -
Lidl online shop breached after service provider hack
Lidl is notifying customers in Germany, Belgium, and the Netherlands that their personal data was stolen in a breach at a third-party service provider, which briefly accessed a file containing customer information from the online shop. The stolen data includes salutation, name, phone number, emai...
Read More » -
SoFi Hong Kong subsidiary hit by third-party data breach
SoFi Hong Kong suffered a data breach after unauthorized access to a database managed by a third-party vendor, discovered on April 30, 2026. The full scope of the breach and which customer data was exposed remains unknown, with an external cybersecurity firm assisting the investigation. SoFi has ...
Read More » -
AI startup Braintrust confirms breach, urges all customers to rotate keys
Braintrust, an AI evaluation startup, is advising all customers to rotate their API keys after an unauthorized party accessed one of its AWS cloud accounts containing customer secrets. The company has contained the breach by locking down the compromised account and auditing access, but an investi...
Read More » -
MANGO Data Breach Exposes Customer Information
MANGO alerted customers to a data breach caused by a third-party marketing partner, exposing personal information like names, email addresses, and phone numbers, but not sensitive financial or password data. The company confirmed its own systems were not compromised, operations continued uninterr...
Read More » -
Renault and Dacia UK alert customers to data breach
Renault and Dacia customers in the UK were affected by a data breach at an unnamed third-party service provider, exposing personal details like names, addresses, and vehicle information. The breach did not compromise banking or financial data, and the third-party provider has contained the threat...
Read More » -
Framework Reduces RAM in Premium Laptop Shipments
Framework has announced a pricing revision for its Laptop 13 Pro due to memory supplier cost increases of more than double, affecting existing preorders with adjusted memory configurations and prices. Some customers are being notified of changes to their preorder's memory setup and price, with Fr...
Read More » -
Ernst & Young data breach exposed after support system hack
EY is alerting clients about a data breach that originated from a compromise of a third-party support ticket system used by its IT staff, exposing sensitive client information. The breach highlights the vulnerability of relying on external vendors for IT support, as a third-party compromise can c...
Read More » -
SonicWall Confirms Firewall Backup Files Breached in Cyberattack
SonicWall experienced a security breach where unauthorized access to its cloud backup service exposed sensitive firewall configuration data for a small subset of customers. The compromised files did not contain unencrypted credentials but included details that could help threat actors target rela...
Read More » -
ManoMano Data Breach Exposes 38 Million European Customers
A major data breach at European online retailer ManoMano, originating from a compromised third-party service provider in January 2026, exposed personal data of approximately 38 million customers. The stolen information includes full names, email addresses, phone numbers, and customer service comm...
Read More » -
Toys "R" Us Canada Data Breach Exposes Customer Information
Toys "R" Us Canada experienced a data breach where unauthorized individuals accessed and distributed customer information, discovered on July 30, 2025, via a dark web posting. The compromised data includes personal details like names, addresses, emails, and phone numbers, but sensitive financial ...
Read More » -
DraftKings Users Hit by Widespread Account Hacks
DraftKings experienced unauthorized account access through a credential stuffing attack, where attackers used stolen login details from external sources to compromise user accounts. The breach exposed personal details like names and contact information, but sensitive data such as full payment car...
Read More » -
Telstra hit with $18m fine over false broadband speed claims
Telstra has been fined $18 million by the Federal Court for downgrading the internet plans of nearly 9,000 Belong customers without their consent, reducing upload speeds from 40 Mbps to 20 Mbps. The ACCC emphasized that the penalty warns businesses against misleading consumers by altering service...
Read More » -
Allianz Life Data Breach Exposes 1.5 Million Customers
Allianz Life experienced a cybersecurity breach compromising personal data of nearly 1.5 million individuals, including names, addresses, birth dates, and Social Security numbers, through a third-party cloud system. The breach has been linked to the ShinyHunters group targeting Salesforce systems...
Read More » -
Vercel Confirms Security Breach
Vercel confirmed a security breach where a "highly sophisticated" attacker exploited an employee's use of third-party tool Context.ai to access Google Workspace and view non-sensitive environment variables. The company stated no npm packages were compromised, meaning Next.js remains safe, and sen...
Read More » -
SitusAMC Data Breach Exposes Client Information
SitusAMC experienced a significant data breach in mid-November 2025, exposing sensitive corporate and client data, including legal agreements and customer information, though no ransomware was used and operations continue uninterrupted. The company, which serves major financial institutions like ...
Read More » -
Medtronic notifies customers of ShinyHunters data breach
Medtronic is notifying customers of a cybersecurity breach by the ShinyHunters extortion group, which exposed sensitive data including names, Social Security numbers, and health information between April 13-19, 2026. The hackers threatened to release over 9 million records but the listing was lat...
Read More » -
Infinite Campus breach alert follows ShinyHunters data theft claim
Infinite Campus, a major student information system provider, notified clients of a data breach after the ShinyHunters cybercriminal group accessed an employee's Salesforce account, but maintains no student databases were compromised. The ShinyHunters group, known for exploiting Salesforce securi...
Read More » -
Optimizely Data Breach Confirmed After Vishing Attack
Optimizely, a major ad-tech firm, suffered a security breach after a sophisticated voice-phishing attack on February 11th, which allowed intruders to access basic business contact information from its CRM. The company confirmed the attackers were contained and could not access sensitive customer ...
Read More » -
Eurail and Interrail Traveler Data Breached
Eurail B.V. experienced a data breach exposing personal details, including passport/ID numbers, of customers who purchased train passes or reservations. The breach also compromised sensitive financial and health data for participants in the EU's DiscoverEU program, heightening risks of identity t...
Read More »