Topic: investigation ongoing
-
Eurail and Interrail Traveler Data Breached
Eurail B.V. experienced a data breach exposing personal details, including passport/ID numbers, of customers who purchased train passes or reservations. The breach also compromised sensitive financial and health data for participants in the EU's DiscoverEU program, heightening risks of identity t...
Read More » -
Prosper Data Breach Exposes 17.6 Million Accounts
Prosper, a peer-to-peer lending platform, experienced a data breach compromising the personal details of approximately 17.6 million individuals, including current customers and loan applicants. Sensitive information such as Social Security numbers, names, addresses, and financial data was exfiltr...
Read More » -
Pennsylvania AG Office Hit by Ransomware, Court Cases Disrupted
A ransomware attack on Pennsylvania's Office of the Attorney General in August caused widespread disruption to court proceedings, forcing systems offline and highlighting public sector vulnerability to cyber threats. Officials confirmed no ransom was paid and are working to restore services, thou...
Read More » -
UN food agency data breach hits 600,000 Gaza households
The UN World Food Programme confirmed a data breach affecting its self-registration application for Palestine, exposing sensitive personal data of approximately 600,000 Gaza households, including names, ID numbers, and location details. The WFP assured beneficiaries that no action is needed and a...
Read More » -
GitHub confirms hackers breached thousands of internal repos
GitHub confirmed a breach that compromised approximately 3,800 internal code repositories after an employee's device was infected through a malicious VS Code extension, with no evidence of customer data exposure so far. The hacking group TeamPCP has claimed responsibility for the breach and is se...
Read More » -
CareCloud breach exposes patient medical records
A data breach at CareCloud on March 16 gave unauthorized access to a patient medical records repository for over eight hours, though it's unclear if data was stolen. The company, which serves millions of patients, quickly restored systems and launched an investigation but has not disclosed the nu...
Read More » -
Student Data Stolen in Victorian Education Dept Hack
An unauthorized party breached a Victorian Department of Education database, accessing student names, school details, and email addresses, but not more sensitive data like birth dates or home addresses. As a precaution, all student account passwords have been reset, with priority given to VCE stu...
Read More » -
SitusAMC Data Breach Exposes Client Information
SitusAMC experienced a significant data breach in mid-November 2025, exposing sensitive corporate and client data, including legal agreements and customer information, though no ransomware was used and operations continue uninterrupted. The company, which serves major financial institutions like ...
Read More » -
U.S. Found 100K SIM Cards That Could Have Crippled NYC's Cell Network
The U.S. Secret Service seized a massive telecommunications setup in New York City, comprising over 300 SIM servers and 100,000 SIM cards, which had the capability to severely disrupt or shut down mobile networks across the city. The equipment, discovered in multiple locations including abandoned...
Read More » -
Levi Strauss confirms hackers stole corporate data in cyberattack
Levi Strauss & Co. confirmed a cyberattack involving theft of corporate data, after hackers used social engineering to compromise three employees' company-issued computers. The company stated its rapid response contained the breach, with no consumer data impacted, and business operations continue...
Read More » -
Betterment Data Breach Exposed in Fake Crypto Scam Alert
A social engineering attack on third-party platforms allowed hackers to breach Betterment's internal systems, compromising sensitive customer data like names, addresses, and dates of birth. The attackers used the stolen information to send a fraudulent cryptocurrency scam message, but Betterment ...
Read More » -
Romania’s land registry hacked, stolen data reportedly for sale
Romania's ANCPI experienced a severe operational breakdown of its e-Terra land registry system on July 14, initially called a technical incident but now officially classified as a cyber attack, with the agency stating that data has not been compromised. The outage has halted property transactions...
Read More » -
ManoMano Data Breach Exposes 38 Million European Customers
A major data breach at European online retailer ManoMano, originating from a compromised third-party service provider in January 2026, exposed personal data of approximately 38 million customers. The stolen information includes full names, email addresses, phone numbers, and customer service comm...
Read More » -
US Banks Rush to Assess Data Theft After Hackers Breach Fintech Firm
A cybersecurity breach at financial technology provider SitusAMC has compromised sensitive corporate data, including accounting records and legal agreements, affecting major banks like JPMorgan Chase and Citigroup. The attack, discovered on November 12, has been contained with no ransomware used,...
Read More » -
Nissan Employee Data Breach Tied to Oracle Zero-Day
Nissan confirmed a breach via a zero-day vulnerability in Oracle PeopleSoft (CVE-2026-35273), exposing sensitive personal data including Social Security numbers, banking details, and tax records of current and former employees in the US, Canada, Mexico, and Brazil. The attack occurred between May...
Read More » -
Substack Confirms Data Breach Exposing User Information
Substack experienced a security breach where an unauthorized party accessed limited user data, including email addresses and phone numbers, in October 2025, but the company only detected and disclosed it in February. The company confirmed that no financial information or passwords were compromise...
Read More » -
Step Finance Blames Hacked Execs for $40M Crypto Theft
A major Solana analytics platform suffered a $40 million security breach, attributed to compromised executive devices, highlighting critical vulnerabilities in DeFi beyond smart contract audits. The breach involved unauthorized access to treasury wallets via a known attack vector, with the platfo...
Read More » -
Upbound hack leads to $13M in fraudulent Acima leases
Upbound Group disclosed a cybersecurity breach that led to $13 million in fraudulent leases through its Acima brand, with threat actors using stolen non-sensitive customer data to create fake lease-to-own agreements and defaulting on payments. The company responded by implementing enhanced authen...
Read More » -
Grafana Labs source code stolen, refuses to pay hacker ransom
Grafana Labs confirmed a security breach where hackers exploited a stolen token to access its GitLab source code repositories, but the company will not pay the ransom demanded to prevent code release. The breach did not compromise customer records or financial data, and Grafana has revoked the co...
Read More » -
West Pharmaceutical confirms hackers stole data, encrypted systems
West Pharmaceutical Services suffered a material cyberattack on May 4, 2026, involving both data exfiltration and system encryption, prompting an immediate global shutdown of systems and law enforcement notification. The attack disrupted global business operations, and while core systems for ship...
Read More »