Breach Accountability
The ongoing major issues seen in articles and topics over time.
The Drivers
102
Articles Related
3,035
The Big Picture

The enduring theme is how organizations prevent, disclose, remediate, and compensate for personal-data breaches, especially when breaches involve vendors, cloud platforms, ransomware, or insider misuse. It includes notification duties, litigation exposure, settlements, credit monitoring, and downstream fraud risk.
Personal-data breaches remain one of the most persistent privacy harms because they convert weak security governance into long-term identity, financial, reputational, and legal consequences for individuals and institutions. The repeated settlement activity shows that breach response is now a standing legal and operational accountability regime, not merely a cybersecurity incident cycle.
Categories
Data Breaches & Exposure Events, Cybersecurity (Privacy-Relevant), Regulation, Law & Enforcement, Corporate Data Practices & Accountability
Keywords
AI supply-chain breach, API key rotation, attorney general breach filing, breach class action, breach notice timing, breach notification template, breach portal vetting, breach reporting rules, breach settlement, breach-enabled fraud, Canvas breach, clinical trial breach, cloud identity breach, corporate breach notification, credential compromise, credit union breach, customer data exfiltration, dark web exposure, data deletion promise, documented loss reimbursement, driver data breach, EDPB breach template, education platform breach, employee benefits breach, false breach notice, financial services breach, forensic cooperation, fraudulent breach notice, health insurer breach, HR payroll breach, identity monitoring settlement, insurer data breach, Klue breach, LiteLLM compromise, long-lived token risk, non-human identity breach, OAuth token compromise, OAuth token theft, Oracle PeopleSoft exploitation, pseudonymized data breach, public-sector vendor breach, ransom-linked deletion, ransomware extortion, SaaS integration breach, Salesforce integration breach, service account exposure, service management platform breach, ShinyHunters extortion, state attorney general breach notice, tax document exposure, third-party integration breach, third-party platform breach, vendor access control failure, vendor breach response
The Drivers
The Topics below, and their articles, all focus on, exemplify, or help to explain this theme.
Primary
- 99
Fidelity Data Breach Settlement

Fidelity Investments and Fidelity Brokerage Services reached a $2.5 million settlement resolving claims tied to unauthorized network access in August 2024. The case involved alleged exposure of Social Security numbers, driver-license data, financial account information, and routing numbers, with potentially more than 160,000 people eligible for benefits. The settlement provides compensation for documented losses and pro rata payments, alongside identity-theft or credit-monitoring services, and illustrates how breach victims are pursuing recovery through class-action litigation.
Articles: 62
Last Updated: 07/31/2026
- 99
Companies Settle Consumer Data Breach Claims

Companies including Comcast, STIIIZY, Compex Legal Services, and SitusAMC are resolving or proposing settlements tied to incidents that exposed consumers’ personal or health information. The remedies generally combine cash payments or reimbursement for documented losses with credit monitoring, identity-theft services, and, in some cases, changes to cybersecurity practices. Eligibility rules, claim deadlines, approval hearings, and pro rata payment terms remain central to the practical impact for affected individuals.
Articles: 60
Last Updated: 07/30/2026
- 99
Eurail Traveler Data Breach Fallout

Recent coverage is dominated by Eurail's disclosure of a December 2025 breach affecting roughly 308,777 travelers and exposing passport, contact, and other sensitive records. Reporting emphasizes dark-web resale, Telegram samples, regulator notifications, and advice to monitor for fraud and phishing.
Articles: 15
Last Updated: 07/01/2026
- 99
Companies Settle Consumer Data Breach Claims

U.S. companies are facing continuing consumer data-breach litigation and settlement activity involving Social Security numbers, financial information, health data, and other personal identifiers. The agreements generally offer reimbursement for documented identity-theft or fraud-related losses, smaller proof-free cash payments, and sometimes credit monitoring, while companies deny wrongdoing or settle without admitting liability. The material also shows that breach remediation increasingly extends beyond incident notification to court-supervised claims deadlines and consumer identity-protection services.
Articles: 10
Last Updated: 07/30/2026
- 99
Moveit Breach Settlement Wave

Recent coverage tracks class action settlements tied to the 2023 MOVEit breach, with banks and service providers offering cash payments, loss reimbursement, and credit monitoring after exposure of customer personal data.
Articles: 6
Last Updated: 07/22/2026
- 99
ICO Fines South Staffordshire Water

The UK Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc about £964,000 after a cyberattack exposed the personal data of more than 633,000 customers and employees. The intrusion began with phishing in 2020, remained undetected for nearly two years, and involved privilege escalation, inadequate monitoring, obsolete software, and unpatched systems before data was published on the dark web. The case highlights regulatory scrutiny of cybersecurity controls at water providers and the consequences of delayed breach detection.
Articles: 4
Last Updated: 05/15/2026
- 99
Carnival Breach Exposes Passenger ID Data

Carnival Corporation disclosed that an attacker used social engineering to compromise an employee account and access a limited portion of its IT environment in April 2026. The company later determined that personal information had been copied, potentially affecting nearly 6 million people, with exposed data varying by individual and including government-issued identification details. Carnival is notifying affected individuals, offering U.S. customers two years of credit monitoring, and investigating the incident with outside experts, while ShinyHunters has claimed responsibility without public attribution from Carnival.
Articles: 75
Last Updated: 07/24/2026
- 99
Vendor-Linked Bank Data Breaches

The cluster is centered on recent bank data breach incidents where third-party/vendor compromise appears to be the main exposure path, with Everest-linked ransomware leak activity, customer notification issues, and emerging litigation over alleged privacy and security failures. The current signal is strongest around Citizens Bank and Frost Bank, while one article adds legal escalation through proposed class actions.
Articles: 3
Last Updated: 05/04/2026
- 99
Pillsbury Completes Breach Notifications

Pillsbury Winthrop Shaw Pittman completed notifications connected to a prior-year social-engineering incident in which an unauthorized actor accessed some firm documents during a short window. The firm said it detected and blocked the activity, reviewed the accessed material for personal information, notified affected clients and individuals, and published substitute notice as the final step. A related proposed class action was voluntarily dismissed without prejudice after mediation, leaving the litigation outcome unresolved.
Articles: 4
Last Updated: 07/21/2026
- 99
Nottingham Student Data Breach

The University of Nottingham confirmed a cyber-attack that exposed a significant amount of data from its student record system, affecting current students and alumni. Reporting indicates the leaked material may include financial details and a wide range of personal identifiers, making the incident both a privacy and identity-risk issue. The university has notified regulators and law enforcement, set up a helpline, and is contacting affected people directly while the investigation continues.
Articles: 12
Last Updated: 07/30/2026
- 99
European Institutions Face Cloud Extortion

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats. The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.
Articles: 8
Last Updated: 06/16/2026
- 99
Cash App Faces Security And Fraud Scrutiny

Cash App owner Block, Inc. is facing scrutiny over alleged weaknesses in fraud protections, identity verification, customer support, and handling of unauthorized activity. A multistate settlement requires $45 million in payments and operational changes, while separate reporting and consumer guidance address earlier data-exposure incidents, settlement eligibility, and account-security steps. The central concern is whether Cash App users received protections and assistance comparable to those associated with traditional banking services.
Articles: 12
Last Updated: 07/08/2026
- 99
Data Breaches Trigger Settlements And Monitoring

The topic centers on U.S. organizations responding to data breaches involving employee, contractor, patient, and consumer information through class action settlements, breach notifications, credit monitoring, and additional security measures. Reported exposures include Social Security numbers, taxpayer identification numbers, names, addresses, and medical information, while settlement benefits generally depend on documented losses, claim volume, and court approval. The pattern highlights the continuing legal and consumer-protection consequences of unauthorized access to corporate systems.
Articles: 10
Last Updated: 07/24/2026
- 99
Krispy Kreme Breach Settlement Claims

Recent coverage is dominated by the claims process for a Krispy Kreme data-breach settlement tied to a November 2024 cyber incident. The recurring facts are a roughly $1.6 million fund, allegations of exposure of Social Security numbers and financial account data, and June 2026 deadlines for filing, objections, and opt-outs. The most stable pattern is a settlement framework built around limited cash payments, reimbursement for documented losses, and one year of credit monitoring. The topic is coherent and narrow, with little fragmentation beyond small differences in reported dates, affected-population counts, and whether the incident is described as a breach, ransomware attack, or unauthorized access. It reads as an ongoing operational/legal matter rather than a broad or fast-changing privacy debate.
Articles: 40
Last Updated: 06/22/2026
- 99
Data Breach Class Actions Spread

Organizations in the legal, financial, healthcare, and home-security sectors are facing lawsuits after cyber incidents allegedly exposed personally identifiable, financial, or employee data. Complaints commonly assert inadequate safeguards, employee training, multi-factor authentication, or breach notification, while defendants dispute the scope or impact of some incidents. The cases illustrate how cyberattacks are generating continuing legal exposure beyond the initial intrusion, including proposed class actions, demands for stronger controls, and disputes over damages and disclosure timing.
Articles: 26
Last Updated: 07/28/2026
- 98
Companies Disclose Breaches Exposing Social Security Numbers

Organizations across logistics, manufacturing, insurance, heavy equipment, construction, and healthcare technology are disclosing breaches involving Social Security numbers and other sensitive personal information. Several incidents also exposed government IDs, financial records, health data, or employee and customer information, while some organizations have not yet provided complete impact counts or data details. The disclosures underscore the continuing exposure of identity and financial information during investigations that can extend months after initial unauthorized access.
Articles: 13
Last Updated: 07/29/2026
- 98
Hong Kong Data Breaches Expose Customers

Two significant cyber incidents in Hong Kong exposed or potentially exposed personal information held by a private club and Shun Hing Group. The cases involve ransomware or malicious encryption, unauthorized system access, and records covering hundreds of thousands of customers and other individuals. They underscore the operational and privacy impact of weaknesses in remote access, authentication, and security maintenance, while investigations continue to clarify the full scope of the Shun Hing breach.
Articles: 3
Last Updated: 07/03/2026
- 98
Ransomware Shifts Toward Data Theft

Ransomware is increasingly monetized through stolen data and extortion, either alongside encryption or without it, as attackers exploit the threat of publication, resale, and downstream pressure on customers or partners. Organizations are often detecting intrusions only after data theft, while improved recovery capabilities, regulatory scrutiny, and law-enforcement activity appear to be reducing the share of victims that pay. The threat remains significant because attacks are becoming more fragmented, operationally disruptive, and capable of extracting larger payments from a smaller pool of willing victims.
Articles: 23
Last Updated: 07/30/2026
- 98
Booking.com Reservation Breaches

This topic centers on Booking.com and related travel booking portals exposing traveler data through breaches, suspicious access, or insecure third-party systems. The disclosed information commonly includes names, email addresses, phone numbers, addresses, reservation details, and, in some cases, accommodation communications or passport images. The main significance is not direct financial theft but the way booking data can be reused for phishing, reservation hijacking, and other targeted scams.
Articles: 46
Last Updated: 07/27/2026
- 98
Retailers Expose Customer Data Through Vendors

Retail and outsourcing organizations disclosed breaches in which attackers accessed customer or business data through external providers, connected systems, or portions of corporate networks. The Lidl and Loblaw incidents primarily exposed contact and identifying information while reportedly leaving payment credentials and passwords unaffected; Telus Digital reported unauthorized access while investigating a much larger theft claim made by ShinyHunters. The incidents highlight how vendor access and interconnected cloud environments can expand exposure, while affected organizations often lack confirmed information about the number of records, data scope, or attacker identity.
Articles: 14
Last Updated: 07/17/2026
- 98
Lithuania Registry Breach Exposes 600,000 Records

Lithuanian authorities are investigating the theft of more than 600,000 records from state property and legal-entity registries after attackers misused credentials belonging to authorized institutions. The exposed data included names, dates of birth, national identification numbers and property addresses, while authorities said financial information and several categories of official documents were not accessed. The incident prompted account blocking, credential resets, leadership changes and renewed scrutiny of Lithuania’s state IT security and disclosure practices, while foreign or Russian involvement remains unconfirmed.
Articles: 4
Last Updated: 07/21/2026
- 98
Fiesta Insurance Breach Exposes Sensitive Data

Fiesta Insurance Franchise Corporation is notifying individuals after determining that files in systems affected by a June 2025 cybersecurity incident may have contained sensitive personal and financial information. Reports cite more than 160,000 potentially affected people, while the company has separately identified 12,097 impacted Texas residents. The incident matters because the exposed data may include Social Security numbers, government identification, financial details, and health-related financial information, although no resulting identity theft or fraud has been reported.
Articles: 7
Last Updated: 07/24/2026
- 98
Third-Party Vendors Expose Sensitive Data

Organizations are notifying customers, patients, and other individuals after unauthorized access at vendors handling personal, financial, and protected health information. The incidents show how external accounting, healthcare, and service providers can become pathways to sensitive data even when the affected organization’s core systems or payment infrastructure are not directly compromised. Confusing or delayed notifications may further reduce the ability of affected people to respond to identity theft and phishing risks.
Articles: 6
Last Updated: 07/22/2026
- 98
California Tightens Breach Notification Rules

The topic centers on California requirements for notifying residents after unauthorized access to covered personal information, including identifiers, financial credentials, health information, login data, and biometrics. The material also emphasizes related CCPA/CPRA litigation, Attorney General reporting for larger incidents, and overlapping healthcare obligations under HIPAA and California medical confidentiality law. A broader regulatory pattern is visible: organizations are expected to identify qualifying incidents quickly, preserve evidence, and notify affected people and authorities within jurisdiction-specific deadlines rather than waiting for investigations to fully conclude.
Articles: 9
Last Updated: 06/21/2026
- 98
Assuranceamerica Breach Exposes Driver Data

AssuranceAmerica disclosed that an unauthorized actor accessed its systems after obtaining an employee credential and copied files containing personal, insurance, vehicle, claims, and driver’s license information belonging to 6,998,886 people. The incident was detected on March 17, 2026, while the investigation concluded on June 15, and notifications began in July. The scale and persistence of driver’s license and other identity data create continuing risks of phishing, identity theft, fraudulent insurance activity, and misuse that may not appear immediately.
Articles: 62
Last Updated: 07/27/2026
- 98
Breaches Expose Tax And Personal Data

Organizations including Ernst & Young, US Tiger Securities, and Yellow Corporation disclosed breaches involving the unauthorized access or copying of files containing highly sensitive personal, financial, tax, medical, or employment information. The strongest recurring pattern is exposure through shared, back-office, or third-party systems rather than disruption of customer-facing production services. The incidents matter because tax records, government identifiers, financial data, and health information can enable identity theft, fraud, phishing, and targeted social engineering, while the scope of affected individuals remains unclear in several cases.
Articles: 79
Last Updated: 07/30/2026
- 98
Data Breach Settlements Expand Across U.s.

U.S. organizations are resolving data-breach lawsuits through class-action settlements that typically combine cash payments, reimbursement for documented losses, and credit-monitoring services. The cases involve exposed health, identity, account, payment-card, and employee information across sectors including retail, healthcare, financial services, payroll, and technology. The pattern highlights the continuing legal and financial consequences of alleged weaknesses in data-security safeguards, while settlement terms remain subject to court approval and do not necessarily establish wrongdoing.
Articles: 39
Last Updated: 07/29/2026
- 98
Ransomware Breaches Expose Sensitive Data

Organizations across insurance, healthcare, employment services, local government, and online platforms are reporting breaches involving personal, financial, medical, and account data. Ransomware and unauthorized access are recurring mechanisms, with several incidents affecting large populations and prompting notifications, monitoring guidance, and legal investigations. The material also includes a distinct dispute involving Suno over exposed user records and alleged music-data scraping.
Articles: 94
Last Updated: 07/29/2026
- 98
Sensitive Data Breaches Hit Service Providers

Organizations that hold sensitive legal, medical, and diagnostic information are investigating breaches involving compromised credentials, impersonation, third-party storage, and exposed portals. The incidents affect diverse data types, including Social Security numbers, clinical records, financial details, and technical documentation, while several organizations dispute or have not confirmed attackers’ claims about the volume and sensitivity of stolen data. The events also show continuing legal and notification consequences when organizations disclose breaches after delays or when attackers allege access through external systems.
Articles: 100
Last Updated: 07/30/2026
- 97
Organizations Tighten Data Breach Response

Organizations are tightening how they detect, contain, investigate, and disclose data breaches, with regulators and security teams emphasizing structured action during the first 72 hours. The European Data Protection Board is moving toward a common GDPR breach-notification template, while operational guidance stresses clear incident ownership, data scoping, forensic preservation, and coordinated communications. The broader pattern is that breach impact depends not only on the initial intrusion but also on response speed, notification accuracy, regulatory exposure, downtime, and recovery costs.
Articles: 47
Last Updated: 07/30/2026
- 97
Coupang Breach Tests U.s.-Korea Ties

Coupang’s customer data breach has expanded from a corporate cybersecurity incident into a dispute over South Korean regulatory enforcement and U.S. treatment of an American-incorporated company. South Korean authorities say a former employee accessed data linked to more than 33 million accounts and imposed a record fine, while Coupang and U.S. lawmakers have challenged the investigation as discriminatory. The disagreement is affecting political and security discussions between Seoul and Washington, while questions remain about the location and use of the exposed data.
Articles: 120
Last Updated: 07/31/2026
- 97
Mortgage Lenders Report Sensitive Data Breaches

Mortgage lenders and related financial organizations are reporting unauthorized access, ransomware activity, and possible theft of sensitive customer or employee information. Exposed data may include Social Security numbers, tax and income records, financial account details, identification data, and account credentials, increasing potential identity-theft and fraud risks. The incidents also show how supplier compromises and delayed notification can extend the impact beyond the initially targeted systems.
Articles: 28
Last Updated: 07/23/2026
- 97
Lemonade Data Breach Settlement

Recent coverage is highly consistent around Lemonade's $10.5 million settlement resolving allegations that its online insurance quote system exposed driver license numbers and other personal data for roughly 190,000 people. The strongest signal is procedural and remedial: settlement administration, claim deadlines, credit monitoring, identity theft insurance, and modest cash payouts. The underlying privacy issue is a consumer data breach tied to data collection workflow and security controls rather than a broad policy debate. The topic is coherent, current, and tightly bounded, with little fragmentation beyond minor differences in the estimated affected population and the status of court approval.
Articles: 10
Last Updated: 07/07/2026
- 97
Bojangles Employee Breach Lawsuit Advances

A North Carolina Business Court judge allowed most claims to proceed in a class-action lawsuit alleging that Bojangles failed to protect employee data and delayed notifying workers after a 2024 breach attributed in court records to Hunters International. The lawsuit alleges that more than 387,000 files containing sensitive employee information were taken and posted on the dark web, while employees were notified 274 days after the breach began. The ruling keeps claims concerning data protection, notification, implied safeguarding duties and potential unfair-trade violations alive, although negligence and invasion-of-privacy claims were dismissed.
Articles: 3
Last Updated: 07/07/2026
- 97
Data Breaches Expose Sensitive Records

Organizations across financial services, education, healthcare, and professional services are disclosing cyber incidents in which attackers accessed or encrypted systems and obtained sensitive personal information. The incidents commonly involve Social Security numbers, financial account data, identity documents, health information, or tax-related records, with some breaches originating in third-party platforms. The disclosures are driving credit-monitoring offers, regulatory notifications, investigations, and legal claims, while the full scope of several incidents remains unresolved.
Articles: 27
Last Updated: 07/20/2026
- 97
Shinyhunters Breaches Salesforce Customers

ShinyHunters is associated with a broad campaign of data theft and extortion against organizations using enterprise platforms and customer-data systems. Reported incidents involving 7-Eleven, McGraw Hill, Kodak and the Council of Europe show a recurring pattern of unauthorized access claims, ransom demands and threatened or completed publication of stolen records. The disclosures expose personal, financial and organizational information, while victim organizations continue to investigate the scope and authenticity of the claims.
Articles: 106
Last Updated: 07/31/2026
- 97
Local Entities Report Personal Data Breaches

Several U.S. townships and companies are notifying individuals that unauthorized access to their networks or files may have exposed names, Social Security numbers, driver's license or state ID numbers, addresses, and financial account information. The incidents show recurring challenges in determining the scope of access and notifying affected people months after the underlying activity, while organizations offer credit monitoring and engage law enforcement or outside investigators. Law firms are also examining potential claims, although the scale of exposure and evidence of actual misuse remain unclear in several cases.
Articles: 7
Last Updated: 06/30/2026
- 97
Tata Electronics Leak Exposes Apple Files

Tata Electronics is investigating a ransomware-linked data breach after the World Leaks group published more than 200,000 purported files on the dark web. The material reportedly includes Apple iPhone 18 Pro images, component and supplier information, and documents associated with Tesla, TSMC, and Qualcomm, while the authenticity of some files has not been independently confirmed. Tata has restricted remote access to sensitive systems, hired a global consultant for a forensic audit, and reported the incident to Indian authorities and affected clients.
Articles: 55
Last Updated: 07/22/2026
- 97
Mercor Breach And AI Data Exposure

Mercor's reported breach remains the main story, with class-action lawsuits, partner reviews, and repeated claims of exposed contractor biometrics, identity records, and interview data tied to a LiteLLM supply-chain attack.
Articles: 12
Last Updated: 07/09/2026
- 97
Maine Portal Hosts Fake Breach Notices

An unknown third party used the Maine Attorney General's public breach-reporting portal to post a convincing but fraudulent notice claiming that more than 2.4 million VRChat users were affected. VRChat said its systems and user data were not compromised, while Maine characterized the filing and a separate Discord submission as hoaxes and temporarily disabled the public portal. The episode shows how unverified regulatory submissions can spread false breach information, create reputational harm, and trigger unnecessary concern before affected organizations can respond.
Articles: 21
Last Updated: 07/22/2026
- 97
Customer Data Breaches In Retail

This topic centers on customer data breaches affecting consumer-facing companies, especially online retail and service operators. The incidents point to a recurring pattern of attackers exploiting web-facing systems or malware access to copy personal data, with companies responding by patching flaws, notifying authorities, and warning customers about phishing and fraud. The material is unified by the exposure of customer records rather than any single vendor, with some inconsistency in the scale and exact contents of the stolen data.
Articles: 8
Last Updated: 07/10/2026
- 97
Breaches Expose Identity And Access Risks

The topic centers on cyber incidents that expose personal information, employee records, credentials, or sensitive operational data across government, education, financial, and consumer-facing organizations. Repeated patterns include social engineering against identity and single sign-on systems, ransomware leak-site claims, insecure data handling, and the continued reuse of older breach data for phishing, account takeover, and identity theft. The scope and impact of several incidents remain under investigation, and some reported data exposures have not been independently confirmed by the affected organizations.
Articles: 82
Last Updated: 07/29/2026
- 96
TPWD Vendor Breach Exposes License Data

Texas Parks and Wildlife Department reported that a cybersecurity incident at an unnamed third-party license-system vendor may have exposed personal information belonging to more than 3 million hunting and fishing license customers. The affected data may include driver’s license and passport information, email addresses, phone numbers, and residential addresses, while the department said there was no evidence that Social Security numbers, dates of birth, or payment information were accessed. TPWD and the vendor are strengthening access controls and monitoring, while affected individuals are being advised to watch for fraud and use offered credit-monitoring services.
Articles: 66
Last Updated: 07/29/2026
- 96
Aflac And KDDI Breaches Expose Data

Two major breaches disclosed in June and July 2026 affected millions of people in Japan. Aflac Life Insurance Japan reported the theft of personal, insurance, and some premium-transfer account information belonging to approximately 4.38 million customers and agents, while KDDI reported unauthorized access to shared ISP email infrastructure affecting at least 12.2 million email addresses and 7.6 million passwords. The incidents highlight the impact of centralized systems and third-party software vulnerabilities, while the final scope of both breaches and the extent of downstream misuse remain under investigation.
Articles: 25
Last Updated: 07/28/2026
- 96
Cyber Insurance Covers Breach Losses

This topic centers on cyber insurance claims and the kinds of losses most often driving payouts, especially data breaches, ransomware, and vendor-related incidents. The material shows insurance covering most average breach losses, while also highlighting that some events remain highly costly because of downtime, business interruption, and legal or settlement expenses. It also points to emerging pressure from AI-enabled social engineering and less traditional exposures such as pixel-tracking litigation.
Articles: 14
Last Updated: 07/30/2026
- 96
Fortinet Credential Leak Fallout

Fortinet VPN and firewall credentials were exposed at large scale, affecting tens of thousands of internet-facing devices and prompting government advisories, vendor warnings, and urgent password-reset guidance. The reporting also points to access brokering and credential cracking as part of the same compromise pattern.
Articles: 8
Last Updated: 07/01/2026
- 96
South Korea Diplomatic Academy Breach

Hackers accessed South Korea’s National Diplomatic Academy online system for roughly nine to ten months, potentially exposing records belonging to current and former Foreign Ministry employees, including diplomats. The Ministry took the platform offline after detection by the National Intelligence Service and reported exposure of identifiers, names, email addresses, and encrypted passwords, while the total affected population and exact data accessed remain uncertain. The incident highlights monitoring and configuration weaknesses in a government-hosted system and sits alongside broader South Korean enforcement against inadequate personal-data protection.
Articles: 20
Last Updated: 07/24/2026
- 95
Public Agencies Face Sensitive Data Breaches

Local and state public agencies in Los Angeles and Washington are confronting incidents in which sensitive legal, personal, and public-benefit records were exposed or accessed without authorization. The reported incidents include a Los Angeles City Attorney third-party environment exposing hundreds of thousands of files, Washington DSHS records viewed by a former employee, and a separate Los Angeles County benefits-data disclosure. The cases highlight the practical risks of weak access controls, third-party storage, and disputes over how long sensitive government records should be retained.
Articles: 15
Last Updated: 07/27/2026
- 95
U.s. Organizations Report Personal Data Breaches

Organizations across the U.S. are disclosing cyber incidents involving Social Security numbers, financial account details, identity documents, and, in one case, extensive health information. The reports show a recurring pattern of unauthorized access or acquisition followed by state notifications, mailed notices, consumer monitoring guidance, and potential litigation or legal investigation. Technical details and the full scope of several incidents remain limited.
Articles: 31
Last Updated: 07/29/2026
- 95
Package Registries Target Developer Secrets

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data. Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.
Articles: 17
Last Updated: 07/15/2026
- 95
Organizations Tighten Data Breach Defenses

Organizations are being urged to reduce data breach risk through layered controls spanning identity security, vulnerability management, cloud configuration, vendor access, monitoring, response, and recovery. The material also emphasizes minimizing raw personal-data sharing and using privacy-enhancing technologies where collaboration is necessary. The broader significance is that breach management increasingly involves limiting data exposure and exfiltration, communicating clearly with affected customers, and continuously validating that defenses work.
Articles: 11
Last Updated: 07/21/2026
- 95
Third-Party Platforms Expose Customer Data

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.
Articles: 9
Last Updated: 07/23/2026
- 94
Blackcat Ransomware Insider Misuse

Recent U.S. enforcement actions and prison sentences show former ransomware negotiators and incident response workers using insider access to help BlackCat extort victims, leak data, and split ransom proceeds.
Articles: 6
Last Updated: 07/10/2026
- 94
Dutch Breaches Expose Personal Data Risks

Dutch organizations are investigating or responding to several cyber incidents involving telecommunications, football, government, and consumer data. The incidents show how weaknesses in employee-facing processes, exposed APIs, shared keys, and customer systems can enable unauthorized access or data theft, while police investigations have led to an arrest and a suspected link to the Odido breach. The practical concern extends beyond the initial intrusion: exposed identity and contact data can support more convincing phishing, impersonation, and identity-fraud attempts.
Articles: 11
Last Updated: 07/24/2026
- 93
Attackers Target Github Developer Workflows

Attackers are abusing GitHub repositories, Discussions, VS Code workflows, JavaScript bundles, and vulnerable web applications to steal credentials or deliver malware. The activity combines social engineering, repository impersonation, supply-chain compromise, exploitation of exposed secrets, and automated attacks against internet-facing software. The common risk is that trusted developer infrastructure and application artifacts can provide access to source code, cloud environments, accounts, and downstream users.
Articles: 12
Last Updated: 07/14/2026
- 93
Attackers Exploit Exposed Enterprise Gateways

Attackers are exploiting or actively probing vulnerabilities in internet-facing email platforms, secure access gateways, AI development infrastructure, mobile devices, and network appliances. The incidents show how flaws in systems that bridge users, applications, and internal networks can enable credential theft, session compromise, code execution, data exposure, or malware delivery. CISA directives and vendor patches underscore the need to prioritize exposed assets and investigate for compromise, although exploitation status and actor attribution remain uneven across cases.
Articles: 14
Last Updated: 07/23/2026
- 92
North Carolina Breaches Fuel Privacy Debate

North Carolina reported 2,349 data breaches in 2025 affecting approximately 9.3 million residents, with ransomware, email compromise, and education-sector incidents prominent in the reporting. The scale of the breaches, including the PowerSchool incident, is driving increased attention to multifactor authentication, vendor security, staff training, enforcement, and how institutions collect and share personal data. Residents and advocates are also questioning whether expanded identity-verification requirements could create additional concentrations of sensitive information without sufficient transparency or safeguards.
Articles: 3
Last Updated: 05/19/2026
- 92
French Public-Sector Data Breaches

This topic centers on multiple cyber incidents affecting French public-sector databases that store identity, contact, and financial records. The strongest thread is not system intrusion alone, but the downstream exposure of citizen and employee data, public notification, and warnings that stolen records could fuel phishing and fraud. Together, the cases show pressure on centralized government data systems and the operational burden of disclosure, investigation, and remediation.
Articles: 29
Last Updated: 06/26/2026
- 92
NAIC Breach Linked To Oracle Peoplesoft Zero-Day

The National Association of Insurance Commissioners confirmed that attackers exploited an Oracle PeopleSoft zero-day, obtained credentials, and moved laterally into internal storage. NAIC said the accessed data primarily consisted of publicly available regulatory and credit-rating information, outdated logs, and configuration files, with no evidence that personal, banking, or payment information was compromised. ShinyHunters claimed a substantially larger theft and published data online, leaving the final scope under forensic review while the incident caused temporary disruption to some insurance data operations.
Articles: 5
Last Updated: 06/29/2026
- 91
Dragonforce Hides Teams Traffic

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.
Articles: 3
Last Updated: 06/20/2026
- 90
UK Biobank And Banking Data Exposures

Recent privacy coverage is dominated by UK Biobank data exposure incidents and a smaller set of UK banking app disclosures, both pointing to weak data isolation, limited access controls, and recurring questions about breach response. The strongest signal is operational rather than legal: sensitive data can still leak through legitimate access, upload workflows, or technical defects even when direct identifiers are absent.
Articles: 11
Last Updated: 07/30/2026
- 90
NVIDIA Geforce NOW Partner Breach

A breach of GFN.am infrastructure exposed personal information belonging to some GeForce NOW users in Armenia. NVIDIA says its own systems were not affected, while GFN.am reported that passwords were not compromised and that users who registered after March 9, 2026 were not affected. The incident highlights how regional partners with separate authentication and customer databases can create localized exposure for major technology services.
Articles: 5
Last Updated: 05/12/2026
- 88
Kraken Insider Data Extortion

Kraken disclosed insider-led access incidents that exposed limited customer support data and led to extortion threats. The main pattern is misuse of legitimate support access, followed by access revocation, user notification, and cooperation with law enforcement.
Articles: 3
Last Updated: 04/17/2026
- 88
Cloud Integrations And Identity Breaches

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.
Articles: 49
Last Updated: 07/22/2026
- 84
Regulators Tighten Privacy, Attackers Hit Vendors

Privacy and cybersecurity policy is tightening while attackers continue to exploit vendors, exposed systems, and weak access controls. U.S. states are expanding privacy and national-security enforcement, the UK and international bodies are developing rules for data use and surveillance technologies, and healthcare organizations face concentrated third-party breach risks that may be amplified by AI. The common direction is greater scrutiny of who can access personal data, how it is used, and whether organizations can secure it across complex technology and supplier networks.
Articles: 105
Last Updated: 08/02/2026
Secondary
- 96
Student Loan Data Breach Settlement

A federal court has finalized a $10 million settlement over a 2022 Nelnet-related data breach that exposed student loan borrowers' personal information. The current focus is on claims administration, eligibility disputes, and payout timing for millions of affected borrowers.
Articles: 6
Last Updated: 05/22/2026
- 94
NYC Health + Hospitals Breach Exposed 1.8 Million Records

A series of breaches and privacy incidents is exposing highly sensitive information through healthcare providers, business associates, public-sector vendors, and poorly handled records. The most significant incidents involve NYC Health + Hospitals, including a major intrusion affecting about 1.8 million people and a separate vendor breach affecting 58,778 patients, while broader reporting shows hacking remains the dominant source of large healthcare breaches. The incidents demonstrate how third-party access, weak monitoring, social engineering, and inadequate records handling can expose medical, identity, biometric, and other difficult-to-replace data.
Articles: 29
Last Updated: 07/29/2026
- 94
Threat Actors Exploit Oracle Peoplesoft

Threat actors exploited an Oracle PeopleSoft PeopleTools zero-day, tracked as CVE-2026-35273, to access sensitive personnel records held by enterprise HR and payroll systems. Nissan reported potential exposure of employee and dependent information across several countries, while reporting linked the broader campaign to ShinyHunters and identified additional affected organizations. The incidents show how compromise of HR platforms can expose identity, payroll, tax, banking, and benefits data, prompting containment measures, vendor coordination, and credit or identity monitoring for affected individuals.
Articles: 18
Last Updated: 07/06/2026
- 92
Healthcare Data Breach Settlements

Healthcare providers, diagnostic laboratories, technology vendors, and credit-reporting services are resolving lawsuits tied to unauthorized access to sensitive personal, financial, and medical information. The settlements commonly provide cash payments, reimbursement for documented losses, credit monitoring, identity-theft protection, or medical monitoring, while defendants generally deny wrongdoing. The pattern highlights the continuing legal and financial consequences of breaches affecting patients and customers through both direct systems and third-party service providers.
Articles: 84
Last Updated: 07/28/2026
- 92
Triwest Warns 11,844 Tricare Beneficiaries Of Data Breach

Healthcare organizations are notifying beneficiaries and members about unauthorized access to systems containing personal and protected health information. TriWest reported that an incident affecting 11,844 TRICARE beneficiaries exposed names, Department of Defense Benefits Numbers and ZIP codes, with more sensitive details involved in fewer than five cases; a separate Wellpoint Washington incident reportedly affected about 12,020 people. The developments highlight the exposure of healthcare administration systems and the need for timely notification, monitoring and security remediation.
Articles: 4
Last Updated: 07/13/2026
- 91
Healthcare Data Breach Disclosures

Healthcare providers and related medical organizations are repeatedly disclosing network intrusions that may expose patient identities, medical records, and financial information, followed by breach notices, credit monitoring offers, and class action investigations. The strongest pattern is not one isolated incident but a steady stream of similar privacy failures across multiple practices and regions, often with long gaps between unauthorized access and notification. Legal response is present in many cases, but the record remains fragmented because each incident is organization-specific and the total scope varies widely.
Articles: 128
Last Updated: 07/30/2026
- 91
Dentaquest Breach Exposes Millions

DentaQuest, a Sun Life-owned dental benefits administrator, disclosed unauthorized access to part of its network after ShinyHunters claimed to have stolen and publicly released a large dataset. Breach analyses and regulatory reporting indicate that millions of accounts or Texas residents may be affected, with exposed information potentially including contact, government identification, insurance, and medical data. The incident has increased risks of identity theft, medical fraud, phishing, and legal action while the final scope remains unsettled.
Articles: 33
Last Updated: 07/29/2026
- 90
Oracle EBS Breach Exposes HR Data

Estée Lauder disclosed a breach of its Oracle E-Business Suite human resources environment that exposed employee and other personal data, with reporting tied to a 2025 Oracle vulnerability and Clop-linked mass exploitation. The strongest signal is a delayed disclosure after prolonged undetected access, followed by identity monitoring and incident-response measures.
Articles: 11
Last Updated: 07/27/2026
- 90
Breaches Hit Universities, Expose Sensitive Data

Universities are reporting unauthorized access and ransomware incidents involving records that may contain Social Security numbers, government identification data, financial details, credentials, and health information. The incidents have prompted breach notifications, credit-monitoring offers, attorney general filings, law-firm investigations, and at least one class-action settlement. The material indicates recurring exposure of high-value personal data across education-sector systems, but details about confirmed acquisition and the effectiveness of security controls remain limited.
Articles: 6
Last Updated: 07/09/2026
- 90
Healthcare Data Breaches Produce Multimillion-Dollar Settlements

U.S. healthcare providers and related service organizations are settling class actions arising from breaches that exposed personal, medical, Social Security, and financial information. The agreements generally combine cash or documented-loss reimbursements with credit, dark-web, or medical identity monitoring, while organizations deny liability or settle without admitting wrongdoing. The cases show how cyber incidents involving large patient populations are producing substantial litigation and remediation costs after the underlying breaches.
Articles: 11
Last Updated: 07/12/2026
- 90
Powerschool Student Data Litigation

PowerSchool faces parallel legal scrutiny over the security and use of K-12 student data. A federal court allowed multiple claims against owner Bain Capital to proceed in litigation related to a breach reportedly affecting millions of students and educators, while a separate $17.25 million Naviance settlement addresses allegations that third-party analytics tools collected student activity and communications without adequate consent. Together, the matters highlight litigation exposure for education technology providers, owners, schools, and technology partners when sensitive data is accessed, shared, or tracked.
Articles: 3
Last Updated: 05/25/2026
- 90
Triwest Data Breach Affects 11,844 Tricare Beneficiaries

TriWest Healthcare Alliance reported unauthorized access to and downloading of information linked to 11,844 TRICARE beneficiaries, including names, Department of Defense Benefits Numbers, and ZIP codes. Fewer than five cases reportedly included Social Security numbers, addresses, and dates of birth, while a Texas filing identified 2,408 affected residents. TriWest has notified individuals, offered 24 months of credit monitoring, and strengthened access controls, monitoring, and employee training.
Articles: 5
Last Updated: 07/17/2026
- 90
Healthcare Data Breach Wave

Healthcare organizations continue to disclose breaches that expose patient identifiers, medical records, and sometimes financial data, with ransomware, email compromise, and vendor incidents recurring across hospitals, specialty practices, and medical service providers. Notification letters, credit monitoring, and HIPAA reporting remain the standard response, while some cases involve delayed discovery, litigation, or unclear root cause.
Articles: 139
Last Updated: 07/29/2026
- 89
Canvas Breach Disrupts California Colleges

A cybersecurity incident at Instructure disrupted Canvas access across colleges and universities, including all 23 California State University campuses, during a critical academic period. Instructure said potentially exposed information included names, email addresses, student and faculty ID numbers, rosters, and user messages, while reporting no evidence that passwords, financial data, birth dates, or government identifiers were involved at the time. The incident also generated extortion claims attributed to ShinyHunters, prompting institutions to restrict access, warn users about phishing, and develop contingency plans for online instruction.
Articles: 12
Last Updated: 07/22/2026
- 88
Canvas Breach Data Deletion Deal

Instructure, the company behind Canvas, is responding to a breach in which an unauthorized actor accessed student-related data and later returned it under a reported agreement to delete remaining copies. The incident matters because Canvas is deeply embedded in school operations, so the breach caused access disruptions during finals and raised concerns about the potential exposure of student contact and message data. The reported involvement of ShinyHunters and the use of ransom-linked threats point to a broader extortion dynamic, even as the company says it has not seen evidence of passwords or financial data being compromised.
Articles: 22
Last Updated: 07/16/2026
- 88
School Tip Line Data Breach

Lawmakers are pressing Navigate360 after reports that its school safety tip line platform was breached and exposed sensitive student data, raising questions about anonymity, cybersecurity, and incident response.
Articles: 6
Last Updated: 07/03/2026
- 88
Canvas Breach Fallout

Instructure is dealing with the fallout from a breach affecting Canvas, the learning platform used by schools and universities worldwide. The incident disrupted access during finals, prompted claims from ShinyHunters about stolen student data, and led Instructure to say it reached an agreement for the data to be deleted, though it cannot verify permanent destruction. The case matters because it combines operational disruption, possible exposure of student and school information, and continuing uncertainty about whether exfiltrated data will be reused or leaked.
Articles: 30
Last Updated: 05/13/2026
- 86
Healthcare Data Breach Investigations Expand

Healthcare providers and related organizations are reporting cyber incidents in which unauthorized actors accessed networks or copied files containing personal and protected health information. The incidents range from several thousand affected individuals to hundreds of thousands or more, although the specific data exposed is not always known. Organizations are responding with investigations, regulatory notifications, security upgrades, and credit or identity-monitoring services, while law firms assess potential claims.
Articles: 8
Last Updated: 07/09/2026
- 86
Shinyhunters Breaches And Defaces Canvas

ShinyHunters compromised Instructure’s Canvas platform, stealing user information and later using cross-site scripting vulnerabilities to alter login portals for hundreds of educational institutions. Instructure temporarily restricted Canvas services, rotated application keys, and investigated the incident while the U.S. House Homeland Security Committee sought testimony about the breach’s scope and response. Instructure says the stolen data was returned and destroyed, but the volume of allegedly affected records and the final impact on institutions remain unsettled.
Articles: 28
Last Updated: 07/30/2026
- 86
Healthcare Vendors Expose Patient Data

Healthcare organizations are facing a recurring pattern of patient-data exposure and service disruption linked to electronic health record providers, billing partners, software vendors, and other third parties. Public disclosures show that affected organizations often have incomplete visibility into vendor security, while investigations may leave the number of affected patients, exposed data types, and attack methods uncertain. The incidents underscore how dependence on external healthcare technology providers can affect both privacy and continuity of care.
Articles: 38
Last Updated: 07/30/2026
- 86
Nintendo Tinypulse Employee Breach

This topic centers on a third-party breach involving TinyPulse, an employee survey platform used by Nintendo of America, where internal employee data was reportedly stolen and used in an extortion attempt. Nintendo says its own systems and customer data were not compromised, but the incident still raises privacy risks for employees whose survey and HR-related information may have been exposed. The case highlights how vendor platforms can become the main path for sensitive data loss even when the target company’s internal network remains intact.
Articles: 21
Last Updated: 07/11/2026
- 86
Chick-Fil-A Credential-Stuffing Breach
Chick-fil-A is notifying customers and state regulators after credential-stuffing attacks on Chick-fil-A One accounts exposed personal, loyalty, and partial payment data. The incident is being reported across multiple states, with remediation focused on forced logouts, password resets, and payment-method removal.
Articles: 62
Last Updated: 07/30/2026
- 84
Medical Device Data Breach Incidents

Recent reporting shows repeated cyber intrusions at medical device companies, with files stolen, systems disrupted, and investigators still determining whether personal or patient data was exposed. The pattern emphasizes containment, recovery from backups, and uncertain notification obligations.
Articles: 8
Last Updated: 07/27/2026
- 82
Edtech Vendors Disrupt Schools, Expose Data

Educational institutions are increasingly exposed to breaches and service outages originating in the EdTech and SaaS vendors that host data or support critical operations. Incidents involving PowerSchool, Canvas, and other suppliers show how one compromise can affect many schools, expose student and staff information, and disrupt examinations or other essential services. The material emphasizes continuous vendor monitoring, enforceable contracts, identity controls, backups, and rehearsed response plans because institutions retain legal and operational consequences even when a supplier operates the affected systems.
Articles: 7
Last Updated: 07/21/2026
- 82
Canvas Breach And Ransom Demand

Instructure's Canvas learning platform was hit by a breach and extortion campaign attributed to ShinyHunters, leading to temporary outages and threats to leak student and staff data. The incident affected schools and universities that rely on Canvas for coursework, deadlines, and exams, making it both an operational disruption and a privacy risk. Instructure later said it reached an agreement with the attackers and received confirmation of data destruction, but the full scope of impacted data remains unclear.
Articles: 4
Last Updated: 05/13/2026
- 80
23andme Faces Genetic Breach Fallout

The topic is dominated by the continuing legal and financial fallout from 23andMe’s 2023 credential-stuffing breach, which exposed genetic, ancestry, health-related, and relative information belonging to millions of customers. State regulators, courts, bankruptcy proceedings, and private claimants are pursuing settlements, fines, data-protection requirements, and other remedies, while separate incidents show how breached information can enable fraud and trigger disputes over liability. The material also highlights uncertainty over the scope of monetary recovery and the effectiveness of existing security safeguards.
Articles: 228
Last Updated: 07/28/2026
- 79
Education Saas Breaches Expose User Data

Education technology providers and connected institutions are responding to breaches involving learning platforms, career services systems, and Salesforce environments. Reported exposures center on names, email addresses, student or staff identifiers, messages, contact records, and locally stored passwords, while several organizations said core academic, financial, or internal systems were not affected. The incidents underscore how compromise of third-party education platforms can create broad phishing, service disruption, and privacy risks across many schools and universities.
Articles: 117
Last Updated: 07/07/2026
- 79
Novo Nordisk Breach Exposes Trial Data

Novo Nordisk disclosed that attackers accessed internal systems and copied non-public data from some clinical trials, including pseudonymized health, demographic, biomarker, and lifestyle information. Data linked to an undisclosed number of healthcare professionals was also reportedly exposed, including contact and workplace details. The company has taken affected systems offline, begun an investigation with external cybersecurity experts, and warned that the information could support targeted phishing or impersonation, while the full scope and breach mechanics remain unclear.
Articles: 28
Last Updated: 07/04/2026
- 78
WFP Breach Exposes Gaza Aid Data

The World Food Programme’s Palestine Self-Registration Application was breached on 14 May 2026, exposing personal information associated with Palestinian households seeking food and cash assistance in Gaza. Reported data included names, identification numbers, phone numbers, and location details, with WFP citing approximately 600,000 affected households while the total number of potentially exposed users remains unclear. The incident has prompted criticism over the 17-day notification delay, limited public disclosure, and the collection and protection of highly sensitive data in an active conflict environment.
Articles: 6
Last Updated: 07/23/2026
- 78
Canvas Breach Disrupts Final Exams

Canvas, the learning management system used by schools and universities, was disrupted by a cyberattack that hit during final exams and forced some institutions to delay tests, extend deadlines, or shift communications off-platform. Reporting indicates unauthorized access exposed at least some user data, including names, email addresses, student ID numbers, and messages, while Instructure said more sensitive data such as passwords and financial information was not implicated. The incident is significant because it combines platform outage, ransom pressure, and education-sector operational disruption across many institutions.
Articles: 16
Last Updated: 05/26/2026
- 78
FTC Orders Illuminate Over Student Breach

The Federal Trade Commission finalized an order requiring K-12 software provider Illuminate Education to strengthen security controls after an alleged breach exposed personal information associated with more than 10.1 million current and former students. The order restricts unnecessary data collection and retention, requires deletion and retention disclosures, prohibits misleading security or breach-notification claims, and imposes recurring independent assessments and reporting. The action highlights increasing regulatory scrutiny of how education technology vendors secure, retain, and communicate about sensitive student data.
Articles: 5
Last Updated: 06/18/2026
- 76
Healthcare Data Breaches Hit Vendor Systems

Healthcare providers and medical-service companies are disclosing breaches in which attackers stole patient personal information and protected health information from business applications, contractor accounts, and external electronic health record portals. iRhythm and AdaptHealth both linked their incidents to social engineering and threat-actor extortion, while Ikron reported a ransomware incident involving separate intrusions into operational and health-record systems. The disclosures show that patient data exposure can occur outside core clinical infrastructure, while the full number of affected individuals and the precise data involved may remain unclear during investigations.
Articles: 12
Last Updated: 07/07/2026
- 74
Malicious Extensions Hijack Browser Sessions

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services. Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.
Articles: 7
Last Updated: 07/18/2026
- 74
Phishing Kits Hijack Microsoft 365 Tokens

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes. Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.
Articles: 9
Last Updated: 07/09/2026
- 74
Infostealers Expose Credentials Across Identities

Infostealer malware and exposed breach databases are turning stolen passwords, session data, email addresses, and account records into reusable access across personal and enterprise services. Large collections analyzed or added to Have I Been Pwned show how endpoint compromise can bypass corporate defenses and connect online identities to employers and sensitive accounts. The main defensive direction is to identify exposed credentials quickly, prevent password reuse, and strengthen accounts with multifactor authentication, password managers, or passkeys.
Articles: 6
Last Updated: 07/17/2026
- 74
Canvas Breach Hits Schools

A cybersecurity incident involving Instructure's Canvas learning platform exposed student and staff information used by schools and universities. Reporting indicates the compromised data likely included names, email addresses, student ID numbers, and messages, while passwords, financial data, and government identifiers were not believed to be affected. The main concern is not system-wide disruption but downstream misuse of exposed data for phishing and other social engineering attacks across education networks.
Articles: 17
Last Updated: 07/28/2026
- 72
Canvas Breach Hits Schools Nationwide

Instructure's Canvas learning platform was hit by a breach and extortion attempt tied to ShinyHunters, exposing student and staff data at schools and universities that use the service. The incident temporarily disrupted access during finals and end-of-term work, while schools and district officials assessed what information may have been exposed. It also renewed scrutiny of how much sensitive student data is concentrated in a small number of education technology platforms and how exposed identities can fuel phishing and other follow-on attacks.
Articles: 17
Last Updated: 06/26/2026
