Breach Accountability
The ongoing major issues seen in articles and topics over time.
The Drivers
98
Articles Related
2,557
The Big Picture

The enduring theme is how organizations prevent, disclose, remediate, and compensate for personal-data breaches, especially when breaches involve vendors, cloud platforms, ransomware, or insider misuse. It includes notification duties, litigation exposure, settlements, credit monitoring, and downstream fraud risk.
Personal-data breaches remain one of the most persistent privacy harms because they convert weak security governance into long-term identity, financial, reputational, and legal consequences for individuals and institutions. The repeated settlement activity shows that breach response is now a standing legal and operational accountability regime, not merely a cybersecurity incident cycle.
Categories
Data Breaches & Exposure Events, Cybersecurity (Privacy-Relevant), Regulation, Law & Enforcement, Corporate Data Practices & Accountability
Keywords
AI supply-chain breach, API key rotation, attorney general breach filing, breach class action, breach notice timing, breach notification template, breach portal vetting, breach reporting rules, breach settlement, breach-enabled fraud, Canvas breach, clinical trial breach, cloud identity breach, corporate breach notification, credential compromise, credit union breach, customer data exfiltration, dark web exposure, data deletion promise, documented loss reimbursement, driver data breach, EDPB breach template, education platform breach, employee benefits breach, false breach notice, financial services breach, forensic cooperation, fraudulent breach notice, health insurer breach, HR payroll breach, identity monitoring settlement, insurer data breach, Klue breach, LiteLLM compromise, long-lived token risk, non-human identity breach, OAuth token compromise, OAuth token theft, Oracle PeopleSoft exploitation, pseudonymized data breach, public-sector vendor breach, ransom-linked deletion, ransomware extortion, SaaS integration breach, Salesforce integration breach, service account exposure, service management platform breach, ShinyHunters extortion, state attorney general breach notice, tax document exposure, third-party integration breach, third-party platform breach, vendor access control failure, vendor breach response
The Drivers
The Topics below, and their articles, all focus on, exemplify, or help to explain this theme.
Primary
- 99
Vendor-Linked Bank Data Breaches

The cluster is centered on recent bank data breach incidents where third-party/vendor compromise appears to be the main exposure path, with Everest-linked ransomware leak activity, customer notification issues, and emerging litigation over alleged privacy and security failures. The current signal is strongest around Citizens Bank and Frost Bank, while one article adds legal escalation through proposed class actions.
Articles: 3
Last Updated: 05/04/2026
- 99
Krispy Kreme Breach Settlement Claims

Recent coverage is dominated by the claims process for a Krispy Kreme data-breach settlement tied to a November 2024 cyber incident. The recurring facts are a roughly $1.6 million fund, allegations of exposure of Social Security numbers and financial account data, and June 2026 deadlines for filing, objections, and opt-outs. The most stable pattern is a settlement framework built around limited cash payments, reimbursement for documented losses, and one year of credit monitoring. The topic is coherent and narrow, with little fragmentation beyond small differences in reported dates, affected-population counts, and whether the incident is described as a breach, ransomware attack, or unauthorized access. It reads as an ongoing operational/legal matter rather than a broad or fast-changing privacy debate.
Articles: 40
Last Updated: 06/22/2026
- 99
Comcast Breach Settlement Moves Toward Payouts

The topic centers on the legal and consumer aftermath of the October 2023 Comcast Xfinity breach, including a reported $117.5 million class-action settlement, eligibility requirements, reimbursement limits, and identity-protection services. It also includes separate settlements involving Constar Financial Services and WaterStreet Company, showing a broader pattern of breach victims being offered capped payments, loss reimbursement, and monitoring services. The Comcast settlement has been described as proposed or pending in some reports and approved in a later report, while claim deadlines and payment amounts vary across accounts.
Articles: 75
Last Updated: 08/28/2026
- 99
Healthcare Data Breaches Trigger Settlements

U.S. organizations are resolving litigation tied to cyberattacks and unauthorized access that exposed personal, financial, medical, insurance, and account information. The reported settlements commonly provide documented-loss reimbursement, smaller no-proof cash payments, credit monitoring, and identity-theft protections, while some agreements also require stronger security controls. Healthcare-related incidents dominate the topic, but the cases vary in size, procedural status, and the information reportedly affected.
Articles: 13
Last Updated: 08/21/2026
- 99
Carnival Breach Exposes Passenger ID Data

Carnival Corporation disclosed that an attacker used social engineering to compromise an employee account and access a limited portion of its IT environment in April 2026. The company later determined that personal information had been copied, potentially affecting nearly 6 million people, with exposed data varying by individual and including government-issued identification details. Carnival is notifying affected individuals, offering U.S. customers two years of credit monitoring, and investigating the incident with outside experts, while ShinyHunters has claimed responsibility without public attribution from Carnival.
Articles: 77
Last Updated: 08/05/2026
- 99
Moveit Breach Settlement Wave

Recent coverage tracks class action settlements tied to the 2023 MOVEit breach, with banks and service providers offering cash payments, loss reimbursement, and credit monitoring after exposure of customer personal data.
Articles: 8
Last Updated: 08/23/2026
- 99
University Of Nottingham Student Data Breach

The University of Nottingham confirmed unauthorized access to a student records system affecting current students and alumni. ShinyHunters claimed responsibility and published sample material, while third-party analysis indicated exposure of large volumes of email addresses and other personal data; the university and UK authorities are still assessing the precise scope. The incident highlights the sensitivity of education records, which can combine identity, contact, enrollment, and financial information across multiple campuses.
Articles: 13
Last Updated: 08/04/2026
- 99
European Institutions Face Cloud Extortion

European institutions are facing a series of cyber incidents involving cloud environments, hosted websites, employee data, and public leak threats. The European Commission confirmed that attackers accessed its AWS environment and exposed data associated with multiple Europa.eu clients, while CERT-EU attributed the intrusion to TeamPCP and linked the stolen credential to a Trivy supply-chain attack. ShinyHunters has separately claimed extensive theft from the Council of Europe, but that allegation remains under investigation and has not been independently verified.
Articles: 8
Last Updated: 06/16/2026
- 99
Sensitive Data Breaches Reach Court

Organizations including Cushman & Wakefield, EY, WilmerHale, Wiley Rein, Hasbro, and Opexus face legal or regulatory scrutiny after breaches involving sensitive personal, financial, tax, employee, or client information. The reported incidents include phishing, compromised accounts, third-party platform access, and alleged insider misuse, with several complaints challenging security controls and notification practices. The recurring significance is the conversion of data exposure into class-action claims, while the extent of misuse, affected records, and organizational responsibility remains disputed in several cases.
Articles: 29
Last Updated: 08/29/2026
- 99
Breach Settlements Fund Security Fixes

Organizations in healthcare, entertainment, and financial services are resolving lawsuits tied to cyberattacks that exposed Social Security numbers, medical information, financial account data, and other personal details. Settlements commonly combine cash payments or reimbursement for documented losses with credit monitoring, identity-theft insurance, and required security improvements. The cases show how breach response increasingly extends beyond notification and compensation to formal cybersecurity leadership, oversight, and business-practice changes.
Articles: 16
Last Updated: 08/28/2026
- 99
ICO Fines South Staffordshire Water

The UK Information Commissioner’s Office fined South Staffordshire Plc and South Staffordshire Water Plc about £964,000 after a cyberattack exposed the personal data of more than 633,000 customers and employees. The intrusion began with phishing in 2020, remained undetected for nearly two years, and involved privilege escalation, inadequate monitoring, obsolete software, and unpatched systems before data was published on the dark web. The case highlights regulatory scrutiny of cybersecurity controls at water providers and the consequences of delayed breach detection.
Articles: 4
Last Updated: 05/15/2026
- 99
Cash App Faces Security And Fraud Scrutiny

Cash App owner Block, Inc. is facing scrutiny over alleged weaknesses in fraud protections, identity verification, customer support, and handling of unauthorized activity. A multistate settlement requires $45 million in payments and operational changes, while separate reporting and consumer guidance address earlier data-exposure incidents, settlement eligibility, and account-security steps. The central concern is whether Cash App users received protections and assistance comparable to those associated with traditional banking services.
Articles: 13
Last Updated: 08/05/2026
- 99
Fidelity Settles 2024 Data Breach Claims

Fidelity Investments is resolving legal and regulatory claims tied to unauthorized access to systems in August 2024, with reported exposure of financial account data and other sensitive personal information. A $2.5 million class-action settlement provides compensation and monitoring benefits, while a separate Massachusetts agreement requires a $1.25 million payment and improvements to notification and cybersecurity practices. The matter highlights the financial and operational consequences of breach response, particularly when affected individuals extend beyond the company’s directly identified customers.
Articles: 65
Last Updated: 08/05/2026
- 99
Eurail Traveler Data Breach Fallout

Recent coverage is dominated by Eurail's disclosure of a December 2025 breach affecting roughly 308,777 travelers and exposing passport, contact, and other sensitive records. Reporting emphasizes dark-web resale, Telegram samples, regulator notifications, and advice to monitor for fraud and phishing.
Articles: 15
Last Updated: 07/01/2026
- 99
Pillsbury Completes Breach Notifications

Pillsbury Winthrop Shaw Pittman completed notifications connected to a prior-year social-engineering incident in which an unauthorized actor accessed some firm documents during a short window. The firm said it detected and blocked the activity, reviewed the accessed material for personal information, notified affected clients and individuals, and published substitute notice as the final step. A related proposed class action was voluntarily dismissed without prejudice after mediation, leaving the litigation outcome unresolved.
Articles: 4
Last Updated: 07/21/2026
- 98
Hong Kong Data Breaches Expose Customers

Two significant cyber incidents in Hong Kong exposed or potentially exposed personal information held by a private club and Shun Hing Group. The cases involve ransomware or malicious encryption, unauthorized system access, and records covering hundreds of thousands of customers and other individuals. They underscore the operational and privacy impact of weaknesses in remote access, authentication, and security maintenance, while investigations continue to clarify the full scope of the Shun Hing breach.
Articles: 3
Last Updated: 07/03/2026
- 98
Retailers Expose Customer Data Through Vendors

Retail and outsourcing organizations disclosed breaches in which attackers accessed customer or business data through external providers, connected systems, or portions of corporate networks. The Lidl and Loblaw incidents primarily exposed contact and identifying information while reportedly leaving payment credentials and passwords unaffected; Telus Digital reported unauthorized access while investigating a much larger theft claim made by ShinyHunters. The incidents highlight how vendor access and interconnected cloud environments can expand exposure, while affected organizations often lack confirmed information about the number of records, data scope, or attacker identity.
Articles: 14
Last Updated: 07/17/2026
- 98
Booking.com Reservation Breaches

This topic centers on Booking.com and related travel booking portals exposing traveler data through breaches, suspicious access, or insecure third-party systems. The disclosed information commonly includes names, email addresses, phone numbers, addresses, reservation details, and, in some cases, accommodation communications or passport images. The main significance is not direct financial theft but the way booking data can be reused for phishing, reservation hijacking, and other targeted scams.
Articles: 46
Last Updated: 07/27/2026
- 98
Third-Party Vendors Expose Sensitive Data

Organizations are notifying customers, patients, and other individuals after unauthorized access at vendors handling personal, financial, and protected health information. The incidents show how external accounting, healthcare, and service providers can become pathways to sensitive data even when the affected organization’s core systems or payment infrastructure are not directly compromised. Confusing or delayed notifications may further reduce the ability of affected people to respond to identity theft and phishing risks.
Articles: 6
Last Updated: 07/22/2026
- 98
California Tightens Breach Notification Rules

The topic centers on California requirements for notifying residents after unauthorized access to covered personal information, including identifiers, financial credentials, health information, login data, and biometrics. The material also emphasizes related CCPA/CPRA litigation, Attorney General reporting for larger incidents, and overlapping healthcare obligations under HIPAA and California medical confidentiality law. A broader regulatory pattern is visible: organizations are expected to identify qualifying incidents quickly, preserve evidence, and notify affected people and authorities within jurisdiction-specific deadlines rather than waiting for investigations to fully conclude.
Articles: 11
Last Updated: 07/31/2026
- 98
Assuranceamerica Identity Data Breach

AssuranceAmerica's March 2026 intrusion exposed driver's license numbers and insurance-related records for 6,998,886 people, driving multistate notifications, consumer fraud precautions, and scrutiny of credential security and disclosure practices.
Articles: 65
Last Updated: 08/24/2026
- 98
Lithuania Registry Breach Exposes 600,000 Records

Lithuanian authorities are investigating the theft of more than 600,000 records from state property and legal-entity registries after attackers misused credentials belonging to authorized institutions. The exposed data included names, dates of birth, national identification numbers and property addresses, while authorities said financial information and several categories of official documents were not accessed. The incident prompted account blocking, credential resets, leadership changes and renewed scrutiny of Lithuania’s state IT security and disclosure practices, while foreign or Russian involvement remains unconfirmed.
Articles: 4
Last Updated: 07/21/2026
- 98
Ransomware-Driven Data Exposure

Ransomware increasingly combines data theft, extortion, and operational disruption, creating privacy exposure even when organizations can restore affected systems. Current reporting also shows rising attack volume, fragmented criminal groups, supply-chain and credential weaknesses, delayed detection, and stronger emphasis on coordinated response, identity controls, and resilient backups.
Articles: 23
Last Updated: 07/30/2026
- 98
Ransomware Breaches Expose Sensitive Records

A dense run of 2026 breach disclosures shows ransomware and related intrusions exposing identity, health, financial, payment, and occasional biometric data across insurers, benefits vendors, local governments, schools, retailers, and online platforms. The main consequences are delayed or incomplete notification, identity-theft exposure, monitoring and security remediation, leak-site publication, and growing litigation or regulatory follow-up.
Articles: 99
Last Updated: 08/25/2026
- 98
Companies Disclose Breaches Exposing Social Security Numbers

Organizations across logistics, manufacturing, insurance, heavy equipment, construction, and healthcare technology are disclosing breaches involving Social Security numbers and other sensitive personal information. Several incidents also exposed government IDs, financial records, health data, or employee and customer information, while some organizations have not yet provided complete impact counts or data details. The disclosures underscore the continuing exposure of identity and financial information during investigations that can extend months after initial unauthorized access.
Articles: 13
Last Updated: 07/29/2026
- 98
Breached Consumers Await Settlement Payouts

A series of U.S. class-action settlements is providing compensation, credit monitoring, or both to consumers whose personal information was allegedly exposed in data breaches. The cases span telecommunications, retail, financial services, nonprofits, hospitality, insurance, and healthcare-related services, with payment levels generally tied to documented losses, proof of impact, or participation in an alternative cash option. The material also shows litigation expanding beyond the breach itself to include delayed notification and unauthorized tracking, while claimants face deadlines and settlement approvals that vary by case.
Articles: 42
Last Updated: 08/28/2026
- 98
Fiesta Insurance Breach Notification Delay

Fiesta Insurance discovered unauthorized activity in June 2025 and began notifying people in July 2026 after a prolonged review of files potentially containing sensitive identity, financial, and health-related data. Reported affected counts range from 12,097 Texas residents to more than 160,000 individuals, while delayed notification has prompted legal scrutiny.
Articles: 7
Last Updated: 07/24/2026
- 97
South Korea Fines Coupang After Breach

South Korea’s Personal Information Protection Commission fined Coupang about 624.7 billion won, or roughly $408–409 million, after finding that a former employee accessed customer data over an extended period and that the company lacked adequate safeguards and timely breach detection. The regulator said information linked to more than 30 million customers was exposed and separately penalized Coupang’s collection of online activity data without consent. Coupang disputes aspects of the findings and the affected-account count, and plans to challenge the enforcement, adding legal, investor, and U.S.-South Korea trade concerns to the privacy case.
Articles: 130
Last Updated: 09/04/2026
- 97
Regulators Tighten Data Breach Notices

Organizations are tightening how they identify, document, and report personal-data breaches across GDPR, UK GDPR, HIPAA, SEC, and U.S. state regimes. The central operational challenge is making risk and materiality decisions quickly enough to meet deadlines—most notably GDPR’s 72-hour supervisory-authority window and HIPAA’s 60-day notification period—while investigations are still developing. Prepared response plans, breach registers, staged reporting, and coordinated regulatory processes are increasingly important as phishing, email compromise, vendor exposure, and overlapping reporting duties continue to complicate incident handling.
Articles: 52
Last Updated: 09/09/2026
- 97
Maine Portal Hosts Fake Breach Notices

An unknown third party used the Maine Attorney General's public breach-reporting portal to post a convincing but fraudulent notice claiming that more than 2.4 million VRChat users were affected. VRChat said its systems and user data were not compromised, while Maine characterized the filing and a separate Discord submission as hoaxes and temporarily disabled the public portal. The episode shows how unverified regulatory submissions can spread false breach information, create reputational harm, and trigger unnecessary concern before affected organizations can respond.
Articles: 21
Last Updated: 07/22/2026
- 97
Local Entities Report Personal Data Breaches

Several U.S. townships and companies are notifying individuals that unauthorized access to their networks or files may have exposed names, Social Security numbers, driver's license or state ID numbers, addresses, and financial account information. The incidents show recurring challenges in determining the scope of access and notifying affected people months after the underlying activity, while organizations offer credit monitoring and engage law enforcement or outside investigators. Law firms are also examining potential claims, although the scale of exposure and evidence of actual misuse remain unclear in several cases.
Articles: 7
Last Updated: 06/30/2026
- 97
Customer Data Breaches In Retail

This topic centers on customer data breaches affecting consumer-facing companies, especially online retail and service operators. The incidents point to a recurring pattern of attackers exploiting web-facing systems or malware access to copy personal data, with companies responding by patching flaws, notifying authorities, and warning customers about phishing and fraud. The material is unified by the exposure of customer records rather than any single vendor, with some inconsistency in the scale and exact contents of the stolen data.
Articles: 8
Last Updated: 07/10/2026
- 97
Shinyhunters Targets Salesforce-Linked Organizations

ShinyHunters is linked by claims or reporting to a series of intrusions affecting 7-Eleven, Brinks Home, Rockstar Games, and associated Salesforce or third-party systems. The incidents combine unauthorized access, alleged theft of personal or corporate data, leak-site publication, and extortion demands. The reporting highlights the difficulty of separating verified compromise from attacker claims while organizations investigate, notify affected individuals, and address potential fraud, litigation, and regulatory costs.
Articles: 111
Last Updated: 08/10/2026
- 97
Data Breaches Expose Sensitive Records

Organizations across financial services, education, healthcare, and professional services are disclosing cyber incidents in which attackers accessed or encrypted systems and obtained sensitive personal information. The incidents commonly involve Social Security numbers, financial account data, identity documents, health information, or tax-related records, with some breaches originating in third-party platforms. The disclosures are driving credit-monitoring offers, regulatory notifications, investigations, and legal claims, while the full scope of several incidents remains unresolved.
Articles: 27
Last Updated: 07/20/2026
- 97
Mercor Breach And AI Data Exposure

Mercor's reported breach remains the main story, with class-action lawsuits, partner reviews, and repeated claims of exposed contractor biometrics, identity records, and interview data tied to a LiteLLM supply-chain attack.
Articles: 12
Last Updated: 07/09/2026
- 97
Lemonade Data Breach Settlement

Recent coverage is highly consistent around Lemonade's $10.5 million settlement resolving allegations that its online insurance quote system exposed driver license numbers and other personal data for roughly 190,000 people. The strongest signal is procedural and remedial: settlement administration, claim deadlines, credit monitoring, identity theft insurance, and modest cash payouts. The underlying privacy issue is a consumer data breach tied to data collection workflow and security controls rather than a broad policy debate. The topic is coherent, current, and tightly bounded, with little fragmentation beyond minor differences in the estimated affected population and the status of court approval.
Articles: 10
Last Updated: 07/07/2026
- 97
Bojangles Employee Breach Lawsuit Advances

A North Carolina Business Court judge allowed most claims to proceed in a class-action lawsuit alleging that Bojangles failed to protect employee data and delayed notifying workers after a 2024 breach attributed in court records to Hunters International. The lawsuit alleges that more than 387,000 files containing sensitive employee information were taken and posted on the dark web, while employees were notified 274 days after the breach began. The ruling keeps claims concerning data protection, notification, implied safeguarding duties and potential unfair-trade violations alive, although negligence and invasion-of-privacy claims were dismissed.
Articles: 3
Last Updated: 07/07/2026
- 97
Mortgage Lenders Report Sensitive Data Breaches

Mortgage lenders and related financial organizations are reporting unauthorized access, ransomware activity, and possible theft of sensitive customer or employee information. Exposed data may include Social Security numbers, tax and income records, financial account details, identification data, and account credentials, increasing potential identity-theft and fraud risks. The incidents also show how supplier compromises and delayed notification can extend the impact beyond the initially targeted systems.
Articles: 28
Last Updated: 07/23/2026
- 96
South Korea Tightens Data Breach Enforcement

South Korea is responding to major breaches affecting matchmaking, credit-card, and diplomatic-training systems with larger fines, service restrictions, and closer scrutiny of data-protection failures. The incidents exposed sensitive personal information and revealed recurring weaknesses including missing patches, inadequate encryption, excessive retention, misconfigured systems, and delayed detection or notification. Together, they show enforcement expanding beyond the breach itself to include prevention, data minimization, retention, and incident-response practices.
Articles: 26
Last Updated: 08/04/2026
- 96
Cyber Insurance Covers Breach Losses

This topic centers on cyber insurance claims and the kinds of losses most often driving payouts, especially data breaches, ransomware, and vendor-related incidents. The material shows insurance covering most average breach losses, while also highlighting that some events remain highly costly because of downtime, business interruption, and legal or settlement expenses. It also points to emerging pressure from AI-enabled social engineering and less traditional exposures such as pixel-tracking litigation.
Articles: 14
Last Updated: 07/30/2026
- 96
TPWD Vendor Breach Exposes License Data

Texas Parks and Wildlife Department reported that a cybersecurity incident at an unnamed third-party license-system vendor may have exposed personal information belonging to more than 3 million hunting and fishing license customers. The affected data may include driver’s license and passport information, email addresses, phone numbers, and residential addresses, while the department said there was no evidence that Social Security numbers, dates of birth, or payment information were accessed. TPWD and the vendor are strengthening access controls and monitoring, while affected individuals are being advised to watch for fraud and use offered credit-monitoring services.
Articles: 66
Last Updated: 07/29/2026
- 96
Fortinet Credential Leak Fallout

Fortinet VPN and firewall credentials were exposed at large scale, affecting tens of thousands of internet-facing devices and prompting government advisories, vendor warnings, and urgent password-reset guidance. The reporting also points to access brokering and credential cracking as part of the same compromise pattern.
Articles: 8
Last Updated: 07/01/2026
- 96
Aflac And KDDI Breaches Expose Data

Two major breaches disclosed in June and July 2026 affected millions of people in Japan. Aflac Life Insurance Japan reported the theft of personal, insurance, and some premium-transfer account information belonging to approximately 4.38 million customers and agents, while KDDI reported unauthorized access to shared ISP email infrastructure affecting at least 12.2 million email addresses and 7.6 million passwords. The incidents highlight the impact of centralized systems and third-party software vulnerabilities, while the final scope of both breaches and the extent of downstream misuse remain under investigation.
Articles: 25
Last Updated: 07/28/2026
- 95
Third-Party Platforms Expose Customer Data

Organizations in the United States and Puerto Rico are reporting breaches involving cloud CRM systems, customer-support tools, and third-party financial service providers. Exposed information ranges from names and contact details to Social Security numbers, driver’s license data, health information, and debit card numbers. The pattern highlights how compromise of connected platforms or vendors can affect large customer populations even when an organization’s own core systems are not directly accessed.
Articles: 9
Last Updated: 07/23/2026
- 95
Package Registries Target Developer Secrets

Attackers are repeatedly compromising or impersonating packages on npm and PyPI to steal developer credentials, cloud secrets, CI/CD tokens, and cryptocurrency wallet data. Several campaigns use trusted publishing accounts, malicious installation hooks, typosquatted dependencies, or self-propagation to reach additional packages and repositories. The activity affects enterprise tooling, AI software, payment integrations, and widely downloaded development ecosystems, while attribution remains mixed between TeamPCP-linked malware, other threat actors using leaked code, and a Microsoft-attributed North Korean operation.
Articles: 17
Last Updated: 07/15/2026
- 95
Organizations Tighten Data Breach Defenses

Organizations are being urged to reduce data breach risk through layered controls spanning identity security, vulnerability management, cloud configuration, vendor access, monitoring, response, and recovery. The material also emphasizes minimizing raw personal-data sharing and using privacy-enhancing technologies where collaboration is necessary. The broader significance is that breach management increasingly involves limiting data exposure and exfiltration, communicating clearly with affected customers, and continuously validating that defenses work.
Articles: 11
Last Updated: 07/21/2026
- 95
Companies Report Sensitive Data Breaches

U.S. companies across scientific, financial, legal, healthcare, and professional-services sectors are reporting incidents in which unauthorized parties may have accessed sensitive personal information. Exposed or potentially exposed data includes Social Security numbers, financial details, identity records, and health information, with some incidents linked to ransomware or threat-group claims. Regulatory notices, consumer warnings, and legal investigations are emerging as organizations continue to determine the scope and impact of the breaches.
Articles: 31
Last Updated: 07/29/2026
- 95
Public Agencies Face Sensitive Data Breaches

Local and state public agencies in Los Angeles and Washington are confronting incidents in which sensitive legal, personal, and public-benefit records were exposed or accessed without authorization. The reported incidents include a Los Angeles City Attorney third-party environment exposing hundreds of thousands of files, Washington DSHS records viewed by a former employee, and a separate Los Angeles County benefits-data disclosure. The cases highlight the practical risks of weak access controls, third-party storage, and disputes over how long sensitive government records should be retained.
Articles: 15
Last Updated: 07/27/2026
- 94
Blackcat Ransomware Insider Misuse

Recent U.S. enforcement actions and prison sentences show former ransomware negotiators and incident response workers using insider access to help BlackCat extort victims, leak data, and split ransom proceeds.
Articles: 6
Last Updated: 07/10/2026
- 94
Dutch Breaches Expose Personal Data Risks

Dutch organizations are investigating or responding to several cyber incidents involving telecommunications, football, government, and consumer data. The incidents show how weaknesses in employee-facing processes, exposed APIs, shared keys, and customer systems can enable unauthorized access or data theft, while police investigations have led to an arrest and a suspected link to the Odido breach. The practical concern extends beyond the initial intrusion: exposed identity and contact data can support more convincing phishing, impersonation, and identity-fraud attempts.
Articles: 11
Last Updated: 07/24/2026
- 93
Attackers Exploit Exposed Enterprise Gateways

Attackers are exploiting or actively probing vulnerabilities in internet-facing email platforms, secure access gateways, AI development infrastructure, mobile devices, and network appliances. The incidents show how flaws in systems that bridge users, applications, and internal networks can enable credential theft, session compromise, code execution, data exposure, or malware delivery. CISA directives and vendor patches underscore the need to prioritize exposed assets and investigate for compromise, although exploitation status and actor attribution remain uneven across cases.
Articles: 14
Last Updated: 07/23/2026
- 93
Attackers Target Github Developer Workflows

Attackers are abusing GitHub repositories, Discussions, VS Code workflows, JavaScript bundles, and vulnerable web applications to steal credentials or deliver malware. The activity combines social engineering, repository impersonation, supply-chain compromise, exploitation of exposed secrets, and automated attacks against internet-facing software. The common risk is that trusted developer infrastructure and application artifacts can provide access to source code, cloud environments, accounts, and downstream users.
Articles: 12
Last Updated: 07/14/2026
- 92
NAIC Breach Linked To Oracle Peoplesoft Zero-Day

The National Association of Insurance Commissioners confirmed that attackers exploited an Oracle PeopleSoft zero-day, obtained credentials, and moved laterally into internal storage. NAIC said the accessed data primarily consisted of publicly available regulatory and credit-rating information, outdated logs, and configuration files, with no evidence that personal, banking, or payment information was compromised. ShinyHunters claimed a substantially larger theft and published data online, leaving the final scope under forensic review while the incident caused temporary disruption to some insurance data operations.
Articles: 5
Last Updated: 06/29/2026
- 92
North Carolina Breaches Fuel Privacy Debate

North Carolina reported 2,349 data breaches in 2025 affecting approximately 9.3 million residents, with ransomware, email compromise, and education-sector incidents prominent in the reporting. The scale of the breaches, including the PowerSchool incident, is driving increased attention to multifactor authentication, vendor security, staff training, enforcement, and how institutions collect and share personal data. Residents and advocates are also questioning whether expanded identity-verification requirements could create additional concentrations of sensitive information without sufficient transparency or safeguards.
Articles: 3
Last Updated: 05/19/2026
- 92
France’s Identity Data Breach Unfolds

France Titres, the French agency responsible for identity and vehicle-registration services, confirmed a breach detected in April 2026 after the threat actor breach3d claimed to possess and sell millions of records. Exposed information reportedly includes names, contact details, birth data, addresses and account identifiers, while the agency said the incident did not enable direct access to user portals and that uploaded identity documents were not affected. The case has prompted user warnings about phishing, regulatory and law-enforcement notifications, and a Paris investigation into a detained teenage suspect; the final scale and full technical cause remain uncertain.
Articles: 41
Last Updated: 08/20/2026
- 91
Dragonforce Hides Teams Traffic

This topic centers on DragonForce ransomware operations that use a custom backdoor, Backdoor.Turn, to hide command-and-control traffic inside Microsoft Teams relay infrastructure. The same campaign is tied to intrusion, credential theft, privilege escalation, data exfiltration, and ransomware deployment against at least one U.S. services company, with separate reporting that DragonForce also claimed an attack on a London production studio. The main significance is the abuse of trusted collaboration infrastructure to make malicious traffic look legitimate and harder for defenders to detect.
Articles: 4
Last Updated: 09/07/2026
- 90
UK Biobank's De-Identified Data Leak

UK Biobank data covering about 500,000 volunteers was reportedly uploaded to online repositories and later offered for sale through Alibaba-linked listings after legitimate access was granted to three research institutions. Although officials said the records lacked direct identifiers such as names and addresses, the data reportedly included detailed health, demographic, socioeconomic, lifestyle, and biological measures that could create re-identification risks when combined with other information. UK Biobank revoked access, removed listings, paused platform access, and began investigations, intensifying scrutiny of how biomedical datasets are downloaded, monitored, and shared.
Articles: 13
Last Updated: 07/30/2026
- 90
NVIDIA Geforce NOW Partner Breach

A breach of GFN.am infrastructure exposed personal information belonging to some GeForce NOW users in Armenia. NVIDIA says its own systems were not affected, while GFN.am reported that passwords were not compromised and that users who registered after March 9, 2026 were not affected. The incident highlights how regional partners with separate authentication and customer databases can create localized exposure for major technology services.
Articles: 5
Last Updated: 05/12/2026
- 88
Kraken Insider Data Extortion

Kraken disclosed insider-led access incidents that exposed limited customer support data and led to extortion threats. The main pattern is misuse of legitimate support access, followed by access revocation, user notification, and cooperation with law enforcement.
Articles: 3
Last Updated: 04/17/2026
- 88
Cloud Integrations And Identity Breaches

The topic centers on cyberattacks that abuse trusted cloud connections, exposed credentials, and convincing impersonation to reach enterprise or personal data. A Klue integration compromise enabled unauthorized access to connected Salesforce environments and led to extortion claims, while separate incidents involving Accenture and The Credit Pros raised concerns about source code, credentials, and sensitive personal information. Phishing campaigns targeting LastPass and Bitwarden users show the same broader reliance on identity and trust-based attack paths, although the incidents are not attributable to a single campaign.
Articles: 49
Last Updated: 07/22/2026
- 84
Privacy Regulators Tighten AI Data Rules

Privacy regulators and courts are expanding obligations for organizations that collect, share, or use personal data, particularly in AI systems, advertising technology, children’s services, health applications, and data-broker markets. The United States remains fragmented across state and federal regimes, while the EU, UK, Switzerland, India, and other jurisdictions apply distinct requirements for risk assessments, transparency, consent, minimization, security, and international transfers. The direction of travel is toward more documentation, stronger individual rights, tighter breach response, and increased enforcement against deceptive or inadequately protected data practices.
Articles: 106
Last Updated: 08/07/2026
- 72
Hackers Target Microsoft 365 Credentials

Threat actors are targeting Microsoft 365 identities through two complementary paths: APT28 has redirected authentication traffic by compromising vulnerable SOHO routers, while a separate campaign used exposed credentials and the Azure CLI to conduct large-scale password spraying. The activity shows how attackers can obtain account access or tokens by exploiting weak edge-device security, legacy authentication flows, incomplete MFA policies, and reused credentials. Law-enforcement disruption has removed some infrastructure, but affected organizations and users still need to patch or replace exposed routers and strengthen identity controls.
Articles: 5
Last Updated: 07/24/2026
Secondary
- 96
Student Loan Data Breach Settlement

A federal court has finalized a $10 million settlement over a 2022 Nelnet-related data breach that exposed student loan borrowers' personal information. The current focus is on claims administration, eligibility disputes, and payout timing for millions of affected borrowers.
Articles: 6
Last Updated: 05/22/2026
- 94
NYC Health + Hospitals Breach Exposes Biometrics

NYC Health + Hospitals disclosed a cyberattack that exposed data belonging to at least 1.8 million patients, employees, and other affiliated individuals. The reported information includes medical records, insurance and billing details, government identifiers, Social Security numbers, and fingerprint and palm-print data, with unauthorized access traced to an unnamed third-party vendor and lasting from late 2025 into February 2026. The incident highlights the consequences of vendor access to healthcare networks and creates extended risks because biometric information cannot be readily replaced.
Articles: 29
Last Updated: 07/29/2026
- 94
Threat Actors Exploit Oracle Peoplesoft

Threat actors exploited an Oracle PeopleSoft PeopleTools zero-day, tracked as CVE-2026-35273, to access sensitive personnel records held by enterprise HR and payroll systems. Nissan reported potential exposure of employee and dependent information across several countries, while reporting linked the broader campaign to ShinyHunters and identified additional affected organizations. The incidents show how compromise of HR platforms can expose identity, payroll, tax, banking, and benefits data, prompting containment measures, vendor coordination, and credit or identity monitoring for affected individuals.
Articles: 19
Last Updated: 07/06/2026
- 92
Triwest Warns 11,844 Tricare Beneficiaries Of Data Breach

Healthcare organizations are notifying beneficiaries and members about unauthorized access to systems containing personal and protected health information. TriWest reported that an incident affecting 11,844 TRICARE beneficiaries exposed names, Department of Defense Benefits Numbers and ZIP codes, with more sensitive details involved in fewer than five cases; a separate Wellpoint Washington incident reportedly affected about 12,020 people. The developments highlight the exposure of healthcare administration systems and the need for timely notification, monitoring and security remediation.
Articles: 4
Last Updated: 07/13/2026
- 91
Healthcare Data Breaches And Legal Response

Healthcare providers, medical groups, law firms, and health-technology companies are disclosing unauthorized access to systems containing patient identifiers, medical records, insurance data, and financial information. The 2026 reporting cycle emphasizes lengthy investigations, regulator notices, credit-monitoring remedies, and class-action scrutiny, while many notices leave the access method, affected population, or actual misuse unresolved.
Articles: 128
Last Updated: 07/30/2026
- 91
Dentaquest Breach Exposes Health Data

DentaQuest, a Sun Life subsidiary and dental benefits administrator, suffered unauthorized network access in May 2026 that exposed personal, insurance, and potentially protected health information. ShinyHunters claimed responsibility, alleged theft of roughly 234 gigabytes of data, and reportedly published the material after failed extortion negotiations. Reported impact estimates vary substantially, but multiple accounts place the affected population in the millions and identify risks of identity theft, phishing, medical fraud, and targeted scams.
Articles: 42
Last Updated: 08/28/2026
- 90
Triwest Data Breach Affects 11,844 Tricare Beneficiaries

TriWest Healthcare Alliance reported unauthorized access to and downloading of information linked to 11,844 TRICARE beneficiaries, including names, Department of Defense Benefits Numbers, and ZIP codes. Fewer than five cases reportedly included Social Security numbers, addresses, and dates of birth, while a Texas filing identified 2,408 affected residents. TriWest has notified individuals, offered 24 months of credit monitoring, and strengthened access controls, monitoring, and employee training.
Articles: 5
Last Updated: 07/17/2026
- 90
Powerschool Student Data Litigation

PowerSchool faces parallel legal scrutiny over the security and use of K-12 student data. A federal court allowed multiple claims against owner Bain Capital to proceed in litigation related to a breach reportedly affecting millions of students and educators, while a separate $17.25 million Naviance settlement addresses allegations that third-party analytics tools collected student activity and communications without adequate consent. Together, the matters highlight litigation exposure for education technology providers, owners, schools, and technology partners when sensitive data is accessed, shared, or tracked.
Articles: 3
Last Updated: 05/25/2026
- 90
Healthcare Data Breaches Hit Patients

Healthcare organizations and service providers are reporting breaches that expose combinations of patient identities, medical histories, insurance details, and financial information. The incidents range from credential compromise and social engineering to ransomware-linked intrusions and unauthorized access to third-party storage or billing systems, with the largest disclosed case affecting more than 1.26 million people through MCBS. The disclosures also show continuing exposure beyond hospitals, including medical equipment suppliers, law firms, insurers, and business associates, followed by credit-monitoring offers, regulatory reporting, and proposed litigation.
Articles: 151
Last Updated: 08/28/2026
- 90
Oracle EBS Breach Exposes HR Data

Estée Lauder disclosed a breach of its Oracle E-Business Suite human resources environment that exposed employee and other personal data, with reporting tied to a 2025 Oracle vulnerability and Clop-linked mass exploitation. The strongest signal is a delayed disclosure after prolonged undetected access, followed by identity monitoring and incident-response measures.
Articles: 11
Last Updated: 07/27/2026
- 90
Breaches Hit Universities, Expose Sensitive Data

Universities are reporting unauthorized access and ransomware incidents involving records that may contain Social Security numbers, government identification data, financial details, credentials, and health information. The incidents have prompted breach notifications, credit-monitoring offers, attorney general filings, law-firm investigations, and at least one class-action settlement. The material indicates recurring exposure of high-value personal data across education-sector systems, but details about confirmed acquisition and the effectiveness of security controls remain limited.
Articles: 6
Last Updated: 07/09/2026
- 90
Healthcare Data Breaches Produce Multimillion-Dollar Settlements

U.S. healthcare providers and related service organizations are settling class actions arising from breaches that exposed personal, medical, Social Security, and financial information. The agreements generally combine cash or documented-loss reimbursements with credit, dark-web, or medical identity monitoring, while organizations deny liability or settle without admitting wrongdoing. The cases show how cyber incidents involving large patient populations are producing substantial litigation and remediation costs after the underlying breaches.
Articles: 12
Last Updated: 08/28/2026
- 89
Canvas Breach Disrupts California Colleges

A cybersecurity incident at Instructure disrupted Canvas access across colleges and universities, including all 23 California State University campuses, during a critical academic period. Instructure said potentially exposed information included names, email addresses, student and faculty ID numbers, rosters, and user messages, while reporting no evidence that passwords, financial data, birth dates, or government identifiers were involved at the time. The incident also generated extortion claims attributed to ShinyHunters, prompting institutions to restrict access, warn users about phishing, and develop contingency plans for online instruction.
Articles: 12
Last Updated: 07/22/2026
- 88
School Tip Line Data Breach

Lawmakers are pressing Navigate360 after reports that its school safety tip line platform was breached and exposed sensitive student data, raising questions about anonymity, cybersecurity, and incident response.
Articles: 6
Last Updated: 07/03/2026
- 88
Canvas Breach Data Deletion Deal

Instructure, the company behind Canvas, is responding to a breach in which an unauthorized actor accessed student-related data and later returned it under a reported agreement to delete remaining copies. The incident matters because Canvas is deeply embedded in school operations, so the breach caused access disruptions during finals and raised concerns about the potential exposure of student contact and message data. The reported involvement of ShinyHunters and the use of ransom-linked threats point to a broader extortion dynamic, even as the company says it has not seen evidence of passwords or financial data being compromised.
Articles: 22
Last Updated: 07/16/2026
- 88
Canvas Breach Fallout

Instructure is dealing with the fallout from a breach affecting Canvas, the learning platform used by schools and universities worldwide. The incident disrupted access during finals, prompted claims from ShinyHunters about stolen student data, and led Instructure to say it reached an agreement for the data to be deleted, though it cannot verify permanent destruction. The case matters because it combines operational disruption, possible exposure of student and school information, and continuing uncertainty about whether exfiltrated data will be reused or leaked.
Articles: 30
Last Updated: 05/13/2026
- 86
Nintendo Tinypulse Employee Breach

This topic centers on a third-party breach involving TinyPulse, an employee survey platform used by Nintendo of America, where internal employee data was reportedly stolen and used in an extortion attempt. Nintendo says its own systems and customer data were not compromised, but the incident still raises privacy risks for employees whose survey and HR-related information may have been exposed. The case highlights how vendor platforms can become the main path for sensitive data loss even when the target company’s internal network remains intact.
Articles: 21
Last Updated: 07/11/2026
- 86
Shinyhunters Targets Education Data

ShinyHunters-linked intrusions exposed education-sector data at Instructure’s Canvas platform and Moody Bible Institute. Instructure said names, email addresses, student IDs, messages, and enrollment-related information were accessed, while it reported no evidence that passwords, financial data, or government identifiers were compromised; Moody disclosures described exposure ranging from email addresses to Social Security and driver’s-license information for a smaller confirmed group. The incidents also involved extortion, Canvas portal defacement, vulnerability remediation, and disputed claims about the total volume of affected records.
Articles: 30
Last Updated: 08/17/2026
- 86
Healthcare Data Breach Investigations Expand

Healthcare providers and related organizations are reporting cyber incidents in which unauthorized actors accessed networks or copied files containing personal and protected health information. The incidents range from several thousand affected individuals to hundreds of thousands or more, although the specific data exposed is not always known. Organizations are responding with investigations, regulatory notifications, security upgrades, and credit or identity-monitoring services, while law firms assess potential claims.
Articles: 8
Last Updated: 07/09/2026
- 86
Chick-Fil-A Warns Of Account Exposure
Chick-fil-A says attackers used credentials obtained from a third-party source to target Chick-fil-A One accounts through automated login attempts against its website and mobile app between June 17 and June 19, 2026. The company determined that some accounts may have been accessed, potentially exposing contact details, loyalty and payment-related information, and account balances. Chick-fil-A forced logouts, removed stored payment methods, restored affected balances, and reset passwords while advising customers to update credentials and monitor their accounts.
Articles: 68
Last Updated: 08/04/2026
- 86
Legacy Cerner Breach Spreads Across Hospitals

An unauthorized third party accessed data held on legacy Cerner systems beginning in January 2025, prompting hospitals across the United States to notify potentially affected patients. The exposed information may include names, Social Security numbers, medical record details, diagnoses, treatments, test results and images, while hospitals generally state that their own systems were not compromised. The incident is unfolding through staggered disclosures and patient notifications, raising questions about vendor responsibility, notification timing and protection of historical health records.
Articles: 41
Last Updated: 08/27/2026
- 84
Healthcare Breaches Disrupt Care And Expose Data

Healthcare providers and medical technology companies are facing cyberattacks that range from unauthorized corporate-system access and data theft to ransomware-driven outages affecting clinics, hospitals, and diagnostic services. The incidents show that attackers can create both privacy exposure and direct interruptions to care, while the extent of stolen patient information often remains unclear during early investigations. Organizations are isolating systems, using manual downtime procedures, engaging law enforcement and security firms, and providing patient support as they assess the damage.
Articles: 11
Last Updated: 08/12/2026
- 82
Canvas Breach And Ransom Demand

Instructure's Canvas learning platform was hit by a breach and extortion campaign attributed to ShinyHunters, leading to temporary outages and threats to leak student and staff data. The incident affected schools and universities that rely on Canvas for coursework, deadlines, and exams, making it both an operational disruption and a privacy risk. Instructure later said it reached an agreement with the attackers and received confirmation of data destruction, but the full scope of impacted data remains unclear.
Articles: 4
Last Updated: 05/13/2026
- 82
Third-Party Vendors Drive Breach Exposure

Organizations increasingly depend on external platforms, suppliers, and managed services that can become pathways into sensitive data and critical operations. Incidents involving education technology providers, EY’s third-party service platform, Target’s contractor access, and public-sector suppliers show how weak permissions, limited visibility, and inadequate segmentation can amplify breaches. The recurring response is a shift from one-time vendor reviews toward continuous monitoring, enforceable security requirements, stronger identity controls, and coordinated incident response.
Articles: 8
Last Updated: 08/20/2026
- 79
Education Saas Breaches Expose User Data

Education technology providers and connected institutions are responding to breaches involving learning platforms, career services systems, and Salesforce environments. Reported exposures center on names, email addresses, student or staff identifiers, messages, contact records, and locally stored passwords, while several organizations said core academic, financial, or internal systems were not affected. The incidents underscore how compromise of third-party education platforms can create broad phishing, service disruption, and privacy risks across many schools and universities.
Articles: 117
Last Updated: 07/07/2026
- 79
Novo Nordisk Breach Exposes Trial Data

Novo Nordisk disclosed that attackers accessed internal systems and copied non-public data from some clinical trials, including pseudonymized health, demographic, biomarker, and lifestyle information. Data linked to an undisclosed number of healthcare professionals was also reportedly exposed, including contact and workplace details. The company has taken affected systems offline, begun an investigation with external cybersecurity experts, and warned that the information could support targeted phishing or impersonation, while the full scope and breach mechanics remain unclear.
Articles: 28
Last Updated: 07/04/2026
- 78
WFP Breach Exposes Gaza Aid Data

The World Food Programme’s Palestine Self-Registration Application was breached on 14 May 2026, exposing personal information associated with Palestinian households seeking food and cash assistance in Gaza. Reported data included names, identification numbers, phone numbers, and location details, with WFP citing approximately 600,000 affected households while the total number of potentially exposed users remains unclear. The incident has prompted criticism over the 17-day notification delay, limited public disclosure, and the collection and protection of highly sensitive data in an active conflict environment.
Articles: 6
Last Updated: 07/23/2026
- 78
Canvas Breach Disrupts Final Exams

Canvas, the learning management system used by schools and universities, was disrupted by a cyberattack that hit during final exams and forced some institutions to delay tests, extend deadlines, or shift communications off-platform. Reporting indicates unauthorized access exposed at least some user data, including names, email addresses, student ID numbers, and messages, while Instructure said more sensitive data such as passwords and financial information was not implicated. The incident is significant because it combines platform outage, ransom pressure, and education-sector operational disruption across many institutions.
Articles: 16
Last Updated: 05/26/2026
- 78
FTC Orders Illuminate Over Student Breach

The Federal Trade Commission finalized an order requiring K-12 software provider Illuminate Education to strengthen security controls after an alleged breach exposed personal information associated with more than 10.1 million current and former students. The order restricts unnecessary data collection and retention, requires deletion and retention disclosures, prohibits misleading security or breach-notification claims, and imposes recurring independent assessments and reporting. The action highlights increasing regulatory scrutiny of how education technology vendors secure, retain, and communicate about sensitive student data.
Articles: 5
Last Updated: 06/18/2026
- 76
Healthcare Data Breaches Hit Vendor Systems

Healthcare providers and medical-service companies are disclosing breaches in which attackers stole patient personal information and protected health information from business applications, contractor accounts, and external electronic health record portals. iRhythm and AdaptHealth both linked their incidents to social engineering and threat-actor extortion, while Ikron reported a ransomware incident involving separate intrusions into operational and health-record systems. The disclosures show that patient data exposure can occur outside core clinical infrastructure, while the full number of affected individuals and the precise data involved may remain unclear during investigations.
Articles: 12
Last Updated: 07/07/2026
- 74
Canvas Breach Hits Schools

A cybersecurity incident involving Instructure's Canvas learning platform exposed student and staff information used by schools and universities. Reporting indicates the compromised data likely included names, email addresses, student ID numbers, and messages, while passwords, financial data, and government identifiers were not believed to be affected. The main concern is not system-wide disruption but downstream misuse of exposed data for phishing and other social engineering attacks across education networks.
Articles: 17
Last Updated: 07/28/2026
- 74
Infostealers Expose Credentials Across Identities

Infostealer malware and exposed breach databases are turning stolen passwords, session data, email addresses, and account records into reusable access across personal and enterprise services. Large collections analyzed or added to Have I Been Pwned show how endpoint compromise can bypass corporate defenses and connect online identities to employers and sensitive accounts. The main defensive direction is to identify exposed credentials quickly, prevent password reuse, and strengthen accounts with multifactor authentication, password managers, or passkeys.
Articles: 6
Last Updated: 07/17/2026
- 74
Phishing Kits Hijack Microsoft 365 Tokens

Cybercriminals are increasingly using device-code phishing, malicious OAuth applications, and adversary-in-the-middle techniques to obtain valid Microsoft 365 authentication tokens without directly stealing passwords or MFA codes. Platforms including Tycoon2FA, ARToken, Forg365, and Kali365 package these methods into phishing-as-a-service offerings that support campaign delivery, token management, mailbox monitoring, and access to Microsoft cloud data. The activity matters because completed legitimate authentication can give attackers persistent access to Outlook, Teams, OneDrive, SharePoint, and connected single sign-on services.
Articles: 9
Last Updated: 07/09/2026
- 74
Malicious Extensions Hijack Browser Sessions

Malicious browser extensions are being used as a durable access layer for credential theft, session hijacking, ad fraud, remote code execution, and abuse of authenticated web services. Campaigns affecting Chrome and Edge have used legitimate-looking functionality, delayed or concealed payloads, shared infrastructure, and multiple publisher identities to reach large user populations. The pattern shows that browser add-ons can convert ordinary browsing access into persistent control over identity data, messaging sessions, enterprise credentials, and connected applications.
Articles: 7
Last Updated: 07/18/2026
- 72
Canvas Breach Hits Schools Nationwide

Instructure's Canvas learning platform was hit by a breach and extortion attempt tied to ShinyHunters, exposing student and staff data at schools and universities that use the service. The incident temporarily disrupted access during finals and end-of-term work, while schools and district officials assessed what information may have been exposed. It also renewed scrutiny of how much sensitive student data is concentrated in a small number of education technology platforms and how exposed identities can fuel phishing and other follow-on attacks.
Articles: 18
Last Updated: 08/08/2026
- 71
Vercel Breach Exposes AI Tool Risk

Recent reporting describes a Vercel security incident that began with compromise of a third-party AI tool, then moved through Google Workspace OAuth access into internal systems and exposed some customer credentials and non-sensitive environment variables. Most coverage now emphasizes third-party access governance, secret rotation, and uncertainty about the full scope of exposure.
Articles: 15
Last Updated: 04/23/2026
