data breach12 articles
EY Breach Exposes Client Tax Data Including SSNs and Card Numbers
Ernst & Young (EY) has begun notifying clients of a data breach involving a third-party service management platform used for tax-related work, with hackers gaining access between March 28 and April 12 after the incident was discovered on April 23. The compromised data includes sensitive personal and financial information such as names, addresses, Social Security numbers, and credit/debit card numbers. EY states it is unaware of any misuse of the data and is offering affected clients two years of free credit monitoring and identity protection services.
23 Million Paidwork Users' Data Dumped Online After Alleged March Breach
A data breach at microtask platform Paidwork has exposed the personal and financial information of over 23 million users, with a stolen 11 GB database first advertised on a cybercrime forum in April and later added to Have I Been Pwned in July. The leaked data is extensive, including bank account numbers, passwords, addresses, transaction records, and more, with the breach traced back to an intrusion in March. Paidwork has yet to publicly acknowledge the incident or respond to press inquiries, leaving affected users advised to change passwords, monitor their finances, and watch for phishing attempts.
Nichirei Cyberattack Leaves Japan's Frozen Food Chain on Ice
Japanese frozen food giant Nichirei was hit by a cyberattack on July 13, forcing it to disconnect its systems and disrupting operations at its refrigerated warehouses and shipping divisions, with knock-on effects for restaurants, retailers, and delivery services. The company confirmed that hackers targeted its servers and that some affected systems contained personal information, prompting an initial report to Japan's Personal Information Protection Commission over a potential data leak. Nichirei announced it would begin gradually restoring operations but has withheld details of the attack, leaving it unclear whether a ransomware group was involved.
Accenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys
Accenture has confirmed a data breach after a hacker claimed on PwnForums to have stolen 35 gigabytes of data, including source code, Azure access keys, RSA/SSH keys, and configuration files from the company. Accenture stated the incident has been remediated and that there is no impact on its operations, though it provided few further details. Security experts warn the stolen data could be leveraged for future attacks, given Accenture's close proximity to major enterprise clients' systems and infrastructure.
ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients
Medical technology company Medtronic suffered a data breach in April 2026 when the extortion group ShinyHunters accessed its corporate IT systems, compromising the personal and medical information of over 3.8 million individuals. Stolen data included names, contact details, dates of birth, Social Security numbers, and health-related information, though Medtronic states there is no evidence the data was publicly exposed. The company is offering affected individuals 24 months of free credit monitoring and identity theft protection services, and has implemented additional cybersecurity safeguards.
Small US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.
A US county government, reportedly Union County, Ohio, paid a $1 million Bitcoin ransom to the Kairos cyber extortion group following a May 2025 brute-force attack in which over 2 terabytes of data were stolen. Negotiations began at $100,000 and ended at $1 million after the attackers imposed a hard deadline, with the group originally demanding $3 million. The breach ultimately affected over 45,000 individuals whose sensitive personal, financial, and medical information was compromised, though no file-encrypting ransomware was involved and there is no independent verification that the stolen data was actually deleted.
Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach
Medtronic is notifying patients that their personal and health data — including names, Social Security numbers, and medical information — may have been stolen during a cyberattack in which unauthorised actors accessed its corporate systems for nearly a week in April. The extortion group ShinyHunters claimed responsibility, alleging it stole over nine million records and demanding a ransom, though Medtronic has not publicly attributed the attack or confirmed whether data was actually exfiltrated. The company states that no medical devices were affected and is offering impacted individuals two years of complimentary credit and identity monitoring services.
One Leaked GitHub Token, 1.3TB Gone: The Novo Nordisk Breach Is a Wake-Up Call for Dev Security
Danish pharmaceutical giant Novo Nordisk suffered a major breach after attackers gained initial access through a single exposed GitHub personal access token, enabling them to clone private repositories, harvest additional credentials, and move laterally through the network for over two months. The threat group FulcrumSec claims to have exfiltrated approximately 1.3TB of data — including source code, proprietary drug research, clinical trial data, and internal AI models — before demanding a $25 million ransom, suggesting the breach was far more extensive than Novo Nordisk has publicly acknowledged. Security experts warn the incident highlights a broader industry failure to treat developer environments and secrets management as identity security problems, noting that machine credentials like API tokens are often poorly monitored, broadly privileged, and rarely rotated, making a single exposed token enough to trigger a catastrophic breach.
Dutch Police Nab Suspect Who Repeatedly Hacked Ajax Amsterdam's IT Systems
Dutch police arrested a 35-year-old man from Buren on suspicion of repeatedly hacking into Ajax Amsterdam's computer systems in early 2026. The attacker exploited vulnerabilities in the club's IT infrastructure to access data on hundreds of individuals, modify stadium bans, and potentially manipulate over 42,000 season tickets and 300,000 fan accounts. Ajax has since patched the vulnerabilities and notified the Dutch Data Protection Authority and police.
Myspace93 Breach: 46,000 Plaintext Passwords Finally Surface, Five Years Late
In January 2021, Myspace93 — a parody site mimicking the old social network — suffered a breach in which trusted members of a Discord community exploited beta app access to steal server files, including an unencrypted store containing the plaintext usernames, passwords, email addresses, and IP addresses of over 46,000 users. The site's co-creator, known as jankenpopp, blamed the betrayal on individuals he considered close collaborators, who concealed the theft and shared stolen data and download tools among themselves. The breach has only recently been highlighted after HaveIBeenPwned ingested the data more than five years later, and affected users are advised to change any reused passwords and enable two-factor authentication.
Shadow AI Is the Insider Threat Nobody's Watching
Verizon's 2026 Data Breach Investigations Report reveals a fourfold increase in "shadow AI" use, with 67% of employees who regularly use AI at work doing so through unauthorized personal accounts, potentially exposing sensitive corporate data such as source code, documents, and proprietary research to unvetted third-party platforms. The report also highlights worsening vulnerability management, with remediation rates for critical flaws dropping from 38% to 26% and resolution times rising from 32 to 43 days, while ransomware featured in nearly half of all breaches. On a positive note, ransom payments continued to decline, with 69% of victims refusing to pay and the median payment falling slightly to just under $140,000.

Grafana Labs Got Its GitHub Raided. It's Not Paying Up.
Grafana Labs has disclosed that an unauthorized attacker obtained a token to access its GitHub environment and stole its codebase, subsequently threatening to release the code unless a ransom was paid. The company refused to pay, citing FBI guidance and the fact that no customer data or operational systems were affected. The incident's impact may be limited, as much of Grafana's code is already open source, though it remains unclear exactly what proprietary code was taken.