data breach44 articles
Berlin Tells Rhysida to Get Lost After 5.7TB Data Heist
Berlin has refused to pay a ransom demanded by the Rhysida ransomware group, which hacked into the city's network between August 7–12 and stole over 5.7 terabytes of data. The stolen data reportedly includes personal information of over 12,000 people, financial documents, passwords, payroll information, and other sensitive files. Rhysida has demanded 30 bitcoin (approximately $2.3 million), but Berlin's governing mayor and interior senator have confirmed the city will not comply.
Hasbro Breach Exposes Employee Data — Monopoly Money Won't Cover This One
Hasbro has notified employees that their personal information, including names, addresses, phone numbers, national ID numbers, and financial details, may have been compromised in a data breach. The breach likely affects hundreds to a few thousand employees and may be linked to a cyberattack in late March that cost the company $11 million in cleanup expenses and delayed $25 million in product sales. Hasbro states it is unaware of any misuse of the exposed data and is offering identity protection services to those affected.
Boston Scientific Hit by Cyberattack, Global Operations in Chaos
Boston Scientific, a major US medical technology company, suffered a cyberattack on August 25 that disrupted global operations, including the ability to process and ship customer orders. The company has disclosed the incident in an SEC filing but cannot yet determine the full scope of operational and financial impacts. It remains unclear whether a data breach occurred or which threat actor is responsible.
ATF Got Hit by Qilin Ransomware. The Reassurances Are Already Flowing.
The ATF has confirmed a cybersecurity incident after the Qilin ransomware group claimed to have attacked the agency, though the breach was limited to a standalone system that was quickly disconnected and did not affect the ATF's broader network or operations. The Department of Justice has designated the event a "major incident" and an investigation is underway. Qilin, a double-extortion ransomware group active since at least 2022 with over 2,000 listed victims, has not yet specified what data was stolen or when it may be leaked.
Berlin Won't Pay Up After Hackers Swipe 5.79TB From City Network
Berlin's state government has confirmed it is the victim of an extortion attempt following a cyberattack in August 2026 that compromised its administrative network and resulted in the exfiltration of data, reportedly 5.79 terabytes according to the attackers. The city has refused to pay the ransom, with Governing Mayor Kai Wegner stating plainly that "the state of Berlin is being blackmailed," while law enforcement and federal security authorities investigate the incident. The ransomware group Rhysida has been named as the likely perpetrator, with officials stating that election infrastructure and sensitive data appear not to have been compromised.
Qilin Ransomware Gang Claims ATF Scalp as Feds Confirm 'Major' Breach
The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is responding to a "major" cybersecurity incident after the Russia-linked Qilin ransomware gang claimed responsibility, posting the agency on its leak site. ATF states that the breach was limited to a standalone computer system containing investigation target information, with no impact on its broader network or operations. The Department of Justice has designated the compromise a "major incident," and an investigation is ongoing, with ATF declining to provide further details.
ShinyHunters Padded the Carhartt Breach With Millions of Fake Records
Carhartt suffered a data breach affecting approximately 12.9 million individuals — roughly half the 25 million claimed by hacking group ShinyHunters, which had padded the dataset with millions of lines of synthetic data. Troy Hunt of Have I Been Pwned uncovered the inflation through careful analysis, using tools to identify fake email domains, implausible demographics, and other anomalies before arriving at the genuine figure. The real breach exposed names, email addresses, phone numbers, and physical addresses, with Carhartt yet to publicly comment on the incident.
Apollo Global Hit by Social Engineering Attack Exposing Names, Contacts and SSNs
Apollo Global Management suffered a data breach after a social engineering (vishing) attack allowed threat actors to access its cloud platforms between July 6–10, potentially exposing personal information including names, contact details, and Social Security numbers. The attack is linked to a cybercrime group known as BlackFile (UNC6671), which has been targeting major financial and private equity firms across North America, Australia, and the UK using IT helpdesk-themed phone phishing tactics. While Apollo is the only confirmed victim of a successful data compromise so far, Apollo states there is no evidence the stolen data has been made public or used for fraud, and affected individuals are being offered identity protection services.
Apollo Global Got Social Engineered. SSNs Walked Out the Door.
Apollo Global Management suffered a data breach between July 6–10 after attackers used social engineering tactics to gain unauthorized access to its cloud systems, stealing sensitive personal information including names, Social Security numbers, dates of birth, and home addresses. The breach is consistent with a broader campaign targeting private equity and financial firms, with Google previously warning that an extortion-focused group called UNC6671 was posing as IT staff to harvest employee credentials. Apollo has notified law enforcement, engaged cybersecurity experts, and is offering affected individuals 24 months of credit monitoring, though key details — such as the number of people affected and which cloud platforms were compromised — remain undisclosed.
France's Tax Authority Breach: 600,000 Affected, Private Messages Included
France's tax authority (DGFiP) has confirmed a data breach affecting approximately 600,000 individuals and businesses, with stolen information including tax identification numbers, personal details, and for around 250 people, the actual contents of private messages exchanged with the authority. Affected parties are being notified and warned of potential follow-on attacks such as phishing and impersonation scams exploiting the stolen data. The incident is the latest in a series of significant cybersecurity breaches targeting French public sector organisations in 2025.
LockBit Claims US Bank Scalp With September Leak Deadline
US Bank is investigating claims by ransomware group LockBit that it breached the bank and stole data, with a threat to leak the information on September 3 unless an undisclosed ransom is paid. The bank states there is currently no indication its internal systems were compromised or that unauthorized access occurred. LockBit, which re-emerged in 2025 with a new ransomware variant after a law enforcement takedown in 2024, has a history of retaining victim data even after ransoms are paid.
Heights Finance Breach Exposes Data of 1.2 Million Borrowers
Consumer lender Heights Finance Holdings suffered a data breach in early May when hackers accessed a third-party cloud-based storage platform, compromising the personal and financial information of over 1.2 million individuals. Stolen data includes names, Social Security numbers, bank account details, and other sensitive information belonging to current and former borrowers. Heights has secured the platform, notified federal law enforcement, and is offering affected individuals 24 months of free credit monitoring and identity protection services.
Threat Actor Claims Millions of Corporate Records Lifted from Azure Tenants
A threat actor called "TheHatman" is claiming to have stolen millions of employee records from the Microsoft Azure environments of major corporations including McDonald's, Vodafone, Tata Consultancy Services, and Kyndryl, with the data reportedly including sensitive details such as employee IDs, job titles, and accounts with Global Administrator privileges. Security firm Hudson Rock assessed the data as "highly likely authentic" but could not determine the exact method of access, suggesting possibilities such as infostealer malware, phishing, or weak multi-factor authentication. Tata Consultancy Services has denied finding credible evidence of a breach, stating the referenced information appears to be over four years old and limited to basic employee data.
Hacker Flogs Azure Directory Data From McDonald's, Vodafone and a Stack of Fortune 500 Names
A threat actor known as 'TheHatman' is selling data allegedly stolen from the Azure tenants of multiple Fortune 500 companies, including McDonald's, TCS, Vodafone, and Wyndham Hotels, with the McDonald's dataset alone containing over 1.7 million records. The data, which appears to have been exfiltrated using leaked credentials from a targeted infostealer campaign, includes sensitive employee information such as names, email addresses, job titles, and privileged account details. Security firm Hudson Rock warns the breach poses a serious risk, as the exposed data could enable attackers to conduct spear-phishing, business email compromise, and privilege escalation attacks against the affected organisations.
French Tax Authority Breach Exposes Financial Data on 680,000 Citizens
France's tax authority (DGFiP) has disclosed a data breach affecting approximately 680,000 individuals, after a threat actor used compromised employee and third-party credentials to access its systems in June and July. Stolen data includes reference tax income, withholding tax rates, company identifiers, and real estate cadastral data, though no passwords or usernames were compromised. The breach was reported to France's data protection authority CNIL, and DGFiP is contacting all affected individuals while continuing to investigate the full scope of the incident.
ShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach
Ernst & Young (EY) suffered a data breach between March 28 and April 12, in which hackers stole sensitive client information — including Social Security numbers, account numbers, and tax-related documents — from a third-party service management platform. The notorious extortion group ShinyHunters has since claimed responsibility, adding EY to its leak site and threatening to release the stolen data if the firm does not make contact by July 31. EY has not disclosed the number of affected individuals or confirmed the attacker's identity, but is offering impacted clients 24 months of free credit monitoring and identity protection services.
France's Tax Authority Confirms Data Breach After Hacker Hawks 2 Million Taxpayer Records Online
France's tax authority (DGFiP) has confirmed a data breach that occurred in late June 2026, in which an attacker using stolen credentials and an MFA bypass technique accessed and extracted data on approximately 2 million taxpayers. The alleged criminal, known as "ZeroBytes," advertised the stolen database on a cybercrime forum and claimed to still have access to DGFiP's systems, though the agency disputes this and says access was severed during a routine audit. The incident is one of several significant cyberattacks targeting French public sector organisations in 2026, following earlier breaches affecting the Finance Ministry, Health Ministry, and the passport and driver's licence agency France Titres.
Madera Community Hospital Took a Year to Tell 150,000 People Their Data Was Stolen
Madera Community Hospital in California has notified over 150,000 individuals that their personal, financial, and medical information was compromised in a cyberattack that occurred in May 2025. Hackers accessed the hospital's network for two days and likely exfiltrated files containing sensitive data, including Social Security numbers, health insurance details, and biometric information, though the hospital found no evidence the data was publicly released. The extortion group behind the attack ultimately withdrew its ransom demand, claiming it did not want to harm patients.
Hackers Raid Liechtenstein's Beneficial Ownership Register, Exposing 31,000 People
A cyberattack on Liechtenstein's register of economic beneficiaries exposed the data of approximately 31,000 individuals linked to companies, foundations, and trusteeships in the principality. The breach occurred overnight between Wednesday and Thursday, was detected the following day, and prompted authorities to take the system offline and establish a crisis unit to investigate. There is no indication that any data was altered or deleted during the attack.
Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the Door
Levi Strauss & Co disclosed a cyberattack in an SEC filing, revealing that social engineering was used to compromise three employees' company-issued computers, resulting in corporate data being accessed and exfiltrated. The company says it has contained the incident and evicted the attackers, with no customer data or business operations appearing to have been affected. The investigation is ongoing, and unconfirmed reports suggest the hacking group UNC6671, known for voice phishing campaigns, may have been responsible.
Ransomware Surges While Everyone's Busy Watching the AI Show
Ransomware attacks surged nearly 20% in July 2024, reaching 799 incidents — the second-highest monthly total of the year — with finance, tech, pharmaceutical, and education sectors seeing the sharpest increases. The US was the most targeted country, accounting for 322 of the attacks, while two gangs — The Gentlemen and Qilin — together claimed responsibility for roughly a third of all incidents. Notably, attacks on utilities, legal firms, and government agencies actually declined during the same period.
Snowflake Breach Hacker Pleads Guilty: 100 Million Records, Stale Passwords, and No MFA
Connor Riley Moucka, 26, pleaded guilty to computer fraud, wire fraud, and identity theft charges related to the 2024 breaches of Snowflake customer accounts, which compromised at least 165 organizations and exposed records of over 100 million people. The attacks required no sophisticated exploits — attackers simply used old credentials harvested years earlier by infostealer malware on accounts with no multi-factor authentication enabled. Moucka faces a mandatory two-year minimum plus up to 30 years on additional charges and is due to be sentenced on October 27, 2025.
3.8 Million Patient Records Exposed in Ohio Healthcare Software Breach
Ohio-based healthcare software company Unlimited Technology Systems (UTS) has confirmed a data breach affecting 3.8 million people, making it the largest healthcare breach reported to US regulators so far in 2026. Hackers accessed its systems between October 5–10, 2025, potentially stealing sensitive personal, medical, and insurance data, including Social Security numbers, diagnoses, and government ID scans. UTS has notified law enforcement, engaged a forensic security firm, and is offering affected individuals 24 months of credit monitoring and identity protection services.
River Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.
River Bank & Trust suffered a ransomware attack on June 16, in which hackers accessed portions of its network and exfiltrated data, prompting the company to take affected systems offline and disable compromised accounts. The bank engaged with the threat actors and obtained representations that the stolen data had been deleted, likely following a ransom payment. The investigation is ongoing, and River has yet to determine whether personal information was stolen or whether the incident will materially impact its business.
ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree Continues
The Police National Legal Database (PNLD) has confirmed a data breach in which cybercriminals stole names, organisations, and work email addresses belonging to police officers, criminal justice staff, government partners, and customers, with no evidence that passwords were compromised. The breach is linked to an extortion group called "ExfilSquad," which claims to have stolen a 1.9 GB dataset containing around 135,000 law enforcement contact records, and also claimed responsibility for a recent breach of the UK Department for Education affecting over 607,000 records. Key details — including how attackers gained access, the exact number of victims, and whether a ransom was demanded — have not yet been disclosed.
ShinyHunters Dumps 41GB of Brinks Home Data After Ransom Goes Unpaid
Brinks Home, a Dallas-based home security firm, has suffered a data breach carried out by the ShinyHunters extortion group, who claim to have stolen over 4.9 million records from the company's Salesforce instance. After Brinks Home refused to pay a ransom, the hackers leaked more than 41GB of files online, which allegedly include personally identifiable information (PII). The company has confirmed the breach but stated that its alarm monitoring and core security systems were not affected, and is working to identify impacted individuals.
American Bank Trusts Ransomware Gang's Pinky Promise to Delete Stolen Data
A US bank used the unusual term "removed" in its data breach disclosure, rather than the more common terms like "stolen," "copied," or "accessed." The wording implies the bank may be suggesting the ransomware group actually deleted the data rather than retaining it — essentially trusting the criminals' promise to dispose of it. The article highlights how the language used in breach disclosures is often carefully chosen, ranging from vague to misleading, to downplay the true nature of what occurred.
Upbound Group's Data Breach Cost It $13 Million in Fake Lease Agreements
Texas-based consumer finance company Upbound Group disclosed in an SEC filing that a recent data breach, in which hackers obtained non-sensitive customer information, was used to facilitate fraudulent lease-to-own agreements. The incident resulted in approximately $13 million in fraudulent contract losses within its Acima segment during the second quarter of 2026. The company has notified law enforcement, engaged external cybersecurity experts, and considers the breach non-material, though its investigation remains ongoing.
Anubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to Pay
The Anubis ransomware group has claimed responsibility for a cyberattack on Fairlife, a Coca-Cola subsidiary, which disrupted production and resulted in the theft of approximately 1 TB of confidential data. The group is threatening to leak the stolen data unless a ransom is paid within one week. Active since December 2024, Anubis employs a double-extortion model and has targeted roughly 100 organisations, and is also notable for a "wiper mode" feature that can permanently delete victims' files.
Clover Health Investments Hit by Social Engineering Attack, Patient Data Exposed
Clover Health Investments disclosed a data breach discovered on July 4, resulting from a social engineering attack that compromised three non-managerial employee accounts with access to personal and protected health information. The company activated its response plan, engaged third-party cybersecurity experts, and believes the attackers have been evicted, though the full scope of the breach remains undetermined. No threat actor or ransomware group has claimed responsibility for the incident.
Estée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack
Estée Lauder has begun notifying employees that their personal data was stolen from its Oracle E-Business Suite (EBS) system in August 2025, when the Cl0p cybercrime group exploited a zero-day vulnerability (CVE-2025-61882) enabling unauthenticated remote code execution. The compromised data includes sensitive information such as Social Security numbers, passport numbers, bank account details, health information, and payroll data. The company is offering affected individuals 24 months of free identity monitoring and has notified law enforcement, though it has not disclosed how many people were impacted.
Suno Data Breach Exposes 55 Million Users, Plus Some Awkward Scraping Receipts
AI music platform Suno suffered a significant data breach affecting over 55 million user accounts, exposing email addresses, phone numbers, and tens of thousands of Stripe payment records containing names, addresses, and partial credit card details. The individual claiming responsibility for the breach also released source code allegedly showing Suno scraping songs and lyrics from platforms like YouTube Music and Deezer to train its AI. The breach comes amid broader legal troubles for Suno, which is already facing a lawsuit from major record labels including Sony, UMG, and Warner over alleged unauthorised mass scraping of copyrighted music.
EY Breach Exposes Client Tax Data Including SSNs and Card Numbers
Ernst & Young (EY) has begun notifying clients of a data breach involving a third-party service management platform used for tax-related work, with hackers gaining access between March 28 and April 12 after the incident was discovered on April 23. The compromised data includes sensitive personal and financial information such as names, addresses, Social Security numbers, and credit/debit card numbers. EY states it is unaware of any misuse of the data and is offering affected clients two years of free credit monitoring and identity protection services.
23 Million Paidwork Users' Data Dumped Online After Alleged March Breach
A data breach at microtask platform Paidwork has exposed the personal and financial information of over 23 million users, with a stolen 11 GB database first advertised on a cybercrime forum in April and later added to Have I Been Pwned in July. The leaked data is extensive, including bank account numbers, passwords, addresses, transaction records, and more, with the breach traced back to an intrusion in March. Paidwork has yet to publicly acknowledge the incident or respond to press inquiries, leaving affected users advised to change passwords, monitor their finances, and watch for phishing attempts.
Nichirei Cyberattack Leaves Japan's Frozen Food Chain on Ice
Japanese frozen food giant Nichirei was hit by a cyberattack on July 13, forcing it to disconnect its systems and disrupting operations at its refrigerated warehouses and shipping divisions, with knock-on effects for restaurants, retailers, and delivery services. The company confirmed that hackers targeted its servers and that some affected systems contained personal information, prompting an initial report to Japan's Personal Information Protection Commission over a potential data leak. Nichirei announced it would begin gradually restoring operations but has withheld details of the attack, leaving it unclear whether a ransomware group was involved.
Accenture Breached: Hacker Claims 35GB Haul Including Source Code and Azure Keys
Accenture has confirmed a data breach after a hacker claimed on PwnForums to have stolen 35 gigabytes of data, including source code, Azure access keys, RSA/SSH keys, and configuration files from the company. Accenture stated the incident has been remediated and that there is no impact on its operations, though it provided few further details. Security experts warn the stolen data could be leveraged for future attacks, given Accenture's close proximity to major enterprise clients' systems and infrastructure.
ShinyHunters Breach Exposes Data of 3.8 Million Medtronic Patients
Medical technology company Medtronic suffered a data breach in April 2026 when the extortion group ShinyHunters accessed its corporate IT systems, compromising the personal and medical information of over 3.8 million individuals. Stolen data included names, contact details, dates of birth, Social Security numbers, and health-related information, though Medtronic states there is no evidence the data was publicly exposed. The company is offering affected individuals 24 months of free credit monitoring and identity theft protection services, and has implemented additional cybersecurity safeguards.
Small US County Paid $1 Million to Make Stolen Data Go Away. It Might Not Have.
A US county government, reportedly Union County, Ohio, paid a $1 million Bitcoin ransom to the Kairos cyber extortion group following a May 2025 brute-force attack in which over 2 terabytes of data were stolen. Negotiations began at $100,000 and ended at $1 million after the attackers imposed a hard deadline, with the group originally demanding $3 million. The breach ultimately affected over 45,000 individuals whose sensitive personal, financial, and medical information was compromised, though no file-encrypting ransomware was involved and there is no independent verification that the stolen data was actually deleted.
Medtronic Tells Patients Their Health Data May Have Walked Out the Door in April Breach
Medtronic is notifying patients that their personal and health data — including names, Social Security numbers, and medical information — may have been stolen during a cyberattack in which unauthorised actors accessed its corporate systems for nearly a week in April. The extortion group ShinyHunters claimed responsibility, alleging it stole over nine million records and demanding a ransom, though Medtronic has not publicly attributed the attack or confirmed whether data was actually exfiltrated. The company states that no medical devices were affected and is offering impacted individuals two years of complimentary credit and identity monitoring services.
One Leaked GitHub Token, 1.3TB Gone: The Novo Nordisk Breach Is a Wake-Up Call for Dev Security
Danish pharmaceutical giant Novo Nordisk suffered a major breach after attackers gained initial access through a single exposed GitHub personal access token, enabling them to clone private repositories, harvest additional credentials, and move laterally through the network for over two months. The threat group FulcrumSec claims to have exfiltrated approximately 1.3TB of data — including source code, proprietary drug research, clinical trial data, and internal AI models — before demanding a $25 million ransom, suggesting the breach was far more extensive than Novo Nordisk has publicly acknowledged. Security experts warn the incident highlights a broader industry failure to treat developer environments and secrets management as identity security problems, noting that machine credentials like API tokens are often poorly monitored, broadly privileged, and rarely rotated, making a single exposed token enough to trigger a catastrophic breach.
Dutch Police Nab Suspect Who Repeatedly Hacked Ajax Amsterdam's IT Systems
Dutch police arrested a 35-year-old man from Buren on suspicion of repeatedly hacking into Ajax Amsterdam's computer systems in early 2026. The attacker exploited vulnerabilities in the club's IT infrastructure to access data on hundreds of individuals, modify stadium bans, and potentially manipulate over 42,000 season tickets and 300,000 fan accounts. Ajax has since patched the vulnerabilities and notified the Dutch Data Protection Authority and police.
Myspace93 Breach: 46,000 Plaintext Passwords Finally Surface, Five Years Late
In January 2021, Myspace93 — a parody site mimicking the old social network — suffered a breach in which trusted members of a Discord community exploited beta app access to steal server files, including an unencrypted store containing the plaintext usernames, passwords, email addresses, and IP addresses of over 46,000 users. The site's co-creator, known as jankenpopp, blamed the betrayal on individuals he considered close collaborators, who concealed the theft and shared stolen data and download tools among themselves. The breach has only recently been highlighted after HaveIBeenPwned ingested the data more than five years later, and affected users are advised to change any reused passwords and enable two-factor authentication.
Shadow AI Is the Insider Threat Nobody's Watching
Verizon's 2026 Data Breach Investigations Report reveals a fourfold increase in "shadow AI" use, with 67% of employees who regularly use AI at work doing so through unauthorized personal accounts, potentially exposing sensitive corporate data such as source code, documents, and proprietary research to unvetted third-party platforms. The report also highlights worsening vulnerability management, with remediation rates for critical flaws dropping from 38% to 26% and resolution times rising from 32 to 43 days, while ransomware featured in nearly half of all breaches. On a positive note, ransom payments continued to decline, with 69% of victims refusing to pay and the median payment falling slightly to just under $140,000.

Grafana Labs Got Its GitHub Raided. It's Not Paying Up.
Grafana Labs has disclosed that an unauthorized attacker obtained a token to access its GitHub environment and stole its codebase, subsequently threatening to release the code unless a ransom was paid. The company refused to pay, citing FBI guidance and the fact that no customer data or operational systems were affected. The incident's impact may be limited, as much of Grafana's code is already open source, though it remains unclear exactly what proprietary code was taken.