< ciso
brief />
Tag Banner

All news with #breach tag

222 articles · page 4 of 12

Booking.com Data Breach Prompts Reservation PIN Resets

🔒 Booking.com confirmed that unauthorized parties accessed booking information associated with some reservations. The company says it immediately forced PIN resets for affected current and past bookings and directly emailed impacted users with updated reservation PINs and guidance. Compromised fields may include full names, email and postal addresses, phone numbers, and communications with property providers. Booking.com warned customers to be vigilant for phishing and noted that app notifications were not sent, which has caused confusion.
read more →

Dutch EHR Vendor ChipSoft Disrupts Services After Ransomware

🔒 Dutch healthcare software vendor ChipSoft has confirmed a ransomware incident that forced it to take its website and patient-facing digital services offline. The provider of the HiX EHR platform warned of "possible unauthorized access" and advised customers to disconnect affected systems while it investigates. The national healthcare CERT, Z-CERT, is coordinating response efforts with ChipSoft and impacted hospitals.
read more →

Eurail Data Breach Exposes Personal Details of 308,777

🚆 Eurail says attackers stole personal information for over 300,000 customers after an unauthorized transfer of files from its network on December 26, 2025. The company disclosed the incident publicly in February and notified affected individuals by letter on March 27, reporting that records contained names, passport numbers and other sensitive identifiers. A sample of the stolen data was posted on Telegram and put up for sale on the dark web; Eurail advises customers to update Rail Planner passwords, reset reused passwords elsewhere, monitor bank accounts, and watch for phishing and suspicious transactions.
read more →

Drift $280M Crypto Heist Tied to Six-Month In-Person Plot

🔒 Drift Protocol says a coordinated, six-month operation led to a $280M+ theft after attackers built "a functioning operational presence" inside the platform and engaged contributors in person and via Telegram. The attackers reportedly hijacked Security Council administrative powers and drained assets in about 12 minutes. Drift suspects two contributors were compromised via a malicious code repository (possible VSCode/Cursor exploit) and a fake TestFlight wallet app. Blockchain firms attribute the campaign to UNC4736, linked to North Korea.
read more →

Stryker Fully Operational After Large Data‑Wiping Attack

🔐 Stryker says it is fully operational three weeks after a March 11 cyberattack in which the Handala group claimed to have stolen roughly 50 TB of data and wiped nearly 80,000 devices. Investigators say attackers created a new Global Administrator account after compromising a Windows domain admin and used a malicious file to conceal activity. Stryker prioritized restoring systems for ordering, shipping and production and is working with third‑party cybersecurity experts and government agencies as the investigation continues.
read more →

Maryland Man Charged Over $53M Uranium Finance Crypto Hack

🚨 A Maryland man has been charged with stealing more than $53 million after allegedly exploiting flaws in smart contract code on the Uranium Finance decentralized exchange in April 2021. Prosecutors say two separate attacks targeted liquidity pools, including manipulation of a rewards calculation and a transaction verification bug that enabled massive withdrawals while depositing almost nothing. Authorities allege the proceeds were laundered through decentralized exchanges and Tornado Cash, with roughly $31m in crypto and collectibles seized.
read more →

Iran-Linked Hackers Breach FBI Director's Email Inbox

⚠️ The FBI confirmed that Iran-linked hackers accessed the personal email account of FBI Director Kash Patel and published private photos and what appears to be his CV. The pro-Iranian hacktivist group Handala posted a selection of personal and work correspondence, with reporters verifying some items from Patel's Gmail account. The FBI said no classified or government systems were compromised and has taken steps to mitigate risks; strong, unique passwords and multi-factor authentication are advised.
read more →

Severe Cyberattack on Die Linke; Qilin Likely Culprit

🔐 Die Linke says it was hit by a serious cyberattack that it attributes to the hacker group Qilin, possibly Russian‑speaking, and has taken parts of its IT infrastructure offline. Party federal secretary Janis Ehling said attackers appear to be seeking sensitive internal and employee data; the membership database was not compromised. Authorities warned the party as the intrusion was detected, and a criminal complaint has been filed as the party coordinates with security services.
read more →

TeamPCP Expands Supply-Chain Attacks via PyPI LiteLLM

📦 The widely used Python package LiteLLM on PyPI was found to contain credential-stealing malware in versions 1.82.7 and 1.82.8, uploaded on 24 March 2026. Security researchers report the malicious code harvested SSH keys, cloud credentials, Kubernetes secrets, database credentials, TLS keys and cryptocurrency wallets, then encrypted and exfiltrated the data to attacker infrastructure and installed persistent backdoors. Endor Labs and JFrog analysis showed the later variant executed whenever any Python process started, enabling silent background operation; version 1.82.6 is the last known clean release and organizations are urged to rotate secrets and audit systems for compromise.
read more →

Musician Pleads Guilty in $10M AI-Powered Streaming Fraud

🎵 North Carolina musician Michael Smith pleaded guilty to running a multi-year streaming fraud that generated over $10 million in illicit royalties. Smith purchased hundreds of thousands of AI-generated songs and uploaded them to Spotify, Apple Music, Amazon Music, and YouTube Music, then used automated bots routed through VPNs to create billions of fake streams between 2017 and 2024. Prosecutors say he ran more than 1,000 bot accounts, agreed to $8,091,843.64 in forfeiture, and faces up to five years in prison after pleading to one count of conspiracy to commit wire fraud.
read more →

Data Analyst Guilty of $2.5M Extortion Against Brightly

🔒 A North Carolina contractor, 27-year-old Cameron Curry (aka "Loot"), was convicted for extorting his employer, Brightly Software, after stealing payroll and corporate data during a six-month contract that ran through December 2023. Curry sent more than 60 threatening emails from lootsoftware@outlook.com demanding $2.5 million and attached screenshots of employee PII. Brightly paid $7,540 in Bitcoin, the FBI seized devices following a January 24, 2024 search, and Curry now faces up to 12 years in prison.
read more →

Aura Confirms Data Breach Exposing 900,000 Contacts

🔒 Aura confirmed an unauthorized party accessed nearly 900,000 records containing names and email addresses after a voice‑phishing attack targeted an employee. The company says the data came from an inherited marketing tool tied to a 2021 acquisition and affected roughly 20,000 current and 15,000 former customers, while noting Social Security numbers, account passwords, and financial data were not exposed. Have I Been Pwned added the leak to its database and observed customer service comments and IP addresses among the files. Aura is conducting an internal review with external experts, has notified law enforcement, and plans to send personalized notifications to affected individuals.
read more →

FBI Seeks Help from Gamers Over Steam Malware Campaign

🕵️ The FBI’s Seattle Division is asking gamers who unintentionally downloaded malware via the Steam platform to assist an ongoing investigation into a campaign active between May 2024 and January 2026. Investigators say several titles — including BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, and Tokenova — have been identified as distribution points and are requesting affected users complete a short questionnaire. The FBI is collecting information on pre- and post-download communications, financial losses, and crypto wallet or bank account details; responses are voluntary, may result in follow-up contact, and victims’ identities will be kept confidential.
read more →

Poland's Nuclear Research Centre Foils Cyberattack

🛡️ Poland’s National Centre for Nuclear Research (NCBJ) says its IT infrastructure was targeted by a cyberattack that was detected and blocked before causing any impact. Security systems and internal procedures enabled rapid containment, and the institute reports that the MARIA research reactor was unaffected and continues to operate safely. Authorities have been notified and an investigation is underway.
read more →

Starbucks Discloses Data Breach Affecting Employees

🔒 Starbucks disclosed a data breach that exposed personal and financial information from Starbucks Partner Central accounts belonging to employees. The company says it discovered unauthorized access on February 6 after threat actors obtained login credentials via websites impersonating Partner Central, compromising 889 accounts. Exposed data may include names, Social Security numbers, dates of birth, and bank account/routing numbers. Starbucks notified law enforcement and is providing two years of Experian identity and credit monitoring to affected partners.
read more →

Telus Digital Suffers Massive Data Breach by ShinyHunters

🔒 Telus Digital, a BPO provider to global clients, is investigating a significant cybersecurity incident after extortion group ShinyHunters claimed to have exfiltrated up to one petabyte of data. The company says core operations and customer connectivity remain unaffected and that it has engaged leading forensics teams and law enforcement. Early indications point to abuse of legitimate access rather than an obvious malware intrusion, and Telus is notifying affected customers and implementing additional safeguards.
read more →

Loblaw Notifies Customers After Network Data Breach

🔒 Loblaw Companies Limited has detected an intrusion into a contained, non-critical portion of its IT network and confirmed that a criminal third party accessed basic customer information. The exposed data includes names, phone numbers, and email addresses, which could be used for phishing and fraud. Loblaw says there is no evidence that financial information, health data, or account passwords were compromised and that PC Financial has not been impacted. The company has automatically logged customers out, urges users to sign in again and change passwords, and continues to investigate.
read more →

England Hockey Probes Alleged AiLock Ransomware Breach

🔒 England Hockey is investigating claims that the AiLock ransomware gang stole approximately 129GB of data and listed the organization on its leak site, threatening to publish files unless a ransom is paid. The governing body says it has prioritized an inquiry involving internal teams, external specialists, and cooperation with law enforcement. England Hockey cannot yet provide specifics while the investigation continues and urges members to remain vigilant for phishing and suspicious account activity.
read more →

Service-Provider Breach Exposes Data of 15,661 Ericsson

🔒 Ericsson Inc. disclosed a data breach impacting 15,661 employees and customers after a third-party service provider detected suspicious activity and identified possible unauthorized access to stored files. Investigators say files may have been accessed between April 17 and April 22, 2025, and the incident was detected on April 28, 2025; a detailed review completed on February 23 confirmed exposure of personal information. The types of data potentially exposed include names, addresses, Social Security numbers, driver’s licence or government ID numbers, financial and medical information. Ericsson notified the FBI, filed state breach notices, did not name the vendor, and is offering complimentary identity protection services through IDX to affected individuals.
read more →

Ericsson US Reports Data Breach via Service Provider

🔒 Ericsson Inc.'s U.S. subsidiary disclosed that attackers stole personal data for an undisclosed number of employees and customers after a breach at a third‑party service provider detected on April 28, 2025. The provider's investigation found files were accessed between April 17 and April 22, 2025, and a review completed on February 23, 2026 identified exposed personal information. Ericsson says it has not seen evidence of misuse and is offering free IDX identity protection and monitoring to affected individuals, with enrollment open through June 9, 2026.
read more →