< ciso
brief />
Tag Banner

All news with #data breach tag

849 articles

TikTok to Pay $400M in U.S. Child Privacy Settlement

📰 The U.S. Department of Justice announced that ByteDance-owned TikTok agreed to pay $400 million to resolve a 2024 lawsuit alleging violations of child privacy laws. The settlement includes $300 million payable immediately and $100 million contingent on vacating a prior consent decree tied to Musical.ly. The complaint, filed with the FTC, accused TikTok of enabling under-13 accounts and improperly collecting data in "Kids Mode," claims the company has disputed as largely tied to past practices. The DoJ called the recovery among the largest under COPPA and noted TikTok has since strengthened age controls and parental oversight.
read more →

Sakura Internet breach exposes up to 1.36M accounts

🔒 Japanese cloud provider Sakura Internet disclosed unauthorized access to its sales management system storing customer contract and membership data. The company said the incident was discovered during a separate investigation into a smaller breach at its Sakura Rental Server service and that up to 1,360,563 accounts may have been affected. Sakura reported no confirmed data exfiltration, noted stored passwords are hashed and no credit card data is kept in the compromised system, and is notifying affected customers and authorities.
read more →

CareCloud data breach impacts 3.7M patients

🩺 CareCloud, a U.S. healthcare IT provider, disclosed a March breach that disrupted services and exposed patient data. The company said an unauthorized third party accessed an AWS environment between March 10 and March 16, 2026, and claimed to have exfiltrated database contents. Notifications began July 25, and impacted individuals are offered identity protection via IDX. No group has claimed responsibility and investigations continue.
read more →

US Charges Iranian Hackers in Massive IP Theft Case

🛡️ The U.S. Justice Department charged eight additional alleged members of the Mabna Institute, bringing the total to 17 Iranians accused of a years-long campaign that stole academic research, intellectual property, emails, and proprietary data from U.S. and international organizations. The DoJ says the operation began around 2013 and compromised roughly 8,000 accounts—targeting over 100,000 professors worldwide—and extracted about 31.5 TB of data valued at $3.4 billion. Rewards of up to $10 million are offered for information on five defendants, and the defendants face multiple charges including conspiracy and aggravated identity theft.
read more →

UT San Antonio IT Systems Taken Offline After Incident

🔒 The University of Texas San Antonio took several IT systems offline after detecting attempted unauthorized activity at the network edge, prompting containment measures by University Technology Solutions and partners. Officials say there is no evidence of data access or exfiltration so far, though the outage disrupted online registration, tuition payments and phone systems ahead of term start. Students were granted extensions and instructed to reset passphrases as remediation steps continue.
read more →

SafePal order-tracking flaw exposed customer data

🔒 SafePal disclosed an authorization flaw in an order-tracking plug-in that exposed names, emails, shipping addresses, phone numbers, and purchase details for about 39,798 customers. The company said no wallet credentials or payment card data were included and that affected customers were notified on August 16. SafePal fixed the flaw, reduced retention, purged affected records from active servers, and engaged an independent firm to validate fixes and review systems.
read more →

Threat actor claims Azure employee data from firms

🛡️ A threat actor using the alias “TheHatman” is advertising employee databases allegedly exfiltrated from Microsoft Azure tenants of multiple large companies, claiming a total of 3.64 million records. The posted dumps, beginning July 31, target organizations such as McDonald’s, Tata Consultancy Services, Gap Inc., Vodafone, HCL, IHG, and Kyndryl and include names, emails, titles, phone numbers, addresses, and tenant account details. Several affected firms say investigations show no evidence of current breaches and that much of the data appears dated and non-sensitive, while cyber intelligence firm Hudson Rock assessed the samples as authentic and noted presence of service and admin accounts that could enable targeted attacks.
read more →

Pokémon Center breach exposes customer data, cancels orders

📣 Pokémon Center has notified UK and German customers that a third-party logistics provider, CEVA Logistics, suffered a cyberattack that exposed customer personal and order information. The breach affected CEVA systems between July 29 and August 1 and disrupted several European warehouses, causing shipping delays and cancellations. Pokémon Center says exposed data may include names, mailing addresses, phone numbers, email addresses, and order details, but not payment card information.
read more →

SafePal data breach exposes nearly 40,000 orders

🔒 SafePal reports a data breach affecting about 39,798 customers after an authorization flaw in an order-tracking plug-in was exploited to steal order information. The exposed data includes names, emails, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. SafePal says sensitive wallet credentials, payment card numbers, and government IDs were not exposed and that it has fixed the vulnerability, notified affected customers, and launched a verification tool. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and the company warns of targeted phishing and social engineering attempts.
read more →

ExfilSquad leaks data from 13 organizations

🔍 New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more →

Shell Probes Possible Data Theft After Clop Claims

🔎 Shell is investigating a potential security incident after the Clop ransomware gang claimed to have stolen 89GB of data, including engineering drawings and project plans. A Shell spokesperson confirmed awareness and said security teams and external experts are examining the matter. Clop listed Shell among 43 victims allegedly targeted via a PTC Windchill and FlexPLM vulnerability tracked as CVE-2026-12569. PTC, CISA, and other authorities have warned of active exploitation and urged urgent patching and mitigations.
read more →

RingCentral Breach Exposes Millions of Account Records

🔒 In July 2026, the ShinyHunters extortion group claimed to have stolen personal data from RingCentral accounts after a reported social engineering intrusion. RingCentral acknowledged a security incident and said remediation steps were taken, noting services continued to operate and only a portion of customers were affected. Have I Been Pwned confirmed leaked data tied to 1.6 million accounts, including names, emails, phone numbers, and addresses.
read more →

Data analyst jailed for $2.5M extortion scheme

🛡️ A former Brightly Software contractor was sentenced to two years in prison after pleading guilty to orchestrating a $2.5 million extortion scheme. He stole payroll and corporate data, emailed employees threatening to leak PII, and demanded ransom in cryptocurrency after his contract ended. Brightly paid a small Bitcoin ransom before involving law enforcement; the FBI recovered devices linking the suspect to the crimes.
read more →

Compromised AWS Key Exposes Data of UK Charities

🔒 Beacon attributes a cyber-attack to a compromised AWS access key likely exposed in public Javascript build artifacts, allowing an attacker to download CRM data belonging to about 1,500 UK charities. The incident, identified in activity starting on July 27, saw data decrypted during download despite being encrypted at rest. Beacon has reset credentials, found no evidence of persistence, and instructed customers to report the breach to the ICO. Affected charities have been notified, and there is no confirmation that stolen data has been published or misused.
read more →

Trezor reports customer data breach via ShipMonk hack

📢 Trezor disclosed a data breach after its shipping partner ShipMonk was hacked, exposing nearly 14,000 customers' order details. The exposed data includes full names, shipping addresses, email addresses, and phone numbers for customers who received orders between May 10 and August 8, 2026. Trezor confirmed its systems and devices were not compromised but warned affected customers to expect heightened phishing attempts. ShipMonk attributed the intrusion to a Metabase zero-day vulnerability that allowed attackers to access stored customer data.
read more →

ICO reprimands ACRO after significant data breach

🔒 The UK's Information Commissioner’s Office (ICO) has issued a reprimand to the Criminal Records Office (ACRO) after a 2023 breach affected 10,920 people. A hacker accessed ACRO’s website and Kentico CMS between August 2022 and March 2023, exposing highly sensitive personal and criminal data. The ICO found failings in patch management and security monitoring, noting unreviewed malware alerts and unclear patch responsibilities. ACRO has taken remedial steps including decommissioning compromised infrastructure and improving monitoring.
read more →

Wesco Investigates CRM Data Exfiltration Claim

🔍 Wesco is investigating a reported cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen CRM data and published alleged records. The company says it worked with its cloud CRM vendor and found no evidence of ransomware or malware, and believes payment card and sensitive customer or employee data are not at risk. Wesco reported no business disruption and stated operations continue as normal.
read more →

Data Breach Impacts Ceva Logistics Supply Chain

🛡️ Ceva Logistics, part of CMA CGM Group, reported a breach affecting its European contract logistics operations, impacting eight warehouses. The company notified affected customers on August 1 after an incident that reportedly ran from July 29 to August 1. Client data potentially exposed included names, emails, addresses, phone numbers and order details, affecting customers such as Valve, Bol, De Bijenkorf, Ajax and ING. Vendors warn of follow-on phishing and impersonation risks and stress logistics firms are high-value attack targets.
read more →

One-click prompt injection exposed Atlassian Rovo data

🛡️ Researchers at DEF CON 34 demonstrated a one-click prompt-injection attack called “RovoBlast” that abused Atlassian’s enterprise AI assistant Rovo by injecting malicious instructions via the rovoChatPrompt parameter. The exploit allowed a single click to make Rovo accept attacker-supplied parameters in a user session, potentially exposing data across connected services like Slack, Microsoft 365, Google Workspace, Jira, and Confluence. Varonis reported the issue through Bugcrowd and Atlassian has issued a fix, while researchers urged limiting Rovo’s access and disabling unneeded automation.
read more →

Valve notifies Steam hardware customers of breach

🔔 Valve is informing Steam hardware customers in Europe that a breach at shipping partner CEVA Logistics exposed delivery-related data. The company says attackers accessed CEVA systems between July 29 and August 1, 2026, and likely obtained names, addresses, phone numbers, emails, and order details. Valve clarified that payment, passwords, and Steam Guard codes were not exposed and warned customers to watch for phishing attempts using the stolen information.
read more →