< ciso
brief />
Tag Banner

All news with #data breach tag

935 articles · page 10 of 47

Telegram admits limits detecting exam leak channels

📄 India's government told the Delhi High Court that it warned Telegram roughly two weeks before blocking the app amid allegations channels were selling leaked NEET-UG 2026 exam papers. The Ministry of Electronics and Information Technology and the National Testing Agency identified groups, channels and bots circulating stolen material and reported them to Telegram. The affidavit says Telegram acknowledged limited proactive detection and relied on reported content, while India's block—initially framed as a measured step—remains in effect pending the court's ruling.
read more →

FortiBleed leak exposes Fortinet VPN credentials

🔒 A newly discovered data leak called FortiBleed appears to expose Fortinet and FortiGate VPN credentials for 73,932 firewall URLs worldwide. Researcher Bob Diachenko discovered a server containing usernames, emails, and plaintext passwords and linked the collection to a Russian-speaking multi-operator group that performed massive credential harvesting and cracking. Hudson Rock and other researchers validated the dataset, noting impacts across many industries and countries, and urged affected organizations to rotate credentials and enforce MFA.
read more →

Kodak confirms data breach amid ShinyHunters claim

🔒 Kodak has confirmed an investigation after an unauthorized third party gained temporary access to a limited amount of company data. The company engaged external cybersecurity experts and is working with law enforcement, asserting there is no threat to systems or operations. The ShinyHunters extortion group has claimed responsibility, alleging over 2.2 million records were stolen and threatening to leak the data.
read more →

iRhythm confirms patient data breach after extortion

🔒 iRhythm Holdings disclosed a data breach after threat actors accessed patient personal and health information stored on third-party business applications. The company detected the incident on June 10, 2026, after receiving a ransom demand the prior week and launched an investigation with external cybersecurity experts. iRhythm said the breach involved data exfiltration via social engineering but did not affect its clinical devices, manufacturing, or financial systems. The firm has not confirmed the exact number of affected individuals.
read more →

Council of Europe Probes ShinyHunters Breach Claims

🔎 The Council of Europe is investigating claims by the ShinyHunters extortion group that it exfiltrated hundreds of thousands of HR and payroll records. The organization, representing 46 member states, said it is assessing the situation and cannot provide further comment. ShinyHunters posted on a dark web leak site, threatening to publish alleged files containing extensive personal and financial data if demands are not met.
read more →

China-linked actors breach REDCap servers, steal research

🔒 Google Threat Intelligence Group attributes a long-running espionage campaign to UNC6508, a China-linked actor, which exploited exposed REDCap servers to deploy the custom Infinitered malware and exfiltrate sensitive medical research. The intrusion began in September 2023 and persisted through November 2025, with attackers harvesting credentials, maintaining persistent backdoors, and using enterprise email compliance rules to siphon data. Administrators are urged to update REDCap, enable MFA/2SV, and apply provided YARA rules and IoCs to detect infections.
read more →

Infinite Campus Salesforce Breach Exposes Staff Data

🔒 Infinite Campus disclosed a Salesforce data theft in March that exposed personal information for school staff across its K‑12 customer base. The attacker, linked to groups known for targeting Salesforce instances, allegedly leaked a 1.2GB archive. Have I Been Pwned found data from 137,100 accounts, including names, emails, job titles and contact details. Infinite Campus said most exposed items appear to be directory information commonly published by schools.
read more →

Maine takes breach reporting portal offline after hoax

🔒 The state of Maine has temporarily taken its public-facing breach reporting database offline after two fraudulent reports impersonating VRChat and Discord were published. The Attorney General's office removed the fake submissions and said it is reviewing procedures to reduce such abuse while keeping legitimate reporting available. Historic notifications can be requested via the consumer protection division.
read more →

Maine Shuts Public Breach Portal After Hoax Filings

🔒 Maine has taken its public data breach reporting portal offline after fraudulent disclosures impersonating Discord and VRChat were published. The Attorney General's Office confirmed the reports were hoaxes and removed them, stating there is no evidence of actual breaches by the named companies. Public access to the database is temporarily disabled while the office reviews procedures; companies may still submit notices but the public must request disclosures directly.
read more →

French government’s Tchap messaging breach disclosed

🔒 The French government’s secure messaging platform, Tchap, was breached after an intruder took over a user account, according to DINUM. The agency blocked the compromised access and is investigating the extent of exposed information. While encryption was not broken, public chat rooms are unencrypted and the intruder reportedly accessed thousands of messages and files. DINUM reminded users that public rooms are visible to any account and should not contain sensitive content.
read more →

Novo Nordisk discloses clinical trial data breach

🔒 Novo Nordisk disclosed an unauthorized access incident affecting internal IT systems and pseudonymized patient data from some clinical trials. The breach exposed trial participant IDs and health, biomarker, lifestyle, and demographic details, while the company says direct identifiers were not accessed. Healthcare professionals' contact details were also compromised, prompting warnings about phishing and impersonation risks. Novo Nordisk has isolated affected systems, engaged external cybersecurity experts, and is investigating the scope and impact.
read more →

French Tchap breach exposed over 73,000 public sector accounts

🔒 DINUM disclosed that a breach of the Tchap encrypted messaging platform impacted over 73,000 French public sector accounts after a compromised user account was used to access the service. The attacker accessed data shared in public chat rooms, which are not encrypted, potentially exposing names, email addresses, avatars, and affiliated organizations. Private conversations remain encrypted and protected, and the malicious account has been blocked while an investigation continues. A threat actor has claimed responsibility and released samples of stolen files.
read more →

Japanese energy firm loses drive with 10.9M accounts

🔒 Kyushu Electric Power disclosed a physical security incident after an external backup drive containing private data for up to 10.9 million accounts went missing from a server room cabinet. The company said the drive was used on April 27 due to storage capacity limits and was found absent on May 26 when staff returned. The lost data reportedly includes customer names, addresses, usage data, phone numbers, and retail provider names, but not bank or credit card details. Authorities and Japan’s privacy commission have been notified, and an investigation and individual notifications are underway.
read more →

ShinyHunters exploited Oracle PeopleSoft zero‑day

🔒 The ShinyHunters extortion group exploited an unpatched Oracle PeopleSoft remote code execution zero‑day (CVE-2026-35273) to compromise enterprise servers, steal data, and extort victims. Mandiant links the activity to UNC6240 and observed attacks from May 27 to June 9, before Oracle published its advisory on June 10. The flaw requires no authentication and exposes PeopleTools 8.61 and 8.62 installations with externally reachable Environment Management Hub endpoints. Universities were heavily targeted; mitigations focus on disabling or blocking PSEMHUB and hunting for post‑exploit indicators.
read more →

South Korea levies record fine after Coupang breach

🔒 The Personal Information Protection Commission (PIPC) fined e-commerce firm Coupang 624.6 billion won (~$409M) after a major data breach that exposed about 37.55 million people’s information. A subsidiary, Coupang Fulfillment Service, was also fined 248 million won for unlawful handling of personal and sensitive data. Investigators cited poor authentication key management, inadequate access controls, delayed breach disclosure, interference with the data protection officer’s independence, and obstruction of the probe.
read more →

Nottingham University student-records breach affects 454,600

🔒 The University of Nottingham confirmed a cyber incident that exposed a significant amount of student record data, affecting current students and alumni. The university reported the breach to the Information Commissioner's Office and Action Fraud and is working with the platform vendor on a forensic investigation. The ShinyHunters extortion group has claimed responsibility and posted an archive they say contains finance, payment, personal and academic data from multiple campuses.
read more →

ShinyHunters Target Oracle PeopleSoft Instances

🛡️ ShinyHunters are actively stealing data from Oracle PeopleSoft instances, claiming breaches across 300 instances at over 100 organizations. The actor says they used a mix of old and zero-day vulnerabilities in a "gadget chain," with many victims in the education sector. Exposed tooling, scripts, and IOCs were found in online directories, and impacted organizations are urged to check logs and begin incident response immediately.
read more →

ServiceNow flaw exploited to gain deeper access

🔒 ServiceNow disclosed a security incident after unidentified actors exploited a vulnerability to obtain unauthorized, deeper access to some customer instances. On June 5, 2026, the company applied a security update to hosted instances to restrict access to an endpoint so only authenticated users can reach it. ServiceNow detected anomalous activity and confirmed successful queries against instance tables for a subset of customers, who have been notified. The issue affects customers on the Australia platform release or those with specific pre-Australia configuration changes.
read more →

French government messaging platform breached by hijack

🔐 DINUM warned that a hijacked user account was used to breach Tchap, the French government's encrypted messaging platform. Developed with ANSSI in 2018 on the Matrix protocol, Tchap serves the French public sector and has grown rapidly since its mandated adoption in August 2025. DINUM and CNIL were alerted after ANSSI detected the intrusion and the compromised account was promptly blocked while investigations continue. A threat actor claimed responsibility and shared samples, alleging large-scale data and message exfiltration.
read more →

Stolen Healthcare Data Fuels Cybercrime Economy

🔍 TrendAI's year-long review of dark web forums, marketplaces, and ransomware leak sites reveals an organised underground market trading stolen healthcare data, system access, and extortion services. The study found ransomware-related data sales made up 36.3% of marketplace activity and highlights growing targeting of EHR/EMR vendors. Researchers warn that healthcare records are highly reusable and permanent, amplifying long-term risk to patients and providers.
read more →