< ciso
brief />
Tag Banner

All news with #data breach tag

935 articles · page 11 of 47

SoFi Hong Kong confirms third-party data breach

🔒 SoFi Hong Kong reported a third-party data breach after detecting unauthorized access to a vendor-hosted database on April 30, 2026. The company engaged a third-party cybersecurity firm and is investigating while notifying affected customers. SoFi has not disclosed the vendor identity, the number of impacted customers, or the exact data exposed. Customers were advised to monitor accounts, enable two-factor authentication, and take extra precautions.
read more →

Weekly cyber recap: supply chain worm and hacks

⚠️ Last week saw a range of high-impact incidents, from the Miasma worm compromising 73 Microsoft GitHub repositories to targeted mailbox espionage and an Instagram account compromise via an AI support tool. Vendors patched active Android flaws, researchers flagged malicious npm packages and a compromised Hola Browser installer, and U.S. agencies disrupted transnational investment fraud. Multiple threat clusters, including China-linked espionage groups and financially motivated actors, broadened their geographic scope and tactics, while many critical CVEs remain urgent for defenders to patch.
read more →

Oxford University reports CareerConnect credential breach

🔒 Oxford University disclosed a data breach after its third-party provider, Group GTI, reported that the CareerConnect platform was compromised on May 28. The attackers accessed users' first and last names, email addresses, and encrypted passwords for accounts not using Single Sign-On; GTI has invalidated those passwords and will require resets. The university said no course materials, uploaded files, appointments, or financial data appear affected, but warned users to watch for phishing attempts.
read more →

Meta: 20,225 Instagram Accounts Exposed by Bug

🔒 Meta disclosed that a bug in its AI-powered High Touch Support (HTS) tool allowed attackers to request password reset links to email addresses not associated with targeted Instagram accounts, enabling unauthorized access where two-factor authentication was not enabled. The issue was discovered on May 31, affecting 20,225 users and exposing contact details, profile data, posts, messages and activity history. Meta disabled the HTS tool, invalidated reset links, enforced mandatory security checkpoints on impacted accounts, and instructed users to reset passwords and enable 2FA while it reviews recovery flows.
read more →

Miasma worm compromises 73 Microsoft GitHub repos

🛡️ Microsoft's GitHub organizations — including Azure, Azure-Samples, Microsoft, and MicrosoftDocs — were hit by the self-replicating Miasma supply chain campaign that affected 73 repositories, prompting GitHub to disable access. The incident notably re-compromised the durabletask package previously infected by TeamPCP, suggesting lingering credential exposure. Miasma, a variant of the Mini Shai-Hulud worm, has mutated rapidly and pushed malicious payloads both to registries and directly to GitHub source repos, leveraging AI coding tools and developer workflows to execute payloads. Security firms warn the campaign exploits trust in maintainers and signing rather than platform vulnerabilities, allowing widespread propagation across the open-source ecosystem.
read more →

Suspicious polyfill login prompts hit major Japanese sites

🔐 Toshiba and Muji warned visitors about unexpected sign-in pop-ups generated by the external service polyfill.io, advising users to cancel and change passwords if they entered credentials. The prompts were caused by remnants of a 2024 incident when the polyfill domain served malicious scripts after changing hands; the domain began responding again in late May 2026 with HTTP 401 requests. Both companies suspended the service and removed the offending code, and other Japanese sites were also affected.
read more →

DentaQuest breach exposed data of 2.6 million accounts

🔒 DentaQuest, a major US dental benefits administrator, disclosed a cybersecurity incident after the extortion group ShinyHunters posted and later leaked over 234 GB of stolen data. The company confirmed limited disruption to services on June 2 and said it engaged external experts to investigate and contain the breach. Analysis by Have I Been Pwned found records for 2.6 million accounts in the leaked dataset, including emails, names, phone numbers, government IDs, insurance details, genders, and dates of birth.
read more →

WFP registration breach exposes Gaza household data

⚠️ The United Nations World Food Programme (WFP) confirmed a breach of its Palestine self-registration application (SRA) that exposed beneficiaries' personal data across the Gaza Strip, including names, ID numbers, phone numbers, and neighborhood locations. The SRA has been temporarily suspended while WFP implements urgent security improvements and investigates the incident. The organization warned recipients to be cautious of impersonation or phishing attempts and said assistance programs will continue as normal for registered beneficiaries.
read more →

Lessons from the Canvas LMS cyberattack

🔒 Over May 6–7, 2026, Canvas LMS users encountered a defaced login page claiming a ShinyHunters extortion of Instructure, alleging theft of 3.65TB of data affecting about 275 million students, faculty, and staff across nearly 9,000 institutions. Instructure identified an exploited support-ticket vulnerability in its Free for Teacher environment and temporarily disabled that service while investigating. The incident disrupted finals and highlighted risks from centralized SaaS platforms, third-party dependencies, communications breakdowns and the evolving economics of extortion.
read more →

Dashlane reports brute-force compromise of few vaults

🔐 Dashlane disclosed a brute-force attack on May 31, 2026, targeting certain personal accounts to bypass two-factor authentication and register new devices. Its security controls triggered temporary suspensions and authentication issues, and although access has been restored, attackers succeeded in downloading encrypted vaults for fewer than 20 personal-plan users. Dashlane stressed that vault contents remain protected by each user's Master Password and that its internal systems were unaffected.
read more →

The Great Messaging Heist: Organized Scam Ecosystem

📩 Kaspersky examines how everyday messaging channels like SMS, WhatsApp, and email are being exploited by organized scam cartels that use speed, familiarity, and AI to trick victims. The research shows average losses of $733 per victim, rapid attack timelines often under 30 minutes, and widespread emotional damage eroding trust in digital communications. The post highlights common schemes, platform distribution, and recommendations to protect yourself.
read more →

California AG Sues 23andMe Over 2023 Data Breach

🔒 Attorney General Rob Bonta has sued 23andMe (now Chrome Holding Co.) for failing to protect sensitive genetic and personal information after a 2023 breach exposed data of nearly 7 million customers, including 855,541 Californians. The suit alleges inadequate safeguards against credential-stuffing, missed detection opportunities, a coding error in the DNA Relatives feature, and misleading public statements about security. It seeks injunctions and statutory penalties under multiple California laws, including CCPA and the California Genetic Information Privacy Act.
read more →

Charter Communications breach exposes 4.9M accounts

🔒 The ShinyHunters extortion gang claims to have stolen personal details from 4.9 million Charter Communications accounts after a vishing attack in early April that compromised an employee's Microsoft Entra account. Charter confirmed the incident but says no sensitive PII or CPNI was exfiltrated, while Have I Been Pwned verified leaked records containing names, emails, addresses, phone numbers and some job titles. The group published stolen Salesforce data after a ransom was refused.
read more →

Dutch police arrest suspect in Ajax app hack

🔒 Dutch police arrested a 35-year-old suspect in Buren for allegedly accessing Ajax football club IT systems, after vulnerabilities in the official Ajax app exposed supporter data. The breach, initially described as affecting a few hundred fans, may have put around 300,000 registered supporters at risk, including email addresses and ticket information. The flaw also allowed manipulation of the club's ban list, potentially harming innocent people, and Ajax says it has patched the vulnerabilities with external help.
read more →

MyPillow and Play gang dispute over alleged breach

🛏️ The Play ransomware group claims to have stolen confidential MyPillow data and threatened a public dump, while CEO Mike Lindell denies any breach and calls the allegations politically motivated. Lindell says MyPillow stores no sensitive data internally and has received no ransom demands, attributing data handling to third parties. The Play group's leak portal set a deadline for release, leaving the truth pending until the deadline passes. The article warns that third-party handling of data still exposes organisations and individuals to meaningful risk.
read more →

Romanian sentenced for hacking Oregon government network

🔒 A Romanian national was sentenced to 56 months in federal prison after pleading guilty to aggravated identity theft and unauthorized access to an Oregon state government computer network. The 46-year-old, known online as "inthematrixl," also sold access and stolen personal data from other U.S. victims, causing at least $250,000 in losses. Authorities coordinated internationally to arrest and extradite him, and the court ordered forfeiture of cryptocurrency and supervised release.
read more →

Carnival Cruise Confirms Breach Impacting Millions

🛳️ Carnival Corporation confirmed a data breach affecting nearly 6 million customers after attackers used social engineering to access an employee account on April 10, 2026. The company began notifying 5,995,277 individuals and engaged third-party security experts while blocking the unauthorized activity. Analysis of leaked data indicates exposed names, dates of birth, emails, genders, locations, and loyalty program details tied to Holland America’s Mariner Society.
read more →

Grandoreiro and BTMOB campaigns target Latin Europe

🛡️ WatchGuard and ESET report two active campaigns spreading Windows and Android banking trojans across Latin America and Europe. The Grandoreiro campaign leverages DLL side-loading, WebRTC/STUN/ICE communications, and phishing to target Portuguese banks and international financial services. ESET details BTMOB, a rapidly evolving Android RAT sold as a service with an APK builder that enables mass phishing-based distribution and remote device control.
read more →

Dutch police arrest suspect in Ajax football hack

🔒 The Dutch National Police arrested a 35-year-old man from Buren suspected of multiple unlawful intrusions into AFC Ajax's computer systems earlier this year. The intrusions allowed access to data belonging to a few hundred individuals, modification of fewer than 20 stadium bans, and reassignment of purchased tickets. Ajax patched the exploited vulnerabilities, reported the breach to the Dutch Data Protection Authority and police, and the investigation remains ongoing.
read more →

Charter Confirms Breach After ShinyHunters Extortion

🔒 Charter Communications confirmed a data breach after the ShinyHunters extortion group claimed to have stolen millions of customer records. The company says it is notifying authorities and maintains that No sensitive personal information (PI) or CPNI was exfiltrated. ShinyHunters alleges the intrusion began via a vishing attack that compromised an employee's Microsoft Entra account and allowed access to Salesforce data.
read more →