< ciso
brief />
Tag Banner

All news with #data breach tag

934 articles · page 4 of 47

ShinyHunters claims Florida DMV data breach

🔒 ShinyHunters says it accessed the Florida Department of Highway Safety and Motor Vehicles' DAVID system and stole over 200,000 records, publishing a screenshot tied to Jeffrey Epstein as proof. The group set a September 11 deadline to negotiate before releasing additional data and claims to have exploited a password-reset weakness to compromise multiple DMV accounts. The alleged intrusion could expose sensitive personal identifiers that enable identity theft and fraud. While IDScan has confirmed a related Nexus ID-scan exposure, the Florida DMV has not publicly verified ShinyHunters' claim.
read more →

Trezor supply-chain breach expands affected customers

📣 Trezor has revealed that a supply-chain breach at shipping partner ShipMonk exposed additional customer order data, expanding the impacted cohort by 67,000 users. The company updated its notification after discovering records from November 2019 to August 2021 were included, revising earlier timelines and increasing the victim count significantly. Trezor warned of heightened phishing and fraud risks and said it is considering legal action while pushing for anonymized delivery options.
read more →

Mathspace data breach exposes over 1 million records

🔒 Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access and stealing personal information belonging to students, staff, and parents in Australia and New Zealand. The company confirmed the intrusion was first leveraged on August 10, with data downloaded on August 27 and a breach confirmed on September 3, 2026. Mathspace says 1,079,819 people were affected but asserts that no passwords, authentication tokens, SSO or API credentials, or academic records were exposed. The firm warned those affected to monitor for suspicious account activity and noted the incident is part of a wider series of Metabase compromises linked to threat actors like ShinyHunters.
read more →

Trezor Data Breach Now Affects 81,000 Customers

🚨 Trezor disclosed that an August data breach at its logistics partner ShipMonk has expanded to affect 81,000 customers after an additional 67,000 U.S. customers were found impacted. The exposed data includes full names, shipping addresses, email addresses, phone numbers, and order numbers for customers who ordered during specific periods between 2019 and 2026. Trezor confirmed its own systems and devices were not compromised and warned customers to expect increased phishing and fraud risk. The incident stems from a Metabase vulnerability and extortion attempts linked to the ShinyHunters gang.
read more →

Lenovo ID flaw let attackers access Dropbox accounts

🔒 Dropbox confirmed roughly 5,000 accounts were accessed in August after attackers abused a legacy Lenovo ID login integration. The issue involved Lenovo allowing new IDs to be registered with someone else's email without verifying inbox ownership, enabling sign-ins to linked Dropbox accounts without a Dropbox password. Dropbox and Lenovo say they collaborated to mitigate the risk, and Dropbox has revoked Lenovo-ID sessions and now requires Dropbox passwords and 2FA.
read more →

Class-action suits follow alleged IDScan.net mega-breach

🔍 Several class-action lawsuits have been filed against IDScan.net after reports of a potential large-scale leak of driver’s license and identity document data. The FBI is investigating following reporting that linked stolen records to a Russian forum listing called “Nexus.” Plaintiffs seek damages and improved security, while law firms are contacting potential victims and advising steps to determine exposure and preserve evidence.
read more →

JetBrains Cadence breach after TeamCity exploit

🔒 JetBrains warns Cadence users to immediately revoke and rotate all credentials after threat actors exploited a critical TeamCity vulnerability (CVE-2026-63077) to breach a Cadence server. The attackers accessed a 2024 backup and may have obtained email addresses, project source code, AWS IAM credentials, and S3-stored files. JetBrains invalidated Cadence plugin tokens and provided IOCs, urging review of connected systems and treating all executions as untrusted.
read more →

Trezor: ShipMonk breach exposed 67,000 US customers

📣 Trezor disclosed that 67,000 additional U.S. customers were impacted by a ShipMonk breach, exposing names, emails, phone numbers, shipping addresses, and order numbers from Nov 2019 to Aug 2021. The company emphasized that hardware wallet security was not affected and that it had repeatedly requested deletion of customer data. ShipMonk reportedly used a Metabase instance vulnerable to CVE-2026-72898, and the incident is tied to the ShinyHunters extortion gang.
read more →

Lawsuits Filed After IDScan Driver’s License Leak

🔎 Multiple lawsuits and investigations target identity verification vendor IDScan after a dark-web service reportedly advertised over 153 million driver’s license scans and millions of other documents. The leak was traced to IDScan by Brian Krebs, and the FBI’s New Orleans office is reported to be investigating. IDScan has not publicly commented, and affected businesses and consumers may face exposure; law firms are pursuing potential class actions.
read more →

FBI probes massive ID scan breach at IDscan.net

🔍 A large cache of 153 million digital driving-license scans and other ID documents was listed for sale on the dark web, traced to identity verification provider IDscan.net. The haul also included millions of ID cards, travel documents and medical cards, and affected high-profile individuals. IDscan.net has not issued a full public statement while an FBI investigation into the source of the images is underway, raising supply-chain security concerns for organizations that rely on third-party verification services.
read more →

Bidding over Spirit Airlines employee data continues

📰 A dispute over the sale of archived Spirit Airlines employee data persists months after the carrier sought bankruptcy protection. Reportedly including hundreds of millions of emails and chats, OneDrive and SharePoint items, and millions of recorded calls, the dataset has drawn competing bids from AI training firms and at least one major cloud company. Former employees and unions object, citing privacy and unpaid compensation concerns. Stakeholders are considering anonymization as a possible compromise.
read more →

French hospital fined €500k after data breach

🔒 France’s data protection authority (CNIL) fined Hôpital privé de la Loire €500,000 after a 2025 breach exposed sensitive records for 727,113 people, including 524,867 patients and 202,246 trusted third parties. The investigation found failures including lack of VPN/MFA for external users, weak access controls, and absent real-time monitoring, enabling extensive data exfiltration. The hospital informed affected patients but did not directly notify all third parties; a teen hacker claiming responsibility sold the data attempt reportedly failed.
read more →

ThreatsDay roundup: phishing kits, AI risks, breaches

🛡️ This ThreatsDay bulletin surveys recent campaigns exploiting trusted tools and social engineering, from Microsoft Teams vishing to resilient phishing-as-a-service kits. It highlights ransomware affiliate playbooks, signed-software sideloading, a large ID-theft marketplace, and supply-chain risks tied to llms.txt misconfigurations. The report also notes Dropbox disclosed ~5,000 account compromises linked to legacy Lenovo IDs.
read more →

Thomson Reuters C-Track Breach Affects Multiple Courts

🔒 Thomson Reuters disclosed that unauthorized access to its C-Track court case management platform occurred in March 2026, impacting courts across 11 U.S. states, the U.S. Virgin Islands, and Ontario. West Publishing detected the activity on June 30 and says some records may include names, SSNs, driver's license numbers, dates of birth, and medical or insurance details. Affected individuals are being offered credit monitoring services and vendor and court notices have been issued while investigations continue.
read more →

Thomson Reuters C‑Track Breach Impacts Courts in US and Canada

🔍 Thomson Reuters disclosed a cybersecurity incident affecting its C-Track court management software, detected on June 30, that resulted in unauthorized access to court records in Canada and multiple US jurisdictions. An investigation found files tied to three Ontario courts and appellate courts in 11 US states and the US Virgin Islands may have been exposed, potentially including names, identification numbers and medical information. Thomson Reuters and affected courts say some redacted or sealed content may be impacted; investigations continue and there is no evidence of financial systems being affected or misuse of the data to date.
read more →

FBI Probes Massive Nexus Identity Data Breach

🔍 The FBI is investigating a reported breach tied to a service called Nexus that allegedly exposed over 153 million driver’s licenses and other identity documents across the US and Canada. The trove was first reported by journalist Brian Krebs, who traced activity to identity verification provider IDScan.net, which is investigating. Security experts warn the breach could have long-lasting consequences because government IDs are immutable and widely used for verification.
read more →

Russian Extradition in Major Freelance Platform Malware Case

📰 A Russian national, Searzhudin Tamirlanovich Aktulaev, has been extradited to the US and appeared in federal court on charges alleging he helped distribute malware to roughly 80,000 users of a freelance employment platform between 2016 and 2017. The indictment accuses him and co-conspirators of using fake messaging accounts to send malicious Excel attachments that installed remote access trojans, harvesting credentials and PII to support fraud. He faces multiple charges including conspiracy, unauthorized access and aggravated identity theft and remains in federal custody pending further proceedings.
read more →

Nutex Health Discloses Patient Data Theft

🔒 Nutex Health reported unauthorized access to its servers that resulted in the exfiltration of sensitive patient, employee and business information, and the attacker has threatened to publish the data online. The company notified the SEC and is investigating the scope while preparing breach notifications for affected patients. Nutex says there has been no material operational or financial impact identified to date.
read more →

FulcrumSec Leak Claims Extensive Manchester Airport Data

🛡️ FulcrumSec has published approximately 549GB of alleged customer data stolen from MAG, the operator of Manchester, Stansted and East Midlands airports. The group says it gained access via Iterable admin keys exposed in frontend JavaScript on the airports’ root domains. The post claims nearly 8.7 million customer profiles, marketing events, purchase records and future bookings were exfiltrated, raising risks of phishing and physical targeting.
read more →

Aesto Health breach impacts over 9.5 million patients

🔒 Aesto Health disclosed a data breach affecting more than 9.5 million individuals after unauthorized access to a portion of its AWS infrastructure. The intrusion occurred in December 2025 and was confirmed on May 26, 2026, following a forensic investigation. Exposed data includes names, dates of birth, medical details, government IDs, and Social Security numbers; affected patients began receiving notification and credit monitoring offers in August.
read more →