< ciso
brief />
Tag Banner

All news with #data breach tag

934 articles · page 6 of 47

ICO reprimands ACRO after significant data breach

🔒 The UK's Information Commissioner’s Office (ICO) has issued a reprimand to the Criminal Records Office (ACRO) after a 2023 breach affected 10,920 people. A hacker accessed ACRO’s website and Kentico CMS between August 2022 and March 2023, exposing highly sensitive personal and criminal data. The ICO found failings in patch management and security monitoring, noting unreviewed malware alerts and unclear patch responsibilities. ACRO has taken remedial steps including decommissioning compromised infrastructure and improving monitoring.
read more →

Wesco Investigates CRM Data Exfiltration Claim

🔍 Wesco is investigating a reported cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen CRM data and published alleged records. The company says it worked with its cloud CRM vendor and found no evidence of ransomware or malware, and believes payment card and sensitive customer or employee data are not at risk. Wesco reported no business disruption and stated operations continue as normal.
read more →

Data Breach Impacts Ceva Logistics Supply Chain

🛡️ Ceva Logistics, part of CMA CGM Group, reported a breach affecting its European contract logistics operations, impacting eight warehouses. The company notified affected customers on August 1 after an incident that reportedly ran from July 29 to August 1. Client data potentially exposed included names, emails, addresses, phone numbers and order details, affecting customers such as Valve, Bol, De Bijenkorf, Ajax and ING. Vendors warn of follow-on phishing and impersonation risks and stress logistics firms are high-value attack targets.
read more →

One-click prompt injection exposed Atlassian Rovo data

🛡️ Researchers at DEF CON 34 demonstrated a one-click prompt-injection attack called “RovoBlast” that abused Atlassian’s enterprise AI assistant Rovo by injecting malicious instructions via the rovoChatPrompt parameter. The exploit allowed a single click to make Rovo accept attacker-supplied parameters in a user session, potentially exposing data across connected services like Slack, Microsoft 365, Google Workspace, Jira, and Confluence. Varonis reported the issue through Bugcrowd and Atlassian has issued a fix, while researchers urged limiting Rovo’s access and disabling unneeded automation.
read more →

Valve notifies Steam hardware customers of breach

🔔 Valve is informing Steam hardware customers in Europe that a breach at shipping partner CEVA Logistics exposed delivery-related data. The company says attackers accessed CEVA systems between July 29 and August 1, 2026, and likely obtained names, addresses, phone numbers, emails, and order details. Valve clarified that payment, passwords, and Steam Guard codes were not exposed and warned customers to watch for phishing attempts using the stolen information.
read more →

Metabase zero-day exploited; urgent patches advised

🔒 Metabase disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) affecting versions from x.58.0 through x.63.x that has been actively exploited in the wild. The flaw allows unauthenticated SQL injection into the application database, enabling attackers to gain administrator access, alter configurations, steal stored database credentials, and exfiltrate data. Metabase Cloud has been patched; self-hosted users must apply updates immediately or block the "/api/session/reset_password" endpoint as an interim mitigation.
read more →

Unlimited Technology Systems Exposes 3.8M Records

🛡️ Unlimited Technology Systems disclosed a data breach affecting 3,803,750 individuals after a server compromise in October 2025. The company, which provides financial and revenue cycle software to specialty healthcare providers, discovered unauthorized access between October 5 and October 10 and notified authorities and patients in July 2026. Affected data may include names, SSNs, dates of birth, contact details, scanned IDs, insurance information, medical records, and diagnosis details. Affected patients were offered identity monitoring through Kroll.
read more →

Levi Strauss reports corporate data theft after breach

🔒 Levi Strauss & Co. disclosed that attackers used social engineering on three employees to access company-issued machines and exfiltrate corporate data. The company says rapid response contained the intrusion and no consumer data was impacted, with no disruption to business operations. An investigation is ongoing and Levi’s will provide additional notifications as required; some reporting links the incident to voice-phishing campaigns.
read more →

Snowflake attacker pleads guilty in mass data hacks

🔒 A Canadian hacker has pleaded guilty to participating in a group that compromised logins and breached a US cloud data warehouse, impacting 165 organizations and resulting in theft of customer records and multimillion-dollar extortion. Identified as Connor Riley Moucka, he worked with two co-conspirators and is linked to intrusions affecting companies such as AT&T, Ticketmaster and Neiman Marcus. The coordinated investigation involved the FBI and international law enforcement partners and led to guilty pleas and arrests tied to the Snowflake-focused campaign.
read more →

Beacon CRM Breach Impacts Around 1,500 UK Charities

🔒 Around 1500 UK charities may have had personal data accessed after a cyber incident at CRM provider Beacon. The provider says customers should assume all stored data, including attachments, was likely downloaded and has notified all affected organisations. Beacon attributes the breach to a compromised access key, is working with external experts to investigate and has contained the incident, while advising charities on reporting and payment safety steps.
read more →

Rising Costs and AI Risks in Data Breaches

🔍 IBM’s 2026 Cost of a Data Breach report, from March 2025 to February 2026, finds the average breach cost rose to $6 million, with AI-enabled attacks comprising one in four incidents. The study of 600 organizations highlights that AI both increases attack speed and, when used defensively, can reduce costs by nearly $2 million. Key issues include poor access controls for AI models, compromised APIs and cloud misconfigurations, and long detection-to-containment times that inflate costs.
read more →

Canadian Hacker Pleads Guilty in Snowflake Extortion Case

🛡️ Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to computer fraud and conspiracy for hacking and extorting more than 165 Snowflake customers and stealing AT&T call and text metadata for over 100 million users. Authorities say the conspirators used stolen credentials where multi-factor authentication was not enforced, exfiltrated terabytes of sensitive data, and extorted victims for ransom. Moucka admitted to threatening officials and security researchers and faces significant prison time at his October sentencing.
read more →

Snowflake breach actor pleads guilty in US court

🔒 Connor Riley Moucka pleaded guilty in Seattle federal court to charges including computer fraud, wire fraud and aggravated identity theft for his role in the 2024 Snowflake customer account intrusions that affected at least 165 organizations and exposed data tied to over 100 million people. Prosecutors say attackers used old credentials harvested by infostealer malware and exploited accounts with MFA disabled, resulting in more than $9.5 million in direct victim losses and at least $495,000 personally taken by Moucka.
read more →

Some Claude Chats Became Publicly Searchable

🔍 Reports reveal that certain shared Claude chat links were indexed by Google, exposing sensitive content from AI-assisted apps and private conversations. The exposed material reportedly included medical notes, cryptocurrency wallet keys, addresses, and other personal data. Anthropic says shareable links are user-controlled and not intentionally discoverable, but archived public content can be crawled. Guidance on correcting the setting was provided.
read more →

UK police national legal database breached

🔒 The Police National Legal Database (PNLD), managed by West Yorkshire Police, has suffered a data security incident identified on July 26 and disclosed on August 3. Information including names, organizations and work email addresses of police officers, criminal justice professionals and partners was published on the dark web, though there is no evidence of compromised passwords. The breach also affected the Ask the Police service, and PNLD is working with cybersecurity specialists and the National Crime Agency to investigate.
read more →

ExfilSquad Leak Impacts Over 100K UK Police Contacts

🔐 A breach of the U.K. Police National Legal Database (PNLD) exposed names and email addresses of over 100,000 police officers, staff, and criminal justice professionals. The intrusion was detected on July 26 and claimed by the ExfilSquad extortion group, which alleges it stole about 135,000 records. PNLD says no passwords or sensitive victim or offender data were accessed and is working with cybersecurity experts and the NCA while notifying the ICO.
read more →

KT fined for security failures after customer fraud

🔒 South Korea’s largest telco, KT, was fined after security lapses allowed attackers to exploit a stolen femtocell and conduct fraudulent micropayments. The PIPC found that long-lived certificates, unrestricted femtocell IP access and weak internal controls enabled the intrusion, exposing PII for 16,647 users and defrauding 368 customers. Investigators also discovered malware infections on internal servers and criticized KT for delayed reporting and log deletions.
read more →

PNLD breach exposes UK police and partner emails

🔒 The Police National Legal Database (PNLD) confirmed that names, organisations and work email addresses for police officers, staff, criminal justice professionals, government partners and customers were compromised and published on the dark web. The incident, identified July 26, also included some Ask the Police submitter contact details, raising phishing risks. PNLD says no passwords or credentials are known to be exposed and is working with the ICO, NCA and cybersecurity specialists while notifying affected parties.
read more →

COLDCARD RNG Flaw Tied to Major Bitcoin Theft

🔒 Researchers attribute an exploit in COLDCARD hardware wallet firmware to the theft of roughly $88.6 million in Bitcoin from thousands of wallets generated with a flawed random number generator. Galaxy Research traced initial drains of about 1,083 BTC on July 30 and later identified further waves raising the total to 1,367 BTC taken from 4,585 addresses. Block and other analysts found an integration error that caused a deterministic MicroPython fallback RNG to be used instead of the STM32 hardware RNG, enabling offline seed reconstruction and address matching.
read more →

Amgen confirms cloud data breach exposed sensitive files

🔒 Amgen disclosed a cloud data breach after threat actors exfiltrated corporate and patient information from third-party cloud environments. The company detected unauthorized activity in July 2026, activated its incident response plan, and engaged independent forensic experts to investigate. Amgen says stolen data includes proprietary data and patient protected health information, and it is assessing the scope, regulatory requirements, and potential notifications.
read more →