< ciso
brief />
Tag Banner

All news with #data breach tag

934 articles · page 8 of 47

23andMe Agrees $18M Settlement and New Security Terms

🔒 A coalition of 42 US attorneys general has secured an $18m settlement with genetic testing firm 23andMe following the 2023 credential-stuffing breach that exposed profile and ancestry data for over six million individuals. The settlement, led by New York Attorney General Letitia James, includes more than $705,000 payable to New York and imposes new data protection requirements on the company and its successor. As 23andMe entered bankruptcy in March 2025, its customer data was transferred to TTAM Research; the agreement mandates risk analysis, an advisory board on data security, and continued consumer deletion rights to safeguard that information.
read more →

23andMe to Pay $18M After Massive Genetic Data Breach

🔒 A coalition of 43 state attorneys general reached an $18 million settlement with 23andMe (now Chrome Holding Co.) over a 2023 data breach that exposed genetic data of 6.9 million customers. Investigators found the company lacked basic protections against credential-stuffing attacks, including multifactor authentication, password blocklisting, and adequate monitoring. The settlement imposes new security requirements, governance measures, and preserves consumer deletion rights while following prior lawsuits and fines.
read more →

Sentencing in TfL cyber-attack highlights motive

🔒 Two young men were sentenced to five years and six months each for an unauthorised cyber-attack against Transport for London (TfL) after pleading guilty under the UK Computer Misuse Act. The judge found motives included "selfish bravado" alongside other factors, and noted their high expertise despite youth and neurodiversity. The attack, linked to group Scattered Spider, caused widespread service and data disruption affecting millions and significant financial losses.
read more →

Lidl warns customers after third‑party data theft

🛡️ Lidl has alerted customers in Germany, Belgium and the Netherlands after personal data was stolen from a third‑party IT provider. The retailer said the online shop itself was not affected but a separately stored file containing names, phone numbers, emails, birth dates and customer numbers was accessed. Lidl stated passwords, payment details and delivery addresses are not impacted and urged vigilance against phishing. Forensics experts and authorities have been engaged and customers are advised to verify senders and avoid clicking unknown links.
read more →

Rival Chinese and Indian Cyber Espionage Hits Pakistan

🔒 SentinelLabs reports that suspected China- and India-linked cyber operators targeted multiple Pakistani law enforcement systems between February 2024 and April 2026, focusing on Balochistan Police. The compromise affected servers hosting biometric records, case files and tenant registrations, and included implants in a public Complaint Management System. Analysts linked PlugX, ShadowPad and Cobalt Strike to China-nexus activity and Remcos to a suspected India-nexus actor. The incidents underscore risks from centralized police IT systems and concentrated intelligence value.
read more →

Lidl discloses online shop customer data breach

🔒 Lidl notified customers in Germany, Belgium, and the Netherlands that attackers accessed a separately stored file at a third‑party service provider and stole personal data from users of its online shop. The retailer said the shop's systems were not affected, but it cannot yet exclude the theft of passwords, billing or payment details. Lidl and the service provider have reported the incident to authorities and engaged forensic experts, while warning customers to watch for phishing and identity fraud.
read more →

Injective Labs SDK compromise exposes wallet keys

🔐 Unknown actors compromised the Injective Labs SDK repository and published a malicious npm package, @injectivelabs/sdk-ts@1.20.21, to exfiltrate cryptocurrency private keys and mnemonic phrases. The backdoored release, deployed on July 8, 2026, was embedded with fake telemetry that captured sensitive wallet data and transmitted it to an external server. The attacker pushed identical poisoned versions across 17 additional @injectivelabs-scoped packages to reach transitive users. A clean update (1.20.23) is now available and users are urged to rotate any exposed keys and check dependencies.
read more →

Police point to Dutch suspects in Odido breach

🔎 The Dutch National Police report strong indications that Dutch-speaking attackers were involved in the February breach of telecom provider Odido. Investigators recovered traces including a phone call where an impersonator posing as an Odido IT employee used social engineering to enable a phishing-based data theft. Odido disclosed the incident affected millions of customers and that exposed records may include names, addresses, contact details, IBANs, and some ID numbers, while call records, billing data and passwords were not exposed. The extortion group ShinyHunters claimed responsibility and released a large archive of stolen records, and the gang has been linked to multiple vishing and SSO-targeting campaigns affecting major providers.
read more →

Dormant GitHub Accounts Exploited to Scrape Orgs

🔎 Datadog Security Labs warns of coordinated campaigns using dormant or compromised GitHub accounts and exposed personal access tokens to enumerate organizations via the GitHub API. Operators use automated scraping tools, aged "ghost" accounts, and legitimate-sounding user agents to blend into normal API traffic, primarily collecting public data but occasionally cloning private repositories. The activity leverages unauthenticated API surfaces and GraphQL queries to map repos, memberships, followers, and other artifacts for reconnaissance.
read more →

AssuranceAmerica breach exposes millions of driver records

🔒 AssuranceAmerica disclosed a data breach impacting 6,998,886 individuals after detecting suspicious activity on March 17, 2026. The incident began with a targeted attack on an employee that allowed unauthorized access and copying of data files. Stolen records include names, contact details, policy and claims information, driver and vehicle data, and driver's license numbers. The insurer has disabled compromised credentials, isolated affected systems, notified law enforcement, and strengthened security controls.
read more →

Mount Royal University confirms data breach incident

🔒 Mount Royal University in Calgary reported a cyberattack on June 17 that disrupted online services and internal systems, and led to theft and deletion of files from university storage drives. External cybersecurity experts have been engaged to investigate and assist recovery efforts. The attackers claimed responsibility as CMD Organization, posted samples of stolen documents, and demanded a 30 BTC ransom. MRU is notifying affected individuals and offering credit monitoring for certain employees.
read more →

KDDI breach exposes millions of email accounts

📧 KDDI, Japan's second-largest telecom, disclosed a breach of an email platform used by five ISPs that exposed millions of email addresses and passwords. The company detected the incident on June 17 and says attackers exploited a zero-day in third-party software on May 16. KDDI reported up to 14.22 million affected accounts, with 12.23 million email addresses and 7.62 million passwords exposed, and is forcing password changes and deploying EDR.
read more →

Accenture confirms breach after hacker offers data

🔒 Accenture has acknowledged an isolated security breach after a threat actor claimed to have stolen 35 GB of source code and related data and tried to sell it on a cybercrime forum. The company said it has remediated the issue and that there is no impact to Accenture operations or service delivery. The attacker, operating as "888," posted claims of exfiltrated source code, keys, tokens, and configuration files and shared a screenshot of an Azure DevOps repository clone. Accenture did not confirm the extent of the accessed data, how access occurred, or whether customer data was affected.
read more →

Vietnam arrests suspects behind major anime piracy

🔒 Vietnamese authorities have arrested seven suspects alleged to have operated HiAnime, the largest anime piracy streaming service before its June shutdown. The group faces charges of copyright infringement and money laundering after reportedly posting over 26,000 pirated anime titles across 100+ sites and earning about $12.85 million in illegal ad revenue. The Alliance for Creativity and Entertainment (ACE) and U.S. partners assisted the multi-year investigation.
read more →

SaaS single points of failure threaten campuses

📘 Higher education now runs core academic operations on a few massive SaaS platforms, creating systemic single points of failure. When a major LMS was breached during finals week 2026, campuses lost access to rosters, grade books and coursework despite SLAs and certifications. The author argues IT must architect independent, read-only continuity layers synchronized from source systems to maintain operations during vendor outages or attacks.
read more →

FortiBleed ties stolen Fortinet credentials to ransomware

🛡️ SOCRadar links the FortiBleed credential-theft campaign to the INC and Lynx ransomware operations after finding a Windows server used by FortiBleed that contained access to ransomware negotiation panels. Investigators discovered FortiGate configuration files, harvested credentials, and a custom "FortiGate Sniffer" tool that intercepted VPN and authentication data. The operation targeted hundreds of thousands of devices and deployed sniffers on thousands, with ongoing investigation into additional servers, a suspected Nextcloud zero-day, and overlapping victim data.
read more →

Kubota reports month-long network intrusion affecting employees

🔒 Kubota North America disclosed that a threat actor accessed parts of its network from March 16 to April 20, exposing personal data for employees and dependents. The company says exposed information may include names, Social Security numbers, dates of birth, tax IDs, driver’s license numbers, bank account and corporate card details, and limited benefits claims. Notifications were sent starting June 30 with instructions to enroll in Kroll identity protection and guidance to monitor accounts; Kubota has enacted additional security measures and has not reported business disruptions.
read more →

FTC fines Amazon for withholding fraud victims’ records

🔎 The FTC says Amazon will pay a $2.25 million penalty after allegedly blocking identity-theft victims from obtaining transaction records required under Section 609(e) of the FCRA. The complaint claims Amazon customer service denied record requests citing "privacy" or "security," often delivered records after the 30-day statutory window, and sometimes refused law enforcement requests. The order requires Amazon to provide requested records within 30 days and notify affected consumers who previously requested records since April 2024.
read more →

Aflac Japan Confirms Major Customer Data Breach

🛡️ Aflac Japan disclosed a data breach after an unauthorized third party accessed systems between June 15 and June 25. The company reported that impacted files may include policy and coverage details, personal data, and bank account information, and said US systems were not affected. Some customer services were taken offline while calls and other channels continue to support claims. Authorities have been notified and no misuse has yet been confirmed.
read more →

Aflac Japan breach exposes policy and bank data

🔒 Aflac disclosed that attackers accessed systems at its wholly owned Japan subsidiary between June 15 and June 25, 2026, prompting suspension of certain systems while operations continue. The insurer is working with external cybersecurity experts, has notified Japanese regulators, and will inform affected individuals. Aflac said U.S. systems were not accessed and the full scope of the incident remains under investigation.
read more →