Editor's Message

Welcome to DBD. Cybercrime made global headlines in 2025. Attacks on well-known brands and organizations have raised public awareness of the severity, frequency and impact of cyber attacks. Ransomware attacks are at their highest ever recorded, and 2026 has the potential to be even worse, as cyber criminals continue to extort their victims, with little chance of being brought to justice. On a lighter note, I'd like to take this opportunity to wish you all a very Merry Christmas and all the best for the New Year. Thanks again for all your support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.



Monday, 29 December 2025

Data Breaches Digest - Week 1 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 29th December 2025 and 4th January 2026.


29th December

1.6 Million+ Salvation Army transactions exposed, hackers claim

2.3 Million WIRED users exposed, hacker threatens release of 40 Million more records

22 Million Affected by Aflac Data Breach

27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials

27 Malicious npm Packages Used in Phishing Attacks on Healthcare, Industrial Sectors

Accused Coupang Data Thief Threw Laptop into the River, Founder Apologizes for Recent Data Breach

After Asiana, Even Korean Air... Employee Names and Account Numbers Exposed

After robbing Amazon of Korea, the attacker threw his MacBook into the river

AI-Powered Phishing Kit Targets Microsoft Users for Credential Theft

As tax filing approaches, hackers target US taxpayers

Automation forces a reset in security strategy

Binance-backed Trust Wallet hit by $7 Million hack, experts warn users

Browser-in-the-Browser Phishing Attack: How to Protect Yourself

Christmas gift: method to exploit MongoBleed vulnerability leaking MongoDB secrets showcased on web

Chrysler allegedly compromised by Everest ransomware gang

CISOs are managing risk in survival mode

Coinbase Breach Fallout: Former Support Agent Arrested in India

Coinbase Data Breach Fallout Reaches India as Insider Arrested

Coinbase’s $400 Million Nightmare: Insider Arrested Following Massive Data Breach

Coupang Allocates €850 Million in Vouchers for Data Breach Victims

Coupang data breach triggers $1.1 Billion compensation and political scrutiny

Coupang offers US$1 billion compensation for data breach victims

Coupang offers 50,000 won voucher but effectively gives customers 10,000 won

Coupang offers 50,000 won vouchers to 33.7 million customers after data breach

Coupang offers compensation to 33.7 million users over data breach

Coupang recovers smashed laptop that alleged data leaker threw into river

Coupang to Issue $1.17 Billion in Vouchers Over Data Breach

Coupang to Pay $1.1 Billion in Compensation to Users After Data Breach

Coupang unveils $1.17 billion compensation plan over data breach

Coupang Unveils Nearly 1.69 Trillion Won Compensation Plan Over Data Breach

Coupang’s W1.7 trillion payout plan fails to quell public anger

Coupang's Billion-Dollar Response to Data Breach

Coupang's compensation plan derided as 'bait'

Critical 0day flaw Exposes 70k XSpeeder Devices as Vendor Ignores Alert

Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

Cyber attacks: 2025 the ‘tipping point’ as Jaguar Land Rover (JLR) and Marks & Spencer (M&S) incidents highlight risks

Data Breach Affects Patients of Multiple Fyzical Therapy & Balance Centers

Data breach at Korean Air leaks 30,000 employee records

Data theft alert: insurer Aflac notifying millions of clients

Dataset containing data from Wired circulating on hacker forums

Dozens of Chrome Extensions Hacked, Exposing Millions of Users to Data Theft

EazyTick Data Breach Exposes Over 20,000 User Records

Elford, Inc. Construction Data Breach: Project Files Leaked Online

Ericher Data Breach: Customs and Logistics Firm Sensitive Data Exposed

Farfetch owner Coupang announces compensation payout after data breach hits nearly 34 Million customers

Farfetch owner offers $1 billion in vouchers for those affected by data breach

Five Key Flaws Exploited in 2025's Major Software Supply Chain Incidents

Former Coinbase support agent arrested for helping hackers

Former Coinbase support agent arrested in India over major data breach as legal and security pressures mount

Fortinet warns of 5-year-old FortiOS 2FA bypass still exploited in attacks

French software company fined $2 million for cyber failings leading to data breach

From the Boardroom to the SOC: Why Some Organizations Recover Quickly from Ransomware While Others Stall

Guernsey data breach ruling upheld over legal papers left outside

Hacker arrested for KMSAuto malware campaign with 2.8 million downloads

Hacker Claims Theft of 40 Million Condé Nast Records After Wired Data Leak

Hacker Dumped MacBook in River in Attempt to Destroy Digital Evidence

Hacker Threw MacBook in River to Erase Evidence in Coupang Data Breach

HoneyMyte APT Campaign Uses Kernel-Mode Rootkit to Deploy ToneShell

How to Spot the Most Common Crypto Phishing Scams

Income Tax Phishing Campaigns Linked to Silver Fox Hackers Target Indian Organizations

Indian train driver loses $29,000 in “digital arrest” scam

IoT Device Vulnerabilities in Smart Pet Feeders: Petlibro Exposes Pet, User and Employee Details

Kaspersky detected a fivefold surge in QR code phishing attacks in the second half of 2025

Korean Air data breach exposes data of thousands of employees

Korean Air discloses data breach after the hack of its catering and duty-free supplier

Korean Air employee data breach exposes 30,000 records after cyberattack

Korean Air employees' personal info leaked after supplier hit by hacking attack

Kumpulan Prasarana Rakyat Johor (KPRJ) Data Breach: 180GB Leaked

LLMs are automating the human part of romance scams

Mens Den Men Data Breach Exposes User Database and Emails

MongoDB Flaw Allows Unauthenticated Memory Access, Immediate Patching Required

MongoDB Vulnerability CVE-2025-14847 Under Active Exploitation Worldwide

New AI-Assisted Phishing Kit Targets Microsoft Users to Steal Login Credentials

New ransomware methods emerge: ClickFix & group alliances

New York Attorney General Fines Capital Region Orthopedic Practice $500K for 2023 Data Breach

Over 22 million were impacted by data breach in June, Aflac says

Phishing scam targets India’s drivers in large-scale e-Challan cyberattack

Rainbow Six Siege Betrayal: Five Hacker Groups and Bribed Ubisoft Staff Spark $339 Trillion Crisis

Rainbow Six Siege players given billions of credits in Ubisoft hack

Ransomware group claims to steal 650GB of Inha University data

Romanian energy provider hit by Gentlemen ransomware attack

Shai-Hulud Returns with ‘Golden Path’ Malware in Latest NPM Supply Chain Attack

Silver Fox Hackers Target Indian Entities Using Income Tax Phishing Lures

SIM Box Scam: A Hidden Phishing Network Powered by Thousands of SIM Cards

Singapore: At least $622,000 lost to phishing scams since November

South Korea’s e-commerce platform Coupang to pay over $1.1B to customers over user data breach

The biggest corporate security blunders of 2025

The Evolution of Ransomware Entry Points: Why the Perimeter Isn’t the Perimeter Anymore

Top 10 Cyber Law Enforcement Operations of 2025

Top Ransomware Attacks of 2025: Major incidents, impacts & rising Cyber Threats Globally

Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

Trust Wallet says 2,596 wallets drained in $7 million crypto theft attack

Two more banks notifying thousands of victims about Marquis Software ransomware attack

Ubisoft Shuts Down Rainbow Six Siege After MongoDB Exploit Hits Players

Ubisoft Takes Down Rainbow Six Siege After a Hacker Plays Santa and Gives Away Billions of In-Game Currency and Items

Why Peak Shopping Seasons Are Now Peak Cyber Risk Periods

‘Why should we pay these criminals?’: the hidden world of ransomware negotiations

You’ve been targeted by government spyware. Now what?

Wednesday, 24 December 2025

Ransomware Operator Claims - Week 51 2025

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 15th December and 21st December 2025, kindly assisted by our partners.

DBD discovered and researched 193 Ransomware Victims over 38 Countries and Islands claimed by 33 Data-Leaking Ransomware Operators, including 2 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 22 December 2025

Data Breaches Digest - Week 52 2025

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 22nd December and 28th December 2025.


28th December

Coinbase CEO Confirms Arrest in India Linked to Data Breach Scandal

Coinbase CEO Confirms First Arrest in Insider Data Breach, Vows Zero Tolerance

Condé Nast faces major data breach: 2.3 Million WIRED records leaked, 40 Million more at risk

Coupang CEO issues apology over data breach, will skip parliamentary hearing again

Coupang Founder Again Skips Parliamentary Hearing as Data Breach Backlash Deepens

Coupang founder apologizes for data breach as government weighs suspension

Coupang Founder Apologises Over 3,000 Customers Data Breach

Coupang founder apologizes over massive data breach, but refuses again to attend parliamentary hearing

Coupang founder Kim Bom apologizes over massive data breach

Data Breach Affecting Goldman Sachs Investment Clients Allegedly Exposes Social Security Numbers

Do you know what phishing is? The electronic scam that is reaching Cuba

Exploited MongoBleed flaw leaks MongoDB secrets, 87K servers exposed

Festive checklist to protect your Christmas gifts from cybercriminals

Foreign hacker who stole $1.18 million in crypto assets extradited to Korea

Hacker claims to leak WIRED database with 2.3 million records

Hacker group threatens major Israeli Prime Minister Netanyahu exposure

Hacker Who Stole Millions in Seconds Finally Caught

How to spot and report an Amazon phishing email

India Arrests Former Coinbase Support Agent Over Data Breach

Indian Police Arrest Former Coinbase Agent in Insider Data Breach Case

Iranian hacker group claims it hacked the phone of the Israeli Prime Minister's chief of staff

Iranian hacker group ‘Handala’ says it breached Israeli Prime Minister Netanyahu chief of staff’s phone

Lithuanian Hacker Extradited to Korea After 1.7 billion won Crypto Heist via Sneaky Malware

Marquis Data Breach Impacts 85,000 South Carolina Residents

Massive Rainbow Six Siege breach gives players billions of credits

One Month On, Coupang’s Data Breach Turns Political: Korea Tests the Boundaries of Tech Governance

Rainbow Six Siege Taken Offline After Major Hacker Attack Causes Infinite Credits and Player Bans

Rainbow Six Siege X Servers Go Dark Following Massive Hacker Attack

South Korea: Top court upholds sentence in case of collusion with North Korean hacker to steal military information

South Korea: Virtual Currency Operator Sentenced for Espionage; Supreme Court Confirms

South Korea extradites hacker behind $1.18 million heist

South Korean retail giant Coupang to compensate $1.1 billion to affected users over data breach

Stolen crypto data is sold on the dark web for $105

Understanding Phishing: The Cyber Scam Reaching Cuba

27th December

AI Fuels Cyber Scams: Deepfakes, Phishing, and Trillion-Dollar Risks

Coinbase Arrests Former Indian Employee in Major Data Breach Case

Coinbase Breach Exposes Cracks in Cryptocurrency Security

Coinbase CEO announces first arrest in India over insider data breach: 'More still to come'

Coinbase confirms arrest in India linked to data breach at cryptocurrency exchange

Coinbase confirms arrests after $20 million extortion data breach

Coinbase Data Breach Case: Ex-Employee Arrested in Hyderabad, CEO Pledges Zero Tolerance for Misconduct

Coinbase Data Breach Leads to Arrest in India

Coinbase Insider Hack Exposed: Human Error Triggers Data Breach With $400M Fallout

Georgia arrests ex-security chief for allegedly aiding global scam call centers

Hacker Leaks 2.3 Million Wired.com Records, Claims 40 Million-User Condé Nast Breach

India: Nationwide Phishing Scam Targets Indian Motorists via Fake e-Challan Portals

India tops Cyble’s APAC cyber target list amid ransomware surge

Iranian hacker group threatens Netanyahu's flight

Isle of Man: Be aware of phishing this time of the year

Marquis data breach affects nearly 85K South Carolina residents

Maui Police Issue Alert on Phishing Scam Exploiting County Board Meeting Info

Microf Data Breach Exposes Social Security Numbers

New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory

Nissan alerts 21,000 customers in Japan after Red Hat-linked data leak

Ransomware Heist on Ghanaian Bank: INTERPOL Says Hackers Stole USD 120,000 in African Cybercrime Crackdown

The AI Arms Race in Cyberspace: How Hackers Are Weaponizing Intelligence and What It Means for Security

Two Banks Issue Urgent Data Breach Alerts, Warn 69,662 Customers After Hacker Hits Third-Party Vendor

26th December

$120,000 stolen from Ghanaian financial institution by hackers

Accounting firm took over a year to inform users of data breach

Aflac confirms June data breach affecting over 22 million customers

Antivirus tools spoofed in Israel-targeted attack campaign

Artisans' Bank Data Breach Exposes SSNs & Addressess

Asiana Airlines Data Breach Exposes Personal Information of 10,000 Employees

Asiana Airlines reports data breach involving employees

Aultman Health System notifies patients of medical data breach

Azerbaijan: The State Security Service has initiated a criminal case regarding the cyber attack on the MİDA system

Capital Region healthcare center fined $500K for patient data breach

Casinos and Cybersecurity: What the IGT Ransomware Claim Reveals About Industry Vulnerabilities

Check Point Warns of Phishing Emails Abusing Google Cloud to Impersonate Legitimate Google Notifications

China-Linked Evasive Panda Ran DNS Poisoning Campaign to Deliver MgBot Malware

Coupang Faces U.S. Lawsuits Over Data Breach

Coupang rejects ‘self-investigation’ accusation into data breach

Coupang Stock Rallies After Company Says Data Breach Less Severe Than Initially Feared

Coupang Uncovers Data Breach Culprit, Confirms Minimal Impact

Coupang’s internal probe into data breach draws renewed bipartisan backlash

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection

Critical Net-SNMP Flaw CVE-2025-68615 Allows Remote Buffer Overflow and Service Crashes

Cybercrimes Double in Decade, Reports Surge 48%

Cyble Uncovers Multi-Domain E-Challan Phishing Campaign In India

Dentistry.One Data Breach Exposes SSNs and Names

Everest Ransomware Group Claims Theft of Over 1TB of Chrysler Data

Fake Grubhub emails promise tenfold return on sent cryptocurrency

Fortinet Warns July-Disclosed SSL VPN Flaw is Being Used to Bypass 2FA

From AI to cyber risk, why IT leaders are anxious heading into 2026

From Gatekeepers to Collaborators: The New Face of Information Security

Georgia arrests ex-spy chief over alleged protection of scam call centers

Goldman Sachs Notifies Clients on Third-Party Data Breach

Goldman Sachs Says Some Client Data May Have Been Exposed in Third-Party Data Breach

Google Cloud Application abuse Campaign

Hacking the hackers

Healthcare Firm Handing up to $5,000 to Victims After Hack Exposed Full Names, Social Security Numbers, Bank Account Info and Confidential Medical Details

India Has Become the Main Target of Phishing Attacks in 2025, Reports Say

Korea elevates government response to Coupang data breach

LLMs can assist with vulnerability scoring, but context still matters

Lynx Ransomware Claims Breach of CSA Tax & Advisory in Massachusetts

Millions of Indian vehicle owners targeted in browser-based e-Challan phishing scam

More banks impacted by Marquis Software Solutions breach

New Iframe-based phishing kit linked to large-scale attacks

Over 36 Fake e-Challan Websites Target Indian Drivers in Large-Scale Phishing Scam

Over 200K law firms threatened by Vincent AI phishing flaw

Pakistan Consulate Warns of Critical Visa Phishing Scam in U.S.

Phishing and Wallet Drainer Incidents Statistics 2025: Hidden Trends

Popular NPM Package lotusbail Exposed as Trojan Stealing WhatsApp Chats

Pro-Russian hackers claim attack on French postal service operator

Ransomware attack on Ghanaian bank led to US$120,000 theft

Romania’s Water Authority Targeted in Ransomware Attack

Shinsegae affiliate reports leak of personal data involving some 80,000 employees

Snyderville Basin Water Reclamation District says it fended off an international cyber attack

Spotify cracks down on unlawful scraping of 86 million songs

Spotify Scraped: 86 Million Songs Leaked in Massive Data Breach

Study confirms AI-Generated NFC Malware has Emerged as a New Cyber Threat

The 10 Biggest Data Breach Fines and Settlements of 2025

The next big IT security battle is all about privileged access

Third-party data breach may affect some Aultman Health System patients

THT Bio-Science Data Breach: NightSpire Ransomware Attack

Top 20 Ransomware Statistics You Should Know

Top Data Breaches in 2025

Trust Wallet Chrome Extension Breach Caused $7 Million Crypto Loss via Malicious Code

TrustWallet Chrome Extension Hacked - Users Reporting Millions in Losses

Trust Wallet confirms extension hack led to $7 million crypto theft

Trust Wallet Investigates How Hackers Submitted New Browser Extension Version After $7 Million Security Incident

University of Phoenix data breach affects nearly 3.5 million people

Veplastic Hit by Chaos Ransomware: 150GB of Data Allegedly Leaked

VeraBank Data Breach Affects Thousands

VisionPoint Eye Center Data Breach Victims Benefit from $750,000 Settlement

25th December

5 Ways AI Is Making Phishing Smarter - and How to Fight Back

Aflac confirms large-scale data breach following cyber incident

Analysing the Trust Wallet Hacker Wallet: Holding Over $4 Million With $1.5 Million in ETH and $1.4 Million in BTC

Asiana Airlines Suffers Data Breach Affecting Over 10,000 Employees

Belarus: Kamunikat.org Library Hit By Hacker Attack

CISA Flags Actively Exploited Digiever NVR Vulnerability Allowing Remote Code Execution

Coupang data breach: Culprit identified, all customers' leaked data deleted

Coupang says all leaked customer information in data breach has been deleted

DragonForce Ransomware Breaches NCR, Tri-State Metal, and Prime Label

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

GreenBills Data Breach: 39 GB of Medical and Insurance Files Exposed

Hermes Medical Solutions Data Breach: Termite Ransomware Attack Targets

INC Ransomware Breaches Wall Street English – 3.5TB Data Leaked

LastPass 2022 Breach Led to Years-Long Cryptocurrency Thefts

LastPass Settlement Reaches Up to $24 Million After Data Breach

More than 20 million impacted by June Aflac data breach

Neighbourly Data Breach: 150GB of User Data and Messages Put for Sale

Pakistani missions warn of visa scam stealing personal data

Phoenix University data breach exposes another 3.4 Million victims of Cl0p Oracle hacks

Qilin Ransomware Attack Hits Seimitsu Thai and LECO Switchgear

South Korean Photo Platform fotoy.co.kr Suffers Data Breach

Study Reveals Businesses Continue to Underinvest in Cybersecurity and Neglect Vulnerability Assessments

The Evolving Economics of Ransomware: Fewer Payments, Bigger Payouts

24th December

59,000 Servers Breached: Operation PCPcat Targets React and Next.js at Internet Scale

70,000 bank customers exposed through vendor attack

Aflac data breach affected 22.65 Million customers

Aflac Data Breach Exposes Personal Data of Over 22 Million Customers

Aflac discloses extent of data breach: More than 22 million customers impacted

Agencies Across Africa Arrest 574, Recover $3 Million in Cybercrime Crackdown

AI powered Cyber Attack hits Chinese TikTok rival Kuaishou

AI-created ransomware and NFC attacks lead the surge in new cyberattacks - here's how you can stay safe this holidays

AllerVie Health Data Breach Leaks Social Security Numbers

Apple Fined €98.6 Million for Privacy Policy Violations Requiring Third-Party Developers to Ask Consent a Second Time

Apple will appeal Italy’s €98M anti-tracking feature fine

ARC Community Services Announces November 2024 Ransomware Attack

Attacks are Evolving: 3 Ways to Protect Your Business in 2026

Autohaus Elstermann Hit by Space Bears Ransomware Attack

Bernaillio County reports potential data breach

Brooklyn Man Indicted for Allegedly Stealing $16 Million in Massive Coinbase Phishing Scheme

Chipotle Data Breach Exposes Employee SSNs & Financial Info

Clop Ransomware Breach Exposes Data of 3.5 Million University of Phoenix Students and Staff

Coordinated Scams Target MENA Region With Fake Online Job Ads

Counterfeit defenses built on paper have blind spots

Couple busted scamming over dozen victims in multi-state credit card phishing spree

Crypto security experts troll North Korean hackers with a Lazarus Group “consultancy”

Cyberattack Knocks La Poste Offline, Disrupting Postal and Banking Services Across France

Data breach exposes sensitive patient information across multiple OSF facilities

Data breach hits over 22 Million Aflac customers

Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws

Evasive Panda APT Asia Cyberespionage Campaign Poisons DNS Requests, Delivers MgBot

Everest Ransomware Group Breaches Accela and Notin

Fake MAS Windows activation domain used to spread PowerShell malware

FBI seizes domain storing bank credentials stolen from U.S. victims

Hackers Claim Massive Spotify Music Scrape, Raising Alarms Over Artist Royalties

Indian Vehicle Owners Warned as Browser-Based e-Challan Phishing Gains Momentum

Interpol Taken Down 6 Ransomware Variants and Arrested 500+ Suspects

Italy Fines Apple €98.6 Million Over App Tracking Transparency (ATT) Rules Limiting App Store Competition

La Poste outage after a cyber attack disrupts digital banking and online services

La Poste Still Offline After Major DDoS Attack

Malicious AV-Themed Documents Deployed in Targeted Attacks Against Israeli Organizations

MongoDB warns admins to patch severe RCE flaw immediately

New MacSync macOS Stealer Uses Signed App to Bypass Apple Gatekeeper

Nissan leak affects 21,000 customers

Nomani Investment Scam Surges 62% Using AI Deepfake Ads on Social Media

Noname057 admits hacking the French Post's headquarters ahead of Christmas 2025, state intelligence moves

North Korean hackers behind bulk of $2.7bn crypto theft in 2025

NPM registry abused in targeted Microsoft phishing campaign

Official Google domain exploited in sweeping phishing campaign

Oklahoma Spine Hospital Agrees to $1.1M Data Breach Settlement

OpenAI says prompt injection attacks “long-term security challenge”

Pell City Schools Targeted by SafePay Ransomware Group

PlayStation Hack Warning Issued, 2FA Won't Protect Your PSN Account

RaccoonO365 Phishing Developer Arrested in Global Cybercrime Probe

Ramside Hall, Durham suffered security data breach

Ransomware Attack on Romanian Waters Authority - 1,000+ IT Systems Compromised

Rogue cyber pros plead guilty to $1.3M ransomware attack

Romania investigates large scale cyber attack on national water body

Russian hackers claim the cyber attack on the French postal service

Securities and Exchange Commission (SEC) Charges Crypto Firms in $14m Investment Scam

Securities and Exchange Commission (SEC) Files Charges Over $14 Million Crypto Scam Using Fake AI-Themed Investment Tips

Spotify Disables Accounts After Open-Source Group Scrapes 86 Million Songs

The End of Excuses: 10 Cybersecurity Investments Every CISO Must Make by 2026

The Gentlemen Breaches HSR Specialist, Santa Casa de Assis and Others

The Year Breaches Stopped Being Loud and Started Being Dangerous

U.S. Authorities Seize Domain Linked to $28 Million Bank Account Takeover Fraud

Vincent AI phishing vulnerability found, 200K+ law firms at risk of credential and data theft

WebRAT Malware Campaign Targets Researchers via GitHub Repositories Containing Fake PoC Exploits for Legitimate Vulnerabilities

What happens to enterprise data when GenAI shows up everywhere

What if your face could say “don’t record me”? Researchers think it’s possible

Wisanka Indonesia Data Breach: 27GB of Internal Files, Designs, and Invoices Leaked

World Leaks Ransomware Hits Ellison Educational Equipment and Chatham Asset Management

23rd December

3.5 Million Affected by University of Phoenix Data Breach

4 Ways Scammers Are Using AI To Trick You (And How To Stay Safe)

574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings

Abuse of Indian Income Tax Themes to Execute Layered Attacks on Enterprises

AI & state-backed cyber spies to drive 2026 threats

Baker University Data Breach Exposes Personal Information of Over 50,000 Individuals

Baker University says 2024 data breach impacts 53,000 people

CISA Flags Actively Exploited Digiever Authorization Flaw in Known Exploited Vulnerabilities (KEV) Catalog

Clop Ransomware Group Linked to 3.5m University of Phoenix Breach

Cloud security is stuck in slow motion

Code that works can also be malware: this WhatsApp API is stealing messages

Cornwall: Kids' books removed from libraries over web links

Coupang Faces Investor Lawsuit Over Massive Data Breach

Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

Cyberattack knocks offline France's postal, banking services

Cybersecurity Stagnation in Healthcare: The Hidden Financial Costs

Data of 21,000 Nissan Customers Exposed via a Red Hat Server Breach, Carmaker Apologizes

Department of Justice (DOJ) Seizes Phishing Domain Behind $14.6M Losses to US Victims

Department of Justice (DOJ) Seizes Stolen Password Database and Domain to Halt Account Takeovers and Disrupt Fraud Network

Distribuidora Nissan Data Breach Exposes 680k Customer Records

Fake listings and phishing emails: How travellers have lost hundreds to Booking.com scams

Feds Seize Password Database Used in Massive Bank Account Takeover Scheme

France’s postal and banking services disrupted by suspected DDoS attack

France’s postal and banking systems attacked as Christmas rush peaks

French postal service brought down by cyber attack

GhostFrame - a super stealthy new phishing kit behind a million attacks

Grupo Panamá Data Breach: 35GB of Financial & Employee Data Leaked

Hackers exploited BitLocker in ransomware attack on Romania's water agency

Hackers stole 86 million songs from Spotify: a 300 TB data breach

Hackers stole over $2.7B in crypto in 2025, data shows

HardBit 4.0 Ransomware Actors Attack Open RDP and SMB Services to Persist Access

Holiday Travel Warning: Cyber Attacks on Business Travellers Surge 30% Over Christmas

Hospitals exposed as medical devices create massive cyber risks

Hundreds of Arrests as Operation Sentinel Recovers $3m

INTERPOL Arrests 574 in Africa; Ukrainian Ransomware Affiliate Pleads Guilty

Interpol Dismantles Six Ransomware Variants, Arrests Over 500 Suspects

Jaguar Land Rover (JLR) suppliers 'on the brink' after cyber attack fallout, warns manufacturing boss

Japan Adopts New Cybersecurity Strategy to Counter Rising Cyber Threats

Korea Construction Safety Association Data Breach Exposes Member PII

Korean Association for Public Administration (KAPA) Database Leaked Exposing Academic and Research Data

Kuaishou Cyberattack Disrupts Livestreaming, Triggers Sharp Stock Decline

Kuaishou’s Shares Slide After Hackers Flood Livestreams With Explicit Content

La Poste Cyberattack Disrupts Postal and Banking Services in France Ahead of Christmas

La Poste DDoS Attack Disrupts French Postal and Banking Services Before Holidays

Malicious extensions in Chrome Web store steal user credentials

Malicious Phantom Shuttle Chrome Extensions Masquerading as a Legitimate VPN Service Intercept Traffic and Steal User Data

Microsoft 365 Accounts Reportedly Breached After Hackers Exploit Legitimate Microsoft OAuth Feature

More than 22 million Aflac customers impacted by June data breach

New MacSync Stealer Disguised as Trusted Mac App Hunts Saved Passwords

Nissan: Thousands Impacted By Red Hat Breach

Nissan confirms customer data exposure tied to Red Hat breach affecting 21,000 customers in Japan

Nissan Confirms Impact From Red Hat Data Breach

Nissan data breach is real and you might be affected

Now you can lose your crypto by video gaming against criminals

Phishing Campaigns Exploit File Sharing Services

Phishing emails and fake adverts flood inboxes this Christmas - and they’re getting harder to detect than ever

Pirate Group Anna’s Archive Copies 256M Spotify Songs in Data Scrape

Pirate group Anna’s Archive says it has scraped 86 million songs from Spotify

Ransomware Attack Disrupts Romanian Waters Authority, Over 1,000 IT Systems Affected

Ransomware Attack Hits Romanian Waters Authority, Compromising 1,000+ IT Systems

Ransomware attack on Romanian water agency hits over a thousand systems

Ransomware Hits Romanian Water Authority, 1000 Systems Knocked Offline

Resilience Starts with Identity: Managing the Ransomware Threat This Holiday Season

Reworked MacSync Stealer Adopts Quieter Installation Process

Romania Water Agency Hit by Massive BitLocker Ransomware Attack Impacting 1,000 Computer Systems

Romanian water agency hit by BitLocker exploit, one thousand systems compromised

Romania’s national water authority hit by ransomware attack affecting about 1,000 systems

Scammers exploit official Google domain to send phishing emails undetected

Securities and Exchange Commission (SEC) sues crypto firms for defrauding investors out of $14 million

Securities and Exchange Commission (SEC) Targets Crypto Platforms in Social Media Scam Crackdown

Shinhan Card reports data breach involving 190,000 merchant records

South Korea: Government launches task force for Coupang data breach probe

South Korea online retailer Coupang faces US securities class action over massive data breach

South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

South Korean firm hit with US investor lawsuit over data breach disclosure failures

Spotify Hit by Massive Data Breach? Piracy Group Claims 86 Million Tracks Scraped

Top Ransomware Trends of 2025

Two Chrome Extensions Caught Secretly Stealing Credentials from Over 170 Sites

U.S. Department of Justice (DoJ) Seizes Fraud Domain Behind $14.6 Million Bank Account Takeover Scheme

University of Phoenix Data Breach - 3.5 Million+ Individuals Affected

University of Phoenix Data Breach Exposes Information of Over 3.5 Million Individuals

University of Phoenix Data Breach Exposes Personal Information of 3.4 Million Individuals

University of Phoenix Data Breach Impacts Over 3.5 Million Individuals

US charges 54 in nationwide ATM jackpotting ring

US disrupts multimillion-dollar bank account takeover operation targeting Americans

US insurance giant Aflac says hackers stole personal and health data of 22.6 million people

Voice Phishing Gang Arrested for Embezzling 1.5 Billion Won in Gold Bars

Weak enforcement keeps PCI DSS compliance low

WebRAT malware spread via fake vulnerability exploits on GitHub

Why are phishing resistant credentials becoming increasingly important?

22nd December

3.5 million hit in US college data breach with full names, dates of birth, SSNs, bank info and more exposed - how to see if you’re affected

86% Surge in Fake Delivery Websites Hits Shoppers During Holiday Rush

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown

1,000 computers taken offline in Romanian water management authority hack - ransomware takes Bitlocker-encrypted systems down

Address poisoning scam costs crypto user $50 Million

Alleged RaccoonO365 phishing kit developer apprehended

America’s Cyber Retreat Is Undermining Indo-Pacific Security

Android Malware Operations Merge Droppers, SMS Theft, and RAT Capabilities at Scale

ARC Community Services Data Breach Exposes Sensitive Information

Arcane Werewolf Hacker Group Added Loki 2.1 Malware Toolkit to their Arsenal

Arcane Werewolf Hacker Group Expands Arsenal with Loki 2.1 Malware Toolkit

Around 1,000 systems compromised in ransomware attack on Romanian water agency

BlindEagle Hackers Attacking Government Agencies with Powershell Scripts

Brooklyn Man Booked in $16M Crypto Phishing Scam Targeting Coinbase Users

Browser agents don’t always respect your privacy choices

Chiesi USA Data Breach Exposes SSNs & Medical Info

CISA flags ASUS Live Update CVE, but the attack is years old

Coupang Faces Class Action Lawsuit Alleging Violations After Data Breach

Coupang Faces Scrutiny After Massive Data Breach

Coupang Inc. Faces U.S. Data Breach Lawsuit

Critical RCE flaw impacts over 115,000 WatchGuard firewalls

Cyber spies use fake New Year concert invites to target Russian military

Cyber-security: cost or strategic necessity?

Cybersecurity 2026: Why Protecting Data Matters More Than Stopping Attacks

Cytek Biosciences Data Breach Exposes Social Security Numbers

Dakota Eye Institute Settles Class Action Data Breach Lawsuit for $1 Million

Data Authorities Probe Trade Union Breach

DDoS incident disrupts France’s postal and banking services ahead of Christmas

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists

Don't make these airport Wi-Fi and public charging mistakes this holiday

EU Chat Control 2.0 Evolves into Going Dark Initiative – Everything You Need to Know

Eurostar AI chatbot flaws exposed after “painful” disclosure process

Fake WhatsApp API Package on npm Steals Messages, Contacts, and Login Tokens

FBI: Deepfake campaign spoofing government officials ongoing for longer than thought

FedEx Data Breach Exposes Sensitive Protected Health Information (PHI)

Five ways AI is changing cyber-attacks: deepfakes, smishing and the new threat landscape

France’s national post office hit by suspected cyber-attack

France's postal service hit by suspected cyber-attack days before Christmas

French authorities arrest 22-year-old over cyber attack on the Interior Ministry

French watchdog fines ad firm with €1M over Deezer leak

Frogblight Malware Targets Android Users With Fake Court and Aid Apps

Fyzical Data Breach Impacts 1,801 in Texas

Google Sues Alleged China-Based Hackers Over Widespread Phishing Scheme

Guilt admitted by former cyber pros over ransomware spree

Guilty plea entered in multinational Nefilim ransomware scheme

Guilty Pleas Highlight Ransomware Risks Within and Beyond the Enterprise

Hackers Abuse Popular Monitoring Tool Nezha as a Stealth Trojan

Hackers attack WatchGuard Firebox firewalls: 120K IPs exposed and vulnerable

Hackers Using Phishing Tools to Access M365 Accounts via OAuth Device Code

Hernando County Responds to Data Breach Exposing Personal Information, Offers Free Credit Protection to Impacted Residents

INC ransomware Claims Evercover and Talarico

Insider Threat: Hackers Paying Company Insiders to Bypass Security

Interpol-led action decrypts 6 ransomware strains, arrests hundreds

Isle of Man: Island businesses targeted in phishing campaign

Judge rules that NSO cannot continue to install spyware via WhatsApp pending appeal

Learn more about Ghost Pairing Cyber Attack via WhatsApp

Legitimate Nezha Monitoring Tool Abused as a Powerful RAT, Providing Complete Control Over Compromised Hosts

Malicious NPM Package ‘lotusbail’ Steals WhatsApp Data

Malicious npm package steals WhatsApp accounts and messages

Microsoft 365 Accounts Hijacked Through OAuth Device Code Phishing Attacks

Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access

MS13-089 Ransomware: Double Extortion Without Encryption

NASA Data Breach: Spanish Teleradiology Data and Source Code Leaked

Nefilim Ransomware Affiliate Pleads Guilty

Nefilim ransomware hacker faces prison after pleading guilty

Nefilim ransomware hacker pleads guilty to computer fraud

Netflix suspension scam targets your inbox

New Flaw in Somalia’s E-Visa System Exposes Travelers’ Passport Data

New MacSync malware dropper evades macOS Gatekeeper checks

New York Home Healthcare Provider Identifies Email Account Breach

NHS England tech provider reveals data breach - DXS International hit by ransomware

Nissan Confirms Data Breach Following Unauthorized Access to Red Hat Servers

Nissan says thousands of customers exposed in Red Hat breach

NIST issues guidance on securing smart speakers

OAuth Device Code Phishing: New Attack Vector for Account Takeover

Ochsner LSU Health Data Breach Impacts 4,519 Individuals

One Community Health Data Breach Exposes Patient PII & PHI

OpenAI says AI browsers may always be vulnerable to prompt injection attacks

Outdoor Smart! (Campfire Collective) Data Breach Affects 19,864 People

Phishing Attacks Abuse OAuth Device Code to Gain Access to M365 Accounts

Phishing Attacks Exploit OAuth Device Codes to Breach Microsoft 365 Accounts

Potential data breach at Fairbanks health clinic, officials say

Prince of Persia ran a covert Iranian spy campaign for over a decade

ProBit Global Crypto Exchange Targeted in Alleged Data Breach

Qilin Ransomware Attack Hits Grupo Olé and Cedar Valley Services

Qilin takes responsibility for major Argentinian football club hack

RansomHouse Ransomware Upgraded: Enhanced Encryption Threat

Report finds most schools are underprepared for ransomware and AI-powered cyberattacks

Romanian national water agency hit by BitLocker ransomware attack

Romanian water authority hit by ransomware attack over weekend

Romanian Water Authority Hit by Ransomware; 1,000 Systems Across 10 Regions Compromised

Romanian Waters confirms cyberattack, critical water operations unaffected

Scripted Sparrow Sends Millions of Business Email Compromise (BEC) Emails Each Month

SIRH Mexico Data Breach: Sensitive Employee Records Leaked

South Korea to require facial recognition for new mobile numbers

South Korea's consumer agency to order SK Telecom to compensate 58 hacking victims

Spotify data breach: 86 million audio files leaked online

Spotify disables accounts after open-source group scrapes 86 million songs from platform

Spotify investigates data breach, after pirate group claims it ‘scraped’ its music library

Spotify’s Music Catalog Leaked in Massive Data Breach

Taminsho Hit by Benzona Ransomware Attack and 80GB Data Exfiltration

Technology and GPS firm Netstar Australia suffers alleged cyber attack

Terport Ransomware Attack: Paraguay Port Operator Breached by Lynx

Think you can beat ransomware? RansomHouse just made it a lot harder

Threat groups steal identities to access Microsoft 365 accounts

Topstep Data Breach Compromises SSNs & Names

U.S. Seizes Crypto Exchange Linked To $70M Ransomware

UK: NHS Supplier Confirms Cyber-Attack, Operations Unaffected

UK Children’s Wellbeing Bill Raises Privacy and Encryption Concerns

UK Foreign Office hit by cyber-attack

Ukrainian hacker admits affiliate role in Nefilim ransomware gang

Ukrainian National Pleads Guilty in Nefilim Ransomware Conspiracy

Ukrainian Nefilim Ransomware Affiliate Pleads Guilty in US

Ukrainian pleads guilty for role in ransomware attacks targeting U.S., Canadian companies

University of Phoenix Data Breach Affects 3.5 Million

University of Phoenix data breach impacts nearly 3.5 million individuals

University of Sydney data breach impacted over 27,000 staff and students

University of Sydney discloses a data breach impacting 27,000 people

Váhostav Targeted by DragonForce Ransomware Attack

Warning issued as surge in OAuth device code phishing leads to M365 account takeovers

WatchGuard Firebox firewalls under attack (CVE-2025-14733)

“We backed up Spotify:” pirates claim to have scraped 300TB of music

What are passkeys really? The simple explanation - for anyone tired of passwords

Yavne Educational Center Data Breach: Sensitive Student Records Leaked