Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 7th September and 13th September 2026.📅 8th September
220 million traveler records exposed in Vietnam-linked APIS leak
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
AI Customer Service Agents Can Be Hacked to Bypass MFA, Steal OTPs and Expose User Data
BigBear 2 Phishing-as-a-Service (PhaaS) Campaign Steals 5000+ Microsoft Credentials
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
BigBear 2.0 Phishing Campaign Hijacks Microsoft 365 Sessions to Bypass MFA
Bitcoin hardware wallets Trezor and Ledger in hot water over data breaches
Compromised identities a key driver of ransomware attacks across education sector
Critical Dell Secure Connect Gateway Flaws Enable Unauthenticated Admin Access and Remote Code Execution
Cyberattack encrypts systems at Bavarian municipal utility
Data breach exposes sensitive data of 220,000 users on cosmetic procedure platform Gangnam Unni
Driver’s License Data Breach: What to Do if Your Information Was Stolen
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
French prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattack
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Grindr to pay out $35 million in UK HIV data-sharing settlement
Hackers Abuse Legitimate Node.js Runtime to Hide Persistent Backdoor in Enterprise Attacks
Hackers Abuse Sliver, Mimikatz and Ethereum C2 in Windows Post-Exploitation Attack
Hackers build AI frameworks for widescale credential theft
Hackers Compromise Coder Module Registry to Serve Malicious Packages and Steal Credentials
How Invisible Text Can Turn AI Assistants Into a Phishing Threat
How to spot the new phishing scam targeting Apple Pay users
If you subscribed to New Yorker, Vogue, or WIRED, your accounts may be breached
IT help-desk vishing tricks executives into handing over Microsoft 365 access
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins
Large KFC franchise operator in South Africa hit by 536GB data breach
Leaving Online Reviews Could Make You A Bigger Target For Phishing Scams
Liquid Network’s $47 Million White-Hat Question: Who Decided the Price of the Rescue?
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
Mathspace breach exposes data on over a million students and parents
Mathspace confirms data breach affecting more than 1 million users
Microsoft Exposes New Phishing Attack: Hiding Within Words
NordVPN uncovers global phishing campaign impersonating 75+ brands to hijack corporate accounts
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready Ransomware-as-a-Service (RaaS)
Panzer Ransomware Uses Double Extortion and Cross-Platform Builds to Target Enterprises
Philippine Ports Authority (PPA) ransomware report false; Department of Migrant Workers (DMW), Department of Labor and Employment (DOLE) sites restored
Ransomware in 2026: What the Data Demands From You
Rhysida Leaks 5.26 TB of Berlin's Secret Files on the Dark Web
ShinyHunters Claims Florida DMV Breach, Posts Jeffrey Epstein Record as Proof
ShinyHunters lawyer up after police release audio clip of suspect in Odido hack
South Korea's 'Gangnam Unni' Beauty Platform Suffers Data Breach Affecting 220,000 Users, Exposing Treatment and Payment Records
THost9 Android RAT Pairs Packed Loader With ADB Worm
Thousands of online shops in danger after critical Adobe Commerce/Magento zero-day exploit
Trezor customers hit with phishing calls and letters after shipping-partner breach
Trezor Supply Chain Breach Now Impacts 81,000 Customers
UK cybersecurity agency urges firms to tackle risks of “shadow AI”
Verve Portraits data allegedly compromised by Settra ransomware attack
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
📅 7th September
$320 Million Vanishes From Liquid Network’s Bitcoin Reserves - And the ‘Hackers’ Say They’re the Good Guys
500 Organizations Breached as Medusa Ransomware Spreads Through Critical U.S. Infrastructure
A whitehat hacker is holding $320 million in drained Bitcoin until developers prove they patched a fatal network flaw
AI Agents could help Ransomware hackers move through networks in just 10 Hours
AI Could Shrink the Supply of Exploits Governments Rely On
Are 200 million LG TVs listening in - even when switched off?
Attackers use rogue ScreenConnect clients to spread malware
Australia: Million-plus students, adults, lose data in major hack
Beaver County agency announces it was a victim of a ransomware attack
Berlin: The hacker group 'Rhysida' stole approximately 5.8 TB of confidential data from the government, leaking information including defense plans and the phone numbers and addresses of government officials
Berlin investigates new data leak after hackers publish stolen login credentials
Berlin Ransomware Leak Exposes State Secrets
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Bitcoin network used by exchanges hit by $320 million exploit. Hackers claim they're the 'good guys'
Breached! Tutoring platform Mathspace says 1 million-plus Australians implicated by data breach
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
ConnectWise warns of new ScreenConnect flaw without patch
Crypto Hardware Wallet Maker Trezor Reports 67K Additional US Customers Impacted in ShipMonk Data Breach
Cryptolocker ransomware: A look back at its widespread impact
Cyber criminals are adapting ASCII smuggling for mass phishing campaigns
Cyber’s 2023 problem: Mini-cats or a new loss trend?
Data Breach: Natural Resources Wales (NRW) published staff ethnicity, religion and sexuality data by mistake
Data Breach: What to do if your information is exposed
Data Breach at American Clothing Giant Carhartt Exposes Nearly 13 Million People
DentaQuest sued for allegedly exposing 15 Million patients’ private information
F6 Threat Report Tracks 600 Million Records Across 164 Database Leaks
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
FBI investigating huge US and Canadian driver's license data breach on Russian cybercrime site
Former employee files class action against Ceva Logistics over data breach
G7, CISA Urge Urgent Shift to Post-Quantum Cryptography
Gangnam Unni breach exposes sensitive data of 220,000 users
Gangnam Unni Breach Leaks 220,000 Users' Personal, Medical Data
Genetic testing giant hit by data breach affecting 2.8 million
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Hackers are using 'invisible' Unicode characters to sneak phishing lures into emails
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication
How Hackers Use Email Addresses for Phishing and Account Takeover
HYBE's Weverse Platform Suffers Data Breach Affecting 420,000 Users, Exposing Payment Records
Identity attacks behind 85 per cent of education ransomware
India: Kerala Faces Cybersecurity Skills Gap as Ransomware Victims Rise 389%
Irish HSE fined €645K after medical records were found in mold and rubble
'It's extremely creepy': LG TVs collect far more data on you than you'd expect, says new report, including logging microphone audio while on standby and detecting your wireless devices including phones and smartwatches - and users are furious
Jaguar Land Rover to cut 4,000 jobs following last year’s cyber attack
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
June 2026 Healthcare Data Breach Report
Kimsuky Hackers Use OpenCode AI Agent to Mass-Produce Phishing Decoys in LNK Attacks
Liquid Hacker Vows to Return 4,000 BTC Once Bug Is Patched
Liquid Network Hack: $320 Million In Bitcoin Walked Out, And The Hacker Wants To Give It Back
Liquid Network Hackers Demand Bug Fix Before Returning $320M BTC
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Mathspace Breach Exposes 1.08 Million Students, Staff
Mathspace Breach Impacts More Than 1 Million Users in Australia, New Zealand
Mathspace data breach affects over 1 million users
Mathspace Data Breach Exposes Over One Million Users in Australia and New Zealand
Mathspace data breach hits over million users across Australia, New Zealand
Mathspace Data Breach Hits 1.08 Million Users in Australia, New Zealand
Mathspace discloses data breach affecting over 1 million people
Mathspace hack: More than one million students, parents and teachers impacted in major data breach
MikroTik under active exploitation: 122,500 routers expose SSH port, emergency patches available
Minnesota County Hit by Second Ransomware Attack After Officials Pay $128,000
Montana Supreme Court confirms records affected in nationwide C-Track data breach
Montana Supreme Court joins New Hampshire court, others in C-Track data breach
More than 1 million users affected in Mathspace data breach across Australia and New Zealand
More than one million affected in major Mathspace data breach across Australia and New Zealand
Multiple Class Action Lawsuits Filed Against IDScan
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able patches max severity N-central flaw amid ongoing attacks
N-able Patches Max-Severity N-central RCE Flaw CVE-2026-86218, Nearly 1,500 N-central Servers Exposed
N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
National Cyber Security Centre (NCSC) Warns Shadow AI Creates New Security Risks
Natural Resources Wales: Notice of personal data breach affecting former and current employees
Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Information
Natural Resources Wales reports personal data breach affecting former employees
New SynkLoader malware distributed via Microsoft Teams phishing
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
OpenAI Confirms Wiki Incident, Plans New Framework for AI Misalignment Disclosures
OpenAI Reports Rogue Agent Web Takeover to EU Regulators as Safety Concerns Grow
Over 420,000 User Accounts Affected In Weverse Data Breach
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Phishers Are Hiding Malicious Emails in Plain Sight With Invisible Unicode
Phishing Network Hijacks Google’s Own Tools to Slip Past Email Filters
Popular travel app used by 23 Million lets anyone spy on users, including soldiers
Ransomware hackers dump 1.4 million stolen records from German government
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
Rhysida Publishes Berlin Government Data After €2 million Extortion Demand Refused
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
South African firms urged to prep for more autonomous AI-driven orchestrated attacks
South Korea Records 40% Drop In Voice Phishing Cases After Tough Crackdown
Supposed White-Hat Hackers Drain $320 Million in BTC From Liquid Network, Say They’ll Return It After Fix
Teenage hacker charged over cyberattack on French tax authority
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE - Public Exploit Released
The Economics of Dwell Time and Why AI Native SIEM Changes the Equation
The Hidden Privacy Cost of Online Payments
The Hugging Face incident: Inside AI-led data breach that is reshaping OpenAI's safety rules
Toy Ghouls Targets Russian Organizations With New Windows Backdoors
Trezor data breach impact now reaches 81,000 customers
TVING Begins Accepting Compensation Claims for Personal Information Leak...Withdrawn Members Also Eligible
TVING Opens Compensation Claims for Data Breach Victims
UK app developers sue Apple for £2 Billion over tracking rules
US military disables ad trackers on troops’ phones over security concerns
US military troops can still be hit by targeted attacks despite disabling ad tracking on their devices - and leaders aren't happy
US Puts $10 Million Bounty on Alleged Iranian Cyber Chief
Weverse data breach affects 422,584 user accounts
Weverse data leak affects 420,000 users
Weverse, Hive's global fandom platform, suffers data breach affecting 422,000 accounts
What is 'ASCII smuggling'? How to safeguard yourself from such online phishing fraud
When does a Data Breach become “Cognizable Damage” under U.S. Law
Why Are So Many Security Professionals Keeping Breaches Quiet?
Why Hiding Chain-of-Thought Alone Doesn’t Stop Distillation Attacks
Zombie accounts could turn your forgotten profiles into hacker targets
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 24th August and 30th August 2026, kindly assisted by our partners.
