Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Tuesday, 22 September 2026

Ransomware Operator Claims - Week 38 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 14th September and 20th September 2026, kindly assisted by our partners.

DBD discovered and researched 210 Ransomware Victims over 56 Countries and Islands claimed by 47 Data-Leaking Ransomware Operators, including 3 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 21 September 2026

Data Breaches Digest - Week 39 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 21st September and 27th September 2026.


📅 25th September

AI Security Awareness is the New Frontline of Cybersecurity

Another week, another data breach for Revolut customers

Australia: Government 36 times slower to detect data breach than private sector

Australia-based finance app Stake caught in data breach: What you need to know

Australian trading platform Stake caught in data breach

Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group

Bitget hit by $352 million hack with North Korea suspected

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Burnaby Schools Hit by Cyberattack, Disrupting Networks and Phone Lines

Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

Columbia University agrees to $16.1 million settlement over 2025 data breach

Crypto Exchange Bitget Exploited for $351M as Hacker Swaps Funds for Ethereum

CYBER ATTACK: Dyfed-Powys Police hit, and the force still can’t say whether staff data was accessed

Cyber attack on Dyfed-Powys Police force confirmed

Cyber attack on Dyfed-Powys Police may have compromised staff data

Doctor's Choice Home Care discloses data breach tied to WellSky vendor

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Duelbits Hit by $7 Million Hack as Crypto Stolen Across Four Blockchains

Dyfed-Powys Police confirms cyber attack investigation

Dyfed-Powys Police force confirms it was victim of cyber-attack

Dyfed-Powys Police hit by cyber attack

Dyfed-Powys Police hit by cyber attack as information at risk

Dyfed-Powys Police hit by major cyber attack where staff data could have been taken

Dyfed-Powys Police says it has suffered a cyber attack

Email attacks evade detection by generating phishing pages directly inside the victim's browser

EU proposal could let AI companies train on Europeans’ data by default, NOYB warns

Fake payroll desktop apps hand attackers a route to company paychecks

Fake Post Office Notices Fuel New Voice Phishing Wave in Korea

Google Chrome 154 Fixes 108 Security Flaws: 11 Are Rated Critical

Hacker ‘IamNotAVillain’ Leaks 150 GB of Alleged Italian Government Data

Hackers steal $351.6 million in Bitget crypto exchange hack

Half of threat hunters say bad data is their biggest problem

LabCorp reaches $2.3 Million multistate settlement over patient data breach

Luxembourg City warns of phishing emails masquerading as municipal administration

MacSync info-stealing malware hides malicious commands in an iCloud calendar

MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks

Microsoft disrupts EvilTokens device code phishing operation

Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families

Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce and Anubis Attacks

Microsoft, Cloudflare disrupt EvilTokens phishing service

One bad Android app could hijack your OnePlus 15, researcher warns

Only 26% of Detected CISA Known Exploited Vulnerabilities Were Fully Remediated

Party Invite Phishing Scams Are the New Missed Connections

PC maker Asus hacked, user data potentially at risk:Told customers that the breach could have exposed contact and order details

Quest Hotels data breach exposes nearly 2 million customers

RemControl Banking Trojan Gives Attackers Remote Control of Android Devices

Researchers Identify AliExpress Phishing Domains Before Registration

Revolut Customers Caught in DriveWealth Data Breach After Third-Party Security Incident

Revolut Data Breach at DriveWealth Follows Impersonation Incident

Revolut Hacker Used Blockchain Analytics to Identify Targets in Data Breach

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Rydox Cybercrime Marketplace Operator Pleads Guilty in Pittsburgh

Rydox marketplace admin pleads guilty, faces 22 years in prison

Ryuk ransomware raider sentenced to two years prison

Salesforce Agentforce vulnerabilities allowed 0-click CRM data theft, anonymous phishing

Scam hotel booking sent family to Wetherspoon pub

SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data

South Korea: Chuseok Voice Phishing Losses Top 100 Billion Won for First Time

Stake data breach exposes customer details after hack at partner DriveWealth

Sweden’s IMY Fines Miljödata SEK 1.8 Million for Data Breach That Exposed Sick Leave and School Records

Swedish software provider fined after data breach exposed data of 2.2 Million people

The US Department of War relied on software built in Russia and linked to Russia’s Federal Security Service (FSB)

Threat detection dashboards are masking security coverage gaps

UK police force hit by cyber attack as fears erupt of 'compromised' information

Ukraine Warns Consumers About Fake Electricity Bills and Phishing Scams

Wales: Cyber attack on police force may have 'compromised' staff information

Wales: Police force confirms it has been hit by cyber attack as investigation under way

Wales: Police force is hit by cyber attack that has disrupted systems and may have left staff information 'accessed or compromised'

Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits

Welsh police cyberattack sparks probe into possible staff data breach

Wisconsin Department of Justice (DOJ) announces $2.3 million Labcorp settlement over 2019 data breach

WordPress Flaw Under Active Attack: Hackers Target CVE-2026-87902 for Code Execution

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA Known Exploited Vulnerabilities (KEV)

Your incident count is missing a few incidents

📅 24th September

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps

A Hacker Put AI Agents to Work - and 600,000 Credit Cards Were Stolen

Aeromexico Confirms Customer Data Exposed in Cyberattack

AI data breach exposes gaps in Australia's government cyber defences

Astrana Health Data Breach Impacts Private, Confidential Information

Astrana latest healthcare tech firm to report data breach to Securities and Exchange Commission (SEC)

Asus hacked, company is telling customers their data potentially at risk

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Australia: New South Wales Premier Chris Minns urges caution with AI after government health data breach

Australia says OpenAI agent hacked government website, checks for more breaches

Australia to investigate if OpenAI hack of government health website broke the law

Australia's Prime Minister rebukes OpenAI after AI agent breached Medicare health portal

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Biglaw Firm Claims Employee Was ‘Deceived’ Into Sending Client Documents To Hacker

Brooklyn man sentenced to 12 years for $16 Million Coinbase phishing scheme

Canada investigates IDScan.net after millions of driver’s licenses leak online

CISA Charts New "Quality Era" for Global CVE Program

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

Critical 9.8 JetBrains TeamCity RCE exploited by ransomware, says CISA

Cyber recovery plans lag behind AI, ransomware threats

Data breach victims are staying silent, leaving insurers with less visibility

Deepfake Attacks Are Moving Phishing from the Inbox to Video Calls

Deepfakes, Voice Cloning & AI Phishing Put Indian Enterprises at Risk

Digital forensics firm with US federal contracts covered up ties to Russia, Department of Justice (DOJ) alleges

Elsevier LAPSUS$ Redirect Attack: Visitors Sent to Leak Page Instead of Journals

Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims

"Entire systems could collapse:" OpenAI government breach is a stark warning for national security

Europe’s technology backbone is becoming a cyber target

EvilTokens Turns Genuine Microsoft Login Into a Phishing Trap

Exposed GitLab project email addresses let attackers push code

FBI hack: ShinyHunters countdown ticks down, claims "we got what we wanted" in new post

FBI says source of its jobs portal breach still unknown as hackers allege employee data compromised

Galago Ransomware Emerges With Shared Infrastructure Ties to Panzer

GNOME 50.5 security patch fixes a gvfs CVE and Epiphany code injection

Hacked FBI data has sensitive information about employees' intelligence roles

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Hacker claims 7.49 Million customer records stolen from major utility

Hacker Finds This Chinese BYD Pickup Shockingly Easy to Break Into and Control Remotely

Hackers Claim Major FBI Data Breach in Apparent Retaliation Against the Bureau

Hackers now exploit critical Roundcube flaw in code injection attacks

Hackers sell AI token draining as a service: DDoS shift threatens massive direct losses

Homoglyph Attacks Turn Lookalike Domain Names Into Convincing Phishing Traps

Indiana woman suing CenterPoint over data breach, court records say

Indonesia Loses US$6.2 billion from Cyber Attacks This Year

Irish Revolut customers affected by data breach at US broker

Irish Revolut customers among those affected by third-party data breach

Irish Revolut customers hit in second data breach

Irish Revolut customers impacted by data breach

Latvia Hacker Arrested Over TSC Data Theft and Extortion Attempt

MacSync malware uses public iCloud calendars to deliver new payloads

Massive security flaws affect entire Tor network: critical patches released

Microsoft Password Reset Portal Can Leak Account Verification Details

Microsoft, Cloudflare disrupt AI-powered EvilTokens phishing service

Millstone Medical Outsourcing Data Breach Exposes SSNs and Health Records

Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats

Nevada reaches settlement with Labcorp over 2019 data breach

New Android malware RemControl steals banking PINs and blocks removal attempts

New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2

New Carbonato malware uses AI agents to hijack exposed Docker hosts

New Galago Ransomware Operation Emerges With Links to Panzer Group

New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group

New Jersey joins $2.2 million multistate LabCorp settlement over 2019 data breach

New ransomware group n0n escalates threats by targeting backups

New RemControl Android Banking Trojan Steals PINs Using AI-Built Phishing Overlays

New York Attorney General James Secures $2.3 Million and Reforms to Protect Consumers After Labcorp Data Breach

Oculus Pathology Notifies 20,000 Patients About April 2026 Security Incident

OpenAI Agent Breached Australia’s Medicare Data Portal, Government Says

OpenAI agent breached Australian government health website, Prime Minister Anthony Albanese says

OpenAI Agent Breached Australian Medicare Statistics Portal

OpenAI Agent Breaches Australian Government Health Service

OpenAI AI Agent Breaches Australian Government Website, Prime Minister Anthony Albanese Demands Answers

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

OpenAI agent hacking spree widens to Australia, targeting government website

OpenAI Agent Hacks Australian Medicare Portal

OpenAI data breach latest in long list of hacks in Australia

OpenAI hacked Australian Medicare govt site, probed data providers

Opportune Data Breach Exposes Social Security Numbers

Over 75% of Organizations Experience Microsoft 365 Governance Issues

Over 77 Percent of Ransomware Groups are targeting the Healthcare Sector

Passkey phishing attacks: Why Microsoft 365 security can't stop at sign-in

PC hardware giant ASUS warns customers of eShop data breach

Pennington County Provides New Details on July Ransomware Attack

Pennsylvania getting $43K in settlement from 2019 data breach

Pennsylvania to Get Part of $2.2 Million Settlement in Data Breach

Pharmacies a Hot Target for Phishing, Vishing, and Other Cyberattacks

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Ransomware gangs now exploiting critical TeamCity flaw

Ransomware gets physical

Ransomware Report Confirms Manufacturing as Top Target

Ransomware risks rise as enterprise recovery capabilities erode

Reconnaissance-First Attacks: The Next Evolution of Phishing

Redesigning Security Architecture in the Agentic AI Era

Revolut confirms some Irish customers affected by new ‘third party’ data breach

Revolut Customers Hit by Second Data Breach in Just One Month

Revolut customers impacted by new data breach

Revolut customers in Ireland affected by ‘third-party’ data breach

Revolut Data Breach Notices Hit Former US Trading Users as DriveWealth Confirms Hack: What Was Exposed

Revolut: Hackers threaten ‘We’re selling customer data’. At least 15 Italians affected

Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Salesforce Agentforce vulnerabilities allowed 0-click CRM data theft, anonymous phishing

Scammers pose as Ville de Luxembourg in latest phishing email

ServiceTitan discloses health plan data breach affecting 4,851 people

ShinyHunters Claims Data Breach at FBI Through PeopleSoft Zero-Day

ShinyHunters Claims FBI Hack, Threatens To Leak Agent Data Over Warning

ShinyHunters FBI Data Breach: Leaked Spreadsheet Names Staff in China, Russia and HUMINT Roles

Some Irish Revolut customers affected by new data breach

South Korea: Chuseok Voice Phishing Damage Surges Past 100 Billion Won

South Korea's 10% breach fines raise global compliance challenges

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Tessco discloses data breach involving Social Security numbers of minors

The Hidden Security Risks of Devices You Forgot Were Connected

‘This kind of data has real utility in the wrong hands’: Cyber experts warn alleged FBI data breach could have serious real world consequences

Ubuntu kernel CVE fixes are moving to a weekly release schedule

UK Government Shifts to Service-Led Cyber Governance After Stinging Audit

UK warns AI gives hackers an advantage over defenders

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

Veterans Affairs (VA) Slams Baylor Genetics Over Delayed Warning of Massive Patient Data Breach

What is known about latest data breach for Revolut users?

Why Australia chose the world's biggest political stage to reveal OpenAI hack

Wiltshire mum 'extremely worried' after daughter's data stolen

WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours

Your security program knows about the firewall, but does it know about the elevator?

Your TV is spying on you: here’s how to make it stop

📅 23rd September

30 million sensitive records leaked, numerous PepsiCo locations exposed

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

A possible IDScan data breach has far-reaching implications

AI Attacks Enter New Era as Hackers Use Deepfakes and Automation to Scale Deception

AI Gives Hackers an Edge Defenders Still Can’t Match, National Cyber Security Centre (NCSC) Warns

Akira exploits two-year-old SonicWall flaw

Arista patches actively exploited VeloCloud Orchestrator zero-day

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Attackers Keep Malware Campaigns Alive by Rotating Domains and Hosting Infrastructure

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Canva reports data breach impacting more than 420 organisations

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Cloudflare & Microsoft disrupt EvilTokens phishing service

Cloudflare And Microsoft Lead Takedown Of Phishing Platform Built To Bypass Multi-Factor Authentication

Cloudflare, Microsoft dismantle AI-powered MFA phishing ring targeting Australia

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

Cyber attack on Ribon compromises BigCommerce, impacts Master of Malt

Cyber Attacks Increase in 2026: What's Driving the Global Threat?

Cyber risk is now operational risk for Australia’s energy sector

DarkMe RAT trades zero-days for plain phishing emails

Dutch privacy watchdog calls for camera glasses ban in hospitals and courts

EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response

EU cybersecurity system hampered by delays and weak information sharing

EvilTokens Phishing Service Uses AI and Device Code Attacks to Hijack Microsoft Accounts

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

Extradited Armenian National Sentenced Over Ryuk Ransomware Scheme

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Fake Claude Max giveaway tricks users into handing over their Google account credentials

FBI agents' data breach

FBI data breach: Hackers claim personal details of thousands of agents were stolen, here is what happened

FBI Hacked, Employee Data Reportedly Exposed

FBI investigates claimed data breach of agent records by hacking group ShinyHunters

FBI investigating alleged ShinyHunters breach of its jobs site

Flock Camera Hacked, Security Leaders Discuss

Gabia Data Breach Exposes Personal Information of 2,998 Customers

Graphalgo Malware Hits Terraform and Go Packages in New Supply Chain Attack

Greece: Courier service reports customer data breach

Hacker claims massive FBI data breach

Hacker detained in Latvia for at least two cyberattacks

Hacker steals 600,000 credit cards while barely lifting a finger

Hackers Exploit Check Point 0-Day to Execute Arbitrary Scripts Without Authentication

Hackers start exploiting critical WordPress flaw for code execution

Hundreds of Leaked GitHub App Keys Still Authenticate

If You’ve Ever Applied For An FBI Job, Hackers May Have Your Address And Social Security Number

InfraTrust report warns network management systems under attack

Kaspersky Uncovers New Stealth Ransomware that Hijacks Corporate Devices without Encrypting Files

Latvia arrests suspected hacker for electronics repair company breach

Leaked GitHub key left US public health agency’s code exposed to poisoning

Los Angeles (LA) freeway sign hijacked to doxx political dissidents in latest Iran-linked hacking

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

MeDirect: Beware of phishing phone calls claiming your account is at risk

Microsoft and UK Police Dismantle AI-Powered ‘EvilTokens’ Phishing Service

Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

Microsoft Takes Down AI Phishing Service EvilTokens

Microsoft Upgrades SharePoint Flaw From Spoofing to 8.8 RCE

Microsoft’s Takedown of EvilTokens Illustrates Broad Use of AI by Threat Actors

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Nearly two-thirds of tested websites fail every bot test

NetBSD 10.2 security fixes close a remote kernel bug in ipfilter

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

New RemControl Android banking malware targets users in Europe and Canada

New Zealand: Privacy Commissioner puts Manage My Health, Health NZ on notice after data breach

Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records

Placeholder domain used in developer documentation now serves ClickFix attacks

Quest Apartment customers urged to check passports and licences after major data breach

Quest Apartment Hotels customers urged to check passport and driver’s licence details after data breach

Ransomware Attacks Reach Record High for 2026

Ransomware group PAYLOAD weaponizes Microsoft Active Directory for disruption

Ryuk ransomware member sentenced to 24 months in prison

Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

ShinyHunters Claim FBI Breach, Offer Sample of Alleged Stolen Data

ShinyHunters claims FBI data breach affecting employees and job applicants

ShinyHunters claims FBI Data Breach, allegedly exfiltrates sensitive Employee Information

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

ShinyHunters Claims It Hacked the FBI, Holds Data on Every Employee, FBI Confirms Probe

ShinyHunters claims major data breach at the FBI

ShinyHunters Hacker Group Claims It Hacked the FBI and Stole Data on Nearly Every Agent

Spokane Public Schools Faces Cybersecurity Incident

StreamRat Android Trojan Turns Fake Streaming Ads Into Full Phone Takeover

Suisun City, California, Resumes Public Access After Cyber Attack

Swedish regulator fines IT provider Miljödata over data breach affecting millions

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

TVING Applies 'Zero Trust' After Massive Data Breach

Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

📅 22nd September

7 to 7 Dental Data Breach Affects 3,526 Texans

A cheap fake base station can still track 5G subscribers

AI Agents Are Opening New Doors for Attackers Into SMBs

AI Agents Are Rewriting the Rules of Lateral Movement

AI Drives Surge in Bot and API Threats

AI Incident Response Readiness Lags Behind AI Adoption

AI is set to help cyber attackers much more than defenders, says UK official

Albany College of Pharmacy and Health Sciences Data Breach Settlement

Aprio Advisory Group Data Breach Exposes Financial and Medical Info

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

AVL Growth Partners Data Breach Exposes W-2 Information

Bangladesh: Alleged ‘hacker’ arrested in Natore

Belgian Sports Federations Hit by Cyberattacks, Data Under Investigation

BigCommerce Data Breach Exposes Customer Details Through Third-Party Apps

BigCommerce Merchants Hit by Data Breach via Ribon App

BigCommerce merchants impacted by third-party app data breach

BigCommerce Ribon: Data Breach via Third-Party Application

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

BYD removes China and surveillance references from car privacy policy

Call-on-Doc Data Breach Exposes Sensitive PHI and PII

Canada’s privacy commissioner investigating massive driver’s licence data breach

Canadian regulator opens probe of IDScan for allegedly violating data privacy laws

Check Point warns of Management Server zero-day exploited in attacks

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Chinese hackers exploit WordPress, Zyxel flaws to steal government data

Chinese hackers weaponize “the gap” by reverse engineering Chrome fixes before they reach users

Chinese-speaking hacker used AI agents to breach 100 companies, steal credit card data

CISA orders feds to patch Zyxel flaw exploited for data theft

CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

Clop Ransomware Gang’s Leak Site Hijacked by Rival ShinyHunters

CLOSEDQUORUM: The Malware That Lets AI Vote on Its Next Move

Columbia to settle June 2025 data breach lawsuit for $16.1 million

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

‘Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware rival

Cyber criminals hack into rival hackers’ site amid ongoing feud

D-Link warns of max severity zero-day bug in DIR-822A routers

Digital Operational Resilience Act (DORA) Year Two: Can Your SOC Actually See the Attack?

Doctor's Choice Data Breach Impacts 14,333 Texans

Education sector faces higher email-driven ransomware and account takeover risks

EU Cyber Resilience Act (CRA): What Manufacturers Selling Digital Products in the EU Need to Know About Vulnerability and Incident Reporting

EU Cybersecurity Response Hampered by Critical Information Gaps

EU Fines Google 403 Million Euros For Location Data Breach

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

FBI Investigating ShinyHunters Claims of Employee Data Theft

Gemini AI Autonomously Hacked 3 Companies, Google Confirms

Google Faces €403 Million GDPR Fine Over Location Tracking

Google fined $463 million over EU data breach

Google’s location tracking comes with a €403 Million fine

Hacker group ShinyHunters claims massive breach of FBI employee data

Hackers are using AI agents to breach companies in just hours, Anthropic says

Hackers breach two Colorado water utility companies

Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Hacking the hackers: ShinyHunters breaches Clop ransomware site

How Much Does a Data Breach Cost in 2026? Global Average Hits Record $4.99 Million as AI Attacks Reach $6 Million

How to Spot and Report Phishing Attacks

India: Gang with China links busted in Rs 1.95-crore whale phishing fraud

India: Pune Police Bust Five-Member Gang With China Links in ₹1.95 Crore Whale Phishing Fraud

India’s Department of Telecommunications (DoT) Warns Citizens Over SIM Fraud and IMEI Tampering

Iranian hacker in IRGC-linked cyber case to be extradited to US

Kaspersky Uncovers ‘Payload,’ a Stealth Ransomware Targeting Corporate Devices

Kaspersky uncovers stealthy ‘Payload’ ransomware campaign targeting corporate networks

Lakes Region Visiting Nurse Association (LRVNA) Data Breach Exposes Sensitive Personal Information

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Meta’s Muse AI Agent Has a Zero-Day That Lets Malware Hijack Its Microphone

Meta’s Muse AI assistant can be hijacked through a simple attack

Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI

Microsoft and Coinbase Take Down EvilTokens, an AI Phishing Service

Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft Takes Down EvilTokens AI Phishing Service

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft’s EvilTokens takedown sheds light on state of AI-powered cybercrime

Millennium Partners Data Breach Exposes Social Security Numbers

MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide

Namibia: Ransomware group targets defence ministry

Nepal: Stock Market reopens after ransomware attack disrupts trading

Nepal: Stock Market Trading Halted Due to Cyber Attack on Data Center

Nepal Stock Exchange (NEPSE) ‘technical glitch’ was a ransomware attack. What happened?

Nepal’s stock market has a bigger problem than a ransomware attack: Everything you need to know

Network Segmentation Failures Are Expanding the Corporate Attack Surface

New ClosedQuorum Windows malware uses AI for attack decisions

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

New TASK#STOMP Windows Backdoor Enables Continuous Document Theft

New Windows Defender zero-day blocks Microsoft antivirus updates

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

North Korean Attackers Hit 30,000 Devices and Steal $10.7 million

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Over 30,000 Veterans' Medical Results, Personal Information Exposed by Cyber Data Breach

PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks

Potential data breach may affect nearly 2 million people in Czech Republic

Princeton investigates potential cybersecurity incident

Quest breach included thousands of credit card CVVs

Quest Hotels data breach: Almost 2 million impacted, almost 50k credit cards compromised

Ransomware Gangs Are Skipping Encryption to Just Steal and Leak Your Data

Ransomware Without Encryption: PAYLOAD Weaponizes Windows Group Policy

RatHat Android Malware Uses AI to Target Banking Credentials in Real Time

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

Researchers uncover malware that uses AI to choose its next move

Rogue external MFA providers can steal passwords during logins

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

ServiceTitan Data Breach Affects 4,851 Individuals: PHI Exposed

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

ShinyHunters breaches Clop ransomware site and demands payment

ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

ShinyHunters claims FBI systems hack, sensitive data "on almost ALL FBI agents"

ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate FBI comment

ShinyHunters hacks Clop and threatens to extort the ransomware gang

ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

South Korea's Kakao Games Data Breach Victims Rise to 243 as 103 More Confirmed

Stolen passwords are exposing America’s water providers to hackers

Suede Data Breach Exposes Social Security Numbers

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Tessco Data Breach Exposes Sensitive Personal Information of Minors

The latest deepfake numbers give CISOs plenty to worry about

The next intellectual property thief may sound like your CEO

The Philippines: Land Transportation Franchising and Regulatory Board (LTFRB) flags data breach

Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals

UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites

Ukrainian Hackers Just Stole Heaps of Classified Data from the Russian Navy

United Underwriters Insurance Data Breach Exposes PII

Unmasking EvilTokens: Getting to the root of device code phishing

Veterans Affairs (VA) criticizes Baylor Genetics for delayed notification after data breach

Warning Issued Over Fake 'Seoul Citizen Safety Insurance' Phishing Sites...Beware of Personal Info Requests

West Virginia hospital faces class-action lawsuit over data breach

When the Phishing Page Exists Only Inside the Browser

Why Ransomware Gangs Are Launching Cyber Attacks on Each Other

Why Security Needs to Stay Alert in the ShinyHunters, Clop Feud

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

📅 21st September

A Background Check Is Only as Reliable as the Identity Behind It

AI agents on Amazon Web Services (AWS) can access and leak secrets, researchers warn

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Allergy Centers Data Breach Compromises Social Security Numbers

Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach

Analysts Link Fetch.ai, NuNet, and SingularityNET Attacks to Single Hacker

Anatomy of a Ransomware Recovery: Hour by Hour

Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

Australian not-for-profit Thorndale Foundation investigating Qilin breach claims

Australians love these cars. Experts have 'real security concerns'

Belgian table tennis, gymnastics federations hit by cyberattacks

BigCommerce alerts merchants of data breach linked to Ribon apps

Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit

Canadian investigation launched into data breach that exposed millions of IDs

CenterPoint Energy confirms data breach exposure for Indiana customers following alleged 7.5 million record leak

ChatMinerva breached, intruder accessed databases with users' chats

China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America

China-nexus actor steals thousands of documents in monthslong exploitation campaign

CISA alerts of active exploitation of three Linux kernel flaws

CISA, FBI and Partners Detail Gunra Ransomware Tactics

ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71 Million in Crypto

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Cyber Attack to Cost Springfield Schools Time on Winter Break

Cyberattack hits University of Munich, potentially exposing student financial data

Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage

Cybercriminal Claims Moneyboxx Finance Breach, Posts Alleged Source Code on PwnForums

Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members

Data Protection Commission fines Google 403 million euros for location data breach

Employees sue global agribusiness following criminal data breach

EU data regulator fines Google more than $460 million for location data violations

EU fines Google 403 million euros for location data breach

EU fines Google €403 million over location data breach

EU hits Google with €403 million fine over location data breach

EU slaps Google with USD 463 million fine over location data breach

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

French Crypto Holders Flooded With Fake Support Calls After Tax Data Breach

Gone Phishing? Cybercriminals Are Getting Savvier

Google Fined €403 Million Over GDPR Violations Tied to Location Data

Google fined €403 million over location data privacy violations

Google Gemini demonstrates ability to Cyber Attack Companies after OpenAI Cyber Incident

Google Hit with €403 million GDPR Fine Over Location Data Practices

Google hit with €403 million GDPR fine over location tracking

Google says Gemini breached three companies during security test

Google Wants Android Apps to Look Beyond the Security Patch Date

Greystar Data Breach Exposes Personal and Financial Data

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Hacked? Qantas investigating WhatsApp phishing reports

Hacker group claims to have hijacked rival gang's website

Hacker Group Exposes Major Vulnerabilities in Flock Automated License Plate Readers

Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Hackers gain brief control over LNG vessel safety systems near Gibraltar

Intent injection attacks are a new worry for AI-native 6G networks

Ireland fines Google €403 million on behalf of EU for location data breach

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed

LeMaitre Vascular Data Breach Exposes Social Security Numbers

Lessons must be learnt from cyber attack on Revolut, experts warn

Lincoln Investment Data Breach Compromises SSNs and Medical Records

LinkedIn wins court order blocking mass scraping of user data

Maltese accounts may be affected by Revolut data breach

Maltese Accounts Reportedly Among 680 Impacted By Revolut Data Breach

Massachusetts fines TradeZero for data breach, compromising personal information of thousands

MedImpact Data Breach Exposes Personal Information

Mexico probes possible Aeromexico customer data breach

Nepal: Glitches on stock trading platform risk investments of 8 million investors

Nepal: Ransomware attack on Data Hub forces stock market to halt trading

Nepal: Ransomware attack shuts stock market as investors raise security concerns

Nepal stock market halted after ransomware attack disrupts 72 brokers

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

New York healthcare provider suffers data breach affecting over 280,000

North Korea’s job interview scam runs both ways

North Korean WaterPlum Hackers Infected 30,000 Devices Through Fake Job Interviews

PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption

PAYLOAD Ransomware Hijacks Active Directory Group Policy for Encryptionless Extortion

Qantas investigates WhatsApp phishing reports targeting customers

Raising the alarm: Brigham Young University (BYU) researchers find AI is an effective tool in phishing scams

Revolut Customers Targeted with New Wave of Phishing Attacks

Rosch Visionary Systems Data Breach Exposes PHI

Royal College of Veterinary Surgeons (RCVS) apologises after month-long Find a Vet data breach

Royal National Lifeboat Institution (RNLI) warns supporters of possible data breach as it faces far-right targeting

Russia reports thousands of cyberattacks on election infrastructure during vote

Rust developers targeted by hackers with fake job calls and malicious commands

Scammers impersonate cops, use arrest threats to extort victims

‘Scary how open’: BYD Shark 6 remotely hacked during cyber safety test

Securing AI Agents Requires More Than a One-Time Risk Assessment

Severe Bluetooth flaw allows hackers to take over DJI drones in mid-air

ShinyHunters allegedly launches Cyber Attack on Clop Ransomware Group leading to Data Theft

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment

ShinyHunters defaces Clop ransomware data leak site, claims data theft

ShinyHunters Extortion Syndicate Hijacks Cl0p Ransomware Dark Web Infrastructure

ShinyHunters Hacks Cl0p’s Dark Web Leak Site in Ransomware Gang Feud

Some Maltese accounts caught up in Revolut data breach, hacker says

South African organisations are taking longer to recover from ransomware attacks

Spanish privacy regulator probes AI agent-driven cyber attack

Taiwan Fines Coupang $47,000 Over Data Breach Hitting 200,000 Users

Taiwan fines Coupang over data breach impacting 200,000 users

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

TD Bank Data Breach Exposes Personal and Financial Information

Texas Regional Asthma, Allergy & Immunology Center (TRAAC) Data Breach Impacts 5,040 Patients: Medical Info Exposed

The Philippines: Data breach hits Land Transportation Franchising and Regulatory Board (LTFRB) online system

The Philippines: National Privacy Commission (NPC) reports Land Transportation Franchising and Regulatory Board (LTFRB) online system data breach

The recovery costs of a ransomware attack in South Africa is over $1 million

The ‘significant’ threat of a major cyber attack on Greater Manchester

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Tishman Speyer Data Breach Compromises Social Security Numbers

WaterPlum Hackers Steal $10.7 Million in Crypto From IT Workers

What To Do After a Healthcare Data Breach: Tips for Nurses

Why Spam Filters Struggle as AI Rewrites Phishing Emails

Why was Nepal’s stock market shut on Monday

WordPress Click2Shell flaw lets hackers execute PHP on the server