Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Tuesday, 15 September 2026

Ransomware Operator Claims - Week 37 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 7th September and 13th September 2026, kindly assisted by our partners.

DBD discovered and researched 167 Ransomware Victims over 42 Countries and Islands claimed by 42 Data-Leaking Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 14 September 2026

Data Breaches Digest - Week 38 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 14th September and 20th September 2026.


📅 20th September

Basic Security Flaws Fuel Breaches Despite AI-Driven Attack Speed

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email

Fetch.ai Exploit: Hacker Drains $2 Million Across Two AI Crypto Projects

Google infiltrated TeamPCP hacker group to disrupt attacks from the inside

Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack

Handala hacker group publishes selfie images of 700 Israeli ‘security’ personnel

Hong Kong: Census and Statistics Department Warns of Fraudulent Website and Phishing Messages Related to 2026 Population Census

Job hunting? North Korean fake recruiters infected 30,000 devices

Malicious npm packages evade install-script defenses at runtime

More than 1,000 hacker attacks in Russia since the start of parliamentary elections

Researchers escape OpenAI Codex sandbox to run commands on host

RNLI fears supporters' data stolen in cyber-attack after charity 'targeted by far-right agitators'

ShinyHunters Hacks Clop Leak Site, Threatens to Extort Rival Ransomware Gang

ShinyHunters hacks Clop ransomware gang and threatens to extort it

ShinyHunters Turns the Tables on a Ransomware Gang With Site Hack

The Philippines: The Land Transportation Franchising and Regulatory Board (LTFRB) probes data breach as platform goes offline

When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain

📅 19th September

AI Agent Insurance Coverage: Enterprise Governance, Claims Evidence, and Liability

BragJack attacks hijack AI browser agents through malicious extensions

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

Deerfield school district investigating phishing email

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Grandma demands $10 Million after botched facial recognition match lands her in jail for 6 months

How Organizations Can Respond to Exposed Edge Devices and Compromised Credentials

North Korean WaterPlum hackers infected 30,000 devices worldwide

ShinyHunters Hacks and Defaces Clop Ransomware Leak Site

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

Suspected cyberattack on third tanker knocks system offline, US now monitoring 20 ships

📅 18th September

98% of fraudulent hires have company credentials by the time they’re caught

Abandoned IoT apps keep sending sensitive data to broken servers

Akira Ransomware Lists Manders in Leak: 70GB Claimed

Android apps can now check security patches down to individual device components

Australia: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group

Catalyst Health Group reveals data breach linked to service provider Aesto Health

ChatGPT Billing Scam Exposes Critical OpenAI Account Risk

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

CISA Upgrades Vulnerability Reporting Platform with More Automation

Cisco Identity Services Engine (ISE) Vulnerability With CVSS 10.0 Score Under Active Attack

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Claude helped hackers to break into OpenAI accounts: ChatGPT affected

Defences improve, but ransomware still threatens South African businesses

Education sector faces significant cybersecurity challenges

Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram

Fake Bpost Parcel Emails Trick Victims Into Handing Over Card and Bank Details in Phishing Campaign

Fake calendar invites can infect your system, and they’re surging - how to protect yourself

Fake ChatGPT billing email targets work and home users

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments

FBI seizes NightmareStresser domains in DDoS-for-hire crackdown

Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum

Gyazo data breach exposed 23.6 million user records and 490 Million image metadata

Gyazo data breach exposed millions of records; company delayed public disclosure

Gyazo server flaw exploited to steal 23.6 million user records

Hacked before their first coffee: Common onboarding mistakes that open the door to cybercriminals

Hacker breach at Korea math academy Thinking Bull leaks parent-student data

Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 - Symbiosis DeFi exchange bit by lack of basic bounds checking in smart contract

Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook

Hackers Crack Flock Camera, Expose 1.6 Million Images in 21 Days

Hackers demand $3 million as Revolut data breach deepens

Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

Hardcoded MCP credentials found in public GitHub files

How Hackers Used Claude Opus 5 to Breach OpenAI Systems

India forces caller-ID apps to feed spam reports to telcos

Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May - and they work even if the email is sent to spam

Manufacturing Accounts for 22% of all Ransomware Victims

Manufacturing ransomware surged in 2026, spreading beyond the US, with 1,183 victims through July

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Most WordPress pros still lack a breach recovery plan

Nations take action on North Korean IT workers after UN report

Nearly two million Quest Apartment Hotels customers affected by data breach

New Check Point flaw lets hackers execute code with root privileges

New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

North Korean Hacker Group behind Crypto Thefts across 100 Countries

North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

Panzer Ransomware Hits 16 Firms as August Sets 997-Attack Record

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Researchers Used Anthropic’s Claude to Breach OpenAI’s Internal Systems

Researchers used Anthropic’s Claude to hack into OpenAI

Revolut Faces $3 million Ransom Demand Following Data Breach of Cryptocurrency Customers

Revolut Hacker Launches Extortion Site Demanding $3 Million After 680 Customer Data Breach

Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links

Settra ransomware group uses MeshAgent RMM in recent attacks

Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs

South Korea: Personal Information of Students and Parents Leaked in Hacker Breach at Saenggakhan Hwangso Math Academy in Daechi-dong

South Korea Math Academy Hit by Cyberattack, Student Data at Risk

Standard Bank investigates 200GB data breach

Stop assuming your contractor’s data security is your liability shield

This Android malware is nuts: it connects to your phone like a developer, but from the inside

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

U.S. House Passes Bill to Give Local Law Agencies Tools to Investigate Cyber Scams

UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day

Ukraine: Payment data were lured through fake websites - police uncovered a large-scale phishing scheme in 20 regions

Ukrainians charged for hacking 610,000 Roblox accounts and selling them to Russian buyers

University of Galway data breach affected almost 190 people, financial statements reveal

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

📅 17th September

A fake ChatGPT billing email is after your OpenAI password

A physically removed Flock camera exposed local surveillance data

AI Agent Carries Out Multi-Stage Data Theft Attack

AI hacks system and accesses personal data in reported breach

Are British Columbians affected by a massive drivers licence data breach?

Autonomous AI Agent Executes Spain’s First Data Breach: Agencia Española de Protección de Datos (AEPD) Incident Analysis and Cybersecurity Implications

Beware! Kaspersky Discovers Phishing Campaign Disguised as Zoom and DocuSign

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

Brevo supply-chain attack injected ClickFix scripts on customer sites

Bug Hunters at Risk: Leaving Them Outside Can Leave Your Enterprise Devoid of a Critical Defense

CenterPoint Energy Data Breach Exposes Customer Information in September

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

China’s FamousSparrow hackers target Latin America with new backdoor

Chinese hackers use SparroWocky malware in government espionage attacks

CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day

CISA Urges Critical Infrastructure to Plant Decoys Inside Networks

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

Cisco Warns of Active Exploitation of Critical Identity Services Engine (ISE) Flaw

Cisco warns of max severity Identity Services Engine (ISE) zero-day exploited in attacks

Cisco Warns of New Zero-Day Identity Services Engine (ISE) Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Clay County housing agency subject of ransomware attack

Connecticut Ransomware Attacks May Have Exposed Data of More Than 12,600 Residents

Cornerstone Staffing discloses 2025 data breach; law firm investigates claims

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Cyber Essentials Has Record Year but Takeup Remains Low

Cyberattack on Springfield schools included data breach

Data breach incident targets prisoner medical records at 2 Massachusetts jails

East Coast Healthcare Firm Agrees To $1,368,025 Data Breach Settlement Affecting 218,884 Patients

EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

Fake AI trading agent steals crypto wallet passwords

Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam

FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor

FBI Dismantles NightmareStresser, One of the Web’s Longest-Running DDoS-for-Hire Services

FBI takes down one of the longest-running DDoS-for-hire services

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

Gyazo Breach Exposes Link IDs Behind Private Captures

Gyazo data breach leaves over 23 million user records exposed, includes half a billion metadata points

Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets

Hacker who extorted money from Stadler sentenced to prison

Hackers claim breach of Russian election systems days before parliamentary vote

Hackers Demand $3 Million Monero Ransom From Revolut After Data Breach

Hackers demand $3 million ransom from Revolut after data breach

Hackers Demand ₹28.73 Crore Ransom From Revolut After Data Breach

Hackers demand Revolut hand over $3 million ransom amid data breach

Inside Immutable Backup Architecture: How Air-Gapped and WORM Storage Actually Stop Ransomware

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Japan's Gyazo Suffers Data Breach: 23.62 Million User Records and 490 Million Image Metadata Entries Leaked

Manufacturers make patching progress, but identity management still major weakness

Manufacturing Remains Ransomware’s Top Target

Mobile Security Can't Move at App Release Speed Anymore

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA

New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs

New RatHat Android malware uses AI to automate device control

New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence

NH NongHyup Bank Sees Voice Phishing Losses Surge 2.3 Times in Two Years Despite Increasing Staff and Budget

NightEagle APT Expands to Russia With GhostContainer Backdoor and Stealth Tunneling

No evidence a large amount of data compromised from HR system hit by ransomware, says Islamic Religious Council of Singapore (MUIS)

OpenAI details more cases of AI agents taking unauthorized actions

OpenAI Details Six New Instances of ‘Concerning’ AI Agent Behavior

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

Over 100,000 websites showed users ClickFix scams for hours after Brevo compromise

Parents say care group's data breach has been 'catastrophic' for their family

PhishByte warns AI phishing has outpaced detection

Property investors targeted in cyber attack spike

Protect Yourself From MyChart Phishing Scams Targeting Patients Worldwide

Ransomware Attacks May Have Exposed Data of 12,600 in Connecticut

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Ransomware Surge Raises Supply Chain Risks for Distributors

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3 Million Ransom

Revolut data breach affects 680 customers; systems were not hacked

Revolut data breach puts Cyprus users on scam alert

Revolut Denies Hacker Contact Over Reported $3 Million Ransom Claim

Revolut faces $3 million Monero ransom after customer data breach

Revolut faces $3 Million ransom demand after data breach

Revolut phishing texts appear days after data breach

Revolut reportedly facing $3m ransom demand after hackers steal hundreds of customers’ data

Rogue OpenAI Agents Probed Hugging Face for Weeks Before July Breach

Scammers leave AI fingerprints all over fake antivirus renewal page

Second Texas-bound oil tanker hit by hackers possibly linked to Iran, FBI confirms both attacks

Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs

South Africa: Regulator probes ransomware attack on Cartrack

South African home loans giant affected by data breach, customer records potentially exposed

South Korea's Communications Regulator Warns of Surge in Phishing Texts Ahead of Chuseok Holiday

Spain reports first data breach involving autonomous AI agent

Spain’s AEPD Logs First Data Breach Caused by AI Agent

Spain's Regulator Logs First Report of an AI-Powered Data Breach

Suno hit with another proposed class action over data breach that leaked information of 55 Million users

Taiwan: Phishing cases on rise, Criminal Investigation Bureau (CIB) says

Telus blames ‘technical issue’ after some customers told to disregard data breach email

“Their blood will be on Revolut's hands, not mine:” Attackers threaten to sell customer data unless they’re paid $3 Million

Third-party data breach linked to Canva affects 424 organizations in Türkiye

Tough week for Cisco admins: network security system under attack, firewall management center vulnerable

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

UK, US and Netherlands Warn of Iranian Spyware and Spear-Phishing Campaign

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

US Coast Guard and FBI board oil tanker to investigate cyber attack

US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

US takes down NightmareStresser DDoS-for-hire platform

Valve says customer data was not exposed in CEVA cyberattack

Voice Phishing Losses at NH Nonghyup Bank Rise 2.3 Times in Two Years

📅 16th September

2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover

8 Places AI Is Quietly Entering Your Enterprise

280,000 Impacted by Premier Medical Group Data Breach

A phantom Chinese online casino empire is quietly spreading malware

Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

AI Agents Behind RubyGems Cyber Attack Uploaded Hundreds of Malicious Packages

Alvita Care Holdings Data Breach Exposes Financial Account Info

An ISP Data Leak Can Expose More Than Your Password

Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection

Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Attackers target GitLab: thousands of exposed servers remain vulnerable to a critical bug

Attackers Target Vite Servers in Scanning Campaign to Steal AWS, Azure Info

Beyond backup: Rethinking data infrastructure for the ransomware era

Boston dumps Flock due to data hole, but keeps surveillance cameras

Bridgeport Capital Data Breach Compromises Social Security Numbers

CenterPoint Breach May Have Hit 7.5 Million Records, Lawsuits Already Piling Up

CenterPoint Data Breach Reached Customer Information; Scope Is Still Unknown

CenterPoint Energy Breach Exposes 7.49 Million Records

CenterPoint Energy Confirms Breach After Hacker Claims 7.49 Million Records Stolen

CenterPoint Energy Confirms Data Breach After Hacker Claims 6.7 Million Customer Records Stolen

CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information

CenterPoint Energy confirms data breach following claims on hacking forum

CenterPoint Energy confirms data breach of customer information

CenterPoint Energy Data Breach Exposes Customers’ Personal Information

CenterPoint Energy says some customer information was in data breach

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

Communauto data breach traced to employee's unauthorized script, company says

ConnectWise ScreenConnect bug exploited in the wild, CISA says

Coupang rejects 100,000 won compensation plan for users affected by data breach

Coupang rejects 100,000 won payouts for data breach victims

Court files about Southport attack victims, survivors and families accessed in data breach

Criminal Investigation Bureau says phishing scams in Taiwan doubled year on year

Critical Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Flaws Let Attackers Gain Admin Access and Execute Remote Code

Critical ScreenConnect flaw now actively exploited in attacks

CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter

Cyber Attack on Commercial Oil Tanker confirmed by FBI

Cyber-Attacks Cost Organizations $52,000 on Average

Data breach at ID verification company may have exposed millions of driver’s license images

Don’t fall for fake MyChart phishing emails

Edenred Pay Data Breach Exposes Social Security Numbers

Employers are using your personal data to make you accept lower pay

FBI Confirms Data Was Breached in Cyber Attack on Springfield Schools

FBI Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF

First Agentic AI Data Breach Reported to Spanish Regulator

Five alleged Black Axe members extradited to face US fraud charges

Flock camera use by internal affairs unit puts Washington, D.C. police at odds with officers’ union

GAMA Data Breach Impacts 6,000 Texans: PII Exposed

GhostCode Abuses Microsoft Device Codes to Steal M365 Tokens and Register Rogue Devices

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

Global fintech Revolut reveals customer data breach

Google fixes actively exploited Android zero-day on Pixel devices

Google issues urgent update warning for severe Pixel bug

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google says some Pixel phone owners were hacked in zero-day attacks

Hackers are hijacking IP cameras to break into corporate networks

Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database

Hackers rip down Flock camera, steal its data, share findings with media

Hackers rip Flock spy camera off pole and crack open its secrets

House passes bill to equip local law enforcement with scam-fighting tools

Identity attacks drive 85% of education ransomware

International Meteor Organization says cyberattack dealt ‘critical blow’ to website

Investigation launched as files about Southport attack victims and families accessed in data breach

Iran-Linked Hackers Deploy CHOSEN BRICK Spyware Against Activists, Joint NCSC-FBI-AIVD Advisory Reveals

Iranian hackers target dissidents, activists, journalists worldwide with Telegram-linked Chosen Brick spyware

Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution

Italian postal police probe Revolut customer data breach

Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

Malware bypasses browser checks to force install Chrome, Edge extensions

Manhattan District Attorney Seizes 12 Deepfake Porn Websites Targeting 1,200 People

McKesson’s data breach impacted over 6.4 million accounts

Member of Conti ransomware group sentenced to four years in prison

Microsoft Teams IT Support Calling? Not So Fast, Hackers are Exploiting Trust in Spring Ring

Microsoft Warns Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

Middle East cyber threats enter a new phase as ransomware surges and AI joins the attacker’s toolkit

Ministry of Justice apologizes after court staff accessed Southport victims' files

MSPs say nearly half their customers rely on them for CISO services

Names and addresses of 224 people exposed in Southampton council data breach

National Cyber Security Centre (NCSC) and Allies Warn of Iranian Spyware Campaign

New VectraRAT Malware-as-a-Service (MaaS) Lets Hackers Bypass Windows UAC and Steal Browser Credentials

Nipigon hospital hit by ransomware attack

NIST and CISA finalize playbook to stop token theft and forgery

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

OpenAI agents' probing of Hugging Face began months before July breach

Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Parents ‘devastated’ after Southport attack victims targeted in data breach

Parents of Southport attack victim 'devastated' by data breach

Passkey Phishing Attacks Are Leading to Cloud Account Takeovers

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

Prescribe FIT Data Breach Affects 1.3k: PII Exposed

Ransomware activity rises across Middle East as criminal groups attack Gulf

Ransomware Costs $5.08 Million as Downtime Hits 50X Ransom

Revolut confirms customer data breach

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

Revolut hackers demand $3 Million in Monero after data breach

Revolut says no direct demand received over alleged data breach

Revolut-style data breach ‘could absolutely happen in Australia’

Revolut’s data breach shows institutions can be at risk even when not directly compromised

Rohto Pharmaceutical Investigates Cyberattack as Hacker Claims 4.1 TB Data Theft

Romania: Natural Disaster Insurance Pool (PADROM) warns about phishing attempts requesting personal data to verify the PAD policy

Royal Canadian Mounted Police aware of FBI probe into alleged data breach of millions of drivers’ licences in Canada, U.S.

Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

South Korea voice phishing bill could reshape banks’ insurance decisions

South Korea's Financial Services Commission (FSC) Launches Emergency Security Review of Payment Gateways After Data Breach Concerns

Southampton: Names and addresses of 224 people exposed in council data breach

Southport attack victims, survivors and families hit by Ministry of Justice data breach

Southport attack victims' and families' court files accessed in data breach

Southport attack victims' court files accessed in data breach

Spain gets its first taste of AI-aided cyber attack

Spain logs its first data breach allegedly carried out by a rogue AI agent

Spain logs the first data breach caused by an autonomous AI agent

Spain Records Its First Data Breach Blamed on an Autonomous AI Agent

Spain reports the first data breach carried out by an AI agent

Spain’s Agencia Española de Protección de Datos (AEPD) Logs First AI-Powered Breach Case

Spanish data watchdog publicises first AI agent-linked data breach report

Springfield officials say extent of school district data breach remains unclear

Springfield schools provide update on cyber attack, data breach investigation

Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49 Million Records Stolen

The CISO's New Liability Problem: Governing What You Don't Control

The Foot and Ankle Wellness Center Data Breach: 653 Affected

The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad

The true cost of a ransomware attack, with and without Business Continuity and Disaster Recovery (BCDR)

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts

TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password

Türkiye: National Intelligence Organization (MİT)-led operation nets five suspects over trade union data breach

UK fintech Revolut reveals customer data breach

Ukraine moves to crack down on scam call centers after corruption scandal

Urgent probe launched after Southport attack victims' files accessed in major data breach

US lawmakers push “No FLOCK Act” to crack down on police surveillance abuse

Vista Del Mar Data Breach Compromises Health Information

Voice phishing bill could reshape banks’ insurance decisions

xHealth Data Breach Affects 118,000 Individuals

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

📅 15th September

4 in 5 Singapore Business Websites Have WordPress Vulnerabilities

12 Irish Revolut Customers Impacted By Data Breach

32 Ransomware Attacks Every Day as Global Threat Hits Record High

A 26-year-old Canadian hacker breached 165 companies and exposed data linked to 100 million people, but an investigation eventually led to his guilty plea

Acronis warns of actively exploited flaw in its cPanel backup plugin

AI the Top Priority for New Spend as Cyber Budgets Flatline

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

Australian software firm Auto-IT confirms customers compromised by Storm ransomware attack

Australia: Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack

BambooToken malware controls Windows and Linux systems via Message Queuing Telemetry Transport (MQTT)

BambooToken Malware Uses Message Queuing Telemetry Transport (MQTT) to Control Windows and Linux Systems

Birdi Data Breach Exposes Impacts Employees: SSNs Exposed

Black Axe Members Extradited to US Over Internet Fraud Claims

Canadian telecom giant Telus alerts customers to data breach

CenterPoint confirms customer info exposed in data breach amid class action lawsuits

CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy confirms data breach after hacker claims 7.49 Million records

CenterPoint Energy confirms data breach of customer personal information

CenterPoint Energy discloses customer data breach in SEC filing

CenterPoint Energy reports customer data breach in the United States

CenterPoint reports customer data breach

Chess.com scraping exposes 4.7 million email addresses

China spy chief points at US AI models in cyber threat warning

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Communauto says it was hit by data breach initiated by its own employee

Compromised HBO Max Reddit Account Fueled Massive ClickFix Malware Campaign

Coupang Establishes Information Security Advisory Committee Following Record $460 Million Data Breach Fine

Coupang forms security panel after massive data breach

Critical VMware RCE flaw now exploited by ransomware gangs

Crypto Industry Figures Blackmailed by Revolut's Hacker

Cyber attacks costing SMEs full working week in operational disruption

Department of Motor Vehicles (DMV) breach confirmed as hackers claim 200,000 records stolen

Electric and gas utility CenterPoint Energy warns of data breach after dark web post

Facing Steep Criticism Over Abuse, Flock Updates Platform But Draws Skepticism From Privacy Advocates

Fake Bitrefill Checkouts Spread Through Search Results

Fake Voicemail Transcript Emails Become the Latest Phishing Lure for Thousands of Organizations

FBI to Springfield: school cyber attack included data breach, maybe Social Security numbers

Hacked by email: attackers exploiting critical zero-day in Cisco’s secure email solution

Hackers demand 10,000 Bitcoin from Revolut following data breach

Hackers hijack HBO Max’s verified Reddit account to spread infostealer malware

Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access

Hackers target WordPress sites via third-party WooCommerce plugin

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Inside Tajin Group’s Phishing and Money Laundering Network

Inside the Scattered Spider Playbook: How UK Retailers Got Social Engineered

International Meteor Organization Hit by Cyberattack, Weeks of Disruption Expected

Investigation ordered over Southport victims and survivors’ data breach

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Japan’s Digital Agency Confirms VPN Flaw Exposed 246,000 Personnel Records

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

Life Unlimited Data Breach Exposes Sensitive Financial and Medical Data

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

Low-quality casino sites conceal highly dangerous threat actors

Majority of Organizations Have Over 50 AI Agents

Malaysia: Port of Tanjung Pelepas resumes operations after cyber attack

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

More than a third of small UK firms impacted by hacks

Most Firms Unable to Recover Quickly from Ransomware

Most Fraudulent Hires Receive Credentials Before Detection

MyChart urges patients to stay alert of phishing scam

Nearly one in three tech workers fell for a phishing test. The biggest predictor was one habit

Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data

Patched VMware vCenter bug targeted in ransomware campaigns

Petco Data Breach Exposes Government ID Numbers

Phishing Scam Targets D.C. Cannabis Applicants and Virginia’s 350 Retail Cap

Ransomware Doesn’t Just Break Systems. It Breaks People

Revolut Breach Exposes IDs, IBANs of 680 Customers

Revolut data breach exposes weakness in security

Revolut Data Breach Hits 680 Customers as UK Regulators Review Case

Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin

Revolut Data Breach Via Fake Government Requests - What We Know So Far

Revolut Faces $780 Million Bitcoin Extortion After Falling Victim to Data Breach Scam

Revolut hacker claims 147 GB stolen from Italian law enforcement

Revolut Hacker Claims 147GB Italian Police Breach

Revolut hacker says they had six months of secret access

Revolut Leaked Customer Data to Fake Government Email Account

Revolut's paperwork breach shows why insurers are rethinking what counts as a 'cyber attack'

Severe oversight flaw - cops abuse Flock network for "LMAO" searches

Severe TP-Link Tapo camera flaw lets hackers watch live feed from your home

South Korea: 12 Sent to Prosecutors for Voice Phishing Laundering, 300 Million Won to China

South Korea: Crackdown on Voice Phishing That Induces Direct Card Payments...Enhanced Credit Card Fraud Detection

South Korea: Financial Supervisory Service (FSS) targets voice phishing of elderly, tightens Korea card fraud checks

Southport attack victims and survivors at centre of ‘unacceptable’ data breach by court staff

Southport attack victims, survivors and families hit by 'completely unacceptable' data breach

Southport attack victims, survivors and families hit by data breach

StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores

Suspected Black Axe gang leaders face cybercrime charges in the US

Swiss Bitcoin Pay Says No Evidence Merchant Bitcoin Wallets Were Compromised

Swiss Bitcoin Pay takes servers offline after data breach

The federal government can’t buy cybersecurity at the speed of a cyber attack

UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

Ukrainian Conti Ransomware Member Gets Four Years in US Prison

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks

Vulnerable kids' records caught up in cyber attack

Your employees are already using AI tools you never approved

Your Twitch login may be exposed: this one extension is leaking it to Russians

📅 14th September

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

AI makes cybercrime campaigns cheaper, increasing ransomware attacks

Android security nightmare: unprivileged app take over flagship phones

Another European country is pushing ban on smart glasses

Anthropic reports September 2026 AI misuse in cyberattacks, weapon development and phishing

Automotive Cybersecurity Forecasts Are All Over the Map. Ransomware and Recalls Explain Why

CenterPoint Energy faces class actions over alleged customer data breach

Chess.com User Data Surfaces Online After Suspected Scraping Incident, Over 4.5 Million Emails Exposed, Reportedly from Previous Breaches

ClickFix attacks are tricking Mac and Windows users into hacking themselves

Community Health Care Data Breach Exposes Social Security Numbers

Compromised Police Credentials Spark Florida DMV Data Breach Investigation

Conti ransomware operator sentenced to 4 years in jail for playing part in a $150 Million extortion campaign

Cyber Insurance Solvency Crises: War Exclusion Clauses, Systemic Catastrophe Models, and Ransomware Liabilities

Cyberattack or insider leak? Kochi Metro data breach under police scanner in Keralam

Cybersecurity attention fades within months after a breach

Cybersecurity vigilance fades fast after data breach

Dark Web Hacker Claims to Have Data on 40,000 Twitch Streamers

Data breach at Revolut after attacker posed as government agency

Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

Diversified Services Enterprises (DSE) Data Breach Exposes PHI and PII: SSNs Compromised

Don’t fall for fake MyChart phishing emails

EasyEquities, Satrix hit by data breach

Elon Musk’s ‘VoteSafe’ site is harvesting and selling voter data

ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities

Fears for Irish Revolut customers' data after bank duped by fraud email

Finnish Police Alert Europe Over Fugitive Vastaamo Hacker

Finnish police extend search for Vastaamo hacker Aleksanteri Kivimäki across Europe

Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses

Florida Department of Highway Safety hacked by international criminal group

Florida Highway Safety was hacked. Did cybercriminals get your info?

From baby monitors to smartwatches - EU's new 24-hour breach reporting rule targets consumer manufacturers

Global ransomware attacks hit record 997 in August 2026 as utility, healthcare and business attacks surge

Google Play Early Access Abused by Thousands of Suspicious Android Apps

Grafton City Hospital Data Breach Affects 1,215 Users

Hacker claims to have stolen 40,000 Twitch streamers’ personal info

Hackers Exploit Maximum Severity Flaw in GitLab

Hackers have published Revolut customer data and are demanding a ransom

Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers now exploit max severity GitLab flaw in attacks

Hackers target exposed Vite development servers to steal AWS, Azure secrets

Hit by a data breach? Here’s what you need to do

Hong Kong: Phishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

Hundreds of fake government websites target users in Central Asia

Inside job suspected in Kochi Metro Rail Ltd (KMRL) data breach

Inside job suspected in Kochi Metro Rail Ltd (KMRL) data breach

Irish Revolut Customers Caught Up in Data Breach After Scammers Pose as Government Officials

Irish Revolut users urged to check accounts as scammers threaten to release data

Israel: Ashkelon man accused of infecting hundreds of computers, stealing sensitive data, hijacking webcams

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Kenya cyber attacks up 6% as ransomware nearly doubles globally

LG Pushes Back on Claims That Its Smart TVs Are Spying on Users

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

Man who drove around Singapore with ‘blaster device’ to transmit over 10.5k phishing messages gets jail

Man who drove around Singapore with 'SMS blaster' that sent more than 10,000 phishing messages gets jail

Mantax Otax Targets Android Phones With Spyware and Ransomware

Members of ‘Black Axe’ cybercriminal group extradited from South Africa

Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach

Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Next Level Medical Data Breach Exposes PHI and PII

OpenAI Agent Swarm Hacks RubyGems Package Manager

PaperCut Flaw Compromise Illustrates the Maturing Use of AI By Attackers

Penfold Motors latest car dealer to fall victim to the Storm ransomware group

Personal, Financial Info Exposed in Revolut Data Breach

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

Ransomware attacks in Japan hit record 123 cases in 1st half of 2026

Ransomware gang leaks more than half a million files after Florida DMV hack

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

Revolut blames ‘sophisticated impersonation scam’ for customer data breach

Revolut Confirms Data Breach After Fraudsters Exploited a Real Government Email, Samples Leak Online

Revolut Confirms Data Breach Through Fake Government Requests

Revolut confirms sensitive customer data breach after fake government requests

Revolut Data Breach: Hackers Leak Customer Documents, Demand Ransom Payment

Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do

Revolut data breach as scammers 'used government email' to steal Irish user data

Revolut Data Breach Exposes Passport Copies, KYC Selfies and Full Transaction Histories

Revolut Data Breach Exposes Records After Email Domain Scam

Revolut discloses accidental data breach following government agency email scam

Revolut discloses data breach exposing financial info, passports

Revolut handed customer data to fraudsters using government email account

Revolut hit by data breach after fake government email scam

Revolut in customer data breach after fake Government requests

Revolut Reveals Data Breach Tied to Faked Official Request

Revolut says some customers’ data exposed in phishing attack

Revolut suffers data breach exposing identity and driving licence details

Russian Hacker Group Claims DDoS Attack on Norway’s Parliament Website

Scammers milking Google Play’s Early Access: no reviews, no ratings, no way to spot the deception

'SMS blaster' in car sent over 10,500 phishing messages as man drove around Singapore

South Korea: "Fell Victim to Phishing"...Waiting for Number Suspension Leads to More Losses

Springfield students back in school, cyber attack still under investigation

Stockton Council: Service boss says threat of cyber-attack to council is 'constant and increasingly sophisticated'

Swiss Bitcoin Pay Shuts Down Servers After Data Breach

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

Texas Mutual Data Breach Affects 2k: Medical Information Exposed

The UK government is killing passwords for 23 Million Brits

The website of the Norwegian Parliament was targeted in a hacking attack by Russia

Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns

Twitch ‘Enhancer’ Extension for Chrome Caught Sending Live OAuth Tokens to Russian Bot Service

Twitch extension with 30K installs exposes users’ OAuth tokens

UK government begins killing off passwords for 23 million users

Vengeful Windows exploit researcher reveals his true identity

What we know about the Revolut data breach so far

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

zHealth EHR Data Breach Exposes Medical Information