Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 20th April and 26th April 2026.21st April
6,000+ Apache ActiveMQ Instances Vulnerable to CVE-2026-34197 Exposed Online
Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul
AI tool Vendor compromise leads to Vercel Data Breach
Alleged Adelaide hacker charged over 'cybercrime spree'
Anubis Ransomware Attack Hits ViaQuest and Samuel I White PC
Arbitrum Freezes $71.1 Million in ETH: Decisive Blow Against Kelp DAO Hacker
Arbitrum Freezes KelpDAO Hacker’s $71 Million But Sparks Debate on Centralization
Arbitrum Pretends to Be a Hacker and “Steals Back” KelpDAO’s Lost Funds
Australia: New South Wales (NSW)-based Strata company allegedly breached by ransomware group
Australia: Treasury staffer charged for New South Wales (NSW) government data breach
Bluesky, Fast-Growing X Alternative, Hit by Sophisticated DDoS Attack
Chartered Institute of Bankers of Nigeria (CIBN) Allegedly Hit by 250GB Data Breach
CISA Adds 8 Exploited Flaws to Known Exploited Vulnerabilities (KEV), Sets April-May 2026 Federal Deadlines
CISA Warns Axios npm Package Was Compromised in Major Supply Chain Attack
DraftKings Hacker Who Helped Steal 600K Sentenced to 30 Months
Dutch consumers launch mass lawsuit against Odido over data breach affecting 6.2 million customers
Fake TikTok Downloader Extensions Infect 130,000 Browser Users
Florida man pleads guilty in ransomware conspiracy targeting U.S. companies
Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers
Lovable AI App Builder Reportedly Exposes Thousands of Project Data via API Flaw
Malicious OAuth Apps Turn GitHub Issue Notifications Into Phishing Lures
Mastodon DDoS Attack Disrupts Flagship Server Temporarily
Nepal: National Cyber Security Centre warns public against rising ransomware attacks
Nepal Government Issues Ransomware Alert Amid Rising Cyberattacks
New PureRAT Campaign Uses PNG Files To Conceal Fileless Payloads
New ransomware group The Gentlemen hits 300+ victims
New Top-Level Domains (TLDs) and phishing risk: What security teams should know
North Korea-Linked UNC1069 Hacks Crypto Pros via Fake Meetings
Oman: E-commerce scams account for 85% of financial phishing
Personal Data Exposed on ANTS Portal, French Authorities Investigate
Poste Italiane, Postepay Fined €12.5 Million for Unlawful User Data Processing
Seiko USA Data Breach: Hackers Steal Customer Database, Issue 72-Hour Ransom Ultimatum
SideWinder Targets Government Webmail With Bogus Chrome PDF Viewer and Zimbra Phishing Clone
The Gentlemen: The Rapid Rise of a Sophisticated New Ransomware Threat
Tycoon 2FA takedown: Phishing ecosystem shifts, competitors rise
Vercel data breach exposes South Africa developer community
20th April
10 Biggest Data Breaches in Germany
52 Million-Download protobuf.js Library Hit by RCE in Schema Handling
58% of Organizations Spend Over 10 Hours a Month Securing AI-generated Code
₹165 Crore Phishing Empire Crushed: FBI Busts Global Cyber Fraud Network
$221K Lost In Ethereum Phishing Attack What Went Wrong
2024 NHS Ransomware Attack Still Causes Healthcare Disruption, 122 Patient Safety Incidents Recorded
2026’s Breach List So Far: FBI Hacked, 1 Billion Androids at Risk, 270 Million iPhones Vulnerable
Add Hasbro to the growing list of defendants facing a class-action lawsuit over a data breach
After Tycoon 2FA Takedown, MFA‑Bypass Phishing Techniques Spread Across New Platforms
AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace - hacker seeking $2 million for stolen data
AI platform ATHR makes voice phishing a one-person job
Ameriprise Data Breach Affected Nearly 48,000
Ameriprise Data Breach Impacts More Than 47,000 People
Amtrak Data Breach Exposes 2.1 Million Records, Reports Suggest Larger Leak
Anthropic Model Context Protocol (MCP) Design Vulnerability Enables RCE, Threatening AI Supply Chain
App host Vercel says it was hacked and customer data stolen
Apple Account Change Alert Emails Exploited in New Phishing Campaign
Apple account notifications abused for iPhone purchase phishing scams
Apple's account change notifications send phishing emails
Arizona & Texas Clinics Notify Patients About Ransomware Incidents
Arnold Clark Faces Data Breach Class Action In Scotland
ATHR Fuels Large-Scale AI Vishing and Phone Phishing Attacks
Attackers Exploit DVR Command Injection Flaw to Deploy Mirai-Based Botnet
Attackers Turn QEMU Into a Stealth Backdoor for Credential Theft and Ransomware
Attackers Exploit Windows Zero-Days to Bypass Microsoft Defender
Australia: Don’t be tricked by phishing scams
Australia: New South Wales (NSW)-based Strata Republic allegedly breached by Kairos ransomware group
Bluesky blames app outage on ‘sophisticated’ DDoS attack
Bluesky Disrupted by Sophisticated DDoS Attack
Booking.com data breach customers fall prey to Reservation Hijacks
Brit pleads guilty amid Scattered Spider hacking spree claims
British Hacker Admits Stealing Millions in Virtual Currency From Targeted Companies
British hacker tied to Scattered Spider campaign pleads guilty in $8 Million scheme
British Hacker Tyler Buchanan Pleads Guilty to $8 Million Hacking Scheme in US
British Scattered Spider Hacker Pleads Guilty in the US
British Scattered Spider hacker pleads guilty to crypto theft charges
Brute-Force Authentication Attacks Targeting Network Devices On The Rise
Caribbean Medical Center Data Breach Affects 92,000
Champhunt Data Breach Exposes Over 224,000 User Records
China's Apple App Store infiltrated by crypto-stealing wallet apps
Chrome Privacy Concerns Rise as Expert Warns of Fingerprinting Risks
Cisco Patches Critical Identity Services Engine (ISE) Vulnerabilities Allowing Remote Code Execution Attacks
Critical Anthropic Model Context Protocol (MCP) Vulnerability Enables Remote Code Execution Attacks
Critical Gardyn Smart Gardens Vulnerabilities Let Attackers Control Devices Remotely
Crunchyroll slammed with lawsuit as millions of users left exposed in data breach
Crypto Exchange Grinex Blames Western Spies for $13m Theft
Crypto industry rocked by $290 Million Kelp DAO exploit, North Korea's Lazarus Group suspected
Crypto infrastructure company blames $290 million theft on North Korean hackers
Cyberattack at French identity document agency may have exposed personal data
Data breach at French National Agency for Secured Documents (ANTS) portal exposes personal user information
Drivers eligible for Arnold Clark cyber attack compensation claim
Dutch ecommerce site Bol.com investigates claims of a data breach
Dutch healthcare tech giant ChipSoft confirms patient records stolen
“Essentially invisible:” How hackers 'trojan-horsed' QEMU virtual machines to bypass security and drop ransomware
Everest Group Breaches Frost Bank, Citizens Bank, Tokoparts, Complete Aircraft Group, Umiles, Nutrabio
Fake TikTok Downloaders on Chrome and Edge Spying on 130,000 Users
Formbook Malware Campaign Uses Multiple Obfuscation Techniques to Avoid Detection
France’s ANTS ID System website hit by cyberattack, possible data breach
Fraudulent Phishing Scams Continue to Target Wisconsin Division of Motor Vehicles (DMV) Customers
Gravesend Panic Room owners put in 'difficult position' following cyber attack
Hacker “Jeffrey Epstein” leaks 400K records from Netherlands' largest webshop
Hackers Abuse Apple Alerts to Bypass Spam Filters
Hackers Are Using Apple Account Notifications for a Phishing Campaign and Malware Attack
Hackers Exploit AppDomain Hijacking To Weaponize Intel Utility
Hackers Exploit CVE-2024-3721 To Deploy Nexcorium Malware On TBK DVRs
Hackers exploit Vercel’s trust in AI integration
Hackers Use FUD Crypt To Deliver Microsoft-Signed Malware With C2 Capabilities
Holidaymakers issued suspicious message alert after major data breach
Ice Open Network hit by an insider data breach, emails, and 2FA exposed
Indian Agency Arrests Key SIM Card Supplier of a Broader Cyber Fraud Network
Inside the Booking.com Data Breach - Should You Be Worried?
Instituto Maria Schmitt Investigates Email Inbox Data Breach
Investigation into Blue Cross Blue Shield of Montana data breach moves forward
Iran’s Ministry of Intelligence and Security (MOIS) Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas
Italian regulator fines national postal service orgs $15 million for data privacy violations
iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution
JanaWare Ransomware Targets Turkish Users via Adwind RAT
JanaWare Ransomware Hits Turkish Users via Tailored Adwind RAT
Justice Department seizes $10 million from ransomware conspirator
KelpDAO suffers $290 million heist tied to Lazarus hackers
Los Angeles County Office of Education (LACOE) Investigating Potential Data Breach
Lovable denies data breach, says public settings are ‘intentional’
Lovable denies mass data breach
Massive police data breach raises national security alarm in South Africa
Mastodon says its flagship server was hit by a DDoS attack
Microsoft Defender Flaws Exploited on Windows, Two Left Unpatched
Microsoft, Meta, Google shamelessly track you even if you opt out
MiningDropper Campaign Targets Android Users with RATs and Data-Stealing Apps
Morocco’s Al Barid Bank Denies Data Breach, Says Customer Accounts Remain Secure
National Cyber Security Centre (NCSC) Outlines Coordinated Plan to Boost National Health Service (NHS) Cyber Resilience
Nepal: Cyber security advisory issued against ransomware attacks
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT
New Malware Campaign Delivers Gh0st RAT With CloverPlus Adware
Next.js Creator Vercel Hacked
Nigeria: Confusion as Corporate Affairs Commission (CAC) suspends portal operations over cyber attack
NIST Shifts to Risk-Based National Vulnerability Database (NVD) Model as Common Vulnerabilities and Exposures (CVE) Submissions Surge 263% Since 2020
North Korea hackers blamed for $290 Million crypto theft
Over 200 Japanese firms paid ransomware attackers, 60% fail to recover data
Over 800 Android Apps Targeted in PIN-Stealing Trojan Campaign
Payouts King ransomware abuses QEMU for hidden VMs and backdoors
Phishing attack warning issued following Booking.com data breach
Phishing scams: Wisconsin Division of Motor Vehicles (DMV) customers targeted, officials say
Popular travel booking site confirms data breach: Here’s what to know
Public Notion Pages Expose Profile Photos and Email Addresses of Editors
QEMU Hijacked as Stealth Backdoor for Credential Theft, Ransomware
Ransomware Attack on Healthcare IT Solutions Provider Impacts Dutch Hospitals
Ransomware’s Next Phase: From Data Encryption to Business Extortion
Read notice on the website that FBI has taken down for stealing millions from internet users across the world
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination Operational Technology (OT) Systems
Researchers Link Iran’s Ministry of Intelligence and Security (MOIS) To Coordinated Hacker Persona Operation
Researchers Say Iranian Ministry of Intelligence and Security (MOIS) Uses Multiple Hacker Personas for One Coordinated Cyber Campaign
Revolution Dancewear Discloses Data Breach Compromising Personal Info for 5,841 Individuals
Scammers are weaponizing Apple’s own notifications in a dangerous new phishing attack - don’t fall for this
SecretarÃa de Seguridad del Estado de México Data Breach
Seiko USA website defaced as hacker claims customer data theft
Seiko USA Website Defaced as Hackers Claim Data Breach
SEO Poisoning Attack Abuses Microsoft Binary To Deploy RMM Tools
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
Standard Bank data breach fallout deepens
Study finds ransomware payments largely ineffective for Japanese firms
The Chartered Institute of Bankers of Nigeria Data Breach
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
The Model Context Protocol (MCP) Disclosure Is the AI Era’s ‘Open Redirect’ Moment
Third-party AI hack triggers Vercel breach, internal environments accessed
Today's Ransomware evolution neutralizes current incident response strategies
Top 3 Cyber Insurance Incident Claims
Tycoon 2FA Loses Dominance as Phishing Attacks Surge Across Emerging Platforms
Tycoon 2FA relinquishes crown to similar PhaaS platforms
UAE Cyber Security Council Warns 1 in 4 Public Files Contain Sensitive Personal Data
Vercel: Data breach exposes customer credentials
Vercel Breach Linked to Context.ai, ShinyHunters Says It’s Not Involved
Vercel Breach Originated from an Employee’s AI Tool
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
Vercel breached via compromised third-party AI tool
Vercel CEO blames highly sophisticated AI for speeding up the massive internal data breach
Vercel Confirms Breach as Hacker Demands $2 Million Ransom
Vercel Confirms Data Breach - Hackers Claim Access to Internal Systems
Vercel Confirms Data Breach Linked to AI Tool, Hackers Demand $2 Million Ransom
Vercel confirms data breach linked to third-party AI tool: All you need to know
Vercel Confirms Major Security Incident as Hacker Claims $2 Million Ransom Demand
Vercel Confirms Security Breach as Hacker Demands $2 Million and Claims to Sell Internal Access
Vercel Data Breach Exposes Customer Credentials After AI Tool Compromise
Vercel Data Breach Linked to Context AI Hack Reportedly Exposes Information
Vercel Data Breach Linked to Earlier Context.ai Compromise
Vercel Employee's AI Tool Access Led to Data Breach
Vercel hacked after fatal OAuth misstep: granting “Allow All” permissions
Vercel hacked, hacker using ShinyHunters name to sell data for $2 million
Vercel Incident Linked to AI Tool Hack, Internal Access Gained
Vercel Reports Data Breach Amid Claims of Compromised Internal Infrastructure
Vercel Security Breach: Hacker Demands $2 Million as Crypto Projects Scramble to Secure Keys
Watch out, hackers are abusing Apple account notifications to distribute malware, steal money and data
'We've identified a security incident': Vercel breach confirmed after hackers claim stolen data for sale online
What the ransom note won't say
What to do if you clicked a phishing link in a business email
Why proactive cybersecurity beats ransomware threats
Why security experts believe we should manage software flaws like a critical illness
ZionSiphon Launches Sabotage Attacks On Israel’s Water Infrastructure
ZionSiphon Malware Targets Water Infrastructure Systems
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 6th April and 12th April 2026, kindly assisted by our partners.
