Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 20th July and 26th July 2026.20th July
271 million Uber Eats and Starbucks records surface on hacker forum: Should you be worried?
Australia: Crypto scam losses of $1.47 million in five days sparks Queensland police alert to new phishing threat
Chinese police repatriate key suspect in phishing and Trojan virus case from Vietnam
Community College of Beaver County (CCBC) Data Breach Exposes Social Security Numbers and More
Craneware confirms data breach after cyberattack
Craneware Confirms Data Breach, Employee Records Among Exposed Data
Craneware reveals cyber attack with employee and customer data stolen
Critical ServiceNow code execution flaw now exploited in attacks
Cruciferra Crypter Uses Process Ghosting to Evade Detection
CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw
Cyberattack hits Coca-Cola's $4 billion dairy brand, suspends US production
Cyberattack pauses Fairlife’s production, working to learn about impact on Webster plant
Data breach hits well-known AI company: ‘Sorry for any disruption’
Don’t run into these ‘Gentlemen’. More on this Ransomware gang
Edinburgh-based healthcare firm 'hit with cyber attack' as hackers steal data
Ernst & Young Data Breach Affects Personal, Financial Information
Ernst & Young data breach exposes personal and financial information of tax clients
Ernst & Young reveals data breach following hack on support system
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended
Fairlife shortage looms after ransomware hits Coca-Cola plants
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
FBI Arrests Florida Man in $220,000 Steam Crypto Theft Case
Governments Weigh Ransomware Payment Bans as Hackers Grow Bolder
Hacker stole from Steam users for years, got caught because he ordered food online
Hacker wipes European country’s entire land registry database, paralyzing real-estate market
Hacker wipes Romania's entire land registry database
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Hackers Are Hiding Invisible Text in Phishing Emails to Fool AI Security Tools
Hackers stole ‘significant’ amount of data from tech firm relied on by thousands of US hospitals and pharmacies
Hackers were inside South Korea's diplomat training system for 9 months
Health tech firm Craneware admits “significant volume” of customer and employee data exposed in cyber attack
Health tech firm Craneware says customer and staff data stolen in cyber attack
Healthcare phishing breach exposes SSNs, medical records for 15 months
Healthcare ransomware attacks up 14% in first half of 2026
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel
Hugging Face breached by autonomous AI agent
Hugging Face confirms breach affected internal datasets and credentials, urges users to take action
Hugging Face Hacked in Autonomous AI Attack
Hugging Face warns an autonomous AI agent hacked its network
Identity-based attacks overtake software flaws as leading ransomware entry point
India: Data breach exposes documents tied to Kudankulam nuclear plant expansion
India says allegedly leaked nuclear plant files pose no safety risk
Information Commissioner Notified After Data Breach Concerns At Former West Sussex County Council Buildings
Italy fines WINDTRE €1.7 million over security flaws behind two data breaches
Jadepuffer: Agentic attack evolves to destroy AI models
JadePuffer Returns With Ransomware Designed to Wipe AI Models
Kenya restores presidential website after cyber attack
Kenya’s Presidential Website Hit by Cyber Incident, Government Says No Data Was Stolen
Kentucky included in settlement with 23andMe following 2023 data breach
LG Monitors Spotted Installing Adware-Like App on Windows PCs
Mythos Didn't Break Your Security Program. Your Exposure Window Could
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
New X phishing scam uses fake login alerts to steal your account
One threat that infiltrated the ANC, Anglo American, Mediclinic, South African Airways, and Pick n Pay
Paidwork breach exposes sensitive data of 23 million user
Paidwork Data Breach Exposes 23 Million User Records, Have I Been Pwned (HIBP) Says
Plugging an LG monitor into a Windows computer installs a potentially unwanted program
Police Chiefs Cite Transport for London (TfL) Hack in Push for Cybercrime Risk Orders
Ransomware attack disrupts fairlife’s US production
Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up
Ransomware detections on Indian SMBs is on the rise
Researchers Build WordPress Exploit Using OpenAI's GPT
Romania races to restore land registry after cyberattack disrupts property market
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Software provider to more than 2,000 US hospitals says hackers stole employee and customer data
South African industrial giant that makes chemicals targeted by one of the world’s most notorious ransomware groups
South Carolina will receive $280,000 in 23andMe settlement after data breach
Thailand: Base-education hacker arrested in Phuket
The Gentlemen deploys new malware to take control of systems before encryption
The New Cyber Frontier: Ransomware Surges as AI Deepfakes Expose Corporate Vulnerabilities
The Odyssey piracy scams surface hours after its theatrical debut
The Rise of Calendar Phishing
The Windows 10 hangover is becoming a security problem
Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
U.S. court seizes $8.37 million in crypto from ransomware negotiator accused of aiding hackers
U.S. Prosecutors Charge Russian Trio in Cybercrimes Causing More Than $62 Million in Losses
United Arab Emirates: Dubai Police Warns Against Online Scams Promising Work and Visit Visas
Unpatched SharkNinja flaw turns vacuum cleaner into a spy, reveals house maps, WiFi passwords
Why Security companies can’t create an invincible Vaccine against Ransomware
WordPress Critical RCE Security Flaw a Threat to Millions of Websites
WordPress urges immediate update: hackers are gaining full control with a critical exploit
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
wp2shell: The Unauthenticated WordPress Exploit That Needs No Login, No Plugins, Just a Vulnerable Core
X users are being hit by fake login alerts: the phishing emails look real
Zero-Day Hack Exposes South Korean Diplomatic Academy to Massive Data Breach
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and
Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 6th July and 12th July 2026, kindly assisted by our partners.
