Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.



Tuesday, 18 August 2026

Ransomware Operator Claims - Week 33 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 10th August and 16th August 2026, kindly assisted by our partners.

DBD discovered and researched 255 Ransomware Victims over 48 Countries and Islands claimed by 46 Data-Leaking Ransomware Operators, including 5 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 17 August 2026

Data Breaches Digest - Week 34 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 17th August and 23rd August 2026.


20th August

9 Million Images Exposed by Facial Recognition Platform

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

77 Firefox Extensions, One Wallet-Draining Operation Abusing

8,539 reasons to rethink how vulnerabilities get patched

AI data giant Alation confirms cyberattack

AI is making fraud harder to spot and identity harder to prove

AI-Driven Ransomware Attack Used Claude Code to Steal Passwords, Hijack VPNs

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Amazon’s Order Email Privacy Change Creates a Potential Phishing Trade-Off

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

Australia: Personal data of 2 million customers exposed in Oz Hair and Beauty breach

CareCloud confirms massive data breach after 3.7 Million patients’ records stolen - What we know

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

CISA warns of hackers exploiting critical MLflow vulnerability

Citrix urges admins to patch new NetScaler flaws as soon as possible

Content Delivery Network (CDN) Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Critical Zimbra RCE flaw now actively exploited in attacks

Cybersecurity Hiring Has Gone Global: Why U.S. Companies Are Looking Beyond the Domestic Talent Pool

Def Con Attendees Targeted by Persistent Phishing Campaign

Don’t Put That in Writing: When Privacy Tools Become Evidence of Concealment

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

Faulty towers: Quest hotel chain discloses third-party customer data breach

Feds Warn Hackers Now Use AI to Write Exploits Targeting US Water Systems’ Siemens PLCs

Hacker Leaks 1,033 Stripe Merchant API Keys and 688K Customer Records

Hackers poison arrayref Rust crate to push infostealer malware

Hong Kong: 150k people affected by Canvas data breach

Hong Kong: More than 153,000 students, staff affected in Canvas data breach

How Medusa Ransomware Attacked 500+ Critical Companies

Industrial Control Systems (ICS) Operators Warned of AI-Driven Attacks on Siemens PLCs

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Kaspersky warns that popular cloud platforms have been used in over 390,000 phishing attacks

Kazakhstan: Suspects involved in phishing schemes to steal personal data detained in Astana

Korea's AI Anti-Fraud Platform Blocks $48 Million in Voice Phishing Losses

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

Medusa ransomware has affected over 500 critical infrastructure organizations

Mid-market firms account for 73% of ransomware victims

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

National Cyber Security Centre (NCSC) Urges Stronger Controls for Agentic AI Systems

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

New Manic Android malware can exfiltrate data through nearby devices

Oz Hair and Beauty Confirms Customer Data Breach, Personal Information Accessed

Oz Hair and Beauty Data Breach Exposes Customer Information

Phishing scam targets drivers with fake DVLA fine threats

Quest Apartment Hotels confirms customer data breach linked to third-party vulnerability

Researchers find a loophole that lets expired credit cards make unauthorized payments

Round 2 of the Target data breach? Hackers threaten to leak data

South Korea: AI Helps South Korea Stop $48 Million in Voice-Phishing Losses

South Korea: AI-based anti-phishing platform prevents over $47.6 million in financial damage

South Korea: Financial Services Commission (FSC) uses AI-based antiphishing platform to prevent 66.4 billion won in losses since last year

South Korea: Phishing Ring That Defrauded Woman in Her 70s of KRW 350 Million by Demanding Account Balance Be Converted to Checks Apprehended

South Korea: Voice Phishing Information Sharing Blocks 66.3 Billion Won in Damages in Just Nine Months

South Korea's Voice Phishing Prevention Platform Delivers $47.6 Million in Blocked Losses Over Nine Months

Student sues Genesee County in Michigan to expose Flock records

Suspected Data Breach Targets South Korean Presidential Officials in Certification Hack

T-Mobile security team cuts the cord in Seattle to thwart Chinese cyber intrusion

The best and worst AI for your privacy, ranked - and how each handles your data

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Updated ToxicPanda Variant Targets 140+ Banking and Crypto Apps

US agencies warn of AI-powered attacks on Siemens industrial controllers

US charges 17 Iranian hackers over 31-terabyte academic data theft

US charges 17 Iranian hackers over years-long IP theft campaign

US Defense Contractors Admit Their Rising Cybersecurity Maturity Model Certification (CMMC) Scores May Not Be Accurate

US says hackers are targeting vulnerable water systems with the help of AI

When Attackers Can Spin Up a Phishing Site in 90 Minutes, Your Blocklist is Already Stale

Why "Shady AI" is Security's Next Big Governance Problem

Xfinity routers are now motion detectors able to tell on you to the police

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Zombie Cards: Researchers Show Expired Visa Cards Can Still Pay for Your Groceries

19th August

73% of ransomware incidents hit mid-market companies amid growing third-party and AI risks

Agencies issue update on Medusa ransomware activity

Amazon’s new order confirmation emails seen boosting phishing risk

Apple American Group Data Breach: Financial and Health Information Exposed

Are You One of 3.8 Million Affected? A Major Health Data Breach Expands

Australian apartment hotel Quest reveals customer data breach after hackers accessed database

Balonx Phishing-as-a-Service (PhaaS) Steals Bank OTPs in Real Time While AI Calls and Android RAT Target Victims

Balonx Phishing-as-a-Service (PhaaS) Targets 20+ Mexican Banks With Real-Time MFA Bypass, Android RAT and AI Vishing

Banks look for fraud signals in customer behavior

Bloom's Bus Lines Data Breach Impacts 1.4k: SSNs Exposed

CareCloud confirms 3.7 Million patients had their medical records stolen in data breach

CareCloud Data Breach Impact Grows to 3.7 Million Individuals

CareCloud Data Breach Impact Jumps to 3.7 Million as HHS Updates Exposure Figures

ChatGPT’s new feature could give infostealers a map of your Mac activity

China-Linked Hacker Shows AI Capabilities in APAC Attack

CISA Updates Advisory on Medusa

CISA Updates Joint Advisory on Medusa Ransomware

CISA Warns of Medusa Ransomware-as-a-Service Attacks Over 300 Organizations

ClarityCheck Data Breach Exposes 9 Million Private Image Files

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Cl0p’s New Windchill Web Shell Isn’t Generic - It Was Built to Know Exactly Where the Data Lives

Cloudflare Workers Spectre Attack Leaks JSON Web Token (JWT) From Co-Located Worker at 12 Bits/Second

Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

Critical Remote Code Execution (RCE) flaw in Windows Internet Key Exchange (IKE) Extension now actively exploited

Crypto Scammer Uses Claude Code to Screen 100,000+ Phone Numbers in Phishing Operation

Cyberattack forces University of Texas (UT) San Antonio to delay start of fall semester

Cyberattack Hits Ukraine Agency Ahead of Major Asset Tender

D-Link Fixes 18 Security Flaws in DWR-M961 Router Web Interface

Delta targeted in Wi-Fi phishing attack

Department of Justice (DOJ) Charges 8 New Iranian Hackers Tied to IRGC in Global University Data Theft Scheme, Totaling 17 Members of the Mabna Institute

Electronic health record company CareCloud says 3.7 million people affected by breach

Expanded CEVA Logistics Data Breach Exposes More Bol Customer Records

Exploits are emerging faster than patches

Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps

FBI warns hackers are targeting Siemens PLCs amid fears over Iran-linked US water attacks

FBI, CISA, HHS update Medusa ransomware advisory, detail RaaS affiliate model, exploited flaws and attack tools

Fintech giant Stripe faces alleged data breach as customer information leaks

France: The tax administration was targeted by a new cyber attack

France Probes Major Tax Authority Data Breach

France’s Tax Agency Hack Exposes Data of 678,000 Taxpayers

Frontier AI compresses cyber attack timelines. Can Singapore's defences respond at machine speed?

Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Gotta catch ‘em all: Pokémon Center caught in CEVA Logistics breach

Grandoreiro Resurfaces in Mexico With New DLL Sideloading Campaign

Hacker arrested after allegedly planting malware in dozens of Israeli companies

Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix

Hackers compromise 14,500 Dahua web cameras in 35-day campaign

Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

Hackers Turn Thousands of WordPress Sites Into StopAndProtect Malware Infrastructure

Hackers Use Fake Claude Guide to Steal Mac Passwords and Hijack Crypto Wallet Apps

Healthtech firm CareCloud data breach impacts 3.7 million patients

Heights Finance data breach impacts over 700,000 customers

Hexaware Tech says no evidence of systems or customer data breach after leakage claim

How to Spot Amazon Phishing Scams After the 2026 Email Changes

'Huge human error' caused 'biggest ever' cyber attack on charity sector with millions warned their data may have been stolen

IBM’s 2026 Data Breach Report: Houston, We Have A Problem

Identity Theft Statistics 2026 - Most Common Types and Victims

India: Samagra Data Breach Raises Security Concerns Over 8 Crore MP Citizens’ Records

Information Commissioner’s Office (ICO) Urges Police to Improve Data Governance in Facial Recognition Rollouts

Japan's Privacy Regulator Issues Administrative Guidance to KDDI Over Data Breach Affecting 12.23 Million Users

Latvian officials resign after cyberattack exposes data on 1.2 million people

Lawsuit says Lennar data breach exposed customer Social Security numbers

Leaked Flock AI tool allows cops to search for suspects by driving habits

Lennar Mortgage data breach exposes personal information of more than 60,000 Texans

Logitech subsidiary, beloved by Twitch streamers, allegedly breached

MacSync Stealer Uses 30+ Rotating Domains to Steal macOS Credentials and Exfiltrate Data

Major Australian hotel chain Quest issues urgent warning to customers after data breach

Major crypto data leak affects 200K customers in Bits of Gold breach

Malware-as-a-Service (MaaS) Campaign Combines ClickFix, ErrTraffic and Cruciferra

Medicare Patients Targeted in New MyChart Phishing Scam, University Health Issues Warning

Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion

Medusa ransomware gang has hit over 500 organizations, CISA warns

Medusa ransomware group attacked more than 500 victims since 2021

Medusa ransomware hit over 500 critical infrastructure organizations

Medusa Ransomware Surpasses 500 Victims as Attackers Exploit New Flaws at Record Speed

Meta glasses and Flock cameras resurrect privacy fears we've been forced to accept

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft patches a flaw that forced Copilot to give away its weaknesses

Mungo Homes Data Breach Exposed SSNs and Medical Information

New White House Cyber Ops Order Appears to Authorize Digital Privateering

NHS worker sent patient record screenshot to partner

NSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technology

One In Three Australia and New Zealand (ANZ) Organisations Still Paying Ransomware Demands Despite High Failure Rate

OpenAI Halts Development of Next-Gen AI System Following Unauthorized Server Breach

OpenAI Pauses Frontier Reinforcement Learning (RL) Training as It Tightens Defenses Against Unsafe AI Behavior

OpenAI puts major frontier AI training run on hold over cyber risks

OpenAI slows down training after its AI carried out hack

OpenAI Tightens AI Safeguards Following Hugging Face Incident

OpenAI's Models Hacked Hugging Face. Every Agentic System Needs a Hacker in the Loop

Origin Energy data breach linked to former call center employee in Manila

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware

Password spraying attacks surge 155x as hackers exploit MFA gaps

Personal information stolen in data breach last year at Autism Services of Saskatoon

Phishing Campaigns Target Hotels With Fake Guest Requests And Booking.com Notifications

Pokémon Center customers hit with data breach and canceled orders

Pokemon Center Cyber Attack Leads To Canceled 30th Anniversary Orders And Stolen Info

Pokémon Center in the UK and Germany hit with the same data breach suffered by Valve's Steam hardware

Pokemon Center Store Affected By Data Breach In UK And Germany

Quest Apartment customer details compromised in data breach

Quest Apartment Hotels confirms data breach

Quest Apartment Hotels hit by data breach; customer data accessed

Quest Apartment Hotels investigates data breach

Quest Apartment Hotels investigates data breach linked to third-party vendor flaw

Quest Builders Group Data Breach Exposes SSNs

Ransom Busters: The new trap for ransomware victims

Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion

Ransom Payments Surge 176% to $1.88 Million Driven by Data Exfiltration Attacks

Ransomware Affiliate Poses as Recovery Firm to Re-Extort Victims After Data Theft

Ransomware disproportionately targets medium-sized firms, straining customer relationships

Ransomware Group Strikes Again

Ransomware Hackers Pose as Recovery Firm and Demand Up to $60,000

Ransomware Has Changed and Your Defenses Need to Change With It

Ransomware victims being duped with fake Ransom Buster Email Communication

RAVEN Steals Entire Elasticsearch Databases and Rebuilds Backdoors After Defenders Delete Them

Reducing Ransomware Risk Across Internal and Third-Party Environments

Rogue ransomware affiliate poses as recovery firm to steal payments

Sakura Internet hack exposes data of up to 1.36 million accounts

Search for accountability begins after massive data breach in Latvia - Road Traffic Safety Directorate (CSDD) chief points to Tet

Security Leaders Discuss Azure Exfiltration Campaign

See's Candies Data Breach Exposes Sensitive Customer Information

Server Mistake Exposes StopAndProtect’s Hacked WordPress Network

SGMC Health Alerts Patients to MyChart Phishing Scam

Shell, Philips and General Electric (GE) Among 50 Firms Affected by Data Breach

SilkParasite Espionage Campaign Targets Central Asian Governments with Five New RATs

Silver Summit Medical Corp. Data Breach Compromises PHI and PII

Singapore: Beware phishing e-mails that offer fake Central Provident Fund (CPF) refund payouts

Singapore: Inside the Phishing Scam That Could Drain Your Retirement Savings

Slovakia discovers Russian backdoor in NERO R-ONE speedometers

Source code potentially compromised in Australian game developer data breach

South Korea: Voice Phishing Gang Relocates to Kazakhstan, Arrested

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network

The Pokémon Company Cancels 30th Anniversary Card Orders Following 'Cyber Incident,' Warns of Customer Data Breach

The Pokémon Center Was Hit By Same Data Breach As Valve, And Customer Orders Are Being Cancelled

The University of the West Indies (The UWI) investigates report of possible ransomware activity

Turner Construction Data Breach Impacts Thousands: SSNs Exposed

UK Fraud Cases Hit Record High in 2026

University of Texas at San Antonio (UTSA) Delays Classes After Cyber Attack

University of Texas (UT) San Antonio Shuts Systems, Delays Classes After Cyber Incident

US Charges 17 Iranian Hackers Over Theft of 31.5TB of Academic Data

US charges Iranian hackers over $3.4 billion intellectual property theft

US charges Iranians for sprawling hacking campaign on government agencies, universities

US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

Using Device Posture and Login Signals to Distinguish Employees From Attackers Accessing Corporate VPNs

Vermont education officials face sophisticated phishing scheme this summer

When the AI Goes Rogue: Who Goes to Jail - and Who Pays?

Your Comcast router doubles as a motion detector now - and a potential police informant

18th August

3C Care Systems Data Breach: 100GB of Patient Data Reportedly Stolen

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

27 Million records exposed: hackers target Microsoft Power Pages in massive data heist

678,000 People Hit in French Tax Authority Data Breach

A hollowed out data layer is making CISOs fly blind into AI attacks

AI drives 36% surge in disclosed vulnerabilities; yet two-thirds of ransomware deployments still start with compromised credentials

AI Models Escaped Test Environments and Hit Real Targets

Akira Ransomware forces victim devices into Safe Mode to evade Security detection

Apple Patches Code Execution and Kernel Memory Flaws in iOS 26.6.1 and macOS 26.6.2

Apple Pays Sentry Founder $150,000 for Private Cloud Compute Vulnerability

Apple Warns Users in 110 Countries of Mercenary Spyware as iPhone Alerts Get Harder to Miss

Apple's iOS 26.6.1 patches 29 security flaws - here's why you'll want to install it

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets

Attackers turn to AI for help identifying files worth stealing

Autonomous AI Cyber Attack on Taiwan Linked to Suspected Chinese Hackers

Back-to-school cyberattack locks 42K students out of Texas university systems days before classes begin

Berlin cuts two state ministries off government network after security breach

Bluesky says its recent outage was caused by another DDoS attack

BTMob Uses Custom Phishing Apps to Turn Android Users Into Remote-Controlled Fraud Victims

BTMob Uses WebSocket C2 for Real-Time Android Command Execution and Data Theft

C2Looper Backdoor Uses GitHub C2 and Shellcode Injection to Establish Ransomware Footholds

Cameron Regional Medical Confirms Ransomware Attack

CG Power reports suspected cyber attack on IT system, core operations unaffected

CISA confirms 2025 Windows Task Host flaw exploited by ransomware groups

CISA Confirms Windows Task Host Flaw Used in Ransomware Attacks

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

CISA Warns of Critical Ray RCE Flaw Exploited in Active Attacks

Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases

Clop created custom web shell for Windchill data theft attacks

Comcast adds motion sensing to millions of its newer routers, with a privacy catch

Comcast turns your Xfinity WiFi into a home motion detector

Copilot Exposed Its Own Vulnerabilities When Prompted

Courts Face New Threat as Litigant Uses Hidden AI Prompt Injection in Filings

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

Critical GitLab flaw lets hackers delete or rewrite repositories - patch now

Cyber Attack Hits Northern California City of Suisun and Disrupts Public Services

Cyber Incident Disrupts Student Services at University of Texas (UT) San Antonio

Cybercriminal claims massive data breach at French education ministry

Data of 1.2 Million people, 200,000 firms stolen in Latvia cyber attack

‘Day by Day’ for Suisun City, California, After Cyber Attack

Duo rejects mediation as South Korea data breach suits escalate

Enterprise Applications Carry 4.31x More Critical and High Vulnerabilities

Fake DMs, phishing & crypto: How hackers are turning high-profile X accounts into traps in India

Famous hacker caught with false plates in Romania’s mountain resort of Sinaia

FBI Pegasus Records Expose a Blind Spot in US Spyware Oversight

Florida woman files class action against homebuilder over data breach

France suffers from unprecedented cyber attack wave, with one hacker supposedly behind it all

French Authorities Issue Urgent Warning Amid Spike In Sophisticated Phishing Scams

French Ministry Data Breach Prompts Fresh EU Privacy Concerns

French tax authority breach exposes data of 678,000 people and businesses

French Tax Authority Data Breach Exposes 600,000+ Users’ Personal Tax-Related Data

French Tax Authority Data Breach Hits 678,000 Taxpayers and Firms

French Tax Authority Data Breach Impacts 678,000 Individuals and Businesses

Frontier AI Models Take Offensive Actions Against Real-World Systems During Cyber Tests

GEEKOM Driver Malware Contacts Domain Previously Associated With Asruex C2

GitLab Critical Vulnerability Lets Unauthenticated Attackers Modify or Delete Projects

Hacker Behind France’s Tax Authority Breach Now Claims 345+ Million Lines From the Education Ministry

Hacker Claims 3.6 Million Azure Records Stolen From McDonald’s, Vodafone and Others

Hacker Claims 3.64 Million Employee Records Stolen From Azure

Hacker claims millions of records stolen from corporate Azure tenants

Hacker claims to have stolen millions of Azure customer records from McDonald’s, Vodafone, Kyndryl, and others - here's what we know so far

Hacker sells McDonald’s and Vodafone records stolen from Azure

Hackers claim BMW ransomware attack, leaking hundreds of motorcycle documents

Hackers Expose Data of 1.2 Million Heights Finance Customers

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

Heights Finance data breach: What customers need to know

Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials

JWR Phishing-as-a-Service Kit Uses WebSockets and AES to Run Real-Time Banking Fraud

JWR Phishing-as-a-Service Targets Banking Customers Across Four Countries

Largest parcel courier company in South Africa allegedly hit by cyberattack

Latest phishing scam targets Medicare patients, University Health warns

Latvian authorities reported a major cyber attack, during which the data of 1.2 million individuals and 200,000 companies were stolen

Law Firms Increasingly Targeted By Ransomware/Vishing Attacks

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

MessiahGPT Criminal AI Service Advertised on BreachForums

Microsoft Azure data breach? Over 3.6 million employee records allegedly stolen, check if you are one of them

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Microsoft starts removing WMIC tool used by cybercriminals

Mid-Market Firms Are Ransomware’s Most Targeted

Midwest Spine and Brain Institute (MSBI) Data Breach Exposed PHI and PII Including Social Security Numbers

Millions of stolen records allegedly dumped online by mystery "Hatman" hacker - McDonalds, Vodafone and more see Microsoft Azure records stolen

More than 200 victims of Medusa ransomware identified over the last year, CISA says

NASA Ground Control Software Flaw Enables Unauthenticated Commands

New data reveals 96% of Americans receive at least one scam call, email or text every week

New TWINLOOT Malware Steals Windows Passwords Via Fake Lock Screen

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

OpenAI institutes new safeguards after Hugging Face breach

OpenAI pauses frontier AI training as models "outstrip pace of safety," says CEO and founder Sam Altman

OpenAI tightens defenses after AI agents breach research environment

Operation ASTERIX Processes 885,000 Phone Numbers to Find Crypto Users for Targeted Fraud

Origin Energy Data Breach Linked to Former Accenture Employee in Manila

Origin Energy hack traced to Accenture's Manila call centre

Patient data potentially compromised in alleged dental clinic data breach

Personal files taken in Buford accounting firm data breach

Phishing-Resistant MFA: How It Works and How to Deploy It Without Disrupting Your Users

Phone number leaked in the Bloctel breach? Here’s what to do

Pokémon Center: Data breach affects customers in Britain and Germany

Pokémon Center Confirms Data Breach - Hackers Stole Customers’ Personal Data

Pokemon Center customers in UK and Germany affected by third-party data breach

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center Data Breach Exposes Customer Names, Addresses and Order Details

Pokémon Center Data Breach Exposes Customers’ Personal and Order Data

Pokémon Center notifies UK and Germany customers of data breach tied to shipping partner, cancels some orders

Product Lifecycle Management (PLM) Zero Day Flaw Exploited by Clop in Massive Data Breach

Projextor Hides Malware Inside the Same Electron Framework Used by Popular Desktop Apps

Quishing: a popular alternative to traditional phishing and how businesses can close the gap

'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

Ransomware groups have stopped locking your clients’ files. Now they just steal them

SafePal data breach exposes nearly 40,000 users' information - is a hardware wallet less secure than a spare iPhone?

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal patches order-tracking flaw after data breach affects nearly 40K customers

SF Express warns of phishing texts as Hong Kong users receive failed delivery messages

Shadow hVNC Lets Hackers Operate a Second Windows Desktop Invisible to the Victim

Shell probes data breach after Clop claims 90GB data theft

ShinyHunters claims RingCentral breach, says 620GB of data stolen

South Korea: Four in five data breach cases go unsolved as cyberattacks surge

Suntree Internal Medicine Data Breach Impacts 9.8k Patients: PHI Exposed

Suspected Chinese Hackers Turn VMware vCenter RCE Into Root Backdoors and ESXi Ransomware

Suspected cyber attack on dozens of Israeli companies

Sweetwater Data Breach: Social Security Numbers Exposed

The hackers are coming for Africa’s critical infrastructure

“TheHatman” Is Selling Millions of Stolen Employee Records From McDonald’s, Vodafone, Tata, Wyndham

The Identity Your IAM Program Forgot: Why Non-Human Identities Keep Causing Human-Scale Breaches

Third-Party Breach Exposes Pokémon Center Customer Data

Threat Actors Use Claude Code, Codex and DeepSeek AI to Power Cyberattacks

Three-quarters of Ransomware Attacks Target Mid-Market Firms

TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

UK Legal Regulator Raises AI Misuse Concerns

UK Phishing Scams Surge 140%: Royal Mail and PayPal Top List of Most Impersonated Brands

Ukrainian software developer faces 12 years in Swiss ransomware trial

University Medical Center Utrecht (UMC Utrecht) reports data breach in guesthouse reservation system

University of Texas forced to take systems offline in San Antonio after cyberattack

VMware Syslog Path Traversal Becomes Root RCE, Persistent SSH Access and ESXi Ransomware

When AI Causes the Loss, Which Insurance Policy Actually Pays?

Why Standard Security Can't Stop AI-Powered Phishing and Digital Fraud

Why the $292 Million KelpDAO Bridge Hack Did Not Affect Bitcoin’s Network

Windows Task Host flaw now exploited by ransomware gangs

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

Wiz’s AI hacks Snowflake: the new normal in cyber defense

17th August

4 in 5 ransomware attacks due to compromised identities

40,000 Impacted by SafePal Data Breach

680,000 Impacted by French Tax Authority Data Breach

A simple video call can compromise millions of Android phones via a Unisoc modem flaw

After Trezor, SafePal reveals data breach affecting nearly 40,000 customers

Akira Ransomware Uses Safe Mode to Bypass EDR

Apple Mac Malware Lets Attackers Control Browser Sessions After Infection

Atrium Centers Data Breach Exposed Sensitive Patient and Employee Information

Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer

Attackers Probe Critical GeoServer SQL Injection Vulnerability

Australian kidswear brand launches investigation following hacker claims

Azure Cloud Credential Theft leads to Data Breach of McDonald’s and Vodafone

Baylor Genetics Data Breach Compromises Personal and Health Information

Baylor Genetics Reports Data Breach Exposing Patient and Employee Information

Binance-Backed SafePal Reveals Data Breach: 40,000 Users' Info Exposed

Bitcoin purchases halted after data breach puts 250,000 crypto users at risk

Bits of Gold Confirms Major Data Breach Affecting 200,000 Crypto Customers

Bits of Gold data breach exposes personal details of up to 250,000 crypto customers

Brazil: Ransomware attacks leave 26 victims of data kidnapping and extortion in July

Brookhaven ENT Data Breach Affects 30,403 Patients

Canada: Manitoba’s largest hospital still working to recover from ransomware attack

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

ChainDrop npm Worm Hijacks GitHub Actions OIDC to Poison 444 Packages With Valid SLSA Provenance

Check Point ransomware report signals rising AI use, faster exploit weaponization, widening threat landscape

China-Nexus Threat Actor Targeting Critical VMware Flaw

Christian charities in the UK affected by cyber attack

Columbia Machine Data Breach Exposes Social Security Numbers

Cost of a Data Breach Reaches Record $5 Million on Average

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts

Crypto wallet provider SafePal discloses data breach affecting nearly 40,000 users’ order information

Cyber Attack Targets French Tax System, 678,000 Users Affected

Data breach also affects About You: logistics operations relocate

Details emerge on BlackFile’s recent attacks on financial companies

Digital Fraud Is Getting Harder to Spot: Read How Scammers Are Changing Their Tactics

ECU Health warns MyChart phishing emails could steal personal and financial information

ECU Health warns patients of MyChart email scams

ECU Health warns patients of phishing scam involving MyChart

European Telecommunications Standards Institute (ETSI) Proposes 17 Cybersecurity Standards to Support Cyber Resilience Act

Evanston Township High School (ETHS) opens amid recovery from ransomware attack

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Evooo1Bot Linux Botnet Hijacks Routers and Firewalls for DDoS, SOCKS5 Proxy and Credential Theft

ExfilSquad Hackers Leak 382GB of Microsoft Dynamics 365 (D365) Data From 13 Victims

Facial recognition gone wrong (again): Sainsbury’s suspends AI software in one of its stores

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

France’s tax authority admits hackers made off with data on 678,000 individuals

'Fraudulent Letters' - Trezor, SafePal Warning As 53,487 Owners Exposed

French tax agency hit by cyberattack, hundreds of thousands potentially exposed

French tax authority data breach affects 678,000 individuals

General Electric (GE) and Philips Investigate Data Theft Claims Following Clop Ransomware Breach

Guam: $1 Million stolen in Judiciary cyber attack wired to JP Morgan accounts, seized by FBI

Hackers are dumping millions of records from McDonald’s, Vodafone, and other Fortune 500 companies

Hacker claims 3.6 million Azure account records stolen from major companies

Hackers Exploit Attempts Target Critical SAP Commerce Cloud RCE Flaw

Hackers Use Compromised Azure Credentials to Steal Millions of Enterprise Employee Records

Health Sciences Centre Winnipeg still working to recover from ransomware attack

Hello, who’s this? RingCentral discloses data breach in wake of ShinyHunters hack claims

Hong Kong Baptist University (HKBU) hit by ransomware attack, data of nearly 1,800 users compromised

How QR-code phishing can slip past corporate security measures

India: Consumer Forum Orders Bank to Pay Rs 1.10 Lakh Over Unresolved Phishing Fraud

Infostealers Harvest 1.7 Billion Credentials in Six Months

Infostealers Hit 7.4 Million Hosts and Steal 1.7 Billion Credentials in 6 Months

Irregular faces criticism over ‘spin’ in AI hacking postmortem

Israel’s Bits of Gold Suffers Data Breach Affecting 200,000 Customers

Israel’s largest crypto broker Bits of Gold hit by data breach affecting 200,000 customers

Israeli Crypto Broker Bits of Gold Warns Customers After a Data Breach

Latvian State Forests blames miscommunication for recent cyber attack

LexisNexis Shuts Down Data Services Following Third-Party Cyber Attack

Liechtenstein Rules Out Paying Hackers’ Ransom After Data Breach

Lincoln Town Office Closed Following Weekend Cyber Attack

Massive Azure Breach Hits McDonald’s, Vodafone, TCS and More

MessiahGPT: An Uncensored AI Platform Selling Automated Cyberattack Tools on the Dark Web

MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phishing Kits

Microsoft working on Defender patch for ShieldBreak zero-day

Multiple Suicides Reported in US Cyber Operations Forces

Nearly 700,000 French Taxpayer Records Reportedly Stolen in Government Cyberattack

Nearly 750k had financial info, SSNs leaked in South Carolina loan company breach

New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks

New MessiahGPT BlackHat AI Tool Helps Hackers Create Ransomware and Phishing Attacks

New Ransomware Strain ‘JanaWare’ Quietly Targets Turkish Users for Years

NHS admits patient data breach...via pager

NHS Blood and Transplant (NHSBT) apologises over organ transplant data breach

Philips and General Electric (GE) investigating Clop ransomware data theft claims

Phishing scams disguised as party invitations target email accounts

Pokémon Center data breach exposes customer info, cancels some orders

Poland probes MyDr healthcare software breach potentially affecting 19 million people

Police bust cybercrime ring accused of stealing €30 million in four-day spree

Ransomware Attacks Double Year over Year as July 2026 Cyber Threat Volumes Continue to Rise Worldwide

Ransomware gang crashes own attack - with no-one to blame but themselves

Rivers Casino Philadelphia Must Face Data Breach Lawsuit, Judge Rules

SafePal Bitcoin Wallet Data Breach Stokes Fears of Physical Attacks

SafePal breach affects 39,798 customers, data allegedly for sale

SafePal Breach Hits Nearly 40,000 Customers, Data Is Already for Sale

SafePal Data Breach: 39,798 Customers’ Personal Information Exposed, Funds Secure

SafePal Data Breach Exposes 39,798 Crypto Customers, Wallet Keys Remain Secure

SafePal Data Breach Exposes 39,798 Crypto Wallet Owners' Details

SafePal data breach exposes 39K users - Why phishing risks are rising

SafePal data breach exposes nearly 40,000 crypto wallet customers

SafePal Data Breach Exposes Nearly 40,000 Customers as Crypto Industry’s Security Problem Persists

SafePal Data Breach Exposes Order Info for Nearly 40,000 Users

SafePal Data Breach Exposes Order Information of Nearly 40,000 Customers

SafePal Data Breach Exposes Personal Details of Nearly 40,000 Crypto Wallet Customers

SafePal Data Breach Exposes Personal Details of Nearly 40,000 Customers

SafePal Data Breach Hits Nearly 40,000 Customers' Order Records

SafePal Data Breach Hits Tens of Thousands of Customers

SafePal Exposes Personal Data of 39,798 Customers

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

SafePal Says 39,798 Customers Hit by Data Breach

SafePal warns of data breach affecting nearly 40,000 customers

SafePal Warns of Phishing Risk After Data Exposure Hits Nearly 40,000 Customers

Sakura Internet's rental server service hit by unauthorized access, potential data breach affecting 583 accounts

Shell Investigates Data Breach After Cl0p Ransomware Claims Theft of 89GB of Corporate Data

Shell Investigates Data Breach After Cl0p Ransomware Group Claims 89 GB Data Theft

Shipping Data Leaks Expose Hardware Wallet Buyers to Theft and Phishing

Signed ClickOnce Installer Uses Google Workspace Decoy to Deploy Credential Stealers and RAT

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Sogang University data breach exposes information of 180,000 people

Sunwest Bank Data Breach Exposes Social Security Numbers

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Tata Consultancy Services (TCS), HCL, Hexaware named in global Azure directory data leak linked to infostealers

The Romanian hacker "Virus", sentenced in the USA in the Gozi case, was caught in Sinaia with false diplomatic plates

The Security Risks of Second-Life Corporate Devices

UK police data lapse exposed highly sensitive records, watchdog says

Ukraine says cyberattack hit Russian e-commerce giant Wildberries amid drone strikes

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Unlimited Technology Systems data breach exposes information of 3.8 Million patients

‘Unprecedented’ number of Apple users received recent spyware alert, say investigators

US Courts To Begin Publishing Spyware Records From 2029

US Government Hired a North Korean IT Worker, FBI Investigating

Vishing Attack Provides Threat Actor with Access to Quantum Health Network

West Midlands Police officer 'snooped' on people in secret data breach

WiFi networks can be used to identify people without cameras, study claims

Windows 11 is fully removing a legacy tool that malware and ransomware have abused for years, meet WMIC

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Windows Malware Corrupts PE Headers While Dropping Files to Evade On-Access Scanners

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover