Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Wednesday, 30 September 2026

Ransomware Operator Claims - Week 39 2026

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 21st September and 27th September 2026, kindly assisted by our partners.

DBD discovered and researched 179 Ransomware Victims over 50 Countries and Islands claimed by 47 Data-Leaking Ransomware Operators, including 3 Newly Discovered Ransomware Operators last week.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 28 September 2026

Data Breaches Digest - Week 40 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 28th September and 4th October 2026.


📅 1st October

16-year-old suspected leader of KillSec ransomware group arrested

850+ fake ChatGPT ads on Google trick Windows users into installing malware

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

AI policy circles targeted in China-linked phishing operation

AI Threats Top Cybersecurity Preparedness Gap

Alleged Grand Theft Auto 6 (GTA 6) hacker arrested amid multiple murder plot claims

Apple CoreGraphics Proof-of-Concept Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

Australia: Queensland Cybersecurity Department Loses $809,000 in Cyberattack

Bee Cheng Hiang data breach exposes 95,364 customer email addresses after AI-assisted script error

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

Bitget Confirms Zero-Day Flaw Behind More Than $387 Million Crypto Theft

Browser-Based Attacks Dominate 2026 Threat Landscape as Phishing Evolves Beyond Email

Casper Orthopedics Data Breach Affects 56,197 Patients

CertiK Tallies $766.4 Million in September Crypto Exploit and Phishing Losses

China-Aligned Phishing Group Targeted US AI-Policy Experts, Proofpoint Says

China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to Known Exploited Vulnerabilities (KEV)

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer

Connecticut Hotel Operator Data Breach Puts SSNs, Financial and Medical Records at Risk

CPAP Medical Supplies and Services Agrees to Pay Up to $500K to Resolve Data Breach Lawsuit

Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation

CVE-2026-73570: Zimbra Mail Server Flaw Exploited in Active Attacks

Cyberattack on major Polish invoicing platform exposes customer data

Data of 25,000 Leaked at Shinhan Bank; Full Compensation Pledged

Employment scam victims tripled at financial firms in 21 countries

Europe’s Police Chiefs Face Growing Threat of AI-Driven Crime

Fake Squarespace “Domain Expiration” Payment Scam Targets Businesses

From Shadow AI to Accountable Agents: Why Agent Governance Needs Enforcement

Gemini 4 Argon Restricted Over Cybersecurity Misuse Risks

Google Restricts Gemini 4 Argon Release Over Cyber Attack Risks

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

Google’s most advanced model is here, but only “trusted cyber defenders” and the US government get to use it

Hackers stole Pentagon personnel records of over 3 million people

Harlow Council refers itself to Information Commissioner after HTS data breach

Holiday lets owner 'devastated' by phishing scam

How to Protect Kids Online From 5 Common Internet Scams

Index Engines Research Finds Ransomware Increasingly Targets Data Integrity to Evade Detection

Jackson National Life discloses data breach exposing Social Security numbers

Japanese Car-Sharing Site Times Car Data Breach Affects 6.6 Million Accounts

Kaspersky warns of phishing campaigns impersonating Zoom and Docusign

KillSec suspected leader unmasked as teen after police seize notorious leak site

Kiteworks patches max severity code injection vulnerability

Many expect AI in the SOC to make entry jobs harder to get

McMinnville Breach: 53K Visits to Leaked Records

McMinnville reaching out to people who had private details stolen in June data breach, city says

Metamask discloses security incident affecting its infrastructure

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

MI5 Warns Over 100 Academics Helped China's Espionage Plans

MikroTik's RouterOS has a near maximum severity bug: CISA urges updating ASAP

Montenegro Extradites Hacker Arrested in Kotor to the US

Montenegro extradites Iranian hacker to the United States

MSP360 Remote Monitoring and Management (RMM) Abused in Phishing Campaigns to Deploy ScreenConnect

Near Intents Hacked for $3.8 Million Days After Denying North Korea-Linked Bitget Hacker

Nearly 100,000 affected as Bee Cheng Hiang suffers Singapore's first AI-related data breach

New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)

OneMain Financial discloses data breach affecting thousands across multiple states

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates

Operational Technology (OT) and Internet of Medical Things (IoMT) Network Segmentation: Where Security Breaks Down and How to Reduce the Risks

Pentagon Breach Exposes 3.05 Million Military Records

Pentagon breach exposes personal data of more than 3 million people

Phishing scam targeting Wero users already in circulation

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader

Ransomware gang's claim on Western Australian school shows where cyber cover can fall short

Shinhan Bank data breach exposes personal information of 25,000 customers

Shinhan Bank data breach leaks personal, credit information of 25,000 customers

Shinhan Bank hit by data breach affecting 25,000 customers

ShinyHunters Site Goes Dark After Claiming Massive FBI Data Breach Amid Dutch Investigation

ShinyHunters Website Goes Offline After FBI Deadline Passes

Some car apps are slipping owners’ data to big tech companies

South Africa: Gauteng committee demands answers after e-Panic Button app data breach sparks outrage

South Korea: Financial Supervisory Service Investigates Shinhan Bank Over Customer Data Breach

South Korean bank hit by data breach affecting thousands of customers

Spanish Police Arrest 16-Year Old Leader of Hacker Group in Europe-Wide Probe

Spanish police have arrested a 16-year-old Romanian suspected of running the KillSec hacker group

Teenager arrested on suspicion of leading hacker group

Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site

Teenagers suspected of leading ransomware group arrested during international operation

Telmate reaches $4.22 million settlement over 2020 cyber attack

The Problem with CISA’s 2026 Cybersecurity Awareness Month Recommendations

The vulnerabilities AI finds are the ones attackers want

Third-Party Software Company Impacted By Online Poker Cyber Attack Issues Statement

Update On Risk: The Threat Is No Longer The Master Hacker

Voice phishing attacks soar as cyber attackers use AI

Warlock Ransomware Attackers Hit Water and Telecom Operators

Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators

Warlock Ransomware Hits Large Spanish, Portuguese Organizations

Western Australia’s St James’ Anglican School investigating cyber incident in wake of ransomware claims

What airports can learn from the Manchester cyber-attack

Why Mobile Device Management Needs Its Own Threat Model

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

Your car is a spy in disguise, Dutch intelligence service warns

📅 30th September

$20.9 Billion and It's Not Phishing: The Scams That Actually Drained Americans in 2025

40 Million McDonald's Records Exposed Through Customer Data Platform

A Hacker Who Attacked Grand Theft Auto (GTA 6) Developer Rockstar Games Has Been Caught - And They Allegedly Committed More Serious Crimes

AI agents leak 13K screenshots from 300+ firms, including Fortune 500 companies

AI Boosts SOC Analyst Capacity but Limits Skill Development

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

AI coding agents leaked 13,000 internal company screenshots to public GitHub repos

AI-Assisted Attackers Move to Massive Data Theft, Executive Targeting, and Millions in Extortion Payments

AI-Found Vulnerabilities More Likely to Enable RCE, Google Says

Alleged hacker arrested over leak that exposed Grand Theft Auto (GTA) Online's daily revenue

Amazon Prime Phishing Scam Uses Fake Billing Alert to Steal Logins and Card Details

Apple Patches CoreGraphics Zero Day Exploited in Attacks

Arizona court data breach exposed foster care records

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Australia: Queensland government department loses $800,000 in cyber attack

Australia: Queensland government’s cyber security department hit by $800k cyber attack

Automakers routinely share personally identifiable connected-car data with third parties, report says

Bee Cheng Hiang customers’ e-mail addresses exposed in first case of AI-related data breach in Singapore

Bee Cheng Hiang customers’ e-mail addresses exposed in Singapore’s first case of AI-related data breach

Bitget hacked via zero-day in third-party security products

China’s AI agents can lie and scheme - just like their US rivals

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Cisco warns of new SD-WAN zero-day exploited in attacks

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Company Behind Leak of Driver's Licenses Says Hacker Had Access for 5 Months

Cyber Worker Allegedly Moonlighted as ShinyHunters Hacker

Cybercriminals now building fake FBI offices to trick victims in "new twist" on agent impersonation scams

Data breach at Jims underestimated: 150,000 members affected

Delaware Men Sentenced to 189 Months for Scam and Phishing Schemes That Diverted Business Wire Transfers

District of Columbia (DC) Medicaid Agency Notifies 400,000 Beneficiaries About Data Exposure

Dutch Institute for Vulnerability Disclosure (DIVD) says Zammad zero-days enabled AI-driven network breach

Eskenazi Health discloses phishing-related breach of Social Security, medical data

EU Cyber Resilience Act requirements for containers and Kubernetes

EvilTokens Bust: Microsoft Hits 12,000 Inboxes

FBI official tells ShinyHunters hackers to get in touch after major data breach

Fighting the Shadow AI Threat: Strategies That Work

Former US Air Force members behind million-dollar Business Email Compromise (BEC) scheme head to prison

French Tax Data Theft Went Undetected for Seven Weeks After Stolen Staff Passwords Opened the Door

Global Group Ransomware Abuses WinMerge to Deploy Encryptor

Gold Star Mortgage Sued 3 Days After BrainCipher Hit

Hackers hit EU data transfer platform as tech sovereignty push grows

Hackers stole millions of US military personnel records during months-long data breach

Hackers Use Fake Zoom and PDF Installers to Deploy Remote Access Tools on Windows PCs

Hawaii joins multistate settlement over Labcorp data breach

How disposable domains make phishing campaigns cheap and hard to stop in Nigeria

HP warns of AI lures & QR phishing targeting crypto

Huge Pentagon data breach exposes personal files of 3 million people

“I’ll Be Watching You”: The Office of Personnel Management (OPM) Data Breaches, FBI Data Breach, and a Hit Song from The Police

India Tops Asia-Pacific Ransomware Claims in August 2026

iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited

Ireland: One in three small businesses report cyber attacks

Kaspersky Identifies Ongoing Phishing email Campaign Mimicking Zoom and Docusign

Kiteworks Recommended Brief Shutdown: Threat Intel Enabling Proactive Security or Overreaction?

Know Your Enemy: Browser-Based Attack Techniques in 2026

Lamb Weston Data Breach Impacts 7,175 Individuals

Major McDonald's data leak exposes 28 million customer details

MALFEX npm Attack Spreads Windows RAT, Steals Discord and Browser Data

Michigan: Multi-State Settlement Reached With Labcorp Over 2019 Data Breach

Microsoft to block Entra ID script injection attacks starting October

Mobile malware warning from Ukrainian researchers includes iPhone exploit kit

Momentum Group company responds to data breach claims

Most open critical and high flaws are over 90 days old

Most organizations need six months or longer to roll out new security controls

Not All AI Risks Are Cyber. The Pentagon, Anthropic and the Strange Case Where the Safety Feature Became the Security Risk

OneMain Financial Breach Hits 16,988+ in 2 States

Onslaught of Linux kernel bugs forces cyber pros to rethink security boundaries

OpenAI apologises to Australia over government portal data breach

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

OpenSSL Fixes DTLS Out-of-Bounds Read in Security Updates

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL Flaw Could Expose Heap Memory and Crash Applications

Over 543,000 valid credentials exposed in public GitHub repositories

Pentagon Confirms Major Data Breach Exposing Sensitive Information of Over 3 Million People

Pentagon data breach exposes info of more than 2.7 million US military and civilian personnel

Pentagon Data Breach Exposes Personal Data of 2.8 Million Living People and Nearly 300,000 Deceased

Pentagon data breach exposes Social Security numbers, personal info of 2.76 Million US military, civilian personnel

Pentagon Recordkeeping Unit Alerts 3 Million After 10-Month Data Breach

Phishing Without Red Flags: How QR Codes, ConsentFix and AI Are Beating Old Checks

Poppins Payroll Data Breach Impacts Hundreds: Financial Info Exposed

Public GitHub code reveals a major issue: over 500,000 secret keys are exposed

Ransomware Attack on Financial Lender triggers customer lawsuit within 48 Hours

Ransomware gangs steal 896 terabytes of data over a year

Ransomware surges 600% as AI lowers cybercrime cost

Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters

Russian state hackers use new RedFlick technique to push malware

Ryuk ransomware operator ordered to pay $1.2 Million after US extradition

ShinyHunters and the New Reality of Identity Theft

ShinyHunters insists it is “fine” after FBI arrests alleged leader

ShinyHunters Says Operations Are ‘Completely Fine’ After Umbreon Arrest, Warns Negotiating Victims

ShinyHunters Suspect Arrested, FBI Data Breach Claim Under Spotlight

Singapore sees first data breach linked to AI use

South African air traffic control firm investigates ransomware-linked malware in Operational Technology (OT) network

South Korea: Telecoms industry opposes no-fault compensation for voice phishing losses

South Korea Imposes 3% Data Breach Fines

South Korea toughens data-breach penalties, elevates CISO to executive

Stevens Point says ransomware attempt behind city cyberattack

Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772)

TeamViewer urges users to patch severe flaws “as soon as possible”

Terrebonne Parish Government offline after cyber attack

The Mental Health Association Data Breach Settlement Agreed

This invite-only AI agent may be a hyped-up privacy nightmare, but users are selling early access on eBay

Times Car Data Breach Hits 6.6 Million Member Accounts

Times Car Rental says data breach affected 6.6 million accounts

US sanctions 10 over ATM malware scheme tied to Tren de Aragua

Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

When Security and Sustainability Report to the Same Boardroom

Who is Rui Pinto? The hacker behind Football Leaks whose work led to Manchester City investigations

Why Space Infrastructure's Biggest Cyber Risk Never Leaves the Ground

Zscaler ThreatLabz 2026 Ransomware Report finds AI‑assisted attacks drive 275% rise in data theft

📅 29th September

17.3 Trillion Microsoft Records Exposed

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

A fake journalist used a real Calendly link to phish a tech founder

After Five Years in Hacker Crosshairs, Manufacturing Must Take the Target Off Its Back

Alleged Rockstar Games Hacker Arrested, Ordered Multiple Murders

Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials

Andover Still Reviewing Possible Data Theft Six Weeks After Cyberattack

Apple Fixes CoreGraphics Flaw Used in Targeted Attacks

Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple patches zero-day exploit possibly used in “extremely sophisticated” attacks

Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

Arizona Supreme Court data breach exposed reports on children in foster care

Arizona Supreme Court says hackers stole residents’ personal data

Astrana Health Data Breach Exposes Confidential Information

Astrana Health Notifies Securities and Exchange Commission (SEC) About Social Engineering Incident

Australia’s next data breach could target these woefully porous government departments after alarming hack on Medicare by a rogue OpenAI agent

Automated AI agent used to breach cybersecurity nonprofit Dutch Institute for Vulnerability Disclosure (DIVD)

Azure Standard Data Breach Exposes Financial Information of Customers

Borrower sues Gold Star Mortgage a day after ransomware gang claims data theft

Carrefour France faces data breach after cyber attack at supplier

Clop Ransomware Group changes Server and vows Not to Pay ShinyHunters

Critical Authlib authentication bypass flaw leaves countless apps in danger

Custom ChatGPTs push ClickFix attacks to deploy RAT malware

Cyber attack on data exchange service FTAPI

Cyber Crime in the West Midlands: What Local Businesses Should Know

Cyber Skills Diminish Quicker than Organizations Can Build Readiness

Cybersecurity Awareness Is Patient Safety

Data breach at Colruyt’s Jims fitness chain much larger than thought

Deepfakes at schools overwhelmingly target girls and women – and most involve explicit content

Deepfakes become a board priority once an executive falls for one

Digital health applications: HelloBetter reports data breach after cyberattack

Dutch Hacker Arrested in ShinyHunters Probe Tied to FBI Breach

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation

Dutch police arrest a suspected ShinyHunters member; court orders 90-day detention

Dutch Police Arrest Convicted Hacker ‘Umbreon’ in ShinyHunters Probe as Group Hits FBI Job Site

Dutch police arrest ShinyHunters hacker accused of planning two murders

Dutch Police Arrest ShinyHunters Suspect as FBI Pursues New Leads

Dutch police arrest suspected member of cyber-crime group that claimed FBI hack

Dutch ShinyHunters Suspect Investigated for Trying to Arrange 2 Murders

Eskenazi Health Data Breach Exposes Sensitive Personal and Medical Info

Eskenazi Health data breach exposes Social Security and medical data

Ex-employee sues Springfield business over data breach affecting 2,667

Fake iPhone Duo Preorder Page Deploys DarkSword iOS Exploit With No Tap Required

Fake Microsoft Store Pages Deliver a RAT That Lets Attackers Watch and Control Windows PCs

FBI Grapples With Fallout From Massive Data Breach

FBI tells ShinyHunters members to turn themselves in after recent arrest

FBI’s Top Cyber Guy Warns ShinyHunters Crew That They Better Watch Their Backs

Feds warns hackers after ShinyHunters arrest over FBI jobsite data breach

Forget Me Not: Connecticut’s New Privacy Law Collides With OSINT and Threat Intelligence

Former ShinyHunters hacker arrested in what could be an elaborate frame job in FBI hack

Former US Air Force members sent to prison over Business Email Compromise (BEC) attacks

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

Fun For Less Tours Data Breach: PHI and PII Exposed

GitHub’s AI agent found 24 Android app vulnerabilities

Hacker-for-Hire Economy: How Cyber Mercenaries Turned Digital Revenge Into a Business

Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

Hackers Turned Ethereum Into a Secret Messaging System for Malware

Hackers Use Hijacked University Emails to Scam Students, Pose as FBI Agent

Hawaiʻi settles $2.3 Billion data breach lawsuit filed with 43 other states

Japanese railway operator Keio hit by ransomware attack

Japanese Railway Operators Hit with Weekend Cyber Attacks

Japanese railway operators Keio Corporation and Tokyo Metro disclose security breaches

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

Kiteworks patches critical flaw, brings customer systems online

Kiteworks Urges Customers to Restart Systems After Shutdown Notice

Malicious Custom GPT on chatgpt.com lures users into installing a RAT

Manage My Health, Health NZ get compliance notices for cyber attack

Meduza Locker Claims Ransomware Breach of Spain’s Junta de Andalucía

Meitav Trade says hacker accessed customer data through vendor API vulnerability

Microsoft Tracks NeedyMantis Post-Compromise Malware Targeting Telecoms and Government Contractors

Microsoft Warns NeedyMantis Malware Enables Persistent Network Access

Modoc Medical Center Data Breach Exposes Medical Information

Nearly 3 Million People Impacted by Defense Department Data Breach Exposing Sensitive Information

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

New Spectre v2 attack variant leaks Linux root password hash in minutes

New Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Memory Despite Existing Defenses

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

OneMain Financial Data Breach Affects 16k: Social Security Numbers Exposed

OpenAI apologizes for agents breaching Australian government websites without authorization

OpenAI apologizes to Australia after its AI agents breached government sites

OpenAI apologizes to Australia over Medicare data breach

OpenAI Disclosed Its AI Agents Accessed Four Australian Government Websites

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions

OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to

Pennington County provides update on July ransomware attack

Pentagon confirms data breach: over 3 million people affected

Pentagon Data Breach - Hackers Reportedly Accessed 3 Million People’s Sensitive Data

Pentagon Data Breach Exposes Records of More Than 3.05 Million People

Pentagon data breach exposes sensitive information on more than 3 million people

Pentagon Data Breach Exposes Social Security Numbers, Military Job Details

Pentagon Data Breach: Pentagon data hack exposes 3 million people's information as FBI probes another data leak

Pentagon database flaw exposed Social Security numbers of more than 3 million people

Pentagon Defense Manpower Data Center (DMDC) data breach exposes records of over 3 million people

Pentagon Personnel Agency Data Breach Impacts 3 Million People

Phishing Abuses RMM Tools for Persistent Access

Phishing Exposure Nears 70% Across Key US Industries. What Should Security Teams Do?

Planet 13 data breach lawsuit highlights cannabis industry ID security risks

Polish Medical Software Hit by Cyberattack, Patient Data Stolen

Popular games on Google Play contain trackers from Russia, China, and Israel, study finds

Ransomware attack disrupts payment systems at Japan's Keio railway group

Ransomware Attack Hits Keio Railway Group Servers and Disrupts Business Systems

RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims

Russian-linked forensics software was used by London police and throughout Europe

Second data breach hits Revolut after service provider cyber attack

ShinyHunters Arrest: Dutch Police Detain Convicted Hacker

ShinyHunters says suspect arrested for Odido attack not affiliated with hacker group

ShinyHunters says they “never intended or planned to” publish FBI data

Should South Africa ban ransomware payments?

SilverFox Malware Campaign Uses Smart Filtering to Hide Fake Software Downloads From Researchers

Social Engineering in the Age of Synthetic Media

Spokane Public Schools Get Back Online After Cyber Attack

Springfield Contractor Hamilton Construction Sued Over Data Breach Hitting 2,667

Star Blizzard refines phishing and malware delivery with the RedFlick technique

Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix

Storm-3168 Targets Azure Storage, Key Vaults and Backups in Destructive Cloud Attacks

Suspected ShinyHunters hacker arrested after FBI data breach

Teen Hacker Finds Auth Flaw in Microsoft System With 17.3 Trillion Data Rows

Telecare Data Breach: Social Security Numbers Exposed

Three Million Affected in Pentagon Personnel Agency Data Breach

US Air Force members given over 6 years in prison for cyber theft of more than $2 million

Vietnamese man charged in $16 million 'pig butchering' crypto scam

Walsh Financial Services Data Breach Exposes SSNs and Financial Data

'We know how to find you': FBI official tells ShinyHunters hacker group to get in touch with agency

What can a person find about you in an hour?

Your car and its mobile app are probably handing over all kinds of data to tech companies

📅 28th September

16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data

29CM Data Breach Wider Than Reported, With 30,000 More Records Exposed

44 State Attorneys General Reach Data Breach Settlement With Lapcorp

23,549 SIMBA Customers Have Identity Card Numbers, Phone Numbers and Other Details Exposed in Data Breach

23,549 Simba customers’ personal info leaked in data breach, including names & Identity Card numbers

80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

AI Ransomware Wiped 100 Azure Accounts in 7 Minutes: Only Pre-Configured Locks Survived

AI Security Agents Struggle With Complex Bugs and Safe Patching

AI tests the limits of enterprise security governance

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Are Your Personal Data and Bank Details Safe? Cyberattacks Surge 27% as India Tops Asia-Pacific Threat List

Arizona court data breach: Cyberattack targets judicial network, protective orders

Australia: Labor defends AI crackdown over Medicare data breach

Bank of Korea (BOK) faces scrutiny over cybersecurity after staff data breach

Bank of Korea Suffers Data Breach, Exposing 186 Employees' Information

Bitget Restarts Bitcoin Withdrawals Following $387.5 million Wallet Breach

Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388 Million

Bright Smile Dental Care of Fishers notified of security breach

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

CISA orders feds to patch exploited Citrix flaws by Wednesday

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

Citrix NetScaler under active zero-day attack: critical patches available, 22K servers exposed

Citrix Patches Critical Zero Days Under Active Exploitation

Clicked A Fake Link? 6 Immediate Steps To Take After Falling For Phishing

Clop ransomware gang moves to new server after Grav CMS vulnerability exploited

Cyber attack takes L&Q’s online services down as correspondence from 12,000 residents hacked

Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

Cyberattack on Polish medical software provider exposes patient data

Cyberattack on Welsh Police Force May Have Exposed Data

Cyble Threat Report: August 2026 Hits Record High with 1,034 Global Ransomware Victims

Dartmouth College reaches $750,000 settlement following data breach affecting 96,000 members of the Dartmouth community

Data breach affects 23,549 customers of Singapore telco Simba, personal data protection commission investigating

Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns

Democratic Alliance (DA) to report e-Panic button data breach to Information Regulator of South Africa

District of Columbia (DC) Health Agency Exposes 400,000 Beneficiary Records

Dutch man arrested in ShinyHunters investigation alleged to have been 'reformed hacker'

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Dutch police arrest security professional in ShinyHunters investigation

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch 'reformed hacker' arrested in ShinyHunters investigation, police and boss say

Everything we know as East Suffolk and North Essex NHS Foundation Trust launch Noah Woods data breach probe

Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts

Fake American Express “non‑compliance” phishing scam targets Australians

Fake Email Thread Tricks AI Summarizer Without Hidden Text

FBI grapples with fallout from massive data breach

FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day

FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data

Finastra reaches $3.13 million settlement in data breach lawsuit

Fishers dental office reports ransomware attack on patient records

Flink hackers turn to customers, demanding ransom to keep their data off the dark web

Flock tries to nuke interactive map built from its own data leak

Football Leaks and the hacker behind Manchester City’s charges

Former Moores staff victims of severe cyber-attack

Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

Gabia Data Breach Exposes Information of 2,998 Customers

Gallagher Transport Data Breach Exposes Social Security Numbers

Gyazo Data Breach Exposes 23.6 Million User Records and Nearly Half a Billion Image Metadata

Hackers Are Running Ransomware Like a Business. Companies Are Paying the Price

Hackers can hijack QR code domains to redirect users to phishing sites

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

How Ransomware Groups Are Adapting by Using Encrypted Exfiltration Methods

India Tops Asia-Pacific Ransomware Claims With 24 Victims In August

JadePuffer agentic AI attacks target Azure, destroy cloud resources

JadePuffer criminals hijacked Azure identities and used them to blow up cloud resources

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Japan Ransomware Activity Rises as Qilin Shows Signs of AI-Generated Tools

Japan travelers targeted by phishing scam mimicking hotel payment gateways

Japan's Keio confirms ransomware attack disrupted business systems

Kiteworks Systems Went Offline After Federal Threat Warning

Mass exploitation of Magento and Adobe Commerce critical flaw: 3,800+ online shops hacked

Model Context Protocol (MCP) Is Creating Major Governance Gaps, Researchers Warn

More than 3 million people affected by military data breach

More than 23,000 Simba Customers’ Personal Info Leaked in Data Breach

Nearly 400,000 Medicaid Beneficiaries Caught in Medicaid and DC Healthcare Alliance Data Exposure

New Mexico jury finds Meta deceived consumers about data privacy practices

New Scam in Europe: How to Avoid Losing Money

Noah Woods suspected data leak leaves NHS staff jobs at risk

OpenAI reportedly ditches model over safety concerns

Other users can watch your browsing and time your keystrokes through OS file notifications

Over 16,000 Supabase databases expose PII, passwords, auth tokens

Park24's Times Car Suffers Data Breach Affecting 6.6 Million Records, Including Driver's License Images

Pentagon Data Breach Exposes Unknown Number of Troops’ Social Security Numbers

Pentagon Data Breach and Kiteworks Targeted in Cyberattacks

Pentagon Data Breach Exposes Military Personnel

Pentagon data breach may affect 4 million

Personal information of over 23,500 Simba telco customers leaked in data breach in Singapore

Previously Convicted Dutch Hacker Arrested in ShinyHunters Odido Probe

Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

Quantum random numbers can pass the tests and still leak clues to attackers

Ransomware activity hits 2026 high as industrial sector bears 31% of attacks and Qilin dominates

Ransomware Attack Hits Japan's Keio Corporation Group, Disrupting Card Payments at Retail Stores

Ransomware attacks hit 2026 high: India most Targeted in Asia-Pacific

Ransomware attacks hit 2026 high in August; India most targeted in Asia-Pacific

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed

Researchers Discover Cybercrime Server Containing AI Tools, Phishing Kits and Stolen Data

ShinyHunters exploiting workarounds for Oracle PeopleSoft bug, Mandiant warns

ShinyHunters Hacks Rival Ransomware Gang Cl0p and Takes Over its Dark Web Tor Data Leak Site

ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends

Simba data breach: Personal information of over 23,500 customers leaked

Simba data breach compromises personal information of more than 23,500 customers

SIMBA data breach exposes 23,549 customer records

SIMBA data breach exposes Identity Card numbers and personal details of over 23,000 customers

Simba data breach exposes personal details of over 23,000 customers

South Africa: Democratic Alliance (DA) to report e-Panic data breach to Information Regulator

Stake and Revolut both impacted by third-party cyber attack

Tech Support Scam Kit Uses Google Ads to Deliver Fake Security Alerts

Ten NHS staff removed over Noah Woods data breach

The devil is still in the email - but wearing a new mask

The Hacker Who Beat Manchester City, and What It Means for Every Boardroom

The Two Biggest Threats to Cybersecurity in 2026: AI - and Not Having AI

Threat Actor Claims 37,000+ Israeli Identity Records Leaked via Ministry of Defense API

Times Car confirms data breach affecting 6.6 million user accounts

Two Citrix NetScaler Flaws Are Being Exploited for Remote Code Execution, CISA Urges Patching (CVE-2026-88771, CVE-2026-88772)

UK: Critical national infrastructure bodies to receive briefings on heightened Russia threats

US: Critical Infrastructure Braces for Sweeping New Cyber Reporting Rules

US soldier gets 70 months in prison for extorting 10 tech, telecom firms

US, UK warn of exploited Citrix NetScaler zero-day bugs

Vendor hack exposes Bank of Korea staff data

World’s top ransomware group claims 2 more Australian victims