Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 14th September and 20th September 2026.📅 20th September
AI is making spear phishing scams more successful
Basic Security Flaws Fuel Breaches Despite AI-Driven Attack Speed
Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
Fetch.ai Exploit: Hacker Drains $2 Million Across Two AI Crypto Projects
Google infiltrated TeamPCP hacker group to disrupt attacks from the inside
Gyazo Breach Exposes 23.6 Million Users, 490 Million Image IDs
Hacker Steals $2 Million From Fetch.ai, NuNet In Single Attack
Handala hacker group publishes selfie images of 700 Israeli ‘security’ personnel
Hong Kong: Census and Statistics Department Warns of Fraudulent Website and Phishing Messages Related to 2026 Population Census
Job hunting? North Korean fake recruiters infected 30,000 devices
Malicious npm packages evade install-script defenses at runtime
More than 1,000 hacker attacks in Russia since the start of parliamentary elections
Phishing scams using Singapore police logo re-emerging, public warned
Putin humiliated as Moscow hit by ‘cyber attack’ on election day and blames UK
Researchers escape OpenAI Codex sandbox to run commands on host
RNLI fears supporters' data stolen in cyber-attack after charity 'targeted by far-right agitators'
Scammers Are Hiding Fake Bank Pages on Google Firebase, Making Phishing Harder to Spot
ShinyHunters Hacks Clop Leak Site, Threatens to Extort Rival Ransomware Gang
ShinyHunters hacks Clop ransomware gang and threatens to extort it
ShinyHunters Turns the Tables on a Ransomware Gang With Site Hack
The Philippines: The Land Transportation Franchising and Regulatory Board (LTFRB) probes data breach as platform goes offline
When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
Wyoming Department of Transportation (WYDOT) Issues Email Phishing Scam Warning
📅 19th September
AI Agent Insurance Coverage: Enterprise Governance, Claims Evidence, and Liability
BragJack attacks hijack AI browser agents through malicious extensions
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
Deerfield school district investigating phishing email
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Grandma demands $10 Million after botched facial recognition match lands her in jail for 6 months
How Organizations Can Respond to Exposed Edge Devices and Compromised Credentials
North Korean WaterPlum hackers infected 30,000 devices worldwide
ShinyHunters Hacks and Defaces Clop Ransomware Leak Site
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
Suspected cyberattack on third tanker knocks system offline, US now monitoring 20 ships
📅 18th September
98% of fraudulent hires have company credentials by the time they’re caught
Abandoned IoT apps keep sending sensitive data to broken servers
Akira Ransomware Lists Manders in Leak: 70GB Claimed
Android apps can now check security patches down to individual device components
Australia: Shellharbour-based Leisure Coast Kitchens listed by Kairos ransomware group
Catalyst Health Group reveals data breach linked to service provider Aesto Health
ChatGPT Billing Scam Exposes Critical OpenAI Account Risk
ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts
CISA Upgrades Vulnerability Reporting Platform with More Automation
Cisco Identity Services Engine (ISE) Vulnerability With CVSS 10.0 Score Under Active Attack
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Claude helped hackers to break into OpenAI accounts: ChatGPT affected
Defences improve, but ransomware still threatens South African businesses
Education sector faces significant cybersecurity challenges
Fake Apps, Real Spies: How Iran Tracks Dissidents Through Telegram
Fake Bpost Parcel Emails Trick Victims Into Handing Over Card and Bank Details in Phishing Campaign
Fake calendar invites can infect your system, and they’re surging - how to protect yourself
Fake ChatGPT billing email targets work and home users
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
FamousSparrow Deploys New SparroWocky Backdoor Against Latin American Governments
FBI seizes NightmareStresser domains in DDoS-for-hire crackdown
Four Countries Attribute “Contagious Interview” Fake-Job Malware Campaign to North Korea’s WaterPlum
Gyazo data breach exposed 23.6 million user records and 490 Million image metadata
Gyazo data breach exposed millions of records; company delayed public disclosure
Gyazo server flaw exploited to steal 23.6 million user records
Hacked before their first coffee: Common onboarding mistakes that open the door to cybercriminals
Hacker breach at Korea math academy Thinking Bull leaks parent-student data
Hacker turns 25 cents into 46 billion fake Bitcoins to steal $770,000 - Symbiosis DeFi exchange bit by lack of basic bounds checking in smart contract
Hackers Are Using Passkey Updates as a New Microsoft Phishing Hook
Hackers Crack Flock Camera, Expose 1.6 Million Images in 21 Days
Hackers demand $3 million as Revolut data breach deepens
Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Hardcoded MCP credentials found in public GitHub files
How Hackers Used Claude Opus 5 to Breach OpenAI Systems
India forces caller-ID apps to feed spam reports to telcos
Keep seeing strange meetings and events in your calendar? It might be because calendar-based phishing has jumped 33,000% since May - and they work even if the email is sent to spam
Manufacturing Accounts for 22% of all Ransomware Victims
Manufacturing ransomware surged in 2026, spreading beyond the US, with 1,183 victims through July
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Most WordPress pros still lack a breach recovery plan
Nations take action on North Korean IT workers after UN report
Nearly two million Quest Apartment Hotels customers affected by data breach
New Check Point flaw lets hackers execute code with root privileges
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
North Korean Hacker Group behind Crypto Thefts across 100 Countries
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
Panzer Ransomware Hits 16 Firms as August Sets 997-Attack Record
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Researchers Used Anthropic’s Claude to Breach OpenAI’s Internal Systems
Researchers used Anthropic’s Claude to hack into OpenAI
Revolut Faces $3 million Ransom Demand Following Data Breach of Cryptocurrency Customers
Revolut Hacker Launches Extortion Site Demanding $3 Million After 680 Customer Data Breach
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
Settra ransomware group uses MeshAgent RMM in recent attacks
Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs
South Korea: Personal Information of Students and Parents Leaked in Hacker Breach at Saenggakhan Hwangso Math Academy in Daechi-dong
South Korea Math Academy Hit by Cyberattack, Student Data at Risk
Standard Bank investigates 200GB data breach
Stop assuming your contractor’s data security is your liability shield
This Android malware is nuts: it connects to your phone like a developer, but from the inside
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
U.S. House Passes Bill to Give Local Law Agencies Tools to Investigate Cyber Scams
UAE Cyber Chief Says Country Faced 640,000 Cyberattacks in One Day
Ukraine: Payment data were lured through fake websites - police uncovered a large-scale phishing scheme in 20 regions
Ukrainians charged for hacking 610,000 Roblox accounts and selling them to Russian buyers
University of Galway data breach affected almost 190 people, financial statements reveal
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Why AI Fluency Is Now an Imperative in Closing the Cyber Skills Gap
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
📅 17th September
A fake ChatGPT billing email is after your OpenAI password
A physically removed Flock camera exposed local surveillance data
AI Agent Carries Out Multi-Stage Data Theft Attack
AI hacks system and accesses personal data in reported breach
Are British Columbians affected by a massive drivers licence data breach?
Autonomous AI Agent Executes Spain’s First Data Breach: Agencia Española de Protección de Datos (AEPD) Incident Analysis and Cybersecurity Implications
Beware! Kaspersky Discovers Phishing Campaign Disguised as Zoom and DocuSign
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Brevo supply-chain attack injected ClickFix scripts on customer sites
Bug Hunters at Risk: Leaving Them Outside Can Leave Your Enterprise Devoid of a Critical Defense
CenterPoint Energy Data Breach Exposes Customer Information in September
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
China’s FamousSparrow hackers target Latin America with new backdoor
Chinese hackers use SparroWocky malware in government espionage attacks
CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cisco Warns of Active Exploitation of Critical Identity Services Engine (ISE) Flaw
Cisco warns of max severity Identity Services Engine (ISE) zero-day exploited in attacks
Cisco Warns of New Zero-Day Identity Services Engine (ISE) Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Clay County housing agency subject of ransomware attack
Connecticut Ransomware Attacks May Have Exposed Data of More Than 12,600 Residents
Cornerstone Staffing discloses 2025 data breach; law firm investigates claims
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Cyber Essentials Has Record Year but Takeup Remains Low
Cyberattack on Springfield schools included data breach
Data breach incident targets prisoner medical records at 2 Massachusetts jails
East Coast Healthcare Firm Agrees To $1,368,025 Data Breach Settlement Affecting 218,884 Patients
EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats
Fake AI trading agent steals crypto wallet passwords
Fake OpenAI Billing Emails Target ChatGPT Users in Credential Phishing Scam
FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
FBI Dismantles NightmareStresser, One of the Web’s Longest-Running DDoS-for-Hire Services
FBI takes down one of the longest-running DDoS-for-hire services
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Gyazo Breach Exposes Link IDs Behind Private Captures
Gyazo data breach leaves over 23 million user records exposed, includes half a billion metadata points
Hacker turned 55 days of failed transactions into a $3 million master key that drained GalaChain wallets
Hacker who extorted money from Stadler sentenced to prison
Hackers claim breach of Russian election systems days before parliamentary vote
Hackers Demand $3 Million Monero Ransom From Revolut After Data Breach
Hackers demand $3 million ransom from Revolut after data breach
Hackers Demand ₹28.73 Crore Ransom From Revolut After Data Breach
Hackers demand Revolut hand over $3 million ransom amid data breach
Inside Immutable Backup Architecture: How Air-Gapped and WORM Storage Actually Stop Ransomware
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Japan's Gyazo Suffers Data Breach: 23.62 Million User Records and 490 Million Image Metadata Entries Leaked
Manufacturers make patching progress, but identity management still major weakness
Manufacturing Remains Ransomware’s Top Target
Mobile Security Can't Move at App Release Speed Anymore
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
New Parallels Desktop Flaw Lets Local Users Seize Root Control of Macs
New RatHat Android malware uses AI to automate device control
New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
NH NongHyup Bank Sees Voice Phishing Losses Surge 2.3 Times in Two Years Despite Increasing Staff and Budget
NightEagle APT Expands to Russia With GhostContainer Backdoor and Stealth Tunneling
No evidence a large amount of data compromised from HR system hit by ransomware, says Islamic Religious Council of Singapore (MUIS)
OpenAI details more cases of AI agents taking unauthorized actions
OpenAI Details Six New Instances of ‘Concerning’ AI Agent Behavior
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
Over 100,000 websites showed users ClickFix scams for hours after Brevo compromise
Parents say care group's data breach has been 'catastrophic' for their family
PhishByte warns AI phishing has outpaced detection
Property investors targeted in cyber attack spike
Protect Yourself From MyChart Phishing Scams Targeting Patients Worldwide
Ransomware Attacks May Have Exposed Data of 12,600 in Connecticut
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware Surge Raises Supply Chain Risks for Distributors
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3 Million Ransom
Revolut data breach affects 680 customers; systems were not hacked
Revolut data breach puts Cyprus users on scam alert
Revolut Denies Hacker Contact Over Reported $3 Million Ransom Claim
Revolut faces $3 million Monero ransom after customer data breach
Revolut faces $3 Million ransom demand after data breach
Revolut phishing texts appear days after data breach
Revolut reportedly facing $3m ransom demand after hackers steal hundreds of customers’ data
Rogue OpenAI Agents Probed Hugging Face for Weeks Before July Breach
Scammers leave AI fingerprints all over fake antivirus renewal page
Second Texas-bound oil tanker hit by hackers possibly linked to Iran, FBI confirms both attacks
Solo Russian hacker built six-figure proxy empire by brute-forcing neglected routers, VPNs
South Africa: Regulator probes ransomware attack on Cartrack
South African home loans giant affected by data breach, customer records potentially exposed
South Korea's Communications Regulator Warns of Surge in Phishing Texts Ahead of Chuseok Holiday
Spain reports first data breach involving autonomous AI agent
Spain’s AEPD Logs First Data Breach Caused by AI Agent
Spain's Regulator Logs First Report of an AI-Powered Data Breach
Suno hit with another proposed class action over data breach that leaked information of 55 Million users
Taiwan: Phishing cases on rise, Criminal Investigation Bureau (CIB) says
Telus blames ‘technical issue’ after some customers told to disregard data breach email
“Their blood will be on Revolut's hands, not mine:” Attackers threaten to sell customer data unless they’re paid $3 Million
Third-party data breach linked to Canva affects 424 organizations in Türkiye
Tough week for Cisco admins: network security system under attack, firewall management center vulnerable
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
UK, US and Netherlands Warn of Iranian Spyware and Spear-Phishing Campaign
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
US Coast Guard and FBI board oil tanker to investigate cyber attack
US House Passes Bill to Help Police Track Down Scammers Targeting Seniors
US takes down NightmareStresser DDoS-for-hire platform
Valve says customer data was not exposed in CEVA cyberattack
Voice Phishing Losses at NH Nonghyup Bank Rise 2.3 Times in Two Years
📅 16th September
2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
8 Places AI Is Quietly Entering Your Enterprise
280,000 Impacted by Premier Medical Group Data Breach
A phantom Chinese online casino empire is quietly spreading malware
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
AI Agents Behind RubyGems Cyber Attack Uploaded Hundreds of Malicious Packages
Alvita Care Holdings Data Breach Exposes Financial Account Info
An ISP Data Leak Can Expose More Than Your Password
Apache Syncope Flaws Enable SQL Injection, JWT Token Takeover and Code Injection
Apple Patches 273 Vulnerabilities as iOS 26.7 Rolls Out
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Attackers target GitLab: thousands of exposed servers remain vulnerable to a critical bug
Attackers Target Vite Servers in Scanning Campaign to Steal AWS, Azure Info
Beyond backup: Rethinking data infrastructure for the ransomware era
Boston dumps Flock due to data hole, but keeps surveillance cameras
Bridgeport Capital Data Breach Compromises Social Security Numbers
CenterPoint Breach May Have Hit 7.5 Million Records, Lawsuits Already Piling Up
CenterPoint Data Breach Reached Customer Information; Scope Is Still Unknown
CenterPoint Energy Breach Exposes 7.49 Million Records
CenterPoint Energy Confirms Breach After Hacker Claims 7.49 Million Records Stolen
CenterPoint Energy Confirms Data Breach After Hacker Claims 6.7 Million Customer Records Stolen
CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy confirms data breach following claims on hacking forum
CenterPoint Energy confirms data breach of customer information
CenterPoint Energy Data Breach Exposes Customers’ Personal Information
CenterPoint Energy says some customer information was in data breach
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
Communauto data breach traced to employee's unauthorized script, company says
ConnectWise ScreenConnect bug exploited in the wild, CISA says
Coupang rejects 100,000 won compensation plan for users affected by data breach
Coupang rejects 100,000 won payouts for data breach victims
Court files about Southport attack victims, survivors and families accessed in data breach
Criminal Investigation Bureau says phishing scams in Taiwan doubled year on year
Critical Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Flaws Let Attackers Gain Admin Access and Execute Remote Code
Critical ScreenConnect flaw now actively exploited in attacks
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter
Cyber Attack on Commercial Oil Tanker confirmed by FBI
Cyber-Attacks Cost Organizations $52,000 on Average
Data breach at ID verification company may have exposed millions of driver’s license images
Don’t fall for fake MyChart phishing emails
Edenred Pay Data Breach Exposes Social Security Numbers
Employers are using your personal data to make you accept lower pay
FBI Confirms Data Was Breached in Cyber Attack on Springfield Schools
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF
First Agentic AI Data Breach Reported to Spanish Regulator
Five alleged Black Axe members extradited to face US fraud charges
Flock camera use by internal affairs unit puts Washington, D.C. police at odds with officers’ union
GAMA Data Breach Impacts 6,000 Texans: PII Exposed
GhostCode Abuses Microsoft Device Codes to Steal M365 Tokens and Register Rogue Devices
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
Global fintech Revolut reveals customer data breach
Google fixes actively exploited Android zero-day on Pixel devices
Google issues urgent update warning for severe Pixel bug
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google says some Pixel phone owners were hacked in zero-day attacks
Hackers are hijacking IP cameras to break into corporate networks
Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
Hackers rip down Flock camera, steal its data, share findings with media
Hackers rip Flock spy camera off pole and crack open its secrets
House passes bill to equip local law enforcement with scam-fighting tools
Identity attacks drive 85% of education ransomware
International Meteor Organization says cyberattack dealt ‘critical blow’ to website
Investigation launched as files about Southport attack victims and families accessed in data breach
Iran-Linked Hackers Deploy CHOSEN BRICK Spyware Against Activists, Joint NCSC-FBI-AIVD Advisory Reveals
Iranian hackers target dissidents, activists, journalists worldwide with Telegram-linked Chosen Brick spyware
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Issabel PBX JWT Key Flaw Enables Unauthenticated Remote Code Execution
Italian postal police probe Revolut customer data breach
Luciferus Uncensored AI Advertised on Hacker Forums for Malware and RAT Development
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Malware bypasses browser checks to force install Chrome, Edge extensions
Manhattan District Attorney Seizes 12 Deepfake Porn Websites Targeting 1,200 People
McKesson’s data breach impacted over 6.4 million accounts
Member of Conti ransomware group sentenced to four years in prison
Microsoft Teams IT Support Calling? Not So Fast, Hackers are Exploiting Trust in Spring Ring
Microsoft Warns Passkey Phishing Attacks Are Leading to Cloud Account Takeovers
Middle East cyber threats enter a new phase as ransomware surges and AI joins the attacker’s toolkit
Ministry of Justice apologizes after court staff accessed Southport victims' files
MSPs say nearly half their customers rely on them for CISO services
Names and addresses of 224 people exposed in Southampton council data breach
National Cyber Security Centre (NCSC) and Allies Warn of Iranian Spyware Campaign
New VectraRAT Malware-as-a-Service (MaaS) Lets Hackers Bypass Windows UAC and Steal Browser Credentials
Nipigon hospital hit by ransomware attack
NIST and CISA finalize playbook to stop token theft and forgery
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
OpenAI agents' probing of Hugging Face began months before July breach
Pakistan Finalizes 90-Day Cybersecurity Action Plan, Federal CERT to Lead Rollout
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parents ‘devastated’ after Southport attack victims targeted in data breach
Parents of Southport attack victim 'devastated' by data breach
Passkey Phishing Attacks Are Leading to Cloud Account Takeovers
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Prescribe FIT Data Breach Affects 1.3k: PII Exposed
Ransomware activity rises across Middle East as criminal groups attack Gulf
Ransomware Costs $5.08 Million as Downtime Hits 50X Ransom
Revolut confirms customer data breach
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
Revolut hackers demand $3 Million in Monero after data breach
Revolut says no direct demand received over alleged data breach
Revolut-style data breach ‘could absolutely happen in Australia’
Revolut’s data breach shows institutions can be at risk even when not directly compromised
Rohto Pharmaceutical Investigates Cyberattack as Hacker Claims 4.1 TB Data Theft
Romania: Natural Disaster Insurance Pool (PADROM) warns about phishing attempts requesting personal data to verify the PAD policy
Royal Canadian Mounted Police aware of FBI probe into alleged data breach of millions of drivers’ licences in Canada, U.S.
Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
South Korea voice phishing bill could reshape banks’ insurance decisions
South Korea's Financial Services Commission (FSC) Launches Emergency Security Review of Payment Gateways After Data Breach Concerns
Southampton: Names and addresses of 224 people exposed in council data breach
Southport attack victims, survivors and families hit by Ministry of Justice data breach
Southport attack victims' and families' court files accessed in data breach
Southport attack victims' court files accessed in data breach
Spain gets its first taste of AI-aided cyber attack
Spain logs its first data breach allegedly carried out by a rogue AI agent
Spain logs the first data breach caused by an autonomous AI agent
Spain Records Its First Data Breach Blamed on an Autonomous AI Agent
Spain reports the first data breach carried out by an AI agent
Spain’s Agencia Española de Protección de Datos (AEPD) Logs First AI-Powered Breach Case
Spanish data watchdog publicises first AI agent-linked data breach report
Springfield officials say extent of school district data breach remains unclear
Springfield schools provide update on cyber attack, data breach investigation
Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49 Million Records Stolen
The CISO's New Liability Problem: Governing What You Don't Control
The Foot and Ankle Wellness Center Data Breach: 653 Affected
The MRI Scan That Wasn’t: Inside Iran’s ‘Chosen Brick’ Malware Campaign Against Its Critics Abroad
The true cost of a ransomware attack, with and without Business Continuity and Disaster Recovery (BCDR)
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Türkiye: National Intelligence Organization (MİT)-led operation nets five suspects over trade union data breach
UK fintech Revolut reveals customer data breach
Ukraine moves to crack down on scam call centers after corruption scandal
Urgent probe launched after Southport attack victims' files accessed in major data breach
US lawmakers push “No FLOCK Act” to crack down on police surveillance abuse
Vista Del Mar Data Breach Compromises Health Information
Voice phishing bill could reshape banks’ insurance decisions
xHealth Data Breach Affects 118,000 Individuals
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
📅 15th September
4 in 5 Singapore Business Websites Have WordPress Vulnerabilities
12 Irish Revolut Customers Impacted By Data Breach
32 Ransomware Attacks Every Day as Global Threat Hits Record High
A 26-year-old Canadian hacker breached 165 companies and exposed data linked to 100 million people, but an investigation eventually led to his guilty plea
Acronis warns of actively exploited flaw in its cPanel backup plugin
AI the Top Priority for New Spend as Cyber Budgets Flatline
Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Australian software firm Auto-IT confirms customers compromised by Storm ransomware attack
Australia: Student photos, bank details stolen by hackers after St James Anglican School in Perth hit by cyber attack
BambooToken malware controls Windows and Linux systems via Message Queuing Telemetry Transport (MQTT)
BambooToken Malware Uses Message Queuing Telemetry Transport (MQTT) to Control Windows and Linux Systems
Birdi Data Breach Exposes Impacts Employees: SSNs Exposed
Black Axe Members Extradited to US Over Internet Fraud Claims
Canadian telecom giant Telus alerts customers to data breach
CenterPoint confirms customer info exposed in data breach amid class action lawsuits
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy confirms data breach after hacker claims 7.49 Million records
CenterPoint Energy confirms data breach of customer personal information
CenterPoint Energy discloses customer data breach in SEC filing
CenterPoint Energy reports customer data breach in the United States
CenterPoint reports customer data breach
Chess.com scraping exposes 4.7 million email addresses
China spy chief points at US AI models in cyber threat warning
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)
Cisco patches Secure Email Gateway zero-day exploited in attacks
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
Communauto says it was hit by data breach initiated by its own employee
Compromised HBO Max Reddit Account Fueled Massive ClickFix Malware Campaign
Coupang Establishes Information Security Advisory Committee Following Record $460 Million Data Breach Fine
Coupang forms security panel after massive data breach
Critical VMware RCE flaw now exploited by ransomware gangs
Crypto Industry Figures Blackmailed by Revolut's Hacker
Cyber attacks costing SMEs full working week in operational disruption
Department of Motor Vehicles (DMV) breach confirmed as hackers claim 200,000 records stolen
Electric and gas utility CenterPoint Energy warns of data breach after dark web post
Facing Steep Criticism Over Abuse, Flock Updates Platform But Draws Skepticism From Privacy Advocates
Fake Bitrefill Checkouts Spread Through Search Results
Fake Voicemail Transcript Emails Become the Latest Phishing Lure for Thousands of Organizations
FBI to Springfield: school cyber attack included data breach, maybe Social Security numbers
Hacked by email: attackers exploiting critical zero-day in Cisco’s secure email solution
Hackers demand 10,000 Bitcoin from Revolut following data breach
Hackers hijack HBO Max’s verified Reddit account to spread infostealer malware
Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Hackers target WordPress sites via third-party WooCommerce plugin
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
Inside Tajin Group’s Phishing and Money Laundering Network
Inside the Scattered Spider Playbook: How UK Retailers Got Social Engineered
International Meteor Organization Hit by Cyberattack, Weeks of Disruption Expected
Investigation ordered over Southport victims and survivors’ data breach
Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Japan’s Digital Agency Confirms VPN Flaw Exposed 246,000 Personnel Records
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far
Life Unlimited Data Breach Exposes Sensitive Financial and Medical Data
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
Low-quality casino sites conceal highly dangerous threat actors
Majority of Organizations Have Over 50 AI Agents
Malaysia: Port of Tanjung Pelepas resumes operations after cyber attack
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
More than a third of small UK firms impacted by hacks
Most Firms Unable to Recover Quickly from Ransomware
Most Fraudulent Hires Receive Credentials Before Detection
MyChart urges patients to stay alert of phishing scam
Nearly one in three tech workers fell for a phishing test. The biggest predictor was one habit
Nintendo Switch Flaw Lets Nearby Attackers Run Code, Steal Data
Patched VMware vCenter bug targeted in ransomware campaigns
Petco Data Breach Exposes Government ID Numbers
Phishing Scam Targets D.C. Cannabis Applicants and Virginia’s 350 Retail Cap
Ransomware Doesn’t Just Break Systems. It Breaks People
Revolut Breach Exposes IDs, IBANs of 680 Customers
Revolut data breach exposes weakness in security
Revolut Data Breach Hits 680 Customers as UK Regulators Review Case
Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin
Revolut Data Breach Via Fake Government Requests - What We Know So Far
Revolut Faces $780 Million Bitcoin Extortion After Falling Victim to Data Breach Scam
Revolut hacker claims 147 GB stolen from Italian law enforcement
Revolut Hacker Claims 147GB Italian Police Breach
Revolut hacker says they had six months of secret access
Revolut Leaked Customer Data to Fake Government Email Account
Revolut's paperwork breach shows why insurers are rethinking what counts as a 'cyber attack'
Severe oversight flaw - cops abuse Flock network for "LMAO" searches
Severe TP-Link Tapo camera flaw lets hackers watch live feed from your home
South Korea: 12 Sent to Prosecutors for Voice Phishing Laundering, 300 Million Won to China
South Korea: Crackdown on Voice Phishing That Induces Direct Card Payments...Enhanced Credit Card Fraud Detection
South Korea: Financial Supervisory Service (FSS) targets voice phishing of elderly, tightens Korea card fraud checks
Southport attack victims and survivors at centre of ‘unacceptable’ data breach by court staff
Southport attack victims, survivors and families hit by 'completely unacceptable' data breach
Southport attack victims, survivors and families hit by data breach
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores
Suspected Black Axe gang leaders face cybercrime charges in the US
Swiss Bitcoin Pay Says No Evidence Merchant Bitcoin Wallets Were Compromised
Swiss Bitcoin Pay takes servers offline after data breach
The federal government can’t buy cybersecurity at the speed of a cyber attack
UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds
Ukrainian Conti Ransomware Member Gets Four Years in US Prison
Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks
Vulnerable kids' records caught up in cyber attack
Your employees are already using AI tools you never approved
Your Twitch login may be exposed: this one extension is leaking it to Russians
📅 14th September
3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
AI makes cybercrime campaigns cheaper, increasing ransomware attacks
Android security nightmare: unprivileged app take over flagship phones
Another European country is pushing ban on smart glasses
Anthropic reports September 2026 AI misuse in cyberattacks, weapon development and phishing
Automotive Cybersecurity Forecasts Are All Over the Map. Ransomware and Recalls Explain Why
CenterPoint Energy faces class actions over alleged customer data breach
Chess.com User Data Surfaces Online After Suspected Scraping Incident, Over 4.5 Million Emails Exposed, Reportedly from Previous Breaches
ClickFix attacks are tricking Mac and Windows users into hacking themselves
Community Health Care Data Breach Exposes Social Security Numbers
Compromised Police Credentials Spark Florida DMV Data Breach Investigation
Conti ransomware operator sentenced to 4 years in jail for playing part in a $150 Million extortion campaign
Cyber Insurance Solvency Crises: War Exclusion Clauses, Systemic Catastrophe Models, and Ransomware Liabilities
Cyberattack or insider leak? Kochi Metro data breach under police scanner in Keralam
Cybersecurity attention fades within months after a breach
Cybersecurity vigilance fades fast after data breach
Dark Web Hacker Claims to Have Data on 40,000 Twitch Streamers
Data breach at Revolut after attacker posed as government agency
Debian 13.7 ships the fixes behind 92 security advisories, updates 106 packages
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
Diversified Services Enterprises (DSE) Data Breach Exposes PHI and PII: SSNs Compromised
Don’t fall for fake MyChart phishing emails
EasyEquities, Satrix hit by data breach
Elon Musk’s ‘VoteSafe’ site is harvesting and selling voter data
ENISA launched the CRA Single Reporting Platform for actively exploited vulnerabilities
Fears for Irish Revolut customers' data after bank duped by fraud email
Finnish Police Alert Europe Over Fugitive Vastaamo Hacker
Finnish police extend search for Vastaamo hacker Aleksanteri Kivimäki across Europe
Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses
Florida Department of Highway Safety hacked by international criminal group
Florida Highway Safety was hacked. Did cybercriminals get your info?
From baby monitors to smartwatches - EU's new 24-hour breach reporting rule targets consumer manufacturers
Global ransomware attacks hit record 997 in August 2026 as utility, healthcare and business attacks surge
Google Play Early Access Abused by Thousands of Suspicious Android Apps
Grafton City Hospital Data Breach Affects 1,215 Users
Hacker claims to have stolen 40,000 Twitch streamers’ personal info
Hackers Exploit Maximum Severity Flaw in GitLab
Hackers have published Revolut customer data and are demanding a ransom
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers now exploit max severity GitLab flaw in attacks
Hackers target exposed Vite development servers to steal AWS, Azure secrets
Hit by a data breach? Here’s what you need to do
Hong Kong: Phishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Hundreds of fake government websites target users in Central Asia
Inside job suspected in Kochi Metro Rail Ltd (KMRL) data breach
Inside job suspected in Kochi Metro Rail Ltd (KMRL) data breach
Irish Revolut Customers Caught Up in Data Breach After Scammers Pose as Government Officials
Irish Revolut users urged to check accounts as scammers threaten to release data
Israel: Ashkelon man accused of infecting hundreds of computers, stealing sensitive data, hijacking webcams
Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
Kenya cyber attacks up 6% as ransomware nearly doubles globally
LG Pushes Back on Claims That Its Smart TVs Are Spying on Users
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Man who drove around Singapore with ‘blaster device’ to transmit over 10.5k phishing messages gets jail
Man who drove around Singapore with 'SMS blaster' that sent more than 10,000 phishing messages gets jail
Mantax Otax Targets Android Phones With Spyware and Ransomware
Members of ‘Black Axe’ cybercriminal group extradited from South Africa
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft Cloud accounts stolen in highly complex impersonation and passkey phishing campaign
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Next Level Medical Data Breach Exposes PHI and PII
OpenAI Agent Swarm Hacks RubyGems Package Manager
PaperCut Flaw Compromise Illustrates the Maturing Use of AI By Attackers
Penfold Motors latest car dealer to fall victim to the Storm ransomware group
Personal, Financial Info Exposed in Revolut Data Breach
Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
Ransomware attacks in Japan hit record 123 cases in 1st half of 2026
Ransomware gang leaks more than half a million files after Florida DMV hack
Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
Revolut blames ‘sophisticated impersonation scam’ for customer data breach
Revolut Confirms Data Breach After Fraudsters Exploited a Real Government Email, Samples Leak Online
Revolut Confirms Data Breach Through Fake Government Requests
Revolut confirms sensitive customer data breach after fake government requests
Revolut Data Breach: Hackers Leak Customer Documents, Demand Ransom Payment
Revolut Data Breach: Your Files Are Public, and Here Is What You Can Do
Revolut data breach as scammers 'used government email' to steal Irish user data
Revolut Data Breach Exposes Passport Copies, KYC Selfies and Full Transaction Histories
Revolut Data Breach Exposes Records After Email Domain Scam
Revolut discloses accidental data breach following government agency email scam
Revolut discloses data breach exposing financial info, passports
Revolut handed customer data to fraudsters using government email account
Revolut hit by data breach after fake government email scam
Revolut in customer data breach after fake Government requests
Revolut Reveals Data Breach Tied to Faked Official Request
Revolut says some customers’ data exposed in phishing attack
Revolut suffers data breach exposing identity and driving licence details
Russian Hacker Group Claims DDoS Attack on Norway’s Parliament Website
Scammers milking Google Play’s Early Access: no reviews, no ratings, no way to spot the deception
'SMS blaster' in car sent over 10,500 phishing messages as man drove around Singapore
South Korea: "Fell Victim to Phishing"...Waiting for Number Suspension Leads to More Losses
Springfield students back in school, cyber attack still under investigation
Stockton Council: Service boss says threat of cyber-attack to council is 'constant and increasingly sophisticated'
Swiss Bitcoin Pay Shuts Down Servers After Data Breach
Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
Texas Mutual Data Breach Affects 2k: Medical Information Exposed
The UK government is killing passwords for 23 Million Brits
The website of the Norwegian Parliament was targeted in a hacking attack by Russia
Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
Twitch ‘Enhancer’ Extension for Chrome Caught Sending Live OAuth Tokens to Russian Bot Service
Twitch extension with 30K installs exposes users’ OAuth tokens
UK government begins killing off passwords for 23 million users
Vengeful Windows exploit researcher reveals his true identity
What we know about the Revolut data breach so far
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
zHealth EHR Data Breach Exposes Medical Information
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and