Editor's Message

Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and PRiSM celebrated it's third anniversary. Both projects have made a huge impact on my life and I'd like to thank each and everyone of you who have supported me, with special thanks to those individuals and communities who have helped me build up my knowledge on cybercrime and ransomware over the years. Thanks again for all your continued support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington D.C.
0
Data-Leaking Ransomware Attacks Tracked This Month
0
Data-Leaking Ransomware Attacks Tracked This Year



Monday, 21 September 2026

Data Breaches Digest - Week 39 2026

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 21st September and 27th September 2026.


📅 22nd September

A cheap fake base station can still track 5G subscribers

AI Agents Are Opening New Doors for Attackers Into SMBs

AI Agents Are Rewriting the Rules of Lateral Movement

AI Drives Surge in Bot and API Threats

AI Incident Response Readiness Lags Behind AI Adoption

AI is set to help cyber attackers much more than defenders, says UK official

Albany College of Pharmacy and Health Sciences Data Breach Settlement

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Belgian Sports Federations Hit by Cyberattacks, Data Under Investigation

BigCommerce Data Breach Exposes Customer Details Through Third-Party Apps

BigCommerce Ribon: Data Breach via Third-Party Application

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

BYD removes China and surveillance references from car privacy policy

Canada’s privacy commissioner investigating massive driver’s licence data breach

CISA orders feds to patch Zyxel flaw exploited for data theft

CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns

Clop Ransomware Gang’s Leak Site Hijacked by Rival ShinyHunters

Columbia to settle June 2025 data breach lawsuit for $16.1 million

‘Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware rival

D-Link warns of max severity zero-day bug in DIR-822A routers

Digital Operational Resilience Act (DORA) Year Two: Can Your SOC Actually See the Attack?

Doctor's Choice Data Breach Impacts 14,333 Texans

Education sector faces higher email-driven ransomware and account takeover risks

EU Cyber Resilience Act (CRA): What Manufacturers Selling Digital Products in the EU Need to Know About Vulnerability and Incident Reporting

EU Cybersecurity Response Hampered by Critical Information Gaps

EU Fines Google 403 Million Euros For Location Data Breach

Google Faces €403 Million GDPR Fine Over Location Tracking

Google fined $463 million over EU data breach

Google’s location tracking comes with a €403 Million fine

Hackers are using AI agents to breach companies in just hours, Anthropic says

Hackers breach two Colorado water utility companies

Hacking the hackers: ShinyHunters breaches Clop ransomware site

India’s Department of Telecommunications (DoT) Warns Citizens Over SIM Fraud and IMEI Tampering

Kaspersky Uncovers ‘Payload,’ a Stealth Ransomware Targeting Corporate Devices

Kaspersky uncovers stealthy ‘Payload’ ransomware campaign targeting corporate networks

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

Meta’s Muse AI Agent Has a Zero-Day That Lets Malware Hijack Its Microphone

Meta’s Muse AI assistant can be hijacked through a simple attack

Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI

Namibia: Ransomware group targets defence ministry

Nepal: Stock Market Trading Halted Due to Cyber Attack on Data Center

Nepal Stock Exchange (NEPSE) ‘technical glitch’ was a ransomware attack. What happened?

Network Segmentation Failures Are Expanding the Corporate Attack Surface

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

New TASK#STOMP Windows Backdoor Enables Continuous Document Theft

New Windows Defender zero-day blocks Microsoft antivirus updates

North Korean Attackers Hit 30,000 Devices and Steal $10.7 million

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks

Potential data breach may affect nearly 2 million people in Czech Republic

Quest breach included thousands of credit card CVVs

Quest Hotels data breach: Almost 2 million impacted, almost 50k credit cards compromised

Ransomware Without Encryption: PAYLOAD Weaponizes Windows Group Policy

Researchers uncover malware that uses AI to choose its next move

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

ShinyHunters breaches Clop ransomware site and demands payment

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

South Korea's Kakao Games Data Breach Victims Rise to 243 as 103 More Confirmed

The latest deepfake numbers give CISOs plenty to worry about

The next intellectual property thief may sound like your CEO

The Philippines: Land Transportation Franchising and Regulatory Board (LTFRB) flags data breach

Warning Issued Over Fake 'Seoul Citizen Safety Insurance' Phishing Sites...Beware of Personal Info Requests

When the Phishing Page Exists Only Inside the Browser

Why Ransomware Gangs Are Launching Cyber Attacks on Each Other

Why Security Needs to Stay Alert in the ShinyHunters, Clop Feud

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

📅 21st September

A Background Check Is Only as Reliable as the Identity Behind It

AI agents on Amazon Web Services (AWS) can access and leak secrets, researchers warn

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Allergy Centers Data Breach Compromises Social Security Numbers

Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach

Analysts Link Fetch.ai, NuNet, and SingularityNET Attacks to Single Hacker

Anatomy of a Ransomware Recovery: Hour by Hour

Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

Australian not-for-profit Thorndale Foundation investigating Qilin breach claims

Australians love these cars. Experts have 'real security concerns'

Belgian table tennis, gymnastics federations hit by cyberattacks

BigCommerce alerts merchants of data breach linked to Ribon apps

Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit

Canadian investigation launched into data breach that exposed millions of IDs

CenterPoint Energy confirms data breach exposure for Indiana customers following alleged 7.5 million record leak

ChatMinerva breached, intruder accessed databases with users' chats

China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America

China-nexus actor steals thousands of documents in monthslong exploitation campaign

CISA alerts of active exploitation of three Linux kernel flaws

CISA, FBI and Partners Detail Gunra Ransomware Tactics

ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71 Million in Crypto

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

Cyber Attack to Cost Springfield Schools Time on Winter Break

Cyberattack hits University of Munich, potentially exposing student financial data

Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage

Cybercriminal Claims Moneyboxx Finance Breach, Posts Alleged Source Code on PwnForums

Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members

Data Protection Commission fines Google 403 million euros for location data breach

Employees sue global agribusiness following criminal data breach

EU data regulator fines Google more than $460 million for location data violations

EU fines Google 403 million euros for location data breach

EU fines Google €403 million over location data breach

EU hits Google with €403 million fine over location data breach

EU slaps Google with USD 463 million fine over location data breach

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

French Crypto Holders Flooded With Fake Support Calls After Tax Data Breach

Gone Phishing? Cybercriminals Are Getting Savvier

Google Fined €403 Million Over GDPR Violations Tied to Location Data

Google fined €403 million over location data privacy violations

Google Gemini demonstrates ability to Cyber Attack Companies after OpenAI Cyber Incident

Google Hit with €403 million GDPR Fine Over Location Data Practices

Google hit with €403 million GDPR fine over location tracking

Google says Gemini breached three companies during security test

Google Wants Android Apps to Look Beyond the Security Patch Date

Greystar Data Breach Exposes Personal and Financial Data

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Hacked? Qantas investigating WhatsApp phishing reports

Hacker group claims to have hijacked rival gang's website

Hacker Group Exposes Major Vulnerabilities in Flock Automated License Plate Readers

Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Hackers gain brief control over LNG vessel safety systems near Gibraltar

Intent injection attacks are a new worry for AI-native 6G networks

Ireland fines Google €403 million on behalf of EU for location data breach

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed

LeMaitre Vascular Data Breach Exposes Social Security Numbers

Lessons must be learnt from cyber attack on Revolut, experts warn

Lincoln Investment Data Breach Compromises SSNs and Medical Records

LinkedIn wins court order blocking mass scraping of user data

Maltese accounts may be affected by Revolut data breach

Maltese Accounts Reportedly Among 680 Impacted By Revolut Data Breach

Massachusetts fines TradeZero for data breach, compromising personal information of thousands

MedImpact Data Breach Exposes Personal Information

Mexico probes possible Aeromexico customer data breach

Nepal: Glitches on stock trading platform risk investments of 8 million investors

Nepal: Ransomware attack on Data Hub forces stock market to halt trading

Nepal: Ransomware attack shuts stock market as investors raise security concerns

Nepal stock market halted after ransomware attack disrupts 72 brokers

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

New York healthcare provider suffers data breach affecting over 280,000

North Korea’s job interview scam runs both ways

North Korean WaterPlum Hackers Infected 30,000 Devices Through Fake Job Interviews

PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption

PAYLOAD Ransomware Hijacks Active Directory Group Policy for Encryptionless Extortion

Qantas investigates WhatsApp phishing reports targeting customers

Raising the alarm: Brigham Young University (BYU) researchers find AI is an effective tool in phishing scams

Revolut Customers Targeted with New Wave of Phishing Attacks

Rosch Visionary Systems Data Breach Exposes PHI

Royal College of Veterinary Surgeons (RCVS) apologises after month-long Find a Vet data breach

Royal National Lifeboat Institution (RNLI) warns supporters of possible data breach as it faces far-right targeting

Russia reports thousands of cyberattacks on election infrastructure during vote

Rust developers targeted by hackers with fake job calls and malicious commands

Scammers impersonate cops, use arrest threats to extort victims

‘Scary how open’: BYD Shark 6 remotely hacked during cyber safety test

Securing AI Agents Requires More Than a One-Time Risk Assessment

Severe Bluetooth flaw allows hackers to take over DJI drones in mid-air

ShinyHunters allegedly launches Cyber Attack on Clop Ransomware Group leading to Data Theft

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment

ShinyHunters defaces Clop ransomware data leak site, claims data theft

ShinyHunters Extortion Syndicate Hijacks Cl0p Ransomware Dark Web Infrastructure

ShinyHunters Hacks Cl0p’s Dark Web Leak Site in Ransomware Gang Feud

Some Maltese accounts caught up in Revolut data breach, hacker says

South African organisations are taking longer to recover from ransomware attacks

Spanish privacy regulator probes AI agent-driven cyber attack

Taiwan Fines Coupang $47,000 Over Data Breach Hitting 200,000 Users

Taiwan fines Coupang over data breach impacting 200,000 users

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

TD Bank Data Breach Exposes Personal and Financial Information

Texas Regional Asthma, Allergy & Immunology Center (TRAAC) Data Breach Impacts 5,040 Patients: Medical Info Exposed

The Philippines: Data breach hits Land Transportation Franchising and Regulatory Board (LTFRB) online system

The Philippines: National Privacy Commission (NPC) reports Land Transportation Franchising and Regulatory Board (LTFRB) online system data breach

The recovery costs of a ransomware attack in South Africa is over $1 million

The ‘significant’ threat of a major cyber attack on Greater Manchester

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

Tishman Speyer Data Breach Compromises Social Security Numbers

WaterPlum Hackers Steal $10.7 Million in Crypto From IT Workers

What To Do After a Healthcare Data Breach: Tips for Nurses

Why Spam Filters Struggle as AI Rewrites Phishing Emails

Why was Nepal’s stock market shut on Monday

WordPress Click2Shell flaw lets hackers execute PHP on the server