Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 21st September and 27th September 2026.📅 22nd September
A cheap fake base station can still track 5G subscribers
AI Agents Are Opening New Doors for Attackers Into SMBs
AI Agents Are Rewriting the Rules of Lateral Movement
AI Drives Surge in Bot and API Threats
AI Incident Response Readiness Lags Behind AI Adoption
AI is set to help cyber attackers much more than defenders, says UK official
Albany College of Pharmacy and Health Sciences Data Breach Settlement
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
Belgian Sports Federations Hit by Cyberattacks, Data Under Investigation
BigCommerce Data Breach Exposes Customer Details Through Third-Party Apps
BigCommerce Ribon: Data Breach via Third-Party Application
Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
BYD removes China and surveillance references from car privacy policy
Canada’s privacy commissioner investigating massive driver’s licence data breach
CISA orders feds to patch Zyxel flaw exploited for data theft
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Clop Ransomware Gang’s Leak Site Hijacked by Rival ShinyHunters
Columbia to settle June 2025 data breach lawsuit for $16.1 million
‘Cyber criminal groups suffer from the same security weaknesses they routinely exploit’: ShinyHunters claims it hacked Clop ransomware rival
D-Link warns of max severity zero-day bug in DIR-822A routers
Digital Operational Resilience Act (DORA) Year Two: Can Your SOC Actually See the Attack?
Doctor's Choice Data Breach Impacts 14,333 Texans
Education sector faces higher email-driven ransomware and account takeover risks
EU Cyber Resilience Act (CRA): What Manufacturers Selling Digital Products in the EU Need to Know About Vulnerability and Incident Reporting
EU Cybersecurity Response Hampered by Critical Information Gaps
EU Fines Google 403 Million Euros For Location Data Breach
Google Faces €403 Million GDPR Fine Over Location Tracking
Google fined $463 million over EU data breach
Google’s location tracking comes with a €403 Million fine
Hackers are using AI agents to breach companies in just hours, Anthropic says
Hackers breach two Colorado water utility companies
Hacking the hackers: ShinyHunters breaches Clop ransomware site
India’s Department of Telecommunications (DoT) Warns Citizens Over SIM Fraud and IMEI Tampering
Kaspersky Uncovers ‘Payload,’ a Stealth Ransomware Targeting Corporate Devices
Kaspersky uncovers stealthy ‘Payload’ ransomware campaign targeting corporate networks
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Meta’s Muse AI Agent Has a Zero-Day That Lets Malware Hijack Its Microphone
Meta’s Muse AI assistant can be hijacked through a simple attack
Microsoft and Coinbase probe leads to arrest of crooks behind ‘EvilTokens’, a DIY phishing network powered by AI
Namibia: Ransomware group targets defence ministry
Nepal: Stock Market Trading Halted Due to Cyber Attack on Data Center
Nepal Stock Exchange (NEPSE) ‘technical glitch’ was a ransomware attack. What happened?
Network Segmentation Failures Are Expanding the Corporate Attack Surface
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
New Windows Defender zero-day blocks Microsoft antivirus updates
North Korean Attackers Hit 30,000 Devices and Steal $10.7 million
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
PAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacks
Potential data breach may affect nearly 2 million people in Czech Republic
Quest breach included thousands of credit card CVVs
Quest Hotels data breach: Almost 2 million impacted, almost 50k credit cards compromised
Ransomware Without Encryption: PAYLOAD Weaponizes Windows Group Policy
Researchers uncover malware that uses AI to choose its next move
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
ShinyHunters breaches Clop ransomware site and demands payment
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
South Korea's Kakao Games Data Breach Victims Rise to 243 as 103 More Confirmed
The latest deepfake numbers give CISOs plenty to worry about
The next intellectual property thief may sound like your CEO
The Philippines: Land Transportation Franchising and Regulatory Board (LTFRB) flags data breach
Warning Issued Over Fake 'Seoul Citizen Safety Insurance' Phishing Sites...Beware of Personal Info Requests
When the Phishing Page Exists Only Inside the Browser
Why Ransomware Gangs Are Launching Cyber Attacks on Each Other
Why Security Needs to Stay Alert in the ShinyHunters, Clop Feud
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
📅 21st September
A Background Check Is Only as Reliable as the Identity Behind It
AI agents on Amazon Web Services (AWS) can access and leak secrets, researchers warn
AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Allergy Centers Data Breach Compromises Social Security Numbers
Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach
Analysts Link Fetch.ai, NuNet, and SingularityNET Attacks to Single Hacker
Anatomy of a Ransomware Recovery: Hour by Hour
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Australian not-for-profit Thorndale Foundation investigating Qilin breach claims
Australians love these cars. Experts have 'real security concerns'
Belgian table tennis, gymnastics federations hit by cyberattacks
BigCommerce alerts merchants of data breach linked to Ribon apps
Boustead Singapore Reveals Cybersecurity Incident at Overseas Unit
Canadian investigation launched into data breach that exposed millions of IDs
CenterPoint Energy confirms data breach exposure for Indiana customers following alleged 7.5 million record leak
ChatMinerva breached, intruder accessed databases with users' chats
China-Linked FamousSparrow Deploys SparroWocky Backdoor in Latin America
China-nexus actor steals thousands of documents in monthslong exploitation campaign
CISA alerts of active exploitation of three Linux kernel flaws
CISA, FBI and Partners Detail Gunra Ransomware Tactics
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Clop Ransomware Responds to ShinyHunters Amid Eight-Figure Demands
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71 Million in Crypto
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Cyber Attack to Cost Springfield Schools Time on Winter Break
Cyberattack hits University of Munich, potentially exposing student financial data
Cybercrime civil war brewing? ShinyHunters reportedly hacks Cl0p ransomware gang and threatens further damage
Cybercriminal Claims Moneyboxx Finance Breach, Posts Alleged Source Code on PwnForums
Data Breach at Translation Vendor Affects UnitedHealthcare Plan Members
Data Protection Commission fines Google 403 million euros for location data breach
Employees sue global agribusiness following criminal data breach
EU data regulator fines Google more than $460 million for location data violations
EU fines Google 403 million euros for location data breach
EU fines Google €403 million over location data breach
EU hits Google with €403 million fine over location data breach
EU slaps Google with USD 463 million fine over location data breach
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
French Crypto Holders Flooded With Fake Support Calls After Tax Data Breach
Gone Phishing? Cybercriminals Are Getting Savvier
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Google fined €403 million over location data privacy violations
Google Gemini demonstrates ability to Cyber Attack Companies after OpenAI Cyber Incident
Google Hit with €403 million GDPR Fine Over Location Data Practices
Google hit with €403 million GDPR fine over location tracking
Google says Gemini breached three companies during security test
Google Wants Android Apps to Look Beyond the Security Patch Date
Greystar Data Breach Exposes Personal and Financial Data
Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Hacked? Qantas investigating WhatsApp phishing reports
Hacker group claims to have hijacked rival gang's website
Hacker Group Exposes Major Vulnerabilities in Flock Automated License Plate Readers
Hacker-on-Hacker Crime: ShinyHunters Is Trying to Extort CLOP Ransomware Group
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Hackers gain brief control over LNG vessel safety systems near Gibraltar
Intent injection attacks are a new worry for AI-native 6G networks
Ireland fines Google €403 million on behalf of EU for location data breach
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
Leggett & Platt Data Breach Impacts Adults and Minor Dependents: Personal Information Exposed
LeMaitre Vascular Data Breach Exposes Social Security Numbers
Lessons must be learnt from cyber attack on Revolut, experts warn
Lincoln Investment Data Breach Compromises SSNs and Medical Records
LinkedIn wins court order blocking mass scraping of user data
Maltese accounts may be affected by Revolut data breach
Maltese Accounts Reportedly Among 680 Impacted By Revolut Data Breach
Massachusetts fines TradeZero for data breach, compromising personal information of thousands
MedImpact Data Breach Exposes Personal Information
Mexico probes possible Aeromexico customer data breach
Nepal: Glitches on stock trading platform risk investments of 8 million investors
Nepal: Ransomware attack on Data Hub forces stock market to halt trading
Nepal: Ransomware attack shuts stock market as investors raise security concerns
Nepal stock market halted after ransomware attack disrupts 72 brokers
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
New York healthcare provider suffers data breach affecting over 280,000
North Korea’s job interview scam runs both ways
North Korean WaterPlum Hackers Infected 30,000 Devices Through Fake Job Interviews
PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
PAYLOAD Ransomware Hijacks Active Directory Group Policy for Encryptionless Extortion
Qantas investigates WhatsApp phishing reports targeting customers
Raising the alarm: Brigham Young University (BYU) researchers find AI is an effective tool in phishing scams
Revolut Customers Targeted with New Wave of Phishing Attacks
Rosch Visionary Systems Data Breach Exposes PHI
Royal College of Veterinary Surgeons (RCVS) apologises after month-long Find a Vet data breach
Royal National Lifeboat Institution (RNLI) warns supporters of possible data breach as it faces far-right targeting
Russia reports thousands of cyberattacks on election infrastructure during vote
Rust developers targeted by hackers with fake job calls and malicious commands
Scammers impersonate cops, use arrest threats to extort victims
‘Scary how open’: BYD Shark 6 remotely hacked during cyber safety test
Securing AI Agents Requires More Than a One-Time Risk Assessment
Severe Bluetooth flaw allows hackers to take over DJI drones in mid-air
ShinyHunters allegedly launches Cyber Attack on Clop Ransomware Group leading to Data Theft
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
ShinyHunters defaces Clop ransomware data leak site, claims data theft
ShinyHunters Extortion Syndicate Hijacks Cl0p Ransomware Dark Web Infrastructure
ShinyHunters Hacks Cl0p’s Dark Web Leak Site in Ransomware Gang Feud
Some Maltese accounts caught up in Revolut data breach, hacker says
South African organisations are taking longer to recover from ransomware attacks
Spanish privacy regulator probes AI agent-driven cyber attack
Taiwan Fines Coupang $47,000 Over Data Breach Hitting 200,000 Users
Taiwan fines Coupang over data breach impacting 200,000 users
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
TD Bank Data Breach Exposes Personal and Financial Information
Texas Regional Asthma, Allergy & Immunology Center (TRAAC) Data Breach Impacts 5,040 Patients: Medical Info Exposed
The Philippines: Data breach hits Land Transportation Franchising and Regulatory Board (LTFRB) online system
The Philippines: National Privacy Commission (NPC) reports Land Transportation Franchising and Regulatory Board (LTFRB) online system data breach
The recovery costs of a ransomware attack in South Africa is over $1 million
The ‘significant’ threat of a major cyber attack on Greater Manchester
The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files
Tishman Speyer Data Breach Compromises Social Security Numbers
WaterPlum Hackers Steal $10.7 Million in Crypto From IT Workers
What To Do After a Healthcare Data Breach: Tips for Nurses
Why Spam Filters Struggle as AI Rewrites Phishing Emails
Why was Nepal’s stock market shut on Monday
WordPress Click2Shell flaw lets hackers execute PHP on the server
Welcome to DBD. On March 8th 2026, DBD celebrated it's sixth anniversary and