Editor's Message

Welcome to DBD. On March 8th, DBD celebrated it's 5th anniversary and PRiSM celebrated it's 2nd anniversary. Little did I know when I started both of these ventures just how much an impact they would have on my life and I'd like to thank each and everyone of you who have supported me over the years, with a special thanks to those individuals who have kindly shared their knowledge with me, and continue to do so. Thanks again for your support. Stay safe. :)


“Data Breaches Digest and its PRiSM portal provide Dentons Global Security Team with valuable insights into the ransomware landscape, from the latest incidents to trends over time, as well as the ability to customize visual analytics. Timely reports and tracking by Data Breaches Digest help inform cyber intelligence for the world’s largest law firm and thus our cybersecurity posture across more than 80 countries worldwide.”
Dentons Senior Analyst, Washington DC



Monday, 15 September 2025

Ransomware Operator Claims - Week 37 2025

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 8th September and 14th September 2025, kindly assisted by our partners.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Data Breaches Digest - Week 38 2025

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 15th September and 21st September 2025.


17th September

300+ Websites Taken Down by Microsoft for Distributing RaccoonO365 Phishing Service

A data breach of epic proportions in Vietnam

A Quarter of UK and US Firms Suffer Data Poisoning Attacks

AI Chatbots Promoting Cybercrime? ChatGPT, Grok and Meta AI Are Happy to Write Phishing Emails

Amended Lawsuit Accuses TaskUs of Concealing Coinbase Data Breach

Android apps with millions of downloads stealing ad money right under Google’s nose

Australia: 36-year-old man charged over alleged phishing scam targeting mobile users

Baltimore hospital network victim of major data breach, hackers claim

Black Hills Regional Eye Institute Alerts Patients to January Data Breach

BreachForums founder resentenced to 3 years prison, former freebie deal revoked by US courts

BreachForums Hacker Sentenced to 3 Years in Prison

BreachForums Owner Sent to Prison in Resentencing

Brits are better than Americans at spotting phishing scams, NordVPN study shows

Building a strong defence: A guide to ransomware resilience

China-aligned TA415 escalates cyberattacks on Taiwanese semiconductor manufacturing, supply chains

Coinbase Data Breach: Customer Records Sold for $200 Per Image

Coinbase Data Breach: Insider Plot and Alleged Cover-Up Exposed

Coinbase Data Breach Hits 69,000 Users After Insider Sells Sensitive Info

Cybersecurity researchers identify ransomware using open-source tools

Cybersecurity training programs don't prevent employees from falling for phishing scams

Data breach at Tiffany’s exposes gift card numbers

Department of Justice (DOJ) Resentences BreachForums Founder to 3 Years for Cybercrime and Possession of Child Sexual Abuse Material (CSAM)

Dutch Tech Firm Vurbis Interactive Allegedly Breached – Data of Nearly 89,000 Users for Sale

Emergency intervention plea as Birmingham Jaguar Land Rover (JLR) supplier makes lay offs

Europol adds Spanish academic to Most Wanted list for aiding pro-Russian hackers

Fairmont Federal Credit Union Data Breach in 2023 Hits Nearly 190,000 People

FileFix In The Wild: Phishing Campaign Hides Malware Inside Photographs

Florida Eye Care Provider Data Breach Affects 153,000 Patients

From Teen Hacker to Inmate: U.S. Court Resentences BreachForums Founder to Three Years Behind Bars

Fundline Finance Corporation of the Philippines Allegedly Hit by Massive Data Breach, 1 Million Users’ Data for Sale

Global Equipment Giant CNH Industrial Allegedly Breached by Ransomware Attack

Global K-12 school ransomware response improving, report finds

GOLD SALEM’s Warlock operation joins busy ransomware landscape

Government urged to step in as UK car maker struggles with cyber attack

Hackers steal client data from Kering’s Gucci, Balenciaga and McQueen

How a Plaintext File On Users’ Desktops Exposed Secrets Leading to Akira Ransomware Attacks

Hackers steal hotel guests’ payment data in new AI-driven campaign

How Enterprises Can Manage Open-Source Security When the Shift Left Meets End of Life

How exposure management could have prevented this data breach

Hundreds of NPM packages compromised as ongoing supply chain attack snowballs out of control

Infamous BreachForums founder will be heading to jail after all

Insight Partners Data Breach Affects Sensitive Info

Introducing The Gentlemen, a new ransomware group who are anything but

Jaguar Land Rover bracing itself for huge £120m hit as it extends shutdown following cyber attack

Jaguar Land Rover cyber attack: No discussions' on taxpayer aid to suppliers

Jaguar Land Rover Cyber Attack: Production Halt Extends To 3 Weeks

Jaguar Land Rover (JLR) cyber attack could cost firm over £100 million

Jaguar Land Rover cyber attack outage continues - systems unlikely to be online for another week

Jaguar Land Rover (JLR) extends shutdown as supply chain suffers

Jaguar Land Rover (JLR) hack: Supply chain staff told to apply for Universal Credit, claims union

Jaguar Land Rover production down for at least another week due to cyberattack

Jaguar Land Rover says IT disruption set to continue

Jaguar Land Rover (JLR) supply chain staff told to apply for universal credit, union claims

Jaguar Land Rover (JLR) supply chain workers told to apply for Universal Credit after cyber attack, union claims

Jaguar Land Rover’s cyber-attack stoppage enters third week

Latvia: Health authority official and IT company head fined for data breach

Lotte Card data breach impacts over 1 million users

Lotte Card's data breach more severe than initially reported

Major Bangladeshi ISP Link3 Technologies Allegedly Breached, Data of 189,000 Users for Sale

Microsoft and Cloudflare disrupt massive RaccoonO365 phishing service

Microsoft and Cloudflare teamed up to dismantle the RaccoonO365 phishing service

Microsoft busts Telegram-based phishing hub RaccoonO365 and links it to Nigerian programmer

Microsoft Dismantles 300+ Websites Used to Distribute RaccoonO365 Phishing Service

Microsoft disrupts global phishing campaign that led to widespread credential theft

Microsoft disrupts Nigerian-led RaccoonO365 phishing network, seizes 338 domains

Microsoft Disrupts RaccoonO365 Phishing Kit, Seizes 338 Malicious Sites

Microsoft Disrupts RaccoonO365 Phishing-as-a-Service, Seizing 338 Domains

Microsoft disrupts the RaccoonO365 Phishing-as-a-Service operation, names alleged leader

Microsoft exposes Nigerian coder behind phishing operation targeting 365 users

Microsoft pulls down Nigerian-led RaccoonO365 Phishing Network, seizes 338 domains

Microsoft Seizes 338 Nigerian-Linked Websites Running Raccoon0365 Phishing Network

Microsoft seizes 340 websites linked to growing phishing subscription service

Microsoft Seizes 340 Websites Linked To Nigerian-Run Phishing Service

Microsoft Seizes 340 Websites Over Phishing

Microsoft seizes websites linked to Nigeria-based phishing

Microsoft Shuts Down RaccoonO365 Phishing Ring, Seizes 338 Websites

Microsoft Takes Down 300+ Websites Behind RaccoonO365 Phishing Scheme

Microsoft Takes Down Major Phishing-as-a-Service, Foiling Attacks on Thousands of Users

Microsoft, Cloudflare disrupt RaccoonO365 phishing-as-a-service platform

Millions of Gucci, Balenciaga and Alexander McQueen customer records ransomed in cyberattack

New Shai-hulud Worm Infecting npm Packages With Millions of Downloads

News-Press & Gazette allegedly compromised by Termite ransomware gang

North Korean operation uses ChatGPT to forge military IDs as part of cyberattack

Official Chinese Enterprise Services Website for Foshan Allegedly Hacked

Old file types, new tricks: Attackers turn everyday files into weapons

Over 1 Million Records of Poste Italiane Customers Allegedly Leaked in Data Breach

Pennsylvania attorney general gives update on cyber attack

Personal data of 1.5 million people leaked in Swedish data breach

Phishing dominates Summer 2025

Phishing-as-a-Service: The New Threat to Global Crypto Business Banking

Pollard & Associates Data Breach Affects Thousands

Potential data breach: York County investigates unauthorized access to email account

RaccoonO365 Phishing Network Dismantled as Microsoft, Cloudflare Take Down 338 Domains

RaccoonO365 Phishing Service Disrupted, Leader Identified

Ransom demands drop 73% as education sector improves ransomware recovery

Ransomware’s new frontier: Extortion attacks evolve in Asia Pacific

Reimagine Network reports data breach impacting nearly 4,800 patients

Rentable Nvidia rigs are putting passwords at risk

Russian hackers bombard Liverpool City Council with cyberattacks

Russian Online Retailer Vincci Allegedly Suffers Data Breach - Customer Database Leaked

Sarcoma Ransomware Group Allegedly Breaches German Companies Pfullendorfer Tor-Systeme, KWG, F1-Generation, and IAD GmbH

Scattered Spider not dark after all: researchers see signs of life in new attacks

Shai-Hulud Worm Infects Over 500 NPM Packages in Sophisticated Supply Chain Attack

Shai-Hulud Worm Prowls npm to Steal Hundreds of Secrets

Sophos Study Reveals Education Sector Gaining Ground in Ransomware Defense

Spanish Airline Helity Copter Airlines Allegedly Breached, 2 Million Records For Sale

TaskUs accused of ‘silencing’ employees investigating Coinbase data breach

TaskUs Employees Behind Coinbase Breach, US Court Filing Alleges

The passwords criminals can crack in under a second, warn experts

The Property Business Australia allegedly breached by Kairos ransomware

The rise of the student hacker: Dozens of UK schools have fallen victim to insider attacks by their own pupils, worrying Information Commissioner’s Office (ICO) research shows

Tiffany & Co. Data Breach Affects Thousands of Customers

Tiffany & Co. Data Breach Exposes Gift Card Details of Over 2,500 Clients

Tiffany & Co. reveals data breach compromised some Canadian customers’ personal information

UEFI Under Attack? What You Need to Know About HybridPetya Ransomware

Ukranian Ransomware Administrator Charged with 250+ Cyber Attacks, $11M Reward Offered

Venture Capital (VC) firm Insight Partners says thousands of staff and limited partners had personal data stolen in a ransomware attack

Vibe Coding: Managing the Strategic Security Risks of AI-Accelerated Development

Wait, this isn’t ChatGPT? Malware Uses Open-Source AI App to Deploy Ransomware

Warlock Ransomware Allegedly Breaches Hitachi HTA, Medkar, ELS Surveying, Webville, SSA Group, Ferus Smit, and Chroma ATE

Who are Jaguar Land Rover cyber attack hackers as Scattered Lapsus$ Hunters issue key statement

Who are Jaguar Land Rover cyber attack hackers? Scattered Lapsus$ Hunters issue statement

World’s Biggest Hacker Forum Admin Gets Resentenced to Serve Three More Years

You May Have to Wait a Little Longer for That Jaguar in the UK as Cyberattack Continues to Hamper Production

16th September

1.1 million Farmers Insurance customers hit by data breach linked to Salesforce hack

15 Ransomware Gangs Declare End of Operations on BreachForum

40 npm Packages Compromised in Supply Chain Attack Using bundle.js to Steal Credentials

After Uvalde CISD cancels classes due to ransomware attack, FBI outlines growing threat

AI Chatbots Like Grok Craft Phishing Scams Targeting Seniors, Reuters Finds

AI video surveillance could end privacy as we know it

Anthropic Report Shows Bad Actors Abusing Claude in Attacks

API Threats Surge to 40,000 Incidents in 1H 2025

Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack

Apple backports zero-day patches to older iPhones and iPads

Assisted Living Pharmacy Service reports cyberattack, ransomware group claims responsibility

Australia: Man arrested over alleged mobile phishing scam

Bags of info stolen from multiple top luxury brands - double check your data now

BreachForums administrator given three-year prison stint after resentencing

BreachForums hacking forum admin resentenced to three years in prison

Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover

ChatGPT, Gemini, Claude, Meta AI easily made phishing emails to scam elders, in a study

Chinese AI Villager Pen Testing Tool Hits 11,000 PyPI Downloads

CrowdStrike Among Those Hit in NPM Attack Campaign

Cyber resilience must be engineered into the UK’s infrastructure future

Data breach exposes secrets of China's censorship firewall

Data Leak Allegedly Hits Israeli Financial Firm GoldenBit

Ex-Employee Sparks Major Data Breach at FinWise Bank

FBI ‘aware’ of Anchorage health clinic data breach as hackers claim 60K patients impacted

Fears Jaguar Land Rover (JLR) shutdown could 'last until November' amid worries suppliers could go bust

Fifteen Ransomware Gangs “Retire,” Future Unclear

Finance apps are much more interested in you than you think

FinWise Bank Warns of Insider Data Breach

Founder of One of World’s Largest Hacker Forums Resentenced to Three Years in Prison

Generative AI enables rapid phishing attacks on older users

GitHub adds post-quantum protection for SSH access

Google Confirms Law Enforcement Portal Breach by “Scattered Lapsus$ Hunters,” Reports No Data Was Accessed

Google nukes 224 Android malware apps behind massive ad fraud campaign

Gucci and Alexander McQueen Hit by Customer Data Breach

Gucci, Balenciaga & Alexander McQueen Victims of Major Data Breach via Salesforce Attack

Gucci, Balenciaga and Alexander McQueen Breach Linked to ShinyHunters

Gucci, Balenciaga and McQueen customers hit in massive Kering data breach

Gucci, Balenciaga Suffer Data Breach, A Whopping 7.4 Million Customer Records Stolen, All You Need To Know

Gucci, Balenciaga, McQueen confirm breach, Shiny Hunters claim 7.4 Million customers' data stolen

Hackers Claim Access to State Bank of Vietnam’s Creditor Database; Investigation Underway

Hackers setting traps for vibe coders: AI assistants can deliver malware

Hackers steal client data from Kering's Gucci, Balenciaga and McQueen

Insider breach at FinWise Bank exposes data of 689,000 American First Finance (AFF) customers

Jaguar Land Rover 'contacting' certain UK households after cyber attack

Jaguar Land Rover (JLR) continues pause on new car production due to cyber attack

Jaguar Land Rover (JLR) cyber attack: production won't restart until 24th September at earliest

Jaguar Land Rover cyber attack 'costing £1 billion in lost sales revenue'

Jaguar Land Rover extends cyber-attack production pause

Jaguar Land Rover (JLR) Extends Production Halt After Cyber-Attack

Jaguar Land Rover extends production pause for another week after cyber attack

Jaguar Land Rover extends production shutdown after cyber-attack

Jaguar Land Rover extends production shutdown after devastating cyber attack in fresh update

Jaguar Land Rover extends production shutdown for another week as 'forensic investigation' into cyber attack drags on

Jaguar Land Rover extends shutdown after cyberattack by another week

Jaguar Land Rover extends shutdown at its factories after cyber attack

Jaguar Land Rover (JLR) extends UK factory closure, union warns of job loss: How Tata-owned carmaker is tackling cyber attack impact

Jaguar Land Rover faces £120 million hit as it extends factory shutdown after cyber attack

Jaguar Land Rover issues major update on cyber attack which has halted production

Jaguar Land Rover issues major update on devastating cyber attack

Jaguar Land Rover issues update on job safety after cyber attack

Jaguar Land Rover says cyberattack shutdown to last 'at least' another week

Jaguar Land Rover supply chain jobs 'at risk' over cyber attack

Jaguar Land Rover's production pause extended for another week after major cyber attack

Kering Confirms Cyber-Attack: Hackers Steal Data from Gucci, Balenciaga, and McQueen

Kering data breach: Gucci and Balenciaga owner confirms hack, says no financial data leaked

Kering hit by massive data breach impacting Gucci and Balenciaga clients

Kering-owned Gucci, Balenciaga and McQueen hit by data breach in cyber attack

Keys Pathology Associates reports vendor breach impacting 13,756 patients

KillSec Ransomware Attacking Healthcare Industry IT Systems

Luxury Leak Horror: Gucci, Balenciaga and McQueen Hacked in Cyber-Attack Exposing Millions of High-End Shoppers

Major fashion company Kering Group confirms data breach

Microsoft blocks bait for ‘fastest-growing’ 365 phish kit, seizes 338 domains

Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing service

Microsoft seizes hundreds of phishing sites tied to massive credential theft operation

Millions of Customer Records Stolen in Cyberattack on Gucci, Balenciaga, and Alexander McQueen

More than 69,000 people in Wisconsin impacted by TransUnion data breach

New FileFix attack uses steganography to drop StealC malware

New FileFix Phishing Variant Deploys StealC Malware via Steganography

New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site

NPM users hit again: Advanced supply chain attack infiltrates over 40 packages

Ongoing FileFix Attack Installs StealC Infostealer Via Fake Facebook Pages

Operational Technology (OT) security needs continuous operations, not one-time fixes

Panama’s Ministry of Economy and Finance Confirms Cyberattack and Data Breach

Parent company of Gucci, Balenciaga hit by cyber attack

Personal data of 1.5 million people leaked in Swedish data breach

Philadelphia warns residents of phishing text scam targeting bank info

Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds

Poland boosts cybersecurity to €1B after Russian hacks on hospitals and water systems

Portugal: Over 60 arrested in €14 million phishing and money laundering scheme

PS&KP Motor Allegedly Breached, Sensitive Customer Data Leaked Online

Ransomware attackers used incorrectly stored recovery codes to disable EDR agents

Ransomware Group Behind Orleans Sheriff’s Attack Emerges

Researchers used AI to design the perfect phishing plot, what happened next shocked everyone

Russian gang claims breach of US broadcaster, executive exposed

Scattered Lapsus claims SK Telecom data breach; company denies

Schools are getting better at navigating ransomware attacks, Sophos finds

Security Leaders Discuss Restaurant Brands International’s Vulnerabilities

Self-propagating supply chain attack hits 187 npm packages

Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attack

SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids

South Korea: Leading telecoms struggle with aftermath of data breach

South Lyon, Michigan, Schools Targeted by Cyber Attack

Study Reveals Chatbots Can Easily Generate Convincing Phishing Emails Targeting Seniors

Survey Surfaces Rising Number of AI Security Incidents

Survival Flight Data Breach Exposes Patient Info

Swedish data breach exposes 1.5 million people’s personal information

Taiwan phishing crimes spread to South Korea, mirroring KT Corporation case

The Moinian Group Data Breach: 4.7TB Stolen

Top Ministry of Defence (MoD) official ‘deeply uncomfortable’ with secrecy over Afghan data breach

Trusteed Plans Service Corporation (TPSC) Data Breach Affects PII & PHI

U.S. Senator Calls for Investigation of Microsoft

UK: Tax Refund-Themed Phishing Slows in 2025

Ukrainian Fugitive Added to EU Most Wanted List for LockerGoga Ransomware

Ukrainian military intelligence claims cyber attack on Russian election systems

Uvalde Consolidated Independent School District (CISD) faces scrutiny over ransomware attack and transparency issues

Vantage Finance Breach Exposes Applicant PII

Vibe coders lose crypto after installing extensions on popular marketplaces

Vietnam: Public Security Ministry debunks National Credit Information Center (CIC) data breach rumors

Vietnam investigates cyberattack on creditors data

VoidProxy Phishing Service Targets Microsoft, Google Accounts

Yellowknife’s IT team says early detection helped avoid a potentially devasting ransomware attack

Yurei ransomware exploits open-source tools, raising double-extortion risks

15th September

6 Browser-Based Attacks Security Teams Need to Prepare For Right Now

2025 Cybersecurity Challenges: AI Threats, Ransomware, and Strategies

689,000 Affected by Insider Breach at FinWise Bank

AI Chatbots Were Happy to Help Craft a Phishing Scam

AI forgeries create military IDs, fake receipts

AI-Forged Military IDs Used in North Korean Phishing Attack

AI-Powered Villager Pen Testing Tool Hits 11,000 PyPI Downloads Amid Abuse Concerns

Australia: New South Wales (NSW) man charged over mobile phishing scheme

Australia: Tomakin man charged over mobile phishing scam

BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies

BlackNevas Ransomware Encrypts Files, Exfiltrates Corporate Data

Bragg confirms cyber attack resolved as new credit facility secured

Careless engineer stored recovery codes in plaintext, got whole organization pwned

Cayetano Heredia National Hospital of Peru Allegedly Breached, 2 Million Records Leaked

China: New Stricter and 4-hour Data Breach Reporting Requirements for Certain Incidents

China Imposes One-Hour Reporting Rule for Major Cybersecurity Incidents

China-Linked AI Pentest Tool ‘Villager’ Raises Concern After 10K Downloads

CISA at Risk After Office of Inspector General (OIG) Accuses it of Wasting Federal Funds

Coinbase Hacker Panic Sells ETH Bought 2 Days Ago, “Loses” Nearly $1M

Coinbase hacker panics, loses $1 million in 2 days

Company that owns Gucci, Balenciaga, other brands confirms hack

Crypto hacker behind $35M theft pulls off another heist on bail

CVE-2025-58434: Critical FlowiseAI Flaw Enables Full Account Takeover

Cybercriminals steal 160 million records from Vietnamese financial system, exposing entire population

DarkCloud Stealer Leveraging Malicious RAR Archives to Attack Financial Sector

Data breach exposes 600K luxury skincare firm users, hackers claim

Double check your Microsoft 365 and Google accounts - this VoidProxy phishing service is hitting them hard

ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass

Europol adds Spanish academic suspected of aiding pro-Russian hackers to most wanted list

Everest Ransomware Claims Attacks on Professional Trust Company, Studio Legale Tisot Iuris, Key 4 Energy, and MFO ITALIA

Ex-WhatsApp Security Chief Sues Meta Over Data Breach Risks

Fairmont Federal Credit Union 2023 data breach impacted 187K people

Fairmont Federal Credit Union Data Breach Hits 187,000 in West Virginia

Fake military IDs, bogus résumés: How North Korean and Chinese hackers use AI tools to infiltrate companies and other targets

FBI warns of Scattered Spider and ShinyHunters attacks on Salesforce platforms

Fifteen Ransomware Groups Announce Sudden Retirement

FinWise insider breach impacts 689K American First Finance customers

Flaw at major enterprise chatbot maker leads to cookie theft

Former FinWise employee may have accessed nearly 700K customer records

Google confirms fraudulent account created in law enforcement portal

Gucci, Balenciaga and Alexander McQueen private data ransomed by hackers

Hacker Deceives 18,000 Script Kiddies with Fake Malware Builder

Hacker ransomware groups announce retirement to enjoy their "golden parachutes" - no further attacks planned, future attributed activities will relate to undisclosed past breaches

Hackers Hide RMM Installs as Fake Chrome Updates and Teams Invites

Hackers start leaking New Orleans sheriff ransomware data

Hackers Steal Confidential Data in Jaguar Land Rover Cybersecurity Breach

Hackers stuffed malware into fake Signal, WhatsApp, and Chrome apps

Hackers using generative AI “ChatGPT” to evade anti-virus defenses

HeyFood Africa Data Breach Allegedly Exposes 139,000 User Records

HiddenGh0st, Winos and kkRAT Exploit SEO, GitHub Pages in Chinese Malware Attacks

Hong Kong Telecom Provider Allegedly Breached; Root Access Sold on Dark Web

How Cyber Threats Are Evolving - And What Businesses Can Do

How to spot phishing scams

HybridPetya Mimics NotPetya, Adds UEFI Compromise

HybridPetya Ransomware Alarmingly Sneaks Past BIOS Secure Boot To Install Malware

INC ransom group claimed the breach of Panama’s Ministry of Economy and Finance

INC Ransomware Allegedly Breaches US Firms Heritage Growth Partners, H.I.E.C., and Rosco Vision Systems

Indian Web Host Ready2Host Suffers Data Breach, 23.4k Customer Records Allegedly Leaked

Integrity Testing & Safety Administrators (ITSA) Data Breach Affects Frontier Airlines Applicants and Employees

Israel announces seizure of $1.5 Million from crypto wallets tied to Iran

It doesn't take a genius to be a cybercriminal - and open source ransomware is making it easier than ever

Jaguar Land Rover (JLR): How Can Companies Avoid a Major Cyber Attack?

Jaguar Land Rover cyber attack more disruptive and complex than M&S hack, bosses tell government

Jaguar Land Rover cyber attack more disruptive than M&S hack, say bosses

Jaguar Land Rover (JLR) still unable to restart production as MPs call for government help

KillSec Ransomware Hits Brazilian Healthcare Software Provider

LIC India, Bouygues, IMSS Data for Sale; Paris Phishing Toolkit Unveiled

Lovesac Admits Data Breach Compromising Sensitive Personal Data

Massive “Great Firewall of China” data leak reveals surveillance tech Silk Road

Medicare Compare USA Data Breach Affects Personal, Financial and Health Info

Meet the Hacker Who Helped Score a $243 Million Verdict Against Tesla

Millions potentially affected after Gucci, Balenciaga and Alexander McQueen hacked in cyber attack

More than 187,000 affected by data breach with Fairmont Federal Credit Union

Most enterprise AI use is invisible to security teams

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs

Mustang Panda, New SnakeDisk Cyber Attack Targeting Thailand

Nevada: State restores firearms background check system following cyber attack

New Evite phishing scam uses emotional event invitations to target victims

New Infostealer Campaign Targets Popular Games, Pirated Software

New Phoenix attack bypasses Rowhammer defenses in DDR5 memory

New Ransomware HybridPetya Can Bypass UEFI Secure Boot and Encrypt EFI Boot Partition

New ransomware Yurei adopts open-source tools for double-extortion campaigns

New Research Reveals One-Third of Cloud Assets Harbor Easily Exploitable Vulnerabilities

New VoidProxy PhaaS Service Attacking Microsoft 365 and Google Accounts

New Yurei Ransomware Group Emerges with Double-Extortion Tactics in Asia, Africa

New Yurei Ransomware Variant Discovered Utilizing PowerShell Automation and ChaCha20 Cipher

New Yurei Ransomware With PowerShell Commands Encrypts Files With ChaCha20 Algorithm

New Zealand sanctions Russian military hackers over cyberattacks on Ukraine

North Korea uses AI deepfakes to forge South Korean military IDs and get hired for malware campaigns

North Korea-linked hackers use AI to forge South Korean military ID in phishing attack

North Korea’s Kimsuky Group Uses AI-Generated Military IDs in New Attack

North Korean hacker group Kimsuky caught using AI to forge military ID cards

North Korean Hackers Deploy Deepfake Military IDs in Spear-Phishing Campaign

North Korean Hackers Exploit ChatGPT to Boost Phishing Attacks

North Korean hackers use AI deepfakes in spear-phishing attack on South Korea

North Korean Hackers Use AI to Forge Deepfake Military IDs in Spear-Phishing Attack

North Korean hackers Use ChatGPT to Launch Deepfake ID Phishing Attack

North Korean hackers used ChatGPT for phishing attack

Philippine Department of Education Division for Masbate Allegedly Breached - Data of Over 115,000 Students and Faculty for Sale

Phishing campaign targets Rust developers

Phishing Campaigns Drop RMM Tools for Remote Access

Ransomware operations ceased by Scattered Spider, others

RatOn Android Malware Automatically Steals Money and Uses Ransomware - How to Protect Yourself

RFK Racing Data Breach Affects Several Thousand

Russian Chemical Exporter Promchimexport Allegedly Breached, Database Leaked

Russian-American News Outlet Kstati.net Allegedly Breached, User Data Leaked

Scams: crucial phishing email and text warnings for UK students heading to university - what to look out for

Scary results as study shows AI chatbots excel at phishing tactics

Scattered Spider Hacker Group Announces Retirement Amid Doubts and Arrests

Security researchers warn VoidProxy phishing platform can bypass MFA

SEO Poisoning Targets Chinese Users with Fake Software Sites

Shibarium and Monero attacked, highlighting network vulnerabilities

Shibarium Team Offers Bounty to Hacker for the Return of Stolen Assets

Skincare giant Clarins allegedly hit in data breach with 600,000 customers exposed - what you need to know

Source Code of American Telecom Firm Airspan Networks Allegedly Leaked Online

Sri Lanka’s Ministry of Finance Allegedly Breached; Full Database and Server Access for Sale

Static feeds leave intelligence teams reacting to irrelevant or late data

Suffolk-based Orwell Housing Association in data breach

Taming AI's Threat Vectors: Why CISOs Must Adopt a Secure Enterprise Browser (SEB)

Teenager Arrested for Spanish Socialist Workers’ Party Hack Advertising 10GB of Data on the Dark Web

Texas agency reports data breach impacting nearly 45,000 victims of natural disasters

The Science Fiction Forum Suffers Alleged Data Breach, 16.2K Users Exposed

This North Korean Phishing Attack Used ChatGPT's Image Generation

Threat Actors Leverage Several RMM Tools in Phishing Attack to Maintain Remote Access

Threat Group Scattered Lapsus$ Hunters Says It’s Shutting Down

Threat notification campaign by Apple should be taken seriously

UEFI Secure Boot circumvented by novel HybridPetya ransomware

Ukraine claims cyber attack on Russian election systems

Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions

Union County town government hacked in recent cyber attack

US national charged in Finnish psychotherapy center extortion

US Offers $11 Million Bounty for Major Ukranian Hacker

Uvalde school district says ransomware attack forcing closure until Thursday

Uvalde Schools Close to Recover From Ransomware Attack

VoidProxy PhaaS Emerges as Major Threat to Microsoft 365 and Google Accounts

VoidProxy PhaaS Targets Microsoft 365 and Google Accounts in New Campaign

VoidProxy phishing operation targets Microsoft 365, Google accounts

What you need to know about high-end fashion cyber attack

Why Banning Ransom Payments Might Not Be A Silver Bullet Solution

Why hackers are targeting the world's shipping

Your IT Helpdesk Tools Could Be a Hacker’s Key

Yurei Ransomware Uses PowerShell to Deploy ChaCha20 File Encryption

Thursday, 11 September 2025

Ransomware Operator Claims - Week 36 2025

Welcome to last week's ROC Report, an exclusive summary of Ransomware Operator's global victims that were claimed during the period between 1st September and 7th September 2025, kindly assisted by our partners.

For further analysis on these (and any historic) Ransomware Operator Claims, including the Victim Names and Industry Sectors attacked, please use our PRiSM application.

Download PDF



Data Source: Data Breaches Digest. Flag Icons created by Freepik and provided by Flaticon.


Monday, 8 September 2025

Data Breaches Digest - Week 37 2025

Welcome to this week's Data Breaches Digest, a catalogue of links concerning Data Breaches and Cyber Security that were published on the Internet during the period between 8th September and 14th September 2025.


14th September

FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data

Hacker breaks into on-campus smart washing machines - management eventually disables devices, leaving thousands of students with no reliable laundry service

Hacker Exploits $YU Token on Polygon, Moves Millions Across Chains

Hacker Exploits $YU Token, Nets a Massive $7.7 Million Across Multiple Chains

New ‘HybridPetya’ Ransomware Can Bypass UEFI Secure Boot

New scam tactics emerge after National Credit Information Center (CIC) data breach in Vietnam

New VoidProxy phishing service targets Microsoft 365, Google accounts

North Korea-linked hackers used ChatGPT to create fake military IDs

North Korean Hackers Use ChatGPT for Deepfake Military ID Phishing

Ohio: Last of 8 defendants sentenced in money laundering “phantom hacker” conspiracy

Ransomware attack cancels school for several days at Texas district

Samsung Fixes Image Parsing Vulnerability Exploited in Android Attacks

Shibarium Bridge Hacked for Approximately $2.3 Million

State Department Offers $11 Million for Information on Alleged Hacker

Teen Hacker’s Digital Crime Spree Unravels, Ends in U.S. Prison Sentence

Vietnam central bank on credit data breach: National Credit Information Center of Vietnam (CIC) does not collect deposit or payment account data

West Midlands Mayor to keep pressing for 'every possible support' to protect Jaguar Land Rover (JLR) jobs after cyber attack

13th September

600 GB of Alleged Great Firewall of China Data Published in Largest Leak Yet

187,038 People Impacted As Hackers Target West Virginia Financial Firm, Names and Other Personal Information Potentially Exposed in the Data Breach

AI Chatbots Like ChatGPT Detect Sophisticated Phishing Scams

Blockstream Alerts Users of Fake Email Phishing Campaign Targeting Wallets

Blockstream Issues Alert Over Fake Email Phishing Campaign Targeting Hardware Wallet Users

Blockstream warns Jade wallet users of new phishing scam

Coinbase $300 million hacker just splashed $19 million on this crypto

Cork Credit Union warns members their data may reach 'dark web' after cyber attack

Cyber Attack Alert: Ignoring Invisible Threats Invites Disaster

Don't fall victim to the new ‘billion dollar’ hack, federal agents warn

FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks

Hacker Attack on Shiba Inu (SHIB) Network: Developers Issue Statement

Hacker exploits AI chatbot in cybercrime spree

Hacker Exploits Claude AI to Automate Cyberattacks on 17 Companies

Hacker Returns 185 ETH to Kame Aggregator After Sei Exploit

HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya

Jaguar Land Rover suppliers face bankruptcy due to cyber attack

Kame Aggregator on Sei Hit by $1M Exploit, Hacker Returns 185 ETH

KillSec Ransomware attacks MedicSolution in Brazil

Kosovo Hacker Admits Guilt in Operating BlackDB Cybercrime Marketplace

New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts

Qrator Labs Mitigated Record L7 DDoS Attack from 5.76 Million-Device Botnet

Spain Arrests 11 Over Sophisticated Phishing Scam

This 'critical' Cursor security flaw could expose your code to malware - how to fix it

UK students hacking their own schools for dares

Uvalde CISD closes schools after ransomware attack on district systems

Uvalde Consolidated Independent School District to close most of next week due to ransomware issue

“Vibe Hacking”: Hacker Turns AI Chatbot Into Cybercrime Mastermind

Vietnam Credit Center Data Breach Exposes Citizen Data

West Midlands Mayor issues Jaguar Land Rover update after 'concerning' cyber attack

'WhiteCobra' floods VSCode market with crypto-stealing extensions

Who is Volodymyr Tymoshchuk and What Are His Crimes?

12th September

85% of UK businesses experienced a phishing attack

17,000 Rhode Island Social Security numbers exposed in TransUnion breach

AI-Powered Phishing Fuels Ransomware Losses

Akira ransomware gang targets SonicWall flaw in Australia and New Zealand

Alleged Iran-Linked Phishing Targets Israeli Actors

Antivirus-proof crypto stealer targets Mac, Windows, and Linux users

Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms

Aspire Rural Health reports data breach impacting nearly 140,000 patients

Association of Southeast Asian Nations (ASEAN) Adopts 10-Year Action Plan to Combat Rising Cybercrime Threat

Attackers Adopting Novel Living-Off-The-Land (LOTL) Techniques to Evade Detection

Attackers are coming for drug formulas and patient data

Axios-driven phishing soars 241% as attackers bypass defences

Blockstream sounds the alarm on new email phishing campaign

Calls for government support over JLR cyber attack shutdown

Cancer Care Center of North Florida reports two cyber incidents linked to ION breach

CISA looks to partners to shore up the future of the Common Vulnerabilities and Exposures (CVE) Program

CISA warns of actively exploited Dassault RCE vulnerability

CISA Warns of Attacks on DELMIA Manufacturing Software Vulnerability

CISOs brace for a new kind of AI chaos

Cook County Administrator addresses Public Health and Human Services (PHHS) data breach

Cook County Public Health and Human Services experience data breach

Cook County Public Health experiences data breach

Cornwell Quality Tools breach toll surpasses 100K

Cornwell Quality Tools Data Breach Exposes 100,000 User Records

Cornwell Quality Tools Suffers Data Breach, 100,000 User Records Exposed

Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning

Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories

Cyber-insurance: managing risk in the supply chain

Cyberattack attempts on Nevada state websites increased 300% after August ransomware attack

Dark Web Profile: BQTLock Ransomware

Dozens of Israeli actors fall victim to Iranian phishing attack

Dozens of Israeli actors reportedly fall for suspected Iranian phishing attack

Education sector improves against ransomware but IT staff suffer

Education sector improving on ransomware, but IT teams are stressed, report shows

EU and US intensify global manhunt for fugitive hacker behind LockerGoga Ransomware strikes

Fake Firmware Emails Target Blockstream Jade Hardware Wallet Owners

Finnish Vastaamo Hacker Freed While Appealing Conviction

France Warns Apple Users of New Spyware Campaign

Google AppSheet abuse fuels new phishing campaign

Gym bros exposed by Hello Gym phone service: 1.6 million audio recordings leaked

Hacker convicted of extorting 20,000 psychotherapy victims walks free during appeal

Hacker-hit Jaguar Land Rover (JLR) production lines to remain shut down well into next week

Hampton Regional Medical Center Data Breach Exposes SSNs

How the Akira ransomware gang is exploiting SonicWall devices

HybridPetya: More proof that Secure Boot bypasses are not just an urban legend

HybridPetya: (Proof-of-concept?) ransomware can bypass UEFI Secure Boot

HybridPetya Exploits UEFI Vulnerability to Bypass Secure Boot on Legacy Systems

Information Commissioner’s Office (ICO) Warns of Student-Led Data Breaches in UK Schools

Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass

Israeli movie actors targeted in alleged Iranian phishing campaign

Israel says suspected Iranian hackers targeted actors in phishing attack

Jaguar Land Rover (JLR) Cyber Attack: Manufacturing Pause to Continue

Jaguar Land Rover (JLR) cyber attack halts production, company confirms data impact

Jaguar Land Rover factories shut by cyber attack, employees sent home

Jaguar Land Rover shutdown extended after cyber attack

Jaguar Land Rover (JLR) suppliers 'face bankruptcy' due to hack crisis

Jaguar Land Rover (JLR) supply chain staff impacted by cyber attack should receive Government support, says Unite

Jaguar Land Rover’s production halt extends to next week after cyber attack

Jaguar Land Rover’s production pause continues

Labour’s mayor candidate for Croydon forced to apologise over data breach

LNER Cyber Attack Exposes Growing Third-Party Risks

LNER Joins Cohort of Major Brands Attacked by Cybercriminals

Looking for Volodymyr Tymoshchuk! 11 million dollars for the Nefilim hacker

Media streaming platform Plex suffers a data breach

Microsoft, Google accounts targeted with novel VoidProxy phishing service

Moncler Korea fined over customer data breach

MoneyBlock Data Breach Exposes Client PII

Most St. Paul services restored following ransomware attack

Muck Stealer Malware Used Alongside Phishing in New Attack Waves

Nevada: ‘Breadth’ of cyber attack identified, 90% of public-facing websites restored

New HybridPetya Ransomware Bypasses UEFI Secure Boot With CVE-2024-7344 Exploit

New HybridPetya ransomware can bypass UEFI Secure Boot

New ‘HybridPetya’ Ransomware Features UEFI Secure Boot Bypass

New ‘sophisticated’ phishing exploit drains $3 Million in USDC from multi-sig wallet

Ohio: 8 people sent to federal prison for ‘phantom hacker’ scam

Philippine military company spied upon with new China-linked malware

Plex GmbH Data Breach Affects User Accounts

Print Media Association Data Breach May Expose Social Security, ID, Financial Records

R1 RCM & Dignity Health to Pay $675,000 to Settle Data Breach Lawsuit

Radiant Hacker Moves $26.7 Million in Stolen Funds to Ethereum

Ransomware, vendor outages, and AI attacks are hitting harder in 2025

Researchers warn VoidProxy phishing platform can bypass MFA

Russian Offensive Cyber Operations: Analyzing Putin’s Foreign Policy Actions

Rust Developers Targeted in Phishing Scam on Crates.io for GitHub Credentials

Salesforce data breach linked to Tenable via Salesloft Drift

Samsung Fixes Critical Zero-Day CVE-2025-21043 Exploited in Android Attacks

Samsung patches actively exploited zero-day reported by WhatsApp

Scattered Lapsus$ Hunters Hacker Group Announces Shutdown

Scattered Spider ransomware group abruptly decides its time to end operations - for now, at least

SEO Poisoning Attack Hits Windows Users With Hiddengh0st and Winos Malware

Sidewinder Hacker Group Exploits LNK Files to Deploy Malicious Scripts

Sidewinder Hacker Group Weaponizing LNK File to Execute Malicious Scripts

SonicWall firewalls targeted by fresh Akira ransomware surge

South Korea: Police arrest 42 in phishing scam using fake teen accounts

SpamGPT cybercrime toolkit enables large-scale automated phishing campaigns in 2025

Student Insider Threats Driving Surge in UK School Data Breaches, Information Commissioner’s Office (ICO) Warns

Thailand targeted by phishing and DDoS

The Evolving Role of the CISO: From Security Experts to Strategic Communicators

Thorne Research Cyber Attack Exposes Consumer PII

Turkish Hacker Contacts Israeli Defense Minister and Publishes Call Recording

U.S. Offers $11 Million Reward for Ukrainian Ransomware Suspect Volodymyr Tymoshchuk

UK students treat hacking school systems as a game, warns Information Commissioner’s Office (ICO)

UK train operator LNER (London North Eastern Railway) discloses a data breach

Ukrainian ransomware administrator Volodymyr Tymoshchuk indicted for global cyberattacks

Union urges government intervention with 100,000 jobs at risk after Jaguar Land Rover (JLR) cyber attack

US Charges Ransomware Criminal Who Targeted Hundreds of Firms Across the World As State Department Offers $11,000,000 Reward

US places $11 million bounty on mastermind Ukrainian hacker

US Senator says Microsoft should be probed for 'gross cybersecurity negligence' after hospital ransomware attacks

Vietnam creditors hit by cyberattack - sensitive data at risk

Vietnam issues warning after data breach at national credit center

Vietnam Probes Breach at National Credit Information Center, ShinyHunters Suspected

Vietnam, Panama governments suffer incidents leaking citizen data

VoidProxy Phishing-as-a-Service Operation Enables AiTM Attacks Targeting Google, Microsoft Accounts

VoidProxy phishing-as-a-service operation steals Microsoft, Google login credentials

"VoidProxy" PhishKit targets Google and Microsoft users

Your heartbeat could reveal your identity, even in anonymized datasets

Yurei & The Ghost of Open Source Ransomware

11th September

1.6 Million Calls and Voicemails Exposed Online

3 Major K-12 Cyber Risks and How to Mitigate Them

80% of ransomware attacks use AI

100,000 Impacted by Cornwell Quality Tools Data Breach

A newly emerged ransomware group - THE GENTLEMEN RANSOMWARE

AI-Driven Ransomware Surges as Malware, Phishing, and Deepfakes Outpace Security Responses

Akira ransomware affiliates continue breaching organizations via SonicWall firewalls

Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw

Akira ransomware exploiting critical SonicWall SSLVPN bug again

Akira Ransomware Exploits SonicWall CVE-2024-40766 in 2025 Attack Surge

Akira Ransomware exploits year-old SonicWall flaw with multiple vectors

Akira ransomware sets sights on vulnerable SonicWall devices

Angolan Government Employee Database Allegedly Leaked Online

Apple warns customers targeted in recent spyware attacks

Apple’s latest iPhone security feature just made life more difficult for spyware makers

Assisted Living Pharmacy Service Data Breach Impacts Thousands

AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto

Australia Warns of Ransomware Attacks Exploiting SonicWall VPN Flaw CVE-2024-40766

Australian Cyber Security Centre (ACSC) warns of Akira ransomware activity targeting Australian organisations

Australian Cyber Security Centre (ACSC) Warns Of Sonicwall Access Control Vulnerability Actively Exploited In Attacks

Authorities Arrested Admins Of “LockerGoga,” “MegaCortex,” And “Nefilim” Ransomware Gangs

Autistic teen who hacked Grand Theft Auto, Uber and EE to demand millions loses appeal against sentence

California legislature passes bill forcing web browsers to let consumers automatically opt out of data sharing

CCI Financial Inc. Data Breach Exposes Customer PII

ChillyHell macOS Malware Resurfaces, Using Google.com as a Decoy

Chinese APT Actor Compromises Military Firm with Novel Fileless Malware Toolset

CISA Launches Roadmap for the Common Vulnerabilities and Exposures (CVE) Program

Cliff Viessman, Inc. Data Breach Affects Thousands

Cornwell Quality Tools Data Breach - 100,000 Users Data Was Compromised

Cyberattacks against schools driven by a rise in student hackers, Information Commissioner's Office (ICO) warns

Cybercrime Tool SpamGPT Used for Massive Phishing Attacks

Da Nang University of Architecture Data Allegedly Breached, Over 20,000 Records Leaked

Daixin Ransomware Group Allegedly Breaches Global Art Gallery Gagosian

Data breach confirmed by Jaguar Land Rover

Data Breach Hit Texas General Land Office Online System

Data Storage and Protection Firm Spectra Logic Allegedly Breached by Qilin Ransomware

Default Cursor setting can be exploited to run malicious code on developers’ machines

‘Dismay and anger’ over Police Service of Northern Ireland (PSNI) data breach compensation ‘mess’

Dubai’s Ports Customs and Free Zone Corporation Allegedly Hit by Massive 1.9 TB Data Breach

E-commerce Platform Shopline Allegedly Breached, Nearly 31,000 Customer Records Leaked Online

Everest ransomware purportedly breaches Allegis Group

Fake Madgicx Plus and SocialMetrics Extensions Are Hijacking Meta Business Accounts

FBI Promised $10 Million for Ukrainian Hacker Involved in Attacks on Global Companies

Federal Trade Commission (FTC) should investigate Microsoft after Ascension ransomware attack, senator says

Federal Trade Commission (FTC) Urged to Investigate Microsoft on Outdated RC4 Encryption and Kerberoasting Flaws

Fileless Malware Deploys Advanced RAT via Legitimate Tools

Finland: Appeal court orders release of convicted psychotherapy centre database hacker

Finland: Kivimäki walks free during appeal over Vastaamo data breach

France: Three Regional Healthcare Agencies Targeted by Cyber-Attacks

France says Apple notified victims of new spyware attacks

Georgia’s Wayne Memorial Hospital Reports Data Breach Affecting Over 160,000 People

'Gentlemen' Ransomware Abuses Vulnerable Driver to Kill Security Gear

Hackers use Apple Calendar invitations to deliver phishing scams through notes field

Healthcare Services Group reports data breach affecting more than 624,000 individuals

Hello Gym Data Breach Exposes 1.6 Million Calls and Voicemails Online

Hijacker helper VoidProxy boosts Google, Microsoft accounts on demand

How attackers weaponize communications networks

iCloud Calendar Phishing Scam: How It Works and How to Protect Yourself

INC Ransomware Claims Massive Data Breach on Healthcare Investor Deerfield and Singular Genomics

Insider threats haunt schools: most cyberattacks are carried out from within

Israeli defense minister falls victim to Turkish hacker group's video call attack

IT Burnout Emerges as Education Sector Battles Ransomware

Jaguar confirms data stolen in breach, staff told to stay home for another week

Jaguar Land Rover Admits Data Was Affected in Cyber-attack

Jaguar Land Rover (JLR) admits that data has been accessed by hackers as firm continues to battle cyber attack

Jaguar Land Rover (JLR) confirms data breach following cyber attack

Jaguar Land Rover Confirms Data Theft in Cyber Attack

Jaguar Land Rover Confirms Data Theft in Major Cyber Attack

Jaguar Land Rover factories to remain shut until next week after cyber attack

Jaguar Land Rover says hackers may have taken data in cyber attack

Jaguar Land Rover shutdown extended to next week

Jaguar Land Rover u-turns on cyber attack containment claims, admits ‘some data has been affected’

Jaguar Land Rover’s production halt extends to next week after cyber attack

Key Operators of LockerGoga, MegaCortex, and Nefilim Ransomware Gangs Arrested

Kids in the UK are hacking their own schools for dares and notoriety

KillSec ransomware targets healthcare industry in Brazil

Korea Telecom (KT) data breach raises three unresolved questions

Korea's major banks see surge in account suspensions related to phishing incidents

LNER Confirms Passenger Data Breach Following Cyber Attack

LNER Reveals Supply Chain Attack Compromised Customer Information

LNER Suffers Major Data Breach After Third-Party Network Hack

LNER warns customers after passenger details exposed in cyber-attack

LNER warns customers to remain vigilant after personal data exposed in cyber attack

LNER warns customers to be “cautious” after cyber-attack exposes passenger details

Major NPM attack steals only $1K as “blueprint for future Web3 fraud” evolves

Massive NPM Supply Chain Attack Earned Only $600 for Attackers

Microsoft adds malicious link warnings to Teams private chats

National Audit Office ‘kept in dark’ over Ministry of Defence’s £850m Afghan data breach

New Google AppSheet Phishing Scam Delivers Fake Trademark Notices

New Indicators Suggest LockBit 5.0 Ransomware May Be Coming Back

New phishing scam targets Prime Video, other cable streaming users

New VMScape attack breaks guest-host isolation on AMD, Intel CPUs

New York Blood Center Discloses Ransomware Attack Details

New York Seniors Targeted by 'Phantom Hacker' Scam as Attorney General Urges Vigilance After $1 Billion in Losses

Northern Ireland: Ministers lobby Treasury over bill for Police Service of Northern Ireland (PSNI) data breach

Pakistan Data Breach Exposes Risks of Biometric Digital ID Systems

Pakistani ISP Skyfi Network Allegedly Breached - Full System Access Sold Online

Panama Ministry of Economy discloses breach claimed by INC ransomware

Passenger details exposed in LNER third-party data breach

Permiso Uncovers Unicode Technique to Compromise Microsoft Exchange Rules

Phishing Campaign Abuses iCloud Calendar Invites

Phishing Scam Targets Apple Users via iCloud Calendar Invites from Trusted Servers

Police arrest ex-Moldovan official for leaking secrets to Belarus

Print Media Association Data Breach Affects Thousands

Radiology Associates Data Breach Affects 13,158 People

Ransomware Administrator Charged with Cybercrimes for Deploying Ransomware Strains Against Hundreds of Victims

Ransomware attacks targeting Australian organisations more than double year on year

Ransomware gang going after improperly patched SonicWall firewalls

SAP Issues Critical Security Patch for NetWeaver and Other Products, Warns of CVE-2025-42944

Sellmark Corp. Data Breach Affects Personal and Financial Info

Senator Demands Federal Trade Commission (FTC) Investigation Into Shoddy Security at Microsoft

Senator Urges Federal Trade Commission (FTC) Probe Into Microsoft After Ascension Ransomware Attack

Senator Wyden Blasts Microsoft Over Kerberoasting Ransomware Risk

Senator Wyden Calls on Federal Trade Commission (FTC) to Investigate Microsoft for Cybersecurity Lapses Related to Ransomware

Senator Wyden Urges Federal Trade Commission (FTC) to Probe Microsoft for Ransomware-Linked Cybersecurity Negligence

SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware Hackers

SonicWall SSL VPNs still under attack from Akira ransomware group

SonicWall SSLVPN Exploitation ‘Ongoing’ By Ransomware Group

South Korea: Voice phishing-linked frozen bank accounts set to hit record high this year

South Korea’s KT Corp admits data breach

SpamGPT is here! The new phishing kit that combines AI, spam, and diabolical genius

SpamGPT Is the AI Tool Fueling Massive Phishing Scams

Supply Chaos: Can Jaguar Land Rover (JLR) Bounce Back as Data Theft is Verified?

Swiss government looks to undercut privacy tech, stoking fears of mass surveillance

The Cyber Attack That Shut Down A Global Carmaker Overnight

The Top Cyber Attack Threats Facing the UK in 2025

This long-exposed SonicWall flaw is being used to infect organizations with Akira ransomware - so patch now

This widely used Remote Monitoring tool is being used to deploy AsyncRAT to steal passwords

Three-Prong Ghost Hacker Scam Targets Seniors, Others

Turkish hackers hold brief video call with Israel Katz and publish image

Turkish Hackers Publicize Call with Israeli Defense Minister in a Personal Cyber-Attack

U.S. Senator accuses Microsoft of “gross cybersecurity negligence”

UK delays introducing new cybersecurity legislation, again

UK Rail Operator LNER Confirms Cyber Attack Exposing Passenger Data

UK Train Operator Confirms Customer Data Breach via 3rd-Party Supplier

UK Train Operator LNER Passengers Data Accessed In Cyber Attack

UK Train Operator LNER Warns Customers of Data Breach

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

University of Iowa Health Care reports data breach affecting 211,000 individuals

US Department of Justice (DoJ) puts $11 million bounty on ransomware king allegedly responsible for stealing $18 billion

US Senator: Microsoft guilty of negligence in ransomware case

US Senator Ron Wyden Urges Federal Trade Commission (FTC) Investigation Over Ascension Ransomware Hack

US Senator urges probing Microsoft over cybersecurity negligence, ransomware risks

US Senator Wyden pushes Federal Trade Commission (FTC) to investigate Microsoft for 'gross cybersecurity negligence'

Vietnam probes suspected cyberattack on its national credit information database

What is Phishing in Crypto and How to Protect from It

When typing becomes tracking: Study reveals widespread silent keystroke interception

Why organizations need a new approach to risk management

10th September

2 Billion Weekly Downloads at Risk: Supply Chain Attack Targets Popular npm Packages

6 million euros a day! That’s the cost of the cyber attack on Jaguar Land Rover

$10 million bounty issued by US Department of Justice (DOJ) for ransomware kingpin responsible for $18 billion of damage

Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

Adobe Issues Urgent Patch for ‘SessionReaper’ Vulnerability in Commerce and Magento

Adobe Releases Emergency Patch for Critical Flaw in Commerce and Magento

AI agents are here, now comes the hard part for CISOs

AI and the Increasing Phishing Threat

Akira ransomware criminals abusing trifecta of SonicWall security holes for extortion attacks

Akira Ransomware Group Claims Breach on US Food Distributor E&S Food and Canadian Homebuilder Fusion Homes

Apple iCloud Phishing Scam Targets Users via Calendar Invites

Apple Introduces Memory Integrity Enforcement in iPhone 17 to Fight Spyware Exploits

Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety

Apple users beware - hackers crack iCloud Calendar invites to sneak malware onto your system, here's how to stay safe

Apple's iPhone 17 has a big anti-spyware upgrade built in - here's what it can do

Automated network pentesting uncovers what traditional tests missed

Axios-powered phishing attacks surge, with success rates up to 70%

Blackpool Credit Union suffers cyber attack

Can I have a new password, please? The $400 Million question

CHILLYHELL macOS Backdoor and ZynorRAT RAT Threaten macOS, Windows, and Linux Systems

China-Linked APT41 Hackers Target U.S. Trade Officials Amid 2025 Negotiations

Chinese APT Deploys EggStreme Fileless Malware to Breach Philippine Military Systems

Chinese APT Hits Philippine Military Firm with New EggStreme Fileless Malware

Chinese companies and bosses to face major fines over cybersecurity incidents

CISOs, stop chasing vulnerabilities and start managing human risk

Cornwell Quality Tools Confirms Data Breach Affecting Over 100,000 Individuals

Cross-border insurance claims in India data breach disputes

Cursor AI editor lets repos “autorun” malicious code on devices

Cursor Autorun Flaw Lets Repositories Execute Code Without Consent

Cyber Attack Causes Severe Operational Disruptions on Jaguar Land Rover’s Production

Cyber attack costing Jaguar Land Rover (JLR) £5 million a day

Cyberstorage: Italian IT Managers’ Response to Ransomware

CyberVolk Ransomware Attacking Windows System in Critical Infrastructure and Scientific Institutions

CyberVolk Ransomware Targets Windows Systems in Critical Infrastructure and Research Institutions

Data Breach: KT, LG Uplus Under Investigation by KT Corp After Possible Leaks of Customer Data After Series of Unauthorised Mobile Payments

Data Breach Claims UK highlights police cyber threats

Data compromised in Jaguar Land Rover cyber attack

DDoS defender targeted in 1.5 Bpps denial-of-service attack

Deepfakes are rewriting the rules of geopolitics

European crypto platform SwissBorg to reimburse users after $41 million theft

Everything we know about the Plex data breach so far

'Extreme disappointment' as Police Service of Northern Ireland (PSNI) rule out compensation for officers impacted by data breach

Farmer Bros. reveals data breach victim count

Farmer Brothers Data Breach Affects 14k People: SSNs Exposed

Fixing silent failures in security controls with adversarial exposure validation

Former WhatsApp Security Chief Sues Meta, Citing Major Privacy Risks

Gentlemen Ransomware Exploits Drivers and Group Policies to Breach Organizations

Gentlemen Ransomware Exploits Legitimate Drivers and Group Policies to Breach Organizations

Georgia Hospital Notifies 160K Individuals of Breach 1 Year After Incident

Global talent management behemoth Allegis Group claimed by hacker gang

Guilt admitted by Kosovo hacker over BlackDB cyber market operations

Hacker exposes own tactics through Huntress trial

HackerOne Confirms Data Breach - Hackers Gained Unauthorized Access To Salesforce Instance

HackerOne Data Breach, Hackers Illegally Access Salesforce Environment

Hackers Impersonate Google AppSheet in Latest Phishing Campaign

Hackers left empty-handed after massive NPM supply-chain attack

Hello Gym Data Leak Exposes 1.6 Million Audio Files of Gym Members

Here's What Blocks In-Progress Ransomware Attacks the Best

Highland rail passengers’ personal details may have been accessed in LNER data breach; train operator runs Inverness to London services

How npm Security Collapsed Thanks To a 2FA Exploit

Iconic British car brand reveals data STOLEN in major cyber attack ‘linked to Marks & Spencer hack’

Identity Risk Management: Locking Down Ephemeral Accounts

INC Ransom Claims Panama’s Finance Ministry Data Breach, Leaks Sample

International search widens for ransomware fugitive on EU Most Wanted

Iranian Hackers Exploit Omani Mailbox in Global Spear-Phishing Campaign

Italian Municipality of Canegrate Targeted in Data Breach - Database Access for Sale

Jaguar Land Rover admits data breach after cyberattack: What Tata Group-owned carmaker is doing to check impact

Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack

Jaguar Land Rover admits data has been compromised in cyber attack

Jaguar Land Rover admits hackers may have taken data

Jaguar Land Rover admits possible data breaches following cyber attack

Jaguar Land Rover (JLR) believes “some data” has been impacted by production-halting cyber attack

Jaguar Land Rover confirms cyber-attack data breach

Jaguar Land Rover (JLR) confirms data affected in cyber attack

Jaguar Land Rover Confirms Data Breach in Last Week’s Cyberattack

Jaguar Land Rover confirms data theft after recent cyberattack

Jaguar Land Rover Confirms Hackers Stole Data in Ongoing Cyberattack

Jaguar Land Rover confirms 'some data has been affected' by recent cyber attack

Jaguar Land Rover cyber attack: 'Some data affected', carmaker reveals

Jaguar Land Rover cyber attack 'linked to Marks and Spencer hack'

Jaguar Land Rover give cyber attack update

Jaguar Land Rover in U-turn as data was accessed in cyber attack

Jaguar Land Rover issue update after company hit by cyber attack

Jaguar Land Rover issues cyber attack update 10 days after staff told to stay at home

Jaguar Land Rover issues cyber attack update amid data breach

Jaguar Land Rover says cyber-attack has affected ‘some data’

Jaguar Land Rover says data accessed in cyber attack

Jaguar Land Rover says data stolen in disruptive cyberattack

Jaguar Land Rover (JLR) says some data has been impacted in a cyber attack

Jaguar Land Rover warns that 'some data has been affected' after devastating cyber attack

Jaguar Land Rover (JLR) workers told to stay at home after cyber attack

KillSec Ransomware Hits Brazilian Healthcare IT Vendor

KillSec Ransomware is Attacking Healthcare Institutions in Brazil

Lazarus Hackers Abuse Git Symlink Vulnerability in Stealthy Phishing Campaign

Lazarus Hackers Exploiting Git Symlink Vulnerability in Sophisticated Phishing Attack

LNER cyber attack: Train passengers’ contact details and journey information accessed in cyber attack

LNER passenger data accessed in cyber attack

LNER reports data breach involving customer details

LNER urges customers to be vigilant after passenger details accessed in cyber-attack

LNER warns customer information accessed in cyber attack

Location Peintures Prestations (LPP), Saelen/Heizomat, and Surtel Technologies Added to The Gentlemen Ransomware’s Victim List

LockerGoga, Nefilim Ransomware Administrator Charged for Targeting 250 Companies Globally

Major Taiwanese Media Group UDN.com Allegedly Breached - Database Access For Sale

Malicious npm Code Reached 10% of Cloud Environments

Malware Injected Into Code Packages That Get 2 Billion+ Downloads Each Week

Massive Data Breach Allegedly Hits Mexico’s Largest Housing Institute Infonavit

Microsoft Fixes 80 Flaws - Including SMB PrivEsc and Azure CVSS 10.0 Bugs

Microsoft, Adobe, SAP deliver critical fixes for September 2025 Patch Tuesday

Microsoft’s Patch Tuesday: About 80 Vulnerabilities Patched

Multi-ransomware gang admin indicted by US

Nevada cyber attack disrupts gun sales amid background check system outage

New Apple A19 chips introduce spyware-defeating memory safety feature

New Buterat Backdoor Malware Found in Enterprise and Government Networks

New Fileless Malware Attack Uses AsyncRAT for Credential Theft

New fugitive uploaded to EU Most Wanted list for major ransomware attacks

New Phishing Attack Mimics Google AppSheet to Steal Login Credentials

New Qantas Policy Ties Amount of Executive Bonuses to Data Breach Failures

Novel The Gentlemen Ransomware Group Targets Critical Industries in Over 15 Countries

Only 20% of ransomware is not powered by AI, but expect that number to drop even further in 2025

Over 10K impacted by New York Blood Center ransomware hack

Pakistan Telecommunication Authority (PTA) denies data breach from telecom sector

Pakistan Telecommunication Authority (PTA) denies subscriber data breach from telecom operators

Pakistan Telecommunication Authority (PTA) rejects allegations of telecom data breach

PayPal and Spotify scam emails are on the rise. Here’s how to stay safe

Pediatric OHNS Associates’ data breach affects 44,000 patients

Peruvian Logistics Firm Urbaner Allegedly Breached, 60,000 User Records Leaked

'Phantom Hacker Scam' money laundering, Brookfield man charged

Pixel 10 fights AI fakes with new Android photo verification tech

Play Ransomware Group Allegedly Hits 13 US-Based Companies in a Widespread Attack

Plex asks users to reset their passwords after data breach

Plex Security Data Breach: Secure Your Plex NAS Now!

Police Service of Northern Ireland (PSNI) 'cannot afford' to pay staff compensation over major data breach

Popular AI chatbots leaking data: millions of users could be affected

Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward

Qilin Ransomware Allegedly Breaches French Wholesaler Wouters France

Ransomware 3.0 raises alarm over AI-generated cyber threats

Ransomware attack at blood center: Organization tells users their data’s been stolen

Ransomware attack hits Highlands Oncology, exposing over 113K patient info

Ransomware Attackers ‘More Systematic,’ Claims Become Costlier

Ransomware attacks fewer but costlier

Ransomware attacks in Australia soar by 110%

Ransomware kits built with AI are behind a 70% surge in attacks

Ransomware Mastermind "deadforz" Faces Charges as Feds Unmask Global Cybercriminal in New York

Ransomware Payments Plummet in Education Amid Enhanced Resiliency

Ransomware upstart ‘The Gentlemen’ raises the stakes for Operational Technology (OT)‑heavy sectors

Ransomware, phishing top threats to businesses in first half

Researchers find spyware on phones belonging to Kenyan filmmakers

Royal Bahamas Police Force (RBPF) warns of rise in phishing scams

Salesloft data breach exposes 700 firms’ details via OAuth attack

SAP Patches Critical NetWeaver (CVSS Up to 10.0) and High-Severity S/4HANA Flaws

Sophos Report Finds Education Sector Strengthening Against Ransomware, but IT Teams Pay Personal Price

South Korea: Prosecution Seeks Heavy Sentences for Cambodia-Based Voice Phishing Ring Members

South Korea: Prosecutors demand 13 years for cambodia voice phishing suspects

South Korean Machinery Giant Hwacheon Allegedly Hit by Gunra Ransomware, 265GB of Financial Data Leaked

Spanish Concert Platform Wegow Allegedly Breached, Data of 45,600 Users Leaked Online

Standards That Keep Smart Cars Safe from Cyber Attack

Streaming giant Plex urges users to reset passwords following a data breach

Streaming service suffers data breach

That new Claude feature 'may put your data at risk,' Anthropic admits

The hunt for “LockerGoga” and “MegaCortex” ransomware admin is on, and $10M is on the line

The rogue hacker states Britain doesn’t want to talk about

The State of Ransomware in Education 2025

Train operator LNER hit by cyberattack

TransUnion Data Breach: Why It’s More Important Than Ever To Freeze Your Credit

Tribe Wants to Protect the Identity of Individuals Affected by a Data Breach

Trigg County Hospital Patients Notified Of Data Breach With Partner Company

Turkey: Police launch raids on illegal betting ring linked to data breach system

Two Zero-Days Among Patch Tuesday CVEs This Month

U.S. places $11 million bounty on Ukrainian ransomware mastermind - Tymoshchuk allegedly stole $18 billion from large companies over 3 years

UK Government not ruling out state involvement in Jaguar Land Rover (JLR) cyber attack as MPs debate major hack

UNC6395 Hackers Accessed Systems via a GitHub Account, Salesloft Says

Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed

US Charges Alleged Ransomware Mastermind as Europe Lists Him on ‘Most Wanted’

US indicts alleged ransomware kingpin tied to $18 Billion in damages

US investors in spyware firms nearly tripled in 2024

US Offers $10 Million Reward for Ukrainian Ransomware Operator

US sanctions billion-dollar cyber scam networks in Myanmar and Cambodia

US Senator pushes Federal Trade Commission (FTC) to investigate Microsoft for "gross cybersecurity negligence"

Watch Out for Salty2FA: New Phishing Kit Targeting US and EU Enterprises

Workday Confirms Data Breach – Hackers Accessed Customers Data and Case Information

Workday Confirms Data Breach Exposing Customer Data and Case Information

Workday Data Breach Exposed Customer Data and Case Details

Wytech Industries Discloses Data Breach Following Ransomware Attack

9th September

2 class action lawsuits filed: Library breach exposes over 335,000 Washington residents’ data

7 steps to stay safe after receiving a data breach notification letter

20 Popular npm Packages With 2 Billion Weekly Downloads Compromised in Supply Chain Attack

45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage

71% of CISOs hit with third-party security incident this year

Adobe patches critical SessionReaper flaw in Magento eCommerce platform

Akira Ransomware Allegedly Breaches RBJ Escrow Software, General Converting, Vardeco, and Keller Laser AG

All Plex users should reset passwords in wake of data breach

Americans scammed out of billions by cybercrime rings in Myanmar and Cambodia

Another Plex data breach sees company urge users to change their password

Anthropic Details AI-Powered Ransomware Program Built By Novices and Sold as a Service

Attackers test the limits of railway cybersecurity

AVA Senior Connect Allegedly Hit by Killsec Ransomware

Average Ransomware Attack Cost Rises by 17%

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

Axios User Agent Helps Automate Phishing on “Unprecedented Scale”

Brazil lesbian dating app shuts down after security flaw exposes sensitive user data

Brookfield man indicted in 'Phantom Hacker Scam' that targeted the elderly

Building cyber-security in the cloud

Bulgarian Investment Firm MK Brokers Allegedly Suffers Major Data Breach

Chinese Cyber Espionage Campaign Impersonates US Congressman

Christian Dior Targeted by Growing Pool of Class Action Lawsuits Over Data Breach

Connected cars are racing ahead, but security is stuck in neutral

Crypto heist nabs $2.4 Million from Nemo Protocol

Cyber Criminals Steal Data from East Valley Institute of Technology

Data Breach at New York Blood Center Exposes Donors’ Sensitive Information

Data breach hits 40,000 Stockholm city employees

Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce

Dynatrace Confirms Data Breach via Salesforce Compromise

Dynatrace Confirms Data Exposure in Salesloft Supply-Chain Attack

Dynatrace Data Breach Exposes Customer Information Stored in Salesforce

Emerging Phishing Threats: MostereRAT, ClickFix, and State-Sponsored Risks

Employees keep feeding AI tools secrets they can’t take back

Ethereum, Solana Wallets Targeted in Massive 'npm' Attack But Just 5 Cents Taken

Fake npm 2FA reset email led to compromise of popular code packages

Feds offer $11M reward for arrest of Ukrainian ransomware hacker

Feds seek to claim $5 million in bitcoin taken in SIM swaps

Florida Pediatric ENT Specialists Confirm Data Breach Affecting 44,000 Individuals

From MostereRAT to ClickFix: New Malware Campaigns Highlight Rising AI and Phishing Risks

Germany’s second-largest bank subsidiary breached, hackers claim

GPUGate Malware Shows Hardware-Specific Evasion Tactics

Hackers are abusing hotel booking notifications to steal credentials in a new phishing campaign

Hackers hide behind Tor in exposed Docker API breaches

How One Phishing Email Compromised 18 npm Packages and Billions of Installs

Intrusion Analysis Reveals Overlap in RansomHub, DragonForce, and Play Ransomware Operations

Is law enforcement powerless against DDoS-for-hire services? Half of all “booters” resurrect within a day

Jaguar Land Rover counts the cost of cyber attack

Jaguar Land Rover (JLR) Cyber Attack: The Global Supply Chain Impact

Jaguar Land Rover cyber attack forces UK's biggest carmaker to shutdown for weeks

Jaguar Land Rover Cyberattack Forces Extended Factory Shutdown and Disrupts Global Operations

Jaguar Land Rover Extends Factory Shutdown Following Cyber Attack

Jaguar Land Rover extends shutdown after cyber attack cripples operations

Jaguar Land Rover Extends UK Plant Shutdowns After Cyber Attack

Jaguar Land Rover getting 'daily' support as workers told to stay at home

JavaScript packages with billions of downloads were injected with malicious code in world's largest supply chain hack, geared to steal crypto - a phishing email is all it took to undermine npm packages

Korea Biomedicine Industry Association Database Allegedly Leaked

Kosovo hacker pleads guilty to running BlackDB cybercrime marketplace

LockBit 5.0 emerges as ransomware group aims for revival

LookCam internet cameras expose your home to strangers, security researcher warns

LunaLock ransomware gang threatens to utilize stolen art for AI training

LunaLock Ransomware threatens victims by feeding stolen data to AI models

Lynx Ransomware Allegedly Breaches US Architecture Firm BGKT Architects

Major blood center says thousands had data leaked in January ransomware attack

Major NPM Supply-Chain Attack Compromises Packages with Over 2 Billion Weekly Downloads

Malaysia: Phishing accounts for over three-quarters of fraud cases in 2024

Massive Number of Internet Exposed Assets Still Lack Web Application Firewall (WAF) Protection

Massive supply chain attack hits NPM as hackers target 18 packages downloaded 2 Billion times weekly

Michigan tribe offers free ID protection to customers affected by data breach

Microsoft forces Azure users to enable MFA starting October 2025

Microsoft Patch Tuesday September 2025 Fixes Risky Kernel Flaws

Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days

Middletown addresses utility bill issues following cyber attack

Minister cannot say if cyber attack on Jaguar Land Rover was state-sponsored

Morris Hospital reaches $1.36 million settlement in data breach class action

New Cyber Attack Weaponizes DeskSoft to Deploy Malware Leveraging RDP Access to Execute Commands

New Docker Malware Strain Spotted Blocking Rivals on Exposed APIs

New Linux Botnet Combines Cryptomining and DDoS Attacks

New Plex Data Breach: It’s Time to Change Your Password

North Oaks Data Breach Affects Several Thousand Patients

Ongoing malvertising campaign targets European IT workers with fake GitHub Desktop installers

Open Source Community Thwarts Massive npm Supply Chain Attack

Phishing attack nets enormous npm supply chain compromise

Phishing Attacks Are Getting Smarter. Here’s How to Stay Ahead

Phishing kit Salty2FA washes away confidence in Multi-Factor Authentication (MFA)

Phishing, Bugs, and Billions at Stake: Lessons From NPM Crypto Exploit Near-Miss

Pierce County library was hit by data breach. What was in the stolen files

PKO Bank Polski Allegedly Breached – Data of 32,000 Employees for Sale

Plex asks users to reset passwords after data breach

Plex Confirms Data Breach, Asks Users to Reset Passwords Immediately

Plex data breach exposes user emails, usernames, and hashed passwords

Plex Data Breach Means It Is Time To Reset Your Password

Plex Issues Urgent Warning To Reset Passwords After Another Data Breach

Plex Says Users Must Reset Passwords after Data Breach, Again

Plex suffers data breach, warns customers to change passwords

Plex suffers major data breach, urges users to reset their passwords

Plex Suffers Second Data Breach in 2025: Reset Passwords Now

Plex tells users to change passwords due to data breach, pushes server owners to upgrade

Plex urges users to change passwords after data breach

Qantas slashes senior management incentives following July cyber incident

Ransomware claims are getting more expensive, new data shows

Ransomware Costs Jump 17% in 2025 Despite Fewer Cyberinsurance Claims

Ransomware costs jump 17 percent though insurance claims fall

Ransomware insurance losses spike despite fewer claims

Ransomware Losses Climb as AI Pushes Phishing to New Heights

RatOn Android Malware Detected With NFC Relay and ATS Banking Fraud Capabilities

Reset your Plex password immediately—your account information was stolen

Russian Engineering Firm Okan Allegedly Hit by WarLock Ransomware

Russian Threat Group Targets Microsoft Outlook With Malware

Salesloft: GitHub Account Breach Was Ground Zero in Drift Campaign

Salesloft Drift Security Breach Expands: Dozens of Companies Confirm Exposure in OAuth-Based Cyberattack

Salty2FA Phishing Kit Unveils New Level of Sophistication

SAP Faces Escalating Cyberattacks on S/4HANA and NetWeaver Flaws

SAP fixes maximum severity NetWeaver command execution flaw

Scammers Are Exploiting Apple Calendar to Send Phishing Emails (Again)

Scot accused of crashing FBI website in cyber attack has case thrown out

Scotland: Case against alleged FBI hacker from Dundee thrown out

SessionReaper Vulnerability Puts Magento & Adobe Commerce Sites in Hacker Crosshairs

South Korea: Phishing Alert - Kimsuky Hackers Masquerade as Tax Authority with ‘September Tax Return Due Date’ Email

South Korean Big Data Platform Textom Allegedly Breached - User Data for Sale Online

SpamGPT: New AI Email Attack Tool Fueling Massive Phishing Operations

SpamGPT - AI-powered Attack Tool Used By Hackers For Massive Phishing Attack

SpamGPT - AI-Powered Tool Fuels Massive Phishing Campaigns

Spanish Socialist Workers’ Party (PSOE) Allegedly Hacked, Sensitive Data Breached

The Gentlemen Ransomware: An Emerging Dark Web Threat Analysis

This 2FA phishing scam pwned a developer - and endangered billions of npm downloads

Threat Actor Accidentally Exposes AI-Powered Operations

Threat Actor Connected to Play, RansomHub and DragonForce Ransomware Operations

TOR-Based Cryptojacking Attack Expands Through Misconfigured Docker APIs

U.S. indicts Ukrainian national for hundreds of ransomware attacks using multiple variants

U.S. sanctions cyber scammers who stole billions from Americans

UK Government 'cannot confirm' state role in Jaguar Land Rover (JLR) hack that leaves workers at home

Ukrainian national charged with helping run LockerGoga, MegaCortex and Nefilim ransomware

University of the People Database Allegedly For Sale on Dark Web - Affecting Over 500,000 Users

Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed

US charges admin of LockerGoga, MegaCortex, Nefilim ransomware

US Feds Indict LockerGoga and MegaCortex Ransomware Hacker

US Non-Profit Melwood Allegedly Hit by Sinobi Ransomware

Virgin Money, BT, TD Bank, Air Canada provider caught in Salesforce breach

Wealthsimple data breach exposes customer information

Why Ransomware Victims Still Pay - and How to Avoid the Ransom Altogether

Why Use a Hardware Wallet Instead of an Exchange for Cryptocurrency Security?

Your Online World, Your Responsibility: From Phishing to Passwords, a Guide to Staying Safe

Zions Bancorporation Data Breach Exposes PII

8th September

80% of ransomware attacks now use artificial intelligence

Account Profile Scam Targets PayPal Users

Amazon Simple Email Service (SES) Turned Rogue: 50K Phishing Emails a Day

AI and Cybersecurity: A Double-Edged Sword in the Digital Age

AI moves fast, but data security must move faster

AI powered autonomous ransomware campaigns are coming, say experts

America’s second largest egg producer breached, claim hackers

Architecture Firm 10DESIGN Allegedly Breached - Database Leaked

Argo CD Security Flaw Rated 9.8 Leaves GitOps Repositories Exposed

Australian Authorities Expose Ransomware Gangs and Their Hidden Careers

Australian Authorities Uncovered Activities and Careers of Ransomware Criminal Groups

Banks strengthen defences against phishing

Canadian Education Platform Step2Education Allegedly Breached - Exposing Healthcare Client Data

Canadian Financial services firm Wealthsimple discloses customer data breach

Canadian investment platform Wealthsimple disclosed a data breach

Cephalus is coming! The ransomware group that attacks via DLL replacement

Chess.com Reports Data Breach via Third-Party File Transfer Tool

Chinese Group Accused of Using Fake U.S. Rep. Email to Spy on Trade Talks

Cloud Storage Full’ Phishing Scam: Tips to Stay Safe

Concerns over impact of Jaguar Land Rover (JLR) cyber attack

Conti and LockBit dominate ransomware landscape with record attacks

Criminal group illegally opens 11,353 prepaid SIM cards for voice phishing

Crippling fallout from Jaguar Land Rover's cyber attack could 'go on for weeks'

Crypto Phishing Losses Surpass $12 Million, Driven by Ethereum-Focused Exploits

Crypto Phishing Scams Surge 72% - How to Keep Your Wallet Safe

Cyber Attack Chaos: Jaguar Land Rover Forced to Shut Down After 'Severe' Hack Rocks Tata's Luxury Brand

Cyber Attack Disrupts Jaguar Land Rover EV Operations

Cyber defense cannot be democratized

Cyberattack on Jaguar Land Rover threatens to hit British economic growth

Cybersecurity for real estate agents: Threats, tips & insurance

Data breach could set back Church of England redress

Data privacy and ransomware shape Australia and New Zealand (ANZ) cyber landscape

Developer snared in crypto phishing net, 18 npm packages compromised

Ethereum phishing scams - $12M lost in August as EIP-7702 exploits surge

Fintech Firm Wealthsimple Says Supply Chain Attack Resulted in Data Breach

FortiGuard Labs Reveals High-Severity Phishing Campaign

Fortune Collective founder loses $1M worth of crypto in video phishing

GhostAction campaign steals 3325 secrets in GitHub supply chain attack

GhostAction Supply Chain Attack Compromises 3000+ Secrets

GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

Global Data Breaches and Cyber Attacks in August 2025: over 17.3 million records exposed

Google Data Breach Achieved with Simple Technique

GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms

Hacker Drains $2.4M From Sui-Based Protocol

Hacker Pwns Programmer, Infects Widely Used Software With Malware

Hackers hijack npm packages with 2 billion weekly downloads in supply chain attack

Hackers steal 3,325 secrets in GhostAction GitHub supply chain attack

How the Salesforce breaches unfolded: root causes identified

Huge Birmingham school data breach after kids personal information leaked

Humanists.org Database Allegedly Breached – Data of 75,000 Members Leaked Online

iCloud Calendar-powered callback phishing scheme discovered

iCloud invitations used for PayPal phishing

Idaho Hacker Appeals 10-Year Sentence after Threatening Victims and Prosecutors

Identity management was hard, AI made it harder

India: Quick Heal Exposes Phishing Sites and Fake Apps in KYC Scams

Indonesian Educational Non-Profit Onno Center Suffers Alleged Data Breach

Insider Threats Surge: What CISOs Must Know to Protect Their Organizations

Jaguar factory workers told to stay at home after cyber attack

Jaguar Land Rover (JLR) calls in security specialists and law enforcement to sort cyber attack

Jaguar Land Rover (JLR) cyber attack: Disruptions to continue into October

Jaguar Land Rover cyber attack could impact operations until October

Jaguar Land Rover extends shutdown after cyber attack

Jaguar Land Rover Factories Remain Shut Following Cyber Attack, Suppliers Also Hit

Jaguar Land Rover halts production after cyber-attack

Jaguar Land Rover in 'truly horrible position' following cyber attack

Jaguar Land Rover shuts production after major cyber attack

Jaguar Land Rover staff home for another day as company reels from cyber attack

Jaguar Land Rover Staff Stay Home After Cyber Attack

Kazakhstan oil giant denies cyberattack, says incident was 'planned' phishing drill

Killsec Ransomware Allegedly Breaches Nathan, Archer Health, GPS Trackit, Suiza Lab, GoTelemedicina, eMedicoERP, and MedicSolution+

Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews

LockBit Attempts Comeback with LockBit 5.0 Ransomware Release

Lovesac confirms data breach after ransomware attack claims

LoveSac Discloses Data Breach After RansomHub Ransomware Attack

LunaLock Ransomware Attacking Artists to Steal and Encrypt Data

Luxembourg National Lottery suffers sports betting data breach

Lynx Ransomware Group Allegedly Targets Major US Egg Producer Rose Acre Farms

Major Data Breach Hits WaterStreet, Impacts 40,000 Velocity Risk Clients

MostereRAT Phishing Campaign Leverages AnyDesk/TightVNC Targeting Windows Systems

MostereRAT Targets Windows Users With Stealth Tactics

MostereRAT Targets Windows, Uses AnyDesk and TightVNC for Full Access

Navigating the Digital Age: Cybersecurity Challenges in Family Law Practice

Nemo Protocol drained of millions in exploit

Nevada’s Division of Insurance (DOI) and Department of Motor Vehicles (DMV) continue to be impacted by a statewide ransomware attack

Northern Ireland: Businesses Warned Over Rise In Phishing Attacks

Novel PromptLock ransomware developed by New York University (NYU) researchers

npm Packages With 2 Billion Weekly Downloads Hacked in Major Attack

NPM Supply Chain Attack: Sophisticated Multi-Chain Cryptocurrency Drainer Infiltrates Popular Packages

Nueces County provides update on cyber attack: Nearly $2M in losses, recovery efforts underway

Over 31K hit by South Carolina school district hack

Pakistan Launches Probe After Massive SIM Data Leak Hits Millions

Philippine Statistics Authority (PSA) warns public against phishing scams targeting National ID holders

Philippines’ Top Science Academy (NAST DOST) Allegedly Breached

Phishing scams surge with record losses in August

Plex tells users to reset passwords after new data breach

Ransomware in Revenue Cycle Management (RCM): Why Your Billing System Is an Overlooked Cybersecurity Risk

Qualys Confirms Data Breach – Hackers Accessed Salesforce Data in Supply Chain Attack

Qualys, Tenable Latest Victims of Salesloft Drift Hack

Qantas Airways Slashes CEO Bonus After Cyberattack Exposes 5.7 Million Customers

Qantas CEO pays the price for cyberattack

Qantas trims executive bonuses over data breach

Remote Access Abuse Biggest Pre-Ransomware Indicator

SafePay ransomware activity gains steam

Salesloft: Hacker broke into systems in March through GitHub account

Salesloft: March GitHub repo breach led to Salesforce data theft attacks

Salesloft Drift data breach: Investigation reveals how attackers got in

Salesloft Drift Incident Expands: Tenable Confirms Customer Data Breach

Salesloft says Drift customer data thefts linked to March GitHub account hack

SAP S/4HANA Users Urged to Patch Critical Exploited Bug

Seasonal phishing campaigns continue to target MSPs

SK Telecom Hit With a Record Data Breach Fine Over Cybersecurity Failures Exposing 23.2 Million People

South Korea: Cops bust crime ring that activated 11,000 SIM cards with foreigners' stolen identities

Surge in networks scans targeting Cisco ASA devices raise concerns

Tenable Confirms Data Breach – Hackers Accessed Customers’ Contact Details

Tenable Confirms Data Breach in Widespread Salesloft Supply-Chain Attack

Tenable Confirms Data Breach; Salesloft and Drift Compromise Contained, Salesforce Integration Restored

Tenable Data Breach Confirmed - Customer Contact Details Compromised

The Cyberthreats No One Talks About but Everyone Faces

These iCloud Calendar invites look legitimate but are tricky phishing attacks – here’s how to tell

Third-party data breach confirmed by Wealthsimple

UC San Diego study questions phishing training impact

University of Southeastern Philippines (USeP) upgrades cybersecurity after breach

US Probes Malware Targeting US-China Trade Negotiations via Email Impersonating Lawmaker

US sanctions companies behind cyber scam centers in Cambodia, Myanmar

Venture Capital (VC) giant Insight Partners notifies staff and limited partners after data breach

Venus Protocol Recovers $11 Million In Record Time

Venus Protocol returns $11 million in crypto to phishing victim

Venus Protocol Returns $11M to User Who Lost Funds in Phishing Scam

We’re inextricably tied to our tech, and cyberstalkers know it

Wealthsimple Confirms Data Breach After Supply Chain Attack

Wealthsimple Data Breach - User Information Leaked Online

Wealthsimple Data Breach Exposes 30,000 Users’ Social Insurance Numbers (SINs) and DOBs

Wealthsimple reveals data breach - users of financial firm warned to be on alert

WinRAR Zero-Day RCE Vulnerability Allegedly for Sale for $65,000

You Didn't Get Phished - You Onboarded the Attacker

Young hackers claim responsibility for Jaguar Land Rover cyber attack

Zero-Day in Sitecore Exploited to Deploy WEEPSTEEL Malware