Data Breaches

Our Data Breaches category brings you the latest updates on security incidents affecting organizations, businesses, and individuals worldwide. From high-profile breaches to industry-specific leaks, we provide timely news and in-depth analysis to help you understand the risks.

Learn how breaches occurred, what data was exposed, and the steps you can take to protect your sensitive information. Explore our expert advice and actionable tips to safeguard your online identity.

New Voldemort Malware Using Google Sheets To Store Stolen Data

New Voldemort Malware Using Google Sheets To Store Stolen Data

Hackers abuse Google Sheets to covertly store and transmit stolen data or execute malicious scripts, taking advantage of its trusted platform status and collaboration features. Cybersecurity researchers at Proofpoint identified an unusual campaign in August...
AWS ENV Extortion 110K Domains

Hackers Exploited AWS ENV Files to Attack 110,000 Domains & Steal Credentials

A sophisticated extortion campaign targeted 110,000 domains by exploiting exposed .env files on unsecured web applications. The attackers obtained AWS IAM access keys from these files, which allowed them to create new IAM roles...
Cyber Attack On AWS

Massive Cyber Attack On AWS Cloud Environment with 230 Million Unique Targets

A complex large-scale campaign was detected by Unit 42 researchers that manipulated and extorted several organizations using cloud systems.  Security analysts discovered this massive, large-scale cyber attack on AWS cloud environments had over 230 million...
ADT Data Breach: Customers Personal Information Exposed

ADT Data Breach: Customers Personal Information Exposed

ADT Inc., a prominent security and automation solutions provider, reported that unauthorized actors accessed specific databases containing customer order information. The company swiftly addressed the breach, which raised concerns about data security and customer...
ServiceNow Flaw Let Remote Attackers Execute Arbitrary Code

ServiceNow Flaw Let Remote Attackers Execute Arbitrary Code

ServiceNow recently disclosed three critical vulnerabilities (CVE-2024-4879, CVE-2024-5217, and CVE-2024-5178) affecting multiple Now Platform versions, allowing unauthenticated remote code execution and unauthorized file access.  The vulnerabilities, with CVSS scores ranging from 6.9 to 9.3, pose...
ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

A massive data breach involving ClickBalance, one of Mexico's largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by cybersecurity researcher Jeremiah Fowler. The breach exposed a staggering 769,333,246 records, totaling 395 GB...
Tools Used By NullBulge Actor, Who Released Disney’s Internal Slack Communications

Tools Used By NullBulge Actor, Who Released Disney’s Internal Slack Communications

Hackers often target internal communications tools to obtain confidential information like employee records, business plans, and proprietary technologies. With these characteristics of trust and openness, internal communications provide valuable but less secure means for cyber-attacks...
BMW Hong Kong Faces Major Data Breach

BMW Hong Kong Faces Major Data Breach: 14,000 Customer Records Exposed

BMW Hong Kong has reportedly suffered a data breach affecting approximately 14,000 customers. The leak, which came to light on July 16, 2024, has exposed sensitive personal information, raising concerns about customer privacy and...
4000+ Domains Used By FIN7 Actors Mimic Popular Brands

4000+ Domains Used By FIN7 Actors Mimic Popular Brands

Russian-linked FIN7 (aka Sangria Tempest, ATK32, Carbon Spider, Coreid, ELBRUS, G0008, G0046, and GOLD NIAGARA) is a financial cybercrime group that has been around since 2013 and it specifically targets the US industries. To achieve...
Evolve Bank Data Breach: 7.6 Million Individuals’ Data Exposed

Evolve Bank Data Breach: 7.6 Million Individuals’ Data Exposed

Evolve Bank & Trust, a prominent financial services institution, has confirmed a data breach that has compromised the personal information of over 7.6 million individuals. The breach, which occurred on February 9, 2024, was...

Recent Posts

CyTwist Launches Advanced Security Solution to identify AI-Driven Cyber Threats in...

CyTwist, a leader in advanced next-generation threat detection solutions, has launched its patented detection engine to combat the insidious rise of AI-generated malware. The cybersecurity...