BigCommerce informed merchants of data breaches after attackers compromised credentials of third-party Ribon apps to inject malicious scripts into stores, highlighting risks from third-party applications in ecommerce.
An attacker accessed about 170 private CrowdSec GitHub repositories using stolen credentials from the May TanStack npm supply chain attack, exploiting a compromised former employee account.
Gyazo confirmed a data breach after a server vulnerability was exploited to steal 23.6 million user records, underscoring risks in platform security.
Attackers compromised Brevo by stealing a Cloudflare API key and injecting malicious scripts into Brevo and its customers' websites, resulting in malware distribution via a supply-chain attack.
CenterPoint Energy confirmed a breach where attackers exfiltrated customers' personal data, emphasizing the ongoing threats faced by critical utility providers.
An attacker used a MeshCentral backdoor to gain root access to internal systems at 3BB, a major Thai broadband provider, exposing subscriber credentials and internal tools.
Attackers accessed the Florida Department of Highway Safety and Motor Vehicles' DAVID database using stolen police department credentials, resulting in a data breach.
IDScan confirmed that hackers accessed customer data on its cloud platform, exposing over 153 million driver’s license scans with sensitive personal identity information.
Healthcare provider AdaptHealth confirmed that data of 4.1 million people was exposed in a July cyberattack tied to the ShinyHunters threat group, highlighting ongoing risks to healthcare organizations.
Hackers exploited a vulnerability in Liquid Network's Elements sidechain to steal nearly 4,000 BTC, returning 3,400 BTC, while around 598.5 BTC remain unrecovered and the network remains paused.
JetBrains suffered a breach after attackers exploited an unpatched TeamCity vulnerability to access Cadence and extract AWS credentials.
IDScan faces multiple lawsuits after hackers allegedly breached its identity verification service and sold data on over 153 million driver’s licenses, highlighting critical risks in personal data security.
Attackers breached Coder's Cloudflare infrastructure to push malicious Terraform modules that embed credential-stealing code, threatening developer credentials.
Attackers leveraged a BGP hijack to redirect Softaculous update traffic, delivering a malicious Virtualizor update that established persistent root access on five hypervisors.
Aesto LLC, operating as Aesto Health, disclosed a data breach impacting over 9.5 million patients, highlighting critical risks to patient data security.
McKesson confirmed unauthorized access to third-party applications, with ShinyHunters claiming theft of 284 million patient records, raising healthcare data security concerns.
Over 9,300 AWS access keys leaked between 2022 and 2026 remain active, exposing corporate accounts to unauthorized access risks.
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients, exposing sensitive healthcare information.
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
Trezor disclosed a data breach affecting nearly 14,000 customers after a logistics partner was hacked, exposing customer information but no wallet security or funds were compromised.
LexisNexis took down several services after detecting unusual activity on servers managed by a third-party vendor, raising concerns about potential data breaches.
The North Carolina Ports Authority confirmed a cyberattack on IT systems at multiple ports causing operational delays and highlighting risks to critical infrastructure.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
A Canadian individual admitted guilt in a data theft scheme targeting Snowflake cloud accounts, compromising sensitive data from at least 165 organizations and pursuing extortion.
A flaw in the COLDCARD hardware wallet's random number generator enabled theft of $88.6 million in Bitcoin, compromising wallet seed security for thousands of users.
Amgen reported a cloud data breach involving unauthorized access to patient health data and proprietary corporate information via third-party cloud systems.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.
Upbound Group disclosed that threat actors exploited stolen data to create $13 million in fraudulent leases on Acima's platform, illustrating data theft risks in fintech.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.
Two hackers were sentenced for their 2024 attack on Transport for London, which disrupted 148 systems and forced a password reset for 27,000 employees, causing significant operational and financial impact.
Japanese telecom giant KDDI suffered a data breach affecting over 12 million people, with attackers accessing email addresses and passwords through a compromised platform used by multiple ISPs. The breach highlights significant risks in telecom infrastructure security.
Japanese ISP KDDI Corporation disclosed a data breach compromising up to 14.2 million email logins from one of its systems shared with five other ISPs. Threat actors gained unauthorized access, impacting multiple large providers.
Tata Electronics has confirmed a cyberattack impacting parts of its IT infrastructure, with hackers leaking some data. The incident highlights the ongoing risks to enterprise security from targeted attacks.