BigCommerce informed merchants of data breaches after attackers compromised credentials of third-party Ribon apps to inject malicious scripts into stores, highlighting risks from third-party applications in ecommerce.
Gyazo confirmed a data breach after a server vulnerability was exploited to steal 23.6 million user records, underscoring risks in platform security.
CenterPoint Energy confirmed a breach where attackers exfiltrated customers' personal data, emphasizing the ongoing threats faced by critical utility providers.
Attackers accessed the Florida Department of Highway Safety and Motor Vehicles' DAVID database using stolen police department credentials, resulting in a data breach.
IDScan confirmed that hackers accessed customer data on its cloud platform, exposing over 153 million driver’s license scans with sensitive personal identity information.
Healthcare provider AdaptHealth confirmed that data of 4.1 million people was exposed in a July cyberattack tied to the ShinyHunters threat group, highlighting ongoing risks to healthcare organizations.
IDScan faces multiple lawsuits after hackers allegedly breached its identity verification service and sold data on over 153 million driver’s licenses, highlighting critical risks in personal data security.
Aesto LLC, operating as Aesto Health, disclosed a data breach impacting over 9.5 million patients, highlighting critical risks to patient data security.
Berlin's city administration confirmed data theft following a ransomware attack by the Rhysida group, who are demanding ransom.
McKesson confirmed unauthorized access to third-party applications, with ShinyHunters claiming theft of 284 million patient records, raising healthcare data security concerns.
A critical ownCloud vulnerability tracked as CVE-2023-49105 has been added to CISA's KEV catalog following exploitation by a Chinese-speaking threat actor targeting a Philippine nuclear research organization.
Healthtech firm CareCloud disclosed a data breach impacting over 3.7 million patients, exposing sensitive healthcare information.
The StopAndProtect campaign uses nearly 2,000 compromised WordPress sites worldwide to distribute malware and collect stolen data, impacting web infrastructure security.
The ShinyHunters group breached RingCentral in July, compromising personal data of 1.6 million user accounts.
Trezor disclosed a data breach affecting nearly 14,000 customers after a logistics partner was hacked, exposing customer information but no wallet security or funds were compromised.
LexisNexis took down several services after detecting unusual activity on servers managed by a third-party vendor, raising concerns about potential data breaches.
A critical zero-day SQL injection vulnerability in Metabase has been exploited to breach customer instances, impacting Framework and Tally by enabling data theft.
Healthcare software provider Unlimited Technology Systems disclosed an October 2025 breach impacting over 3.8 million individuals and sensitive healthcare data.
A Canadian individual admitted guilt in a data theft scheme targeting Snowflake cloud accounts, compromising sensitive data from at least 165 organizations and pursuing extortion.
Two critical vulnerabilities in Paperclip, an open-source AI control plane, permit attackers to execute remote commands and expose sensitive data.
Amgen reported a cloud data breach involving unauthorized access to patient health data and proprietary corporate information via third-party cloud systems.
The ShinyHunters extortion gang claimed responsibility for a data breach at Ernst & Young obtained through a supply-chain attack involving stolen system credentials.
Upbound Group disclosed that threat actors exploited stolen data to create $13 million in fraudulent leases on Acima's platform, illustrating data theft risks in fintech.
The Anubis ransomware group has claimed responsibility for a cyberattack on Coca-Cola's Fairlife brand and threatened to leak stolen data if ransom demands are not met.
Abbott Laboratories is investigating unauthorized access incidents affecting Exact Sciences legacy systems and its LabCentral portal, with allegations of stolen company data linked to extortion.