Ceva Logistics: One Processor, Ten Controllers, and a Notification Chain That Took Five Days
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
53 articles on data-breach โ privacy laws, security frameworks, and regulatory compliance.
A cyberattack on eight European warehouses run by Ceva Logistics has produced breach reports to the Dutch data protection authority from at least ten ...
Amgen detected unauthorized activity in July 2026 and filed a Form 8-K on 29 July declaring the incident material. Attackers exfiltrated proprietary i...
Levi Strauss & Co. filed a Form 8-K on 7 August 2026 disclosing that an unauthorized third party accessed company files through social engineering aga...
Connor Riley Moucka pleaded guilty on 5 August 2026 to computer fraud, conspiracy, and aggravated identity theft over the 2024 Snowflake extortion cam...
CareCloud, a revenue cycle management vendor serving more than 45,000 U.S. healthcare providers, began notifying at least 345,000 individuals in late ...
Attackers were inside Medical Computer Business Services of Augusta, Georgia between 22 and 26 September 2025. The investigation concluded on 28 May 2...
When we covered the DentaQuest breach in June, the working figure was 2.6 million people. Notification letters that began rolling out on 17 July 2026 ...
An intruder was inside the network of Mercadien, P.C., CPAs between 17 September and 9 October 2025. Pinnacle Financial Partners did not determine tha...
Ernst & Young LLP is notifying clients that an unauthorized third party accessed a third-party IT service management platform between 28 March and 12 ...
A bipartisan coalition of 43 state attorneys general secured an $18 million settlement from 23andMe over the 2023 credential-stuffing breach that expo...
Lidl notified online shop customers in Germany, Belgium, and the Netherlands that attackers stole personal data from an external IT service provider โ...
An extortion group calling itself Shadowbyt3$ stole roughly 859 MB of Nintendo of America employee data โ including W-9 tax forms and bank statement P...
The extortion group World Leaks published nearly 19,000 files (14.3 GB) tied to India's Kudankulam Nuclear Power Plant. The plant operator's systems w...
Conduent Business Solutions told federal regulators on June 4, 2026 that 62,224,658 people had data exposed in a SafePay ransomware intrusion โ the th...
Attackers exploited a zero-day in unnamed third-party software to sit inside the shared email platform behind six Japanese ISP brands for a month, exp...
AssuranceAmerica detected intruders in its network on March 17, 2026 โ roughly 24 hours after a credential attack on an employee. Notification letters...
A threat actor called 888 is selling what they claim is 35 GB of Accenture source code, plus RSA keys, SSH keys, Azure personal access tokens, and sto...
Mount Royal University confirmed that attackers who breached its network on June 17, 2026 stole data from its student and employee file storage, then ...
Between May 27 and June 10, 2026, attackers linked to ShinyHunters exploited CVE-2026-35273, a critical Oracle PeopleSoft zero-day, against more than ...
The National Association of Insurance Commissioners โ the body that wrote the insurance industry's data security model law โ confirmed it was compromi...
Medtronic has begun notifying individuals that attackers accessed its corporate IT systems between April 13 and 19, 2026, stealing names, dates of bir...
In J.M. v. Illuminate Education, the California Supreme Court rejected a line of appellate decisions that had forced data-breach plaintiffs to prove a...
On June 26, 2026, breach disclosures surfaced for MagMutual Insurance, 911 Driving School, and Germany's Atlas Elektronik on the same day. The three i...
In June 2026, attackers used social engineering to break into third-party-hosted business applications at iRhythm Holdings, maker of the Zio cardiac p...
In June 2026, the cybercrime group ShinyHunters breached Madison Square Garden Sports and affiliated MSG entities, claiming more than 26 million custo...
ShinyHunters breached Instructure's Canvas learning platform, exposing data tied to hundreds of millions of users across roughly 8,800 institutions an...
Comcast agreed to pay $117.5 million to resolve claims from the October 2023 Xfinity breach that exposed the data of more than 30 million customers. T...
LabCorp agreed to a $35 million settlement over the American Medical Collection Agency breach that exposed data on more than 10 million of its patient...
The administrator of 23andMe's bankruptcy plan agreed to pay $46.75 million to victims of the 2023 breach that exposed genetic and personal data of ro...
A wave of class-action lawsuits accuses Charter Communications of failing to safeguard the data of Spectrum customers after a vishing attack let hacke...
Novo Nordisk disclosed that patient data from some clinical trials was copied externally in a cyberattack. The data was pseudonymized, not anonymized ...
South Korea's Personal Information Protection Commission hit e-commerce giant Coupang with a record fine of more than $409 million after a breach expo...
The extortion group ShinyHunters leaked roughly 234 GB of data tied to DentaQuest, the Sun Life-owned dental benefits administrator, exposing names, d...
May 2026 saw 95 publicly disclosed ransomware attacks across 17 countries, with Qilin and ShinyHunters leading a campaign that increasingly skips encr...
NYC Health + Hospitals confirmed a breach affecting 1.8 million individuals โ including fingerprints and palm prints โ originating through a third-par...
Charter Communications confirmed on May 25, 2026 that a ShinyHunters vishing attack on a Microsoft Entra credential gave the threat actor access to Ch...
West Pharmaceutical Services detected a ransomware attack on May 4, 2026, disclosing via SEC 8-K that attackers exfiltrated data and encrypted systems...
On May 2, 2026, Trellix โ the cybersecurity company formed from the merger of McAfee Enterprise and FireEye, serving more than 50,000 enterprise and g...
In late April and early May 2026, Cushman & Wakefield confirmed a cyberattack originating from a voice phishing operation that gave ShinyHunters acces...
ShinyHunters breached Instructure's Canvas learning management system twice in May 2026, stealing an estimated 275 million records โ names, email addr...
In January 2026, France's data protection authority fined Free Mobile โฌ27 million and its parent Free โฌ15 million โ a combined โฌ42 million โ for three...
In April 2026, ShinyHunters executed two related but technically distinct supply chain attacks: a Salesforce Experience Cloud misconfiguration at McGr...
On April 20, 2026, the Everest ransomware gang listed both Citizens Financial Group and Frost Bank on its dark web leak site, claiming to hold 3.4 mil...
On April 22, 2026, Netherlands-based luxury cosmetics chain Rituals confirmed that attackers had accessed its customer membership database, exposing n...
A software defect introduced during an overnight IT update on March 12, 2026 caused Lloyds, Halifax, and Bank of Scotland app users to see other custo...
Booking.com confirmed hackers accessed customer reservation data in April 2026, raising immediate GDPR 72-hour notification questions โ and echoing a ...
A threat actor known as 'Mr. Raccoon' claims to have stolen 13 million Adobe customer support tickets and 15,000 employee records โ not by hacking Ado...
Europe's largest fitness chain confirmed on April 13, 2026 that a cyberattack exposed the personal and bank account details of approximately one milli...
In the span of a single week, five separate class action lawsuits landed in federal courts against Mercor.io Corporation. The complaints vary in scope...
A supply chain attack, a compliance fraud scandal, and invasive contractor surveillance converge in a single federal lawsuit โ exposing the fragile tr...
In 2025, ransomware groups launched 1,174 publicly disclosed attacksโa 49% year-over-year increaseโand healthcare bore the heaviest burden with 22% of...
Cornwall Council exposed the personal data of 10 complainants โ including home addresses, emails, and phone numbers โ after redacted PDFs automaticall...
Two class-action lawsuits now target Mercer Advisors after ShinyHunters exposed 5.7 million records and hit Beacon Pointe and Pathstone. Analysis of F...