Skip to main content

Threats Tagged 'data-breach'

View all threats tagged with 'data-breach'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: data-breach

Threats Tagged 'data-breach'

Click on any threat for detailed analysis and mitigation recommendations

A data breach occurred at ShipMonk, a shipping provider for Trezor, exposing personal details of approximately 13,689 customers who placed orders between May and August 2026. Exposed data includes full names, email addresses, phone numbers, and shipping addresses. Trezor's own systems and hardware wallets were not compromised. The breach increases the risk of phishing attacks targeting affected customers. Trezor has notified impacted individuals and is working with ShipMonk to investigate and secure systems. Customers are advised to be vigilant against phishing and not to share wallet backups or sensitive information.

Join the discussion

This report highlights findings from IBM's 2026 Cost of a Data Breach study, emphasizing that AI adoption correlates with increased breach costs. Factors such as shadow AI, ungoverned agents, and unmonitored model access expand the potential impact of breaches. The report suggests that attackers move faster and detection windows shrink in AI environments, leading to higher costs. Recommended mitigations include discovering all AI systems, enforcing runtime policies on data flows, maintaining immutable audit trails, and implementing rapid kill switches to contain incidents.

Join the discussion
0

In June 2026, a large data breach involving stealer logs was added to the Have I Been Pwned (HIBP) database. The breach includes approximately 56.28 million unique email addresses and 124 million unique passwords collected from various stealer logs. These logs aggregate stolen credentials from multiple sources, making the data searchable by individuals and organizations via HIBP. The breach notification differs from traditional company database breaches, as it reflects aggregated stolen credentials rather than a single entity's compromise.

Join the discussion

Healthcare technology company Xsolis, Inc. disclosed a data breach affecting approximately 1.4 million individuals. The breach resulted from a targeted phishing attack detected on January 22, 2026, which allowed unauthorized access to files containing personal and protected health information. Compromised data includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information. The company is not aware of any misuse of the stolen information. The incident was publicly disclosed in early June 2026 and added to the US Department of Health and Human Services data breach tracker.

Join the discussion

Maine's official data breach notification portal allowed anyone to submit breach disclosures without verification, leading to fake breach reports being publicly posted. Notably, fraudulent notices impersonating Discord and VRChat were submitted, causing these companies to publicly deny the incidents. The portal has been taken offline while the Maine Attorney General's office reviews the situation. This lack of authentication in the submission process risks misinformation, reputational damage, and public panic.

Join the discussion

Kodak confirmed a data breach involving unauthorized access to a limited amount of company data. The ShinyHunters extortion gang claimed responsibility, stating they stole over 2.2 million records containing customer personally identifiable information (PII) and internal corporate data. Kodak is investigating the incident with external cybersecurity experts and cooperating with law enforcement. The company has not disclosed how the attackers gained access or whether the internal network was breached. ShinyHunters has a history of targeting multiple organizations and extorting data. Kodak has not yet provided details on remediation or mitigation.

Join the discussion

SoFi has confirmed a data breach involving unauthorized access to a database at a third-party vendor supporting its Hong Kong subsidiary, SoFi Securities (Hong Kong) Limited. The breach was discovered on April 30, 2026, and the investigation is ongoing, with the company not yet knowing the full scope or specific data exposed. SoFi has engaged a third-party cybersecurity firm to respond and has implemented additional safeguards and monitoring. Customers have been advised to remain vigilant for phishing and suspicious activity, update passwords, enable two-factor authentication, and monitor accounts closely. The company has not disclosed the number of affected customers or the identity of the vendor involved. Support contact information has been provided for affected customers.

Join the discussion

GitHub has announced that its internal data was breached. The announcement was made publicly via a social media post. No detailed technical information or specifics about the nature or scope of the breach have been provided. There is no indication of affected product versions or known exploits in the wild. The incident is classified with medium severity based on the available information.

Join the discussion

A ransomware attack on Covenant Health resulted in a data breach affecting over 478,000 individuals. The attack involved malware that encrypted or compromised sensitive health data, leading to significant exposure of personal information. Although no specific exploited vulnerabilities or affected software versions are detailed, the breach highlights the ongoing risk ransomware poses to healthcare organizations. There is no indication of known exploits in the wild beyond this incident. The breach underscores the importance of robust cybersecurity measures in protecting sensitive health data. European healthcare organizations face similar risks due to comparable threat landscapes and regulatory environments. Mitigation requires targeted strategies including network segmentation, advanced endpoint detection, and incident response readiness. Countries with large healthcare sectors and high adoption of similar IT infrastructure are most at risk. The severity is assessed as high due to the scale of data exposure, potential for patient harm, and operational disruption. Defenders should prioritize proactive ransomware defenses and comprehensive data protection protocols.

Join the discussion

A hacker claims to have stolen over 3 million records from Tokyo FM, a major Japanese radio broadcaster, indicating a significant data breach. The breach was reported via Reddit and linked to an external news source, but technical details and affected systems remain undisclosed. No known exploits or patches have been identified yet. The breach poses a high risk to confidentiality due to the volume of data compromised, potentially including personal information of listeners or employees. European organizations may face indirect impacts through partnerships or data sharing with affected entities. Mitigation focuses on enhanced monitoring, incident response readiness, and reviewing data sharing agreements. Countries with strong media sectors and close business ties to Japan, such as Germany, the UK, and France, are more likely to be affected. Given the scale and nature of the breach, the suggested severity is high due to the potential for identity theft, reputational damage, and regulatory consequences. Defenders should prioritize verifying the breach scope, securing exposed systems, and preparing for possible secondary attacks leveraging stolen data.

Join the discussion

Showing 1 to 10 of 134 results

Filters:Tag: data-breach
Page 1 of 14
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses