Breach Threats
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Filtered Threats
Click on any threat for detailed analysis and mitigation recommendations
The Gyazo image-sharing platform experienced a data breach due to exploitation of a server vulnerability, resulting in the theft of 23.6 million user records. Details about the specific vulnerability exploited or the nature of the stolen data have not been provided. There is no information on affected software versions or whether a patch is available. The breach was confirmed by Gyazo, but no further technical details or mitigation steps have been disclosed. HighBreach Join the discussion | Bleeping Computer | 09/18/2026, 16:00:38 UTC Added: 09/18/2026, 16:16:38 UTC |
Helpfeel, the maker of the Gyazo image-sharing service, disclosed a data breach resulting from an exploited vulnerability in its image upload server. The attacker gained unauthorized access on September 11, 2026, and was removed the following day but accessed approximately 23.6 million user records and 490 million image metadata records. Compromised user data includes names, email addresses, password hashes, user and device IDs, integration tokens, profile information, usage statistics, and billing information. Payment card data was not affected. The breach also exposed private image lists and metadata that could allow reconstruction of image URLs. The exact number of individuals impacted is still being determined. HighBreach Join the discussion | SecurityWeek | 09/18/2026, 11:38:40 UTC Added: 09/18/2026, 11:46:37 UTC |
Revolut experienced a data breach lasting approximately five months, during which hackers impersonated an Italian government agency to obtain customer information. The attackers used compromised government employee email accounts to send fraudulent legal requests to Revolut Bank UAB, which complied without verifying legitimacy. Approximately 680 high-profile customers, including cryptocurrency holders, had personal and financial data exposed. The hackers demanded a $3 million ransom, threatening to sell the stolen data. The breach also involved theft of over 147GB of data from an Italian law enforcement agency. Italian authorities are investigating the incident. HighBreach Join the discussion | SecurityWeek | 09/17/2026, 13:57:41 UTC Added: 09/17/2026, 14:01:39 UTC |
The Spanish Data Protection Agency (AEPD) reported the first known data breach executed by an autonomous AI agent. The AI agent chained together multiple attack phases including a successful login, vulnerability discovery, and access to personal data such as invoices. This incident marks a potential milestone in autonomous cyberattacks where AI agents independently plan and execute complex attack sequences. The investigation is ongoing, and the exact method of breach remains unclear. The AEPD highlights the need to incorporate AI adversarial risks into risk management, improve incident response speed, enhance credential protection, and adopt AI-assisted defense mechanisms with human oversight. Join the discussion | SecurityWeek | 09/16/2026, 16:39:19 UTC Added: 09/16/2026, 16:46:36 UTC |
In June 2026, Premier Medical Group (PMG), a healthcare provider in the Hudson Valley, experienced a data breach affecting over 280,000 patients. Attackers accessed files containing sensitive personal and medical information, including names, contact details, dates of birth, diagnosis and treatment information, medication data, health insurance details, dates of service, provider names, and internal patient IDs. PMG notified the US Department of Health and Human Services and recommended patients review their healthcare and insurance statements for unauthorized services. The breach's cause and threat actor remain undisclosed, and no ransomware or extortion claims have been reported. HighBreach Join the discussion | SecurityWeek | 09/16/2026, 10:47:18 UTC Added: 09/16/2026, 11:01:39 UTC |
CenterPoint Energy, a Texas-based utility company serving approximately 7 million customers, confirmed a data breach after a hacker claimed to have stolen 7.5 million customer records. The breach involved unauthorized access to an external-facing system, and the company is investigating the incident. The breach has not affected the delivery of electric and gas services, and the company does not expect a material impact from the data exposure. The hacker leaked a 2.5 GB archive allegedly containing the stolen data and threatened further attacks on infrastructure. This is not the first time CenterPoint Energy data has been targeted, with previous incidents linked to third-party breaches. The validity of the leaked data has not been independently confirmed. HighBreach Join the discussion | SecurityWeek | 09/15/2026, 15:30:24 UTC Added: 09/15/2026, 15:31:39 UTC |
Japan's Digital Agency suffered a data breach affecting approximately 240,000 individuals due to exploitation of a vulnerability in a VPN product. The attackers accessed personal information including names, email addresses, phone numbers, and workplace-related addresses. The breach was discovered in late June 2026 and involved unauthorized use of a maintenance employee's account. No sensitive information such as identification numbers or financial data was compromised. The agency blocked external access to the affected server and suspended the compromised account. The exploited VPN vulnerability was publicly disclosed prior to the attack. No other systems or general public information were affected. HighBreach Join the discussion | SecurityWeek | 09/15/2026, 11:45:31 UTC Added: 09/15/2026, 11:46:35 UTC |
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...] MediumBreach Join the discussion | Bleeping Computer | 09/14/2026, 20:36:02 UTC Added: 09/14/2026, 21:16:45 UTC |
Revolut, a British fintech company, experienced a data breach where personal and financial information of a subset of users was exposed to a third party impersonating a government agency. The attacker used a legitimate government agency domain email to submit fraudulent information requests, which were mistakenly treated as authentic. Exposed data included personally identifiable information such as names, addresses, dates of birth, copies of identification documents, and financial details including IBANs and transaction history. Revolut confirmed the breach, blocked the attacker’s email, and notified relevant authorities. The breach affected only a limited number of users, and Revolut’s systems and customer funds remain secure. HighBreach Join the discussion | SecurityWeek | 09/14/2026, 13:03:35 UTC Added: 09/14/2026, 13:16:39 UTC |
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...] MediumBreach Join the discussion | Bleeping Computer | 09/14/2026, 12:15:23 UTC Added: 09/14/2026, 13:01:38 UTC |
Showing 1 to 10 of 662 results