Skip to content

Topic

Data Breaches

Incidents where attackers gain unauthorized access to personal, financial, or organizational data, often followed by theft, exposure, or extortion.

Current stories

securityConfirmed10 publishers

Arrests of ShinyHunters suspects reach at least three in two weeks after FBIjobs.gov breach

FBI Director Kash Patel says agents arrested another ShinyHunters suspect, at least the third detained in two weeks since the FBIjobs.gov breach. The group says it is leaving Telegram as members are arrested, and it has promised not to publish the FBI staff data it stole.

Perspective Coverage

10 publishers
Builder
Builder 16%
Operator
Operator 65%
Investor
Investor 19%

Reality

Evidence66
Adoption
Insufficient
Hype gap+20
Incentives60
Confidence62
securityConfirmed17 publishers

South Korea suspects AI agents in bank breaches that leaked data on at least 25,000 Shinhan customers

President Lee Jae Myung says AI appears to have been used in hacks on South Korean banks that leaked data on at least 25,000 Shinhan customers. If his claim that AI removes the need for specialized skills holds up, banks should plan for many more attackers.

Perspective Coverage

18 publishers
Builder
Builder 32%
Operator
Operator 52%
Investor
Investor 16%

Reality

Evidence70
Adoption35
Hype gap+20
Incentives55
Confidence64
investOne report1 publisher

Japan's FSA asks banks and crypto exchanges to drop photo-ID checks before the 2027 deadline

Japan's FSA asked banks and crypto exchanges to swap photographed-ID checks for IC-chip reading now, ahead of an April 1, 2027 deadline. The request follows a Times Car breach of about 1.6 million license images, Cryptopolitan reported, and leaves each firm to decide whether to pay for the switch this year or wait for the law.

Reality

Evidence42
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
leadershipConfirmed2 publishers

Asos widens its breach disclosure after hackers share a data sample with the BBC

Asos says hackers took detailed profiles of potentially millions of customers, after first telling investors only basic contact details may have been accessed. The revision followed the attackers' approach to the BBC, so the people holding the records set the timing of the fuller disclosure.

Reality

Evidence68
Adoption
Insufficient
Hype gap+10
Incentives60
Confidence65
investConfirmed2 publishers

Revolut will pay for new IDs after sending 680 customers' data to a hijacked Italian police email

Revolut will pay to replace identity documents for the 680 customers whose data it sent to a hijacked Italian government email address. The bank has not put a price on the pledge, and it disagrees with Italy's interior minister over whose check let the request through.

Reality

Evidence62
Adoption
Insufficient
Hype gap+12
Incentives70
Confidence60
securityOne report1 publisher

JPCERT/CC links Japan's data-leak run to app APIs and BI tools owners thought were internal

JPCERT/CC says attackers abused mobile-app APIs and exploited a known Metabase flaw in a leak run Macnica puts at 119 Japanese incidents this year. Some leaks came from BI tools and staff systems their owners never expected outsiders to reach, so the alert asks for access control on every endpoint, public or not.

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
investConfirmed3 publishers

Attackers' servers held 960,000 member records from Korea's Yoido Full Gospel Church

Oasis Security says attackers' servers held about 960,000 Yoido Full Gospel Church member records with resident registration numbers. The church is still verifying, but the cache shows how much identity and donation data sits behind one administrator account at a large congregation.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 55%
Investor
Investor 12%

Reality

Evidence58
Adoption
Insufficient
Hype gap+30
Incentives35
Confidence60
securityConfirmed15 publishers

Denmark says hackers reached 8.8 million people's records through a company's register access

Denmark says hackers used a Danish company's search access to the Central Person Register to reach names, addresses and ID numbers of 8.8 million people. Because that access is a service offered to businesses by design, every partner account with search rights is part of the register's security perimeter.

Perspective Coverage

15 publishers
Builder
Builder 24%
Operator
Operator 67%
Investor
Investor 9%

Reality

Evidence74
Adoption
Insufficient
Hype gap+12
Incentives30
Confidence70
securityConfirmed3 publishers

Rhysida gives Berlin seven days before it auctions 5.79TB of city data

Kai Wegner has ruled out paying, which leaves a seven-day clock running on 5.79 terabytes the group says it holds. Two Berlin department networks were already offline for days, and the city still cannot say what was in the files.

Perspective Coverage

3 publishers
Builder
Builder 13%
Operator
Operator 77%
Investor
Investor 10%

Reality

Evidence65
Adoption
Insufficient
Hype gap−25
Incentives60
Confidence62
securityConfirmed6 publishers

One phishing click let attackers copy over 150,000 foster-care reports from Arizona court backups

Arizona's Supreme Court says attackers copied over 150,000 foster-care review reports dating to 2010 from backups after an employee clicked a phishing link. The court kept those copies to recover from ransomware, so the store meant to survive an attack is the one that leaked.

Perspective Coverage

6 publishers
Builder
Builder 24%
Operator
Operator 68%
Investor
Investor 8%

Reality

Evidence78
Adoption
Insufficient
Hype gap−20
Incentives35
Confidence72
securityOne report1 publisher

Bromcom removes a legacy SSO registration feature after a breach exposed users' email addresses

UK education software supplier Bromcom says unauthorized access to a legacy SSO registration feature exposed users' email addresses and reference numbers. Its school records system was not reached, so the question for schools is which older login features suppliers still run.

Publishers:scworld.com

Reality

Evidence45
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
investOne report1 publisher

Hackers took data on 25,000 Shinhan customers through a site built for loan recruiters

South Korea's financial regulator gave lenders until Thursday to check every internet-facing system after hackers breached at least seven banks. Attackers entered through tools built for loan recruiters and staff, so the repair falls on how much credit data banks let outsiders see.

Reality

Evidence60
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence55
investConfirmed2 publishers

FSC chief Lee Eok-won promises strict accountability for whichever Korean lender is breached next

FSC chairman Lee Eok-won told Korean financial firms they will be held strictly accountable under law if the hacks that hit six lenders happen again. The threat covers future breaches, so for the firms already hit the cost so far is five requests, including security checks and customer compensation.

Reality

Evidence58
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence55

Earlier coverage

  1. Korea orders every bank and card firm to audit exposed systems after leaks at four lenders

    Invest · October 3, 2026 · Confirmed2 publishers

  2. Pentagon personnel agency discovered the file-server flaw nine months after intruders began using it

    Security · September 29, 2026 · Confirmed7 publishers

  3. Pentagon breach exposes the job specialties of 2.8 million current and former personnel

    Product · October 1, 2026 · Confirmed2 publishers

  4. Fakturownia breach may have exposed bank details and integration tokens of its invoicing customers

    Security · October 1, 2026 · One report1 publisher

  5. Arizona's court system says hackers copied residents' data without deploying ransomware

    Security · October 1, 2026 · Confirmed2 publishers

  6. ShinyHunters threatens to publish FBI agents' medical records unless the bureau retracts a May advisory

    Security · September 30, 2026 · One report1 publisher

  7. Ransomware at Tokyo rail operator Keio reaches the group's hotel business

    Security · September 30, 2026 · Confirmed4 publishers

  8. Researchers say leaked FBI assignment data puts agents at risk of direct targeting

    Security · September 28, 2026 · One report1 publisher

  9. DataSuckers prices a claimed 68 million Dodo Pizza records at $100,000

    Security · September 29, 2026 · One report1 publisher

  10. ShinyHunters vows to withhold FBI employee files it has already used against one agent

    Security · September 28, 2026 · One report1 publisher

  11. Times Car confirms driver's license images were taken in breach of 6.6 million accounts

    Security · September 28, 2026 · One report1 publisher

  12. ShinyHunters' leak samples expose named FBI agents' medical exams

    Security · September 28, 2026 · One report1 publisher

  13. ShinyHunters says its FBI haul of up to three terabytes includes staff psychiatric records

    Invest · September 26, 2026 · One report1 publisher

  14. Beacon cannot tell what the attacker took, so 1,000-plus charities must assume everything

    Security · August 14, 2026 · Confirmed2 publishers

  15. RingCentral's platform held. Its customer records are on the internet anyway.

    Security · August 14, 2026 · Confirmed3 publishers

  16. SafePal's breach came through an order-tracking plug-in, and that is the point

    Product · August 16, 2026 · Confirmed3 publishers

  17. Stolen logins, not a SaaS breach: nine enterprises' Entra directories are now for sale

    Security · August 17, 2026 · Confirmed5 publishers

  18. SafePal's leaked order book is a target list: 39,798 wallet buyers, with addresses

    Security · August 16, 2026 · Confirmed8 publishers

  19. Heights Finance says its loan systems held. 1.2 million records went anyway.

    Security · August 18, 2026 · Confirmed5 publishers

  20. ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch

    Invest · September 26, 2026 · One report1 publisher

  21. The counter scan that cleared a customer for entry is now for sale by name

    Product · September 2, 2026 · Confirmed7 publishers

  22. MAG's car park and airport Wi-Fi systems gave up 8.7 million identity records

    Security · August 28, 2026 · Confirmed6 publishers

  23. Nexus sells 153 million license scans that Krebs traces to a Louisiana IDV vendor

    Security · September 1, 2026 · Confirmed7 publishers

  24. North Korea's WaterPlum fake-recruiter campaign has stolen $10.7 million from IT workers

    Security · September 25, 2026 · One report1 publisher

  25. Trezor says ShipMonk kept 67,000 customer records it had certified as deleted

    Security · September 6, 2026 · Confirmed3 publishers

  26. IDScan.net's breach notice puts 153 million licenses in cloud accounts it kept after the check

    Product · September 11, 2026 · Confirmed5 publishers

  27. Florida traces the DAVID driver database breach to one Plant City police account

    Security · September 11, 2026 · Confirmed2 publishers

  28. Revolut handed over passport scans to fraudulent requests sent from a real government domain

    Product · September 12, 2026 · Confirmed2 publishers

  29. Revolut released passports and Bitcoin histories on an email that passed domain authentication

    Invest · September 12, 2026 · Confirmed5 publishers

  30. CenterPoint confirms a customer data theft it learned about from a dark web post

    Security · September 16, 2026 · Confirmed6 publishers

  31. Gyazo's breach exposed the 32-character image IDs that were the only protection on older captures

    Security · September 17, 2026 · Confirmed6 publishers

  32. ShinyHunters claims an Oracle PeopleSoft exploit opened the FBI's job application portal

    Product · September 23, 2026 · One report1 publisher

  33. France logged fake crypto support calls five months before the tax breach began

    Invest · September 21, 2026 · Confirmed2 publishers

  34. Nexus sold access to 153 million genuine US and Canadian driver's licences

    Security · September 10, 2026 · One report1 publisher

  35. Stolen infrared and UV scans put the document check itself inside the IDScan.net breach

    Leadership · September 7, 2026 · Confirmed4 publishers

  36. 88 breaches, 2.15 billion records, and 41 leaks that nobody can reset

    Security · August 26, 2026 · One report1 publisher