A 2025 intrusion at a medical billing company shows how one vendor network can become a large-scale privacy event when regulated health and identity data sit in the same place.
A sextortion campaign is reusing exposed email addresses and personal details to sound credible, while the payment demand stays fixed at $2,000 in Bitcoin.
A reported breach affecting 900,000 Australians sits alongside an unverified claim of information from 2 million customers, underscoring how quickly scale can be framed before it is verified.
The alleged credential theft tied to Ernst & Young is a reminder that supply-chain claims can signal risk even before the technical details are confirmed.
A Vatican-linked app case shows how broken access control can turn ordinary web requests into large-scale data exposure, even when the interface looks harmless.
Coca-Cola has confirmed a data breach tied to a ransomware incident involving Fairlife, while Anubis has claimed the attack and threatened to leak data.
A breach at DentaQuest puts a spotlight on a less visible target class: the claims and benefits systems that can concentrate identity, billing, and health-related records in one place.
MCBS has linked a breach to 1.2 million affected individuals, while the PEAR ransomware group claimed to have taken 3 TB of information - a reminder that volume claims and verified exposure are not the same thing.
A link-sharing feature can be convenient for collaboration, but if the resulting page is crawlable, a private conversation can drift into search results with no attacker required.
A convenience feature can turn into an exposure surface when a public chat link is reachable by crawlers, reminding users that AI collaboration tools can create web objects, not private notes.
A browsable API endpoint appears to have exposed personal details for more than 700,000 users, underscoring how quickly weak data controls can turn an ordinary service into a sensitive data source.
More than 13,000 Chick-fil-A customer accounts were caught in a credential-stuffing campaign, a reminder that the weakest link in many consumer platforms is often the login box itself.
A confirmed security incident at an Australian energy company has turned into a privacy and fraud problem, with attackers claiming customer data and threatening to publish it.
The company has confirmed customer data was compromised, but the unresolved question is how many Australians are in the blast radius and what the stolen records could be used for next.
A loyalty-account incident shows how credential stuffing can turn a consumer login into a privacy problem and a stored-value problem at the same time.
A reported breach at Upbound Group shows how even data described as non-sensitive can become a fraud tool when criminals target contract origination and verification workflows.
Stadler Rail says it will not pay the ransom demand after technical data was reportedly taken from a supplier’s file-sharing platform, leaving the scope of the incident under scrutiny.
A confirmed incident affecting Chick-fil-A One accounts shows how credential stuffing can turn ordinary password reuse into a serious account-security and payment-risk problem.
A cyber incident at the Korea National Diplomatic Academy shows how a routine government training portal can become a high-value target when authentication and access controls are weak.
A confirmed unauthorised-access incident at an energy retailer is a reminder that identity data, billing records, and trust in official communications can all become attack surfaces at once.